Post-Quantum Cryptography and Crypto-Agility for CompTIA SecurityX (CAS-005)
Every TLS handshake, VPN tunnel, and signed firmware update running today relies on math problems that classical computers can't solve in a reasonable amount of time — mainly integer factorization and discrete logarithms. A sufficiently powerful quantum computer would solve both quickly, which is why CompTIA added post-quantum cryptography and crypto-agility to the SecurityX (CAS-005) exam's Security Engineering domain. This guide breaks down what you actually need to know, in the depth CAS-005 expects.
Why Post-Quantum Cryptography Matters Now
No cryptographically relevant quantum computer exists yet, so it's tempting to treat this as a future problem. SecurityX candidates need to think like architects, not just administrators: data encrypted today with RSA or elliptic curve cryptography (ECC) can be captured now and decrypted later, once quantum hardware catches up. For data with a long confidentiality shelf life — medical records, government secrets, trade secrets, long-lived signing keys — "later" is close enough to matter today. That's the entire justification for migrating before the threat is fully realized, and it's exactly the kind of forward-looking risk reasoning CAS-005's Governance, Risk and Compliance domain also tests.
Shor's Algorithm, Grover's Algorithm, and the Quantum Threat
Two algorithms explain why quantum computing breaks modern cryptography differently depending on the algorithm family:
- Shor's algorithm efficiently factors large integers and solves discrete logarithm problems, which breaks RSA, Diffie-Hellman, and ECC outright. These are the asymmetric algorithms underpinning most key exchange and digital signatures today.
- Grover's algorithm provides a quadratic speedup against symmetric key search, which weakens but does not break algorithms like AES. The practical fix is doubling key length — AES-256 remains considered quantum-resistant, while AES-128 does not provide an adequate margin.
Expect CAS-005 scenario questions to test whether you know which algorithm family is vulnerable to which quantum attack, and why symmetric cryptography needs a much smaller adjustment than asymmetric cryptography.
Harvest Now, Decrypt Later: The Risk Hiding in Today's Traffic
"Harvest now, decrypt later" (HNDL) describes an adversary — frequently a nation-state — recording encrypted traffic today with the intent of decrypting it once quantum capability exists. This threat model is closely related to the forward secrecy concepts covered in our forward secrecy and harvest-now-decrypt-later article: perfect forward secrecy protects individual sessions if a long-term key is later compromised, but it does nothing against an adversary who simply waits for the underlying algorithm itself to be broken. On the exam, HNDL is the scenario cue CompTIA uses to justify starting post-quantum migration now rather than waiting for "Q-Day," the point at which quantum computers can realistically break current public-key cryptography.
NIST's Post-Quantum Standards: ML-KEM, ML-DSA, SLH-DSA, and FN-DSA
In August 2024, NIST finalized the first set of post-quantum cryptography (PQC) standards after an eight-year public evaluation process. CAS-005 expects you to recognize these by name:
- ML-KEM (FIPS 203), based on CRYSTALS-Kyber, is a module-lattice-based key encapsulation mechanism used for key exchange — the post-quantum replacement for Diffie-Hellman and ECC-based key agreement.
- ML-DSA (FIPS 204), based on CRYSTALS-Dilithium, is a module-lattice-based digital signature algorithm and NIST's primary recommended signature scheme.
- SLH-DSA (FIPS 205), based on SPHINCS+, is a stateless hash-based signature scheme. It's larger and slower than ML-DSA but relies on different mathematical assumptions, giving defenders a backup if lattice-based cryptography is ever broken.
- FN-DSA, based on FALCON, is a compact lattice-based signature scheme finalized separately for size-constrained use cases.
These algorithms will show up on CAS-005 primarily as recognition questions — matching the algorithm family (lattice-based vs. hash-based) to its use case (key exchange vs. signing) and understanding why NIST standardized more than one signature option instead of a single winner.
