On 13 August 2024, the United States National Institute of Standards and Technology published the world’s first finalised post-quantum cryptography standards β three documents that begin the largest coordinated migration in the history of digital security: re-cryptographing the internet, banking, email and state secrets against computers that do not yet exist. The standards finalised algorithms named ML-KEM, ML-DSA and SLH-DSA β lattice and hash constructions selected through an eight-year global competition β to replace the RSA and elliptic-curve mathematics that secure nearly everything today and that a sufficiently large quantum computer would break.
On this page
This card, dated the day after publication, assembles the exam kit: why quantum breaks today’s locks, what the new standards contain, the harvest-now-decrypt-later urgency, India’s assets and gaps in this migration, and how the examination treats a threat whose deadline is written in arithmetic rather than announcement.
The Standards Themselves: FIPS 203, 204, 205
The three documents β what each does.
- FIPS 203: ML-KEM. Module-Lattice Key Encapsulation β the key-exchange standard (selected from Kyber) that lets two parties who have never met agree on a shared secret over an open channel; this replaces the key-agreement half of TLS.
- FIPS 204: ML-DSA. Module-Lattice Digital Signature Algorithm (from Dilithium) β the signature standard for authentication; this is the bulk-use replacement for RSA and elliptic-curve signatures.
- FIPS 205: SLH-DSA. Stateless Hash-based Digital Signature Algorithm (from SPHINCS+) β the conservative backup signature built on hash functions alone, slower and larger but mathematically the most conservative of the set.
- The fourth selection. Falcon β the fourth competition selection, a lattice signature with compact output, was scheduled as a future standard due to implementation complexity β a detail that separates well-prepared candidates.
- The exam line. KEM from Kyber, signatures from Dilithium and SPHINCS+, Falcon pending β the three-plus-one lineup every prelims set can scramble.
Why Quantum Breaks Today’s Locks
The two-sentence physics, then the two-sentence maths.
- Shor’s algorithm. A large fault-tolerant quantum computer running Shor’s algorithm factors integers and solves discrete logarithms in polynomial time β collapsing the mathematical assumptions under RSA and elliptic-curve cryptography at a stroke.
- Grover’s algorithm. The weaker threat: quadratic speedup for brute-force search, halving effective symmetric key lengths β the answer is doubling key sizes, not new mathematics.
- Qubits versus quality. Today’s noisy machines have hundreds to low thousands of physical qubits with high error rates; breaking RSA-2048 needs millions of physical qubits error-corrected into thousands of logical ones β an engineering gap measured in years of hard work.
- The certainty problem. Nobody knows when a cryptographically relevant quantum computer arrives β estimates range from a decade to never; security planning cannot wait for the answer.
- The exam line. Shor breaks public-key, Grover weakens symmetric, logical-qubit thresholds still far, arrival date unknowable β the four-fact threat model.
Harvest Now, Decrypt Later
The threat that makes this urgent today.
- The attack logic. An adversary records encrypted traffic today, storing it until a quantum computer exists to decrypt it retroactively β data captured in 2024 can be read in the 2030s.
- Who is exposed. Long-lived secrets β state archives, health records, biometric databases, diplomatic cables β anything whose sensitivity outlives the decade is already at risk.
- Mosca’s inequality. If secrecy-lifetime plus migration-time exceeds time-to-quantum, you are already late β the simple arithmetic (often taught as 10 + 10 > 15) that converts an abstract risk into a deadline.
- The intelligence race. State actors are assumed to be harvesting already β the reason migration is classified as national-security infrastructure, not IT maintenance.
- The exam line. Record now, decrypt later; long-lived data exposed; Mosca’s sum decides urgency β the three-part justification for acting before the machine exists.
The Migration: Largest in Cyber History
Standards are paper; migration is a decade of work.
- The scale. Every TLS endpoint, certificate authority, banking switch, government certificate, embedded device and IoT sensor β billions of endpoints running RSA and elliptic-curve must move to new mathematics; the Y2K comparison understates it because the deadline is invisible.
- Crypto-agility. The era’s real lesson: systems must be built to swap algorithms without re-engineering β the property regulators and standard-setters now demand by name.
- Hybrid deployment. Near-term deployments pair classical with post-quantum algorithms β combining keys so an attacker must break both; the bridge architecture of the migration decade.
- The discovery problem. Organisations do not know where their cryptography is β inventory first, then replace; the unglamorous first step every migration guide begins with.
- The exam line. Billions of endpoints, crypto-agility as doctrine, hybrid bridges, inventory-first β the four-part migration answer.
India’s Position: Assets and Odds
What India has and what it lacks for the migration.
