🌌 Quantum Cryptography Stack β€” Dari Klasik ke Post-Quantum sampai Quantum-Native

Cryptography 2026 berada di titik balik sejarah: komputer kuantum skala-tinggi ancam algoritma klasik (RSA, ECC), tapi satu-satunya jawaban belum tersedia. Vault punya catatan untuk kriptografi klasik, post-quantum, dan quantum-key-distribution β€” tapi tidak ada satu dokumen pun yang memetakan roadmap migrasi lengkap. Catatan ini memetakan 7 lapisan, dari math foundation sampai production deployment, dengan timeline spesifik dan decision tree: kapan migrasi, ke algoritma apa, dengan cara bagaimana.


Daftar Isi

  1. 1. Premise β€” Mengapa Sekarang?
  2. 2. Seven-Layer Cryptography Stack
  3. 3. Layer 0 β€” Mathematical Foundation
  4. 4. Layer 1 β€” Classical Cryptography (1990-2025)
  5. 5. Layer 2 β€” Transition Phase
  6. 6. Layer 3 β€” Post-Quantum Cryptography (PQC) Standardized
  7. 7. Layer 4 β€” Quantum Key Distribution (QKD)
  8. 8. Layer 5 β€” Quantum-Resilient TLS Migration
  9. 9. Layer 6 β€” Storage, Identity, and Long-Term Data
  10. 10. Timeline 1990-2035 β€” Migrasi
  11. 11. Decision Tree β€” Kapan Migrasi ke Apa
  12. 12. Cross-Reference ke Vault
  13. References

1. Premise β€” Mengapa Sekarang?

Tahun 2024-2026 adalah inflection point:

Driver 1: Harvest-Now-Decrypt-Later (HNDL) Attacks

  • Adversary menyimpan encrypted traffic sekarang
  • Decrypt nanti saat punya quantum computer
  • Target: anything dengan confidentiality >10-15 tahun (medical records, state secrets, IP)

Driver 2: NIST PQC Standards Published (2024)

  • August 2024: FIPS 203 (ML-KEM / Kyber), FIPS 204 (ML-DSA / Dilithium), FIPS 205 (SLH-DSA / SPHINCS+)
  • Migration has begun in earnest

Driver 3: Quantum Ambition 2030+

  • Google’s Willow (Dec 2024), IBM Quantum Heron (2024)
  • Logical qubit error rate down 10Γ— per year
  • Cryptographically-relevant quantum computer (CRQC): 2029-2035 most estimates

Driver 4: Long Tail of Compliance

  • Regulatory mandates for PQC migration underway
  • CNSA 2.0 (NSA, 2024 timeline)
  • EU PQCMigration roadmap (2025)

2. Seven-Layer Cryptography Stack

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Layer 6 β€” Storage, Identity, Long-Term Data             β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Layer 5 β€” Quantum-Resilient TLS / Network Protocols     β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Layer 4 β€” Quantum Key Distribution (QKD)                β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Layer 3 β€” Post-Quantum Cryptography (NIST PQC)        β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Layer 2 β€” Hybrid Crypto (Classical + PQC combined)    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Layer 1 β€” Classical Cryptography (RSA/ECC/AES/SHA)   β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Layer 0 β€” Mathematical Foundation                       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
        ↑   HIGHER = MORE FORWARD-LOOKING

3. Layer 0 β€” Mathematical Foundation

3.1 Dua Fondasi Matematis

FondasiAlgoritma yang Berdiri Di AtasnyaDipengaruhi Quantum
Integer FactorizationRSAβœ… Shor’s (1994)
Discrete LogarithmDiffie-Hellman, DSA, ECDSA, Ed25519βœ… Shor’s
Elliptic Curves (EC)ECDSA, Ed25519, X25519βœ… Shor’s
Symmetric cryptoAES, ChaCha20🟑 Grover’s (effective security halved)
Hash functionsSHA-256, SHA-3, BLAKE3🟑 Grover’s (quadratic speedup)
Lattice problemsKyber, Dilithium, NTRU❌ Unknown quantum exploit (yet)
Hash-based signaturesSPHINCS+, XMSS, LMS❌ Secure
Code-basedClassic McEliece❌ Secure (since 1978)
MultivariateRainbow (broken), MAYO🟑 Some risks
Isogeny (broken)SIKE (broken 2022)❌ Broken (non-quantum)

