Application insights
Quantum computing,
domain by domain
Where quantum computing actually stands across five high-complexity domains — the theoretical upside, but also an honest read on NISQ-era limits and the quantum advantage that has not yet been demonstrated. Four of the five (communications, autonomous driving, robotics, cryptography) tie directly into the post-quantum (PQC) migration business.
0
proven quantum-advantage cases
01
Quantum computing in nuclear fusion
mid/long-term
Fusion couples three brutally hard physics regimes — plasma dynamics, materials science, and nuclear reactions — sub-problems where classical supercomputers are already nearing their ceiling. That motivates the interest in quantum approaches; it is not yet a demonstrated win.
To be blunt up front: no published result shows a quantum computer solving a fusion problem that classical machines cannot. This section separates genuine theoretical potential from the hard limits of the NISQ era.
Four research directions
- Plasma & MHD / Vlasov PDEsThe 6-D phase-space kinetic equations suffer dimensional blow-up. Quantum linear-systems (HHL) and Hamiltonian simulation offer theoretical exponential promise for such high-dimensional PDEs — but state-prep, readout, and conditioning costs currently eat most of the gain.
- First-wall materials & neutron damageDefect formation and transmutation in plasma-facing materials under 14 MeV neutron flux is a strongly-correlated many-body electronic-structure problem. VQE and quantum phase estimation map onto it naturally — but the logical qubits needed for chemical accuracy far exceed today's hardware.
- Nuclear reaction cross-sectionsNuclear-structure calculations for D-T and advanced fuel cycles are strongly-coupled few-body problems. Early quantum-simulation attempts target light nuclei and remain far from engineering-grade accuracy for fusion reaction rates.
- Coil-geometry optimizationStellarator coil and magnetic-configuration optimization is a high-dimensional non-convex combinatorial problem. QAOA and quantum annealing are candidates — yet classical optimizers and quantum-inspired tensor-network methods remain the practical workhorses today.
10⁹⁺
phase-space DOF in kinetic plasma sims that strain classical grids
thousands
fault-tolerant logical qubits for useful fusion-relevant electronic structure — far beyond today
0
proven quantum-advantage cases on any fusion sub-problem
2035+
realistic research horizon for engineering-relevant fusion QC
Sub-problem to quantum-method mapping
Vlasov / plasma kinetics
Quantum linear-systems (HHL) & Hamiltonian simulation · maturity: algorithm-design
Many-body materials & defects
VQE & quantum phase estimation · maturity: lab-scale on small molecules
Nuclear cross-sections
Light-nucleus Hamiltonian simulation · maturity: early proof-of-concept
Coil-geometry optimization
QAOA & quantum annealing · maturity: quantum-inspired on classical hardware
Classical HPC vs quantum on fusion sub-problems
| Approach |
What it does well |
Current limit |
| Classical HPC (grid / PIC) | Mature, trusted, already drives ITER-scale design | Cost blow-up at high-dimensional kinetics & strong correlation |
| Quantum-inspired tensor networks | Compresses some high-dimensional problems on classical hardware today | Bound by entanglement structure; not a universal speedup |
| NISQ quantum processors | Demonstrates small Hamiltonian-sim & VQE prototypes | Noise & scale yield no fusion-grade practical result yet |
| Fault-tolerant QC | Theoretical exponential promise for electronic structure & some PDEs | Hardware does not exist; needs thousands of logical qubits |
Players & ongoing work
UKAEA fusion agency
UK Atomic Energy Authority openly explores quantum computing for fusion and has signed MOUs with quantum vendors.
IBM & Google many-body
Exploratory many-body and small-molecule quantum-simulation work — methodological groundwork for fusion materials problems.
ITER / tokamaks classical baseline
ITER-scale design is still driven by classical HPC — the real benchmark any quantum method must beat to matter.
Stellarator coil research optimization
The stellarator coil-optimization community is a natural testbed for QAOA, annealing, and quantum-inspired combinatorial optimization.
