Member Login Become a Member
Advertisement

Pentagon Math Over Physics

  |  
09.17.2026 at 06:00am
Pentagon Math Over Physics Image

What a Fork in the Road of Advanced Cryptography Means for Protecting National Security Communications

In June 2026, the Department of War released a formal Post-Quantum Cryptography (PQC) Strategy, announced by Department Chief Information Officer Kirsten Davies one day after President Trump signed a pair of executive orders on quantum technology, one of which was devoted to cryptographic security. The strategy sets two deadlines: impact systems must run on post-quantum cryptography or be phased out by December 31, 2030, and every Department of War (DoW) system must run on quantum-resistant algorithms by 2031. Another rule in the strategy places quantum key distribution, the physics-based encryption approach China has pursued since 2016, on the strategy’s list of prohibited technologies.

Post-quantum cryptography is software designed to resist quantum computing factorization involved in new forms of cryptanalysis. Quantum computers, which remain an immature technology, may have utility in breaking the cryptographic algorithms used in public key infrastructure (PKI) for encryption. PKI is the scheme used to produce session keys from enormously large prime numbers that are easy to multiply but hard to factorize. (After the session keys are exchanged, traditional cryptography is employed to exchange data in an encrypted format.) Quantum computing would make that factorization far easier, significantly weakening PKI protection. US adversaries equipped with quantum computers may be able to apply them to decrypt intercepted messages encrypted with algorithms that are not quantum-resistant. A hint at how the quantum cryptanalysis project is advancing may come from cyber-criminals or state actors able to use the factorization capability to unlock cryptocurrency wallets of users who’ve lost their passwords, and thus access to them.

Cryptography remains a foremost concern for US national security, as it did when the first PKI deployments began to roll out during the 1990s, enabling private email messaging, online transactions, and secure access to web resources. With the arrival of quantum computing, a race is on to develop new means for protecting sensitive data. One such approach is quantum key distribution, known as Quantum Key Distribution (QKD), a physics-based method distinct from software-based post-quantum cryptography. QKD uses the physics of individual photons to generate encryption keys with a built-in alarm system: any attempt to intercept the key alters it. China built the first demonstration of this at a national scale, launching the Micius satellite in 2016 and completing an approximately 1,250-mile Beijing-to-Shanghai quantum network the same year. By 2025, China had a national ground-to-space QKD network, a capability no other nation has matched, including the European Space Agency, whose Eagle-1 satellite has slipped repeatedly and is now not expected to launch before late 2027. Measured by hardware fielded, China is years ahead.

The Defense Science Board’s judgment, as reported by the Congressional Research Service, is that QKD has not been implemented with sufficient capability or security for the Department of War’s use. QKD requires purpose-built hardware at each point in the network, and because the photon signal weakens over distance, it must be received and retransmitted at relay stations where the data is briefly unprotected, recreating exactly the vulnerability the system was designed to prevent. There is also no path to protecting most DoW systems that will keep running on conventional networks for years to come. Requiring line-of-sight to a satellite or a significant fiber-optic run, QKD implementation presents a bottleneck that the US defense establishment is unwilling to accept.

The mathematical foundation for PQC was already in place. NIST finished building it in August 2024, when it finalized the first three post-quantum standards after an eight-year evaluation process. The post-quantum cryptography standards, ML-KEM for key exchange and ML-DSA and SLH-DSA for digital signatures, were published as Federal Information Processing Standards (FIPS) 203, 204, and 205. The DoW’s strategy splits deployment into two acquisition tracks: one for the most sensitive military systems, using the Security Agency (NSA) controlled encryption hardware tied to weapons platforms and tactical networks, and a second for everything else, built on the same NIST algorithms already moving into commercial enterprise software. The NSA’s parallel migration framework, the Commercial National Security Algorithm Suite 2.0, requires legacy equipment and software signing to complete the transition by 2030, the same year the Pentagon’s high- impact systems deadline falls, with full migration phased through 2033. The new strategy builds on a November 2025 CIO memorandum that already required cryptographic inventories and named migration leads across every service. PQC is an evolutionary step, using longer key lengths and a lattice-based computational architecture that is resistant to the acceleration quantum systems provide to codebreaking, or cryptanalysis.

