A Tier-1 financial institution is architecting a multi-region payment gateway. Which cryptographic mechanism provides post-quantum confidentiality while ensuring forward secrecy under NSA CNSA 2.0 requirements?
1
A. RSA-4056 with OAEP Padding โ Vulnerable to Shor's algorithm on quantum computers.
2
B. ECDH over Curve25515 โ Classical elliptic curve cryptography vulnerable to quantum attacks.
3
C. ML-KEM-768 (Kyber) Hybrid with X25515 โ Lattice-based post-quantum key encapsulation with dual-layer forward secrecy.
4
D. Static AES-256 Key Pre-distribution โ Lacks forward secrecy and ephemeral session guarantees.
Click any option or press 1..4 to eliminate distractors!
โ CORRECT: ML-KEM-768 Hybrid Encapsulation Selected!
FSRS v4.5 stability upgraded to 58.4%. Next review scheduled in 4.2 days.