As computer scientists march forward in the process of taking quantum computing into the practical realm, cybersecurity vendors and practitioners will need to be ready with encryption mechanisms that can withstand the power of quantum's compute potential. But risk experts say that future-proofing measures for post-quantum cryptography don't have to be created in panic.
Contrary to the way some early pundits have painted the post-quantum computing landscape, the truth is that there will be no quantum cliff in which today's encryption mechanisms will suddenly become obsolete, says Dr. Colin Soutar, the US quantum cyber-readiness leader and managing director for Deloitte Risk & Financial Advisory, which just released a report on quantum encryption. He explains that in reality, the transition to quantum is going to be an ongoing process.
"There's a lot of discussion around quantum right now, and there's a lot of conflation of different ideas. There are even some alarmist statements about how everything needs to change overnight to update to quantum-resistant algorithms," says Soutar. "That implies there's a specific date (for quantum adoption), and there's really not."
Viewing post-quantum security problems from that kind of lens can help the cybersecurity industry start to work the issue with the same kind of risk management and roadmap planning steps they'd take for any other kind of serious emerging technology trend.
One thing is for certain: The drumbeat for quantum computing and post-quantum cryptography is getting louder.
Quantum computing stands to give the computing world a major boost in the ability to tackle multi-dimensional analysis problems that strain today's most advanced traditional supercomputers. Whereas traditional computers fundamentally work based on the storage of information in binary, quantum computing is not limited by the "on" or "off" position of information storage.
Quantum computers depend on the phenomenon of quantum mechanics called superposition, in which a particle can exist in two different states simultaneously. They take advantage of that phenomenon by using "qubits," which can store information in a variety of states at the same time.
Once perfected, this will give quantum computers the ability to greatly speed up data analysis on tough problems in areas as disparate as healthcare research and AI. However, this kind of power also makes these computers ideal for cracking cryptographic algorithms. This is the crux of the push for awareness from security advocates over the last several years to ensure that the industry starts preparing for that post-quantum reality.
"Our view on this is less about being alarmist and saying, 'You need to update everything now' and more of raising the awareness to start to think about what your data are, what your risk could be relative to that data and the crypto you use," Soutar says. "And then deciding when you might want to think about, start looking at discovery on your roadmap, and then updates later."
According to the survey released by Deloitte this week, the good news is that among those technology and business executives who are aware of quantum computing, a little over 50% also understood the attendant security considerations to it as well.
The trick in all of this for security professionals is that there are a lot of fires to put out elsewhere before worrying about something that could be years away. Today's quantum computers operate in the research realm only. They require immensely specialized equipment including microwaves manipulating quantum objects within supercooled environments that operate at near absolute zero in many instances. There is a long way to go on the research front for quantum computers to work in a commercially viable fashion, and no one is quite sure on what the timeline will be.
That "ambiguity of the timeline" is complicated, says Soutar, who explains there are numerous timelines to consider from a post-quantum cryptography perspective.
"The implications of quantum computing on cybersecurity is fairly well known, and it could be huge. I mean, cryptography is endemic in what we do throughout the economy. The thing is that the timing is unknown because first, a quantum computer needs to be mature and viable enough and commercially robust as well, to actually be able to run Shor's algorithm," he says, referring to an algorithm for finding prime factors of an integer that is the benchmark for whether a quantum computer could effectively break public key cryptography. "Secondly, attackers need to get access to data, and they need to untangle that data."
The other variable in this is a concept of attack called "harvest now, decrypt later," where attackers gather encrypted information now with the understanding that they could break it through quantum computing resources at a later date. The Deloitte survey shows that 50.2% of organizations believe they could be at risk for harvest now, decrypt later schemes.
"That then opens up risk to this data that I'm expecting to be good for the lifetime out of an individual," Soutar says. "Maybe it's personal information, or it's financial information that I want to be secure for at least 10 years. Or it's national security information which may have longer requirements on it."
He adds, "So, people are starting to think about, 'Well, what data do I have and how do I need to protect it? For how long? Secondly, how long is it going to take me to do the updates to post quantum cryptography? When should I start thinking about it?'"
These are the big timeline questions for security and quantum computing experts, who are still at odds over whether we've got 5, 10, or 15 years before the quantum effect impacts encryption. Soutar reiterates that perhaps the better thought process is to stop thinking about it as a definitive date the industry times for, and instead think about relative risk over time. He explains that this is an idea put forward by Dr. Michele Mosca, co-founder and CEO of Evolution Inc, and co-author of a report earlier this year that details that line of thinking.
"Then you can start to think, if I'm with a huge organization, maybe it's going to take me a decade to do the updates," Soutar explains. "I've got all these medical devices or other OT devices that I've got to think about the supply chain communications, and how do I enforce this on my suppliers?"
He adds, "So, again, it's getting that right degree of understanding so that people can start to maybe even quantify what the risk is, and stack that up against other cyber-risks that they're looking to invest in over time."
