This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Preparing Your Organization for a Post-quantum World

Download resources

About this session

David Ott, senior staff researcher at VMware Research, explains why scaled quantum computers threaten today's public-key cryptography and what organisations should do about it now. He starts with the hardware (IBM's dilution-cooled machines and its qubit roadmap) and then the mathematics: RSA, Diffie-Hellman and elliptic-curve schemes rest on trapdoor functions that Shor's algorithm inverts in polynomial time, while Grover's algorithm only halves the effective strength of AES and SHA-2, which larger key and hash sizes can absorb. He surveys the post-quantum families under NIST standardisation (hash-based, code-based, lattice, multivariate, isogeny), their very different key and signature footprints, and the expected timeline of draft standards in 2022 and final ones around 2024. He distinguishes post-quantum cryptography from quantum key distribution, then spends the rest of the talk on cryptographic agility: cipher-suite negotiation, hybrid key exchanges and hybrid X.509 certificates, modular crypto libraries, and the research gaps for migrating complex, cloud-hosted enterprise stacks. He closes with practical readiness steps for organisations.

Preparing Your Organization for a Post-quantum World With the rise of quantum computing, the cybersecurity community now faces the prospects of migrating public key cryptography to new standards -- an undertaking that many agree will be complex given its massive scale. In this session, we will discuss the motivations and timeline of this coming change and key issues to watch for in the evolution of
scaled quantum computing. We’ll also talk about the new post-quantum cryptography algorithms and how your organization can prepare itself for what’s to come. This includes an industry-wide call for cryptographic agility in the
systems we develop and deploy.  

Key takeaways

  • Symmetric ciphers and hashes survive quantum attack with doubled key and output sizes; RSA, Diffie-Hellman and elliptic-curve schemes must be replaced outright.
  • Post-quantum algorithms are not drop-in replacements: expect much larger keys or signatures and different CPU cost, so test them in your own systems before the standards land.
  • Do not confuse post-quantum cryptography, which runs on ordinary computers, with quantum key distribution, which is a separate quantum-physics technology.
  • Plan the transition through hybrids (a FIPS algorithm plus a post-quantum one in the same handshake or certificate) so each keeps its guarantees while implementations mature.
  • Stand up an internal working group now, inventory every use of public-key cryptography, watch qubit counts and error-correction progress, and run pilot migrations.

Speakers

David Ott
David Ott
Snr. Staff Researcher & Academic Program Dir. · VMware Research
David Ott is a Senior Staff Researcher and Academic Program Director within VMware Research. VMware’s Academic Program is the external research arm of VMware, bringing together top academic researchers and company technical leaders to better… Read moreRead less

David Ott is a Senior Staff Researcher and Academic Program Director within VMware Research. VMware’s Academic Program is the external research arm of VMware, bringing together top academic researchers and company technical leaders to better understand disruptive technology trends and to explore new areas of innovation. Ott works on a range of topics at the intersection of security and systems and is a Ph.D. graduate in computer science from UNC Chapel Hill. He has spoken at the International Cryptographic Module Conference; Northeastern University Khoury College of Computer Science Speaker Series; Florida Institute for Cybersecurity Research; the National Institute of Standards and Technology (NIST) virtual workshop on Considerations in Migrating to Post-Quantum Cryptographic Algorithms and RSA Conference.

Resources

Tags

More from GoSec 2021

Also from David Ott

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.