Education
Grover's algorithm and AES: why symmetric crypto mostly survives
Boards often ask whether quantum computers break all encryption. Grover's algorithm affects symmetric crypto — but the mitigation path is different from the RSA/ECC crisis.

Grover vs Shor
| Algorithm | Targets | Impact | Mitigation |
|---|---|---|---|
| Shor's | RSA, DH, ECC | Exponential speedup on factoring/ discrete log | New PQC algorithms (ML-KEM, ML-DSA) |
| Grover's | Symmetric keys, hash preimage | Quadratic speedup (effective key halved) | Double key sizes (AES-128 → AES-256) |
NIST's PQC overview treats public-key migration as the urgent program; symmetric upgrades follow established key-length guidance.
Practical guidance
- Prefer AES-256 for data at rest and TLS bulk encryption where policy allows.
- Ensure key derivation and wrapping use quantum-safe public-key layers — AES alone does not fix RSA-protected key exchange.
- Do not defer PKI migration because AES still works; Shor's breaks the envelopes protecting AES keys in most protocols.
ML-KEM (FIPS 203) addresses key exchange; AES handles bulk encryption after keys are established.
This quarter
- Audit systems still on AES-128 for long-retention data.
- Prioritize RSA/ECC replacement in TLS and key wrapping before symmetric key upgrades.
- Document algorithm inventory including both public-key and symmetric suites.
Continue on the Q-Day hub: What is Q-Day? guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- What Makes Quantum Computers SO Powerful?Veritasium (YouTube) · 2023Covers Shor's threat, harvest-now-decrypt-later, NIST PQC competition, and migration urgency.
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)NIST · 2024-08Standardized post-quantum key encapsulation (formerly Kyber).
- Shor's Algorithm: A Quantum Threat to Modern CryptographyPostQuantum.com · 2024Written explainer for security professionals — RSA, ECC, Shor's steps, and PQC migration strategies.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.