What Would Have to Hold for the New DCP Result to Reach ML-KEM
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

What Would Have to Hold for the New DCP Result to Reach ML-KEM

A preliminary paper reaches the mathematics under lattice-based post-quantum cryptography

The Cryptology ePrint Archive received Paper 2026/1591 on August 3, 2026 and posted it three days later. In it, Daniel R. Simon of the Amazon Web Services Cryptography Group presents a polynomial-time quantum algorithm for the Dihedral Coset Problem, which has resisted a polynomial-time solution for more than two decades. Combined with Oded Regev's reduction of lattice problems to that problem, the abstract claims polynomial-time quantum algorithms for two distinct targets: the Shortest Vector Problem at a square-root-of-n polylogarithmic approximation factor, and Learning With Errors instances in a parameter regime the abstract states as alpha equal to square-root-of-n polylog(n).

What the paper does not claim

It analyzes no standardized scheme, offers no key-recovery attack, and gives no qubit, gate or error-correction estimate. The claim is complexity-theoretic and unreviewed; the author records discussions in progress with Daniele Micciancio, Vinod Vaikuntanathan and Thomas Vidick. Nothing standardized broke in August 2026, and no honest reading of the abstract says otherwise.

Why it still lands on the migration desk

Four conditions stand between this abstract and ML-KEM, and none has been met. But certification calendars were set on the cryptographic judgment of 2024 and do not pause for a preprint. What lets an organization respond to a result like this is crypto-agility resting on a current cryptographic inventory: knowing which systems use which algorithms, and how long a substitution actually takes. That capability is built before the verdict arrives, not after.

Read More
The Post-Quantum Web Arrived as a Platform Setting
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

The Post-Quantum Web Arrived as a Platform Setting

Nearly half, one default

A new longitudinal study tested more than two billion TLS handshakes across one million domains from 11 global vantage points. By March 2026, 49.22 percent of its stable panel negotiated a hybrid post-quantum key exchange by default. Every one of those default negotiations selected the same construction, X25519MLKEM768. The web appears to be moving quickly, but the route is narrower than the policy calendars suggest.

The platforms moved first

The paper attributes 93.92 percent of observed post-quantum TLS deployment to configurations likely managed by infrastructure providers. Cloudflare and Fastly alone account for nearly 70 percent. Owner-managed services, including many government domains, remain mostly classical. This changes how migration progress should be read: a high aggregate percentage may describe one upstream platform decision repeated across thousands of customers, while slower institutions still face their own software, procurement and legacy-system work.

A safer handshake can keep old baggage

The hybrid exchange added a predictable number of bytes but no meaningful median latency in the measured public-web setting. At the same time, provider-managed post-quantum domains often retained older protocol versions and deprecated cipher support. The result connects engineering, policy and market power. Cryptographic infrastructure concentration can accelerate protection at remarkable speed, yet it can also obscure who made the change, which services inherited it and how much of the harder migration remains unfinished.

Read More
HAWK Left the Standards Track Before NIST Spoke
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

HAWK Left the Standards Track Before NIST Spoke

A candidate disappeared between meetings

HAWK began the week as a live candidate in the third round of NIST’s Additional Digital Signatures process. It ended the week withdrawn by its own developers after an AI-assisted cryptanalysis project identified a structural weakness in the scheme. NIST later acknowledged the exit and updated its Round 3 record, without announcing a rule for assessing model-generated mathematical work or issuing an independent technical judgment on the finding. The outcome arrived through researchers, expert checking and voluntary withdrawal.

The process worked without a written rule

The disclosed technique concerns HAWK and its particular lattice structure. It does not establish a transfer to NIST’s finalized FIPS 203, 204 and 205 standards. The episode still changes standards governance. It shows machine-assisted cryptanalysis entering a live selection process, where a research result can alter vendor roadmaps and comparative engineering choices before an agency publishes its own reasoning.

Crypto-agility has a nearer deadline

HAWK also gives crypto-agility a practical meaning. An algorithm may leave a standards track during the life of a contract because analysis advances faster than certification, procurement and product refresh. Institutions need separate technical, procedural and commercial records: what was affected, how the finding was checked, and which dependencies must change. A compact public disclosure receipt would make the next case easier to govern. The central control is public reason-giving: a precise claim, reproducible artifacts, a response from the scheme’s developers and a dated status note once disclosure risks permit.

