3.6 Cryptographic Solutions & PKI
3.6 Cryptographic Solutions & PKI
Cryptography protects information by applying mathematical techniques to confidentiality, integrity, authentication and related security requirements.
For CISSP, the important skill is not simply recognising algorithm names. You need to understand which cryptographic mechanism solves which problem, how keys are managed and how trust is established through systems such as Public Key Infrastructure.
Encrypt
Protect information against unauthorised disclosure.
CONFIDENTIALITYHash
Produce a fingerprint that can help detect modification.
INTEGRITYSign
Bind cryptographic evidence to the holder of a private key.
AUTHENTICATION & INTEGRITYThe Big Idea
Different cryptographic mechanisms solve different security problems.
Start with the security requirement.
Ask: Do I need confidentiality, integrity, authentication, key establishment or some combination of them?
Encryption vs Hashing vs Digital Signatures
| Mechanism | Main purpose | Uses a key? | Reversible? |
|---|---|---|---|
| Encryption | Confidentiality | Yes | Yes, with the appropriate key |
| Hashing | Integrity / fingerprinting | Normally no | Designed to be one-way |
| HMAC / MAC | Integrity and message authentication | Shared secret | Not an encryption mechanism |
| Digital Signature | Integrity, authentication and evidence supporting non-repudiation | Private / public key pair | Not used to recover the original message |
Crypto Shortcut
Encrypt = Confidentiality ยท Hash = Integrity ยท Sign = Identity + Integrity
๐ Symmetric Cryptography One shared secret key
Symmetric cryptography uses a shared secret key.
The communicating parties must both possess appropriate secret key material.
Strengths
Challenges
A 50 GB backup needs to be encrypted.
Symmetric encryption is well suited to the bulk encryption of the backup because it is efficient for large amounts of information.
Common Example - AES
The Advanced Encryption Standard - AES - is a widely used symmetric block cipher.
AES supports key sizes including:
Symmetric
Symmetric = Fast but Secret-Key Distribution Matters
๐งฑ Block & Stream Encryption Different ways of processing information
Processes information in fixed-size blocks.
AES is the classic CISSP example.
Generates a keystream that is combined with the data stream.
Appropriate nonce and key handling are critical.
Simply knowing that an algorithm uses AES does not tell you everything about how the encryption has been implemented.
Mode selection, initialization values, authentication and key management also matter.
Authenticated Encryption
Modern cryptographic designs commonly use authenticated encryption so confidentiality and integrity protection are provided together.
Instead of merely asking:
"Can an attacker read this?"
authenticated encryption also asks:
"Can an attacker alter this without detection?"
๐๏ธ Asymmetric Cryptography Public key + private key
Asymmetric cryptography uses a mathematically related key pair.
Designed to be distributed to others.
Must remain under the control of the key owner.
Confidentiality Use
Asymmetric Confidentiality
Public locks it ยท Private unlocks it
Typical Uses
For that reason, modern systems often combine asymmetric and symmetric cryptography rather than using public-key cryptography to encrypt every byte of a large data stream.
Symmetric vs Asymmetric
| Symmetric | Asymmetric | |
|---|---|---|
| Keys | Shared secret | Public/private pair |
| Performance | Fast | Relatively slower |
| Bulk encryption | Excellent | Usually not the primary approach |
| Digital signatures | No | Yes |
| Key distribution | Difficult if no secure mechanism exists | Public keys may be distributed publicly, but their authenticity must be established |
| Examples | AES | RSA and elliptic-curve techniques |
๐ค Hybrid Cryptography Combine asymmetric trust with symmetric performance
Modern secure communications commonly use both asymmetric and symmetric cryptography.
Your browser does not normally use public-key cryptography to encrypt every byte of a large website session.
Instead, public-key mechanisms help establish trust and session secrets, after which efficient symmetric cryptography protects the bulk communication.
Hybrid Cryptography
Asymmetric starts it ยท Symmetric carries it
๐ Elliptic Curve Cryptography - ECC Public-key cryptography using elliptic-curve mathematics
Elliptic Curve Cryptography is a family of asymmetric cryptographic techniques based on the mathematical properties of elliptic curves.
ECC can provide strong public-key cryptographic security using comparatively smaller key sizes than some older public-key approaches.
Common Uses
Elliptic Curve Digital Signature Algorithm.
Used for digital signatures.
Elliptic Curve Diffie-Hellman.
