PLAIN QUANTUM
← Guide overview
Quantum Readiness for Banking Professionals · Reference

Glossary

Quantum Readiness for Banking Professionals: all chapters

The terms used in this guide, in plain English.

AES
The standard symmetric encryption algorithm. With 256-bit keys it remains strong against quantum computers.
Asymmetric cryptography
Another name for public-key cryptography. Both the vulnerable algorithms (RSA, elliptic-curve) and the new post-quantum ones are asymmetric.
CBOM (cryptographic bill of materials)
A structured inventory of cryptographic assets: what is used, where, what it protects and what depends on it. CycloneDX is an open standard for recording one.
Certificate
A digital document that binds a public key to an identity, such as a website or a bank, vouched for by a certificate authority's signature.
Certificate authority (CA)
A system or organisation that issues certificates. Certificates form chains from a root authority down to individual systems.
CNSA 2.0
The US National Security Agency's algorithm requirements for national security systems. Not a deadline for commercial banks.
CRQC (cryptographically relevant quantum computer)
A quantum computer large and reliable enough to break RSA and elliptic-curve cryptography at the sizes used today. None exists today.
Crypto-agility
The ability to change cryptographic algorithms, keys and parameters through configuration or policy, without re-engineering the systems that use them. In practice it also needs interoperability with partners, managed key and certificate lifecycles, validated implementations and operational controls such as testing and rollback.
Elliptic-curve cryptography (ECC)
A family of public-key algorithms widely used for modern key agreement (such as ECDHE) and signatures (such as ECDSA). Based on a discrete-logarithm problem that a large quantum computer could solve.
Envelope encryption
Encrypting data with one key and protecting that key with another. If the outer key is RSA or elliptic-curve, the whole envelope is quantum-vulnerable.
FN-DSA
A compact post-quantum signature algorithm (formerly Falcon) being standardised by NIST.
Grover's algorithm
A quantum search algorithm that speeds up searching for a secret key, weakening symmetric encryption; 256-bit keys keep a comfortable margin. Its effect on hash functions depends on how the hash is used, and current guidance treats SHA-256 and larger hashes as remaining secure.
Harvest now, decrypt later
Recording encrypted data today in order to decrypt it once a capable quantum computer exists.
Hash function
A function that produces a short fingerprint of data, used to detect changes. Modern hashes such as SHA-384 remain strong.
HQC
A backup key-agreement algorithm selected by NIST in 2025, based on different mathematics from ML-KEM.
HSM (hardware security module)
A tamper-resistant device that stores and uses cryptographic keys. It protects keys from theft, not from quantum attacks on their mathematics.
Hybrid cryptography
Using a current algorithm and a post-quantum algorithm together. When the two are combined using a standard method and implemented correctly, a connection stays secure as long as at least one of them remains unbroken.
Key agreement
The process by which two systems establish a shared secret key over an open network. Today this mostly uses elliptic-curve methods (such as ECDHE); older systems sometimes transport keys with RSA instead.
KEM (key encapsulation mechanism)
A way for two systems to establish a shared secret: one side uses the other's public key to wrap a fresh secret, and only the holder of the private key can unwrap it. ML-KEM is a KEM; it does the job that key exchange does today.
ML-DSA
The main NIST post-quantum digital signature standard (FIPS 204).
ML-KEM
The main NIST post-quantum key encapsulation mechanism (KEM) standard (FIPS 203), used for key agreement.
Mosca's inequality
A planning rule: if the time data must stay secret plus the time to migrate exceeds the time until a quantum computer can break it, the data is already at risk.
Post-quantum cryptography (PQC)
Public-key algorithms designed to resist known classical and quantum attacks, running on ordinary computers. Like all cryptography, they remain subject to continuing analysis.
Public-key cryptography
Cryptography using a pair of keys, one public and one private, for key agreement, signatures and certificates. Today's widely used schemes (RSA and elliptic-curve) would be broken by a large quantum computer; post-quantum schemes are public-key cryptography designed to resist it.
Q-day
An informal name for the day a cryptographically relevant quantum computer exists. Its date is unknown.
RSA
A widely used public-key algorithm for signatures and certificates, and in older systems for transporting keys. Based on factoring, which a large quantum computer could do.
Shor's algorithm
The quantum algorithm that would break RSA and discrete-logarithm systems, including elliptic-curve cryptography, on a large enough quantum computer.
SLH-DSA
A conservative, hash-based NIST post-quantum signature standard (FIPS 205), with larger signatures.
Symmetric cryptography
Cryptography where the same key encrypts and decrypts, such as AES. Weakened only modestly by quantum computers.