Chinese PQC Vendors & Case Studies
A growing cluster of Chinese cryptography vendors is building post-quantum (PQC) capability — crypto cards and HSMs, gateways, PKI and key-management platforms — and pairing it with industry pilots in government, finance, and power. This page synthesizes the vendor and case-study material from the 安全牛 (Aqniu) 2025 technical guide into a concise English snapshot. It is a complement to our domestic-policy overview in china-overview.html and the algorithm picture in sm-pqc.html.
How China's PQC industry is taking shape
China's PQC push is driven by a 政产学研 (government–industry–academia–research) collaboration model, sharpened after NIST finalized FIPS 203/204/205 in 2024. National algorithm standards are still being formed: SCA's commercial-cryptography research institute opened a "next-generation" algorithm call in early 2025, still in evaluation, so vendors today build on internationally standardized PQC (ML-KEM, ML-DSA, SLH-DSA) while also tracking follow-on standardization candidates such as FN-DSA/Falcon and HQC, and keeping domestic SM compatibility. Two features stand out: hardware + software co-design (PQC pushed down into crypto chips and cards, not just libraries), and a strong preference for hybrid / dual-algorithm deployment plus QKD integration to ease migration. See hybrid.html and qkd-vs-pqc.html for those approaches in depth.
Representative vendors
| Vendor | PQC focus |
|---|---|
| 东进技术 (Dongjin) | Full-stack PQC migration suite: crypto cards, HSMs, gateways, KMS |
| 格尔软件 (Koal Software) | Dual-track QKD + PQC; quantum-safe PKI/CA, gateways, full product line |
| 吉大正元 (Jit / JLU-Zhengyuan) | PQC PKI, hybrid TLS 1.3 component, crypto cards/HSMs, integrated appliance |
| 三未信安 (Sansec) | PQC silicon-first: chips, cards, HSMs, gateways, UKey, KMS |
| 信安世纪 (Infosec Technologies) | PQC migration research, hybrid KEM/co-sign protocols, service platform |
东进技术 (Dongjin)
Dongjin offers a full-stack PQC migration product system spanning crypto cards, HSMs, crypto gateways, and a key-management platform, aiming for a smooth hardware-to-application upgrade. The design uses a layered, dual-mode architecture: hardware provides quantum-safe compute, gateways run a hybrid encryption mode (classical + NIST PQC on the link), and protocol negotiation (e.g. a TLS 1.3 extension) auto-selects the best cipher suite during the transition. Its PQC crypto card co-locates domestic high-performance chips for both PQC and classical algorithms over PCIe, with an algorithm-upgrade module for over-the-air updates. As a unified communications + cryptography company, Dongjin's strength is audio/video and data-in-transit security.
格尔软件 (Koal Software)
A listed cryptography vendor, Koal has pursued both QKD and PQC tracks since 2018, partnering with QKD makers (问天量子, 九州量子) and universities (Fudan, SJTU). In June 2024 it released a full quantum-safe product solution covering quantum-safe PKI/CA, key management, gateways, HSMs, VPN, and sign/verify servers. Its stack implements NIST algorithms plus domestic PQC candidates (CTRU/CNTR, LMS-SM3/HSS-SM3) and layers PQC into both international protocols (TLS, IPsec IKE, SSH, CMS) and Chinese commercial protocols (TLCP, GM IPsec VPN, SCEP, ACME). Its PQC authentication gateway was an early product to pass CTTL verification testing.
吉大正元 (Jit / JLU-Zhengyuan)
Jit ships a broad PQC line: a post-quantum PKI system (decoupled crypto engine / key / certificate modules, X.509v3-compliant, with a PQC dual-certificate option), a TLS 1.3 hybrid key-agreement component (plug-in negotiation, NIST curves mixed with ML-KEM), a hash-based (multi-layer Merkle tree) PQC signature system, plus PQC crypto cards and HSMs. Its crypto card integrates ML-KEM/ML-DSA alongside domestic LMS/HSS-SM3 signatures; its HSM supports the full PQC set (ML-KEM, ML-DSA, FN-DSA, SLH-DSA, XMSS/XMSSMT, LMS) while staying compatible with SM1/2/3/4. The 元密 integrated appliance packages all this into a one-stop, virtualized platform.
