Google Online Security Blog
Follow
Post-Quantum Cryptography: Standards and Progress
NIST has released three finalized standards for post-quantum cryptography (PQC), safeguarding internet information from potential quantum computer threats. PQC algorithms can be implemented on current computers, addressing risks such as data stored for later decryption and compromised hardware products. Organizations should prepare for PQC migrations by implementing crypto agility best practices, including cryptographic inventory, key rotation, abstraction layers, and end-to-end testing. Google has been actively testing and using PQC, contributing to standards development and providing PQC algorithms in its open-source library, Tink. Google has enabled PQC for internal communications and will continue to update its services, including Android, Chrome, and Cloud, with PQC advancements. By adopting these standards and best practices, organizations can ensure the confidentiality and security of their data in the face of future quantum computing advancements.