24 September 2026

Pentagon Math Over Physics

Small Wars Journal | Morgan Bazilian, Chris Bronk

The US Department of War’s June 2026 Post-Quantum Cryptography Strategy mandates that all high-impact military systems transition to quantum-resistant algorithms by December 31, 2030, to prevent adversaries from decrypting intercepted national security communications. This directive explicitly bans quantum key distribution, a physics-based encryption method heavily prioritised by China.

The decision highlights a fundamental divergence in cryptographic philosophy between Washington's software-centric approach and Beijing's extensive hardware-based quantum network. While China has fielded a 1,250-mile Beijing-to-Shanghai quantum network and a ground-to-space capability, the Pentagon rejected this infrastructure-heavy model due to signal degradation at vulnerable relay nodes. Instead, the American strategy relies on mathematical standards finalised by NIST in August 2024, including ML-KEM and ML-DSA. Security remains provisional. In 2022, researchers broke a leading post-quantum candidate using a single desktop computer, highlighting the risks of relying on mathematically unproven algorithms. Implementation falls on individual military services, raising concerns over potential delays.

Comment

The Pentagon's rejection of quantum key distribution in favour of software-based post-quantum cryptography shifts the US military's security burden from physical infrastructure to mathematical integrity. By adopting the National Institute of Standards and Technology's FIPS 203 standard, known as ML-KEM, the United States avoids the immense capital expenditure of deploying dedicated hardware across global military networks. This software-first approach allows rapid deployment across legacy tactical networks, but it introduces a systemic vulnerability if the underlying lattice-based mathematics of ML-KEM are compromised by unforeseen cryptanalytic breakthroughs.

The operational mechanism of this transition relies on the National Security Agency's Commercial National Security Algorithm Suite 2.0, which mandates specific key sizes and signature schemes to withstand quantum attacks. Unlike China's Micius satellite network, which requires trusted physical relay stations to regenerate weakened photon signals, the American model relies on mathematical complexity that can be updated via software patches. However, the 2022 compromise of the SIKE algorithm by researchers at KU Leuven demonstrates that mathematical assumptions can fail instantly, leaving entire suites of military hardware vulnerable without physical recourse.

Strategic Question for Discussion
If a mathematical vulnerability is discovered in the ML-KEM algorithm before the 2030 deadline, how would the National Security Agency adapt its Commercial National Security Algorithm Suite 2.0 without disrupting active tactical networks?
The available evidence points toward a reliance on hybrid cryptographic implementations, which run classical and post-quantum algorithms in parallel to mitigate sudden mathematical failures. In the event of an ML-KEM compromise, the National Security Agency would likely fall back on alternative lattice-based standards or accelerate the deployment of secondary algorithms like ML-DSA for digital signatures. This dual-track transition framework suggests that the Pentagon's architecture is designed to absorb algorithmic failures without requiring immediate hardware overhauls.
Share your assessment in the comments below.