A bank moves money over the internet using a handshake that takes a few milliseconds. A diplomat sends a cable to a capital using a key exchange that takes even less. The handshake and the key exchange are protected by mathematics that has held since the 1970s. Specifically, they rely on the hardness of factoring large integers and on the discrete logarithm problem on elliptic curves. A classical computer needs longer than the age of the universe to break either, so the encryption is treated as practically unbreakable.
A sufficiently large quantum computer breaks both in hours. The algorithm that does it, published by Peter Shor in 1994, is one of the few cases in computer science where a quantum machine offers an exponential speed-up over classical methods. The quantum computer that can run Shor’s algorithm at the necessary scale does not yet exist. Most estimates suggest it is at least a decade away, possibly longer. But the data being encrypted with classical algorithms today, including bank records, medical records, government communications, and military traffic, will still be sensitive when that machine arrives. An adversary that records ciphertext today and decrypts it later still wins.
Post-quantum cryptography, or PQC, is the response to this threat. It is the design of new public-key algorithms that run on ordinary computers but are believed to resist attack by quantum computers. The first set of these algorithms became official US standards in August 2024. India, through C-DOT and the National Quantum Mission, has begun a parallel migration. For UPSC, the topic sits at the intersection of cyber security, critical and emerging technology, and the policy choice between mathematics and physics in protecting national information.
What PQC Is and What It Is Not

Post-quantum cryptography is a family of mathematical algorithms that run on classical computers, the same hardware that everybody already uses, but are designed so that no known quantum algorithm can solve them efficiently. The hard problems used by PQC algorithms include lattice problems, code-based problems, hash-based signatures, and isogeny problems on elliptic curves. None of these is broken by Shor’s algorithm.
PQC is therefore an upgrade of the existing public-key infrastructure. A bank that runs RSA today can run Kyber tomorrow. The change happens in the software libraries that perform key exchange and signature, not in the hardware. This makes PQC the only practical approach to defending the bulk of the world’s encrypted traffic against the eventual arrival of a quantum computer.
PQC is often confused with quantum cryptography. The two are different categories. Quantum cryptography, of which the leading example is quantum key distribution or QKD, uses the physical properties of photons to detect any eavesdropper on a communications channel. It needs dedicated hardware, fibre or free-space optical links, and is fundamentally limited by distance. PQC uses no quantum hardware. The two are complementary, not substitutes. India’s strategy combines QKD for high-security strategic links and PQC for mass civilian use.
Why Today’s Encryption Is Vulnerable
The two pillars of today’s public-key cryptography are RSA and elliptic curve cryptography. RSA, named after its inventors Ron Rivest, Adi Shamir, and Leonard Adleman, relies on the hardness of factoring the product of two large prime numbers. To break RSA at the standard 2048-bit key length on a classical computer, the best known algorithm requires more operations than the number of atoms in the observable universe. So the algorithm is safe in practice.
Elliptic curve cryptography, used in protocols such as ECDSA for digital signatures and ECDH for key exchange, relies on the hardness of the discrete logarithm problem on an elliptic curve. The key sizes are smaller than RSA, but the security argument is similar. No classical algorithm in polynomial time exists to compute discrete logarithms on a properly chosen curve.
Shor’s algorithm changes this. It runs on a quantum computer and computes both factoring and discrete logarithms in polynomial time. A sufficiently large quantum computer would therefore break RSA and ECC simultaneously. The size of the quantum computer required is significant. Recent estimates put it in the range of several million physical qubits, or several thousand logical qubits after error correction. No such machine currently exists. The largest publicly disclosed quantum processors in 2026 have a few thousand physical qubits, of which only a small number are logically usable.
Symmetric encryption, such as AES, is more robust. Grover’s algorithm, the other major quantum algorithm relevant to cryptography, offers a quadratic speed-up rather than exponential. The practical effect is that AES-128 becomes equivalent to 64-bit security against a quantum attacker, which is too weak. The recommended response is simply to use AES-256, which retains 128-bit equivalent security. Symmetric primitives need adjustment, not replacement.