Read More
Post-Quantum Security Has to Survive the Radio
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Post-Quantum Security Has to Survive the Radio

The handshake has a physical footprint

A remote sensor can carry strong cryptography and still fail before useful data moves. A new University of Colorado Boulder preprint models that problem on narrow radio links, where post-quantum certificates, signatures and keys arrive as long packet trains. The authors estimate bandwidth, memory, compute time and battery draw for certificate-based authentication on an NB-IoT connection. Under their stated assumptions, a security Category 1 ML-DSA-44 and ML-KEM-512 exchange produces 334 real-world packets and consumes 10,688 millijoules for transmission and reception. The proposed shared-secret route with ephemeral ML-KEM reduces those figures to 112 packets and 3,584 millijoules.

Loss changes the result

The satellite case makes packet count more than an efficiency metric. With 10 percent independent packet loss, the paper models a 0.8 percent single-attempt success rate for a 46-packet certificate-based exchange and 23 percent for a 14-packet shared-secret exchange. Those are first-order calculations, not field measurements, and the authors spell out assumptions about packet size, throughput, retransmission and device hardware. Even so, the comparison exposes a practical post-quantum authentication problem: a secure algorithm may still miss the contact window in which the device can use it.

Key management moves to the center

The proposed design uses an existing 5G or 6G shared-secret ecosystem, a Kerberos-style key distribution center and a DTLS pre-shared-key handshake with ephemeral ML-KEM. It preserves a post-quantum key-establishment step while avoiding digital-signature certificates at the endpoint. That can ease the radio and battery load, while placing more weight on enrollment, secret storage, lifecycle controls and the trusted key-distribution service. Constrained-network PQC therefore reaches beyond algorithm selection. It changes who holds trust, which infrastructure must remain available and whether a medical sensor, asset tracker or satellite terminal can authenticate reliably at all.

Read More
A Public Quantum Claim Built on a Private Attack Circuit
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

A Public Quantum Claim Built on a Private Attack Circuit

A claim with a missing circuit

Google Quantum AI researchers published lower resource estimates for using Shor’s algorithm against ECDLP-256, a cryptographic problem that protects many cryptocurrency systems. Their March 30 preprint describes two compiled circuits: one below 1,200 logical qubits and 90 million Toffoli gates, another below 1,450 logical qubits and 70 million Toffoli gates. Under stated assumptions, the authors estimate execution in minutes on fewer than 500,000 physical superconducting qubits. They did not publish the underlying attack circuits. That makes this a distinctive case of quantum vulnerability disclosure: the public receives a serious technical claim and a migration warning while a potentially useful attack roadmap stays private.

Zero knowledge changes the bargain

The proof makes a narrower statement than the headline resource estimate. It attests that the authors possess size-bounded reversible circuits that correctly compute secp256k1 point addition across 9,024 pseudorandom inputs derived from each circuit’s hash. Additional reasoning connects that subroutine to the overall Shor resource estimate. Google’s March 31 account says the team engaged with the U.S. government before publication. Zero-knowledge verification can expose a bounded proposition to checking while preserving sensitive implementation detail. It does not validate every hardware assumption, predict the arrival of a cryptographically relevant machine or supply a universal “Q-Day.”

The revision carries its own warning

The April 15 revision acknowledges that Keegan Ryan of Trail of Bits found a software flaw that allowed an attack on the soundness of the earlier proof. Version 2 corrects the proof layer and credits the finding. That repair belongs at the center of the story: cryptographic attestation can narrow a disclosure problem, while its software and statement still require hostile review. The case links cryptography, scientific reproducibility, market confidence and public oversight without treating the current proof as wider than it is.