Used to establish shared secrets.
ECDH is associated with key agreement.
ECDSA is associated with digital signatures.
#๏ธโฃ Cryptographic Hashing Create a one-way fingerprint of information
A cryptographic hash function accepts data of varying size and produces a fixed-size output commonly called a hash or digest.
Important Properties
It should be computationally infeasible to reconstruct the original input from the digest.
The same input produces the same digest.
A small input change should significantly change the output.
It should be difficult to find different inputs producing the same digest.
Common Uses
There is no normal decryption operation that turns the digest back into the original message.
Original file:
Hash = ABC123
Downloaded file:
Hash = ABC123
Matching hashes provide evidence that the content has not changed.
An attacker who changes a file may also calculate a new hash.
Authentication requires an additional trustworthy mechanism.
๐ง Salts & Password Hashing Passwords should not normally be stored as plaintext
Password-verification systems commonly store derived password values rather than plaintext passwords.
A unique random salt is added when deriving the stored password representation.
Why Salt?
Imagine two users choose:
Password123!
Without unique salts, identical passwords can result in identical stored hashes.
With different salts, the resulting values differ.
Its purpose is primarily to make precomputed attacks less effective and prevent identical passwords from automatically producing the same stored representation.
Password Salt
๐ MAC & HMAC Integrity plus authentication using a shared secret
A Message Authentication Code - MAC - uses secret key material to provide integrity and message authentication.
HMAC is a widely used construction based on a cryptographic hash function and a secret key.
Provides
Both communicating parties possess the shared secret.
Either party could therefore potentially create a valid HMAC.
Hash vs HMAC
โ๏ธ Digital Signatures Private key signs ยท Public key verifies
Digital signatures use asymmetric cryptography to provide evidence relating a message to the holder of a private signing key.
Signing
Verification
Provides
Signing a document does not automatically hide its contents.
If confidentiality is also required, encryption must be applied appropriately.
Digital Signature
Private Signs ยท Public Verifies
Public-Key Encryption vs Digital Signature
| Confidentiality | Digital Signature | |
|---|---|---|
| Primary goal | Keep message secret | Integrity and signer authentication |
| Key used by sender | Recipient's PUBLIC key | Sender's PRIVATE key |
| Key used by receiver | Recipient's PRIVATE key | Sender's PUBLIC key |
Whose Key?
Secret for them = Their public key ยท Proof from me = My private key
๐ค Key Establishment & Agreement Create shared secrets over untrusted networks
Secure communication often requires two parties that have never previously shared a secret to establish symmetric session key material.
Diffie-Hellman
Diffie-Hellman techniques allow parties to derive a shared secret over a public channel without directly transmitting the resulting shared secret itself.
Classical Diffie-Hellman key agreement.
Diffie-Hellman using elliptic-curve mathematics.
Establishing a secret does not automatically prove who is on the other end.
Secure protocols therefore combine key establishment with authentication mechanisms.
Forward Secrecy
Ephemeral key-agreement mechanisms can provide forward secrecy.
The goal is that compromise of a long-term private key in the future does not automatically reveal previously established session keys.
Forward Secrecy
๐ TLS as a Cryptographic System A practical example of several crypto mechanisms working together
Transport Layer Security - TLS - demonstrates why secure systems combine several cryptographic techniques.
No single cryptographic mechanism provides every required property.
What Problem Does PKI Solve?
Asymmetric cryptography gives us public and private keys.
But one critical question remains:
Public Key Infrastructure provides processes, technologies, policies and trust relationships used to manage public-key identities and digital certificates.
PKI
PKI = Trust the Public Key
๐๏ธ PKI Components CA ยท RA ยท Certificates ยท Repositories ยท Status Services
Issues and digitally signs certificates.
The CA is a central trust component.
May perform identity validation and registration activities on behalf of the CA.
Binds identity or subject information to a public key.
Makes relevant certificates and status information available.
Certificate Revocation List containing certificates that have been revoked by the issuing authority.
Provides online certificate-status information.
CA vs RA
RA validates ยท CA certifies
๐ Digital Certificates Bind a public key to a subject
X.509 certificates are widely used in PKI systems.
Certificate information commonly includes:
The entity associated with the certificate.
The CA that issued the certificate.
Public-key information associated with the subject.
Unique identifier assigned by the issuing CA.
When the certificate is considered valid.
Additional constraints and uses associated with the certificate.
