后量子密码学时间表:企业何时需要开始迁移?
Post-Quantum Cryptography Timeline: When Should Enterprises Start Migration?
| iDev PR | 2026-08-28T09:20:01
量子计算威胁正在从理论走向现实。本文分析后量子密码学(PQC)标准化进展,评估量子威胁时间表,并为企业制定密码学迁移路线图提供建议。
Quantum computing threats are moving from theory to reality. This article analyzes post-quantum cryptography (PQC) standardization progress, evaluates the quantum threat timeline, and provides guidance for enterprise cryptography migration roadmaps.
量子威胁的现实化2026年,全球多家量子计算公司宣布在量子纠错方面取得突破性进展。虽然能够破解当前加密体系的通用量子计算机尚未出现,但「先存储后解密」(Store Now, Decrypt Later)攻击的风险已经是现实威胁——攻击者现在截获加密数据,等待量子计算机成熟后再进行解密。PQC 标准化进展NIST 于2024年正式发布了首批后量子密码学标准,包括:ML-KEM(原 CRYSTALS-Kyber):基于格密码的密钥封装机制,用于密钥交换ML-DSA(原 CRYSTALS-Dilithium):基于格密码的数字签名算法SLH-DSA(原 SPHINCS+):基于哈希的数字签名算法,作为备选方案威胁时间表评估业界对「密码学相关量子计算机」(CRQC)的出现时间预测差异较大。乐观估计为2030年至2035年,保守估计为2040年以后。但考虑到大型企业的密码学迁移通常需要5到10年,即使按保守估计,现在也应该开始准备。企业迁移建议我们建议企业采取分阶段的迁移策略。首先进行密码学资产盘点,识别所有使用 RSA 和 ECC 的系统和数据。其次对高价值长期数据(如医疗记录、政府机密、知识产权)优先启用混合加密模式(同时使用传统算法和PQC算法)。最后制定完整的迁移路线图,逐步将所有系统升级到后量子密码学标准。
Quantum Threats Becoming RealityIn 2026, multiple global quantum computing companies announced breakthrough progress in quantum error correction. While universal quantum computers capable of breaking current encryption systems have not yet appeared, the risk of 'Store Now, Decrypt Later' attacks is already a present threat -- attackers intercept encrypted data now, waiting for quantum computers to mature before decrypting it.PQC Standardization ProgressNIST officially published its first batch of post-quantum cryptography standards in 2024, including:ML-KEM (formerly CRYSTALS-Kyber): Lattice-based key encapsulation mechanism for key exchangeML-DSA (formerly CRYSTALS-Dilithium): Lattice-based digital signature algorithmSLH-DSA (formerly SPHINCS+): Hash-based digital signature algorithm as a backup optionThreat Timeline AssessmentIndustry predictions for the emergence of 'Cryptographically Relevant Quantum Computers' (CRQC) vary significantly. Optimistic estimates place it between 2030 and 2035, while conservative estimates suggest after 2040. However, given that cryptographic migration for large enterprises typically takes 5 to 10 years, preparation should begin now even under conservative estimates.Enterprise Migration RecommendationsWe recommend enterprises adopt a phased migration strategy. First, conduct a cryptographic asset inventory to identify all systems and data using RSA and ECC. Next, prioritize enabling hybrid encryption modes (simultaneously using traditional and PQC algorithms) for high-value long-term data such as medical records, government secrets, and intellectual property. Finally, develop a comprehensive migration roadmap to gradually upgrade all systems to post-quantum cryptography standards.