
From False Alarms to Real Threats: Protecting Cryptography Against Quantum
Tommy Charles and Thalia Laing, HP Security Lab
Table of contents
Executive Summary
Introduction
Learning from False Alarms
The First Alarm: Quantum Algorithm for Solving Lattice-Based Cryptosystems
The Second Alarm: Quantum Annealing Public Key Cryptographic Attack
Staying Prepared Amid False Alarms
Understanding the Real Alarm Level
The Real Alarm Level: Recent Progress in Quantum Computing Technology
Migrating Quantum-Vulnerable Cryptography is on a Whole New Level Compared to Patching a Zero-Day Vulnerability
Responding to the Quantum Threat
Nations Taking Action Now
Driving the Response: Standards Collaboration
HP’s Strategic Response: Quantum-Ready from the Hardware Up
Conclusion
References
Executive Summary
Quantum computers could break asymmetric cryptography, which would be catastrophic for society’s digital infrastructure. Quantum computers powerful enough to break cryptography do not exist today, but the threat of one being created steadily advanced in 2024. With multiple quantum computing technologies overcoming development obstacles, the security community is now more sure than ever that sufficiently powerful quantum computers will come. Some think it could be ten years, but with the speed of recent innovation, an unexpected breakthrough could accelerate that. This has created a significant security risk because we rely on protections for a long time and need them in place before threats arise.
Since we last wrote on this topic a year ago[1], authorities around the world have increased efforts to urge organisations to start migrating systems to quantum-resistant cryptography. Critical industries are especially advised to mitigate these quantum risks given they are high profile targets. Particular priorities for migration include sensitive data vulnerable to capture-and-decrypt attacks, and protections rooted in hardware. Without upgraded protections at the hardware and firmware foundation, quantum attackers can compromise devices even if the software running on the hardware is quantum-resistant.
2024 also saw several false alarms of quantum breaks to cryptography. We expect that to become a trend as innovation in quantum computing progresses. What we have seen is that such false alarms will elicit panic from some, but only complacency from others. But they also proved useful in raising the conversation about readiness and an understanding of the consequences of a real alarm. In short, we must stay vigilant and prepare for the real threat.
Over the last year, we at HP also made progress to protect customers from the threat of cryptography being broken by quantum computers. Last year we announced the world’s first business PCs to protect firmware integrity against quantum computer attacks[2]. Today, we are announcing the world’s first printers to protect firmware integrity against quantum computer attacks[3]. These security innovations demonstrate our dedication to safeguarding our customers against future threats.
“As innovation progresses towards more powerful quantum computers, it is urgent to prepare for the threat this represents to the asymmetric cryptography we depend on in our daily digital lives. This starts with migrating systems that cannot be updated easily once deployed. After the introduction of quantum-resistant firmware integrity protection in PCs last year, today we are announcing the launch of printers with similar capability to protect against future quantum computing threats. We continue with our commitment to lead the way with endpoint security innovation, and keep our customers safe into the future.” – Boris Balacheff, HP Fellow and Chief Technologist for Security Research and Innovation. Head of the HP Security Lab.
Introduction
In the past 12 months, the cryptography and security community has experienced heightening concern about the progress of quantum computing. The last year has been marked by key developments in quantum computing technology, as well as multiple instances of false alarms over potential quantum breakthroughs that put cryptography at risk. Although these alarms were ultimately disproven, when considered alongside genuine advancements in quantum computing, they highlighted the fragility of society’s digital infrastructure. A sufficiently powerful quantum computer could break much of the cryptography relied upon globally. Given how fundamental cryptography is to security everywhere, a quantum computing breakthrough before the world is ready would jeopardise security. It could allow attackers to run riot across our digital infrastructure – giving them freedom to access network services, takeover devices, steal blockchain assets, decrypt sensitive data, and more.
In reaction to these advancements, there has been an increased sense of urgency to fortify cryptography, driven by technical authorities and experts. This urgency has led to accelerated timelines and new policies to address the looming quantum threat[1]. Against this backdrop, the security community has intensified its preparations. Academia, standards bodies, governments, and industry are collaborating and making concerted efforts to migrate technologies to being quantum-resistant.