National fusion labs quantum-inspired
Several national labs apply tensor-network and other quantum-inspired methods to high-dimensional plasma problems on classical hardware.
Timeline
- 1994Shor's algorithm The theoretical origin of the belief that quantum computers can deliver exponential speedups — and the backdrop for post-quantum cryptography and this page.
- 2000sTensor-network methods Classical quantum-inspired methods mature into practical compression tools for high-dimensional plasma and many-body problems.
- 2020sNISQ proof-of-concept era Small VQE and Hamiltonian-sim demonstrations on light nuclei and small molecules — still bounded by noise and scale.
- recentUKAEA quantum MOUs A fusion agency and quantum vendors establish formal exploratory partnerships — interest moves from papers to institutions.
- 2030sFault-tolerant horizon If thousands of logical qubits become real, electronic structure and some PDEs could enter the engineering-relevant regime — timing highly uncertain.
For fusion, quantum computing is a theoretically grounded mid/long-term research direction — not a near-term commercial hook. Honestly separating the two is itself the value we offer.
Reality checkNo published result shows QC solving a fusion problem classical machines cannot. It is best positioned as mid/long-term research, not a near-term commercial hook. Any claim of fusion quantum advantage today should be treated with skepticism.
02
Quantum computing in autonomous driving
exploratory
Largely exploratory today, concentrated on a handful of compute-intensive bottlenecks. In the in-car real-time perception and decision loop there is no deployable quantum advantage; the genuine commercial landing zone is post-quantum migration for V2X.
For autonomous driving, quantum computing is more a threat AVs must defend against than a tool that drives them. A vehicle a future CRQC can eventually break needs quantum-safe keys today.
Four exploratory directions
- Path planning & real-time combinatorial optimizationAnnealing and QAOA for fleet dispatch, routing and traffic-flow assignment — small-scale simulation only, far from in-car scale and latency.
- Sensor fusion & uncertaintyHigh-dimensional Bayesian inference and QML kernels; the Volkswagen + D-Wave traffic-flow and battery-materials work is back-office research, not in-car inference.
- NN training accelerationVariational quantum circuits (VQC) handle only toy subtasks today, with no material speedup for perception-model training.
- Cryptography & V2X securityThe reversed-logic direction: AVs need PQC to defend against quantum attack — the vertical market for the Quantum-Safe Scanner and Migrator.
~10 ms
in-car decision latency budget — QC jobs run in seconds
0
proven quantum-advantage cases in AV perception/decision
HIGH
V2X security relevance
10–15 yr
vehicle road life — keys must outlast a future CRQC
Bottleneck → candidate quantum method → honest maturity
Path planning & fleet dispatch
QAOA / quantum annealing — small-scale simulation
Sensor fusion & uncertainty
QML kernels — experimental
Perception model training
VQC — toy subtasks only
V2X cryptography
PQC migration — production-relevant today
QC enabling AVs vs PQC defending AVs
| Dimension |
QC enabling AVs |
PQC defending AVs |
| Maturity | Lab PoC | Standardized, deployable |
| Needs fault-tolerant QC hardware | Yes | No — classical software |
| Commercial readiness | No | Yes |
| In-car real-time feasible | No | Yes |
| Tie to our product line | Weak | Strong — Scanner/Migrator |
Real players & drivers
Volkswagen + D-Wave exploratory
Lisbon quantum traffic-flow trial and battery-materials research — back-office optimization, not in-car systems
Bosch research
Quantum-sensing and materials exploration programs — no direct in-car real-time deliverable yet
Toyota / Hyundai exploratory
Early quantum exploration in materials, batteries and optimization — honestly, still frontier research
UNECE WP.29 R155/R156 regulation
Mandatory cybersecurity and software-update management systems — the real driver of V2X security compliance
Auto-ISAC industry
Automotive threat-intelligence sharing, pushing PQC migration onto OEM agendas
CN OEM / ICV market
Intelligent-connected-vehicle demand for GM (国密) compliance and quantum-safe V2X migration — the closest landing market
Timeline
- 2017–2019Volkswagen + D-Wave run quantum traffic-flow optimization trials in Lisbon — proving back-office optimization, not in-car capability.
