29 Oct Encryption’s new dawn
Dr Víctor Mateu, Chief Researcher of the Cryptography Research Center at the Technology Innovation Institute, considers what the HQC Standard means for the future of cryptography.
The US National Institute of Standards and Technology (NIST), which has been working on finding algorithms to withstand cyberattacks that could come from quantum computers, recently selected HQC, a cryptographic algorithm built on code-based security, as its fifth and latest post-quantum cryptography (PQC) standard, a critical milestone for the global cryptographic community.
The rise of quantum computing poses a fundamental challenge to today’s public-key cryptographic systems. Algorithms currently safeguarding global digital infrastructure, from banking transactions to healthcare information, could one day be rendered obsolete by sufficiently advanced quantum machines. That’s why the standardisation of quantum-resistant algorithms has become one of the most consequential undertakings in cybersecurity today. That urgency is what makes NIST’s selection of HQC so significant.
As the world prepares for the era of quantum computing, one of the building blocks of secure communication is the Key Encapsulation Mechanism (KEM), a method used to safely exchange encryption keys between two parties.
HQC, short for Hamming Quasi-Cyclic, is a promising KEM that takes a different approach from most early post-quantum standards. Many of the standards selected by NIST rely heavily on lattice-based mathematical techniques, which secure data using complex geometric structures called lattices. But HQC relies on a fundamentally different approach focused on error-correcting code-based cryptography.
Code-based cryptography is built on the challenge of decoding scrambled messages, a technique widely used in data storage and satellite communications. HQC’s resilience stems from mature, well-studied principles, now tailored for post-quantum security, which makes it more trustworthy.
The inclusion of HQC by NIST marks a deliberate step toward algorithmic diversity. It mitigates systemic risks that might arise if vulnerabilities were discovered in any single family of cryptographic assumptions. This diversification offers a way to build a more resilient and secure global cryptographic ecosystem.
Protecting communications against quantum attacks is one of the most urgent challenges of our time. Creating secure algorithms is only half the battle, trying to break them is the other. That’s why investment in cryptanalysis is just as important as innovation.
This dual focus on design and validation reflects a core belief, at the Technology Innovation Institute (TII) and within the broader community, that the resilience of future cryptographic standards will rest on both creativity and on scrutiny.
Standards like HQC are born from rigorous peer review, iterative improvement and a global, collective effort grounded in transparency. For example, HQC was initially developed by a group of researchers coming from several French universities including the University of Limoges and University of Toulon as well as from research centres such as TII.
As quantum computing evolves from theoretical possibility to practical reality, the cryptographic community must continue to act with both urgency and caution.
The adoption of HQC is a milestone. But it is not an endpoint.
As quantum technology progresses, our cryptographic defenses must evolve. Standardisation should remain a living process, shaped by ongoing research, open collaboration and continual scrutiny.
Standards matter because they shape the future of secure communication. Finding the right standards has become central to the mission to help guide a safer digital world in the face of quantum uncertainty.
Sorry, the comment form is closed at this time.