HP is actively preparing for the quantum threat. Our security innovation strategy has long been focused on making the necessary preparations to protect our customers from emerging and evolving cyber threats, and this includes the threat to cryptography from future quantum computers. In this effort, we are prioritising quantum resistance for the critical device foundations that secure our customers – starting from hardware and low-level firmware.
In this blog post, we discuss two false alarms that percolated through the community over the last year and what we learnt from them. We explore the current state of the quantum computing threat to cryptography and how the community is preparing a response. Finally, we summarise HP’s strategy and progress with quantum-resistant cryptography migration[2], including today’s announcement of the world’s first printers to protect firmware integrity against quantum computer attacks[3].
Learning from False Alarms
The First Alarm: Quantum Algorithm for Solving Lattice-Based Cryptosystems
The first false alarm took place in April 2024 during the NIST 5th PQC Standardization Conference[4], which had convened to discuss cryptography designed to withstand quantum computer attacks. The trigger for the alarm was an academic paper – newly published and not yet reviewed or corroborated – describing a new quantum computer attack that could have been effective at breaking the very cryptography the technical community had been working on for almost a decade. This cryptography was meant to become a global standard to protect digital infrastructure, should quantum computers break traditional asymmetric cryptography like RSA and most Elliptic Curve Cryptography (ECC). A claim it was broken was shocking and would leave the quantum-resistant migration in disarray, if confirmed true.
Speculation about the paper, entitled “Quantum Algorithm for Solving Lattice-Based Cryptosystems”[5], lit up our technical social media networks. One of our team was at the conference. While the talks continued and the audience listened attentively, attendees gradually started to form small huddles, trying to make sense of the publication. Remarkably, no one was sure the paper was incorrect. Most believed it probably was incorrect, but at face value it was convincing – presenting a credible nine-step algorithm that put quantum-resistant lattice-based cryptography in a very precarious position.
For eight days, there was furious analysis among cryptographers and quantum computation experts. But with very few people who can claim to be experts in both fields, many researchers wrestled with analysis beyond their areas of expertise. A Discord community sprang up, crowd-sourcing a comprehensive analysis and triage of the paper’s claims. This intense assessment phase ended when two researchers found an inconsistency in the final step of the algorithm. The paper’s author engaged with this critique and confirmed the final step had an irreconcilable error.
And thus, the community breathed again. But for an entire week, the community responsible for developing the cryptography that will protect much of our digital lives into the future had seriously considered the possibility that they could have got it wrong. Because this was so technical and didn’t impact the cryptography we use currently, the news did not make the broader security community panic – and the doubt didn’t last long enough within the cryptography technical community to gain momentum and spread.
The Second Alarm: Quantum Annealing Public Key Cryptographic Attack
The second moment of 2024 when the broader security community thought that cryptography was broken was also triggered by an academic paper. The paper, “Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage”, was published in May 2024 in the Chinese Journal of Computing. This false alarm caused more widespread uncertainty and panic in the technical community and beyond, with several reports stating incorrectly that some researchers were able to break RSA encryption using a D-Wave Advantage quantum computer. With a general audience unable to assess the original paper (only the abstract was published in English), the reports generated a real anxiety. However, there was little credibility in the claim that RSA had been broken, and expert consensus rapidly emerged. With a bit of scrutiny, it was established that the researchers had only broken a very small scale, simplified RSA, and their solution didn’t scale to the kind of numbers used for security and was therefore not a feasible threat.
Once again, after a week or so, concerns about cryptography being broken were largely quelled. However, for several months after, incorrect reports still appeared, sparking fresh waves of concern amongst those who had missed the initial reporting.
Staying Prepared Amid False Alarms
One benefit of these events is that they test the security community’s preparedness for the sudden removal of some fundamental underlying cryptographic primitive. From that perspective, these alarms have been like the safety briefing before an airplane flight – forcing the community to grapple with what to do in the worst-case scenario. If the event were real, are we ready? What preparations should be in place, and are they?