- 2020+C-V2X cellular vehicle-to-everything deployment scales up, widening the vehicle communications attack surface.
- 2022/2024UNECE R155/R156 cybersecurity and software-update regulations take effect for new vehicle types, making crypto compliance mandatory.
- 2024NIST finalizes ML-KEM/ML-DSA/SLH-DSA (FIPS 203/204/205), giving quantum-safe migration deployable standards.
- now →Long-lived fleets with 10–15 yr road life enter the migration window: keys shipping today must outlast a future CRQC.
Reality check
No public result shows deployable quantum advantage in AV perception or real-time decisions; most work is NISQ-stage PoC or quantum-inspired classical methods.
Business landing zone
V2X PQC migration (scan + migrate + compliance) is closer to the product line than "QC optimizing AVs", meeting Chinese OEM and intelligent-connected-vehicle demand for GM (国密) standard compliance and HNDL risk reduction.
03
Quantum computing in robotics
exploratory
Mostly motion planning, control-policy training, multi-robot coordination, perception, and security — but the one direction genuinely near commercial landing is not "robots using quantum computing," it is post-quantum migration of industrial-robot / AMR firmware and comms.
~kHz
real-time control-loop rate QC cannot meet
0
proven quantum-advantage cases in robotics
discrete
most realistic early use = discrete multi-robot scheduling
millions
connected industrial-robot install base, growing exposure
Main directions
- 1. Motion planning & trajectory optimization. Inverse kinematics, obstacle avoidance and many-DoF path planning are at heart constrained-optimization problems. Annealing / QAOA have been tried on discretized path search — a theoretical edge on combinatorial sub-problems — but only at simplified simulation scale, nowhere near replacing mature classical planners (RRT*, MPC).
- 2. RL & control-policy training. QML / VQC could in theory accelerate parts of the linear algebra inside policy-gradient and value approximation, but qubit count and noise confine it to toy scale and offline simulation only — it does not enter the real control loop.
- 3. Multi-robot coordination & swarm. Warehouse / logistics AGV routing and task allocation are textbook combinatorial problems that map naturally to QUBO — the clearest theoretical edge, and the most realistic early landing in robotics. Yet solved instances stay small, and a measured win over classical heuristics is not yet established.
- 4. Sensor processing & SLAM. Localization and mapping lean on heavy matrix operations and probabilistic inference. Quantum linear algebra (HHL-class) has theoretical room for large linear systems, but HHL's preconditions are stringent and it is far from robotics' latency, power and form-factor budgets — not near-term feasible.
- 5. Cryptography & robot security (directly relevant). Industrial robots, cobots and AMRs routinely connect to factory networks and the cloud. Their firmware updates and device identity lean on RSA / ECC, now exposed to harvest-now-decrypt-later (HNDL) — adversaries capture encrypted traffic today and decrypt once quantum matures. Control systems need PQC to withstand a future quantum adversary. The logic is reversed: robots don't need quantum computing, they need post-quantum crypto.
Robots don't need to "use quantum computing" — their control systems need PQC to survive a future quantum adversary.
Workload → candidate quantum method → honest maturity
Motion planning / trajectory opt.
