Post-Quantum Security – PQC

Embracing post-quantum cryptography for a quantum-proof security.

What is post-quantum cryptography (PQC)?

The next game-changer for cybersecurity

Post-quantum cryptography (PQC) consists in all cryptographic methods that withstand a quantum computer.

Nearby on the computing horizon quantum computers will be capable of factorizing large prime number products and solving the discrete logarithm problem.

As cryptography relies on algorithms, quantum will disrupt key encryption and cybersecurity as we currently know it.

PQC Explorer

PQC Explorer enables interactive exploration of Post-Quantum Cryptography (PQC) algorithms through two modules:

  • PKI Dashboard for generating and managing certificates
  • CMS Dashboard for encryption and digital signing
Test our new PQC Explorer tool (opens in a new tab)

Risks quantum poses to your security

What if everything you thought was secure was not anymore?

By disrupting cryptography, quantum computers jeopardizes the security of all assets and activities as we currently do them. All data protection, email exchange, payment, communication and much more are secured with algorithms — and these will soon be broken by quantum computing.

Migrating to PQC is not an option, rather a vital requirement to maintain your business continuity and security.

Exposure to "Harvest now, decrypt later" attacks

Exposure to "Harvest now, decrypt later" attacks

Unfriendly governments already start to harvest your data now, hoping that in the massive amount of data they capture at least one is critical and/or sensitive to your business and provides a competitive advantage.

2037: the security apocalypse?

2037: the security apocalypse?

Quantum computers are expected to reach maturity by 2037. By then they will be able to break all KEM currently in use (e.g. RSA, TLS, SSL...) meaning that no payment or data exchange, or else, will be secure anymore.

Now is your chance: get Quantum-proof before Quantum hits

Now is your chance: get Quantum-proof before Quantum hits

According to the CSA, a medium-size business asset's migration to PQC would need an inreducible 3-years time. Before that you must have already run your cryptographic inventory and risk assessment to prioritize assets to be migrated first and fast.

PQC migration: you have no choice but to climb that mountain

A triptyc of challenges

Even though successfully migrating to PQC will not be a sinecure, organizations who may rest on their laurels, considering there is way enough time to migrate, greatly risk facing the security apocalypse induced by Quantum.

The clock is ticking, don't miss the boat

The clock is ticking, don't miss the boat

Worry now AND act now! As you must first and foremost run an exhaustive cryptography inventory (architecture, assets and keys) and perform a risk assessment to prioritize the assets to migrate to PQC, you will reach the irreducible 3-years migration timeline before you even realize.

Gigantic transformation

Gigantic transformation

It is not just about switching cryptography algorithms, rather mainly about identifying which KEM you used, for what assets, and why. In parallel prioritization of assets to be migrating relies on whether their data shelf time overlapps the quantum-computing maturity time horizon.

Skills gap

Skills gap

While the cybersecurity industry is already short of 3.4 million people, the cryptography skills gap is abyssal. Successfully migrating to PQC will require you to get support from the rare cryptographs worldwide. Furthermore to get your Board's investment approval, raising awareness on PQC is essential.

Embark on the PQC migration journey

PQC is to cybersecurity what the advent of the Internet was to IT

On your marks, set, go for the marathon to quantum-proof security! Remember those who thought "there's time before it hits us" while the Internet bubble was growing? Make sure not to miss the boat.

Awareness and education

Awareness and education

Protecting yourself from quantum computers is a real challenge, and one that requires some serious math skills. Therefore stakeholders must understand the basics of PQC to ensure a successful migration.

Cryptography inventory

Cryptography inventory

Exhaustively identify all the Key Encryption Methods (KEM) used for each of your assets (application, file, network…), their data shelf time and sensitivity level.

Risk assessment

Risk assessment

Assess the level of risk and exposure of leaving an asset with non-PQC KEM, hence exposing it to quantum brute-force attack and decryption.

Implementation

Implementation

Start migrating the prioritized assets to PQC algorithms, and permanently deleting all the former instance.

Quantum-ready cybersecurity products

Manage your data protection and your trusted digital identities

Data Encryption

Data Encryption

Protect and encrypt your most sensitive data, at rest and in motion. For cloud, virtual and on-premises infrastructures, and any level of encryption.

Digital Identity

Digital Identity

Eviden Digital ID accompanies customers in the PQC transition. Our product portfolio is evolving to support PQC at every step of the value chain. Discover our end-to-end approach from generation to usage of digital identities.

Identity & Access Managemen

Identity & Access Managemen

Only give the right people access to the right information at the right time. See who has access, why they have it and how they use it.

How can Eviden support you?

Speak with an expert

Our experts are here to discuss your challenges and design solutions tailored to your organization’s specific needs.