The International Organization for Standardization (ISO) has officially approved the post-quantum algorithm Classic McEliece as part of the updated asymmetric encryption standard ISO/IEC 18033-2. This decision marks a crucial step in global preparations for the era of quantum computing, when traditional cryptosystems such as RSA and the Diffie-Hellman protocol will become vulnerable.
Time-Tested Cryptographic Strength
Classic McEliece, developed back in 1978 by Robert McEliece, fundamentally differs from conventional algorithms. Instead of mathematical problems like factorization or discrete logarithms, it uses coding theory, specifically binary Goppa codes for error correction. This fundamental difference makes it resistant to attacks from quantum computers, which can efficiently solve classical problems.
According to experts at the Okinawa Institute of Science and Technology, this algorithm is one of the most conservative and reliable designs in post-quantum cryptography. Over more than 45 years of existence, the system has not only remained unbroken but has also withstood all known cryptanalytic attacks, confirming its high safety margin.
The Main Trade-off: Key Size
A key feature of Classic McEliece is the enormous size of its public key — ranging from 255 KB to 1.3 MB. This is a significant drawback for mobile devices and the Internet of Things. However, developers at Post-Quantum note that the ciphertext size remains compact (up to 208 bytes). This makes the scheme ideal for scenarios with static keys, such as VPN connections, file encryption, or database protection.
Global Recognition and Future Standardization
The ISO decision is of great importance, as the U.S. National Institute of Standards and Technology (NIST) previously postponed the standardization of Classic McEliece, favoring the HQC algorithm. Nevertheless, NIST has left open the possibility of adopting a standard based on the ISO version in the future. Recognition by ISO paves the way for adoption by governments and companies from the organization's 177 member countries.
Classic McEliece is already mentioned in recommendations from regulators in the Netherlands and Germany, and its support has been implemented in projects such as Debian, Ubuntu, and the Bouncy Castle library. Moreover, Post-Quantum, together with STV Group, successfully tested the algorithm on combat drones under limited communication conditions, proving its viability even with massive keys.
Expert Opinion: The standardization of Classic McEliece is not just a technical achievement but a strategic signal for the entire industry. While NIST and other regulators deliberate, ISO is already laying the groundwork for practical implementation. For the cryptocurrency sector, where protecting long-term assets (e.g., "sleeping" wallets from the Satoshi era) is critical, this step could become a starting point for migration to post-quantum algorithms. The only question is how quickly the industry can adapt to the gigantic key sizes.