QAOA / annealing — simplified-scale simulation, not in the real-time loop
RL / control-policy training
QML / VQC — toy scale, offline sim, bounded by qubits & noise
Multi-robot scheduling / swarm
QUBO / annealing — most promising but still small-scale, measured edge unproven
SLAM / perception
Quantum linear algebra / HHL — theoretical only, far from latency/power budgets
Firmware / identity crypto
PQC migration (ML-KEM / ML-DSA) — actionable now, standards and product landing exist
Continuous control vs discrete combinatorial scheduling
| Problem type |
QC fit — why / why not |
Current status |
| Continuous control (servo / force / balance) |
Poor fit — needs kHz deterministic real-time loops; circuit latency, noise and measurement overhead simply can't meet that |
Classical MPC / PID dominate, no quantum role |
| Discrete combinatorial scheduling (AGV routing / task allocation) |
Better fit — maps to QUBO, with a clearer theoretical edge on NP-hard combinatorics, and is not real-time |
Annealing / QAOA in research, still small-scale, edge unproven |
| Firmware / comms security |
Directly relevant — not QC, but PQC migration against HNDL and device-identity risk |
Standards finalized (FIPS 203/204/205), deployable now |
Players & reference points
Toyota / Bosch / Siemens exploratory
Industrial majors run quantum-exploration teams on scheduling, logistics and materials — robot control itself remains research, not product
AGV / 仓储调度研究 QUBO
Academic and D-Wave-style work applies quantum annealing to AGV routing and multi-robot allocation — small-scale, but the closest to a landing zone
ROS 2 / micro-ROS · SROS2 security baseline
The de-facto robot software stack; SROS2 brings DDS-based auth and encryption — the classical security baseline now needing a PQC path
OPC-UA · IEC 62443 compliance driver
Industrial-comms and OT-security standards mandating device auth and encrypted channels — the compliance driver pushing vendors to migrate their crypto
AMR / 协作机器人厂商 PQC customer
Vendors shipping long-lived, fleet-connected AMRs and cobots are a direct customer pool for firmware / identity PQC migration
Timeline
- 2018–Cobots & AMRs scale in smart manufacturing — connected-robot install base grows fast, expanding the security exposure
- 2018–Quantum-annealing AGV / scheduling research — QUBO-coded multi-robot routing and allocation become the liveliest quantum thread in robotics
- 2010s–IEC 62443 industrial cybersecurity adoption — OT-security standards spread across plants, mandating device auth and encrypted comms
- 2020China Cryptography Law & 密评 requirements — commercial-cryptography mandated; critical infrastructure must pass 密评, pulling robot makers into the customer pool
- 2024NIST PQC standards finalized — FIPS 203/204/205 — ML-KEM / ML-DSA / SLH-DSA finalized, giving firmware and identity migration a concrete basis
- 2025+Firmware migration windows for long-lived fleets — industrial robots serve 10+ years; under HNDL the migration window opens now, and earlier is safer
Reality check
No public evidence shows real quantum advantage in robot motion control or perception — the overwhelming majority is NISQ-era proof-of-concept or quantum-inspired heuristics running on classical hardware (not necessarily quantum at all). Treating robots' continuous real-time control as a quantum use case is the most common over-claim here.
Business relevance
Firmware and comms-security compliance for industrial robots / AMRs sits much closer to the Quantum-Safe Scanner / Migrator line (scan + migrate + compliance) than "QC optimizing robots." China's industrial-internet and smart-manufacturing 密评 (commercial-cryptography application security assessment) makes robot makers a direct, reachable customer pool — the genuinely sellable landing zone in this domain.
04
Quantum computing in communications
three threads
Quantum and communications actually split into three very different logic lines that get conflated constantly — worth untangling first: which one is just research, which is a separate hardware stack, and which actually connects to the business.
~100%
of comms public-key crypto rides on RSA/ECC
~100s km
QKD's practical fiber reach without trusted nodes
NO
can QKD replace PQC? (key distribution only)
10–50 yr
data-secrecy horizon HNDL must outlast
I. QC "enabling" classical comms
- 1. Network routing & resource allocation. 5G/6G spectrum allocation, base-station load balancing and network-slice scheduling are high-dimensional combinatorial problems. Operators (Vodafone, SK Telecom) have run small annealing/QAOA trials — limited scale, mostly proof-of-concept, with no evidence yet of a real edge over classical heuristic solvers.
- 2. Signal processing & channel estimation. Massive-MIMO channel estimation and beamforming involve large matrix operations; quantum linear algebra (HHL-style routines) has theoretical room, but state-preparation and readout overheads keep it off the deployment path — no commercial use exists yet.
