01
Assess the threat precisely
There is a house style for quantum security copy and it works by making the reader nervous. Nothing useful is bought with that. What an evaluator needs is the narrow version: which cryptography a large quantum computer actually defeats, what the standards bodies have already published in response, and which holdings are exposed in a way that survives scrutiny rather than in a way that merely sounds serious.
Those facts are settled and unglamorous. The machine does not exist yet. The replacement algorithms do: NIST published FIPS 203, 204 and 205 in August 2024, and US NSM-10 put 2035 on the calendar as the migration goal. What remains is sequencing and procurement rather than research.
Urgency, where there is any, comes from the recording rather than from the machine. Anything captured now under encryption that will not outlast the secret inside it is a live problem today, and the number of categories that genuinely qualify is small. A biometric qualifies without argument.
Attackers can collect encrypted data now
The strategy needs nothing exotic in the present: disk space, an interception point, and a judgment that a particular payload will still be worth opening years from now. No quantum computer is required to start.
Prioritize migration by data lifespan
Mosca's inequality is the planning tool: weigh how long a secret must stay confidential against how long migration takes and how far away the machine is. Anything valid for a decade belongs at the front of the queue by that arithmetic alone.
A face does not expire
Every other credential in an estate can be rotated on a schedule, which is what makes it a poor target for a decades-long wait. The one that cannot be rotated is the one a patient adversary would choose to record against.
02
What the paper explains
The argument then moves off strength and onto absence. Controls are bought to protect a store; it is the store that gives a recording its value; take the store away and a patient adversary is recording against nothing, however capable the hardware eventually becomes.
The triage is then run on our own architecture without softening. A deployment here is biometric-blind, so there is no face database behind the API and no template vault behind the console. The paper assumes a full-take recording over years, assumes the classical key exchanges eventually fall, and works through what the adversary is holding, artifact by artifact, once the plaintext is finally in hand.
The quantum-safe claim here describes the face-token construction. It uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256 and SHA-256. No proprietary or non-approved cryptographic primitives are used. The token contains no public-key structure for Shor’s algorithm to attack. PKI and IdP federation have separate algorithm and key lifecycles.
- Which primitives Shor's algorithm ends and which Grover's algorithm merely weakens, and why that split decides what to migrate first
- How Mosca's inequality behaves when the secret in question stays valid for as long as its owner does
- The full-take recording scenario worked through artifact by artifact, first at capture and then after a hypothetical future decryption
- The primitives inside the face token, and the exact sense in which the construction earns the description quantum-safe face token
- Why short-lived signature artifacts are the wrong target for a decrypt-later strategy, and where hybrid post-quantum TLS (X25519MLKEM768) already applies today
- Five tests an operator can apply to whichever biometric system they already run, none of which depend on this platform
03
Who this paper is for
Risk leads and cryptographers assembling a post-quantum inventory, and the reviewers who will have to defend that inventory to somebody else. Every claim here is narrow enough to be tested, which is the only kind worth entering in a register.
It is also useful pointed outward. Vendors have begun describing entire platforms as quantum-safe, and the paper gives a reader the language to ask which construction the label actually covers and what the protocol layer around it is doing in the meantime.
04
Assess your own stored biometric data
Seven pages, including an artifact table for the capture-and-decrypt scenario and a timeline that puts the published standards, the migration window and the credible machine estimates on one axis. The checklist at the end is the part to carry into a planning meeting.
The gated download sits on sensecrypt.com, and a copy of the PDF is available on request. If your own inventory work raises something the paper does not cover, that is the more interesting conversation to have with our engineers.
05
Frequently asked questions
Is SenseCrypt a quantum-safe platform?
Post-quantum claims are specific to the construction. The IdP face token uses AES-256-GCM, HKDF-SHA256 and SHA-256. IdP retains encrypted tenant signing keys: OIDC uses classical ES256 and SAML uses RSA. Separately, PKI generates post-quantum key-pairs, stores public keys and never stores private keys. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
Why act before a quantum computer exists?
Because recording is already happening, and so is the decision about what to hold on to. Anything intercepted today under classical encryption is openable later, which leaves one useful test: will the contents still be worth something at that point. For almost all traffic they will not. This paper concerns the exception.
So what does the platform actually store?
A sealed face token is persisted, and it is worth being exact about what that is: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment. Each token is bound to one tenant and one enrolled user, and every successful sign-in retires it and mints a fresh one, so a recorded copy is already spent long before any future decryption could reach it.
Where does hybrid post-quantum TLS fit into this?
At the transport layer, and it is in use rather than planned: hybrid post-quantum TLS (X25519MLKEM768) protects traffic in flight, so a recording taken today has to defeat both halves of the exchange. That is a separate control from the token construction, and the paper keeps them in separate sections rather than letting one borrow credibility from the other.