PQC & Cryptography
Inventory, hybrid key exchange, cert migration, HNDL defense.
Harvest-now-decrypt-later is already in your threat model — this is the migration map.
Cryptographic Inventory
You cannot migrate what you have never actually catalogued.
Hybrid Key Exchange
Neither algorithm alone is fully trusted yet — that’s exactly the point.
Certificate Migration to PQC
Cross-signed certificates let old and new trust chains coexist during the transition.
Harvest-Now-Decrypt-Later Defense
The data being stolen today is being stolen for a decryption key that doesn’t exist yet.
VPN Migration to PQC
A VPN tunnel that outlives the classical algorithm protecting it is a tunnel worth re-examining today.
Quantum Key Distribution
Eavesdropping on this channel doesn’t just risk detection — it physically disturbs the very thing being measured.
PQC Algorithm Selection Framework
Standardized doesn’t mean interchangeable — each algorithm trades off differently.
Code-Signing Migration to PQC
Code signed today may still need to verify as authentic a decade from now.
PQC in IoT and Embedded Devices
A device with no field-upgrade path has effectively already made its cryptographic decision for its entire operational life.
Crypto-Agility Architecture
The next migration should be a configuration change, not a rewrite.