Identifies the mechanism used by the issuing CA to sign.
Protects the certificate's integrity and establishes the issuer's assertion.
The corresponding private key must remain appropriately protected by its owner.
โ๏ธ Certificate Chain of Trust Leaf โ Intermediate โ Root
PKI trust is often hierarchical.
A root certificate is typically self-signed.
It is trusted because the root has been deliberately installed or distributed as a trust anchor - not merely because it signed itself.
Why Intermediate CAs?
Root CA private keys are extremely sensitive.
Rather than using a root key for routine certificate issuance, organisations commonly use subordinate or intermediate CAs.
Certificate Chain
Leaf โ Intermediate โ Trusted Root
โ Certificate Validation A signed certificate is not automatically trustworthy
When validating a certificate, a relying system may need to consider several conditions.
A website presents a cryptographically valid certificate.
However, the certificate belongs to:
different-example.com
while the user is visiting:
bank-example.com.
A valid signature alone does not make that certificate appropriate for the connection.
๐ซ Certificate Revocation What happens when a certificate must stop being trusted?
A certificate may still be within its published validity period but become unsafe or inappropriate to trust.
Reasons for Revocation
CRL - Certificate Revocation List
A CA can publish a signed list identifying certificates that have been revoked.
OCSP - Online Certificate Status Protocol
OCSP provides a mechanism to request certificate-status information online rather than relying solely on downloading a complete revocation list.
| CRL | OCSP | |
|---|---|---|
| Approach | Download revocation information | Query certificate status |
| Information | List of revoked certificates | Status response for certificate |
| Potential issue | Lists can become large or stale between publications | Requires status-service availability and can introduce privacy considerations |
CRL vs OCSP
Certificate Lifecycle
Organisations need visibility of certificates, owners, expiration dates, associated private keys and dependencies.
An unexpected expired certificate can become an availability incident.
๐๏ธ Cryptographic Key Lifecycle Generating a strong key is only the beginning
Cryptographic security depends heavily on how keys are managed throughout their lifetime.
An attacker may not need to break the algorithm if they can simply steal the key.
Key Lifecycle
โณ Cryptoperiod Keys should not necessarily be used forever
A cryptoperiod is the period during which a cryptographic key is authorised for a particular use.
Appropriate cryptoperiods depend on factors such as:
Limiting how long one key is used can reduce the amount of information or number of systems affected if that key is compromised.
Key rotation needs to balance security requirements with reliable distribution, availability and operational complexity.
๐งฐ Key Recovery & Escrow What happens if legitimate access to an encryption key is lost?
Some encryption systems require a controlled recovery capability.
An employee encrypts important corporate information and then leaves the organisation.
If the only decryption key disappears with the employee, the information may become permanently unavailable.
Key Escrow
Key escrow stores recoverable cryptographic key material with an authorised third party or controlled organisational mechanism.
Key Recovery
Key recovery allows authorised access to protected key material when a legitimate recovery condition occurs.
Recovering encryption keys may be necessary to preserve access to organisational data.
Duplicating or escrowing private signing keys can undermine confidence that only the claimed signer controlled the key.
Encryption keys may need recovery because data availability matters.
Signature keys depend strongly on sole control and authenticity.
๐ฅ Split Knowledge & Dual Control Reduce reliance on one privileged individual
Sensitive information is divided so one individual does not possess the entire secret.
Two or more authorised individuals must participate in a sensitive operation.
Several security officers each possess part of the information or authorisation required to activate a highly sensitive cryptographic key.
No single individual can perform the operation alone.
Split vs Dual
๐ฆ Hardware Security Modules - HSM Protect valuable cryptographic keys and operations
HSMs are specialised security devices designed to protect cryptographic keys and perform cryptographic operations within a controlled hardware environment.
A root CA's private signing key represents an extremely high-value organisational secret.
Keeping the signing operation inside protected cryptographic hardware can significantly reduce the exposure of that private key.
The safest private key is often one that does not need to be exported into ordinary application memory or stored as a normal file.
Algorithm Selection
Selecting a cryptographic algorithm is a risk-management and architecture decision.
Security Strength
Is the algorithm and parameter set sufficiently strong?
Purpose
Encryption, signature, hashing or key establishment?
Data Lifetime
How long must the information remain protected?
Performance
What processing and latency constraints exist?
Platform
Which devices and implementations must support it?
Standards
Which organisational or regulatory requirements apply?
