Quantum Safe Bangladesh Dancing with qubits

Post-quantum cryptography

The data being copied today will be read later

An adversary does not need a quantum computer now. They need your encrypted traffic now, and a quantum computer eventually. For records that must stay secret for a decade — citizen identity, land titles, health, financial and diplomatic data — the deadline has already passed.

b₁ b₂ shortest?
Given two long vectors, find the shortest one they generate. Easy to state, hard to solve at scale — and now the foundation under the encryption standard the world is migrating to.
Finalised standards FIPS 203 · 204 · 205 Backup KEM selected HQC, March 2025 In development FIPS 206 (FN-DSA)

The shape of the problem

Harvest now, decrypt later

Encrypted traffic can be recorded cheaply and stored indefinitely. Whenever a cryptographically relevant quantum computer arrives, everything held in that archive is opened at once — retroactively, including data sent today.

RSA · ECC Public-key algorithms that Shor's algorithm breaks. They protect nearly every session, signature and certificate in use today.
AES · SHA-2 Symmetric and hash algorithms are weakened, not broken. Larger key and digest sizes are the usual answer.
10+ years Secrecy lifetime of national identity, land, health and financial records — the measure that decides how urgent your migration is.
The question is not when a quantum computer arrives. It is how long your data must stay secret, plus how long your migration takes. If those two numbers together exceed the time remaining, you are already late. Mosca's inequality, in plain terms

Standards

What is final, and what is not

Status precision matters here. Final, draft, selected and candidate are not synonyms, and a migration plan should say which one it is relying on.

StandardAlgorithmPurposeStatus
FIPS 203 ML-KEM (from CRYSTALS-Kyber) Key encapsulation — the replacement for RSA and ECDH key establishment. Final · Aug 2024
FIPS 204 ML-DSA (from CRYSTALS-Dilithium) Digital signatures — the general-purpose replacement for RSA and ECDSA signing. Final · Aug 2024
FIPS 205 SLH-DSA (from SPHINCS+) Hash-based signatures — conservative, stateless, useful for firmware and long-lived roots. Final · Aug 2024
FIPS 206 FN-DSA (from FALCON) Compact lattice signatures for bandwidth-constrained protocols and certificates. In development
— HQC Code-based backup KEM, chosen for mathematical diversity against ML-KEM. Selected · Mar 2025

We avoid the words unbreakable and future-proof. Post-quantum algorithms are designed and believed to resist known classical and quantum attacks; they remain subject to cryptanalysis, implementation error and revision, like all cryptography. Crypto-agility — the ability to swap an algorithm without rebuilding the system — is the part of this work that keeps paying off.

How we work

Five steps, in this order

Most organisations cannot say where their keys are. That is the first deliverable, and it is the one everything else depends on.

Discover

Build a cryptographic bill of materials: every certificate, key store, VPN, HSM, database at rest, signing pipeline and embedded device. Which algorithm, which key length, which expiry, which owner. Automated scanning plus interviews, because the undocumented systems are the risky ones.

Rank by secrecy lifetime

Sort assets by how long their contents must stay confidential and how long their signatures must stay trustworthy. A one-hour session token and a citizen's biometric record do not carry the same urgency. This ranking becomes the migration order.

Make the system agile

Isolate cryptography behind interfaces so an algorithm can be replaced without touching business logic. In many systems this refactor is the largest piece of work — and it is also the piece that survives the next standards change.

Pilot in hybrid

Deploy hybrid key exchange — a classical and a post-quantum KEM together — so security holds if either one fails. Measure the real cost: handshake size, latency, certificate chain growth, HSM support, and what breaks on older clients.

Re-issue and retire

Move the PKI: new roots and issuing certificates with post-quantum signatures, staged re-issuance, and a dated plan to withdraw the classical-only paths. Then keep the inventory alive, because it goes stale in months.

Where it matters here

Bangladeshi systems with long-lived secrets

These are the places where secrecy lifetime, national dependence and cryptographic sprawl all overlap.

Finance

Banking and mobile money

Interbank transfer rails, card networks, mobile financial services and the HSM estate behind them. High transaction volume, strict latency budgets, and regulatory retention measured in years.

Identity

National ID and land records

Biometrics cannot be reissued, and a land title must remain provable for generations. Signature longevity, not just confidentiality, is the exposure here.

Infrastructure

Telecom, e-government and PKI

Certificate authorities, e-procurement, government service gateways and the long-lived device certificates in telecom and power networks, where firmware signing outlives the hardware refresh cycle.

Engagements

Four ways to start

Each one is scoped to produce a document your board, your regulator and your engineers can all use.

Readiness assessment
Four to six weeks. Where you stand against the finalised standards, what your exposure window looks like, and what to do in the first year.
Cryptographic inventory
A living CBOM of algorithms, keys, certificates and owners across your estate, with the tooling to keep it current.
Migration roadmap
A sequenced, costed plan tied to your systems and your regulator's expectations — including what you deliberately defer, and why.
Training
Workshops for engineering and risk teams: what changed, what a hybrid handshake actually costs, and how to review a vendor's PQC claims.

Questions we get

Before you commission anything

Nobody has a quantum computer that can break RSA. Why now?
Because the archive is being built now, and because migration is slow. Replacing public-key cryptography across a national banking or identity system takes years of inventory, refactoring and re-issuance. The work has to start before the threat lands, not after.
Can we wait for the remaining standards?
The three standards you need for key establishment and signatures were finalised in August 2024. HQC and FN-DSA add diversity and compactness later. Waiting for them delays the inventory and refactoring work, which is the part that takes the longest and does not depend on which algorithm you finally choose.
Our vendor says their product is already quantum-safe. Is it?
Ask three questions: which FIPS-validated implementation, in which mode, covering which part of the traffic. A product can support ML-KEM in one protocol and still terminate every other session on classical-only cryptography. We review those claims as part of an assessment.
Does this connect to the agricultural platform?
Only in the mathematics — both rest on lattices — and in the group that works on them. Operationally they are separate engagements with separate teams and separate data.

Find out where your keys are

The first conversation is short and free. Bring one system you care about, and we will tell you what an inventory of it would involve.