• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Security»Shield your data from a quantum attack: The path to PQC migration
Security

Shield your data from a quantum attack: The path to PQC migration

September 24, 2022No Comments6 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Shield your data from a quantum attack: The path to PQC migration
Share
Facebook Twitter LinkedIn Pinterest Email

Were you unable to attend Transform 2022? Check out all of the summit sessions in our on-demand library now! Watch here.


For many in this community, a functioning quantum computer will probably still feel quite fictional — an innovation that’s still light-years away. There’s also the idea that, well, wouldn’t a functioning quantum computer be a good thing? Won’t a functioning quantum computer, for example, enable scientists to accelerate drug discovery and development?

The flip side is that while these computers will bring many benefits, they also bring new security risks, which are much closer to hand than many expect. The first functioning cryptographically relevant quantum computer (CRQC) will have the power to break through the public-key encryption widely relied upon today to protect information. That means that data, no matter how secure it may be right now, will be vulnerable to a future attack on a scale never seen before.

To remedy this danger, the National Institute of Standards and Technology (NIST) began running a competition in 2016 to identify new quantum-safe encryption algorithms. It has recently made its decision on what algorithms will become the new standard. Companies that have been waiting for certainty about what kind of new encryption to use can now begin migrating their infrastructure to protect their data.

Let’s look at what this migration should look like and how organizations can best set themselves up to protect their data for years to come.

Event

MetaBeat 2022

MetaBeat will bring together thought leaders to give guidance on how metaverse technology will transform the way all industries communicate and do business on October 4 in San Francisco, CA.

Register Here

The quantum threat

As alluded to above, it is widely accepted that a sufficiently mature quantum computer will be able to break today’s public-key encryption (PKC) standards — RSA and Elliptic Curve.

See also  Data shows who has been hit the hardest in the great tech layoff wave – DailyTech

So, what are the implications? Put simply, without secure encryption, the digital economy would cease to function, as PKC is used everywhere in our daily digital interactions. With a mature quantum computer, a hacker could:

  • Empty people’s bank accounts or cryptocurrency wallets
  • Intercept and decrypt sensitive communications
  • Disable critical infrastructure like power grids and communications networks
  • Expose virtually any secret we wish to keep secret

The timing here is still much debated, but many predictions mistakenly focus on commercial quantum computers being up to 15-20 years away. The threat that I am referring to is not a commercial quantum computer that JP Morgan can buy to do its own trading analysis. I’m talking about the sheer power to do code-breaking under lab conditions, which will come far sooner. The cybersecurity community estimates this could occur in as few as five years.

Even if we can’t predict the exact moment a functioning quantum machine proliferates, billions of dollars are being poured into quantum computing R&D, meaning it’s really only a matter of time until the encryption relied on by virtually every application in use today can be cracked. Further, even if the first quantum computer isn’t seen until 2030, we are still in a race against time to stay secure. It’s estimated that it would take at least 10 years to migrate the existing cryptographic infrastructure, because that entails transforming most electronic devices that connect to the internet.

Harvest now, decrypt later  

Adding to this threat is the possibility that, even today, organizations with sensitive data that has a long shelf life could see that data being harvested and captured by criminals intending to decrypt it once a sufficiently powerful quantum computer arrives. In other words, any data with a multi-year lifespan could be collected today and decrypted in the future. This could include government secrets, R&D innovation, trading data in financial services, and strategic plans.

See also  Musk looks to end acquisition, says Twitter hasn't provided required data

This harvest-now, decrypt-later (HNDL) threat is backed up by numerous pieces of research, which find that rogue actors will likely start collecting encrypted data with long-term utility, expecting to eventually decrypt it with quantum computers. I’d argue that this could already be happening, such as in instances where we see internet traffic re-routed on unusual global paths for no apparent reason before returning to normal. To back up my observations, several Five Eyes agencies have also commented on this phenomenon becoming more frequent.

Mapping a path to protection

With this array of threats, NIST has taken the lead in coordinating a global response. Its Post-Quantum Cryptography (PQC) Program is a multi-year effort to identify new encryption algorithms that are resistant to a future code-breaking quantum computer and can protect data from HNDL attacks.

After drawing upon entries from top academic and private-sector cryptographers, NIST has finally decided which algorithms will become the new standard in global cryptography. NIST has chosen CRYSTALS-Kyber for general encryption and CRYSTALS-Dilithium, FALCON, and SPHINCS+ for digital signatures. It has also advanced four other candidates for additional scrutiny, including the ultra-secure Classic McEliece. Whereas the current PKC standards (RSA and Elliptic Curve) can be used for both encryption and digital signing, different post-quantum algorithms cannot, which means that they will replace existing PKC with a pair of different algorithms. 

With these new standards now finalized, companies that have been waiting for certainty on what kind of new encryption to use can begin migrating their infrastructure to protect their data. This will be no easy task, so here is a non-exhaustive list of recommendations for organizations looking to take this PQC migration seriously:

See also  LA school district was warned of ransomware threat before recent shutdown

1. If you haven’t done so already, set up your Y2Q crypto-migration project now, and give it significant backing and investment. Just as with any large IT program or project, you will need to have a dedicated team with the right skills and resources to ensure success.

2. Once this is in place, the initial goal of the project team should be to conduct a crypto inventory audit. This means taking stock of where cryptography is deployed today across the organization, making sure that you can map out a migration path that prioritizes high-value assets while identifying any expected impact on operational systems.

3. One of the main considerations for your project team is adopting hybridization. This means choosing and deploying solutions that keep the tried and tested classical cryptography we use today, like RSA, alongside one or more post-quantum algorithms, ensuring you’re protected against both current and future threats. 

Further, the use cases where encryption is needed vary across industries and sectors, so adopting crypto agility — where different PQC algorithms can be used depending on the applications — will give you greater flexibility. This is particularly the case with algorithms that are being analyzed in a fourth round, which have the potential to also become future standards, some potentially more appropriate for high-security use cases. 

4. Finally, you should consider deploying a hybrid quantum-safe VPN. The Internet Engineering Task Force (IETF) has developed a set of specifications for such VPN products, recommending crypto-agile solutions that support hybrid key establishment, meaning post-quantum algorithms can work alongside today’s standards. Quantum-safe VPN products based on the IETF specification are already on the market, so upgrading is a relatively simple step you can already take.

Andersen Cheng is CEO of Post-Quantum.

Source link

Attack data migration Path PQC Quantum Shield
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Google Mourns Veteran Engineer Luiz André Barroso Who Invented the Modern Data Center

September 22, 2023

The Most Popular Digital Abortion Clinics, Ranked by Data Privacy

August 21, 2023

Chris Wright’s Path To Hospitality Excellence

August 14, 2023

Generative AI Is Making Companies Even More Thirsty for Your Data

August 10, 2023
Add A Comment

Comments are closed.

Editors Picks

Wizards of the Coast quietly removes D&D lore after criticism of racism

September 4, 2022

GTA V, Mafia, and Red Dead Redemption 2 VR mods are dead – and Take 2 Interactive killed them

July 7, 2022

Finest Verizon Fios new buyer offers for July 2022

July 25, 2022

HBO Max finishes rolling out its much-needed app redesign

August 8, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.