As Google and IBM race to become the first to create a fully functional quantum computer that can be applied to practical problems, voices warning the advancement of this technology could have very real unintended consequences are growing increasingly loud among cyber security professionals.
Virtually every aspect of our lives nowadays relies on strong encryption, from financial services to shopping sites, email and often elements of our work life such as HR or expenses systems. The security systems they use must be and largely are reliable and trusted.
Advertisement - Article continues below
To break the RSA public key cryptographic systems, for example, would take millions of years with the standard computers available today. A quantum computer able to run thousands of quantum bits (qubits) would be able to do it in a far more reasonable time, but with the leading developers claiming a maximum of 100 qubits with their implementations, we are far from building a quantum computer to challenge current security protocols. What of the future, though?
In its report, the RAND Corporation concludes steps must be taken today to meet the challenges of a post-quantum cryptographic security environment. "If an adequate implementation of new security measures has not taken place by the time capable quantum computers are developed, it may become impossible to ensure secure authentication and communication privacy without major, disruptive changes," said Michael Vermeer, lead author of the report and a physical scientist at RAND.
Advertisement - Article continues below
The security systems that businesses and individuals rely upon every day use two forms of encryption: symmetric and asymmetric. How you securely communicate with your bank or use your mobile phone without anyone eavesdropping on your calls will use a combination of these security systems.
Advertisement - Article continues below
Current security systems used to protect sensitive data typically use a combination of Advanced encryption standard (AES) developed back in 2001, RSA (RivestShamirAdleman) and Elliptic-curve cryptography (ECC). As financial services tend to use asymmetric cryptography such as RSA and ECC, these systems are vulnerable to attack by quantum computers. AES is less susceptible as the systems are symmetric, but could still be broken.
Speaking to IT Pro, Dustin Moody of the NIST Post-Quantum Cryptography (PQC) team, explains: A working, large-scale quantum computer would have some impacts on the crypto we currently use. First, such a computer would be able to run Shor's algorithm, which would break all currently deployed public-key cryptography. Second, a quantum computer would be able to run Grover's algorithm, which would have the effect of us having to use longer keys/hash functions for the algorithms we use for symmetric-key cryptography.
Moody continues: We use both public-key and symmetric-key cryptographic techniques to provide the security we expect today. If we made no changes in advance of this, then yes, security would be severely threatened. Note that we will need completely new quantum-resistant public-key crypto algorithms, while for the symmetric-key algorithms, we only need to use larger parameter sets. NIST has a post-quantum cryptography standardisation project ongoing to address these issues before a large-scale quantum computer comes into existence.
Estimates vary wildly regarding the timeframe for a practical working quantum computer. The timelines are even longer when quantum encryption systems are considered. The security community, in general, is advising we should be undertaking research into how a post-quantum encryption security environment could look like as NIST is currently doing.
Advertisement - Article continues below
Advertisement - Article continues below
The cryptographic community is beginning to focus more on post-quantum cryptography, but more time and testing is needed to improve the efficiency and build confidence in post-quantum cryptography, as well improve its overall usability, says Kevin Curran, IEEE senior member and professor of cyber-security at Ulster University. We may very well find that we do not actually need post-quantum cryptography, but this is too risky if we do not conduct the research now, then we may lose years of critical research in this area later on.
Understanding the massive challenges still ahead to design and build a quantum computer that can perform useful work is critical to place the concerns regarding quantum computers and encryption into a realistic context.
Brian Hopkins, VP and principal analyst serving CIOs and technology leaders at IBM, explains: The market doesnt understand how frighteningly immature quantum computers are. We are all intrigued or concerned about some future powerful quantum computer with huge theoretical potential. But we have so far to go. For example, each qubit in an IBM quantum computer takes something like four physical cables to control. Each cable costs thousands of dollars. Thats to control 20 qubit machines. How will we scale this to millions of qubits in a cost-effective way? Millions of cables running into deep freezers on a quantum computer the size of a building? The truth is, nobody knows.
Advertisement - Article continues below
Hopkins concludes: Even the best firms say they won't get to quantum advantage in small scale NISQ (noisy intermediate-scale quantum technology) use cases for five-to-ten years. That's a lot of time for things to change. And all the while, classical computers are still getting more powerful and we are developing other types of computing neuromorphic chips, optical chips, memristor chips and so on that can do things like machine learning much better than quantum computers can.
Research from DigiCert revealed over 70% of respondents are aware of PQC, showing IT departments are already thinking about the possibility of future security breaches.
