Skip to content
ContentLora

    Tip: press / anywhere to search.

    Explainer

    How post-quantum cryptography works

    Post-quantum cryptography uses ordinary computers to run algorithms built on math problems, mainly structured lattices and hash functions, that experts believe neither classical nor quantum computers can solve efficiently.[1] The new algorithms do the same two jobs as RSA and elliptic curves, establishing keys and signing data, but with much larger keys and signatures.[2][3][4]

    Editor reviewedUpdated Post-quantum cryptography and securityComputing

    Two jobs, new math

    Public-key cryptography does two jobs. It lets two strangers agree on a secret key over the open internet, and it lets someone sign data so others can check who sent it. Post-quantum algorithms do the same two jobs.[2] What changes is the math underneath. Instead of factoring, NIST’s first choices rely on structured lattices (three algorithms) and hash functions (one). Experts believe these problems are hard for both normal and quantum computers.[1]

    Think of a lattice as an endless grid of points in hundreds of dimensions. Add some deliberate “noise” and it becomes extremely hard to find your way back to the right grid point. That noise is what protects the secret.[5]

    ml-kem and ml-dsa rest on Module Learning With Errors (MLWE): recovering a secret from a system of noisy linear equations over a module lattice.[5][6] slh-dsa makes only hash-function assumptions, which gives it a conservative security story at the cost of large signatures.[7][8] hqc uses error-correcting codes and was chosen to give key establishment a non-lattice backup.[9]

    How key encapsulation works

    Classic key exchange has both sides mix numbers until they arrive at the same secret. The new standard uses a “key-encapsulation mechanism” (KEM) instead. Alice publishes a public key. Bob uses it to lock up a fresh random secret and sends the locked box back. Only Alice can open it, with her private key. Now both share a secret and can switch to fast symmetric encryption.[10][11]

    In ML-KEM, Alice generates an encapsulation key and a decapsulation key. Bob runs encapsulation to get a shared secret and a ciphertext, and Alice decapsulates the ciphertext to recover the same 32-byte secret.[11][3] FIPS 203 defines three parameter sets, ML-KEM-512, -768 and -1024.[12] NIST’s SP 800-227 (September 2025) gives guidance on using KEMs securely.[13]

    The cost: size

    The new algorithms are fast but bulky. An ML-KEM-768 public key is 1,184 bytes.[3] ML-DSA signatures are 2,420 to 4,627 bytes.[4] The hash-based backup, SLH-DSA, produces signatures between 7,856 and 49,856 bytes.[8] That matters most for website certificates, which the UK’s cyber agency expects to be one of the hardest things to migrate.[14]

    Size drives most deployment decisions. With ML-KEM-768, a hybrid TLS handshake carries an extra 1,184-byte encapsulation key and 1,088-byte ciphertext. Even so, client support grew from under 3% to over 60% of Cloudflare’s traffic between early 2024 and February 2026.[3][15] Signatures are harder. A Web PKI chain carries several signatures and public keys, which is why the UK NCSC singles out the Web PKI as a hard migration target.[14] Work on signatures continues: NIST still has FN-DSA, based on FALCON, pending, and is evaluating additional schemes that could back up ML-DSA or suit special use cases.[16][17]

    Why hybrids and backups

    Candidates can fail late. SIKE, an isogeny-based candidate that reached NIST’s fourth round, fell to a classical attack in 2022 that took about ten minutes on a single core.[18] In 2024 a claimed quantum attack on Learning With Errors was withdrawn within days, after reviewers found a bug that its author could not fix.[19]

    Deployments hedge in two ways. Hybrids combine a post-quantum and a classical algorithm and stay secure if either holds.[20] Backups based on different math, SLH-DSA for signatures and HQC for key establishment, are standardized in case a weakness is found in the lattice-based primaries.[21][9] Both hedges assume systems can change algorithms without being rebuilt, the goal known as crypto-agility.[22] To see these algorithms in use, read hybrid-post-quantum-tls.

    Questions readers ask

    Do I need a quantum computer to use post-quantum cryptography?

    No. Post-quantum algorithms are classical algorithms that run on today's computers; they are built on math problems believed hard even for quantum computers.[1]

    What is a key-encapsulation mechanism?

