SandboxAQ announced that the NIST (National Institute of Standards and Technology) has officially selected HQC (Hamming Quasi-Cyclic) as the fifth algorithm in its suite of post-quantum cryptographic (PQC) standards. Out of these five algorithms, three will be used for signatures. The other two, HQC and ML-KEM, will be the NIST-approved algorithms that will protect the confidentiality of communications across the Internet, cellular networks, payment systems, and more.
The selection of HQC marks SandboxAQ’s second major contribution to NIST’s post-quantum standardization effort, a key step in ensuring the protection of the world’s most critical data. This landmark decision represents a significant milestone in the global transition to a robust, quantum-safe encryption future and further solidifies SandboxAQ at the forefront of cryptographic innovation.
HQC is a key encapsulation mechanism designed to secure the exchange of encryption keys in a quantum-resistant manner. Unlike traditional public-key encryption systems such as the widely-used public key cryptosystem, RSA, and elliptic-curve cryptography (ECC), which quantum computers render obsolete, HQC is built on the well-established mathematical foundation of error-correcting codes, which is not vulnerable to quantum attacks. It provides strong security guarantees while balancing performance factors such as computational efficiency and key size, which are primary considerations for large-scale real-world deployments. In NIST’s final selection report, the HQC algorithm, co-invented by SandboxAQ team members, stood out as a robust and reliable candidate for wide-scale adoption across industries, following multiple rounds of global cryptanalysis and peer review.
Prior to HQC, the SandboxAQ team also played a significant role in the development of SPHINCS+, one of the initial algorithms already selected by NIST as part of its initial set of PQC standards in 2022. With HQC now formally accepted into the standardization process, SandboxAQ has contributed to two of the five critical PQC standards for key exchanges and signatures, demonstrating deep and sustained leadership in quantum-resistant cybersecurity and ushering in a safer digital world.
“HQC has foundations in coding theory that offer strong theoretical and practical protection against known quantum decryption methods, while its efficient performance profile makes it well-suited to real-world adoption,” said Taher Elgamal, Partner at Evolution Equity Partners and Senior Advisor at SandboxAQ, who is colloquially called ‘the father of SSL’. “With SPHINCS+ and HQC both standardized by NIST, SandboxAQ has solidified its leadership in developing effective PQC solutions for enterprises and government agencies. This is not just a milestone for SandboxAQ, it’s a win for global security in the face of future quantum disruption.”
“We began developing HQC in the 2000s, and by the 2010s, we had demonstrated that this protocol resolved a 40-year-old open problem in code-based key exchanges. Today, HQC stands as one of only two protocols securing the confidentiality of nearly all global communications,” said Carlos Aguilar Melchor, Chief Cybersecurity Scientist at SandboxAQ. “At SandboxAQ, we’ve long championed the importance of standardization, and contributing to two of the five NIST PQC standards reflects our commitment to shaping the future of cryptography.“
SandboxAQ has a unique position to improve cryptographic postures and ensure better compliance, fewer outages, and robust cybersecurity. It produces world-class cryptographic research, internationally recognized standards, and widely adopted cryptographic innovations. Leveraging this world-leading expertise, SandboxAQ also offers an industry-leading cryptography management product, uniquely positioning it within the global cryptographic landscape. Our flagship cryptographic offering, AQtive Guard, is trained on billions of cryptographic findings, meticulously structured and enriched with supplemental data by our world-class cryptography team. By cross-referencing and augmenting our customers’ inventories, we empower efficient exploration and actionable insights. Leveraging our distinctive AI approach, seamless third-party integrations, and comprehensive 360-degree coverage sensors, AQtive Guard delivers unparalleled visibility and effectiveness for the protection of enterprises and governments.