Interoperability
Which external systems must communicate?
Future Migration
Can the algorithm be replaced when requirements change?
Cryptographic algorithms and parameter sizes that were once considered appropriate may eventually become unsuitable because of advances in cryptanalysis, computing capability or standards.
๐ Cryptographic Agility Design systems so cryptography can change
Cryptographic agility - often shortened to crypto agility - is the ability to replace or adapt cryptographic algorithms and mechanisms without requiring a complete redesign of the surrounding system.
One encryption algorithm is hard-coded into:
- thousands of applications;
- firmware;
- databases;
- network protocols;
- third-party integrations.
Replacing it becomes a multi-year engineering project.
Cryptographic functions and policies are designed so algorithms, certificates and parameters can be changed in a controlled way.
Crypto Agility Requires Visibility
Crypto Agility
Quantum Computing & Cryptography
Large-scale cryptographically relevant quantum computers would threaten important classes of traditional public-key cryptography.
This creates a long-term architectural requirement to identify cryptographic dependencies and prepare systems for migration.
An attacker may collect encrypted information today and retain it in the hope that future technology allows them to decrypt it.
This is particularly relevant when information must remain confidential for many years.
โ๏ธ Post-Quantum Cryptography - PQC Cryptographic algorithms designed to resist quantum attacks
Post-quantum cryptography uses mathematical algorithms intended to remain secure against attacks from both classical and sufficiently capable quantum computers.
Importantly:
NIST's Initial PQC Standards
| Standard | Algorithm | Purpose |
|---|---|---|
| FIPS 203 | ML-KEM | Key encapsulation / shared-secret establishment |
| FIPS 204 | ML-DSA | Digital signatures |
| FIPS 205 | SLH-DSA | Hash-based digital signatures |
Organisations first need to know where vulnerable public-key algorithms are used before they can replace them.
This is another reason crypto agility is increasingly important.
PQC
๐ก Quantum Key Distribution - QKD Use quantum properties to establish secret key material
Quantum Key Distribution uses quantum-mechanical properties to help establish secret key material between parties.
One important idea is that attempting to observe the quantum communication can disturb it in a detectable way.
PQC uses new mathematical cryptographic algorithms running on conventional computing systems.
QKD uses quantum communication technology to establish secret keys.
Establishing key material does not by itself solve every problem of identity, authentication, certificate management or application security.
PQC vs QKD
Cryptography is a System, Not an Algorithm
A secure cryptographic architecture requires more than selecting a strong cipher.
Connecting to an Online Bank
A customer visits an online banking website using HTTPS.
Several cryptographic mechanisms work together.
Certificates do not perform the whole job.
Symmetric encryption does not establish identity.
Hashing alone does not establish trust.
Secure protocols combine several mechanisms.
Sending a Confidential Signed Message
Alice wants to send Bob a message that:
- only Bob can read;
- Bob can verify that Alice signed it;
- Bob can detect whether the message changed.
Signature
Alice signs using:
Alice's PRIVATE key.
Bob verifies using:
Alice's PUBLIC key.
Confidentiality
The message or session key can be protected for:
Bob using Bob's PUBLIC key or another appropriate key-establishment mechanism.
Bob accesses the protected information using:
Bob's PRIVATE key or resulting session secret.
Alice โ Bob
๐ CISSP Scenarios Identify the correct cryptographic mechanism
An organisation needs to encrypt several terabytes of backup data efficiently.
Which approach is MOST appropriate?
Symmetric encryption.
Alice wants Bob to receive information that only Bob can decrypt using asymmetric cryptography.
Which public key should Alice use?
Bob's public key.
Alice digitally signs a document.
Which key should Alice use?
Alice's private key.
Bob receives Alice's digitally signed document.
Which key should Bob use to verify the signature?
Alice's public key.
A file's digest changes after one character in the file is modified.
Which cryptographic concept is demonstrated?
Cryptographic hashing and the avalanche effect.
Two systems share a secret and need to verify that API messages have not been modified and came from a party possessing that secret.
Which mechanism is appropriate?
MAC / HMAC.
Two users have chosen the same password, but their stored password values should not automatically be identical.
Which mechanism helps?
Unique password salts.
A browser needs to determine whether a website public key really belongs to the claimed website.
Which infrastructure helps establish this trust?
PKI and digital certificates.
A CA delegates identity verification to another organisational component before certificate issuance.
