With projections that quantum computers could be commercialized in as little as 5 to 10 years, quantum security is drawing attention. Corporations are accelerating the development and deployment of related security solutions to prepare for the so-called "Q-day," when quantum computers—whose theoretical computing speed is 10 million times faster than supercomputers—could neutralize existing cryptographic systems.
◇ Existing public-key cryptosystems could be broken in a short time
According to the industry on the 22nd, as big tech corporations have recently stepped up quantum computer development, the view that commercialization will arrive sooner than expected is gaining traction. Peter DeSantis, Amazon's chief AI officer (senior vice president), said this month that "a small commercial quantum computer will appear within 5 to 7 years." Google said commercialization of quantum computers is possible within five years, and Microsoft (MS) and IBM projected they could develop commercially usable quantum computers by 2029.
Experts warn that once quantum computers reach a stage of practical use, the existing cryptographic systems used in finance, telecommunications, and the public sector could collapse. Widely used public-key cryptosystems (RSA and ECC) are based on the integer factorization problem. Using the principle that factorization becomes harder as numbers grow, it would take from thousands of years to more than 1 million years for conventional computers to decrypt. Quantum computers, using "qubits (Qubit, the basic unit of quantum information)," compute 10 million times faster than supercomputers and can dismantle public-key cryptosystems in a short time.
Hackers are planning "harvest now, decrypt later (HNDL)," in which they steal encrypted data that current technology cannot decrypt and store it for future decryption once quantum computers arrive, and experts stress the need to prepare for the coming "Q-day" threat in advance. Until now, even if data was stolen by hacking, it remained safe because it could not be decrypted, but once quantum computers are commercialized, sensitive information such as military secrets and semiconductor technologies could be exposed, leading to uncontrollable damage.
A representative of Palo Alto Networks, the world's largest cybersecurity corporation, said, "Data with more than 10 years of retention value, including various state secrets, medical records, and financial contract information, is exposed to the 'harvest now, decrypt later' threat even at this very moment," adding, "If you respond after Q-day has passed, it will be too late, so we must start preparing right now."
◇ Governments and corporations move to prepare for "Q-day"… France to tighten certification starting next year
As the "harvest now, decrypt later" threat grows with the advent of quantum computers, major governments and corporations have begun building defenses. The French government has moved to phase out existing cryptographic systems. Last week, the National Cybersecurity Agency of France (ANSSI) said it will stop certifying security products that do not apply so-called "quantum-safe" technologies that can withstand quantum computer–based attacks, such as post-quantum cryptography (PQC), starting next year. Corporations and government agencies must adopt only quantum-safe products by 2030. The United States, the United Kingdom, and Korea also said they will transition national cryptographic systems to PQC by 2035.
Post-quantum cryptography (PQC) is next-generation encryption that protects data using mathematical algorithms that are difficult to solve even with quantum computers. According to market research firm Technavio, driven by efforts from governments and corporations to proactively address potential security threats posed by quantum computers, the global PQC market is expected to grow at an average annual rate of 43.4% to reach $3.42 billion (about 4.7 trillion won) by 2030.
Global corporations are also leading the PQC transition. Palo Alto Networks rolled out its "Quantum Safe Security" solution early this year to help corporations transition servers, apps, and certificates to PQC, and Fortinet has embedded state-of-the-art PQC technologies across its FortiOS firewall operating system. Cloudflare, which handles about one-fifth of global internet traffic, is deploying PQC at scale across internet infrastructure and has set a goal of transitioning all product lines to quantum-safe by 2029. French defense corporation Thales is integrating PQC capabilities into its key management systems for defense encryption keys (values used for data encryption and decryption).
In Korea, Genians is developing foundational next-generation quantum security technologies. The goal is to create a composite security architecture by incorporating PQC into its existing zero trust network access (ZTNA) solution and embedding a high-performance key management system (KMS) that securely controls the entire lifecycle of cryptographic keys. A company representative described it as "next-generation zero-trust security that protects corporations' network perimeters from the ultra-fast computational hacking threats of quantum computers."
Raonsecure is seeking to lead the finance sector's quantum security market with "KeySharpCrypto," a software-based cryptographic modularization solution that makes PQC easy to apply. Last month it signed a contract to supply a PQC solution to KDB Life Insurance, and it recently completed a proof-of-concept applying PQC-based segment encryption security to Korea's first open medical data platform at Severance Hospital. AXGATE has put forward its "X-Quantum" platform—combining PQC with a quantum random number generator (QRNG), a technology that leverages quantum mechanics to create unpredictable random numbers—as its next growth engine.
AXGATE CEO Joo Gap-soo said at a press briefing last week that "once a single weapons system is completed in the defense sector, it is operated for 20 to 40 years, and if information stolen now is later decrypted by quantum computers, core technologies could be exposed in their entirety," emphasizing the importance of quantum security.