Advertisement - Article continues below
Doing business in a 'quantum-safe' environment will take shape as quantum computers themselves evolve. We already have security protocols that should be safe from attack from hackers equipped with a quantum computer. OASIS KMIP and IEEE std 1363.1 are leading the way to a future where reliable security systems continue as we use them today.
Advertisement - Article continues below
Distributed Ledger Technology (DLT) and the blockchain, meanwhile, have been heralded as the next evolution of data security. Moving away from centralised data stores that can be compromised to a distributed system is held by many as the solution to current data security challenges. Thankfully, they also seem to be resistant to the problem posed to security by practical quantum computers. In its 2018 report on the matter, Forrester states: Quantum computing isnt going to blow apart DLT-based systems today or even in the foreseeable future.
This doesnt mean businesses can be complacent, though. The systems being built today may well have to contend with an environment where practical quantum computing is real. Its critical, therefore, to think about how data security is being handled with technologies like DLT to understand how they could be impacted in a post-quantum landscape.
As NISTs Dustin Moody notes: Technologies like blockchains and the like use different cryptographic components. You have to examine the quantum threat for each component. In the simplest case, a blockchain requires computing hash functions and needs to use (public-key) digital signatures. The digital signatures will need to use quantum-resistant or quantum-safe algorithms to be protected from a quantum computer. The hash functions will need to use longer outputs, which is not too hard to do (ie you could use SHA-512 instead of SHA-256).
For now, the security platforms in use are more than adequate and it could be decades before we have to worry about the security protocols being rendered useless. Nevertheless, the future may require radical rethinking of how we approach every security system currently in use
The IT Pro guide to audio collaboration
Make audio a priority for a successful remote working strategy
How malware and bots steal your data
Protect your organisation with a layered defence
Modern networking for the borderless enterprise
5 ways top organisations are optimising networking at the edge
IT managers best practice guide to hybrid cloud
Your blueprint to hybrid cloud success
Read the original:
Quantum security: The end of security as we know it? | IT PRO - IT PRO
- To Foil NSA Spies, Encrypt Everything [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- What is cryptography? - A Word Definition From the ... [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- cryptography: Definition from Answers.com [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Cryptography - Wikipedia, the free encyclopedia [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Cryptography - CISSP Domain 07 - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Cryptography Advanced Encryption Standard AES Tutorial,fips 197 - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Faraday Project for Network Security and Cryptography - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- An Overview of Cryptography - Gary C. Kessler [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- An Open Letter from US Researchers in Cryptography and ... [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Gambling with Secrets Part 4 8 Private Key Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Gambling with Secrets Part 1 8 What is Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Public Key Cryptography RSA Encryption Algorithm - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Public Key Cryptography Diffie Hellman Key Exchange - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Intro to Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Caesar Cipher Ancient Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- 50 top US cyber security experts write open letter calling for end to NSA 'snoop-ops' [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Prominent cryptography and security researchers deplore NSA's surveillance activities [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Obama Stays Silent on Reform of NSA's Crypto Subversion [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Cryptography experts sign open letter against NSA surveillance [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- US crypto researchers to NSA: If you must track, track responsibly [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Java Cryptography Architecture (JCA) Overview - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Cryptography - Part 1 - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Cryptography - Part 2 - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- International Journal on Cryptography and Information Security ( IJCIS) - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Bitcoin Lowdown: Block Chain Cryptography Trumps Human Trust, Deal With It - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Bitcoin Lowdown: Block Chain Cryptography Trumps Human Trust - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- NSA and GCHQ spoofed LinkedIn to hack Belgian cryptography professor [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Lecture 17: Elliptic Curve Cryptography (ECC) - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Cryptography event - Pravega 2014 - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Lecture 1: Introduction to Cryptography - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- US and UK spy agencies accused of swoop on Belgian cryptography expert [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Conceal: Facebook's new Java APIs for