Which component performs that function?
Registration Authority - RA.
A website certificate was issued legitimately but its private key has since been compromised.
What should happen?
The certificate should be revoked and replaced.
A client downloads a periodically published list of invalid certificates from a CA.
Which mechanism is this?
CRL.
A client asks an online service for the current status of a specific certificate.
Which protocol is MOST relevant?
OCSP.
A company protects all encryption keys using powerful algorithms, but keeps them in plaintext configuration files.
Primary weakness?
Key management.
Two administrators must both participate before a root CA signing key can be activated.
Which concept is demonstrated?
Dual control.
No administrator possesses the entire sensitive key component.
Which concept is demonstrated?
Split knowledge.
A future compromise of a TLS server's long-term private key should not expose session keys from previously recorded connections.
Which property is required?
Forward secrecy.
An organisation cannot easily replace an obsolete algorithm because it has been hard-coded into hundreds of systems.
Which capability was missing?
Cryptographic agility.
An organisation wants a quantum-resistant mechanism for establishing shared secret key material using ordinary computers.
Which current concept is MOST relevant?
Post-quantum Key Encapsulation Mechanism such as ML-KEM.
Two locations use quantum properties of transmitted photons to help establish secret key material.
Which technology is this?
Quantum Key Distribution - QKD.
A very large database is encrypted using public-key cryptography for every record even though a symmetric session key could provide the required confidentiality more efficiently.
Which architecture is generally preferable?
Hybrid cryptography - asymmetric mechanisms for trust or key establishment and symmetric encryption for bulk data.
Recognise the Clue Words
Bulk Encryption
Fast, shared secret, large data.
SymmetricPublic / Private Pair
Signatures and key establishment.
AsymmetricFixed-Length Fingerprint
Detect modification.
HashShared Secret + Integrity
Authenticate message between parties sharing key.
HMACPrivate Signs
Public verifies.
Digital SignatureConfidential for Bob
Use Bob's public key.
Public-Key ConfidentialityWho Owns This Public Key?
Identity-to-key binding.
Certificate / PKIChecks Identity
Before certificate issuance.
RASigns Certificate
Trust authority.
CAList of Revoked Certificates
Download status list.
CRLOnline Certificate Status
Query certificate.
OCSPProtect Valuable Keys
Dedicated cryptographic hardware.
HSMNo One Knows Whole Secret
Divide sensitive information.
Split KnowledgeNo One Acts Alone
Multiple participants required.
Dual ControlPast Sessions Stay Safe
Future long-term key compromise.
Forward SecrecyReplace Algorithms Easily
Prepare for cryptographic transition.
Crypto AgilityQuantum-Resistant Algorithms
Conventional computers.
PQCQuantum Communication
Establish secret keys using quantum properties.
QKDโ ๏ธ Common CISSP Mistakes The key direction questions are especially important
Encryption is reversible with appropriate key material.
Hashing is designed as a one-way transformation.
A signature protects integrity and supports authentication.
It does not hide the message.
Encrypt using the recipient's public key.
Sign using the sender's private key.
HMAC uses a shared secret.
A digital signature uses asymmetric key material.
Both parties may possess the shared secret and therefore may both be capable of creating a valid authentication code.
Password salts are normally stored alongside the password-derived value.
Certificates distribute public-key information.
Private keys should remain protected.
A root CA is trusted because it is deliberately configured as a trust anchor.
Expiration occurs when the certificate reaches the end of its validity period.
Revocation invalidates a certificate before normal expiration.
CRL provides a revocation list.
OCSP provides online certificate-status responses.
Weak keys, poor randomness, bad implementation or exposed key material can defeat otherwise strong cryptography.
Recovery may be important for encryption keys.
Private signing keys require especially careful protection of sole control.
PQC is quantum-resistant mathematical cryptography.
QKD uses quantum communication to establish key material.
Post-quantum algorithms are intended to run on conventional computers.