    A set of algorithms that lets two parties establish a shared secret key over a public channel, which is then used with symmetric encryption.[10]

    Why are post-quantum keys and signatures so big?

    It is a property of the new math. An ML-KEM-768 public key is 1,184 bytes, ML-DSA signatures run from 2,420 to 4,627 bytes, and SLH-DSA signatures from 7,856 to 49,856 bytes.[3][4][8]

    Has any post-quantum algorithm been broken?

    Yes, among candidates. SIKE, an isogeny-based scheme in NIST's fourth round, was broken in 2022 by a classical attack that took about ten minutes on one core. The standardized algorithms have not been broken.[18]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      Of the four algorithms NIST first selected, three are based on structured lattices and one on hash functions, math problems experts believe are hard for both classical and quantum computers. confirmedas of 2026-10-10

    2. [2]

      Post-quantum algorithms are designed for two main tasks, general encryption (establishing keys) and digital signatures used for authentication. confirmedas of 2026-10-10

    3. [3]

      In ML-KEM-768 the encapsulation (public) key is 1,184 bytes and the ciphertext 1,088 bytes, and every parameter set produces a 32-byte shared secret. confirmedas of 2024-08-13

    4. [4]

      ML-DSA's three parameter sets, ML-DSA-44, ML-DSA-65 and ML-DSA-87, have public keys of 1,312, 1,952 and 2,592 bytes and signatures of 2,420, 3,309 and 4,627 bytes. confirmedas of 2024-08-13

    5. [5]

      ML-KEM's security rests on the difficulty of solving certain systems of noisy linear equations, the Module Learning With Errors (MLWE) problem, and it is believed to be secure even against quantum adversaries. confirmedas of 2024-08-13

    6. [6]

      ML-DSA is based on the Module Learning With Errors problem and is believed to be secure, and strongly unforgeable, even against an adversary with a large-scale fault-tolerant quantum computer. confirmedas of 2024-08-13

    7. [7]

      SLH-DSA is a stateless hash-based digital signature algorithm based on SPHINCS+. confirmedas of 2024-08-13

    8. [8]

      FIPS 205 approves 12 SLH-DSA parameter sets, tuned for either small signatures ("s") or fast signing ("f"), with public keys of 32 to 64 bytes and signatures from 7,856 to 49,856 bytes. confirmedas of 2024-08-13

    9. [9]

      On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11

    10. [10]

      A key-encapsulation mechanism (KEM) is a set of algorithms that lets two parties establish a shared secret key over a public channel; that key is then used with symmetric algorithms for encryption and authentication. confirmedas of 2024-08-13

    11. [11]

      In a KEM, Alice publishes an encapsulation key; Bob uses it to generate a shared secret and a ciphertext, and Alice recovers the same secret from the ciphertext with her private decapsulation key. confirmedas of 2024-08-13

    12. [12]

      FIPS 203 specifies three ML-KEM parameter sets, ML-KEM-512, ML-KEM-768 and ML-KEM-1024, in order of increasing security strength and decreasing performance. confirmedas of 2024-08-13

    13. [13]

      On 18 September 2025 NIST published SP 800-227, recommendations for implementing and using KEMs securely. confirmedas of 2025-09-18

    14. [14]

      The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20

    15. [15]

      Cloudflare Radar measured client support for post-quantum encryption growing from under 3% of traffic at the start of 2024 to over 60% in February 2026. confirmedas of 2026-02-27

    16. [16]

      In August 2024 NIST said a draft FIPS 206 standard built around the FALCON algorithm would follow, with the algorithm renamed FN-DSA. confirmedas of 2024-08-13

    17. [17]

      NIST's additional signature process seeks schemes that could back up ML-DSA or address special use cases. confirmedas of 2026-08-05

    18. [18]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    19. [19]

      An April 2024 preprint claimed a polynomial-time quantum algorithm for the Learning With Errors problem, but within days its author reported a bug he could not fix and said the claim no longer held. confirmedas of 2024-04-19

    20. [20]

      Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12

    21. [21]

      NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13

    22. [22]

      NIST defines cryptographic agility as the capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations. confirmedas of 2025-12-19

    Revision history (1)
    1. Page created.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "How post-quantum cryptography works." ContentLora, updated Oct 10, 2026. https://contentlora.com/explain/how-post-quantum-cryptography-works

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.