3.2 Shor’s vs Grover’s Algorithm

AlgorithmTargetQuantum SpeedupImpact
ShorInteger factorization, discrete logExponentialRSA/ECC broken (2048-bit in hours)
GroverBrute-force searchQuadraticAES-256 β†’ AES-128 effective strength

Implikasi:

  • Gunakan AES-256 (Grover’s resistance)
  • Ganti RSA/ECC dengan lattice/hash-based (Shor’s resistance)
  • Hash output harus 2Γ— lipat (SHA-256 β†’ SHA-512)

4. Layer 1 β€” Classical Cryptography (1990-2025)

4.1 Rekomendasi Saat Ini (Pre-PQC)

Use CaseAlgorithmKey Size
Symmetric encryptionAES-256-GCM256 bit
Symmetric backupChaCha20-Poly1305256 bit
HashingSHA-3-256, BLAKE3256+ bit
Key exchangeX25519256 bit
SigningEd25519256 bit (pub/priv)
Password hashingArgon2id64-128 MB memory
TLS 1.3All above via OpenSSL 3.x-

4.2 Status 2026

  • Masih aman untuk kebanyakan kasus (CRQC masih dalam horizon)
  • Tidak aman untuk long-term confidentiality (HNDL attack relevan)
  • Sudah deprecated di beberapa compliance (CNSA 2.0 NSA ban pure-RSA in NSS by 2033)

Koneksi ke Vault:


5. Layer 2 β€” Transition Phase: Hybrid Crypto (2024-2030)

5.1 Mengapa Hybrid First?

Migrasi langsung ke PQC memiliki risiko:

  1. Implementasi PQC baru β€” bugs di library
  2. Standard baru (NIST) masih terus direview
  3. Performance trade-offs besar (key size 10-100Γ— larger)
  4. Compatibility issue di protokol lama (TLS, JWT, X.509)

Solusi: hybrid β€” jalankan classical + PQC paralel. Hasil union β€” aman dari keduanya.

5.2 Pattern Hybrid Key Exchange

Traditional TLS:
  Client ← KeyShare (X25519) β†’  Server
  β†’ shared secret = ECDH(X25519)

Hybrid TLS (X25519+ML-KEM-768):
  Client ← KeyShare (X25519, ML-KEM-768) β†’  Server
  β†’ shared secret = KDF( ECDH(X25519) || ML-KEM_decaps(pk) )
  β†’ Aman dari quantum attack (PQC) + bug PQC (classical)

5.3 Hybrid Implementations (2026)

ImplementationAlgorithmsStatus
TLS 1.3 hybridX25519 + ML-KEM-768Chrome + Firefox support (2024)
OpenSSL 3.5+PQC providerReleased 2025
Cisco TLSX25519 + ML-KEM-768Production 2025
AWS KMSRSA + ML-KEMInternal pilot 2024
IBM HSMECC + ML-DSAHybrid 2025

5.4 Hybrid Trade-offs

ProCon
Aman dua arahBandwidth naik ~1-2 KB per handshake
Compliance-friendly (roll-forward)Latency naik 10-20% (ML-KEM dilithium lebih lambat)
Incremental rolloutLebih kompleks dari pure-PQC
Backward compatible (melalui TLS 1.3)2 algorithm agility perlu

5.5 Standar Hybrid

  • IETF draft-ietf-tls-hybrid-kem β€” RFC track
  • X25519+ML-KEM-768 β€” sudah di Chrome/Firefox
  • P384+ML-KEM-1024 β€” quantum-resistant hybrid
  • X25519+Kyber768 β€” serupa

