SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
Story image

SandboxAQ algorithm selected for NIST crypto standards

Fri, 28th Mar 2025

The National Institute of Standards and Technology (NIST) has selected the HQC (Hamming Quasi-Cyclic) algorithm by SandboxAQ as part of its suite of post-quantum cryptographic standards.

The HQC algorithm is the fifth addition to NIST's set of post-quantum cryptographic (PQC) standards intended to safeguard digital communications against potential threats posed by quantum computing. Out of the five PQC algorithms chosen, HQC joins ML-KEM as one of the two algorithms dedicated to protecting the confidentiality of communications ranging from cellular networks to payment systems.

This selection reflects SandboxAQ's second major contribution to NIST's PQC standards, following its earlier involvement with the algorithm SPHINCS+. "HQC has foundations in coding theory that offer strong theoretical and practical protection against known quantum decryption methods, while its efficient performance profile makes it well-suited to real-world adoption," expressed Taher Elgamal, a Partner at Evolution Equity Partners and senior advisor at SandboxAQ.

HQC applies a key encapsulation mechanism designed to secure the exchange of encryption keys in a manner resistant to quantum attacks. Unlike RSA or elliptic-curve cryptography (ECC), which quantum computers could potentially disrupt, HQC is underpinned by mathematical principles of error-correcting codes. This foundation provides a balance between strong security and computational efficiency, factors essential for application at a large scale.

The HQC mechanism arose from extensive R&D, as Chief Cybersecurity Scientist at SandboxAQ, Carlos Aguilar Melchor, elaborated: "We began developing HQC in the 2000s, and by the 2010s, we had demonstrated that this protocol resolved a 40-year-old open problem in code-based key exchanges. Today, HQC stands as one of only two protocols securing the confidentiality of nearly all global communications."

NIST's final selection report acknowledged HQC as a reliable candidate owing to its robust performance, demonstrated through multiple rounds of global cryptanalysis and peer reviews. With SPHINCS+ and HQC now both incorporated into the PQC standards, SandboxAQ positions itself as a leader in the development of quantum-resilient cybersecurity solutions that are crucial for enterprises and governments worldwide.

This endeavour highlights SandboxAQ's commitment to driving forward cryptographic research and innovation on an international scale. The company's expert cryptography team is also involved in delivering a cryptography management product known as AQtive Guard, which offers extensive insights and security capability enhancements through its AI-driven solutions.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X