B. QUANTUM COMPUTING AND NETWORKS
Quantum computing represents both the most serious threat ever faced by the security of digital communications and, paradoxically, an opportunity to develop new forms of inherently secure communication. Understanding this issue has become essential for network professionals, as the migration of infrastructure to quantum-resistant solutions is a project that must begin now, well before quantum machines capable of threatening current algorithms even exist.
1. quantum threat to current cryptography
Quantum computers exploit phenomena from quantum mechanics – superposition (a qubit can represent both 0 and 1 simultaneously) and entanglement (two qubits can be correlated regardless of the distance between them) – to perform certain types of calculations exponentially faster than the best classical computers. It is not simply a question of speed: certain mathematical problems that would take billions of years to solve on current computers could be solved in a matter of hours by a sufficiently powerful quantum computer.
Shor's algorithm, proposed by the mathematician Peter Shor in 1994, lies at the heart of the threat. It theoretically enables a quantum computer to factor large integers in polynomial time, that is, to find the prime factors of a number with several hundred digits within a reasonable amount of time.
However, it is precisely this factorisation problem that underpins the security of the RSA algorithm, which is used to encrypt almost all internet communications:
· HTTPS connections
· VPN IPsec
· SSH
· digital certificate signatures
· TLS protocols.
A quantum computer capable of running Shor’s algorithm on a large scale would render these safeguards obsolete overnight.
Grover’s algorithm, another fundamental quantum algorithm, halves the effective security of symmetric encryption algorithms. In practical terms, AES-128 would offer security equivalent to just 64 bits against a quantum attacker, which is considered insufficient. The solution is simple: double the size of the symmetric keys. AES-256 therefore remains secure even against quantum computers, provided it is implemented correctly.
The state of the art in 2025 shows that existing quantum computers are still a long way from posing a threat to current cryptosystems. The machines currently available are NISQ (Noisy Intermediate-Scale Quantum) systems: they contain between a few dozen and a few hundred physical qubits, but these qubits are highly sensitive to external disturbances (quantum noise) and do not yet incorporate effective quantum error correction. Google’s Willow processor (105 qubits, 2024) has demonstrated quantum supremacy on specific computational tasks, but these tasks have no direct cryptographic application. Experts estimate that a quantum computer capable of breaking RSA-2048 would require around 4,000 fault-tolerant logical qubits, which corresponds to millions of physical qubits with error correction, with an estimated timeframe of between 2030 and 2040.
⚠ The ‘Harvest Now, Decrypt Later’ strategy
Even though quantum computers capable of breaking RSA do not yet exist, malicious actors (nation-states, sophisticated criminal groups) are already collecting encrypted communications in transit, with the intention of decrypting them at a later date when quantum computers become available. This ‘Harvest Now, Decrypt Later’ strategy justifies an urgent migration to post-quantum cryptography for any data with a sensitivity period exceeding 5–10 years: trade secrets, medical data, diplomatic communications, and intellectual property.
2. Post-quantum cryptography (PQC)
Post-quantum cryptography (PQC) refers to the set of cryptographic algorithms designed to withstand attacks from a quantum computer, whilst still running on ordinary classical computers. Unlike quantum cryptography (which requires a special physical infrastructure), PQC is a set of software algorithms that can be deployed on existing infrastructure—servers, routers, browsers and smartphones—simply by means of a software update.
These algorithms are based on mathematical problems that differ from those threatened by Shor’s algorithm. Rather than integer factorisation or discrete logarithms, they rely on problems related to Euclidean lattices (lattice-based cryptography), error-correcting codes, hash functions or multivariate systems. These problems are considered difficult even for quantum computers, at least given our current understanding of quantum mechanics.
Between 2016 and 2024, the US National Institute of Standards and Technology (NIST) led a lengthy process of international standardisation for PQC algorithms, involving academic and industrial cryptographers from around the world. In August 2024, NIST published the first official post-quantum cryptography standards. The FIPS 203 standard (ML-KEM, derived from the CRYSTALS-Kyber algorithm) provides a key encapsulation mechanism (KEM) based on Euclidean lattices, which will replace RSA and ECDH for key exchange in TLS. The FIPS 204 standard (ML-DSA, derived from CRYSTALS-Dilithium) provides a digital signature scheme to replace RSA and ECDSA in certificates. The FIPS 205 standard (SLH-DSA, derived from SPHINCS+) provides a signature alternative based on hash functions, the security of which relies on more conservative mathematical assumptions.