The urgency behind the 2030 deadline rests on many assumptions, not least that quantum computing could render data encrypted with current algorithms and techniques transparent, an existential threat to Department operations. Today, an adversary can capture encrypted traffic and store it, waiting for a quantum computer powerful enough to break current encryption to arrive. At that point, years of intercepted diplomatic cables, weapons designs, or troop movements could become readable at once. For data that needs to stay secret for a decade or more, the quantum computer does not need to exist yet to pose a risk. That logic is what makes the 2030 deadline urgent, even though the machines capable of breaking today’s encryption remain years away, according to most public estimates.

Responsibility for most of the actual migration work is assigned to what the document calls DoW Components, meaning every military service and defense agency individually, although the National Security Agency and Defense Information Systems Agency would have outsized roles in this implementation. For an organization whose Cryptographic Modernization program has been running, with recurring schedule slippage, for more than a decade. However, spreading execution across dozens of components with no interim milestones between now and 2030 is the kind of structure that tends to discover its own delays only when the deadline arrives. Still, the Pentagon’s own press materials claimed the department would move faster than the executive order requires. Making PQC work at the Pentagon is predicated on many “what ifs” regarding advances in cryptography, the mathematics of secure systems, as well as cryptanalysis, which concentrates on breaking cryptographic schemes. The DoW will likely deploy a form of hybrid encryption that combines classical and post-quantum encryption in parallel. PQC may be used to transmit keys between parties, but it will still depend on traditional forms of symmetric encryption after session keys are passed.

The Pentagon’s rejection of QKD for its own networks does not mean the technology has no future in America. NASA’s Space Communications and Navigation program continues to build toward intercontinental quantum networking. In March 2026, the Turkish-Dutch startup Qubitrium launched an entangled photon key distribution payload aboard a commercial CubeSat on SpaceX’s Transporter-16 mission, beginning an in-orbit validation phase toward the kind of trusted node architecture China has already fielded at scale. The National Quantum Initiative Reauthorization Act, advancing through Congress in 2026, directs federal agencies to study quantum communication corridors linking national laboratories and universities. Lockheed Martin has separately signed a contract with Norwegian components producer EIDEL to build post-quantum cryptography into satellites, a sign that even the commercial space sector is following the Pentagon’s lead rather than China’s.

China’s QKD investment buys strategic communications security for a domestic network of fixed nodes, built at a cost and complexity not replicated at that scale by any other country, and that still cannot reach a submarine, a fighter jet, or a soldier’s radio. The American strategy prioritizes breadth: encryption that can be updated across satellite constellations, weapons platforms, and battlefield networks through software alone, reaching systems far more numerous and far more mobile than any point-to-point quantum link could serve. Each pathway to protecting data in transit and at rest has pitfalls, not least that the points of potential failure are not yet well understood.

The post-quantum algorithms themselves, mathematically young by cryptographic standards, must hold up under years of sustained attacks from researchers trying to find weaknesses. In 2022, Belgian mathematicians Wouter Castryck and Thomas Decru of KU Leuven broke the Supersingular Isogeny Key Encapsulation (SIKE) algorithm, which had advanced to the fourth round of NIST’s own standardization process. Using little more than a single desktop computer, the researchers’ exploit is a reminder that mathematical security is provisional until proven otherwise. For the adversary timeline, the date a quantum computer can break contemporary encryption must remain far enough in the future to give the migration room to finish.

About The Authors

  • Morgan Bazilian

    Morgan Bazilian is a professor and director of the Payne Institute for Public Policy at the Colorado School of Mines. Previously, he was a lead energy specialist at the World Bank.

    View all posts
  • Chris Bronk

    Chris Bronk is a professor of public policy at the University of Houston’s Hobby School of Public Affairs and a non-resident fellow at the Baker Institute for Public Policy’s Center for Energy Studies.

    View all posts

Article Discussion:

0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted