50 Years Of RSA: Preparing For The Internet’s Next Cryptographic Transition

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
RSA succeeded beyond what its creators could have imagined. But as we approach its 50th anniversary, we are also approaching a historic inflection point.

Dr. Amit Sinha is CEO of DigiCert. Prior to DigiCert, he was President of Zscaler.

getty​In April 2027, the technology industry will mark 50 years since the MIT technical memo from Ronald Rivest, Adi Shamir and Len Adleman introduced the RSA algorithm, one of the most important practical implementations of public-key cryptography. Its formal journal publication followed in 1978, but the transition began in 1977.

Whitfield Diffie and Martin Hellman introduced the concept of public-key cryptography the year before, but RSA turned it into a practical method for secure communication between parties who had never met and shared no prior secret. It also made digital signatures practical, enabling identity verification and authentication across open networks.

Half a century later, the trust model RSA helped make practical, including public keys, digital signatures and certificate-based identity, still underpins much of the modern internet, even as algorithms have evolved. Modern TLS increasingly relies on elliptic-curve methods, and TLS 1.3 eliminated RSA key exchange. RSA’s enduring legacy is the broader architecture of certificates, signatures and key-exchange protocols it helped establish.

Every time we open a banking application, complete an online purchase, connect to a VPN or verify the authenticity of a website, we rely on public key infrastructure (PKI), a framework rooted in these cryptographic concepts that enabled digital trust to scale across billions of users, devices and systems.

In many ways, RSA succeeded beyond what its creators could have imagined. But as we approach its 50th anniversary, we are also approaching a historic inflection point.

The mathematical problems that made RSA and elliptic-curve cryptography secure—specifically, the difficulty of factoring large numbers and solving discrete logarithms—are threatened by advances in quantum computing. While today’s classical computers cannot practically break these systems, a sufficiently powerful quantum computer could eventually do so using algorithms such as Shor’s.

The quantum threat is not distant or theoretical. Governments, cloud providers, browser vendors and technology companies increasingly agree that the transition to post-quantum cryptography should already be underway. Gartner has said conventional cryptography could become unsafe to use by 2029. NIST finalized ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures and has ​told organizations to start migrating today.

Two recent research results explain why the timeline just moved up. Researchers from Google, UC Berkeley, Stanford and Ethereum showed that Shor’s algorithm could break ECC-256 encryption using fewer than 1,200 logical qubits. Under their assumptions, the attack could require fewer than 500,000 physical qubits, roughly a 20-fold reduction from previous estimates. A separate team from Oratomic, Caltech and UC Berkeley estimated that Shor’s algorithm could operate at cryptographically relevant scales with as few as 10,000 reconfigurable atomic qubits. With greater parallelism, the researchers estimated that roughly 26,000 qubits could break ECC-256 in about 10 days, while approximately 102,000 could break RSA-2048 in about 97 days.

Major infrastructure providers have turned that math into deadlines. Google set a 2029 target to migrate its full stack, including Chrome, Android and Cloud, to post-quantum cryptography, citing faster-than-expected progress. Cloudflare matched that target. Microsoft has since moved its own quantum-safe deadline to 2029. Three companies that run large parts of the internet’s infrastructure are now on the same timeline.

The urgency is amplified by a second reality: Cryptography is deeply embedded across enterprises, often without centralized visibility. Decades of digital transformation have distributed certificates, keys, encryption libraries, machine identities, APIs, connected devices and cloud workloads across business units and environments. Organizations cannot modernize cryptography they cannot see.

That gap is about to get harder to ignore. The CA/Browser Forum has set a schedule that shrinks the maximum lifespan of public TLS certificates from 398 days today to 200 days in 2026, 100 days in 2027 and 47 days by 2029, the same year major technology providers are targeting for post-quantum migration. Manual renewal processes become untenable as certificates approach 47-day lifespans.

Quantum readiness, therefore, is not simply about deploying a new algorithm. Organizations must understand where cryptography exists, which systems depend on it and whether those systems can evolve without disruption. That makes crypto-agility, or the ability to rapidly discover, manage and update cryptographic assets, a critical cybersecurity priority.

For most enterprises, quantum readiness should begin with five actions: inventory cryptographic assets, classify data by sensitivity and useful life, identify systems that depend on RSA or ECC, test post-quantum and hybrid approaches in controlled environments, and automate certificate lifecycle management so algorithms and certificates can be rotated without disruption.

These investments address more than quantum readiness. Certificate lifespans are shrinking, machine identities are multiplying across cloud and AI systems and expectations around cryptographic governance are increasing. Cryptographic inventory, certificate lifecycle automation, centralized visibility and modern PKI can help organizations address these challenges today while preparing for post-quantum migration.

This transition will not stop at websites and VPNs. The same trust principles that let browsers authenticate websites will increasingly be needed to authenticate software, digital content, connected devices and AI agents. As synthetic media and autonomous systems proliferate, organizations will need to verify identity, prove content provenance and determine whether AI agents are authorized to act.

RSA’s 50th anniversary represents both an ending and a beginning. It celebrates one of cryptography’s most influential innovations while signaling a new transition in how trust is established across the internet, cloud, AI systems and connected devices.

The next era of digital trust will not be built on a single algorithm. It will be built on crypto-agility: the ability to know where trust exists, prove it continuously and change it quickly when standards, threats or business requirements shift.

RSA helped create the modern internet by enabling trust at global scale. Succeeding in the quantum era will require organizations to treat cryptography as a living system that evolves alongside technology. The transition has already begun. The question is no longer whether organizations need to prepare but whether they can prepare fast enough.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/10/05/50-years-of-rsa-preparing-for-the-internets-next-cryptographic-transition/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business