Reality check
This thread is the "QC optimizes telecom networks" research narrative — it sounds close to operator workloads, but there is no public quantum-advantage evidence today. It is not where the business logic lands; the business sits on thread III (the threat side).
II. Quantum communication (a different track, often mistaken for "an application of QC")
- 1. Quantum key distribution (QKD). Uses no-cloning to distribute keys and can in principle detect eavesdropping. China has invested most (Micius satellite 墨子号, the Beijing–Shanghai backbone 京沪干线), but QKD has hard practical limits: dedicated fiber/satellite infrastructure, limited range (a few hundred km without trusted relays), high cost — and it only solves key distribution, not data encryption, signatures or authentication. It cannot replace PQC.
- 2. Quantum internet. Entanglement-based long-distance quantum-state networks remain at the lab / small-trial stage (quantum repeaters, error correction and other core problems unsolved) — far from practical use and irrelevant to near-term enterprise procurement.
QKD is a niche key-distribution hardware play; PQC is the software migration that actually secures comms — they are not substitutes but different layers. Betting comms security on QKD swaps how keys are handed over, while leaving the lock on the door unchanged.
QKD vs PQC — the key comparison
| Dimension |
QKD (quantum key distribution) |
PQC (post-quantum cryptography) |
| What it protects |
Key exchange only — distribution of symmetric keys |
Encryption, digital signatures and key encapsulation — the full set |
| Infrastructure |
Dedicated fiber/satellite + quantum transceiver hardware |
Software-only, runs on existing networks |
| Range & scale |
~Hundreds of km without trusted relays; mostly point-to-point |
Internet-scale, end-to-end across any topology |
| Authentication |
Cannot bootstrap trust — still needs a classical/PQC-authenticated channel |
Provides signatures — establishes trust on its own |
| Standards |
ETSI QKD series |
NIST FIPS 203/204/205, plus GM/T (国密) |
| Cost |
High — dedicated hardware, build-out and upkeep |
Low — library and firmware upgrades |
| Replace classical public-key crypto everywhere? |
No |
Yes |
III. QC as a threat to comms security (directly tied to the business)
- 1. Comms crypto is almost all RSA/ECC. TLS/HTTPS, VPN/IPsec, 5G/6G core-network authentication and satcom encryption — their handshakes and certificates run almost entirely on RSA/ECC. Once a CRQC (cryptographically relevant quantum computer) exists, those public-key links fall to Shor's algorithm — not weakened, but with private keys recoverable outright.
- 2. Harvest now, decrypt later (HNDL). Traffic intercepted today can be stored and decrypted in the future — a real threat to long-secrecy communications (diplomatic, military, financial, long-lived satcom links), and the clock is already running. This makes telecom operators, satellite communications and government/enterprise private networks the core PQC-migration customer base.
