Curriculum / Quantum Cryptography / Post-Quantum Cryptography Standards

Lesson 5 of 21ReadingPro+75 XP

Post-Quantum Cryptography Standards

Understand NIST's post-quantum cryptographic standards and when to use them.

Post-Quantum Cryptography Standards

In 2024, NIST finalized the first post-quantum cryptographic standards after a 7-year competition. These algorithms are designed to be secure against both classical and quantum computers, including hypothetical future quantum computers running Shor's and Grover's algorithms.

Why New Standards Were Needed

RSA and ECC (elliptic curve cryptography) dominate modern public-key cryptography. Both are broken by Shor's algorithm on a sufficiently powerful quantum computer. The transition cannot wait until quantum computers reach that scale: systems with long data lifetimes (government, medical, financial) need to migrate now to avoid "harvest now, decrypt later" attacks.

NIST launched its PQC standardization process in 2016, receiving 69 submissions from cryptographers worldwide. After three rounds of public cryptanalysis and competition, four algorithms were standardized in 2024.

The Four NIST Standards

CRYSTALS-Kyber (now called ML-KEM, FIPS 203) A key encapsulation mechanism (KEM) based on the hardness of the Module Learning With Errors (MLWE) problem. Used as a drop-in replacement for RSA key exchange and ECDH. Security rests on lattice problems believed hard for both classical and quantum computers. Key sizes: 800-1568 bytes (vs 256 bytes for ECC-256 key exchange).

CRYSTALS-Dilithium (now called ML-DSA, FIPS 204) A digital signature algorithm based on MLWE and Module Short Integer Solution (MSIS). Replaces RSA signatures and ECDSA. Signature size: 2420-4595 bytes (vs 64 bytes for Ed25519). Faster signing and verification than RSA.

FALCON (now called FN-DSA, FIPS 206) A compact digital signature algorithm based on NTRU lattices. Smaller signatures than Dilithium (666-1280 bytes) but more complex implementation (floating-point arithmetic, timing side-channel risk). Preferred when bandwidth is constrained.

SPHINCS+ (now called SLH-DSA, FIPS 205) A stateless hash-based signature scheme. No lattice assumptions: security reduces to the hash function's collision resistance. Conservative choice: still secure even if lattice assumptions turn out to be breakable. Larger signatures (7856-49856 bytes) and slower than lattice-based alternatives.

This is the opening of the lesson. The full walkthrough, the interactive circuit, and the graded challenge continue inside myqubit.

How this lesson works

A guided reading lesson with interactive knowledge checks. Concepts are explained step by step with circuit diagrams and runnable examples, and you confirm understanding before moving on.

Part of: Quantum Cryptography

Master quantum key distribution, the threat quantum computers pose to classical cryptography, and post-quantum cryptographic standards.

This lesson is part of Pro

Unlock Quantum Cryptography and all 10 tracks with Pro: $12.99/month, $79/year, or $97 lifetime. Start with the free track first if you are new.