SolveFor42 Research Publication No. 1Post-Quantum Cryptography

Hiding Secrets in the Dimensions

Understanding Post-Quantum Cryptography Through Geometry — and Why Businesses Need to Prepare Now

Author
Jeff Campbell
Published
July 25, 2026
Reading time
18 minutes

Executive Summary

Encryption is the invisible trust layer under modern business. It protects banking, healthcare, remote work, software updates, identity systems, private communications, cloud services, backups, APIs, and vendor integrations.

For decades, much of public-key security has relied on mathematical problems that ordinary computers find extremely difficult to reverse. RSA, Diffie-Hellman, and elliptic-curve cryptography are not protected because their handshakes are hidden. They are protected because the public information exposed during those handshakes should not be enough to recover the private secret.

Quantum computing changes that assumption for specific families of cryptography. Shor’s algorithm is not merely faster brute force. It is a different mathematical shortcut that can expose hidden structure in RSA, Diffie-Hellman, and elliptic-curve systems once sufficiently powerful fault-tolerant quantum computers exist.

The most urgent issue is not panic-driven replacement. It is visibility: knowing where cryptography lives.

Why This Matters Now

The post-quantum discussion is no longer only theoretical. Standards now exist. Vendors are beginning to implement them. Government guidance recommends readiness roadmaps, cryptographic inventories, vendor engagement, and migration planning.

The harder question is whether an organization knows enough about its own environment to migrate when it needs to.

The Invisible Trust Layer

In a modern business, cryptography is not one system. It exists throughout certificates, TLS endpoints, VPN tunnels, APIs, databases, identity systems, cloud platforms, software pipelines, and vendor services.

Post-quantum readiness is therefore not only a cryptography problem. It is also an infrastructure, application, vendor, procurement, compliance, and long-term risk-management problem.

How Key Exchange Really Works

Modern encryption assumes that an attacker may observe the conversation.

The secret is not protected because the attacker cannot see the handshake. It is protected because the handshake exposes public mathematical material while private information remains private.

The systems do not send the finished session key across the network. Each side combines public information with its own private information and independently arrives at the same shared secret.

Why Quantum Changes the Rules

Quantum computers do not make every difficult problem easy.

For particular mathematical problems, however, they change the battlefield. Shor’s algorithm gives a sufficiently capable quantum computer a shortcut through the mathematical structures used by RSA, Diffie-Hellman, and elliptic-curve cryptography.

The threat is therefore not simply that quantum computers may be faster. It is that they can use a different type of algorithm against the assumptions underlying current public-key systems.

Harvest Now, Decrypt Later

An attacker does not need to decrypt sensitive information immediately.

Encrypted traffic, medical records, legal files, intellectual property, source code, identity data, or government communications can be captured today and retained until better tools become available.

If information remains valuable for years or decades, the risk begins before a cryptographically relevant quantum computer exists.

Post-Quantum Cryptography in Plain English

Post-quantum cryptography does not mean cryptography that runs on a quantum computer.

It means cryptography designed to run on ordinary computers while resisting attacks from both ordinary and quantum computers.

In many deployments, symmetric encryption such as AES or ChaCha20 will continue protecting application data. The post-quantum change occurs primarily in key establishment and digital signatures.

The Three NIST Standards

Standard Plain-English role Where it may matter
ML-KEM Helps two systems establish a shared secret. TLS, VPNs, IPsec, APIs, and cloud connections
ML-DSA Creates digital signatures proving authenticity and integrity. Certificates, code signing, firmware, and identity
SLH-DSA Creates hash-based digital signatures. Long-term, specialized, and high-assurance signing

A Dot-Grid Exercise

Begin with a flat grid of dots. Each dot has a two-dimensional address, such as:

(2, 1)

Add stacked layers, and a location may be described using three coordinates:

(2, 1, 4)

After the third dimension, stop looking for another physical direction. Instead, think of each additional coordinate as another attribute that narrows the address.

A high-dimensional address can be understood as a highly specific description containing hundreds or thousands of components.

From Dimensions to Lattices

A lattice is a structured collection of points in a high-dimensional space.

The structure permits legitimate users to perform useful operations while making certain problems extremely difficult without secret information.

The legitimate user has information that makes the structure manageable. An attacker sees public information but faces a difficult geometric problem across an enormous space.

The Role of Noise

Lattice-based cryptography intentionally introduces noise.

The answer is moved slightly away from a clean and obvious point. Someone with the appropriate secret can manage that displacement. Someone without the secret must recover a precise relationship across many dimensions while deliberate uncertainty obscures the target.

What This Means for Business Leaders

Business leaders do not need to become cryptographers.

They need a practical way to:

  • identify where cryptography is used;
  • classify information by secrecy lifetime;
  • understand vendor dependencies;
  • identify systems that cannot be upgraded easily;
  • evaluate crypto-agility;
  • and plan migration before an emergency.

A Practical Readiness Roadmap

  1. Create a cryptographic inventory.
  2. Classify data by secrecy lifetime.
  3. Identify harvest-now-decrypt-later exposure.
  4. Ask vendors for their post-quantum roadmaps.
  5. Evaluate crypto-agility.
  6. Test hybrid post-quantum options.
  7. Update procurement language.
  8. Document exceptions.
  9. Build a staged migration plan.
  10. Revisit the plan regularly.

Conclusion

Quantum computing does not mean the internet ends.

It does mean that assumptions underlying much of today’s public-key cryptography are changing.

The next generation of digital security will not be won by organizations that panic first. It will be won by those that prepare before the emergency.

The math may be complicated. The responsibility is not.

Find where encryption lives. Understand what must stay secret. Ask vendors hard questions. Build crypto-agility. Test early. Migrate deliberately.

Suggested Citation

Campbell, Jeff. Hiding Secrets in the Dimensions. SolveFor42 Research Publication No. 1, 2026.