Crypto-Agility: Designing Systems That Can Swap Algorithms
Crypto-agility is the architectural property that lets an organization replace a cryptographic algorithm, key length, or protocol version without redesigning the entire system. For CAS-005's Security Architecture and Security Engineering domains, crypto-agility is as much about design discipline as it is about cryptography itself. Practical crypto-agility includes:
- Abstracting cryptographic operations behind libraries or APIs instead of hardcoding specific algorithms throughout an application.
- Centralizing key management, including PKI issuance and revocation, so that algorithm changes don't require touching every endpoint individually.
- Maintaining an inventory of where every cryptographic algorithm is used — including embedded systems and legacy protocols — so that a deprecated algorithm (like the vulnerabilities covered in our cryptographic vulnerabilities article) can actually be located and retired.
- Testing failover and rollback procedures before an algorithm is deprecated, not after it's compromised.
Crypto-agility is what keeps an HNDL risk from becoming a crisis: an organization that can swap algorithms quickly is far less exposed than one locked into a single implementation.
Hybrid Cryptography and Migration Strategy
Because post-quantum algorithms are newer and less battle-tested than RSA or ECC, most real-world migrations use hybrid cryptography: a classical algorithm and a post-quantum algorithm run side by side, and the session is only considered secure if both hold up. This hedges against two risks simultaneously — an unforeseen quantum breakthrough on the classical side, and an undiscovered weakness in the newer post-quantum math. A typical migration path looks like this:
- Inventory cryptographic assets and classify data by confidentiality shelf life to prioritize what needs protection first.
- Pilot hybrid key exchange (classical plus ML-KEM) on high-value, long-lived traffic such as VPN and TLS termination points.
- Update hashing and digital signature infrastructure, since code signing and firmware validation have long trust lifespans and are common HNDL targets.
- Track vendor and protocol support (TLS 1.3 extensions, HSM firmware, PKI tooling) since many organizations are dependent on third parties updating before they can fully migrate.
This mirrors how our hashing algorithms guide frames algorithm selection generally: pick based on the threat model and performance constraints, not just because an algorithm is new.
CAS-005 Exam Tips
- Know which algorithm family each named standard belongs to: ML-KEM is key encapsulation (confidentiality/key exchange), while ML-DSA, SLH-DSA, and FN-DSA are signatures (authenticity/integrity). Don't mix up "encapsulation" with "signature" on scenario questions.
- If a question describes an adversary recording traffic for future decryption, the answer is almost always pointing at harvest-now-decrypt-later and justifies early PQC migration, not a "wait and see" approach.
- Remember that Grover's algorithm only weakens symmetric cryptography (favor AES-256), while Shor's algorithm breaks asymmetric cryptography outright (RSA, Diffie-Hellman, ECC all need PQC replacements).
- Expect crypto-agility to appear as a design requirement in architecture scenarios, often phrased around minimizing future migration cost or avoiding vendor lock-in — similar reasoning to asymmetric encryption key management decisions, just applied at an algorithm-lifecycle level.
- Hybrid cryptography (classical + post-quantum together) is the real-world transition approach CompTIA expects you to recommend, not an immediate full cutover to PQC-only systems.
Key Takeaways
- Shor's algorithm breaks asymmetric cryptography (RSA, Diffie-Hellman, ECC); Grover's algorithm only weakens symmetric cryptography, which AES-256 already absorbs.
- Harvest-now-decrypt-later is the threat model that justifies migrating to post-quantum cryptography before quantum computers are actually capable of breaking current algorithms.
- NIST finalized ML-KEM (FIPS 203) for key exchange and ML-DSA (FIPS 204), SLH-DSA (FIPS 205), and FN-DSA for digital signatures in August 2024.
- Crypto-agility is the architectural ability to swap cryptographic algorithms without a full system redesign — a core CAS-005 design requirement.
- Hybrid cryptography, combining classical and post-quantum algorithms, is the standard real-world migration strategy and the answer CAS-005 scenario questions are usually steering you toward.
Comments
Post a Comment