Author:
Engineer Đỗ Hoàng Sơn
On August 13, 2024, the United States National Institute of Standards and Technology (NIST) announced its first three completed post-quantum cryptographic standards, comprising FIPS 203 on key establishment, and FIPS 204 and FIPS 205 on digital signatures.
Post-quantum cryptography, abbreviated as PQC, refers to algorithms designed to withstand known attack methods from both conventional computers and quantum computers. After issuing the standards, NIST recommends that organizations begin planning their transition as early as possible, since the process of inventorying, replacing algorithms, and upgrading products can take years.
For elevators, the urgency does not lie in an existing quantum attack, but rather in the disparity between the long lifecycle of the equipment and the pace of change in cryptographic technology.
When elevators become connected devices
Modern elevators are no longer standalone mechanical–electrical systems. Many major manufacturers have developed dedicated connectivity platforms for their elevator monitoring systems.
Depending on the configuration, operational data may be transmitted to a monitoring platform for equipment condition analysis and predictive maintenance support. Elevators can also connect to building management systems, access control, smartphone calling applications, or other digital services. Some architectures even allow for on-site or remote updates of software code and configuration.
Each of these communication channels is protected by a type of digital key — like a lock but based on mathematical algorithms. The two most common types of keys today are called RSA and ECC.
What they have in common: both are based on mathematical problems that would take conventional computers thousands of years to solve, but a sufficiently powerful quantum computer could solve in a few hours.

As elevators continue to evolve from standalone electromechanical systems into connected, software-controlled platforms, cybersecurity has become nearly as important as physical safety.
According to the Global Risk Institute's 2024 Quantum Threat Timeline Report, surveyed experts estimated the probability of RSA cryptography being broken within the next 15 years at approximately 33%, and within 30 years at over 70%.
This is an expert probability assessment, not a determined timeline. But for equipment with a lifecycle measured in decades, that uncertainty still needs to be factored into the design process.
Three challenges for elevators
Equipment lifecycle exceeds cryptographic lifecycle
An elevator installed in 2026 may still be in operation in the 2040s or 2050s. Meanwhile, NIST's transition roadmap draft aims to phase out or discontinue acceptance of many public-key algorithms vulnerable to quantum computers after 2035.
This is precisely the scenario that the cybersecurity community calls harvest now, decrypt later, applied to physical infrastructure: attackers can collect data and control codes today, store them, and wait for quantum computers to emerge to unlock them and inject malware into equipment that was installed long ago.
Cyber incidents can affect operations
The direct impact of a cyberattack on an elevator system could include service disruption, corruption of diagnostic data, unauthorized access to maintenance tools, or loss of monitoring connectivity.
Whether a cyber incident can spread to safety functions depends on the architecture of each system, particularly the degree of separation between the connectivity platform, the operational controller, and the safety circuits.
Therefore, it cannot be assumed that breaching the cloud service equates to the ability to disable brakes or safety mechanisms. However, for a device that directly transports people, every connection to the control system needs to be carefully assessed and protected in multiple layers.
Legacy equipment is not easily upgraded
An elevator system may consist of multiple components with varying computing capabilities: controllers, communication boards, monitoring devices, connectivity gateways, and cloud servers. Some older embedded devices have limited memory, processing capability, and bandwidth.
Meanwhile, the keys, ciphertexts, and signatures of some post-quantum algorithms are significantly larger than those of RSA or ECC. The transition may therefore require changes to software, communication protocols, or even hardware.
It can be compared to requiring a 50cc motorbike to carry the same payload as a truck — not impossible, but it requires a complete redesign.

New post-quantum cryptographic algorithms require many times more memory and bandwidth than older algorithms.
The elevator industry is not entirely on the sidelines
Elevator cybersecurity has been addressed within the international standards system.
ISO 8102-20:2022 specifies cybersecurity requirements for new elevators, escalators, and moving walks. The standard covers the stages of product development, manufacturing, installation, operation, maintenance, and disposal; it also establishes minimum requirements for essential functions, safety functions, and alarm functions.
In February 2026, ISO continued by publishing ISO/TS 8102-21:2026, addressing on-site and remote software code and configuration updates. This document does not apply to equipment installed prior to its publication date — precisely the group that may face the most difficulty in transitioning technology.
Major manufacturers have also implemented cybersecurity programs, secure product development processes, or vulnerability disclosure channels.
However, in the publicly available product documentation reviewed, no manufacturers have been found to specifically disclose post-quantum algorithms or transition deadlines for individual product lines.

Elevator cybersecurity has been addressed within the international standards system.
Mr. Dustin Moody, Head of NIST's Post-Quantum Cryptography Project, in a speech at a major cybersecurity conference in 2024, emphasized: manufacturers of long-term infrastructure equipment need to design this flexibility into their current product lines, to avoid having to replace hardware en masse in the 2030s.
Cryptographic flexibility can be compared to a multi-standard electrical outlet system: a building designed to standard does not need to demolish walls when plug standards change, only to replace the outlet faceplate. Conversely, a device with encryption keys hard-cast into the chip is like wiring soldered directly into the wall — changing it requires demolition.
Where does Vietnam stand in this picture?
Vietnam has two layers of policy simultaneously addressing this issue. At the quantum strategy layer, Decision No. 1018/QĐ-TTg of September 2024 approved Vietnam's Semiconductor Industry Development Strategy to 2030, with a vision to 2050, along with efforts to develop a National Strategy on Quantum Technology, laying the foundation for developing domestic post-quantum cryptographic capabilities.
At the infrastructure cybersecurity layer, the 2015 Law on Information Security and the 2018 Law on Cybersecurity have established the concept of information systems critical to national security, but the specific list under Decree 85/2016/NĐ-CP mainly focuses on finance, telecommunications, and energy — it does not yet include in-building transport infrastructure.
Along with the growth of smart buildings, the number of elevators integrated with remote monitoring, mobile applications, and building management systems will continue to increase. Most newly installed elevators today are already internet-connected — meaning that each year Vietnam is adding tens of thousands of quantum-vulnerable points to its urban infrastructure.
The lesson is not to ban elevator imports or wait for post-quantum cryptography to be perfected before installing. The lesson is three tasks that need to be done in parallel:
(1) Update the list of critical infrastructure to bring smart building control systems (including connected elevators) under enhanced cybersecurity management;
(2) Incorporate cryptographic flexibility requirements into national standards (TCVN) for connected elevators;
(3) Build domestic post-quantum cryptographic certification capabilities to avoid complete dependence on certificates issued by foreign laboratories.
The question that needs to be asked about an elevator installed today is not "has the device used post-quantum cryptography yet," but rather: 10 or 20 years from now, when cryptographic standards change, can the system be upgraded without having to replace the entire controller?
For infrastructure that may continue operating until 2050, the answer needs to be determined right from when the equipment is still on the drawing board.






























