11
2

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

Post-Quantum Cryptography at Japan’s 47th Cybersecurity Task Force

11
Posted at

I'm Satoru Kanno from GMO Connect Inc.

Our previous article received a lot of attention from overseas readers, so we decided to publish an English version.
There’s a question about PQC that I’ve been pondering for a while, and I finally took the opportunity to write about it.

I’d be grateful for any feedback you may have.


The topic of this article is the 47th Cybersecurity Task Force, which was held on September 1.
In particular, see Document 47-1: Status of Initiatives Based on the "Mid-Term Priority Guidelines for ICT Cybersecurity Policy".

The other distributed materials are also quite informative, so I encourage you to take a look at them as well.


On page 17 of Document 47-1, you’ll find a section of particular interest.
It discusses the status of research on everyone’s favorite topic: post-quantum cryptography (PQC).
For more details, see the screenshot below:

image.png

Some of you might be wondering, “What is PQC? Can you eat it?”
Well, let me explain.

PQC stands for post-quantum cryptography—cryptographic algorithms designed to remain secure even in the era of quantum computers.
Those with sharp intuition may ask: “If there’s cryptography that’s quantum-safe, does that mean the algorithms we use today are quantum-safe?”

Exactly!

There are concerns that today’s widely used public-key algorithms, such as RSA and ECDSA, may be vulnerable to attacks.
To address this risk, a transition to PQC is being considered. This challenge is often referred to as the “2030 Cryptography Problem.”

Note that the 2030 problem has more than one dimension; it’s not just about migrating to PQC. That’s why it requires careful attention.

Here’s a screenshot from some materials I used in a talk:

image.png


As the name suggests, the PQC transition is planned for 2030. But there are many hurdles:
theoretical research → technical evaluation → standardization → prototyping/demonstration → commercialization.

Here’s an outline of the expected timeline:

image.png

In August 2024, the US National Institute of Standards and Technology (NIST) selected three PQC algorithms. That leaves only six years until 2030.
The US is steadily preparing, and the EU is also making progress.

In contrast, Japan lags slightly behind, as activities related to security and performance evaluation reportedly only began in March 2025.
Without a clear government policy, it’s easy to imagine that manufacturers may hold off on supporting PQC—delaying the development of new PQC-enabled products.

If this trend continues, Japanese citizens may find themselves left behind compared to the rest of the world.

Since adopting new technology in practice always takes time, I sincerely hope that a clear policy will be finalized soon, enabling companies to focus on product development.


That said, PQC is already around us—believe it or not!

For example, a certain government agency’s web server communicates in a PQ / T Hybrid setting (using both traditional encryption and PQC). Many people may be unaware that they are already using PQC-based encryption.

image.png

Note: The current key exchange uses X25519 and ML-KEM768.


So, that’s a brain dump of what I’ve been thinking about.
I hope this gives you some insight into the current PQC situation in Japan.


Finally, GMO Connect offers a wide range of services, including research and development, international standardization support, and technical verification.
Please do not hesitate to contact us with any inquiries.

👉 Contact us: https://gmo-connect.jp/contactus/

11
2
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
11
2

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?