cryptography on Android [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Cryptography Apps: How To Keep Your Personal Info Private [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Cryptography Breakthrough Could Make Software Unhackable [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Oi, Android devs! Facebook wants your apps to be more secure [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Lecture 19: Elgamal Digital Signature - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Lecture 18: Digital Signatures and Security Services - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Cryptography 1. List some of the attacks on the Diffie ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Cryptography Breakthrough Could Make Software Unhackable ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Cryptography: Secret Coding, Spying, and E-Commerce - Video [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Cryptography - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Public Key Cryptography: RSA Encryption Algorithm - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Is Bitcoin Anonymous? Arvind Narayanan | Princeton University | Real World Cryptography Workshop - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- A Competitive Study of Cryptography Techniques over Block Cipher - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- How Quantum Computing Will Change Cryptography [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- REALITY LOST - EXCERPT SIX (QUANTUM CRYPTOGRAPHY) - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- Introduction to Cryptography of Bitcoin, Explained! - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- [FOSDEM 2014] USE OTR or how we learned to start worrying and love cryptography - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- Reshif's Cryptography Challenge Solution/Walkthrough - Video [Last Updated On: February 20th, 2014] [Originally Added On: February 20th, 2014]
- [DEFCON 19] Steganography and Cryptography 101 - Video [Last Updated On: February 22nd, 2014] [Originally Added On: February 22nd, 2014]
- A Brief Rundown Of The Spying Questions Intel's CEO Won't Answer [Last Updated On: February 25th, 2014] [Originally Added On: February 25th, 2014]
- DEF CON 8 - Jon Erickson - Number Theory Complexity, Theory, Cryptography, and Quantum Computing. - Video [Last Updated On: February 26th, 2014] [Originally Added On: February 26th, 2014]
- Was YOUR iPhone at risk of being hacked? Bug in Apple update left mobiles open to identity theft for up to 18 months ... [Last Updated On: February 27th, 2014] [Originally Added On: February 27th, 2014]
- Security researchers urge tech companies to explain their cryptographic choices [Last Updated On: February 27th, 2014] [Originally Added On: February 27th, 2014]
- Apple reveals algorithm behind 'encrypted' iMessages [Last Updated On: February 28th, 2014] [Originally Added On: February 28th, 2014]
- Wiliest Ways to Keep the NSA at Bay [Last Updated On: March 1st, 2014] [Originally Added On: March 1st, 2014]
- How to Pronounce Cryptography - Video [Last Updated On: March 1st, 2014] [Originally Added On: March 1st, 2014]
- cryptography in DNS - Video [Last Updated On: March 3rd, 2014] [Originally Added On: March 3rd, 2014]
- Who is the reclusive billionaire creator of Bitcoin? [Last Updated On: March 4th, 2014] [Originally Added On: March 4th, 2014]
- How to say cryptography in Italian - Video [Last Updated On: March 4th, 2014] [Originally Added On: March 4th, 2014]
- Massive Linux security flaw dwarfs Appleās cryptography problems of just last week [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Security lessons from RSA [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Visual Cryptography - Video [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Classical Computing Embraces Quantum Ideas [Last Updated On: March 6th, 2014] [Originally Added On: March 6th, 2014]
- Quantum Cryptography Conquers Noise Problem [Last Updated On: March 6th, 2014] [Originally Added On: March 6th, 2014]
- REALITY LOST Bonus scene 4. Quantum cryptography Founding Fathers. - Video [Last Updated On: March 7th, 2014] [Originally Added On: March 7th, 2014]
- Quantum Cryptography: From Theory to Practice - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- Forcing Trust: Nonlocal Games and Untrusted-device Cryptography - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- TrustyCon 2014 - New Frontiers in Cryptography - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- REALITY LOST Bonus scene 3. Christian Kurtsiefer on hacking quantum cryptography. - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- Nerlens Noel Tweets Date for Potential NBA Debut [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- CISSP SG Cryptography - Video [Last Updated On: March 10th, 2014] [Originally Added On: March 10th, 2014]
- More secure communications thanks to quantum physics [Last Updated On: March 13th, 2014] [Originally Added On: March 13th, 2014]
- New Cryptography Scheme Secured By Quantum Physics [Last Updated On: March 13th, 2014] [Originally Added On: March 13th, 2014]
- History Of Cryptography - Video [Last Updated On: March 14th, 2014] [Originally Added On: March 14th, 2014]
- avc 19 Cryptography x264 - Video [Last Updated On: March 15th, 2014] [Originally Added On: March 15th, 2014]
- Edward Snowden Speaks at SXSW [Last Updated On: April 10th, 2017] [Originally Added On: March 15th, 2014]
- Tor is building an anonymous instant messenger [Last Updated On: April 10th, 2017] [Originally Added On: March 15th, 2014]
- learn cryptography learn the following pkcs refrences - Video [Last Updated On: March 16th, 2014] [Originally Added On: March 16th, 2014]
- [Lec-2][Part-2] Shift Cipher - Symmetric ciphers - Video [Last Updated On: March 16th, 2014] [Originally Added On: March 16th, 2014]