At the end of the day, Soutar says that maybe that the quantum lens can be a bit distracting to security. As long as organizations keep quantum on the horizon, it may just be a matter of making "perfunctory updates to crypto" that might not be that big of a deal for the industry if it is all done in due time.
"The quantum threat to crypto should really just be something that's addressed over time. Just do updates as the algorithms get standardized," says Soutar, who believes that the industry should be talking about the nuts and bolts of standardization, which can be boring but also are the most important way to start moving forward. "As they go through that process, then companies and governments have more confidence in making the changes, doing the updates, and they just do it. So, it really should be a non-event."
That's not to say that Soutar believes security practitioners should be sticking their heads in the sand with regard to quantum risk to security postures. The risks will accelerate, but it's just a matter of working that encryption roadmap like any other part of the cyber-risk roadmap. That includes doing risk assessments, discovering and classifying data, and projecting risk over time.
"It's never a bad idea to go look around in the attic. You don't know what you're going to find there. When we do that, when we go through basic cryptography, there are things that we find," he says. "You might say, 'Well, let's update that or let's make sure that we've got the right segregation of duties relative to that.' Or, 'Have we got all the responsibilities and governance laid out?' Again, it's the boring things. But those are things that you find when you look through the quantum lens."
Deloitte's survey shows that it may take some kind of regulatory push to prod security practitioners into serious steps on post-quantum cryptography. Soutar hopes that the industry is able to come together in the coming years to develop a framework for post-quantum cryptographic methods perhaps in the same spirit as the NIST Cybersecurity Framework (CSF).
"It's not a bad idea to have some framework out there when there's a whiff of potential regulation downstream," he says. "I think that's always better than just regulation, having something that's voluntary and outcome-based."
Read the original here:
Time to Quell the Alarm Bells Around Post-Quantum Crypto-Cracking - DARKReading
- Time Crystals Could be the Key to the First Quantum Computer - TrendinTech [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- The Quantum Computer Revolution Is Closer Than You May Think - National Review [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Chinese scientists build world's first quantum computing machine - India Today [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Quantum Computing | D-Wave Systems [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Quantum computing utilizes 3D crystals - Johns Hopkins News-Letter [Last Updated On: May 4th, 2017] [Originally Added On: May 4th, 2017]
- Quantum Computing and What All Good IT Managers Should Know - TrendinTech [Last Updated On: May 4th, 2017] [Originally Added On: May 4th, 2017]
- World's First Quantum Computer Made By China 24000 Times Faster Than International Counterparts - Fossbytes [Last Updated On: May 4th, 2017] [Originally Added On: May 4th, 2017]
- China adds a quantum computer to high-performance computing arsenal - PCWorld [Last Updated On: May 6th, 2017] [Originally Added On: May 6th, 2017]
- Quantum computing: A simple introduction - Explain that Stuff [Last Updated On: May 6th, 2017] [Originally Added On: May 6th, 2017]
- What is Quantum Computing? Webopedia Definition [Last Updated On: May 6th, 2017] [Originally Added On: May 6th, 2017]
- Quantum Computing Market Forecast 2017-2022 | Market ... [Last Updated On: May 6th, 2017] [Originally Added On: May 6th, 2017]
- China hits milestone in developing quantum computer - South China Morning Post [Last Updated On: May 8th, 2017] [Originally Added On: May 8th, 2017]
- China builds five qubit quantum computer sampling and will scale to 20 qubits by end of this year and could any beat ... - Next Big Future [Last Updated On: May 8th, 2017] [Originally Added On: May 8th, 2017]
- Five Ways Quantum Computing Will Change the Way We Think ... - PR Newswire (press release) [Last Updated On: May 8th, 2017] [Originally Added On: May 8th, 2017]
- Quantum Computing Demands a Whole New Kind of Programmer - Singularity Hub [Last Updated On: May 9th, 2017] [Originally Added On: May 9th, 2017]
- New materials bring quantum computing closer to reality - Phys.org - Phys.Org [Last Updated On: May 9th, 2017] [Originally Added On: May 9th, 2017]
- Researchers Invent Nanoscale 'Refrigerator' for Quantum ... - Sci-News.com [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- China's New Type of Quantum Computing Device, Built Inside a Diamond - TrendinTech [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Molecular magnets closer to application in quantum computing - Next Big Future [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- New Materials Could Make Quantum Computers More Practical - Tom's Hardware [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Home News Computer Europe Takes Quantum Computing to the Next Level With this Billion Euro... - TrendinTech [Last Updated On: May 13th, 2017] [Originally Added On: May 13th, 2017]
- Researchers seek to advance quantum computing - The Stanford Daily [Last Updated On: May 13th, 2017] [Originally Added On: May 13th, 2017]
- quantum computing - WIRED UK [Last Updated On: May 13th, 2017] [Originally Added On: May 13th, 2017]
- Scientists Invent Nanoscale Refrigerator For Quantum Computers - Wall Street Pit [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- D-Wave Closes $50M Facility to Fund Next Generation of Quantum Computers - Marketwired (press release) [Last Updated On: May 17th, 2017] [Originally Added On: May 17th, 2017]
- Quantum Computers Sound Great, But Who's Going to Program Them? - TrendinTech [Last Updated On: May 17th, 2017] [Originally Added On: May 17th, 2017]
