Insider Brief
- Atsign has integrated NIST-approved post-quantum cryptography into its core SDKs to help developers protect applications and data flows against quantum threats.
- The update is designed to support new applications, existing application modernization, and legacy systems that cannot be modified through Atsign’s NoPorts service.
- Atsign says the integration provides a path to post-quantum protection without requiring a full application rewrite, with its development work publicly available through GitHub.
Press release – Atsign today announced the integration of NIST-approved, Post-Quantum Cryptography (PQC) across its core SDKs. The integration gives developers and enterprise teams a zero-code-rewrite path to protecting sensitive data flows against emerging quantum threats.
Breaking the key elements of current cryptographic techniques, such as digital signatures, digital identity and key exchange, is beyond the reach of today’s computers. But quantum computers sufficiently powerful to break these asymmetric algorithms are widely expected to emerge by the early 2030s, turning today’s impractical attack into a viable attack in just a few years.
But, as numerous governments and cybersecurity agencies have already warned, the prospect of a quantum computing future poses a real threat now due to “harvest now, decrypt later” (HNDL) attacks. HNDL describes the capture and storage now of secrets or data that need to remain secret, or will still have value, well beyond the date by which quantum computing will be able to decrypt them. Bad actors are stealing and storing encrypted such secrets and data now, intending to decrypt them just as soon as sufficient quantum computing power becomes available.
As a result, and in a scenario not dissimilar to but arguably more serious than the Year 2000 Problem of the 1990s, organizations must consider more than just new application development. They must also identify where quantum-vulnerable cryptography is used across existing applications, code, and devices, then update, test or replace those systems.
For many organizations, post-quantum integration will be a complex, multi-year challenge. However, Atsign provides a major shortcut to post-quantum readiness, enabling multiple ways for organizations to:
- build new applications using the updated SDKs, whether via traditional development or using Atsign’s visual development tool, AI Architect.
- modernize or retrofit existing applications, integrating the SDKs to protect relevant data flows, also via traditional development processes or AI Architect.
- protect systems that cannot or will not be modernized, using NoPorts. NoPorts provides authenticated, end-to-end encrypted access to existing services without exposed inbound ports or changes to the underlying application. The new update mean such connections can also receive post-quantum protection, protecting the connection and the data flow to systems even if the underlying legacy system itself is not, technically, quantum-safe.
Aparna Rayasam, CEO of Atsign, said: “At its core, this integration makes anything built on our platform quantum-safe by default. Achieving post-quantum readiness shouldn’t require multi-year application overhauls. By embedding NIST-approved algorithms directly into our SDKs, we’re delivering true crypto agility so engineering teams can focus on innovation rather than complex cryptographic mechanics.”
Rick Deacon, Head of Platform at mental wellbeing company and Atsign customer NeuroVitals, said: “Built-in post-quantum security will remove a significant burden for our development and security teams. What we really want to focus on is delivering and securing new capabilities for our customers, and this means we can do just that.”
Many organizations are already preparing for a post-quantum world, but are moving at very different speeds. Google, for example, has set a 2029 timeline for its own transition.
Developing its PQC integrations in the open, Atsign’s roadmap, architecture decisions, and code progress remain fully accessible to the public via the company’s GitHub repository.
Facts Only
* Atsign integrated NIST-approved Post-Quantum Cryptography (PQC) into core SDKs.
* The integration supports protecting applications and data flows against quantum threats.
* The update supports new applications, application modernization, and legacy systems not modified by the NoPorts service.
* The integration offers a path to post-quantum protection without requiring a full application rewrite.
* Development work is publicly available on GitHub.
* Post-quantum integration addresses vulnerabilities in breaking current asymmetric algorithms like digital signatures and key exchange.
* Adversaries pose a "harvest now, decrypt later" risk by storing encrypted data for future quantum decryption.
* Atsign's platform makes applications built on it quantum-safe by default.
Executive Summary
Atsign has integrated NIST-approved Post-Quantum Cryptography (PQC) into its core SDKs, offering a path for developers to protect applications and data flows against quantum threats. This update supports new application development, modernization of existing applications, and legacy systems that cannot be modified via the NoPorts service. The integration provides a method for post-quantum protection without requiring a complete application rewrite, with development work publicly available on GitHub.
The threat stems from quantum computers potentially breaking current asymmetric cryptographic methods like digital signatures and key exchange, necessitating action against "harvest now, decrypt later" attacks where adversaries store encrypted data for future decryption. Organizations must address this by identifying quantum-vulnerable cryptography across existing systems. Atsign provides a shortcut to post-quantum readiness through its SDKs, allowing organizations to build new systems, modernize legacy ones, or protect unmodifiable systems using NoPorts.