6. Layer 3 β€” Post-Quantum Cryptography (PQC) Standardized

6.1 NIST PQC Standards (Final 2024)

StandardAlgoritmaUse CaseType
FIPS 203ML-KEM (Kyber768)Key EncapsulationLattice (Module-LWE)
FIPS 204ML-DSA (Dilithium3)Digital SignatureLattice (Module-LWE)
FIPS 205SLH-DSA (SPHINCS+)Signature (conservative)Hash-based

Also standardized/non-standardized:

AlgorithmTypeStatus
FN-DSA (Falcon)Lattice signatureNIST standards-track (final near)
Classic McElieceCode-basedAlternate (long keys, slow)
BIKECode-basedAlternate candidate
HQCCode-basedAlternate candidate
MAYOMultivariateUnder review

6.2 Performance Comparison (ML-KEM vs RSA/ECC)

AlgorithmPublic Key (B)Ciphertext/Sig (B)Sign/Enc TimeVerify/Dec Time
RSA-20482562561.5 ms0.03 ms
ECDSA P25664640.05 ms0.1 ms
Ed2551932640.05 ms0.1 ms
ML-KEM-768121610880.02 ms0.03 ms
ML-DSA-65195232930.5 ms0.2 ms
SLH-DSA-SHAKE-128s32785650 ms5 ms
Falcon-5128976140.4 ms0.1 ms

Key Insight: ML-KEM jauh lebih cepat dari RSA, tapi key size 10-100Γ— lebih besar. Trade-off bandwidth/signature inline.

6.3 Implementation Libraries (2026)

LibraryLanguagesAlgorithmsStatus
liboqsCAll NISTMainstream
Open Quantum Safe (liboqs)C, Python bindingsAllProduction
pqcrypto (Python)Python wrapping liboqsAllResearch
Bouncy Castle (Java)JavaML-KEM, ML-DSAProduction
openssl-pqc-provider (3.5+)CML-KEM, ML-DSAProduction
Go BoringSSL PQCGoX25519+ML-KEMProduction
AWS s2n PQCCML-KEM hybridAWS-internal

7. Layer 4 β€” Quantum Key Distribution (QKD)

7.1 Apa QKD Bukan?

QKD bukan post-quantum cryptography. QKD adalah metode berbeda:

  • Kirim key melalui quantum channel (photon polarization)
  • Secara fisik aman β€” eavesdropping terdeteksi melalui quantum mechanics
  • Membutuhkan hardware khusus β€” fiber optic, single-photon detector, satellite link
  • Distance-limited β€” ~100 km per hop di fiber, bisa ribuan km via satellite

7.2 Protokol QKD

ProtokolTahunMekanisme
BB841984Photon polarization (4 state)
E911991Entangled pairs
B9219922-state
BBM921992Ekstensi E91
MDI-QKD2012Measurement-device-independent
TF-QKD2019Twin-field, longer distance

7.3 QKD Networks (2026)

NetworkLokasiStatus
Tokyo QKD NetworkJepangProduction (10+ banks)
Beijing-ShanghaiCina2000 km backbone
EU Quantum InternetEropaIn development
Madrid Quantum NetworkSpanyolTestbed
UK Quantum NetworkUKTestbed
Korea KQNetKoreaProduction
Singapore-SingtelSingapuraTestbed
DARPA QKD TrialsUS2024-2026
Micius SatelliteCinaGlobal QKD via satellite

7.4 QKD vs PQC trade-offs

AspekPQCQKD
HardwarePure softwarePhoton source/detector
DistanceUnlimited~100 km fiber, sat unlimited
Speed100K+ ops/s~10-100 Kbps
DeploymentTLS upgrade highwayNew infrastructure
Cost$0 (algoritma)$$ - $$$$
MaturityNIST standards doneLimited deployments

Hybrid PQC+QKD β€” best of both. QKD untuk high-confidentiality session, PQC for general.