The fact that a broad audience was alarmed tells us that there is a growing understanding of the critical impact of the quantum threat, and that action will increasingly be called for. The successful resolution of these incidents underscores the importance of a measured and collaborative approach to evaluating cryptographic research, for the community has shown it can be relied upon to robustly evaluate these complicated ideas. Unfortunately, analysing such academic papers is inherently complex, requiring expertise that is rarefied and spans multiple fields – cryptography, mathematics, quantum algorithms, quantum computer engineering and physics. So, we should anticipate regular moments of doubt in the security of our cryptography and have the patience to wait for assessment before any panic-induced reactions.
One day, there could be surprise news, or even a significant rumour, of a real breakthrough. Rather than panic, we should instead ensure we are prepared and put in place quantum-resistant protections – starting with our priorities.
This said, there is also concern that too many false alarms related to quantum computing breakthroughs could lead to a sense of complacency and inaction[6]. This might cause people to believe the quantum threat is not yet a serious concern. If too many incidents lead to unwarranted panic, a genuine threat might be ignored as just another false alarm when it finally arises.
With so many possible quantum breakthroughs to be assessed, and uncertainty about what is credible, it can be difficult to understand the landscape of quantum computing and separate fact from fiction. Let us take a closer look at the reality.
Understanding the Real Alarm Level
The Real Alarm Level: Recent Progress in Quantum Computing Technology
To gauge the true alarm level, we should examine the progress in quantum computing technology. Over the past year, there has been impressive advancement in several technologies, with multiple promising pathways emerging. Even if some fail, others may succeed. Compared to a year ago, large-scale quantum computing now seems more likely. We look to experts to quantify this likelihood.
The Global Risk Institute’s 2024 report[7] highlights a “significant chance” of a quantum threat by 2034, posing an “intolerable risk from a cybersecurity perspective”. Nearly a third of the 32 experts surveyed estimate a 50% or greater chance of quantum computers breaking cryptography by 2034, with an average estimate of 27% – the highest in the six annual surveys conducted so far. To summarise recent change, the report states: “The progress in the last year has induced many people both within and outside the quantum research community to realize that the quantum threat may be closer than they thought.” The German Information Security authority, BSI, recently updated their comprehensive assessment of quantum computer technologies.[8] The report concludes that, due to major roadblocks being resolved, quantum computers are likely to break cryptography within at most 16 years but recognises that new developments could lead to a breakthrough in as soon as a decade.
Progress has been made not only in various quantum computing candidate technologies, but also in aspects like stability, scale, inter-connectivity, and operating software.
Stability is a major challenge for current quantum technologies, as they do not hold their state for long before deteriorating. Reducing noise and using effective error-correction – where more errors are corrected than introduced – is crucial for long-term stability. Demonstrating this effectiveness is a milestone that has been achieved by four technologies: Superconducting Transmons (Google[9]), Ion Traps (Microsoft-Quantinuum[10][11]), Neutral Atoms (Harvard-MIT-NIST-QuEra[12]), and Color Centers (Delft-Juelich-Element Six[13]).
Sizes of systems have increased as production processes mature, with Google announcing the 105-qubit Willow[14], IBM introducing the 156-qubit Heron[15] with a roadmap for processor scaling[16], and Microsoft and Quantinuum upgrading the H2 Trapped Ion processor to 56 qubits[17]. The stability and size of the relatively new Neutral Atom technology, whose key elements were only demonstrated as recently as 2022[18], has also shown a massive improvement with potential for acceleration[12][19]. The QuEra start-up that came out of this research has just this February been backed with a $230M investment[20] which gives an indication of the high interest in this approach. Of very recent note, a new technology with greater natural stability – the topological qubit – has been demonstrated for the first time as a proof of concept by Microsoft[21] who claim the technology offers a “clear path to fit a million qubits on a single chip”, which would be needed for scaling.
