Quantum-safe cloud storage is storage infrastructure in which every cryptographic mechanism protecting data, including key exchange, encryption at rest, and authentication, is resistant to attacks from both classical and quantum computers. It is not simply a matter of choosing a strong cipher: the threat model changes fundamentally when quantum hardware becomes available, and most commonly used asymmetric algorithms collapse under that pressure.
Why Conventional Encryption Is No Longer Sufficient
Today’s cloud encryption relies on asymmetric algorithms such as RSA and elliptic-curve cryptography (ECC) for key exchange and authentication. These are mathematically secure against classical computers but are broken efficiently by Shor’s algorithm running on a sufficiently powerful quantum computer.
“Harvest now, decrypt later attacks mean adversaries are already collecting encrypted data today, intending to decrypt it once quantum computers become powerful enough.”
Dustin Moody, mathematician and post-quantum cryptography project lead, NIST
This is not a theoretical future risk. Organisations holding data with a confidentiality horizon of ten or more years, such as legal contracts, health records, or intellectual property, are already exposed. The data collected today can be decrypted tomorrow.
What Actually Makes Storage Quantum-Safe
Quantum-safe storage requires replacing vulnerable asymmetric components with post-quantum cryptography (PQC) algorithms at every layer, not only at the transport layer.
Encryption at rest
AES-256 for encryption at rest is relatively robust: Grover’s algorithm reduces its effective quantum security to 128 bits, which remains practically unbreakable. The vulnerability lies in how the AES keys themselves are protected. If key wrapping or key encapsulation uses RSA or ECC, those keys are exposed. A quantum-safe implementation replaces that key encapsulation with an algorithm from the NIST post-quantum portfolio.
Key exchange and authentication
In August 2024, NIST finalised its first post-quantum cryptography standards under the Federal Information Processing Standards (FIPS) series. The three primary standards are:
| Standard | Algorithm | Purpose |
|---|---|---|
| FIPS 203 | ML-KEM (CRYSTALS-Kyber) | Key encapsulation for secure key exchange |
| FIPS 204 | ML-DSA (CRYSTALS-Dilithium) | Digital signatures for authentication and integrity |
| FIPS 205 | SLH-DSA (SPHINCS+) | Stateless hash-based signatures as a backup alternative |
A provider that does not reference these specific FIPS designations when asked about post-quantum support has almost certainly not implemented it properly.
Key sovereignty
Quantum-safe algorithms cannot protect data from compelled legal disclosure. If the provider controls your encryption keys and is subject to the US CLOUD Act or equivalent legislation, a court order can compel key handover regardless of which algorithm was used. Genuine quantum-safe storage therefore requires client-controlled or customer-managed keys, combined with hosting in a jurisdiction aligned with your compliance obligations such as the EU under GDPR or Switzerland under the revised Federal Act on Data Protection (revFADP).
“The question is not whether quantum computing will break current encryption, but when. Organisations that wait until quantum computers exist have already lost.”
Michele Mosca, co-founder, Institute for Quantum Computing, University of Waterloo
Questions to Ask Any Provider
Before signing a contract, IT managers and CISOs should request explicit answers to the following:
- Which NIST FIPS post-quantum standards (203, 204, 205) have you implemented, and at which layer: transport, key encapsulation, or signing?
- Which cryptographic library handles PQC operations, and has it been independently audited?
- Where are encryption keys stored, who controls them, and under which country’s legal jurisdiction?
- Is encryption at rest applied per-file, per-volume, or at the hardware level, and does it use AES-256 or a weaker variant?
- Do you offer hybrid encryption (classical plus post-quantum) during the transition period, and when will the classical component be deprecated?
How Managed Nextcloud Deployments Address This
Nextcloud Enterprise, the open-source collaboration platform, supports end-to-end encryption and can be configured with post-quantum key encapsulation through integration with PQC-capable libraries. Managed deployments, such as those offered by Qsentinel, take this further by layering NIST-compliant post-quantum cryptography over the standard Nextcloud encryption stack, hosting infrastructure in Switzerland or on-premise at the client’s site, and providing customer-managed key options that remove provider access to plaintext data entirely. This architecture directly addresses both the algorithmic vulnerability (quantum-resistant algorithms) and the jurisdictional vulnerability (no foreign cloud act exposure).
For organisations evaluating alternatives to Microsoft 365 or Google Workspace, the comparison is not only about features. It is about whether the provider’s cryptographic architecture, hosting location, and key control model will remain defensible over a ten-year horizon, which is precisely the window in which quantum threats are expected to materialise.
FAQ: Quantum-Safe Cloud Storage
Is AES-256 encryption already quantum-safe for stored data?
AES-256 at rest is considered relatively resistant to quantum attacks because Grover’s algorithm only halves the effective key length, leaving 128 bits of quantum security. However, the key exchange and authentication mechanisms used alongside AES are typically RSA or ECC-based, which are vulnerable to Shor’s algorithm. Quantum-safe storage requires replacing those asymmetric components with NIST-approved post-quantum algorithms.
What is a “harvest now, decrypt later” attack?
Adversaries intercept and store encrypted data today, before quantum computers exist, planning to decrypt it once sufficiently powerful quantum hardware becomes available. Sensitive data with a long confidentiality horizon, such as medical records, legal documents, or intellectual property, is especially at risk.
Which NIST post-quantum standards apply to cloud storage specifically?
NIST FIPS 203 (ML-KEM, based on CRYSTALS-Kyber) governs key encapsulation and is the most directly relevant standard for securing data in transit and for key wrapping in storage scenarios. FIPS 204 (ML-DSA) covers digital signatures used for authentication and integrity verification. Both were finalised by NIST in August 2024.
Does hosting location matter for quantum-safe storage?
Yes. Regulatory frameworks including GDPR and the Swiss revFADP restrict where personal data may be processed. Beyond compliance, encryption key sovereignty matters: if a provider controls your keys and is subject to the US CLOUD Act, post-quantum algorithms alone do not protect you from compelled disclosure.
How do I verify that a provider actually implements post-quantum cryptography?
Ask for the specific algorithm names and FIPS references in the service agreement or technical documentation. Request the name of the cryptographic library used, such as liboqs or a BoringSSL fork with Kyber support, and whether the implementation has been independently audited. Vague claims without algorithm specifics are a red flag.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