- Quantum Computing Could Use Graphene To Create Stable Qubits - International Business Times [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Bigger is better: Quantum volume expresses computer's limit - Ars Technica [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- IBM's Newest Quantum Computing Processors Have Triple the Qubits of Their Last - Futurism [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- It's time to decide how quantum computing will help your business - Techworld Australia [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- IBM makes a leap in quantum computing power - PCWorld [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- IBM scientists demonstrate ballistic nanowire connections, a potential future key component for quantum computing - Phys.Org [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- The route to high-speed quantum computing is paved with error - Ars Technica UK [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- IBM makes leap in quantum computing power - ITworld [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Researchers push forward quantum computing research - The ... - Economic Times [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Quantum Computing Research Given a Boost by Stanford Team - News18 [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- US playing catch-up in quantum computing - The Register-Guard [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Stanford researchers push forward quantum computing research ... - The Indian Express [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- NASA Scientist Eleanor Rieffel to give a talk on quantum computing - Chapman University: Happenings (blog) [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- Graphene Just Brought Us One Step Closer to Practical Quantum Computers - Futurism [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- IBM Q Offers Quantum Computing as a Service - The Merkle [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- How quantum computing increases cybersecurity risks | Network ... - Network World [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- Quantum Computing Is Going Commercial With the Potential ... [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- Is the US falling behind in the race for quantum computing? - AroundtheO [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Quantum computing, election pledges and a thief who made science history - Nature.com [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Top 5: Things to know about quantum computers - TechRepublic [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Google Plans to Demonstrate the Supremacy of Quantum ... - IEEE Spectrum [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Quantum Computing Is Real, and D-Wave Just Open ... - WIRED [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- IBM to Sell Use of Its New 17-Qubit Quantum Computer over the Cloud - All About Circuits [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- Doped Diamonds Push Practical Quantum Computing Closer to Reality - Motherboard [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- For more advanced computing, technology needs to make a ... - CIO Dive [Last Updated On: May 30th, 2017] [Originally Added On: May 30th, 2017]
- Microsoft, Purdue Extend Quantum Computing Partnership To Create More Stable Qubits - Tom's Hardware [Last Updated On: May 30th, 2017] [Originally Added On: May 30th, 2017]
- AI and Quantum Computers Are Our Best Weapons Against Cyber Criminals - Futurism [Last Updated On: May 30th, 2017] [Originally Added On: May 30th, 2017]
- Toward mass-producible quantum computers | MIT News - MIT News [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Purdue, Microsoft Partner On Quantum Computing Research | WBAA - WBAA [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Tektronix AWG Pulls Test into Era of Quantum Computing - Electronic Design [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Telstra just wants a quantum computer to offer as-a-service - ZDNet [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- D-Wave partners with U of T to move quantum computing along - Financial Post [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- MIT Just Unveiled A Technique to Mass Produce Quantum Computers - Futurism [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Here's how we can achieve mass-produced quantum computers ... - ScienceAlert [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Research collaborative pursues advanced quantum computing - Phys.Org [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Team develops first blockchain that can't be hacked by quantum computer - Siliconrepublic.com [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Quantum computers to drive customer insights, says CBA CIO - CIO - CIO Australia [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- FinDEVr London: Preparing for the Dark Side of Quantum Computing - GlobeNewswire (press release) [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- Scientists May Have Found a Way to Combat Quantum Computer Blockchain Hacking - Futurism [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Purdue, Microsoft to Collaborate on Quantum Computer - Photonics.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- From the Abacus to Supercomputers to Quantum Computers - Duke Today [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Microsoft and Purdue work on scalable topological quantum computer - Next Big Future [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Are Enterprises Ready to Take a Quantum Leap? - IT Business Edge [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- A Hybrid of Quantum Computing and Machine Learning Is Spawning New Ventures - IEEE Spectrum [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- The Machine of Tomorrow Today: Quantum Computing on the Verge - Bloomberg [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- KPN CISO details Quantum computing attack dangers - Mobile World Live [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- Accenture, Biogen, 1QBit Launch Quantum Computing App to ... - HIT Consultant [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- Angry Birds, qubits and big ideas: Quantum computing is tantalisingly close - The Australian Financial Review [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- Consortium Applies Quantum Computing to Drug Discovery for Neurological Diseases - Drug Discovery & Development [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- Accenture, 1QBit partner for drug discovery through quantum computing - ZDNet [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- How to get ahead in quantum machine learning AND attract Goldman Sachs - eFinancialCareers [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- Quantum computing, the machines of tomorrow - The Japan Times [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Toward optical quantum computing - MIT News [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Its time to decide how quantum computing will help your ... [Last Updated On: June 18th, 2017] [Originally Added On: June 18th, 2017]