PQC migration, layer by layer
TLS / HTTPS
Exposure: RSA/ECC handshake → Action: hybrid ML-KEM key agreement (X25519+ML-KEM)
VPN / IPsec
Exposure: DH/ECDH key exchange → Action: swap to a PQC KEM (ML-KEM)
5G/6G core auth
Exposure: ECC certs & device identity → Action: PQC certificates (ML-DSA signatures)
Satcom links
Exposure: long-lived keys → Action: migrate first — highest HNDL exposure
Real players & projects
Vodafone operator
Annealing/network-optimization trials, plus PQC pilots (quantum-safe calls with device makers)
SK Telecom operator
Network-optimization exploration; active across quantum-safe efforts (both QKD and PQC)
Micius / Beijing–Shanghai QKD infra
The world's largest QKD infrastructure — satellite + backbone fiber; proves QKD yet exposes its dedicated-infra and range limits
Toshiba / ID Quantique QKD vendor
Commercial QKD systems and single-photon hardware — dedicated-equipment business, still a niche market
GSMA PQ Telco Network task force
Operator-led post-quantum migration task force — a signal that telcos treat PQC as real engineering, not research
ETSI vs NIST standards
ETSI maintains QKD standards; NIST maintains PQC (FIPS 203/204/205) — two standards for two distinct tracks
Cloudflare / Google shipping
Hybrid PQC TLS (X25519+ML-KEM) is live at scale in Chrome and on Cloudflare's edge — the proof that PQC is shipping now
Timeline — real milestones
- 2016Micius quantum-science satellite launched — first satellite-to-ground QKD
- 2017Beijing–Shanghai QKD backbone completed (~2000 km, relying on trusted-relay nodes)
- 2023–24Cloudflare / Chrome roll out hybrid X25519+ML-KEM TLS at scale — PQC reaches real traffic
- 2024NIST finalizes FIPS 203 (ML-KEM) / 204 (ML-DSA) / 205 (SLH-DSA) — a firm standards baseline for comms migration
- 2024+GSMA post-quantum telco task force drives operator migration guidance; 5G network functions and 6G design windows become PQC entry points
Business relevance
Communications (especially 5G/6G core, satcom, operator private networks) is a high-priority PQC vertical. The chain is clean: comms depend on classical public-key crypto (RSA/ECC) → QC (Shor + HNDL) threatens that layer → the Scanner locates the weak points and the Migrator replaces them with ML-KEM/ML-DSA while staying GM/T-compatible, delivering a compliant migration path. This is a far sturdier story than "QC optimizing comms networks" — that one is research, this one is a hard requirement. It also maps directly onto a Huawei 6G quantum-security engineer background — itself a strong credibility anchor in front of telecom/operator customers.
05
Quantum computing in cryptography
core thesis
Quantum computing and cryptography sit at both the threat and defense ends at once — this is the core thesis the entire post-quantum business rests on. The same physics that breaks RSA is what drives PQC standardization and migration.
~10³ logical / 10⁶ physical
qubits to break RSA-2048 — today only hundreds of noisy physical qubits
2024
NIST PQC standards finalized — FIPS 203 / 204 / 205
HNDL
migrate NOW — long-secrecy data faces harvest-now-decrypt-later
2
PQC candidates already broken — Rainbow & SIKE
I. How QC threatens today's crypto (attack side)
- Shor — breaks public-key. Polynomial-time factoring & discrete log; once a large low-error CRQC exists, RSA / ECC / DH are fully broken and the private key is directly recoverable.
- Grover — weakens symmetric & hashes. Quadratic speedup: AES-128 → ~64-bit effective (still 2^64 ops, limited real threat), AES-256 → ~128-bit (safe). This is why NIST PQC focuses on public-key while symmetric just needs longer keys.
- Harvest now, decrypt later (HNDL). Intercept & store ciphertext today, decrypt later once a CRQC matures; this drives national timelines (US NSM-10, CNSA 2.0).
II. How crypto responds (defense side / PQC)
- Lattice. ML-KEM (ex-Kyber, KEM) and ML-DSA (ex-Dilithium, signatures), built on LWE; the mainstream path and the specialty of LAC co-designer Lu Xianhui 路献辉.
- Hash-based. SLH-DSA (ex-SPHINCS+); the most conservative assumption, relying only on hash functions, at the cost of large signatures.
- Code-based. HQC, selected by NIST as a backup KEM in March 2025; Classic McEliece dates back to 1978 and has survived decades of public analysis.
- Multivariate & isogeny — proven unreliable. Rainbow was broken over a weekend on a laptop in 2022; SIKE was broken the same year — the lesson: a quantum-safe label must survive long public cryptanalysis.
The duality thesis: the same physics that breaks RSA is why post-quantum migration is now a compliance deadline, not a research topic.