- The mission. India’s National Quantum Mission β approved April 2023, βΉ6,003 crore, 2023-2031 β funds quantum computing, communication, sensing and metrology; the domestic base for both threat and opportunity.
- The research base. C-DAC and academic groups work on PQC algorithms and implementations; DRDO programmes on quantum communication include satellite QKD experiments β the scientific assets to draw on.
- The standards gap. No Indian PQC mandate existed as of this date β no RBI circular, no telecom-security direction, no e-governance migration order; the National Cyber Security Strategy draft had circulated but not been notified, leaving migration unorchestrated.
- The opportunity. PQC products, consulting and integration are a global market being born β India’s services industry can own a share of the migration the way it owned Y2K remediation.
- The exam line. National Quantum Mission 2023, C-DAC and DRDO research, no mandate yet, services opportunity β the four-line India position.
How Exams Ask This Card
Question shapes and their marking engines.
- Algorithm matching. Shor with factoring, Grover with search, ML-KEM with key exchange, ML-DSA with signatures β the matching set built from this card.
- Standard numbers. FIPS 203-204-205 contents and their competition names (Kyber, Dilithium, SPHINCS+) β the direct prelims pair.
- Mains: evaluate migration urgency. Harvest-now-decrypt-later plus Mosca’s inequality plus the inventory problem β structure an answer on why standards now, migration immediately.
- India linkage. National Quantum Mission, C-DAC and DRDO work, the absent mandate β the linking question that connects global standard to domestic readiness.
- Essay and interview. Secrecy into the future β the harvest-now logic is the general-knowledge question interviewers use to test horizon-scanning; Mosca’s arithmetic is the crisper answer they reward.
Quick Revision: Ten Lines
One glance before the hall.
- The event. NIST published the first final PQC standards 13 August 2024 β FIPS 203, 204 and 205.
- The algorithms. ML-KEM (Kyber) for key exchange; ML-DSA (Dilithium) and SLH-DSA (SPHINCS+) for signatures; Falcon to follow.
- The threat. Shor’s algorithm breaks RSA and elliptic-curve math on a large fault-tolerant quantum computer; Grover weakens symmetric crypto.
- The timeline uncertainty. Cryptographically relevant machines need millions of physical qubits; arrival estimates range from a decade upward.
- The urgency logic. Harvest-now-decrypt-later β traffic recorded today can be decrypted retroactively; long-lived secrets are already exposed.
- Mosca’s inequality. Secrecy lifetime plus migration time versus time to quantum β if the left side exceeds the right, the migration is already late.
- The migration. Billions of endpoints, hybrid classical-plus-PQC bridges, crypto-agility as doctrine, inventory-first practice.
- India’s base. National Quantum Mission (April 2023, βΉ6,003 crore, to 2031), C-DAC PQC projects, DRDO quantum-communication research.
- India’s gap. No migration mandate yet β no regulatory circular, no e-governance direction; orchestration missing as of this date.
- The opportunity. PQC integration as the Y2K analogue for India’s services industry β a migration market measured in billions.
Conclusion: Re-Keying Civilisation
Post-quantum cryptography is the rare security story in which the defence arrives before the threat β standards published while the breaking machine remains a laboratory ambition. That inversion is the exam’s favourite twist: the urgency comes not from the computer but from the arithmetic of recorded traffic and long-lived secrets, which is why migration begins the day standards exist. India enters the migration decade with a quantum mission funding the science and a services industry that has executed exactly this kind of global remediation before. What GS3 asks β and this card answers β is why lattice mathematics replaced factoring, why the deadline is now though the machine is not, and where India’s assets and gaps sit on the migration path.
Quick revision
- FIPS 203: ML-KEM.: Module-Lattice Key Encapsulation β the key-exchange standard (selected from Kyber) that lets two parties who have never met agree on a shared secretβ¦
- FIPS 204: ML-DSA.: Module-Lattice Digital Signature Algorithm (from Dilithium) β the signature standard for authentication; this is the bulk-use replacement for RSAβ¦
- FIPS 205: SLH-DSA.: Stateless Hash-based Digital Signature Algorithm (from SPHINCS+) β the conservative backup signature built on hash functions alone, slower andβ¦
- The fourth selection.: Falcon β the fourth competition selection, a lattice signature with compact output, was scheduled as a future standard due to implementationβ¦
- The exam line.: KEM from Kyber, signatures from Dilithium and SPHINCS+, Falcon pending β the three-plus-one lineup every prelims set can scramble.
- Shor’s algorithm.: A large fault-tolerant quantum computer running Shor’s algorithm factors integers and solves discrete logarithms in polynomial time ββ¦