Advances in inter-connecting quantum states between different chips are starting to show promise for enabling the distributed quantum computation needed for large quantum computers.[22][23][24] Additionally, an ecosystem of organisations[25] are developing the necessary developer tools and software stack for operating quantum computers and creating quantum programs. This stack, like the classical computation stack, ranges from physical machine instructions to higher-level programming languages, allowing specialists to effectively use their expertise and enhance progress.
Given all these advancements, Scott Aaronson[26], a quantum computing expert, recently said he believes that the “race to build a scalable fault-tolerant quantum computer is actually underway”. His position on the urgency of addressing the quantum threat to cryptography has shifted from “maybe” to “unequivocally, worry about this now. Have a plan.”
In summary, in the past year, breakthroughs in quantum computing have strengthened the consensus that quantum computers capable of breaking today’s cryptography may become feasible soon. It may only take a surprise acceleration from one of the promising technologies to break cryptography in less than a decade[8]. Therefore, it’s crucial to assess our preparedness and take action to ensure we are fully ready.
Migrating Quantum-Vulnerable Cryptography is on a Whole New Level Compared to Patching a Zero-Day Vulnerability
It is tempting to think the problem of fixing quantum-vulnerable cryptography is like patching a zero-day vulnerability in code. However, this analogy under-represents the scope of the quantum threat. A zero-day vulnerability is an error in a specific sequence of computer instructions in a specific program or library, which can typically be identified and then patched. Even if the error occurs in a pervasively common library, such as the Log4j vulnerability[27], it is still fixable by deploying a patch.
Unlike a zero-day, the quantum threat does not apply to a specific sequence of computer instructions but instead applies to all implementations of vulnerable asymmetric cryptography. These implementations vary widely, potentially manifesting in millions of different code sequences. When quantum computers become viable, each of these will need patching individually, by upgrading the cryptographic algorithms and keys used, requiring a global effort and collaboration by security practitioners, business leaders, and cryptographic experts.
This process of patching has already started and is part of the migration to quantum-resistant cryptography that the security community is currently undertaking. But how should organisations be responding? Let’s move on to that.
Responding to the Quantum Threat
Nations Taking Action Now
Across government, industry, academia and standards bodies, mechanisms to protect against quantum attacks are being put into place with some urgency. Our advice is to start by inventorying what would be vulnerable to quantum attackers. Then prioritise what needs migrating and protecting first, as set out in our blog[1]. The most urgent priorities for most organisations include:
- Protecting data with long-term confidentiality requirements
- Protecting long-lived systems by upgrading cryptography in hardware
The cost of upgrading hardware is expected to be significant. In July 2024 the US Office of the National Cyber Director published a report[28] estimating the total cost of quantum-resistant cryptography migration for prioritised US government systems between 2025 and 2035 at approximately $7.1 billion. In their calculation, they specifically call out that migrating the cryptography hardwired into hardware or firmware would constitute a significant portion of that overall cost.
Government authorities are uniquely positioned with expert insights and the responsibility to protect national assets. Understanding their strategy and policies for critical systems and infrastructure should help any organisation plan for migration with appropriate urgency.
Let’s start with the US, who have a comprehensive plan and set of actions in place. In 2022, US authorities established a tempo for migration[29]. This has led to all federal agencies planning, taking inventories, and reporting on progress annually. A timetable to migrate National Security Systems[30] was also established, with all new acquisitions from 2027 needing to be quantum-resistant, and all non-migrated products to have been phased out by the end of 2030. Migration of firmware signing is prioritised as even more urgent, with migration of firmware roots of trust (i.e. firmware integrity protections in hardware) expected to be “implemented for some long-lived signatures in 2025”. Since 2022, authorities have put in place guidance (including this guide published by CISA, NSA and NIST[31]) and organised outreach to help engage and ready industry[32]. Most recently, the Executive Order on “Strengthening and Promoting Innovation in the Nation’s Cybersecurity” of 16 January 2025[33], further emphasised the urgency to migrate. It specified that when procuring products, federal agencies must require quantum-resistant cryptography when it is widely available in a product category and require quantum-resistant protection in networks “as soon as practicable”.
