Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Protection - NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
Data Protection Encryption Latest News News & Analysis

NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard

Adam ParlettBy Adam ParlettApril 7, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
NIST PQC Standard
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

An important recent development in the National Institute of Standards and Technology (NIST) standardization project has seen them select SandboxAQ’s Hamming Quasi-Cyclic (HQC) as the fifth algorithm to be added to their suite of post-quantum cryptography (PQC) standards. 

HQC will act as a backup in the event that quantum computers become capable enough in the future to crack the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) specified in Federal Information Processing Standard (FIPS) 203. 

FIPS 203 

FIPS 203 is NIST’s primary standard for general encryption. It is based on the CRYSTALS-Kyber algorithm, which was subsequently renamed to ML-KEM – the algorithm it specifies. ML-KEM belongs to the class of lattice-based cryptographic systems, which rely on the difficulty of solving problems in lattice structures. Its security is based on the hardness of the Module Learning with Errors (MLWE) problem, a specific type of lattice problem. 

Key Encapsulation Mechanisms 

Key-encapsulation mechanisms (KEMs) like ML-KEM differ from traditional key exchange methods in that they are specifically designed to be unsusceptible to classical and quantum computing attacks. KEMs enable two parties to securely exchange keys over public channels, provide authentication, and give proof of possession. 

HQC 

HQC is a code-based KEM that utilizes the cryptographically challenging Quasi-Cyclic Syndrome Decoding Problem as its base and is built on the mathematical foundation of error-correcting codes. Significantly, it is a key encapsulation mechanism designed to secure the exchange of encryption keys in a quantum-resistant manner, unlike traditional public-key encryption systems such as one of the oldest and most widely used Rivest–Shamir–Adleman (RSA). 

HQC is designed to deliver strong security without having to compromise performance factors like computational efficiency and key size, which are essential for large-scale real-world deployments. 

In their final selection report, NIST observed how the HQC algorithm stood out as a robust and reliable candidate for mass cross-industry adoption following several rounds of global cryptanalysis and peer review. They commented that HQC “would provide a good complement to MLKEM since it is based on a different underlying security problem and still retains reasonable performance characteristics for general applications.” 

Setting the Standards 

The selection of HQC is SandboxAQ’s second major contribution to NIST’s post-quantum standardization effort after NIST previously standardized SPHINCS+. 

Taher Elgamal, a partner at Evolution Equity Partners and senior advisor at SandboxAQ, believes that the moves by NIST have greatly strengthened the infosec community. “With SPHINCS+ and HQC both standardized by NIST, SandboxAQ has solidified its leadership in developing effective PQC solutions for enterprises and government agencies. This is not just a milestone for SandboxAQ; it’s a win for global security in the face of future quantum disruption.” 

Future-Proofing 

Quantum computers are no longer a distant dream and could be built ‘within years rather than decades,’ Microsoft has claimed following the recent unveiling of its Majorana 1 chip. The chip is the first quantum chip ‘top conductor,’ capable of creating a new state of matter that is not a solid, liquid, or gas. Developments like this, along with the introduction of Sectigo PQC Labs, serve to emphasize the urgent need for quantum-safe cryptography. The NIST standards are doing invaluable work in providing organizations with a framework that can help secure their systems against future quantum threats. 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers
  • Adam Parlett
    PAC Report Highlights the Challenges Facing UK AI Growth Plan

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}