The race for post‑quantum hardware: Intel, Nvidia, and IBM prepare chips that resist quantum computers
Vulnerabilities

Illustrative image generated with AI

The race for post‑quantum hardware: Intel, Nvidia, and IBM prepare chips that resist quantum computers

Intel, Nvidia, IBM develop post-quantum chips to counter quantum threats. Learn about harvest-now-decrypt-later attacks, NIST standards, and hardware transition.

Text generated by artificial intelligence, published without human review. AI transparency

Harvest now, decrypt later: the quantum threat is no longer deferrable

The problem has a precise name: harvest now, decrypt later. Sensitive data can be intercepted and stored today, then decrypted when quantum computers become powerful enough to break current cryptographic schemes. There is no need to wait for those computers to exist: the damage begins now, silently. Asymmetric cryptography based on RSA and ECC, used to protect digital signatures and key exchange over public networks, is considered vulnerable to quantum attacks. The federal NIST responded by standardizing in 2024 the first post‑quantum cryptography algorithms, designed to resist these attacks. But standardization is only the starting point: the transition to hardware capable of accelerating them takes years.

Intel accelerates on Xeon 6 and targets 2029 for full coverage

Intel has begun providing PQC capable support in Xeon 6 server processors. Anand Pashupathy, Intel vice president and general manager for product assurance and security, announced it in April at the Google Cloud Next conference. The message is direct: defend now, not in three years. The transition of all Intel chips to PQC compliance will take multiple years. The new algorithms will coexist with other schemes such as AES to handle both quantum and standard web traffic. The company intends to protect standard AES Internet traffic by strengthening handshakes with PQC and hardware acceleration.

Pashupathy indicated that coverage will increase generation after generation and that the company will be ready by 2029. In the meantime, AES‑256 is already accelerated in Intel hardware and should be used to prevent harvest‑and‑decrypt‑later attacks. Intel will also continue to provide acceleration for asymmetric cryptography and will expand acceleration of PQC algorithms in the next platform generations.

Nvidia brings PQC to confidential computing

Nvidia is integrating post‑quantum standards into the security layers that underpin confidential computing. Daniel Rohrer, Nvidia vice president of software security, explained this also at Google Cloud Next. In these layers, trust and attestation are established for secure data exchange. Implementation is now moving forward since the NIST standards have been approved, both in hardware and in other features. The move aims to make quantum‑resistant the mechanisms that ensure integrity and confidentiality of processing enclaves.

IBM led the way with the z16 mainframe

IBM was the first to introduce post‑quantum cryptography accelerators in hardware. The credit goes to the z16 mainframe, released in 2022. Since then, the company has updated the firmware to keep it compliant with NIST PQC standards. This detail is important: even systems already in production can receive firmware improvements without being replaced. However, it is not a universal solution.

Asymmetric versus symmetric: the long hardware timelines

To understand what is at stake, we need to distinguish two families of cryptography. PQC is asymmetric: it uses public/private key pairs and is designed to resist quantum attacks. RSA and ECC, also asymmetric, are instead considered vulnerable. AES‑256 is a single‑key symmetric technology used to encrypt large volumes of data such as Internet traffic, and is quantum‑resistant according to Nelly Porter, director of product management for GCP Confidential Computing and Encryption.

Hardware cryptography is faster than software cryptography, but product implementation takes years. NIST published AES in 2001, the standard went into effect in 2002, but it only appeared in AMD and Intel chips in 2010. The lesson applies to PQC as well: even with approved standards and announced roadmaps, widespread adoption will not be immediate.

Countermeasures: use AES‑256, update firmware, and replace hardware that cannot be updated

The known mitigations revolve around a few concrete points. Adopt PQC in handshakes and chips, making it coexist with AES. Use AES‑256, already accelerated in Intel hardware, to prevent harvest‑and‑decrypt‑later attacks. Update the firmware of existing systems — such as the IBM z16 mainframe — to NIST PQC standards. Perform a complete hardware assessment and replace equipment that cannot be updated, such as old network appliances.

Jack Gold, principal analyst at J. Gold Associates, warns that updating chips with PQC is only the beginning. A comprehensive hardware assessment is needed. Many infrastructures with built‑in cryptography can be difficult to update or, like old network equipment, impossible. In those cases, the only option is to replace them.

Porter adds an element of urgency: companies must start protecting systems immediately. Every sensitive bit and byte that is unprotected and not quantum‑resistant can be stored now and decrypted when quantum computers become available. There is no CVSS score for this type of threat, but the priority is described as high. The hardware transition is multi‑year: for Intel, full coverage will arrive only in 2029. The time to start, according to the manufacturers, is now.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicspost-quantum cryptographyquantum computingIntelNvidiaIBMAES-256NIST standardsharvest now decrypt later
Back to home