Project Oxygen & Ideo-LabIDEO LAB Dashboard 2026

Ultimate Cryptography Guide

A complete, practical guide inspired by the structure of your previous HTML guide: clear hero section, dense card grid, large modal deep-dives, tabs, and a lighter IDEO‑Lab look. This version covers classical cryptography, RSA, post‑quantum cryptography, military stakes, key management, “unbreakable code” myths, and a concrete migration roadmap.

Structure
24 cards + deep modals
Core axes
RSA ‱ PQC ‱ Defense ‱ Operations
Design intent
Strategic + Technical + Practical
Usage
Guide, training, architecture support
0

Introduction & Philosophy

What cryptography does, what it does not do, and how to reason like an architect instead of trusting slogans.

MindsetScopeStrategy
1

Security Goals

Confidentiality, integrity, authenticity, non‑repudiation, forward secrecy, and trust distribution.

CIAAuthenticityTrust
2

Threat Models

Cybercrime, insiders, states, interception at scale, and long‑term archival threats.

RiskHN-DLAdversaries
3

Randomness & Entropy

RNG failures, weak seeding, nonces, and how bad randomness destroys otherwise strong designs.

EntropyRNGNonces
4

Hashes, MACs, KDFs

Integrity primitives, HMAC, derivation, digests, and why hashing is not encryption.

HashHMACKDF
5

Symmetric Crypto

AES, ChaCha20, authenticated encryption, disk encryption, and why symmetric crypto remains central.

AESChaCha20AEAD
6

RSA Fundamentals

Prime generation, modulus, exponents, hardness assumptions, and what RSA is actually used for today.

RSAMathModulus
7

RSA Operations

OAEP, PSS, encryption vs signatures, performance costs, and padding disasters.

OAEPPSSPadding
8

PKI & Certificates

Roots, intermediates, leaf certs, revocation, ceremony discipline, and private trust chains.

PKICAX.509
9

ECC & Modern Practice

Why ECC displaced much RSA usage, and why quantum transition touches both families.

ECCTLSCurves
10

Quantum Threat

Shor, Grover, what breaks, what weakens, and where urgency is justified versus exaggerated.

ShorGroverFuture risk
11

PQC Landscape

Post‑quantum KEMs, signatures, lattice families, hybrid migration, and ecosystem readiness.

PQCLatticesHybrid
12

ML‑KEM

Quantum‑resistant key establishment, session setup, and practical roles in secure transport.

ML‑KEMKEMHandshake
13

PQC Signatures

ML‑DSA, FN‑DSA, SLH‑DSA, signature size and performance tradeoffs, and long‑term assurance.

ML‑DSASLH‑DSAAuthenticity
14

Hybrid Transition

Why coexistence matters, how to phase deployment, and how to keep rollback options sane.

HybridInteropMigration
15

Military Stakes

Classified systems, strategic confidentiality, satellite and platform trust, and long‑lived secrets.

DefenseNSSStrategic
16

“Unbreakable Codes” Myths

One‑time pads, side‑channels, endpoint compromise, and why marketing language is misleading.

OTPMythsReality
17

HSM, KMS, Key Storage

Trusted boundaries, cloud KMS, hardware roots, and where file‑based key handling becomes unacceptable.

HSMKMSCustody
18

Implementation Failures

Nonce reuse, padding oracles, timing leaks, weak APIs, and unsafe homegrown crypto.

APISide-channelFailures
19

TLS, VPN, Email, Files

Where cryptography actually lives: transport, archives, remote access, certificates, and file exchange.

TLSVPNEmail
20

Secure Messaging & Exchange

Envelope encryption, signing workflows, metadata exposure, and B2B data transfer patterns.

MessagingEnvelopeMetadata
21

Key Lifecycle

Generate, activate, rotate, revoke, archive, destroy — and why lifecycle beats clever mathematics.

RotationRevocationLifecycle
22

Governance & Audit

Crypto inventories, ownership, approved algorithms, exceptions, and evidence for compliance and control.

PolicyInventoryAudit
23

Migration Roadmap

How to move from inventory to hybrid pilots to controlled rollout with realistic operational discipline.

RoadmapProgramExecution

Official reference points used to anchor the 2026-oriented sections

  • NIST finalized FIPS 203 (ML‑KEM), FIPS 204 (ML‑DSA), and FIPS 205 (SLH‑DSA) in August 2024.
  • NIST explicitly presents ML‑KEM as a standardized KEM for establishing shared secret keys over public channels.
  • NSA’s post‑quantum resources point to CNSS Policy 15 and CNSA 2.0 guidance for National Security Systems.
  • ANSSI states PQC is the most promising path against the quantum threat and recommends strong hybridization during transition, with special treatment for hash-based signatures.
  • ANSSI has also published recent technical transition notes for SSHv2 and TLS 1.3 in early 2026.