The safest biometric database is the one that was never built.
A calm version of the quantum argument
Most quantum security copy asks you to be afraid. This paper asks you to be precise instead about what actually breaks and what the field has already shipped in response. No cryptographically relevant quantum computer exists. The replacement standards were finalized in August 2024, which turns migration into a scheduling problem rather than a research problem.
So the urgency was never about the machine. It is about data recorded today under encryption that will not hold for the lifetime of the secret inside it. A biometric is the extreme case: valid for a lifetime, reused at every service that verifies the same face, and impossible to reset.
What the paper establishes
Harvest now, decrypt later needs no quantum computer in the present. It needs cheap storage, patience, and a target whose value survives the wait. Almost no data clears that bar. A face clears it without effort.
From there the paper argues for absence over strength. A control you can buy protects a store that still exists, and a store that still exists is what the patient attacker is recording against. The triage is run honestly, including on our own architecture.
- What Shor's and Grover's algorithms actually threaten, and why the distinction decides your migration order
- Mosca's inequality as the planning tool, applied to a credential with a human lifetime
- An artifact-by-artifact account of what a full-take recording of a SenseCrypt deployment yields, at capture time and after a future decryption
- Which primitives the face token is built from, and the precise sense in which that construction is quantum-safe
- The honest boundary: where the claim stops, stated so a risk register can quote it
- A five-point checklist any operator can apply to their own biometric estate
Who it is for
Cryptographers, risk leads, and anyone assembling a post-quantum migration inventory. The claims are scoped tightly enough to be checked rather than taken on trust, and the closing checklist applies to whatever biometric estate you already run.
One caution before you quote it. The quantum-safe claim in this paper belongs to one construction, not to the platform, and a risk register that loses that distinction is worse than one that never drew it.
Frequently asked questions
Is SenseCrypt a quantum-safe platform?
No, and the paper says so directly rather than in a footnote. The face token construction is quantum-safe because it uses symmetric and hash primitives exclusively; the protocol layer around it is classical public-key cryptography that migrates with the industry's standards. The paper draws that boundary precisely, which is the point of it.
Why act before a quantum computer exists?
Because the recording happens now. Traffic captured today under classical encryption can be opened later, so the question is whether anything inside it still has value by then. For most data the answer is no. The paper is about the data for which it is yes.
How long is it?
Seven pages, including a capture-and-decrypt artifact table and a timeline diagram.
Related reading