The transition to PQC is a long-term project that cannot be rushed. Organisations must first carry out a comprehensive cryptographic audit: identifying all systems using vulnerable algorithms (RSA, ECDSA, ECDH, DH), the data they protect, and the duration for which that data remains sensitive. Next comes the deployment of hybrid algorithms, which combine the existing classical algorithm with the new PQC algorithm in parallel: if one is compromised, the other still provides protection. This hybrid approach allows for a gradual migration without breaking compatibility with systems that do not yet support PQC. Finally, the phased deprecation of classical algorithms will take place between 2026 and 2030 for critical infrastructure.
ℹ Status of PQC deployment in 2025
The Chrome and Firefox browsers are testing hybrid TLS algorithms (X25519Kyber768, combining Curve25519 and Kyber). Cloudflare, Google and Amazon CloudFront are experimentally supporting PQC in TLS 1.3. The French ANSSI has published its PQC migration recommendations for 2024, prescribing the adoption of NIST standards. The US NSA is mandating PQC migration for defence systems from 2025 onwards.
3. Quantum Key Distribution (QKD)
QKD (Quantum Key Distribution) is a fundamentally different approach to PQC. Whilst PQC is a set of software algorithms whose security relies on mathematical assumptions (however robust they may be), QKD exploits the physical laws of quantum mechanics to guarantee the security of key exchanges in a manner proven by physics: any attempt to intercept a QKD key inevitably alters the transmitted photons, making the interception detectable. In other words, QKD does not rely on the difficulty of solving a mathematical problem, but on the physical impossibility of measuring a quantum state without disturbing it.
The BB84 protocol, devised by Charles Bennett and Gilles Brassard in 1984, is the founding QKD protocol. It encodes key bits onto the polarisation of single photons sent through an optical fibre. The transmitter and receiver publicly compare their measurement bases (without revealing the values) to derive a shared key. If an eavesdropper (Eve) has intercepted the photons to measure them, their interference introduces detectable errors in the key, revealing the compromise. The E91 protocol (Arthur Ekert, 1991), on the other hand, uses pairs of entangled photons for even more robust security in theory.
QKD deployments around the world demonstrate the interest that governments have in this technology. China has deployed the world’s most extensive QKD network, linking Beijing to Shanghai over a distance of 2,000 km, and has been operating the Micius quantum satellite since 2016, which has demonstrated QKD over a distance of more than 7,000 km via space. The European Union is funding the EuroQCI (European Quantum Communication Infrastructure) project to deploy a pan-European secure quantum communication network by 2027. In France, Orange, Thales and the CEA are leading pilot projects for metropolitan QKD networks.
However, QKD has significant limitations that currently make it a complementary solution to PQC rather than a universal replacement. The maximum distance over optical fibre without a quantum repeater is typically limited to around 100 kilometres, beyond which photon losses become prohibitive. Quantum repeaters, which are expected to overcome this limitation, are still at the research stage. The cost of QKD equipment (tens to hundreds of thousands of euros per node) and the need for dedicated infrastructure limit its deployment to the most sensitive government and financial communications.
4. Towards a quantum internet
Beyond point-to-point QKD, research is focusing on a far more ambitious concept: the quantum internet, a network capable of distributing quantum entanglement between remote nodes across the globe. Such a network would not only enable perfectly secure end-to-end communications, but also distributed quantum computing, allowing multiple quantum computers to collaborate on calculations that would be impossible for a single machine, and quantum metrology, with atomic clocks synchronised remotely with unrivalled precision. The components of a quantum internet present considerable scientific challenge. Quantum memories must store quantum states for sufficiently long periods to allow for the synchronisation of nodes. Quantum repeaters must amplify quantum signals without measuring them (which would destroy the quantum information), using swapping entanglement and entanglement purification techniques. Quantum frequency converters must adapt the wavelengths of photons to the optimal transmission windows of optical fibres. The first demonstrations of functional quantum repeaters took place in 2023–2024 at the laboratories of TU Delft in the Netherlands and Harvard in the United States, marking important milestones towards this long-term goal.
ℹ European Quantum Flagship
The European Union is funding the Quantum Flagship programme with €1 billion over the period 2018–2028, covering projects relating to quantum networks, quantum computers, quantum sensors and quantum simulation. The European Commission regards quantum networks as a strategic infrastructure for Europe’s digital sovereignty, on a par with undersea cables and Galileo satellites.