三未信安 (Sansec)
Sansec takes a silicon-first approach, treating high-speed implementation and crypto chips as the research core and achieving full-chain coverage: PQC chips, cards, HSMs, security gateways, PQC UKey, PQC IC cards, KMS, and a PQC certificate-authority system. It published a 2024 PQC technology & application white paper. Beyond NIST ML-DSA/ML-KEM/SLH-DSA/FN-DSA, its products also support domestic candidates (Aigis-enc, Aigis-sig, LAC.PKE, CTRU/CNTR, LMS-SM3/HSS-SM3). Dedicated chip-level optimization and multi-core / high-speed PCIe design give it strong throughput, and a modular architecture keeps algorithm agility for future standard changes.
信安世纪 (Infosec Technologies)
Infosec concentrates on PQC migration research across the network, transport, and application layers, then productizes it as a service platform. Its hybrid post-quantum key-agreement and two-party Dilithium co-signature schemes won a third prize at the 2024 "金融密码杯" national contest and hold granted patents. Notable building blocks include a hybrid KEM that mixes a classical SM2 shared secret with a Kyber-encapsulated secret through a KDF (forward-secure, no large PKI rework), and KEMTLCP — an authenticated-KEM variant of the TLCP protocol that avoids costly PQC signatures for identity authentication. Its PQC service platform serves finance, government, telecom, and enterprise customers with unified encrypt/sign/certificate services.
Application case studies
| Case | Vendor |
|---|---|
| City government extranet pilot (政务外网) | 东进技术 |
| 银河证券 anti-quantum securities pilot | 格尔软件 |
| Large state financial institution — QKD key distribution | 吉大正元 |
| PQC in the power / energy industry | 三未信安 |
| Financial institution PQC migration practice | 信安世纪 |
Government extranet pilot — 东进技术
For a city government extranet carrying campus and city-wide video-surveillance traffic, Dongjin deployed PQC IPsec gateways combined with QKD: QKD-supplied keys replaced the classical IPsec keys, and the link ran a hybrid mode mixing classical and NIST PQC algorithms, with embedded modules and lightweight gateways encrypting video transparently at the terminals. The pilot reached roughly 10 Gbps tunnel throughput and lifted the key-refresh cadence from hourly to per-minute, giving end-to-end protection that satisfies both 国密 and 标密 dual-compliance.
银河证券 anti-quantum pilot — 格尔软件
To bring quantum-safe cryptography into the securities/futures industry, Koal designed a four-layer scheme (crypto hardware, infrastructure, security support, business application) on a "PQC + SSL VPN" hybrid model, plus a new anti-quantum PKI to re-anchor the trust chain. Three flexible deployment options (typical / complete / transitional) let the pilot reuse existing 国密 software while adding PQC, and the migration blueprint was found to be reusable for other PQC pilots.
QKD-based key distribution — 吉大正元
A large state-owned financial institution centrally generates symmetric keys and distributes them to provincial/municipal branches over 国密 digital-envelope and TLCP channels. Working with China Telecom Quantum, Jit used a QKD network so the central KMS protects symmetric keys with quantum-distributed keys before delivery — solving how to securely distribute symmetric keys against future quantum attack. The approach is replicable to other institutions with similar needs.
PQC in the power industry — 三未信安
For a power enterprise that had already completed cryptography upgrades and crypto-compliance assessment at its dispatch center and several plants, Sansec introduced PQC algorithms and protocols on top of existing capability: PQC-supporting crypto hardware plus a virtualized PQC cloud crypto-resource platform letting the grid run PQC and classical algorithms side by side. Run as a migration pilot with rolling, iterative tuning, it addressed a 卡脖子 ("chokepoint") gap for critical energy infrastructure and produced reusable experience for the wider energy sector.
Financial institution PQC migration practice — 信安世纪
A large financial institution wove PQC into its PKI (CA) backbone — issuing PQC-capable certificates and using lattice-based key exchange and anti-quantum hash signatures, with a hybrid (dual) certificate mechanism for a smooth transition. Infosec built a validation environment (sign/verify server, crypto control, HSM, UKey) and ran the migration across typical business systems, confirming feasibility and performance with low business disruption and a controlled, smooth cutover from classical to post-quantum algorithms. For the general migration workflow, see industry-scenarios.html.
Standards & references
- 安全牛《后量子密码安全能力构建技术指南(2025版)》(Aqniu, "Technical Guide to Building Post-Quantum Cryptographic Security Capabilities, 2025 edition") — primary source; vendor and case material above is synthesized and rewritten, not reproduced.
- SCA — State Cryptography Administration, https://www.oscca.gov.cn/ (algorithm standardization and commercial-cryptography regulation).
- china-overview.html — China PQC & commercial-cryptography policy overview.
