Skip to content
Tech News
← Back to articles

Building a practical path to post-quantum cryptography

read original more articles
Why This Matters

This article highlights the importance of a pragmatic approach to post-quantum cryptography, emphasizing that the threat posed by quantum computers is gradual rather than immediate. It underscores the need for deliberate planning and modernization in cybersecurity to safeguard sensitive data against future quantum attacks, with government initiatives signaling confidence in transitioning to quantum-resistant standards. Recognizing this evolution allows the tech industry and consumers to prepare proactively, rather than reactively, ensuring long-term data security.

Key Takeaways

A natural evolution, not a cliff edge

The "quantum threat" narrative often swings between two extremes: imminent catastrophe or distant irrelevance. The reality occupies a more pragmatic middle ground. Quantum computers are highly specialized accelerators that exploit quantum physics to solve specific hard problems. They have the potential to crack modern encryption, but they will not replace classic servers overnight, nor will they instantly break every encryption protocol on the internet. What they will do is gradually shift the security landscape, much as previous cryptographic transitions have done over the past three decades.

In late 2024, the Global Risk Institute, a Toronto-based financial services think tank, surveyed 32 quantum computing experts on when a quantum computer could break a 2048-bit RSA key within 24 hours. An average of optimistic and pessimistic estimates from the experts gave it an even 50-50 probability of reaching this code-breaking milestone by 2040. This timeline, uncertain but measurable, creates space for deliberate planning rather than emergency reaction. The near-term focus should be on "harvest now, decrypt later" scenarios, where adversaries collect encrypted data today and then hold it for future decryption later when that capability becomes possible. This is particularly applicable for information requiring confidentiality beyond 10 years.

For most enterprises, this can be a manageable risk when addressed through methodical modernization.

Government signals as confidence builders

The U.S. government has issued new directives for National Security Systems (NSS), which would likely be first on the list for potential quantum attack. Beginning in January 2027, new NSS acquisitions must be capable of supporting Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requirements for PQC algorithms standardized by the National Institute of Standards and Technology (NIST) and selected by the National Security Agency, the U.S. intelligence agency responsible for signals intelligence and information assurance. Implementation for new systems (with certain exceptions) is then required by 2031, with 100% adoption targeted by 2035.

For commercial enterprises, these timelines are not mandates, but could be signposts. They indicate where vendors, standards bodies, and auditors are headed, providing a reference architecture for responsible stewardship. Organizations can borrow this discipline without necessarily copying the exact timelines, using government guidance to calibrate their own risk tolerance and investment cadence.

Intel's role: Infrastructure ready for the transition

Intel is at the heart of the AI revolution by delivering quantum-resistant capabilities across our product portfolio. This is not just aspirational roadmap language; it is starting to be shipping technology.

For instance, the Intel Xeon 6 Processor already incorporates quantum-safe memory encryption (AES-256) and microcode signing to protect processor integrity. Upcoming platforms will extend post-quantum algorithms to more firmware and software signing, device interconnects, attestations, and secure boot functions, aligning with the most stringent government and industry directives.

... continue reading