8. Layer 5 β€” Quantum-Resilient TLS Migration

8.1 Status TLS 2026

  • TLS 1.3 default everywhere
  • Hybrid key exchange (X25519+ML-KEM-768) implemented in:
    • Chrome 131+ (Sept 2024)
    • Firefox 132+ (Oct 2024)
    • OpenSSL 3.5+
    • AWS CloudFront
    • Cloudflare

8.2 Quantum-Resilient TLS Stack

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Application (HTTPS, gRPC, etc)                       β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ TLS 1.3 (RFC 8446) + Hybrid KX extensions           β”‚
β”‚   β”œβ”€ KeyShare: { x25519: pub1, ml_kem768: pub2 }    β”‚
β”‚   β”œβ”€ KDF: ECDH(X25519) || ML-KEM_decaps(...)        β”‚
β”‚   └─ Result: shared secret 32-byte                  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Transport (TCP / QUIC)                                β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

8.3 Migration Checklist (Production)

[ ] Update OpenSSL/BoringSSL ke 3.5+ / 2024 edition
[ ] Hybrid keyshare configured in TLS group selection
[ ] Cert verification accepts both classical & hybrid chain
[ ] Test performance with slower x25519+ml-kem768
[ ] EDR/XDR updated to detect anomaly PQC usage
[ ] Monitoring β€” alert on TLS failures (hybrid tidak bisa fallback)
[ ] Roll-out phase: 1% β†’ 10% β†’ 50% β†’ 100%
[ ] Documented rollback ke X25519-only

8.4 Browser Support TLS PQC

BrowserPQC Hybrid SupportDate
Chrome 124+X25519Kyb768 (legacy group)2024
Chrome 131+X25519+ML-KEM-7682024-09
Firefox 124+X25519Kyb7682024
Firefox 132+X25519+ML-KEM-7682024-10
SafariRFP / in progress2025-2026
EdgeInherits Chrome2024+

9. Layer 6 β€” Storage, Identity, and Long-Term Data

9.1 HNDL: Harvest-Now-Decrypt-Later

Data dengan confidentiality >10-15 tahun perlu quantum-resistant protection SEKARANG:

Data CategoryConfidentiality PeriodMigrasi Harus Mulai
Geopolitical secrets50+ years2024
Medical genetic dataLifetime2024
Industrial R&D10-25 years2025
Financial transaction7-10+ years (regs)2026
Government comms20+ years2024

9.2 Storage Cryptography

KomponenPre-PQCPQC Hybrid
Disk encryption (LUKS)AES-256-XTSAES-256-XTS unchanged (Grover-resistant)
S3 SSE-KMSAES-256AES-256 β€” secure storage tetap aman
BackupAES-256 + RSA wrapping keyWrapping key β†’ ML-KEM
PGP / GPGRSA-4096ML-KEM-768 + (RSA optional)
JWT (RS256)RS256ML-DSA-65
X.509 certRSA/ECDSAML-DSA or hybrid

9.3 Identity & PKI Migration

ComponentMigration
Root CATetap RSA/ECC (signs infrequently, long lifetime) β€” wrap dengan ML-DSA sebagai β€œshield”
Issuing CADual-signed: classical + ML-DSA
End-entity certIssued dengan ML-DSA
CMP/ESTAdd PQC algorithm negotiation
CRL/OCSPSigned dengan classical or ML-DSA
SCEP/CMSAdd PQC support

9.4 Code Signing & Software Supply Chain

ToolPre-PQCPQC
Sigstore (cosign)ECDSAML-DSA-65
Sigstore FulcioECDSAML-DSA-65
SLSA provenanceECDSAML-DSA-65
TUF (The Update Framework)RSA/ECDSAML-DSA-65
Microsoft AuthenticodeRSA-2048ML-DSA-65 (research 2024)
Notary v2ECDSAML-DSA-65

Koneksi ke Vault:


10. Timeline 1990-2035 β€” Migrasi

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Era          β”‚ Major Milestone                                    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ 1990-2000    β”‚ RSA/ECC symmetric dominance                       β”‚
β”‚ 2000-2014    β”‚ TLS 1.0/1.2, ECDSA emerges                       β”‚
β”‚ 2014-2016    β”‚ SHA-1 broken, SHA-256 default                     β”‚
β”‚ 2016-2022    β”‚ Shor awareness, NIST PQC competition launch      β”‚
β”‚ 2022         β”‚ SIKE broken (quantum hype peak)                   β”‚
β”‚ Jul 2022     β”‚ NIST selects 4 PQC algorithms (Kyber, Dilithium, β”‚
β”‚              β”‚ Falcon, SPHINCS+)                                  β”‚
β”‚ Aug 2024     β”‚ FIPS 203/204/205 published (ML-KEM, ML-DSA, SLH-DSA)β”‚
β”‚ Sep-Oct 2024 β”‚ Chrome/Firefox ship X25519+ML-KEM-768 hybrid     β”‚
β”‚ 2025         β”‚ OpenSSL 3.5+ PQC provider mainstream              β”‚
β”‚ 2026         β”‚ Production hybrid everywhere                     β”‚
β”‚ 2027-2029    β”‚ State actors begin PQC-only for high security    β”‚
β”‚ 2030-2032    β”‚ NSA's CNSA 2.0 mandates pure PQC for NSS         β”‚
β”‚ 2030+        β”‚ CRQC (cryptographically relevant quantum) emergence β”‚
β”‚ 2033         β”‚ NIST classical-only ban di NSS complete          β”‚
β”‚ 2035         β”‚ QKD networks production-ready (limited use)      β”‚
β”‚ 2040s        β”‚ Pure PQC + QKD mostly standard                    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

10.1 Rekomendasi Migrasi Berdasarkan Level Confidentiality

Confidentiality horizonPure PQC mulai produksiHybrid production
<5 years20302026
5-10 years20282025
10-15 years20262024
15-30 years20252024
30+ years20242024

11. Decision Tree β€” Kapan Migrasi ke Apa

                START
                  β”‚
          Confidentiality >15 years? (HNDL relevan)
                /       \
             Yes         No
              β”‚           β”‚
        Long-term       Short-term
              β”‚          ("secure-classical OK for now")
              β”‚              β”‚
    Pure PQC, today      Hybrid tahun ini
    (X25519+ML-KEM)      (X25519+ML-KEM+ML-DSA)
              β”‚              β”‚
       ● Disk encryption unchanged
       ● KMS wrapping key β†’ ML-KEM
       ● Cert β†’ ML-DSA (signed)
       ● Backup β†’ wrap key ML-KEM
              β”‚
        QKD feasible infra?
              / \
           Yes   No
            β”‚     β”‚
     Use QKD for    Pure-PQC
     backbone       suffit

12. Cross-Reference ke Vault


References

  1. NIST. β€œFIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM).” (2024).
  2. NIST. β€œFIPS 204: Module-Lattice-Based Digital Signature (ML-DSA).” (2024).
  3. NIST. β€œFIPS 205: Stateless Hash-Based Digital Signature (SLH-DSA).” (2024).
  4. Shor. β€œPolynomial-Time Algorithms for Prime Factorization.” FOCS 1994.
  5. Grover. β€œA Fast Quantum Mechanical Algorithm for Database Search.” STOC 1996.
  6. NIST. β€œPost-Quantum Cryptography.” https://csrc.nist.gov/projects/post-quantum-cryptography
  7. CNSS. β€œCNSA 2.0: Quantum-Resistant Cryptography.” (2022-2024).
  8. ETSI. β€œQuantum Key Distribution (QKD); Use Cases.” (2024).
  9. IETF. β€œdraft-ietf-tls-hybrid-kem.” (2024).
  10. Cloudflare. β€œPost-Quantum TLS Performance.” (2024).
  11. Google. β€œPost-Quantum in Chrome.” (2024).
  12. AWS. β€œHybrid Post-Quantum TLS in CloudFront.” (2024).
  13. CISA. β€œQuantum-Readiness Migration to PQC.” (2024).
  14. NSA. β€œQuantum Computing and Post-Quantum Cryptography FAQ.” (2024).
  15. Open Quantum Safe Project. β€œliboqs documentation.” https://openquantumsafe.org/