/ THE IDEA
Some public-key locks rely on one-way calculations. RSA multiplies two secret prime numbers—whole numbers divisible only by 1 and themselves—and publishes the product. A sufficiently capable quantum computer running Shor’s algorithm could reverse that particular step far more efficiently. Post-quantum standards replace it with different mathematical problems for which no efficient ordinary or quantum attack is currently known.
THE FORMAL IDEA
lattice-style toy: b = (a × s + e) mod q
| s = secret number; a and b = numbers an attacker may see | | e = a small random error that makes each public clue slightly imperfect | | mod q means the arithmetic wraps around after q, like a clock |
|
RUN THE TINY EXAMPLE
Hide one secret behind noisy clues
Choose q = 17 and secret s = 3 a = 2, error e = +1 → public b = (2 × 3 + 1) mod 17 = 7 Change a to 5 and e to −1 → public b = (5 × 3 − 1) mod 17 = 14 An attacker sees many slightly inconsistent clues and must recover s
|
With only seventeen possible secrets, this toy is easy. NIST's ML-KEM standard hides many secret values behind large collections of wrapped, noisy equations; at its chosen sizes, the best known ordinary and quantum attacks require impractical work. Real encryption adds more steps; this toy isolates the hard problem.
/ SO WHAT?
This is why an apparently premature standards change is rational. Large systems take years to inventory, upgrade, test and retire. Long-lived data makes the risk clock start before the hardware clock.
ONE CAVEAT |
| Post-quantum cryptography is ordinary software using new mathematics; it is not the same as quantum communication, and no one knows when a computer capable of breaking today’s public-key systems will exist. |
KEEP THIS
If a secret must outlive its current encryption, protect it for the future now.
|
NEXT: Why NASA’s next telescope sees more sky
|