出典:MIT Tech Review · AI原文を見る ↗
原文の著作権は出典元に帰属します。当サイトでは収録、翻訳、体裁調整のみを行います。
メディア:0件確認済み、1件は出典のみ
事実関係
解説と影響
导读摘要
量子计算在技术圈长期游走于“突破性明星”与“过度承诺”之间。其强大的计算能力确实对当前广泛使用的公钥加密算法(如 RSA 与 ECC)构成理论上的破解威胁——一旦足够规模的容错量子计算机问世,基于大数分解和离散对数难题的加密体系将不再安全。但对于企业管理者而言,MIT Technology Review 指出,这并不意味着需要立即、全面地将所有系统切换到后量子算法。
报道强调,务实的过渡路径应当从“加密资产盘点”开始。企业首先需要识别哪些系统依赖易受量子攻击的算法,哪些数据具有长期保密价值——即所谓“现在截获、日后解密”的风险场景。在此基础上,再按照风险优先级分阶段替换,而非一次性推翻现有基础设施。原文未提供具体的算法清单或实施时间表,但核心逻辑是:将后量子迁移视为一个持续数年的工程管理问题,而非单一的技术切换事件。
从行业背景看,美国国家标准与技术研究院(NIST)此前已发布多轮后量子密码学标准草案,为算法替换提供了技术基准。与此同时,围绕加密与监控的公共讨论也在升温——例如近期 The Guardian 报道了美国政府针对左翼及反 ICE 抗议者的大规模监控行动,这从侧面说明加密技术的现实社会意义远超纯技术范畴。量子威胁虽然尚未成为当下最紧迫的安全事件,但其长期影响要求组织尽早建立过渡意识。
参考資料
出典原文
Quantum computing has alternated between breakthrough darling and overhyped promise in technology circles. Its powerful new capabilities come with a threat to break current cryptography, but for business leaders navigating the noise, the signal should be clear: post-quantum cryptography (PQC) is a manageable evolution, not a crisis.
The mathematics behind today’s encrypted digital transactions may yield to quantum computers one day, but the transition to quantum-resistant algorithms is neither sudden nor insurmountable. For executives concerned about disruption, cost, or complexity, a structured and phased approach exists with trusted technology partners like Intel that are already beginning to deliver the infrastructure to make it possible.
A natural evolution, not a cliff edge
The “quantum threat” narrative often swings between two extremes: imminent catastrophe or distant irrelevance. The reality occupies a more pragmatic middle ground. Quantum computers are highly specialized accelerators that exploit quantum physics to solve specific hard problems. They have the potential to crack modern encryption, but they will not replace classic servers overnight, nor will they instantly break every encryption protocol on the internet. What they will do is gradually shift the security landscape, much as previous cryptographic transitions have done over the past three decades.
In late 2024, the Global Risk Institute, a Toronto-based financial services think tank, surveyed 32 quantum computing experts on when a quantum computer could break a 2048-bit RSA key within 24 hours. An average of optimistic and pessimistic estimates from the experts gave it an even 50-50 probability of reaching this code-breaking milestone by 2040. This timeline, uncertain but measurable, creates space for deliberate planning rather than emergency reaction. The near-term focus should be on “harvest now, decrypt later” scenarios, where adversaries collect encrypted data today and then hold it for future decryption later when that capability becomes possible. This is particularly applicable for information requiring confidentiality beyond 10 years.
For most enterprises, this can be a manageable risk when addressed through methodical modernization.
Government signals as confidence builders
The U.S. government has issued new directives for National Security Systems (NSS), which would likely be first on the list for potential quantum attack. Beginning in January 2027, new NSS acquisitions must be capable of supporting Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requirements for PQC algorithms standardized by the National Institute of Standards and Technology (NIST) and selected by the National Security Agency, the U.S. intelligence agency responsible for signals intelligence and information assurance. Implementation for new systems (with certain exceptions) is then required by 2031, with 100% adoption targeted by 2035.
For commercial enterprises, these timelines are not mandates, but could be signposts. They indicate where vendors, standards bodies, and auditors are headed, providing a reference architecture for responsible stewardship. Organizations can borrow this discipline without necessarily copying the exact timelines, using government guidance to calibrate their own risk tolerance and investment cadence.
Intel’s role: Infrastructure ready for the transition
Intel is at the heart of the AI revolution by delivering quantum-resistant capabilities across our product portfolio. This is not just aspirational roadmap language; it is starting to be shipping technology.
For instance, the Intel Xeon 6 Processor already incorporates quantum-safe memory encryption (AES-256) and microcode signing to protect processor integrity. Upcoming platforms will extend post-quantum algorithms to more firmware and software signing, device interconnects, attestations, and secure boot functions, aligning with the most stringent government and industry directives.
Post-quantum algorithms carry different key sizes and computational overhead than legacy methods. Intel addresses this through dedicated cryptographic accelerators, optimized libraries, and specialized CPU instructions that reduce latency and preserve service-level agreements. Technologies such as Intel QuickAssist Technology offload cryptographic workloads, enabling enterprises to adopt stronger algorithms without sacrificing performance.
PQC is not a processor-alone problem. System builders and application owners must take a comprehensive view spanning solid-state drives, network interface cards, operating systems, hypervisors, applications, and connected services. Intel is delivering its pieces of the stack, while collaborating with ecosystem partners to ensure interoperability and smooth transition paths.
A more in-depth discussion of post-quantum algorithms and attacks can be found in my recent blog posted on Intel’s Community forum: “Post-Quantum Crypto: Panic Like It’s 1999?“
A practical roadmap for enterprises
The path forward does not require upheaval, just discipline. Organizations can follow a phased approach that mirrors patterns emerging in government and critical infrastructure sectors:
Approach PQC as modernization, not mitigation. Frame the transition as an opportunity to strengthen cryptographic foundations, reduce technical debt, and improve system maintainability.
Leverage trusted partners. Technology suppliers like Intel are already shipping quantum-resistant capabilities with performance acceleration. Evaluate platform readiness and vendor roadmaps as part of procurement decisions.
Start with visibility. Cryptography is embedded throughout modern technology stacks: not just in database encryption settings but in data at rest, data in transit, digital signatures, code signing, device identity, password hashing, and software update mechanisms. Start by mapping where cryptographic assets live, what algorithms protect them, and which data sets have the longest confidentiality requirements.
Protect long-lived data first. Not all cryptographic uses age at the same rate. Encryption protecting long-lifespan intellectual property, personal data, or state secrets faces more immediate attention than short-lived session keys or rotating certificates. Focus initial investments on high-value, long-retention data stores and the trust anchors (root certificates, firmware signing keys) that underpin system integrity.
Design for evolution and agility. Post-quantum algorithms are not simple drop-in replacements. They carry different key sizes, performance characteristics, and integration requirements that ripple through protocols, APIs, and hardware. Design systems that can transition algorithms without business disruption: testing compatibility, ensuring vendor roadmaps align, and engineering for rotation.
The bottom line
Quantum computing will reshape cryptography, but despite what occasional click-bait headlines say, it will not upend business overnight. The transition to post-quantum algorithms is a measured, multi-year journey, one that organizations can navigate with confidence by partnering with capable technology providers, prioritizing long-lived data, and designing for agility. Leaders who approach this as an engineering evolution rather than a threat response will not only be ready for whatever timeline quantum delivers; they will emerge with more robust, transparent, and maintainable cryptographic foundations across their platforms.
This content was produced by Intel. It was not written by MIT Technology Review’s editorial staff.