Alongside this, NIST recently released its draft plan[34] to deprecate classical asymmetric cryptography – RSA and relevant ECC – from the end of 2030 and entirely disallow it for security purposes after 2035. Assuming this plan is confirmed, this will be highly influential in establishing migration urgency, because it means there is an end date within the lifetime of many current systems. Even during 2031-2035, data owners will only be able to use quantum-vulnerable cryptography by exception, where they evaluate and accept the risk[35].
Beyond the US, the Australian Cyber Security Centre (ACSC) is also setting an urgent timeline for migration. The ACSC recently updated its Cryptography Guidelines for government and industry[36] to disallow quantum-vulnerable cryptography after 2030.
In Europe, the security authorities of the UK, France, Germany, the Netherlands, Sweden, Norway, and Switzerland, all urge preparation and are giving increasingly comprehensive guidance on how to migrate and prioritise. In April 2024, the European Commission recommended establishing a strategy to migrate public services and critical infrastructures as soon as possible[37]. Building on this, in November 2024, 18 EU Member States issued a Joint Statement[38] urging nations to make the transition to quantum-resistant cryptography a “top priority” and protect the most sensitive data “as soon as possible, latest by the end of 2030.”
The last 12 months have seen an intensification of the calls to migrate by national authorities. This underlines the need to act: assess cryptography dependencies, plan and prioritise for migration, and start to migrate priority assets.
Driving the Response: Standards Collaboration
The heightening of the quantum threat to cryptography and the intensification of national calls to action during the last year have fortunately been met with significant progress in the range and availability of mitigation solutions. New quantum-resistant cryptographic algorithms were released as NIST Standards[39] last year to celebration of government, academia and industry – following a collaborative selection process spanning nearly a decade. These new algorithms offer quantum resistance suitable for general use in protocols and applications. They also complement existing standardised quantum-resistant hash-based signatures[40] suitable for special purposes, such as code signing. With this suite of standards, it has now become possible for industry to migrate in many scenarios.
Standards capture community consensus and security best practice, whilst enabling interoperability between different elements across a system. As such, standards are a crucial part of industry migration to quantum resistance. From standards that define new cryptographic algorithms, through to protocols that use these algorithms and applications that adopt them, the community is carefully and steadily integrating quantum resistance into the technology stack and making resistance available to customers in products.
This is why collaborating with other vendors and participating in standardisation efforts is essential. Notably, we are engaged in NIST’s National Cybersecurity Center of Excellence (NCCoE) Migration to Post-Quantum Cryptography project[41]. This NCCoE project was convened to bring industry and end-user organisations together to help solve the practicalities of quantum resistance adoption and transition.
HP’s Strategic Response: Quantum-Ready from the Hardware Up
To stay ahead of the quantum threat to cryptography, we cannot afford to take a “wait and see” approach. At HP, our strategy is to prioritise quantum resistance from the hardware up and securely migrate from there. When prioritising and planning what protections to migrate, it is crucial to consider the cost, effort and difficulty of engineering the change. Migrating hardware – and the solutions baked into hardware – often requires changes to physically-engineered parts, which can be slow and needs a lot of forward planning, sometimes years ahead.
Last year, we introduced PCs with quantum-resistant protection of firmware integrity designed into hardware[2]. Our quantum-resistant hardware foundation defends against a quantum computer attacker forging the signature on malicious firmware and taking over the device. For more about how we designed our upgraded PC foundation, see our blog on the topic[42]. Today, we announced the launch of the world’s first printers designed to protect firmware integrity against quantum computer attacks[3]. These new printers safeguard the integrity and authenticity of low-level firmware against quantum attackers, with firmware protection integrated into the hardware.
Without this quantum-resistant foundation, a quantum attacker could run their own code at the most privileged level and totally compromise the security of the printer – handing an attacker control of the device and access to all its data. The high impact of a successful attack and the long lifespan of modern printers were key to why we have prioritised making our printer security foundation quantum-resistant. This upgrade also provides an anchor for further quantum-resistant updates to printer software.
