Abstract
Modern encryption presents an interesting paradox. Cryptographic algorithms such as AES remain computationally resistant to direct brute-force attacks when correctly implemented and supplied with sufficiently strong keys. Yet encrypted systems continue to be compromised.
The explanation is increasingly found outside the mathematical core of the cipher.
Rather than attempting to decrypt ciphertext directly, practical attacks often target the surrounding cryptographic ecosystem: passwords, recovery keys, key-encryption keys, memory, Trusted Platform Modules (TPMs), implementation vulnerabilities, endpoint compromise, and other mechanisms through which cryptographic keys are generated, stored, protected, or released.
At the same time, organizations face a fundamentally different long-term threat. Advances in quantum computing create the possibility that encrypted information captured today could be stored and decrypted in the future once sufficiently capable quantum computers become available. This “harvest now, decrypt later” scenario is one of the principal reasons organizations are beginning their transition toward post-quantum cryptography.
These two developments create a transitional period for information security. Organizations must protect cryptographic keys against attacks that exist today while simultaneously preparing cryptographic architectures for attacks that may become practical tomorrow.
The central challenge is therefore no longer simply choosing a strong encryption algorithm. It is achieving cryptographic agility while protecting the complete lifecycle of cryptographic keys.
1. Introduction: Strong Encryption Does Not Mean an Unbreakable System
When discussing encryption security, attention traditionally focuses on the strength of the cryptographic algorithm.
This remains important. However, a modern encrypted system consists of much more than an algorithm:
Plaintext → Encryption Algorithm + Key → Ciphertext
If a sufficiently strong algorithm is correctly implemented, attacking the ciphertext directly may be computationally impractical.
This changes the attacker’s economic calculation.
Why spend enormous computational resources attempting to break a strong cipher if the attacker can instead obtain the key required to decrypt the information?
Consequently, the practical attack surface moves from the mathematical algorithm toward the surrounding key-management infrastructure:
Ciphertext → Key → Key Storage → Key Protection → Endpoint → User
This distinction is essential for understanding the current state of cryptographic security.
2. BitLocker as an Example: Attack the Key, Not AES
Microsoft BitLocker provides a useful example.
The important point is not that the underlying encryption algorithm has somehow become cryptographically weak. Instead, forensic and security research demonstrates that access to encrypted storage can sometimes be achieved by targeting mechanisms responsible for protecting or releasing encryption keys.
Commercial forensic vendor Passware, for example, states that its current forensic products can decrypt certain TPM- and fTPM-protected BitLocker systems. For supported configurations, the company describes obtaining the BitLocker Volume Master Key (VMK) using information associated with the TPM rather than cryptanalytically breaking the underlying encryption algorithm.
This distinction is fundamental:
The cipher does not necessarily need to be broken if the key can be recovered.
The same principle extends beyond BitLocker.
Depending on the architecture and implementation, attackers may attempt to obtain cryptographic material through:
- compromised endpoints;
- memory acquisition;
- weak passwords protecting keys;
- recovery mechanisms;
- implementation vulnerabilities;
- improperly protected backups;
- compromised administrative accounts;
- key-management infrastructure;
- physical access to devices;
- vulnerabilities affecting TPMs, HSMs or their surrounding software;
- social engineering.
Encryption can therefore remain mathematically secure while the encrypted system as a whole becomes accessible.
3. The Security Boundary Has Moved
This leads to an important conceptual shift.
Historically, the central cryptographic question could be expressed as:
“Can an attacker break the encryption algorithm?”
For modern systems, an equally important question is:
“Can an attacker obtain or cause the legitimate system to release the decryption key?”
This changes how encryption security should be evaluated.
A cryptographic key has a lifecycle:
Generation → Distribution → Storage → Use → Rotation → Recovery → Revocation → Destruction
A weakness at any stage can potentially undermine an otherwise strong cryptographic system.
Therefore, encryption governance should evaluate not only algorithm strength but also the complete lifecycle of the cryptographic material.
4. The Second Problem: Steal Today, Decrypt Tomorrow
There is another attack model where stealing the key today may not be necessary.
An adversary can capture encrypted information and simply preserve it.
The information may remain unreadable for years.
However, if future computational capabilities make the underlying public-key cryptography vulnerable, some captured information could potentially be decrypted later.
This concept is commonly described as:
Harvest Now, Decrypt Later (HNDL).
The risk is particularly relevant to information with a long confidentiality lifetime.
Consider information that must remain confidential for 20 years.
If it is intercepted in 2026 and quantum computers capable of attacking the relevant cryptography become available before 2046, protecting the information only against today’s computational capabilities may be insufficient.
Security architecture therefore has to consider:
Data confidentiality lifetime > Expected cryptographic protection lifetime
This transforms quantum computing from a purely future concern into a current information-governance problem.
5. Post-Quantum Cryptography Changes Part of the Equation
In August 2024, NIST finalized its first three principal post-quantum cryptography standards:
- FIPS 203 — ML-KEM
- FIPS 204 — ML-DSA
- FIPS 205 — SLH-DSA
However, these algorithms serve different purposes.
ML-KEM
Module-Lattice-Based Key-Encapsulation Mechanism is designed for establishing shared secret material between communicating parties.
It addresses the future quantum vulnerability of traditional public-key key-establishment mechanisms.
