QNSI

Key Encapsulation

HQC

Hamming Quasi-Cyclic Key Encapsulation

FIPS-pendingcode-based3 parameter setsQNSI tier: default+provider: liboqsalso called: HQC-128, HQC-192, HQC-256, HQC-1, HQC-3, HQC-5
NIST-selected code-based backup KEM. QNSI offers HQC as an explicit diversity option with liboqs 0.16.0, which updates the implementation to the 20250822 specification; ML-KEM remains the FIPS-final default.

Mechanism

How it works

HQC is based on quasi-cyclic syndrome decoding. It gives QNSI a code-based hedge against lattice-only concentration while retaining larger public keys and ciphertexts than ML-KEM.

Parameter Sets

3 variants shipped

Each variant trades security category against key, ciphertext, or signature size. QNSI exposes all variants via the @heossihq/liboqs-native binding; tenant crypto-policy determines which are allowed.

VariantNIST LevelPublic KeySecret KeyCiphertextNote
HQC-128 / HQC-1L12,241 B2,321 B4,433 B
HQC-192 / HQC-3L34,514 B4,602 B8,978 B
HQC-256 / HQC-5L57,237 B7,333 B14,421 B

NIST ACVP

Conformance evidence

QNSI runs the official NIST ACVP test vectors against every shipped algorithm. Live evidence + SHA-3-256 tamper digest at /verify/conformance.

@noble/post-quantum
non-addressable
Pure-JavaScript reference; cross-verification secondary on Maximum + Government tiers.
@heossihq/liboqs-native
non-addressable
Native-C primary production engine. Runs across every QNSI backend service.
NIST selected HQC for standardization in March 2025, but final FIPS and ACVP coverage are not yet published.
View live ACVP evidence →

Use Cases

When to use it

  • Explicit code-based KEM diversity where a backup to ML-KEM is required
  • Migration and interoperability evaluation ahead of the future HQC standard

Trade-offs

What you give up, what you get

  • Not FIPS-final today - excluded from government finalized-only policy tiers
  • Larger public keys and ciphertexts than ML-KEM

FAQ

HQC - frequently asked questions

Concise, source-of-truth answers to the questions buyers and engineers ask most about this algorithm.

What is HQC?

HQC (Hamming Quasi-Cyclic Key Encapsulation) is a code based post-quantum key encapsulation mechanism. It is designed to resist attacks from both classical and quantum computers, and QNSI ships 3 of its parameter sets. It is also known as HQC-128, HQC-192, HQC-256, HQC-1, HQC-3, HQC-5.

Is HQC NIST-standardized?

HQC has been selected by NIST for standardization; its FIPS standard (draft) is not yet finalized. QNSI ships it today and tracks the draft, so you can adopt it now and inherit the final standard once NIST publishes it.

What is HQC used for?

On QNSI, HQC is used for Explicit code-based KEM diversity where a backup to ML-KEM is required; Migration and interoperability evaluation ahead of the future HQC standard. It is available from the default crypto-policy tier upward via the liboqs provider.

References

Primary sources

QNSI privacy choices

Necessary storage keeps the site secure. With your permission, privacy-bounded analytics help HEOSSI understand pages, journeys, and campaign outcomes. No advertising profiles are created.

Cookie policy