If you have ever shopped online, sent an encrypted email or made a bank transfer, your trust has rested on two acronyms: RSA and ECC. They are the algorithms protecting almost every encrypted connection on the planet. And they are, in all likelihood, living on borrowed time.
Not because they will die suddenly: what threatens them is a kind of computer that does not yet exist in a useful form, but that the industry is already taking seriously. It is called a quantum computer, and post-quantum cryptography is the race to build locks that such a machine cannot open.
Why a quantum machine breaks RSA
RSA rests on a problem that is easy to state and seemingly hard to invert: multiplying two large prime numbers is fast, but working out which primes produced a given product is extremely expensive. With 2048-bit keys, a classical computer would take longer than the age of the universe to factor it.
That changes with Shor’s algorithm, from 1994. This method reduces factoring (and its relative, the discrete logarithm that ECC relies on) to a problem a quantum computer solves in polynomial time: going from “impossible” to “a matter of minutes or hours”. A quantum machine with more than 20 million physical, error-corrected qubits would be enough to break RSA-2048; a distant figure today, but not a theoretical absurdity.
The NIST competition: choosing the replacement defenses
Well aware of this, the US National Institute of Standards and Technology (NIST) launched a public competition in 2016 to standardize new algorithms. After years of analysis and attacks, in 2024 it published the first standards:
- ML-KEM (formerly Kyber, FIPS 203): a key-encapsulation cipher, designed to replace the RSA/ECC key exchange.
- ML-DSA (formerly Dilithium, FIPS 204): digital signatures to authenticate and validate documents.
- SLH-DSA (formerly SPHINCS+, FIPS 205): a hash-based backup signature, immune even to quantum attacks on lattices.
They will be joined by FN-DSA (Falcon), with very compact keys for low-bandwidth contexts.
The backbone: lattices and the LWE problem
ML-KEM and ML-DSA rely on a mathematical family called lattice cryptography. A lattice is an infinite grid of points with regular structure, analogous to the cell of a crystal. Security no longer depends on factoring numbers, but on a problem called LWE (Learning With Errors): given a set of linear equations slightly contaminated with noise, recovering the exact solution is extremely hard — and that “noise” is completely invisible to a quantum computer, whose most powerful attack (Shor’s) does not apply here.
It is an elegant idea: while old cryptography breaks if the attacker can factor in parallel, lattice cryptography is resistant by construction. Nobody has yet shown a way, even quantum, to solve LWE quickly.
KEM: exchanging keys is not the same as encrypting
One technical nuance matters: in the classical world, symmetric keys are transported with asymmetric encryption (RSA). In the post-quantum world, a KEM (Key Encapsulation Mechanism) is used instead — a protocol where the sender “encapsulates” a random key into a message that only the receiver (holding the private key) can “decapsulate”. It is a scheme distinct from encrypting long messages, which is why the standards treat it as a separate module.
Slowing the migration only makes the bill worse
The biggest danger is not the quantum machine as physical hardware, but time. Harvest now, decrypt later attacks are already a credible concern: criminals can record today’s RSA-encrypted traffic and archive it until a powerful quantum computer exists. Anything transmitted now that must remain secret in 10 or 15 years is at risk.
Migration happens in layers and often in hybrid mode: a classical exchange (X25519) is combined with a post-quantum one (ML-KEM) so that overall security holds as long as either path is robust. Tools such as OpenSSH, TLS 1.3 and X.509 certificates already support these modes, and some large clouds even enabled them internally in 2024.
The real cost: bigger keys, heavier computation
There is no free lunch. ML-KEM public keys take up on the order of a kilobyte, versus 256 bytes for an RSA-2048 key or 32 for a P-256 one. Signatures are bulkier and operations are more CPU-intensive. In mobile or IoT settings, where every byte and every battery charge counts, that forces choices such as ML-KEM-512, or resorting to SLH-DSA only when the risk justifies it.
The result is an engineering debate more than an algorithmic one: how to deploy it with the least real impact.
What you can do today
For the end user, the good news is that the revolution is invisible: when your browser negotiates TLS 1.3, your provider already decides whether to add ML-KEM transparently. For administrators and developers, the practical advice is to start testing hybrids on critical services, audit the compatibility of their stack (libraries such as OpenSSL 3.5 and TLS libraries already support it) and, above all, not to wait for the quantum machine to hit the headlines before starting to move.
RSA took care of us for decades. But the next generation of keys will no longer carry its signature: it will be the one of the lattices.






