How does Cryptosmart Mobile ensure long-term protection of sensitive data against quantum threats?

  • Defence
  • Cyber
  • Cybersecurity
  • Type Product presentation

Discover through this article how Cryptosmart Mobile ensures long-term protection of sensitive data against quantum threats

© Ercom et Adobe stock

Quantum computing represents a major technological breakthrough which, in the long term, could compromise traditional encryption systems. Asymmetric algorithms such as RSA and ECC, currently used on a large scale, will become vulnerable to the future computing power of CRQCs (Cryptographically Relevant Quantum Computers). This threat is not only a future concern: attackers are already adopting methods aimed at intercepting and storing encrypted communications today in order to decrypt them in the future.

To counter this threat, organisations must adopt robust and scalable security solutions capable of resisting both present-day and future attacks. In this context, Cryptosmart, ERCOM’s security solution, positions itself as an essential protection layer for devices, data, and communications. It integrates hybrid encryption mechanisms combining proven technologies with post-quantum resistant algorithms. Through this article, discover how Cryptosmart Mobile enables organisations to protect their data exchanges today while ensuring a smooth transition towards tomorrow’s security standards thanks to its progressive approach.

1. The challenges of post-quantum security for mobile communications

The security of mobile communications is facing increasingly sophisticated threats, among which quantum attacks are becoming a major concern. These concrete threats manifest themselves in several ways:

  • Passive attacks (Harvest Now, Decrypt Later – HNDL): This approach consists of intercepting and storing encrypted communications today while waiting for the arrival of quantum computers capable of decrypting them in the future. Although passive, this threat is particularly insidious because it can compromise sensitive data over the long term.
  • Vulnerability of asymmetric algorithms (RSA, ECC): Asymmetric encryption algorithms such as RSA and ECC are widely used to secure communications. However, they are vulnerable to quantum attacks, meaning their effectiveness could eventually be compromised.

The post-quantum risk assessment can be better understood through the XYZ model. This model helps determine when an organisation should begin its transition towards post-quantum cryptography. It is based on three variables:

  • X: the duration for which data must remain protected
  • Y: the time required to migrate cryptographic systems to a post-quantum solution
  • Z: the number of years before quantum computers become capable of breaking current algorithms

If X + Y is greater than Z, the organisation is at risk: its data could be compromised if the transition has not started in time. This is why organisations must act now.

2. Cryptosmart Mobile: a hybrid PQC approach for enhanced protection

Cryptosmart Mobile adopts a hybrid and crypto-agile post-quantum approach. The solution integrates mechanisms combining both classical and post-quantum cryptographic building blocks. It is also designed to evolve over time according to changes in standards, performance requirements, and newly discovered vulnerabilities.

Crypto-agility refers to a system’s ability to rapidly integrate new algorithms or replace existing ones without redesigning the overall architecture or disrupting users. This approach is essential in a context where post-quantum algorithms, although promising, remain relatively new and may evolve significantly in the years ahead.

Integrated technologies include:

  • ML-KEM-1024, a post-quantum key encapsulation mechanism standardised by NIST under FIPS 203 (formerly CRYSTALS-Kyber)
  • A hybrid approach combining post-quantum and pre-quantum encryption to maximise resilience
  • Compatibility with cyberSIM and existing infrastructures, ensuring deployment without impact on devices already in production
  • Backward compatibility with previous versions of Cryptosmart Mobile & PC

Since August 2024, the main post-quantum algorithms selected by NIST have officially been incorporated into FIPS standards:

  • FIPS 203: ML-KEM
  • FIPS 204: ML-DSA (formerly Dilithium)
  • FIPS 205: SLH-DSA (formerly SPHINCS+)

Only Falcon, although selected, currently remains in draft form under the future FIPS 206: FN-DSA.

At the same time, FrodoKEM, an algorithm supported by ANSSI and the BSI, is currently undergoing ISO standardisation. Its mathematical robustness and alignment with certain European requirements make it a strategic alternative, once again demonstrating the importance of an open, modular, and scalable architecture.

Cryptosmart Mobile is currently the only sovereign solution capable of delivering encrypted voice communications integrating post-quantum cryptography. This unique capability has already been demonstrated through several experiments conducted since 2021, including the first secure PQC telephone calls. These achievements prove that the solution is not merely theoretical, but already operational in the field to meet future security requirements.

3. Key requirements for a post-quantum mobile security solution

To ensure effective protection against quantum threats, a post-quantum mobile security solution must meet several key requirements:

  • Sovereignty, security, standardisation, certification: Certifications and validations from trusted organisations such as ANSSI guarantee compliance with the highest security standards. ERCOM is committed to delivering security solutions that respect the digital sovereignty of its customers.
  • Migration, crypto-agility, backward compatibility, operations: The solution must be easy to deploy and manage in order to minimise operational disruption. It must remain compatible with existing infrastructures to facilitate the transition towards PQC. The solution must also be designed to evolve alongside emerging threats and technologies, ensuring long-term protection.
  • User experience: The solution must remain transparent and easy to use for end users to ensure adoption and satisfaction. It must not significantly impact device performance in order to maintain an optimal user experience.

4. Why choose Cryptosmart Mobile?

Thanks to its proven expertise and advanced technological approach, ERCOM provides a structured three-phase migration strategy:

Phase 1: Cryptosmart

Immediate protection against passive attacks through ML-KEM, now standardised as FIPS 203.

Phase 2: Securing digital signatures

Integration of hybrid post-quantum digital signatures compliant with FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).

Phase 3: Full transition to post-quantum cryptography

Adoption of future fully PQC-compatible components, integration of upcoming ANSSI recommendations, European certifications, and support for future standards such as FIPS 206 or ISO FrodoKEM.

Cryptosmart Mobile is the only solution currently available that integrates post-quantum protection against passive attacks. Unlike alternative solutions, ERCOM offers a deployable solution available today, together with long-term support.

  • Cryptosmart already integrates immediately usable PQC protection
  • It is a sovereign solution developed in France, compliant with ANSSI and European requirements
  • Cryptosmart Mobile ensures a progressive transition and compatibility with existing infrastructures
  • ERCOM anticipates future standards to ensure continuity of protection

Conclusion

Cryptosmart Mobile positions itself as the comprehensive solution for protecting mobile communications against quantum threats, both today and tomorrow. Thanks to its advanced capabilities, the solution delivers long-term, sustainable protection that evolves alongside emerging threats, enabling organisations to stay ahead.

Do not let quantum threats compromise the security of your communications. Contact ERCOM today and request a meeting to deploy your post-quantum mobile security solution with Cryptosmart Mobile.