ICTK and Jiran Security are building Q-BRIDGE to connect cryptographic asset discovery with hardware-rooted post-quantum security for enterprise, government, and financial clients
Post-quantum migration is moving from abstract risk assessment toward a defined hardware deployment workflow through Q-BRIDGE, a new initiative from South Korean companies ICTK Co., Ltd. and Jiran Security.
The companies have signed a Memorandum of Understanding to offer end-to-end Post-Quantum Cryptography migration for enterprise, government, and financial-sector clients. Reports published in South Korea on September 17-18, 2026 describe Q-BRIDGE as a five-stage framework: cryptographic-asset inventory, analysis of exposure to quantum attacks, deployment of a PQC-based trust infrastructure, field testing, and full system migration.
The central proposition is operational rather than algorithmic: identify where cryptography is used, assess the exposure, plan the transition, then connect that plan to security hardware capable of supporting post-quantum algorithms. This distinction is important because choosing a quantum-resistant primitive is only one part of a migration. An organization must also locate certificates, keys, protocols, libraries, devices, and applications that depend on legacy public-key cryptography.
Jiran Security will lead the opening stage through its Crypto Discovery platform. The software is intended to scan an organization's cryptographic assets and support vulnerability analysis, quantum-risk scoring, and migration planning. Jiran says the platform is used across a domestic base of more than 6,000 internal clients in South Korea, giving the inventory component a potentially substantial operational footprint.
That inventory step matters because a migration cannot be managed reliably if an organization does not know which certificates, keys, security modules, network links, and applications depend on existing cryptographic infrastructure. It also helps identify long-lived information that could be collected now and decrypted later if future quantum computers make currently deployed public-key systems vulnerable.
Quantum risk is not identical across all algorithms. Shor's algorithm provides a theoretical route to breaking integer-factorization and discrete-logarithm systems such as RSA and elliptic-curve cryptography on a sufficiently capable fault-tolerant quantum computer. Grover's algorithm offers a quadratic search speedup against generic symmetric-key search, which is generally addressed through suitable key-length choices rather than by replacing symmetric cryptography with a quantum protocol.
ICTK supplies the hardware layer. Its architecture combines post-quantum algorithms with the company's silicon-proven VIA PUF(TM) Hardware Root of Trust chips. A Physically Unclonable Function is used here as the foundation for hardware-rooted security: physical variations introduced during semiconductor fabrication can provide device-specific responses, although the security value depends on implementation, enrollment, error correction, protection against modeling attacks, and secure lifecycle management.
The partnership's stated goal is to connect that trust layer with the broader systems required for deployment. ICTK's responsibilities include the design, supply, integration, and interoperability verification of post-quantum Certificate Authorities, Key Management Systems, Hardware Security Modules, and Virtual Private Networks. The company also identifies PQC algorithm acceleration across NIST and KpqC requirements as part of its technical mandate.
Current standardization work provides a useful technical reference point. NIST has selected and standardized lattice-based mechanisms including ML-KEM for key establishment and ML-DSA for digital signatures, alongside the hash-based signature standard SLH-DSA. These mechanisms are designed to run on classical computing infrastructure, but their real-world security still depends on correct parameter selection, implementation quality, side-channel resistance, certificate handling, and safe integration into existing protocols. The agency's PQC program overview places algorithm selection within a broader transition and inventory effort.
The division of labor gives Q-BRIDGE a clear architecture. Jiran Security handles client engagement, diagnostic auditing, risk assessment, roadmap consulting, and project management. ICTK handles hardware supply, integration, testing, performance verification, and field Proofs-of-Concept. Independent research communities at MIT and CERN have demonstrated how rapidly advanced computing and experimental infrastructure can evolve, but neither quantum progress nor laboratory capability automatically translates into a production-ready attack against deployed cryptographic systems.
The partners plan field PoCs to test multi-vendor interoperability. That is a more meaningful test of readiness than a standalone algorithm demonstration because enterprise migration involves several systems that must exchange certificates, keys, authentication data, and protected traffic without interrupting existing operations.
According to an earlier analysis of quantum-safe networking, post-quantum protection belongs to a wider security transition that can involve both conventional infrastructure and newer quantum-related technologies. Q-BRIDGE is focused specifically on PQC migration and hardware-rooted protection rather than quantum key distribution.
In practice, a credible PoC should measure more than whether two endpoints can complete a handshake. Relevant observations include certificate-chain compatibility, key-generation and encapsulation latency, signature size, handshake bandwidth, CPU and memory overhead, HSM throughput, failure recovery, logging, credential rotation, and behavior during algorithm or certificate changes. A field test can expose integration constraints that remain invisible in a laboratory benchmark.
The initiative also proposes joint bids for South Korea's national public-sector and defense-sponsored PQC modernization projects. Those bids are planned activities, not evidence that the partners have already secured contracts or completed deployments. The same distinction applies to the PoCs: they are intended to validate interoperability and performance, but the announcement provides no results from those tests.
Q-BRIDGE addresses a real bottleneck by joining cryptographic discovery to physical security infrastructure. Yet the announcement does not provide measured deployment performance, migration timelines, customer PoC results, algorithm benchmarks, certification outcomes, or independent verification. It therefore establishes a partnership structure rather than a demonstrated end-to-end system.
The technical challenge will be proving that the proposed stack works across the varied environments it is meant to serve. Certificate authorities, key management systems, hardware security modules, and VPNs must interoperate with existing software and equipment while maintaining dependable key handling and operational continuity. The release identifies interoperability testing as a task for ICTK, but does not report its outcome.
The wider Korean ecosystem described in industry coverage includes Hanbit S&I, Bigo, Unikey, and KAIST, with roles associated with networking, authentication, CA/PKI, and PQC-transition consulting. That broader participation suggests that the project is being positioned as more than a bilateral hardware-and-audit offering, although the available announcements do not establish completed integrations or quantified results from those participants.
That restraint is important in a field where the phrase "post-quantum" can blur the difference between selecting an algorithm and completing a secure migration. Peer-reviewed work in Nature and related journals has shown that quantum algorithms are mathematically precise, but the engineering path from an algorithmic speedup to a large, fault-tolerant machine involves demanding requirements for error correction, physical qubits, control electronics, and system-scale reliability. Q-BRIDGE's immediate problem is narrower and more practical: preparing conventional organizations before such uncertainty becomes an operational emergency.
Q-BRIDGE has a practical advantage in its sequencing: Jiran's discovery process is intended to map the estate before ICTK's hardware is integrated. Whether that becomes a repeatable commercial framework will depend on field evidence, including transparent test conditions, supported algorithms and protocols, measured performance, security evaluation, and documented migration outcomes.
Post-quantum cryptography is designed to run within conventional computing and network infrastructure; it is not the same as quantum cryptography. A hardware root of trust can strengthen the protection and management of keys, but it does not by itself prove that an organization's entire cryptographic environment has been migrated or that every implementation is secure. Q-BRIDGE is therefore best understood as a credible integration plan with a useful division of responsibilities, not yet as a completed technology deployment.