Together with our introduction last year of firmware integrity protection against quantum computer attacks in PCs, this new announcement is an exciting step forward in our efforts to migrate the security foundation to quantum-resistant cryptography and continue to deliver the most secure devices with security built-in to withstand future threats. We proactively anticipate and respond to emerging threats, including quantum threats, leveraging our history of security innovation to ensure our customers’ long-term security needs are met. The false alarms of the last year and our assessment of the risk for the future confirms the importance of our quantum resistance strategy: continuously assess the evolution of the threat, prioritise, and proceed with migrating critical use-cases, starting with establishing quantum-resistant security foundations for hardware and firmware.
Conclusion
The threat quantum computers pose to cryptography has steadily advanced this past year, creating an unacceptable security risk to the algorithms fundamental to securing our digital lives. It would be devastating if these cryptographic algorithms were broken. In response, this last year national authorities and industry experts have intensified their calls to migrate to quantum-resistant cryptography.
Multiple quantum technologies have shown improved stability and scalability, providing promising pathways to a large-scale quantum computer. Experts now estimate that there is a 27% likelihood of a quantum computer breaking cryptography by 2034[7]. Furthermore, the US, Australia and several European nations have set timelines and guidance for the transition, with 2030 emerging as the probable pivotal date after which many organisations should not rely upon existing quantum-vulnerable asymmetric cryptography.
Organisations should be preparing now by assessing their risks and engaging their vendors to introduce quantum resistance ahead of the threat being realised, prioritising protection of long-lived sensitive data and the hardware security foundation. With general purpose quantum-resistant cryptography algorithms now standardised by NIST and being adopted internationally, 2025 is the first full year where most quantum-vulnerable implementations now have a viable migration path. As a result, we expect to see protocols and products offering quantum resistance on a widespread scale. So, now is the time to ask vendors how they will be providing quantum-resistant protection.
Two significant false alarms of a quantum breakthrough sent jitters through the security community last year. Though these were effectively assessed, they serve to keep us alert to how damaging a real breakthrough could be on our digital infrastructure if we do not get ahead and prepare now.
HP understands the quantum threat. Our strategy is to prioritise quantum resistance in hardware foundations and securely migrate from there. Last year, we introduced the world’s first business PCs to protect firmware integrity against quantum computer attacks[2]. Today, we announced the world’s first printers to protect firmware integrity against quantum computer attacks[3]. These security innovations show our commitment to anticipating threats and protecting customers into the future.
References
[1] Anticipating the Quantum Threat to Cryptography | HP Wolf Security, Feb 2024
[2] HP Launches World’s First Business PCs to Protect Firmware Against Quantum Computer Hacks | HP® Official Site, 7 March 2024
[3] HP Launches World’s First Printers to Protect Against Quantum Computer Attacks | HP® Official Site, 18 March 2025
[4] Fifth PQC Standardization Conference | CSRC, May 2024
[5] Yilei Chen. Quantum Algorithms for Lattice Problems, April 2024
[6] Quantum Threat Timeline 2025: Executive Perspectives on Barriers to Action – Global Risk Institute, February 2025
[7] Global Risk Institute Quantum Threat Timeline 2024 Report, December 2024
[8] BSI – Bundesamt für Sicherheit in der Informationstechnik. Status of quantum computer development. Entwicklungsstand Quantencomputer, August 2024
[9] Google Quantum AI and Collaborators. Quantum error correction below the surface code threshold | Nature, December 2024
[10] M.P. da Silva et al “Demonstration of logical qubits and repeated error correction with better-than-physical error rates”, 2404.02280, November 2024
[11] Microsoft announces the best performing logical qubits on record and will provide priority access to reliable quantum hardware in Azure Quantum – The Official Microsoft Blog, September 2024
[12] D. Bluvstein et al. Logical quantum processor based on reconfigurable atom arrays. Nature 626 (2024) Logical quantum processor based on reconfigurable atom arrays, February 2024
[13] M. H. Abobeih, Y. Wang, J. Randall, S. J. H. Loenen, C. E.Bradley, M. Markham, D. J. Twitchen, B. M. Terhal, and T. H.Taminiau. Fault-tolerant operation of a logical qubit in a diamond quantum processor. Nature, 606(7916):884–889, May 2022 Fault-tolerant operation of a logical qubit in a diamond quantum processor – PMC,
[14] Meet Willow, our state-of-the-art quantum chip, December 2024
[15] IBM Expands Quantum Data Center in Poughkeepsie, New York to Advance Algorithm Discovery Globally – Sep 26, 2024
[16] Technology | IBM Quantum Computing,
[17] Quantinuum upgrades H2 quantum computer from 32 to 56 qubits – DCD
[18] D. Bluvstein, H. Levine, G. Semeghini, T. T. Wang, S. Ebadi, M. Kalinowski, A. Keesling, N. Maskara, H. Pichler, M. Greiner, V. Vuletić, M. D. Lukin. “A quantum processor based on coherent transport of entangled atom arrays.” Nature 604, 451 (2022).