The NIST PQC Process
The US National Institute of Standards and Technology launched the PQC standardisation process in 2016. The goal was to identify and standardise public-key algorithms that resist quantum attack and that are practical to deploy in the protocols and devices that already exist. The process invited submissions from cryptographers around the world. Sixty-nine first-round submissions were narrowed to twenty-six in the second round in 2019, to seven finalists and eight alternates in 2020, and to four selected algorithms in 2022.
In August 2024, NIST published the first three finalised standards. FIPS 203 is Module-Lattice-Based Key Encapsulation Mechanism, also known as ML-KEM, derived from the Kyber submission. It is the standard for general-purpose key exchange. FIPS 204 is Module-Lattice-Based Digital Signature Algorithm, or ML-DSA, derived from the Dilithium submission. It is the standard for general-purpose digital signatures. FIPS 205 is Stateless Hash-Based Digital Signature Algorithm, or SLH-DSA, derived from the SPHINCS+ submission. It is a hash-based signature for use cases that need diversity from the lattice family.
A fourth standard, derived from the Falcon submission and also based on lattices, is in the process of being finalised. It is intended for applications where signature size is critical, such as constrained devices.
NIST has also begun a fourth round of evaluation focused on alternate key encapsulation mechanisms, including code-based options like Classic McEliece, BIKE, and HQC, in case a future cryptanalytic breakthrough weakens the lattice family.
How a Lattice-Based Algorithm Actually Works
The intuition behind lattice cryptography is geometric. A lattice is an infinite grid of points in a high-dimensional space, generated by adding integer multiples of a small set of basis vectors. The shortest vector problem and the closest vector problem on such a lattice are believed to be hard for both classical and quantum computers when the dimension is high.
Module-LWE, the specific problem underlying Kyber and Dilithium, asks an attacker to recover a secret vector given a sample of vectors that are close to the lattice spanned by a public matrix, plus some small random noise. Without the secret, the noise is indistinguishable from the unknown lattice contribution. With the secret, decryption recovers the message because the noise is small enough to be cleaned up.
The advantage of lattice cryptography over older proposals is that the operations are very fast, the keys are reasonably small, and the security argument has held up under twenty years of academic attack. The disadvantage is that lattice keys are still larger than RSA keys at equivalent security, which means more bandwidth in TLS handshakes and larger certificates, although the difference is small enough to be acceptable.
PQC vs QKD

The clearest distinction in the policy literature is between PQC and quantum key distribution. QKD uses the physics of single-photon transmission to create a shared key between two parties such that any eavesdropping disturbs the photons in a detectable way. The protocol most often cited is BB84, proposed by Charles Bennett and Gilles Brassard in 1984.
QKD is unconditionally secure in an information-theoretic sense, but only if the underlying hardware is correct. It needs dedicated optical fibre or a free-space link, it is range-limited because photons are absorbed over distance, and it is currently expensive. In India, ISRO and DRDO have demonstrated free-space QKD between ground stations, and C-DOT has commercially deployed QKD over fibre between Delhi and Hyderabad. The use case is high-security government and defence links where dedicated infrastructure is justified.
PQC is mathematically secure in a computational sense, runs on standard laptops and servers, works over any network including ordinary internet, and costs little more than a software upgrade. Its security depends on the assumed hardness of the underlying mathematical problems, which is a stronger assumption than the laws of physics, but it scales to billions of users in a way QKD cannot. India’s PQC use case is mass civilian deployment, including UPI, Aadhaar, and ordinary HTTPS traffic.
The right answer for a national strategy is both. PQC for the public internet and the bulk of government communications. QKD for the most sensitive strategic links between command centres and embassies.
The Y2Q Problem and Harvest Now Decrypt Later
The risk associated with the eventual arrival of a quantum computer has acquired the shorthand Y2Q, by analogy with Y2K. The exact date of Y2Q is uncertain. Most credible projections place it somewhere between 2030 and 2040. Some hardware roadmaps suggest a working cryptographically relevant quantum computer by 2035. Others are more pessimistic.
The reason the migration cannot wait until Y2Q itself is the harvest-now-decrypt-later attack. An adversary that records encrypted traffic today and stores it, even if it cannot break the encryption, will be able to decrypt it on the day Y2Q arrives. Any data with a sensitivity lifespan longer than the gap between today and Y2Q is therefore at risk now, not in the future. Government records, medical records, and intelligence material easily clear that bar.
