POST-QUANTUM CRYPTOGRAPHY / INTERMEDIATE

The Maths Families Behind Post-Quantum Cryptography, Without Equations

Lattices, hashes, codes, multivariate equations and isogenies. A plain-language guide to the hard problems behind post-quantum algorithms, and which families have held up.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Every public-key algorithm depends on a mathematical problem that is easy to set up and hard to undo. RSA depends on factoring large numbers. Elliptic curve cryptography depends on the discrete logarithm problem. A quantum computer running Shor’s algorithm solves both, so post-quantum cryptography needs problems of a different kind.

Researchers have built post-quantum schemes on five main families of problem, plus a couple of newer approaches. This article explains each one in plain terms, names the algorithms that use it, and notes which families have held up under attack.

Lattices

Picture a vast grid of points stretching in hundreds of dimensions. Given a point that has been nudged slightly off the grid, finding the nearest grid point is easy in two dimensions and extremely hard in hundreds. Lattice cryptography builds on problems of this kind.

A small example shows the idea. Picture clock arithmetic, where numbers wrap round after reaching a fixed value, as the hours do after 12. ML-KEM works this way with a modulus of 3,329.1 Now suppose you are given many equations of the form 3a + 5b + 2c = 41 in that wrap-around arithmetic, except that every answer on the right has been nudged up or down by a small random amount. Without the nudges, standard algebra would recover the unknowns quickly. With them, and with hundreds of unknowns instead of three, the best known classical and quantum methods are believed to need an impractical amount of work at the sizes used in practice.

ML-KEM rests on a problem called Module Learning With Errors, which hides a secret inside equations that have small random errors added.1 ML-DSA relies on the same problem plus a variant of the Module Short Integer Solution problem.2 FN-DSA, the coming standard based on Falcon, uses a different structure known as NTRU lattices.3

Lattice schemes are generally fast, with keys, ciphertexts and signatures under five kilobytes in the standardised versions,12 and they now carry NIST’s primary standards. The trade-off is concentration: most of the near-term post-quantum ecosystem sits on one family.

Hash Functions

Hash-based signatures are the most conservative family. Their security depends only on the hash function they use, the same kind of building block that already underpins much of today’s security, rather than on a newer algebraic problem.4

The family has two branches. SLH-DSA (FIPS 205) is stateless, so it can be used like any other signature scheme, at the cost of large signatures. LMS and XMSS (NIST SP 800-208) are stateful: the signer must track which one-time keys have been used, which makes them suitable for controlled settings such as firmware signing.4

Error-Correcting Codes

Error-correcting codes let data survive noisy channels by adding structured redundancy. Code-based cryptography turns this around: the sender deliberately adds errors, and only the holder of a secret description of the code can strip them out. To anyone else, decoding a random-looking code is hard.

HQC, selected by NIST in March 2025, is code-based. NIST preferred it over the similar BIKE scheme because it judged HQC’s analysis of decryption failure rates to be more mature.5 Classic McEliece, the oldest scheme in the family, was not selected. NIST cited public keys of 261,120 bytes even at its lowest security level, which make it a poor fit for most common uses.5 Germany’s BSI had recommended it, but as of October 2026 its guidance page reports significant cryptanalytic progress against Classic McEliece in 2026 and advises against it for new applications, while noting that the recommended parameters are not practically broken.6

Multivariate Equations

Multivariate schemes rely on the difficulty of solving large systems of quadratic equations in many variables. They can produce short signatures, but designers must hide a trapdoor inside the equations, and that is where attacks have struck.

Rainbow, a third-round finalist, was broken in 2022 by an attack that recovered keys for its lowest security level in about 53 hours on a laptop.7 Other multivariate designs survive. UOV, MAYO, QR-UOV and SNOVA are all in the third round of NIST’s search for additional signatures.8

Isogenies

Isogenies are maps between elliptic curves. Finding a hidden path between two curves is believed to be hard even for quantum computers. Isogeny schemes are known for very small keys.

The family suffered the most dramatic break of the competition. SIKE, an isogeny-based KEM, fell in 2022 to a classical attack that recovered a key for its lowest parameter set in about ten minutes on a single core.9 The attack targeted the specific structure SIKE exposed, not isogenies in general. SQIsign, which uses isogenies differently, is still in NIST’s third round.8 Its designers report public keys of 83 bytes and signatures of 200 bytes at the lowest security level, with signing far slower than verification.10

Newer Approaches

Two further approaches appear in NIST’s third round. MPC-in-the-head schemes, such as MQOM and SDitH, build signatures by simulating a secure multi-party computation. FAEST builds signatures from symmetric primitives similar to AES.8

FamilyHard Problem In Plain TermsStandardisedIn ProgressBroken
LatticeFinding the nearest point in a huge, high-dimensional gridML-KEM, ML-DSAFN-DSA (FIPS 206)None of the selected schemes
Hash-basedReversing a hash function, or finding a second input with the same outputSLH-DSA, LMS, XMSSNoneNone
Code-basedDecoding a random-looking error-correcting codeNone yetHQC (FIPS 207)None of the selected schemes
MultivariateSolving large systems of quadratic equationsNoneUOV, MAYO, QR-UOV, SNOVARainbow (2022)
IsogenyFinding a hidden map between elliptic curvesNoneSQIsignSIKE (2022)
MPC-in-the-headProving knowledge of a secret by simulating a computationNoneMQOM, SDitHNone
Symmetric-basedBreaking a block cipher such as AESNoneFAESTNone
Post-quantum maths families and their status, as of October 2026.

Footnotes

  1. NIST, FIPS 203, “Module-Lattice-Based Key-Encapsulation Mechanism Standard”, August 2024. csrc.nist.gov ↩ ↩2 ↩3

  2. NIST, FIPS 204, “Module-Lattice-Based Digital Signature Standard”, August 2024. csrc.nist.gov ↩ ↩2

  3. R. Perlner (NIST), “FIPS 206 Status Update”, presentation, 2025. csrc.nist.gov ↩

  4. NIST, SP 800-208, “Recommendation for Stateful Hash-Based Signature Schemes”, October 2020. csrc.nist.gov ↩ ↩2

  5. NIST, IR 8545, “Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process”, March 2025. csrc.nist.gov ↩ ↩2

  6. BSI, “Technical Guideline TR-02102” web page, including its notice on Classic McEliece, checked 7 October 2026. bsi.bund.de ↩

  7. W. Beullens, “Breaking Rainbow Takes a Weekend on a Laptop”, IACR ePrint 2022/214, February 2022. eprint.iacr.org ↩

  8. NIST Computer Security Resource Center, “Round 3 Additional Signatures”, updated 28 September 2026. csrc.nist.gov ↩ ↩2 ↩3

  9. W. Castryck and T. Decru, “An efficient key recovery attack on SIDH”, IACR ePrint 2022/975, July 2022. eprint.iacr.org ↩

  10. SQIsign team, “SQIsign” specification summary, sqisign.org (submitters’ own figures). sqisign.org ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.