- sm-pqc.html — the SM suite under quantum threat and domestic PQC efforts.
- Resources — full standards register
国内后量子密码厂商与案例
国内一批密码厂商正在构建后量子密码(PQC)能力 — 密码卡与密码机、网关、PKI 与密钥管理平台 — 并在政务、金融、电力等行业落地试点。本页把安全牛 2025 年技术指南中的厂商与案例素材综合改写为一份精简快照,与本站的国内政策概览 china-overview.html 以及算法视角 sm-pqc.html 互为补充。
国内后量子密码产业格局
国内 PQC 推进以政产学研协同为主线,在美国 NIST 于 2024 年定稿 FIPS 203/204/205 后明显提速。国家算法标准仍在形成中:商用密码标准研究院在 2025 年初发起新一代算法征集,目前处于评估阶段,因此厂商当下普遍基于已国际标准化的 PQC(ML-KEM、ML-DSA、SLH-DSA)落地,同时跟踪 FN-DSA/Falcon、HQC 等后续标准化算法,并保持国密 SM 兼容。两个特点尤为突出:一是软硬协同设计,把 PQC 下沉到密码芯片与密码卡而不只停留在算法库;二是偏好混合双算法部署并融合 QKD,以降低迁移风险。混合方案与 QKD 路线可参见 hybrid.html 与 qkd-vs-pqc.html。
代表性厂商
| 厂商 | PQC 重点 |
|---|---|
| 东进技术(Dongjin) | 全栈 PQC 迁移体系 密码卡 密码机 网关 密钥管理平台 |
| 格尔软件(Koal Software) | QKD 与 PQC 双线 量子安全 PKI/CA 网关 全套产品 |
| 吉大正元(Jit) | 后量子 PKI 混合 TLS 1.3 组件 密码卡密码机 一体机 |
| 三未信安(Sansec) | 芯片优先 后量子芯片 卡 密码机 网关 UKey 密钥管理 |
| 信安世纪(Infosec Technologies) | 迁移研究 混合 KEM 与协同签名协议 服务平台 |
东进技术 Dongjin
东进提供覆盖密码卡、密码机、密码网关、密钥管理平台的全栈 PQC 迁移产品体系,目标是从硬件到应用层的平滑升级。方案采用分层双模兼容架构:硬件层提供量子安全算力,网关依托混合加密模式在通信链路上兼容传统算法与 NIST PQC 算法,并通过协议协商机制(如 TLS 1.3 扩展)自动选择最优加密套件。其后量子密码卡在单板上并置多颗国产高性能芯片分别承载 PQC 与经典算法,经 PCIe 接口集成,并设算法升级模块支持在线更新。作为一体化通信与密码复合型企业,东进在音视频与数据传输安全场景具有先天优势。
格尔软件 Koal Software
格尔软件是密码领域上市企业,自 2018 年起沿 QKD 与 PQC 双线并行布局,与问天量子、九州量子等量子厂商及复旦、上海交大等高校合作。2024 年 6 月发布国内全套抗量子密码产品方案,覆盖量子安全 PKI/CA、密钥管理、网关、密码机、VPN、签名验签服务器等。其产品既实现 NIST 算法,又集成国产 PQC 候选(CTRU/CNTR、LMS-SM3/HSS-SM3),并把 PQC 叠加到国际协议(TLS、IPsec IKE、SSH、CMS)与国密商用协议(TLCP、国密 IPsec VPN、SCEP、ACME)。其抗量子认证网关较早通过信通院验证性测试。
吉大正元 Jit
吉大正元产品线较广:后量子 PKI 系统(密码引擎、密钥、证书模块充分解耦,符合 X.509v3,提供后量子双证书体系)、TLS 1.3 后量子混合密钥协商组件(算法插件化,NIST 标准曲线与 ML-KEM 混合)、基于多层默克尔树的后量子签名系统,以及后量子密码卡与密码机。其密码卡集成 ML-KEM/ML-DSA 并融入国产 LMS/HSS-SM3 签名;密码机支持全系后量子算法(ML-KEM、ML-DSA、FN-DSA、SLH-DSA、XMSS/XMSSMT、LMS)并兼容 SM1/2/3/4。元密一体机把上述能力封装为一站式虚拟化平台。
三未信安 Sansec
