🚀 𝗖𝗿𝘆𝗽𝘁𝗼𝗴𝗿𝗮𝗽𝗵𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗤𝘂𝗮𝗻𝘁𝘂𝗺 𝗔𝗴𝗲: 𝗦𝘁𝗮𝗿𝘁𝗶𝗻𝗴 𝗡𝗼𝘄
written by Stefan Christoph
- 3 minutes read🚀 𝗖𝗿𝘆𝗽𝘁𝗼𝗴𝗿𝗮𝗽𝗵𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗤𝘂𝗮𝗻𝘁𝘂𝗺 𝗔𝗴𝗲: 𝗦𝘁𝗮𝗿𝘁𝗶𝗻𝗴 𝗡𝗼𝘄
Yesterday I had the pleasure to listen to and discuss with my colleagues Sviatoslav Redko and Viacheslav Romanov during their talk “Cryptography in the Quantum Age: Starting Now.” They guided us through the future of data security with insights on quantum-resistant cryptography.
🔍 What We Explored:
1️⃣ The impact of quantum computing on traditional encryption 2️⃣ Vulnerabilities in current cryptographic systems 3️⃣ Post-quantum solutions emerging in the industry 4️⃣ Latest NIST standards and important industry collaborations 5️⃣ Security strategies specifically designed for cloud users 6️⃣ Roadmap for migrating workloads to quantum-resistant cryptography
💡 A Familiar Challenge with New Urgency
This isn’t actually a completely new situation, and you don’t need to develop a deep understanding of quantum computing. In traditional computing, we’ve long lived in a world where computing power per dollar tends to increase over time — the cost-performance trend popularly associated with Moore’s Law (strictly, Gordon Moore’s observation about transistor density doubling at a steady cadence, not a guarantee about computation cost).
When you encrypt data today using methods considered “safe enough” against current attack capabilities, attack capabilities keep improving — so depending on the algorithm, the key size, and how long the data must stay confidential, a point may come when attackers can afford enough computing power (or benefit from enough cryptanalytic progress) to break that encryption. Depending on your requirements, periodic re-encryption of the data you still control may be necessary. Remember: once your encrypted data has been shared (intentionally or not), the holder of your data may eventually be able to decrypt it without your key — re-encrypting your copy does nothing for theirs. This is something we should always keep in mind, especially with encryption in transit.
⚠️ Why the Urgency Now?
While everything above remains true, quantum computation’s arrival is not a general increase in computing power like the Moore’s-Law-style trend — its leaps are algorithm-specific. For the math protecting today’s public-key encryption (factoring and discrete logarithms), Shor’s algorithm turns problems believed to require exponential classical effort into polynomial-time quantum work. For those schemes that’s a dramatic leap rather than a gradual increase, potentially rendering them obsolete once sufficiently capable quantum machines exist. (Symmetric ciphers and hashes are a different story: the known generic quantum speedup there is roughly quadratic, which larger key sizes absorb.)
✅ The Good News: Post-quantum cryptography standardization has already delivered: NIST finalized its first three standards in August 2024 — FIPS 203 (ML-KEM) for key encapsulation, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. AWS is heavily invested in this area and in adopting post-quantum cryptography across their services. [1]
🔐 Remember the Shared Responsibility: This isn’t solely AWS’s concern. As the shared responsibility model [2] reminds us, AWS secures the cloud infrastructure, but you must ensure your workloads are secure.
🔧 Time to Dive Deep
Now is an excellent time to explore this topic further. I recommend checking out the “Using Post-Quantum Cryptography on AWS” workshop [3] to better understand the concepts and gain hands-on experience.
💬 Is post-quantum cryptography top of mind for you? Is it on your backlog/roadmap?
References: [1] Post-Quantum Cryptography - https://aws.amazon.com/security/post-quantum-cryptography/ [2] Shared Responsibility model - https://aws.amazon.com/compliance/shared-responsibility-model/ [3] Workshop “Using Post-Quantum Cryptography on AWS” - https://catalog.workshops.aws/using-pq-crypto-on-aws/en-US
📝 Last updated: August 13, 2026 — Technical corrections from a quality audit