Qernelzoo
Quantum-resistant cryptography accelerator
How do you change every lock on the internet before someone can pick them?
Most of the Encryption where anyone can lock a message with a public key but only the holder of the matching private key can unlock it. that guards the internet rests on one of three maths problems: factoring big integers, the discrete logarithm, and its elliptic-curve cousin. RSA is safe only because factoring large numbers is out of reach, and no ordinary computer is known to factor integers in polynomial time.
A quantum algorithm that factors integers and solves discrete logarithms fast enough to break today's public-key systems. changes that. On a quantum computer it factors in polynomial time, and it could break RSA and both flavours of Diffie–Hellman key exchange. The catch, for now, is size. Beating a classical machine may take millions of The basic units of a quantum computer, which unlike ordinary bits can hold a mix of 0 and 1., because quantum error correction eats so many of them.
So cryptographers built new locks. NIST has finalised standards designed to withstand a quantum attacker: ML-KEM, formerly Kyber, for setting up encryption keys, and ML-DSA, formerly Dilithium, for digital signatures. Both are Built on geometric grids of points in many dimensions, where finding the shortest step between points is believed to be very hard.. Their security leans on the shortest vector problem, which is thought to be hard to solve efficiently even with a quantum computer.
Further reading Post-quantum cryptography (Wikipedia)Shor's algorithm (Wikipedia)NIST Releases First 3 Finalized Post-Quantum Encryption Standards (NIST)Lattice-based cryptography (Wikipedia)
- i.
Steal now, read later
Nobody needs a quantum computer today to plan for one. "Harvest now, decrypt later" means copying encrypted traffic you can't read yet and storing it until decryption catches up. Plenty of data recorded now will still be sensitive for decades, so the clock on a migration starts well before the machine exists.
- ii.
Heavier keys
The new locks are bulkier. Many post-quantum algorithms need larger keys than the ones they replace. At its middle security level, an ML-KEM public key is 1,184 bytes and a The scrambled output of encryption, which is what actually travels over the wire. 1,088. In one chat-encryption test, swapping the elliptic-curve exchange for ML-KEM made it about 2.3 times slower and added roughly 70 times more data overhead. Most of that runtime goes on internal hashing, which is the kind of work that benefits from hardware acceleration.
- iii.
Crypto hides everywhere
Cryptography sits in TLS connections, SSH keys, code signing, certificate authorities, and the firmware of hardware security modules and IoT devices. When every product picks its own scheme in code, each swap turns into a hunt across the network. The standards body's own advice is to start now, because full integration will take time. It has happened before: DES, 512-bit RSA and RC4 were all once considered secure.
Further reading Harvest now, decrypt later (Wikipedia)Post-quantum cryptography (Wikipedia)Kyber (Wikipedia)Quill: Crypto-agile security against quantum attacks (Qernel Technologies)NIST Releases First 3 Finalized Post-Quantum Encryption Standards (NIST)Cryptographic agility (Wikipedia)
Qernelzoo works on efficient cryptography, with an eye on the day fault-tolerant quantum computers arrive. Its first product, Quill, is about the unglamorous middle of the problem: finding the old locks, working out which to change first, and making sure the next change is cheaper than this one.
Further reading Qernel (Qernel Technologies)Quill: Crypto-agile security against quantum attacks (Qernel Technologies)
- Step 1: Find every lock
Quill scans code and networks, writes a cryptographic bill of materials, or CBOM, and turns each finding into a prioritised path to post-quantum. It can also grade a domain from the outside, reading the TLS key exchange, certificate chains and signature algorithms it already publishes.
- Step 2: One place to change
The bigger idea is Designing systems so their cryptographic algorithms can be swapped without rebuilding everything around them.: being able to swap cryptographic algorithms with ease and at least partly automatically. Instead of every service picking its own scheme in code, call sites resolve their keys from one policy, so the migration after this one is a single edit.
Further reading Quill: Crypto-agile security against quantum attacks (Qernel Technologies)Cryptographic agility (Wikipedia)
When will a quantum computer big enough actually show up?
Nobody knows. Lab demonstrations of Shor's algorithm have only factored small numbers, and one team's machine managed 15 and 21 but not 35. Even so, some experts predict a code-breaking device within a decade.
How much should we trust the new maths?
Lattice schemes like NTRU have been studied for many years without a feasible attack. Another widely noticed post-quantum scheme, SIDH/SIKE, was spectacularly broken, though that attack only works on its own family. That's why some deployments use Running a new post-quantum scheme alongside a proven classical one, so data stays safe if either holds., pairing each new post-quantum scheme with a more proven classical one.
Further reading Shor's algorithm (Wikipedia)Post-quantum cryptography (Wikipedia)NIST Releases First 3 Finalized Post-Quantum Encryption Standards (NIST)
Qernelzoo is a seed-stage cybersecurity company developing quantum-resistant cryptography acceleration software.
- public-key cryptography
- Encryption where anyone can lock a message with a public key but only the holder of the matching private key can unlock it.
- Shor's algorithm
- A quantum algorithm that factors integers and solves discrete logarithms fast enough to break today's public-key systems.
- qubits
- The basic units of a quantum computer, which unlike ordinary bits can hold a mix of 0 and 1.
- lattice-based
- Built on geometric grids of points in many dimensions, where finding the shortest step between points is believed to be very hard.
- ciphertext
- The scrambled output of encryption, which is what actually travels over the wire.
- crypto-agility
- Designing systems so their cryptographic algorithms can be swapped without rebuilding everything around them.
- hybrid encryption
- Running a new post-quantum scheme alongside a proven classical one, so data stays safe if either holds.
- 1Shor's algorithm · Wikipedia
- 2NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST
- 3Post-quantum cryptography · Wikipedia
- 4Kyber · Wikipedia
- 5Lattice-based cryptography · Wikipedia
- 6Harvest now, decrypt later · Wikipedia
- 7Cryptographic agility · Wikipedia
- 8Quill: Crypto-agile security against quantum attacks · Qernel Technologies
- 9Qernel · Qernel Technologies