Future quantum computers could break RSA and elliptic-curve cryptography. NIST has standardised new algorithms that resist these attacks, and .NET 10 makes them available in System.Security.Cryptography.
The algorithms
- ML-KEM: key exchange (encapsulation), to establish a shared secret.
- ML-DSA: lattice-based digital signature.
- SLH-DSA: hash-based digital signature, very conservative.
Checking support
The implementations rely on the operating system (Windows cryptographic libraries or OpenSSL on Linux), so before using them you check whether the platform supports them.
using System.Security.Cryptography;
if (MLKem.IsSupported)
{
using MLKem key = MLKem.GenerateKey(MLKemAlgorithm.MLKem768);
Console.WriteLine($"Key generated: {key.Algorithm.Name}");
}
else
{
Console.WriteLine("ML-KEM is not available on this platform.");
}
"Harvest now, decrypt later"
Why worry today? Because an attacker can record encrypted traffic today and decrypt it years from now. For data that must stay confidential for a long time, such as health data, contracts or trade secrets, the transition must be planned now.
A gradual transition
The recommended path is the hybrid approach, which combines a classical algorithm and a post-quantum one: security holds even if one of the two turned out to be weak. The first practical step is an inventory of where your application uses cryptography, so you know what will have to change.
Comments (0)
No comments yet.