Post-quantum cryptography overview
Post-quantum cryptography (PQC) represents new encryption algorithms that can strongly resist quantum computer attacks, addressing the urgent need for quantum-resistant security.
PQC is a new generation of cryptographic algorithms that resists attacks from quantum computers. Unlike current encryption methods such as Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC), PQC algorithms can strongly resist computational power of quantum computers using Shor's algorithm.
Quantum computer threat
Quantum computers pose a significant threat to current cryptographic standards with their capability to break traditional encryption methods that protect most digital communications. This vulnerability creates a security concern related to attacks that collect encrypted data with the intention of decrypting it after quantum computers are available.
PQC regulations
Cryptographic Asset Compliance checks PQC compliance against the following regulation standards:
- NIST FIPS 204 (ML-DSA): Module-Lattice-Based Digital Signature Algorithm
- NIST FIPS 203 (ML-KEM): Module-Lattice-Based Key-Encapsulation Mechanism
- ISO/IEC 27001 Annex A 8.24: Information security control for the use of cryptography
Cryptographic agility
Cryptographic Asset Compliance supports the ability to quickly and efficiently transition between cryptographic algorithms without significant changes to system architecture. It provides comprehensive visibility into your organization's cryptographic landscape, which enables you to understand your current cryptographic dependencies before transitioning to quantum-resistant algorithms.
With Cryptographic Asset Compliance, your organization can identify which systems and applications rely on vulnerable algorithms, prioritize migration efforts based on risk assessment, and track progress throughout the PQC transition.