Quick Reference
| If you need to... | Think... |
|---|---|
| Encrypt large quantities of data efficiently | Symmetric Encryption |
| Use a public/private key pair | Asymmetric Cryptography |
| Detect data modification | Hash |
| Authenticate a message with a shared secret | HMAC / MAC |
| Authenticate a signer cryptographically | Digital Signature |
| Encrypt data for Bob using public-key cryptography | Bob's Public Key |
| Verify Alice's signature | Alice's Public Key |
| Sign as Alice | Alice's Private Key |
| Establish a shared secret | DH / ECDH / KEM |
| Trust a public key | PKI / Certificate |
| Validate certificate applicant | RA |
| Issue certificate | CA |
| Check a revocation list | CRL |
| Request online certificate status | OCSP |
| Protect high-value private keys | HSM |
| Divide secret information between people | Split Knowledge |
| Require multiple people to perform an operation | Dual Control |
| Protect previous sessions after future key compromise | Forward Secrecy |
| Replace algorithms without redesigning everything | Crypto Agility |
| Use quantum-resistant mathematical algorithms | PQC |
| Distribute key material using quantum communication | QKD |
Cryptography Master Memory Aid
Encrypt ยท Hash ยท Authenticate ยท Sign ยท Trust ยท Manage
The CISSP Key Direction Shortcut
Secret for THEM โ Their Public ยท Proof from ME โ My Private
Key Takeaways
Cryptographic solutions should be selected according to the security property that needs to be achieved.
Symmetric cryptography uses shared secret key material and is highly efficient for bulk encryption.
Asymmetric cryptography uses public/private key pairs and enables capabilities such as digital signatures and secure key establishment.
Modern systems commonly use hybrid cryptography: asymmetric mechanisms establish trust or session secrets while symmetric cryptography protects bulk information efficiently.
To protect confidentiality for a recipient using public-key encryption, use the recipient's public key.
The recipient uses their private key to perform the corresponding private operation.
Cryptographic hashing produces a one-way fingerprint and is commonly used to support integrity checking.
HMAC combines shared secret material with a hash-based construction to provide integrity and message authentication.
Digital signatures use the signer's private key to sign and the signer's public key to verify.
Digital signatures support integrity, authentication and evidence used for non-repudiation, but do not automatically provide confidentiality.
Salts help protect password-verification systems against precomputed attacks and ensure identical passwords do not automatically produce identical stored representations.
Diffie-Hellman and ECDH are associated with key agreement, while ECDSA is associated with digital signatures.
Ephemeral key agreement can provide forward secrecy so compromise of a long-term key does not automatically expose previously established sessions.
PKI solves the trust problem surrounding public keys by binding identities to public keys using certificates and trusted authorities.
A Registration Authority may validate identity while a Certificate Authority issues and signs certificates.
Certificate trust can be established through a chain from an end-entity certificate through intermediate CAs to a trusted root.
Certificate validation should consider trust chain, signature, validity period, identity, intended usage and revocation status.
CRLs provide revocation lists while OCSP provides online certificate status information.
Strong algorithms do not compensate for weak key management.
Key management includes secure generation, establishment, storage, use, rotation, revocation, recovery where appropriate and eventual destruction.
Split knowledge means no one individual possesses the complete secret, while dual control requires multiple people to participate in a sensitive operation.
Cryptoperiods limit the authorised usage period of cryptographic key material.
HSMs can protect highly sensitive keys and perform cryptographic operations inside dedicated hardware.
Crypto agility allows organisations to migrate algorithms and cryptographic mechanisms when security requirements change.
Post-quantum cryptography uses mathematical algorithms intended to resist quantum attacks while running on conventional computing systems.
Quantum Key Distribution is a different concept that uses quantum communication to establish secret key material.
Cryptography is a system: algorithm + key + implementation + lifecycle + trust. Weakness in any part can undermine the protection.
๐ Sources & Further Reading Authoritative cryptographic and PKI references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-57 Part 1 Rev. 5 - Recommendation for Key Management
View NIST key-management guidance - NIST FIPS 186-5 - Digital Signature Standard
View the NIST Digital Signature Standard - NIST SP 800-52 Rev. 2 - TLS Implementation Guidelines
View NIST TLS guidance - NIST FIPS 203 - Module-Lattice-Based Key-Encapsulation Mechanism
View FIPS 203 - ML-KEM - NIST FIPS 204 - Module-Lattice-Based Digital Signature Standard
View FIPS 204 - ML-DSA - NIST FIPS 205 - Stateless Hash-Based Digital Signature Standard
View FIPS 205 - SLH-DSA - NIST - Considerations for Achieving Crypto Agility
View NIST crypto-agility guidance - NIST - Post-Quantum Cryptography Project
Explore NIST post-quantum cryptography - NIST - What Is Quantum Cryptography?
Read about quantum cryptography and QKD