[19] Hannah J. Manetsch, Gyohei Nomura, Elie Bataille, Kon H. Leung, Xudong Lv, Manuel Endres. [2403.12021] A tweezer array with 6100 highly coherent atomic qubits, December 2024
[20] Quantum computing startup QuEra closes $230 million funding round | Reuters
[21] Microsoft’s Majorana 1 chip carves new path for quantum computing – Source
[22] Oxford University photonics teleportation. A ‘Teleportation’ Breakthrough for Quantum Computing Is Here | WIRED
[23] D Main et al, “Distributed quantum computing across an optical network link”. https://www.nature.com/articles/s41586-024-08404-x, February 2025
[24] Ion-Ion Entanglement
[25] Including IBM (IBM Qauntum Platform), Microsoft (Azure Quantum documentation, QDK & Q# programming language – Azure Quantum | Microsoft Learn) and Amazon (Cloud Quantum Computing Service – Amazon Braket – AWS)
[26] Shtetl-Optimized » Blog Archive » Quantum Computing: Between Hope and Hype, September 2024
[27] Apache Log4j Vulnerability Guidance | CISA
[28] bidenwhitehouse.archives.gov/wp-content/uploads/2024/07/REF_PQC-Report_FINAL_Send.pdf, July 2024
[29] National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems | The White House, (NSM-10), May 2022.
[30] NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems > National Security Agency/Central Security Service > Article, September 2022
[31] Quantum-Readiness: Migration to Post-Quantum Cryptography | CISA, August 2023
[32] Readout of White House Roundtable on Protecting Our Nation’s Data and Networks from Future Cybersecurity Threats | OMB | The White House, February 2024
[33] Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity | The White House, January 2025
[34] IR 8547, Transition to Post-Quantum Cryptography Standards | CSRC, November 2024
[35] Using an algorithm that is declared ‘deprecated’ by NIST means data owners have security risk and must examine that risk and decide to continue using it.
[36] Guidelines for cryptography | Cyber.gov.au, December 2024
[37] Recommendation on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography | Shaping Europe’s digital future, April 2024
[38] BSI – Press – BSI and partners from 17 other EU member states demand transition to Post-Quantum Cryptography, November 2024
[39] Post-Quantum Cryptography FIPS Approved | CSRC, August 2024
[40] A. Huelsing, D. Butin, S. Gazdag, J. Rijneveld and A. Mohaisen, “RFC 8391: XMSS: eXtended Merkle Signature Scheme,” May 2018, https://datatracker.ietf.org/doc/html/rfc8391. D. McGrew, M. Curcio and S. Fluhrer, “RFC 8554: Leighton-Micali Hash-Based Signatures,” IETF, April 2019, https://datatracker.ietf.org/doc/html/rfc8554. D. A. Cooper, D. C. Apon, Q. H. Dang, M. S. Davidson, M. J. Dworkin and C. A. Miller, “NIST Special Publication 800-208: Recommendation for Stateful Hash-Based Signature Schemes,” October 2020, https://doi.org/10.6028/NIST.SP.800-208.
[41] Migration to Post-Quantum Cryptography | NCCoE
[42] Designing PC Firmware Protection for the Quantum Era | HP Wolf Security, July 2024




