- In everyday life
- The day someone shows up with a master key that opens the padlock model the whole city uses.
- What it means here
- The day the first quantum computer able to break today's cryptography switches on. Nobody knows the date: there are estimates from different sources, and they move.
- Where it appears
- HubThe deadline
formerly: CRQC · cryptographically relevant quantum computer
- In everyday life
- Not a faster computer for everything; a very specific tool, like a master key that opens only one kind of lock.
- What it means here
- The CRQC: a quantum computer large and stable enough to run Shor's algorithm against public-key locks. It does not exist yet; estimates of when it will are the heart of this section.
- Where it appears
- The deadlineThe quantum stack
formerly: PQC · post-quantum cryptography
- In everyday life
- Swapping the door padlock for a model the new master key can't open, before that key reaches town.
- What it means here
- New algorithms that run on today's ordinary computers but rest on mathematical problems even a quantum computer can't solve quickly. NIST standardized the first ones in August 2024.
- Where it appears
- HubThe inventoryEncrypted telemetry
formerly: RSA · ECDH · ECDSA · secp256k1 · public-key cryptography
- In everyday life
- The padlock with two keys: one anyone can have to lock it, another, only yours, to open it.
- What it means here
- The public-key cryptography that protects almost everything: RSA and ECDH to agree on a conversation's password (the HTTPS padlock), ECDSA to sign (prove who sent it), secp256k1 for Bitcoin and Ethereum wallets. These are exactly the ones a quantum computer breaks.
- Where it appears
- The deadlineThe inventoryDevice identity
formerly: symmetric cryptography · AES-256 · SHA-256
- In everyday life
- The safe whose combination both people already know: there is no public part to attack.
- What it means here
- AES-256 encrypts the content; SHA-256 takes the fingerprint. The best known quantum attack on them (Grover) only halves their strength: AES-256 keeps the equivalent of 128 bits, which is enough. This is not where you need to migrate.
- Where it appears
- HubEncrypted telemetry
formerly: Shor's algorithm
- In everyday life
- A method that, with the right tool, works out the opening key just by looking at the padlock.
- What it means here
- The 1994 recipe that, on a large quantum computer, finds the private key from the public key in RSA and elliptic curves. It already exists on paper; the machine is what is missing.
- Where it appears
- The quantum stackThe deadline
formerly: Grover's algorithm
- In everyday life
- Hunting for one key in a ring of a thousand by trying each, but with a trick that cuts the tries to the square root.
- What it means here
- The quantum attack on the shared-secret lock. A real shortcut, but modest: doubling the key size undoes the gain. That is why AES-256 stays safe.
- Where it appears
- The quantum stack
formerly: harvest now, decrypt later · HNDL
- In everyday life
- Photocopying sealed letters you can't read today and keeping them in a drawer until someone figures out how to open the seal.
- What it means here
- Whoever records traffic encrypted with public-key locks today can read it on Q-Day. So the deadline that matters is not Q-Day: it is Q-Day minus the time your data must stay secret.
- Where it appears
- HubThe deadlineDevice identity
formerly: ML-KEM · FIPS 203 · Kyber
- In everyday life
- The new way for two people to agree on a password in public without an eavesdropper deducing it, even with the quantum master key.
- What it means here
- The NIST-standardized replacement (FIPS 203) for ECDH when agreeing on a conversation's password. It migrates first, because it is what protects against "store now, open later".
- Where it appears
- Encrypted telemetryThe quantum stackBACEN before 2028
formerly: ML-DSA · FIPS 204 · Dilithium · SLH-DSA · FIPS 205
- In everyday life
- A notarized signature, in a style the forger holding the new master key can't imitate.
- What it means here
- The NIST-standardized replacements for ECDSA and RSA when signing: ML-DSA (FIPS 204) for everyday use and SLH-DSA (FIPS 205) as the more conservative alternative. Signatures get bigger, which weighs on certificates and small channels.
