Post-Quantum Cryptography
Proof of Concept Results and Crypto-Migration Strategy at Daiwa Securities Group
July 24, 2026
Summary
◆With the advancement of quantum computers, currently widely used public-key cryptography such as RSA and elliptic curve cryptography may face decryption risks in the future. In particular, preparing for “Harvest Now, Decrypt Later” (HNDL) attacks—where encrypted data is collected now to be decrypted later—is crucial for financial institutions that require long-term confidentiality. Adapting to PQC is not only a medium- to long-term security issue but also a management issue. In addition, the U.S. National Institute of Standards and Technology (NIST) published its first PQC standards in 2024, and in Japan, transition studies are underway in the government and financial sectors with an eye toward around 2035.
◆The Daiwa Securities Group conducted a PQC proof-of-concept (PoC) experiment using the development environment of its online services. The verification results confirmed that for general web service applications in this demonstration environment, the impact on communication due to the PQC adaptation of key exchange (KEM) is limited. The increase in TLS handshake time during key exchange was limited, and no significant increase in CPU or memory usage was observed even with a PQC software-compatible load balancer, with the increase in communication volume remaining at about 5%. On the other hand, since an increase in communication volume due to the larger key and certificate sizes associated with the change to PQC will inevitably occur, individual impact assessments are necessary for systems with narrow communication bandwidths, poor communication quality, or strict low-latency requirements.
◆In practice, it is important not to view the PQC transition as a simultaneous overhaul, but to proceed in the following order: (1) inventory of cryptographic assets, (2) development of a cryptographic inventory, (3) risk assessment and prioritization, (4) roadmap formulation, and (5) phased transition. As of March 2026, the standardization of PQC signatures and certificates has not been completed. Discussions on how to use them in TLS and X.509 certificates are taking place in the Internet Engineering Task Force (IETF), and operational rules for public PKI are being discussed in the Certification Authority/Browser Forum (CA/B Forum). Therefore, in the first phase of the transition, it is realistic to start with key exchange, which is effective against HNDL attacks and has advanced implementation, and to proceed with PQC adaptation for signatures and certificates while monitoring standardization and product support. It is desirable to proceed in stages, prioritizing critical systems and focusing on responses at the edge termination and common cryptographic infrastructure, while keeping crypto-agility in mind.
Appendix
Daiwa Institute of Research Ltd. reserves all copyrights of this content.
Copyright permission of Daiwa Institute of Research Ltd. is required in case of any reprint, translation, adaptation or abridgment under the copyright law. It is illegal to reprint, translate, adapt, or abridge this material without the permission of Daiwa Institute of Research Ltd., and to quote this material represents a failure to abide by this act. Legal action may be taken for any copyright infringements. The organization name and title of the author described above are as of today.