ML-DSA
Module-Lattice-Based Digital Signature Algorithm provides quantum-resistant digital signatures.
SLH-DSA
Stateless Hash-Based Digital Signature Algorithm provides another approach to quantum-resistant digital signatures based on hash functions.
Thus, post-quantum migration is not simply a matter of replacing one encryption algorithm with another.
It requires redesigning parts of the key-establishment and digital-signature infrastructure upon which secure communications depend.
6. Post-Quantum Cryptography Does Not Solve Key Theft
This distinction is particularly important.
Suppose an organization replaces a quantum-vulnerable key-establishment algorithm with ML-KEM.
This can protect against an attacker using a future quantum computer to defeat the mathematical key-establishment problem.
But what happens if the resulting secret key is subsequently stolen from memory?
What if an endpoint is compromised?
What if privileged credentials provide access to the key-management system?
What if an implementation vulnerability causes cryptographic material to be exposed?
Post-quantum cryptography does not automatically solve these problems.
In simplified form:
PQC protects against new attacks on cryptographic mathematics.
Key management protects against attacks on cryptographic implementation and operation.
Both are necessary.
7. We Are Living Through a Cryptographic Transition
The current situation should therefore be understood as a transition rather than simply an algorithm replacement.
Organizations simultaneously operate several generations of cryptography:
Classical cryptography
↓
Strengthened classical cryptography
↓
Hybrid classical + post-quantum mechanisms
↓
Post-quantum cryptographic architectures
Canada provides a useful example of this transition.
The Canadian Centre for Cyber Security currently recommends RSA keys of at least 2048 bits for relevant applications, while stating that RSA modulus lengths should increase to at least 3072 bits by the end of 2030. It further recommends phasing out RSA without a post-quantum key-establishment or signature scheme by the end of 2035.
The Government of Canada’s PQC migration roadmap establishes additional milestones, including completion of migration for high-priority systems by the end of 2031 and remaining systems by the end of 2035.
This demonstrates why organizations cannot simply wait for quantum computers to arrive before taking action.
Migration itself takes years.
8. The Strategic Problem: What Should We Protect Against?
Security teams therefore face an uncomfortable decision.
They must defend against today’s practical attacks while preparing for tomorrow’s cryptographic attacks.
Resources allocated entirely to PQC migration could leave conventional weaknesses unresolved.
Resources allocated exclusively to current endpoint and key-management security could leave long-lived information exposed to future cryptographic developments.
The correct strategy depends on several variables:
Information Value × Confidentiality Lifetime × Threat Model × Key Exposure Risk × Migration Complexity
For example, information that becomes public after six months has a fundamentally different quantum-risk profile from diplomatic, military, intellectual-property, health, or government information that may need confidentiality for decades.
The cryptographic strategy should therefore follow the information rather than simply follow the newest algorithm.
9. From Algorithm Strength to Cryptographic Resilience
The long-term objective should not be to identify a single “perfect” algorithm.
- Algorithms change.
- Standards change.
- Implementations change.
- Threats change.
- Computational capabilities change.
The more sustainable objective is cryptographic resilience supported by crypto-agility.
An organization should be able to:
- identify where cryptography is used;
- identify what information each cryptographic mechanism protects;
- inventory algorithms, certificates and keys;
- understand how and where keys are generated and stored;
- rotate or replace keys rapidly;
- replace cryptographic algorithms without redesigning entire systems;
- support hybrid migration where appropriate;
- and continuously reassess cryptographic protection according to changes in threats and information value.
NIST’s recent work on crypto-agility reflects precisely this broader requirement: migration should become an architectural capability rather than an emergency project performed whenever an algorithm reaches the end of its useful life.
10. A Different Way to Think About Encryption
Perhaps the most important lesson of the current transition is that we should stop viewing encryption as an isolated mathematical operation.
Encryption is a system.
Its real security can be represented conceptually as:
Cryptographic Security = Algorithm Strength + Key Security + Implementation Security + Operational Security + Cryptographic Agility
An extremely strong algorithm cannot compensate for an exposed key.
Likewise, excellent key management cannot indefinitely compensate for an algorithm that becomes mathematically vulnerable.
And neither protects an organization indefinitely if its infrastructure cannot migrate when the threat environment changes.
Conclusion: Security During the Transition
We are currently in an unusual period in the history of cryptography.
For many practical attacks, breaking modern encryption directly remains considerably less attractive than obtaining the cryptographic material required to legitimately perform decryption. Products capable of accessing certain encrypted devices illustrate an important principle: the weakest component of an encrypted system may not be the cipher itself, but the mechanism protecting its keys.
At the same time, quantum computing introduces the opposite problem. An attacker may not need today’s key at all if encrypted information can be collected now and cryptographic assumptions defeated later.
Organizations therefore have to defend information across two timelines:
Today: protect keys, endpoints and cryptographic implementations.
Tomorrow: migrate quantum-vulnerable cryptographic mechanisms before they become practically exploitable.
This makes the present period fundamentally transitional.
The question is no longer simply:
“Which encryption algorithm should we use?”
A more useful question is:
“How long must this information remain protected, where are the keys that protect it, and how quickly can we change the cryptographic architecture when today’s assumptions are no longer valid?”
That is the foundation of cryptographic resilience in the transition to the post-quantum era.
Leave A Comment