- Where it appears
- Device identityEncrypted telemetry
formerly: lattice · Module-LWE
- In everyday life
- Finding the nearest point on a grid with millions of dimensions, deliberately jumbled with a little noise.
- What it means here
- Most new locks (ML-KEM, ML-DSA) rest on this kind of problem, which nobody knows how to solve fast, not even with a quantum computer. Every so often a claimed break appears; the 2024 one fell apart in about eight days. That is why this section insists on swapping the lock without swapping the door.
- Where it appears
- The quantum stackThe FHE frontier
formerly: hybrid TLS · X25519+ML-KEM
- In everyday life
- Putting the old padlock and the new one on the door at the same time: the thief has to open both.
- What it means here
- Agreeing on the conversation's password with today's lock and the new one together. If the new one has an unknown flaw, the old one holds; if the quantum computer arrives, the new one holds. It is how major browsers and servers are already migrating.
- Where it appears
- Encrypted telemetryThe deadline
formerly: PKI · X.509 certificate · CA
- In everyday life
- The registry office that issues each server's and device's ID card, and whoever checks that ID at the door.
- What it means here
- The set of authorities, certificates and checks that proves who each end of a connection is. It is the layer furthest behind in the migration: key exchange is moving, identity barely.
- Where it appears
- Device identityBACEN before 2028
formerly: RoT · root of trust · HSM · TPM
- In everyday life
- The safe soldered onto the board that keeps the key and only uses it inside, never handing it out.
- What it means here
- A piece of hardware that stores the device's key and performs the signing math without exposing it. In fleets that stay 15 to 20 years in the field, it has to be born ready for the new locks.
- Where it appears
- Device identity
- In everyday life
- A door built to take another padlock model without being ripped out of its frame.
- What it means here
- Systems designed to change algorithm through configuration, not rewrites. It matters twice: to migrate now and to migrate again if a new lock falls.
- Where it appears
- The inventoryDevice identity
formerly: cryptographic inventory · CBOM
- In everyday life
- Before changing a company's padlocks, walking the building and noting where each padlock is, what model and who holds the key.
- What it means here
- The survey of where cryptography is, of what kind and with what expiry: in code, dependencies, certificates and devices. It is the first step of any migration, and the one most often skipped.
- Where it appears
- The inventoryThe assessment
formerly: AEAD · GCM tag · AES-256-GCM
- In everyday life
- The envelope seal that, once broken, reveals someone opened it on the way.
- What it means here
- Encrypting and sealing at once: AES-256-GCM locks the content and attaches a 16-byte seal that exposes any tampering. In heavily compressed telemetry, that seal can weigh more than the data itself.
- Where it appears
- Encrypted telemetry
formerly: physical qubit · logical qubit · error correction
- In everyday life
- A choir of a thousand off-key voices singing together to sound like one voice in tune.
- What it means here
- Physical qubits make many errors; grouping many of them with error correction yields a reliable "logical qubit". Q-Day estimates depend on how many logical qubits a break needs and on keeping the machine running non-stop for hours or days.
- Where it appears
- The deadlineThe quantum stack
formerly: FHE · homomorphic encryption · fully homomorphic encryption
- In everyday life
- Sending a locked safe to the accountant, who does the sum inside through gloved holes, never seeing what is being added.
- What it means here
- A family of techniques that computes on data that stays encrypted the whole time; only the key holder reads the result. It also rests on lattices. It works today for shallow batch computations; long computations are still expensive.
- Where it appears
- 20 applicationsFHE maturityThe FHE frontierInteractive tutorial
formerly: bootstrapping · bootstrap (FHE)
- In everyday life
- Every sum done in the dark leaves a little dust; after a few, you must stop and sweep before continuing.
- What it means here
- In FHE, each multiplication piles noise onto the encrypted data. The clean-up clears that noise without opening the data, and it is the expensive part: on our bench, with real 128-bit parameters, 1 min 18 s per operation and 10.26 GB of keys.
- Where it appears
- The FHE frontierFHE maturity
No term with that word. Try the technical name (e.g. "Dilithium").
← Post-quantum · stickybit.com.br