The implication is that PQC migration must begin years before the threat is operational. The US government has set a 2035 deadline for federal systems to be PQC-compliant. The EU has issued similar guidance. India’s CERT-In has indicated through its February 2024 advisory that critical sector entities should begin cryptographic agility planning, and the National Quantum Mission’s mandate includes PQC research and deployment.
India’s Response
India’s approach is built on three legs. The first is the National Quantum Mission, approved in April 2023 with an outlay of about six thousand crores, which funds work on quantum computing, communication, and sensing across IISc, IISER Pune, IIT Madras, and other institutions. PQC research is one of the mission’s verticals.
The second is C-DOT, the Centre for Development of Telematics under the Department of Telecommunications. C-DOT has developed indigenous quantum-secure encryptors, including a Compact Encryption Module that supports the new NIST PQC algorithms and is intended for deployment in government networks. C-DOT has also operated QKD links and combined products that use both PQC and QKD in the same device.
The third is policy. The Ministry of Electronics and Information Technology has been consulting since 2024 on a quantum-safe cryptography roadmap that would specify migration timelines for critical infrastructure, banks, and central government systems. CERT-In’s role in coordinating cryptographic agility is expected to expand. The Reserve Bank of India has begun internal evaluation of PQC readiness for the financial sector.
What an Organisation Should Be Doing Now

Three concrete steps are recommended for any institution that handles long-lived sensitive data. First, conduct a cryptographic inventory: identify every system that uses public-key cryptography, every protocol version it negotiates, and every certificate it relies on. Second, implement cryptographic agility: ensure that the algorithms used in any system can be swapped without rewriting the application, by abstracting them behind well-defined interfaces. Third, begin hybrid deployment: combine a classical algorithm such as ECDH with a PQC algorithm such as ML-KEM in the key exchange so that an attacker has to break both to succeed. Hybrid mode protects against both classical and quantum attacks during the transition.
For India, where the deployment surface includes hundreds of millions of UPI transactions, an Aadhaar authentication system that handles billions of requests, and a defence and diplomatic backbone that has its own assurance requirements, the migration is not a one-time project. It is a multi-year programme that will continue through the 2030s. The work that begins now determines whether the country crosses Y2Q with its data intact.
Frequently Asked Questions
What is post-quantum cryptography?
Post-quantum cryptography refers to mathematical algorithms that run on classical computers but are designed so that no known quantum algorithm can break them efficiently. PQC is intended to replace today’s RSA and elliptic curve algorithms before a sufficiently large quantum computer is built. The first three NIST standards, ML-KEM, ML-DSA, and SLH-DSA, were finalised in August 2024.
How is PQC different from quantum cryptography?
Post-quantum cryptography uses mathematics and runs on ordinary computers and networks. Quantum cryptography, of which quantum key distribution is the leading example, uses the physical properties of photons and requires dedicated optical hardware. PQC scales to billions of users and is suited to mass civilian use; QKD is more secure in an information-theoretic sense but is limited in distance and cost.
What is the Y2Q problem?
Y2Q is shorthand for the year a sufficiently large quantum computer will be able to break current public-key encryption using Shor’s algorithm. The exact date is uncertain but most projections place it between 2030 and 2040. The harvest-now-decrypt-later threat means encrypted data with long sensitivity lifespans is at risk today, since an adversary can record it now and decrypt it after Y2Q.
What is C-DOT doing on PQC in India?
The Centre for Development of Telematics has developed indigenous quantum-secure encryption hardware, including a Compact Encryption Module that supports the NIST post-quantum algorithms. C-DOT also operates quantum key distribution links and produces combined products that use both PQC and QKD. Its work supports the National Quantum Mission and the broader migration of Indian government networks.
Will AES need to be replaced because of quantum computers?
Symmetric algorithms like AES are not broken by Shor’s algorithm. Grover’s algorithm provides only a quadratic speed-up against AES, which means AES-128 becomes equivalent to 64-bit security and is too weak, but AES-256 retains 128-bit equivalent security against quantum attack. The standard recommendation is to use AES-256 going forward; AES itself does not need to be replaced.
Tell Google you want more of this.
Add Anantam IAS as a preferred sourceOne tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.