Algorithm families
| Algorithm |
Type |
Hard problem |
NIST status |
Key·sig size tradeoff |
GM/T note |
| ML-KEM |
Lattice KEM |
Module-LWE |
FIPS 203 |
Moderate keys, fast, best all-round |
Maps to GM/T key-exchange path |
| ML-DSA |
Lattice sig |
Module-LWE/SIS |
FIPS 204 |
Moderate sig, fast verify, mainstream |
Parallels SM2 signature migration |
| SLH-DSA |
Hash sig |
Hash security |
FIPS 205 |
Large sig, most conservative |
Pairs with SM3 for archival |
| HQC |
Code KEM |
Code decoding |
Backup KEM (2025) |
Larger keys, non-lattice backup |
Diversity backup to lattice path |
| Classic McEliece |
Code KEM |
Code decoding |
Candidate, not standardized |
Huge public key, robust since 1978 |
Fits high-secrecy long-term data |
| Rainbow / SIKE |
Multivariate / isogeny |
Assumption failed |
Broken |
Unusable, cautionary case |
Labels are not proofs |
Migration mapping
RSA-2048/3072 key exchange
ML-KEM-768 (hybrid X25519 + ML-KEM)
ECDSA / RSA signatures
ML-DSA-65 / SLH-DSA
Long-term archival
Conservative hash/code-based (SLH-DSA / Classic McEliece)
Highest security level
ML-KEM-1024 & ML-DSA-87
GM/T: SM2 / SM3 / SM9
Map to GM/T national PQC path (dual-compliance)
Players
NIST PQC project standards
Drives global PQC standardization — FIPS 203/204/205 plus HQC backup KEM.
Daniel J. Bernstein analysis
cr.yp.to — long-time cryptanalysis & implementation-bug research; math security is not implementation security.
Lu Xianhui 路献辉 lattice
Designer of the LAC lattice scheme; a representative force in China's lattice cryptography research.
China GM/T 国密 regulation
GM/T standards & 商用密码 regulation — SM2/SM3/SM9 form the mandatory baseline for the China market.
Cloudflare / Google deploy
Already running hybrid-PQC key exchange in production TLS at scale, proving engineering feasibility.
SIKE / Rainbow breaks lesson
2022 Castryck–Decru broke SIKE, Beullens broke Rainbow — labels aren't proofs.
Timeline
- 1994 Shor's algorithm — poly-time factoring & discrete log, the theoretical basis of the quantum threat.
- 2016 NIST PQC competition launched — open global public evaluation.
- 2022 Rainbow & SIKE broken — multivariate and isogeny paths eliminated.
- 2022 US NSM-10 & CNSA 2.0 — national migration timelines set.
- Aug 2024 FIPS 203/204/205 finalized — ML-KEM, ML-DSA, SLH-DSA standardized.
- Mar 2025 HQC backup KEM — non-lattice diversity for the lattice path.
- 2026 Implementation-layer vulnerabilities — Bernstein flags issues in several official ML-DSA implementations.
Core meaning for the business
Scanner finds RSA / ECC weak points (future Shor targets); Migrator replaces them with ML-KEM / ML-DSA while staying GM/T compatible; dual-compliance (NIST + GM/T) is the core selling point for Chinese customers.
Note for the BP
Math security is only half — implementation bugs are the other half. A June 2026 Daniel J. Bernstein paper showed that even NIST-standardized ML-DSA had signature-forgery vulnerabilities in several official implementations; the Scanner must therefore detect both the right algorithm AND whether the implementation matches known vulnerability patterns.
References & sources
The factual claims on this page — standards, algorithm breaks, policy timelines, infrastructure — trace back to the authoritative primary sources below. Links open in a new tab.
Cryptography · attack & defense
Policy, standards & timelines
Communications & quantum comms
Autonomous driving & V2X security
Robotics & industrial security
Nuclear fusion & quantum simulation
From insight to a migration path
The genuinely landable commercial value across these five domains concentrates on the post-quantum migration side. The Scanner surfaces RSA/ECC-dependent weak points; the Migrator replaces them with ML-KEM/ML-DSA while staying GM/T-compatible — dual compliance, covering both the algorithm and implementation layers.