三未信安走芯片优先路线,将高速实现与密码芯片作为研究重点,实现全产业链覆盖:后量子芯片、密码卡、密码机、安全网关、后量子 UKey、后量子 IC 卡、密钥管理系统与后量子数字证书认证系统,并发布了 2024 抗量子密码技术与应用白皮书。除 NIST 的 ML-DSA/ML-KEM/SLH-DSA/FN-DSA 外,产品还支持国产候选(Aigis-enc、Aigis-sig、LAC.PKE、CTRU/CNTR、LMS-SM3/HSS-SM3)。芯片级专项优化与多核、高速 PCIe 设计带来高吞吐,模块化架构保证后续算法敏捷应对标准变化。
信安世纪 Infosec Technologies
信安世纪聚焦网络层、传输层、应用层的 PQC 迁移研究,再产品化为服务平台。其混合式后量子密钥协商与两方 Dilithium 协同签名方案获 2024 年金融密码杯全国大赛三等奖并取得发明授权。代表性技术包括:把经典 SM2 共享秘密与 Kyber 封装秘密经 KDF 混合的混合 KEM(具前向安全、无需大规模 PKI 改造),以及 KEMTLCP — 基于后量子密码的 TLCP 协议变体,用密钥封装完成身份认证以规避开销较大的后量子签名。其后量子密码服务平台面向金融、政务、通信、企业提供统一的加密签名证书服务。
应用实践案例
| 案例 | 厂商 |
|---|---|
| 某市政务外网试点 | 东进技术 |
| 银河证券抗量子试点课题 | 格尔软件 |
| 某大型金融机构基于 QKD 的密钥分发 | 吉大正元 |
| 电力行业后量子密码研究与应用 | 三未信安 |
| 某金融机构后量子密码迁移实践 | 信安世纪 |
政务外网试点 — 东进技术
面向承载园区与城市级视频监控流量的某市政务外网,东进部署后量子 IPsec 网关并结合 QKD:用 QKD 量子密钥替代经典 IPsec 密钥,链路采用兼容传统算法与 NIST PQC 的混合加密模式,并在终端侧通过嵌入式模块与轻量网关对视频流透明加密。试点 IPsec 隧道加密吞吐达约 10 Gbps,密钥更新频率从小时级提升至分钟级,实现满足国密与标密双重合规的端到端防护。
银河证券抗量子试点 — 格尔软件
为把量子安全密码引入证券期货业,格尔基于 PQC + SSL VPN 混合模式设计了密码硬件层、基础设施层、安全支撑层、业务应用层的四层方案,并构建抗量子 PKI 重新锚定信任链。典型、完整、过渡三套可灵活组合的迁移方案让试点尽可能复用现有国密软件并叠加 PQC,其迁移实施方案可复用于其他后量子密码应用试点。
基于 QKD 的密钥分发 — 吉大正元
某国有大型金融机构集中产生对称密钥,并向各省市基于国密数字信封与 TLCP 通道分发。吉大正元联合中电信量子,借助 QKD 网络,使中央密钥管理系统用量子密钥保护对称密钥后再分发,解决了量子威胁下对称密钥安全分发的实际问题,并可平行复制推广到其他有同类需求的机构。
电力行业后量子密码 — 三未信安
针对已在集控中心及若干电厂完成密码改造并通过密评的某电力企业,三未信安在现有密码能力基础上引入 PQC 算法与协议:部署支持 PQC 的密码硬件,并以虚拟化的后量子密码云资源平台让电网兼容后量子与传统算法。以迁移试点形式开展、滚动迭代调优,解决了关键能源基础设施的 卡脖子 难题,并形成可供能源行业借鉴的经验。
金融机构后量子迁移实践 — 信安世纪
某大型金融机构把 PQC 融入 PKI(CA)体系 — 通过数字证书实现身份认证与密钥分发,采用基于格的密钥交换与抗量子哈希签名,并以混合双证书机制平衡过渡期的安全与兼容。信安世纪搭建了包含签名验签服务器、密码控件、加密机、UKey 的验证环境,在典型业务系统上完成迁移,验证了可行性与性能,做到业务低感知、平滑可控地从传统算法过渡到后量子算法。迁移流程可参见 industry-scenarios.html。
标准与参考
- 安全牛《后量子密码安全能力构建技术指南(2025版)》— 主要来源;上述厂商与案例内容为综合改写,非原文复制。
- 国家密码管理局(SCA)— https://www.oscca.gov.cn/(算法标准化与商用密码监管)。
- china-overview.html — 国内后量子与商用密码政策概览。
- sm-pqc.html — 量子威胁下的国密算法与国内 PQC 进展。
- 资源链接 — 完整标准登记册