Skip to content

Education

Grover's algorithm and AES: why symmetric crypto mostly survives

Boards often ask whether quantum computers break all encryption. Grover's algorithm affects symmetric crypto — but the mitigation path is different from the RSA/ECC crisis.

Grover's algorithm impact on AES key sizes.
What Makes Quantum Computers SO Powerful? Watch on YouTube

Grover vs Shor

AlgorithmTargetsImpactMitigation
Shor'sRSA, DH, ECCExponential speedup on factoring/ discrete logNew PQC algorithms (ML-KEM, ML-DSA)
Grover'sSymmetric keys, hash preimageQuadratic speedup (effective key halved)Double key sizes (AES-128 → AES-256)

NIST's PQC overview treats public-key migration as the urgent program; symmetric upgrades follow established key-length guidance.

Practical guidance

  • Prefer AES-256 for data at rest and TLS bulk encryption where policy allows.
  • Ensure key derivation and wrapping use quantum-safe public-key layers — AES alone does not fix RSA-protected key exchange.
  • Do not defer PKI migration because AES still works; Shor's breaks the envelopes protecting AES keys in most protocols.

ML-KEM (FIPS 203) addresses key exchange; AES handles bulk encryption after keys are established.

This quarter

  1. Audit systems still on AES-128 for long-retention data.
  2. Prioritize RSA/ECC replacement in TLS and key wrapping before symmetric key upgrades.
  3. Document algorithm inventory including both public-key and symmetric suites.

Continue on the Q-Day hub: What is Q-Day? guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.