Act IV · Post-quantum cryptography
The theft you can’t see yet
Post-quantum cryptography means replacing today's public-key locks, such as RSA, with ones designed to resist future quantum computers. It matters now, not later, because encrypted data can be recorded today and read whenever the maths finally gives way. This page explains how a quantum computer would break RSA by finding a hidden repeat, how one idea used in some post-quantum locks, adding noise, leaves no such repeat to find, and how to judge when to switch.
Messages kept for later
In 1943, American codebreakers began studying Soviet cables they couldn't read. The project, later called VENONA, kept them anyway. Under wartime pressure, the Soviets had printed duplicate copies of some one-time-pad pages, the key pages each meant to be used only once. Those duplicates gave analysts a way in. After years of work, some messages were read, and they helped identify spies, including the Los Alamos physicist Klaus Fuchs. Much of the traffic was never read.
The story simplifies this history. A one-time-pad page used only once, as intended, doesn't become breakable as computers improve. The Soviet weakness was the reuse. What carries over to today is the value of a stored archive: messages kept long enough can become readable.
How RSA locks a secret
RSA is a widely used public-key lock. It starts with two secret prime numbers multiplied together. Anyone can see the result, but working backward to the two primes is very hard, and that difficulty keeps the lock shut. The lab uses 113 × 127 = 14351 so you can watch. Real RSA uses numbers hundreds of digits long.
The repeat that gives RSA away
Start with 1 and keep doubling. Each time the number gets bigger than 14351, divide by 14351 and keep only the remainder. After 28 steps, the sequence is back to 1, and from there it repeats in the same order. The number of steps before a sequence starts over is called its period. Halfway through, at step 14, the number is 2033. Simple arithmetic turns that into the primes: the greatest common divisor of 2032 and 14351 is 127, and of 2034 and 14351 is 113.
For a real RSA lock, the sequence is far too long to watch, and finding the period is the hard part. In 1994, Peter Shor showed that a quantum computer could do it. His method, Shor's algorithm, doesn't try every key. It makes the right period stand out, and the rest is ordinary arithmetic. The lab shows the period lining up by winding the sequence around a circle and lighting the result, all calculated on an ordinary computer. It doesn't simulate a quantum computer. It only tests periods from 15 to 50, because numbers that divide evenly into 28, such as 14, 7 and 4, would line up too. Within that range, only 28 lines up.
Why the post-quantum lock holds
The lab's second lock follows a simpler rule: multiply the step number by 3, divide by 8 and keep the remainder. Without noise, that repeats every 8 steps, and the hidden number, 3, is easy to find. The lock protects it by adding a small error, from −2 to 2, to every number it gives out. The errors are a fixed set, so the comparison is the same every time. With the noise on, there's no clean repeat, so the same search finds nothing. Turning the noise off only shows what it protects. Turning it back on starts a new test; it can't make an already revealed number secret again.
Adding noise is one idea used in some post-quantum cryptography, which is designed to resist quantum computers. One real post-quantum standard, ML-KEM, published by NIST as FIPS 203, relies on a related but far more complex problem, called Module Learning with Errors, with carefully chosen parameters. It's believed to be hard for quantum computers as well as ordinary ones. A flat chart in a toy like this proves nothing about its security.
Why migration has to start early
Recording encrypted data now, in the hope of reading it later, is known as "harvest now, decrypt later". Whether any particular data is at risk depends on how it was encrypted, how it was captured and how long it must stay secret. This experience knows nothing about your own data.
Switching to post-quantum locks, called migration, takes years. The migration clock adds how long data must stay secret to how long migration takes, then compares the total with a guess for when a quantum computer could break RSA. The two times add up because data locked with RSA just before migration finishes still has to stay secret for years afterwards. If the total is longer than the guess, migration is already late; if they're equal, there's no room for delay. The arrival date is a guess, not a forecast.
What you can try
Watch the lab run a simple sequence of numbers through a small RSA lock, find its 28-step period, and use it to find the two primes and open a captured message. Then try the same search on a post-quantum lock, with its noise on and off, and compare the results. Finally, set three estimates on the migration clock to see when switching would need to begin.
Where the model stops
The lab runs on an ordinary computer. It shows how a repeat can be found and used; it doesn't simulate a quantum computer. Its second lock is a tiny example inspired by Learning with Errors, not RSA with noise added and not a secure version of ML-KEM, and a flat chart doesn't prove anything is secure. The migration clock is a planning tool built on your guesses, not a forecast, and not evidence that your own data has been taken.
Narration transcript
The narration as spoken in Act IV. The explanation above covers what the illustrations leave out.
You've probably heard how this ends: a quantum computer tries every key at once. It's a good story.
It's false, and the truth is stranger.
Nineteen forty-three. American codebreakers begin receiving Soviet cables they cannot read.
The encryption is unbreakable on the day each cable is sent.
They keep them anyway. Thousands of messages, filed into an archive that grows for years.
Patience is part of the attack.
Under wartime pressure, the Soviets print some of their secret code pages twice.
Two different messages pass through the same mask. The mistake is invisible when they are sent.
Years later, codebreakers place those messages together.
The repeated mask begins to cancel itself, and structure from the messages underneath starts to show.
The cables open. The spies inside are exposed
One of them, a physicist at Los Alamos, in the same halls where Feynman was cracking safes.
The messages outlived the promise that sealed them.
It is happening again, right now.
Encrypted traffic, some of it yours, is being recorded and stored. Not to read today. To read when the mathematics catches up.
The quantum threat is different, but the useful clue is simple.
Some hard problems hide a repetition inside a sequence that looks irregular.
A quantum computer can make the repeated parts reinforce one another while everything else fades.
It is not trying every key. It is making a pattern stand out.
And once the pattern is visible, the lock may not stay locked.
So what does that pattern sound like? You're about to listen.
Sources
- NSA — The VENONA Story
The NSA's history of VENONA: reused one-time-pad pages, years of analysis, and the spies it helped expose.
- IBM Quantum Learning — Shor’s algorithm
How Shor's algorithm uses a quantum computer to find a period, and the ordinary arithmetic that turns it into factors.
- NIST — FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard
NIST's standard for ML-KEM, a post-quantum method based on Module Learning with Errors.
- Rivest, Shamir and Adleman, A Method for Obtaining Digital Signatures and Public-Key Cryptosystems
How RSA builds a public lock from two secret primes.
- IBM, What is public key encryption?
That RSA is widely used.
- Peter Shor, Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer
Shor's 1994 result.
- NIST — What Is Post-Quantum Cryptography?
What post-quantum cryptography is, and why the move to it has begun.
- ETSI TR 104 016 V1.1.1 — A Repeatable Framework for Quantum-Safe Migrations (2024)
A repeatable framework for planning the move to quantum-safe cryptography.