Why quantum computers threaten cryptography
Asymmetric cryptography uses one key for encryption and another for decryption. It is based on an elegant principle: a mathematical operation is easy to perform but extremely difficult to reverse, such as multiplying large prime numbers. Reversing this process to identify the original factors would take classical computers millions of years. Quantum computers could accomplish the same task in minutes. This is made possible by Shor’s algorithm, developed in the early 1990s, although the necessary hardware has only recently begun to emerge.
These machines are now becoming a reality. IBM, Google and various research groups have already demonstrated successful implementations of Shor’s algorithm, and development is accelerating rapidly. Experts expect cryptographically relevant quantum computers to become available within the next five to ten years – initially in the hands of governments, intelligence agencies and major corporations.
Even symmetric cryptographic methods, which use the same key for encryption and decryption, will no longer be entirely secure. Grover’s algorithm effectively halves their key length and therefore their strength.
The consequences are significant: encrypted communications could be intercepted, documents and identities could be forged, and industrial espionage would become considerably easier. Furthermore, no one will know who already possesses such a quantum computer.
The solution already exists
The good news is that the countermeasure is already available. Post-Quantum Cryptography (PQC) refers to cryptographic methods based on alternative mathematical foundations – such as lattice-based cryptography – that remain secure even against quantum computers. They can run on existing hardware.
Following a multi-year open selection process, the US National Institute of Standards and Technology (NIST) has already standardised the first PQC algorithms: ML-KEM, ML-DSA and SLH-DSA. At least two more are currently in development. Germany’s Federal Office for Information Security (BSI) also recommends additional methods. The landscape is still evolving, but the direction is clear.
What organisations should do now
What does this mean for organisations? Many applications, including browsers, operating systems and common communication software, will be upgraded to PQC through vendor updates. Not every organisation therefore needs to replace everything immediately. Nevertheless, there are areas that remain under direct organisational responsibility.
The first step is to establish a crypto inventory: a structured overview of which cryptographic methods are used across the organisation and where. This is less complex than it may sound and delivers benefits beyond PQC. Organisations that know which algorithms are deployed and where can respond much more quickly when new vulnerabilities are discovered.
When prioritising actions, it is important to consider the time dimension. Real-time applications such as logins will only become vulnerable once quantum computers are actually available. More critical are data sets that can be collected today and decrypted later – the so-called 'harvest now, decrypt later' scenario. Research and development data, confidential contracts and other long-term sensitive information should therefore be treated as a priority.
What to expect
PQC algorithms are conceptually mature but not yet as efficient as their predecessors. Keys and signatures are larger, and calculations require more resources. On standard computers this is barely noticeable. Embedded systems, smart cards and tokens with limited storage capacity and processing power, however, face genuine challenges. In some cases, it is still unclear which PQC methods will ultimately be suitable for these environments.
The migration of existing infrastructures such as VPNs and PKIs will also take time, even where vendor updates are available. Upgrades, testing and process adjustments cannot be completed overnight. Organisations that begin assessing their current position today will gain a significant advantage tomorrow.
Post-Quantum Cryptography is no longer a future concept – it is the logical response to an evolving threat landscape. Organisations do not need to overhaul everything immediately. However, they should understand their current position, identify which processes are affected and determine where action is required. Those who establish a solid foundation now will be able to manage the transition far more confidently.
Author: Dr. Markus von Detten, Senior Consultant PKI, achelos GmbH