同样的算法,不同的规则手册
世界已就后量子密码学的数学原理达成共识,但在如何应用这一原理上尚存分歧——而网络流量的形态已悄然改变。过去两周内的四项进展,及其对新西兰的意义。
后量子故事有一个令人安慰的版本:美国标准机构 NIST 于 2024…
我们的服务
A measured, evidence-led baseline of your quantum exposure. We identify which systems and datasets carry potential post-quantum risk, benchmark your posture against NZISM and frameworks, and characterise the threat honestly, including where there is no threat worth acting on. You finish with a clear picture and a defensible priority order.
Exposure snapshot, NZ$4,500 + GST. An external read of every public domain, mail exchanger and certificate you run, a discovery session, a shelf-life inventory of your most important datasets, an NZISM 2.4 gap check, and a short written report with a priority order. About two weeks.
Full readiness snapshot, NZ$12,500 + GST. Everything above, plus an inside cryptographic inventory of the systems that protect your long-lived data (keys, certificates, libraries, protocols), a supplier readiness check industry-standard vendor questions, a frozen point-in-time baseline for future re-scans, a board-ready report, and a leadership briefing. About three to four weeks.
A phased, costed transition plan for the systems that warrant it. We sequence the work against your operational constraints, supplier dependencies and regulatory timeline, using hybrid strategies that keep you interoperable throughout. This is the organisational programme, not a cryptographic parts swap. The hard part of PQC migration is the coordination, and coordination is what the roadmap manages. From there we work the plan together, staying agile as new or unexpected challenges arise. Our flexibility and transparency keep the migration fluid.
Standards move, suppliers ship, and your own systems change. A regular re-scan and review keeps your baseline current, tracks your suppliers’ readiness, and flags what has shifted since the last point of reference. This way quantum risk stays a managed line item rather than an ad hoc audit. We keep up to date with the frameworks, standards, regulatory policies and guideline updates and will advise you when action or change is recommended or necessary.
近期更新
世界已就后量子密码学的数学原理达成共识,但在如何应用这一原理上尚存分歧——而网络流量的形态已悄然改变。过去两周内的四项进展,及其对新西兰的意义。
后量子故事有一个令人安慰的版本:美国标准机构 NIST 于 2024…
世界已就后量子密码学的数学原理达成共识,但对于如何使用它尚无定论——而网络流量的形态已然改变。过去两周的四项进展,及其对新西兰的意义。
关于后量子密码学,有一个令人宽慰的叙事:美国标准机构 NIST 已于 2024…
导语:一个经过验证的硬件安全模块、一项针对电网的法案,以及一个指向证书层的芬兰研究项目。同一周内发生的三项进展传达着同一个信息:后量子过渡中最难的部分已不再是密码学本身。第四项——一篇正在广泛传播的供应商博客——则提醒人…
导言:一个已验证的硬件安全模块、一项针对电网的法案,以及一个指向证书层的芬兰研究项目。同一周内的三项进展传达着相同的信息:后量子过渡的难点已不再是密码学本身。第四项——一篇再度流传的厂商博客——提醒我们在阅读论点之前先看…
“收集”加密数据真正需要对手付出什么代价,要读取这批存储数据需要具备什么条件,以及真正的威胁究竟藏在哪里。本文从第一原理出发,梳理一个五道关卡框架(物理访问、存储经济、可解密性、数据有效期和对手动机),并结合对当今互联网…
7月28日,Anthropic发布了两项使用其Claude Mythos Preview模型得出的密码分析结果。其中一项改进了对AES简化轮数变体的攻击——理论上颇有趣味,实际上无关紧要,并非本文主题。另一项则是HAWK…
六月和七月的三周内,美国发布了后量子密码学的硬性截止期限,美国军方就哪些量子安全技术不被认可发表了直白声明,并有一篇经机器验证的论文详述了破解 RSA-2048 和 P-256 的实际代价。新西兰仍是唯一一个没有设定迁移…
我们对一项关于量子计算与安全的大规模新调查的解读,始终绕回到同一个未被充分重视的问题。同周发表的两篇专业论文揭示了为何让组织实现量子安全正变得愈发困难,而非更简单。
在五月末至六月初的短短两周内,arXiv 上相继…
2026年6月2日,我们对同一批118家新西兰关键基础设施实体重新运行了后量子密码学(PQC)就绪性扫描器,此前我们于2026年4月14日完成了首次评估。七周对于密码学迁移而言是一个较短的时间间隔——总体数字也印证了这一…
2026年5月第二周发表的三篇论文,分别从不同角度涵盖了后量子迁移栈的各个层面:美国国家标准与技术研究院(NIST)发布的下一代数字签名候选算法新报告、某生产银行内部的后量子密码学(PQC)概念验证部署,以及在树莓派硬件…