Post-Quantum Cryptography (PQC)

Quantum computing poses a risk to classical cryptographic algorithms. Widely adopted public key cryptography standards are expected to become vulnerable within the next several years. In response to this emerging threat, the US National Institute of Standards and Technology (NIST) has evaluated and selected several quantum-resistant algorithms for different use cases. These algorithms are collectively referred to as post-quantum cryptography (PQC).

For more information about post-quantum cryptography, see Security in the quantum computing era.

Encryption in transit

It is recommended to deploy an IBM Application Gateway (IAG) or IBM® Verify Identity Access Reverse Proxy in front of the Digital Credentials service to protect REST APIs. For instructions on configuring these products to support PQC, see IBM Verify Identity Access and IBM Application Gateway documentation.

Encryption at rest

The Digital Credentials service provides application-level encryption for sensitive data (such as keys and digital credentials), that are stored in the configuration database. This encryption uses the AES-256-CBC algorithm, which is considered quantum-resistant. However, it is recommended to configure database-level encryption and security settings according to your database vendor’s guidance.