Interactive Research Tool
PQC Lab
See exactly how RSA and Lattice-based (ML-KEM) cryptography hold up against a quantum attacker. Adjust key sizes, choose your quantum computing era, and watch the break unfold — or fail to.
Quantum Computing Era
RSA Key Size
Qubits required (Shor's): ~4,196 logical
Lattice (ML-KEM) Security Level
Configure parameters on the left and
launch the quantum attack to see results.
What This Simulator Doesn't Show
Algorithm hardness is one input to your real security margin. The other five inputs determine whether your post-quantum posture is genuinely defensible or merely compliant on paper.
All Six, Assessed Together
USMC assesses every dimension and combines them into a single QRESB Assurance Index. One verdict. Defensible to a regulator.
Entropy Quality
Your keys are only as strong as the randomness that generates them. Compromised or low-quality entropy collapses cryptographic security regardless of which algorithm sits on top.
Protocol and Reconciliation Leakage
Real cryptographic protocols leak information during error correction and reconciliation. The bits lost to leakage are bits no longer available as security margin against an adversary.
Side-Channel Resistance
A correctly chosen PQC algorithm still leaks key material through timing, power, or electromagnetic emissions if the implementation is not constant-time. Algorithmic security is not implementation security.
Architecture and Network Exposure
Cryptographic strength assumes secrets stay where you put them. Trust boundaries, key distribution paths, and adversary placement in the network can expose material before any algorithm is tested.
Finite-Size Effects
Production systems generate finite-length keys under finite-time security proofs. The gap between asymptotic guarantees and real finite-size security is a measurable cost most teams never account for.
Why This Dimension Matters
Shor's Algorithm
A cryptographically relevant quantum computer running Shor's algorithm can factor large integers in polynomial time, rendering RSA and ECC mathematically broken, regardless of key length.
Lattice Hardness
ML-KEM (CRYSTALS-Kyber) security rests on the hardness of the Learning With Errors problem. No quantum algorithm provides a meaningful speedup against well-parameterised LWE. NIST standardised it in 2024.
Harvest Now, Decrypt Later
Adversaries are recording encrypted traffic today. Once a quantum computer exists, historically captured ciphertext becomes readable. Migration cannot wait for the threat to be confirmed.