Read More
A Green Check Mark Can Hide a Classical Trust Decision
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

A Green Check Mark Can Hide a Classical Trust Decision

Two credentials can yield one old decision

A new preprint tests whether hybrid X.509 certificates produce genuinely hybrid authentication. Taesung Kim, Boheung Chung, Keonwoo Kim and Yousung Kang examined eight path-validation stacks, nine validation modes and six certificate schemes. Under a policy requiring hybrid authentication, nearly every tested stack that could parse a separable hybrid certificate accepted through the classical path without making the post-quantum credential decisive. A system can therefore show a successful result while the newer credential never carried the trust decision.

Revocation exposes the practical gap

The paper's lifecycle experiment makes the issue concrete. When a bound post-quantum credential was revoked while the classical certificate remained valid, default validation could still accept because the newer credential sat outside the decision's scope. This matters for certificate authorities, trust stores, hardware security modules and applications whose owners may renew or revoke credentials on different schedules. It also matters for autonomous agents that consume authentication responses at machine speed and preserve whatever meaning the verifier supplies.

Migration claims need a visible scope

NIST's ML-DSA standard establishes a post-quantum signature primitive. It does not decide how every relying party should interpret a hybrid certificate. The defensible unit of assurance is one verifier decision under one explicit policy. Quentir reads the paper as a move from counting deployed certificate objects to understanding which credential actually determined access, with direct consequences for migration warranties, audit trails and trusted digital services.

Read More
Bitcoin’s Quantum Upgrade Now Has a Patron
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Bitcoin’s Quantum Upgrade Now Has a Patron

A private fund enters a public protocol

Galaxy has committed up to $5 million to Bitcoin post-quantum research and development. Its July 21 initiative names developer grants, a research program and an advisory council. Grants are to be evaluated individually and paid against milestones, with priorities that include transaction proposals, post-quantum signatures, wallet and custodian migration tools, and formal security audits. The announcement gives a neglected maintenance problem money, deadlines and institutional attention. It does not give Galaxy authority to change Bitcoin’s consensus rules.

The protocol record is still plural

BIP 360 remains a draft soft-fork proposal. It would create Pay-to-Merkle-Root, removing the quantum-vulnerable key-path spend from a new output type, while its authors explicitly limit the design to long-exposure attacks. Faster attacks during transaction confirmation may require post-quantum signatures and a different set of tradeoffs. NIST’s ML-DSA standard supplies a standardized post-quantum signature primitive, yet standardization alone does not settle Bitcoin integration, transaction weight, wallet support or consent across the network. The initiative’s first return may be better public disagreement before any code becomes difficult to reverse. Quentir reads the grant program as a new institutional layer in decentralized infrastructure: useful capital, real agenda-setting power and no substitute for open technical review.

Read More
Which Part of a Network Is Actually Quantum-Resilient?
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Which Part of a Network Is Actually Quantum-Resilient?

The label covers several systems

AT&T and Palo Alto Networks announced a Quantum-Resilient SASE Fabric on July 16, 2026. Their account reaches across management traffic, data tunnels, telemetry, branch hardware, multiple underlays and automated policy distribution. That breadth is useful because a network does not become quantum-safe in one place. It also makes the phrase quantum-resilient network harder to interpret. A product name can describe an architecture while leaving deployment state, algorithm choice, fallback behavior and covered traffic to the customer’s configuration.

The cited protocols have defined jobs

The announcement points to IETF RFC 9370, RFC 9242 and RFC 8784. These standards describe mechanisms within IKEv2: multiple key exchanges, an intermediate exchange before IKE authentication that can carry larger payloads, and the mixing of preshared keys for post-quantum security. The intermediate exchange permits IKE-level fragmentation, which can avoid problematic IP fragmentation. These mechanisms support important migration designs. They do not, by themselves, show which algorithms were negotiated on a particular circuit or prove that every control, data and telemetry path received the same protection. TLS 1.3 is also a protocol framework; calling traffic TLS 1.3 does not identify a post-quantum key exchange.

Operations decide what the label means

The useful unit is a live path from endpoint to endpoint, including the branch device, tunnel negotiation, classical fallback, management plane, software version and supplier handoff. Post-quantum network migration therefore connects engineering, procurement, regulated outsourcing and public trust. Hospitals, payment systems and public services depend on networks whose security claims must survive failover, upgrades and mixed infrastructure. The strongest reading of the launch is architectural: major connectivity vendors are preparing PQC controls for ordinary network operations. The unresolved part is observational: what each deployed path negotiates under normal and degraded conditions.

Read More
FINMA Writes Mid-2027 Into the Quantum-Safe Finance Calendar
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

FINMA Writes Mid-2027 Into the Quantum-Safe Finance Calendar

A supervisory date appears

FINMA Guidance 05/2026 recommends that supervised Swiss financial institutions draw up a post-quantum cryptography roadmap by mid-2027. The guidance follows a survey of 60 banks, insurers, asset managers and financial-market infrastructures conducted between November 2025 and January 2026. Only 8 percent reported having a specific roadmap, while 72 percent said they had not planned or implemented measures. The date gives quantum-safe finance a concrete planning horizon without pretending that a cryptographically relevant quantum computer already exists.

The roadmap reaches beyond cryptography teams

FINMA connects the transition to board-approved strategy, institution-specific risk analysis and a continuously updated cryptographic inventory. That inventory reaches encryption in transit and at rest, digital signatures, key management and authentication across internal systems, outsourced functions and services. Long-lived data receives priority because information stolen today may remain sensitive when stronger quantum machines arrive. Hybrid cryptography may help during migration, although the regulator also notes its added implementation complexity.

Outsourcing terms enter the calendar

The guidance makes crypto-agility in outsourcing a commercial issue. FINMA recommends it as a requirement for new software and data arrangements and asks institutions to incorporate it into existing requirements at the earliest opportunity. Responsibility for an outsourced function remains with the supervised institution. The mid-2027 date therefore measures more than the existence of a document: it exposes whether architecture, supplier dependencies and accountability have entered one credible timetable.

Read More
Korea turns post-quantum migration into a finance-sector rehearsal
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Korea turns post-quantum migration into a finance-sector rehearsal

Why the Korean pilot matters

South Korea’s Ministry of Science and ICT and KISA have moved a 2026 finance-sector PQC pilot into execution with named delivery roles, a defined end date and a consortium tied to Hana Card. That makes the Korean file useful beyond Korea: it shows how post-quantum migration starts to look once a government treats the transition as an operational conversion project, with the standards discussion already in the background.

The practical signal

The important detail is the hybrid conversion model. The project is described as a step-by-step transition intended to avoid service interruption, with key-management, cryptographic modules, diagnostics and financial authentication all in scope. For banks, payment firms, fintech platforms and long-lived data holders, this is a rehearsal for the contract questions now arriving behind the technical work: who owns the migration duty, what counts as adequate crypto-agility, and how a supplier proves that a service can move without breaking customer operations.

Quentir’s read

This post connects the Korean finance pilot with recent U.S. federal PQC deadlines, NSF Project Triad and the wider move from quantum programs to sector-level execution. The core governance object is crypto-agility in finance: inventories, key lifecycles, authentication flows and supplier warranties that can survive algorithm change.

Read More
What Counts as Quantum-Safe After the Department of War Strategy?
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

What Counts as Quantum-Safe After the Department of War Strategy?

The new line around quantum-safe

The Department of War post-quantum cryptography strategy, reported on 1 July 2026, does more than set a deadline. It narrows what can count as quantum-safe security for defense networks: native asymmetric PQC and CNSA 2.0 paths are in; QKD, quantum networking, non-local randomness, proxy-only overlays, simple key-size increases and symmetric pre-shared-key workarounds are out.

What Q-Day means

Q-Day is the point at which a cryptographically relevant quantum computer can break widely used public-key cryptography. The practical risk starts earlier, because long-lived data, signatures, certificates and authentication records can be harvested now and attacked later. That is why the strategy treats Q-Day as a migration horizon rather than a calendar prediction.

Why the exclusions matter

That exclusion list changes the procurement conversation. A vendor cannot rely on a quantum-labeled channel, a gateway wrapper or a future network claim if the protected system still depends on legacy cryptography underneath. The useful question becomes simpler and harder: which primitive protects which data flow, which system owner accepts the migration duty, and which deadline governs retirement of the old path?

Quentir’s reading

The strategy also travels beyond defense. It specifies NIST, IETF and NATO cooperation on crypto-agility, while OMB implementation guidance pushes agencies toward inventories, provider coordination, automation where feasible and 120-day migration planning. For contractors and cloud suppliers, PQC migration governance is becoming less about announcing a quantum program and more about proving that old algorithms can be found, replaced and kept out.

Read More
ML-KEM Has Moved Into the Hardware Test Lab
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

ML-KEM Has Moved Into the Hardware Test Lab

The standard is now a device

Post-quantum cryptography has crossed an awkward threshold. ML-KEM is no longer only a standards document, a migration milestone or a line item in a crypto-agility plan. Once it lands in hardware, firmware and embedded libraries, its security also depends on power traces, electromagnetic leakage and the exact sequence of operations during decapsulation. A new 30 June 2026 arXiv paper on Fujisaki-Okamoto verification in ML-KEM makes that point concrete: the verification step can become a visible leakage surface during physical side-channel analysis.

Why procurement changes

The useful commercial lesson is narrow and important. Buyers should not treat ML-KEM implementation security as a checkbox created by adopting a NIST algorithm name. They need to know whether their chips, HSMs, gateways, telecom equipment, IoT modules and cloud cryptographic services have been tested against the way the algorithm runs in the real device. That moves post-quantum transition work closer to product assurance, certification, warranty drafting and supplier disclosure.

Quentir’s reading

This does not weaken the case for migration. It sharpens it. The next mature post-quantum program will connect algorithm selection with side-channel assurance, validated components, patch rights, test reports and contractual responsibility when a “quantum-safe” implementation leaks through the hardware layer. That is where policy deadlines become operational.

Read More
Quantum Deadlines Are Now a Supply-Chain Question
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Quantum Deadlines Are Now a Supply-Chain Question

Two clocks now converge

The United States has joined two clocks that many organizations still treat separately: the race toward useful quantum computing and the migration away from vulnerable public-key cryptography. The June 2026 federal quantum actions point toward a scientifically useful fault-tolerant machine by 2028, while the same policy cycle pushes federal high-value assets and high-impact systems toward NIST-approved post-quantum cryptography by the 2030/2031 horizon. That combination changes the commercial question. It is no longer enough to ask when a system will be upgraded. Procurement teams, platform owners, telecom operators and cloud customers need to know which libraries, chips, certificates, export-control rules and supplier warranties sit underneath the upgrade path.

What changes for suppliers

The useful signal is the movement from policy language to post-quantum supply-chain governance. Validated cryptographic libraries, DOE’s Quantum Genesis push, BIS advanced-computing controls, UK ProQure, Canada’s National Quantum Strategy and China’s photonic quantum infrastructure all point in the same direction: cryptographic migration now depends on physical and jurisdictional infrastructure. For Quentir readers, the practical object is crypto-agility procurement: contracts, supplier attestations and product roadmaps that can absorb changing NIST standards without pretending that a single software patch solves the problem. The result is a cleaner question for every serious buyer: can each critical supplier show the path from today’s encryption stack to the validated post-quantum stack it will depend on tomorrow?

Read More
Federal PQC Is Becoming a Contractor Evidence Test
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Federal PQC Is Becoming a Contractor Evidence Test

Federal post-quantum policy is no longer only a standards story. For boards, general counsel, procurement teams and security leaders, the June 2026 federal signal turns PQC migration into a dated evidence problem: which systems still depend on RSA or elliptic-curve cryptography, which suppliers control those systems, and what proof shows that rotation can happen before government and contractor expectations harden.

This Quentir brief reads the PQC timetable as a contractor evidence test. It explains why a useful board packet should include a cryptographic inventory, named migration owners, supplier flow-down questions, a crypto-bill-of-materials posture, tested rotation paths, vulnerability-disclosure expectations and an exception register. It also separates direct federal obligations from broader procurement influence, so private organizations can prepare without overstating legal exposure. The practical point is simple: a supplier saying it “supports PQC” is not the same as an auditable record showing which connection, certificate, library, credential or outsourced service was tested. Use this brief to frame the first board discussion, supplier questionnaire or procurement evidence request.

Read More