When quantum computers can crack today's encryption, online banking, digital government, and every HTTPS connection become vulnerable overnight. To prepare for that day, three organizations from Japan and Canada have demonstrated a way to swap out the encryption underpinning the internet's trust system without a single second of downtime. Here's how they solved the "changing the locks while the door stays open" problem.
The Quantum Threat: Why Today's Encryption Has an Expiration Date
The security of the internet rests on "public key cryptography", the mathematical system that powers the padlock icon in your browser, secures your email, and authenticates every digital government service you use.
Current encryption methods like RSA and ECDSA rely on math problems so complex that traditional computers would need billions of years to crack them. But quantum computers, using an approach called Shor's algorithm, could solve these same problems in minutes. This isn't science fiction, Google published research in March 2026 showing that cracking elliptic curve cryptography (the backbone of ECDSA) will require far fewer quantum resources than previously estimated.
Perhaps more alarming is the "Harvest Now, Decrypt Later" threat. Adversaries are already collecting encrypted data today, planning to decrypt it once quantum computers become powerful enough. For medical records, military secrets, and financial data that needs protection for decades, this threat is already real.
The Global Race to Quantum-Resistant Encryption
The U.S. National Institute of Standards and Technology (NIST) spent eight years evaluating 82 algorithms from 25 countries before publishing three finalized post-quantum cryptography (PQC) standards in August 2024: ML-KEM for key exchange, ML-DSA for digital signatures, and SLH-DSA as a hash-based alternative.
Governments worldwide are setting firm deadlines. The U.S. NSA's CNSA 2.0 mandates quantum-resistant algorithms for national security systems by 2030. The European Union has published a coordinated roadmap requiring member states to begin transitioning by the end of 2026, with critical infrastructure fully migrated by 2030. Google has announced a 2029 target for migrating its authentication services to PQC, and all three major cloud platforms, AWS, Microsoft Azure, and Google Cloud, have already begun offering PQC-capable TLS connections.
Japan, too, has been positioning itself in this race, and just demonstrated one of the most practical solutions yet.
What Japan Just Proved: Migrating the Internet's Trust Infrastructure
TOPPAN Holdings (one of Japan's largest printing and technology conglomerates), NICT (Japan's National Institute of Information and Communications Technology), and ISARA Corporation (a Canadian quantum-safe security firm) have successfully demonstrated a seamless migration from current cryptography to PQC within the certificate authority (CA) system.
Why This Is Hard
A certificate authority is the trusted third party that issues digital certificates, the mechanism that guarantees "this website is really who it claims to be." These certificates form a chain of trust, anchored by a "root certificate" at the top.
Here's the dilemma: if you change the encryption algorithm of the root certificate, older devices that don't understand the new algorithm simply can't verify anything anymore, their connections break. But updating every device on Earth simultaneously is obviously impossible, and taking services offline during migration isn't acceptable either.
The "Second Root Certificate" Solution
ISARA developed a "Second Root Certificate", a hybrid certificate signed with both current encryption (ECDSA) and quantum-resistant encryption (ML-DSA). This clever approach means:
- Legacy devices continue verifying certificates using the familiar ECDSA signature, nothing breaks
- Updated devices can use the ML-DSA signature for quantum-resistant verification
- Both work simultaneously, enabling a gradual, zero-downtime migration
Three-Phase Validation
The team tested this on NICT's quantum cryptography network testbed using TOPPAN's IC card authentication system, validating three migration phases:
- Phase 1: Legacy-only environment (current encryption), confirmed normal operation
- Phase 2: Hybrid environment (current + PQC coexisting), confirmed compatibility
- Phase 3: Full PQC environment, confirmed complete migration
IC card authentication and web access worked flawlessly across all three phases, proving that seamless, disruption-free migration is achievable.
Where Japan Fits in the Global PQC Picture
This demonstration was conducted under Japan's Cabinet Office SIP program ("Application Promotion of Advanced Quantum Technology Platforms to Social Challenges"), reflecting the government's strategic prioritization of quantum technology.
What sets this work apart from many PQC initiatives worldwide is its focus on the practical "how" rather than the theoretical "what." NIST has standardized the algorithms, but figuring out how to deploy them into existing, running PKI infrastructure without breaking anything is an entirely different engineering challenge, and that's exactly what this collaboration tackled.
The consortium is now targeting real-world deployment in healthcare and finance, aiming for full-scale social implementation around 2030. TOPPAN plans to extend this migration approach beyond IC cards to web services, IoT devices, and other systems.
How Close Is the Quantum Threat?
Experts at the Global Risk Institute estimate that a cryptographically relevant quantum computer is quite possible within 10 years and likely within 15. Google's own research suggests the hardware requirements are lower than once assumed. The consensus among security professionals has shifted from "someday" to "we need to start now", since a full enterprise PQC migration typically takes two to five years.
Meanwhile, the "harvest now, decrypt later" clock has already been ticking. Every day that sensitive data travels over quantum-vulnerable encryption is a day that data becomes potentially recoverable in the future.
Japan's demonstration shows that the tools for migration exist and work in practice, the question now is how quickly organizations around the world will begin using them.
How far along is your country's preparation for the quantum encryption transition? What are your government and industry doing to get ready? We'd love to hear your perspective.
Global Discussion
15 comments