Security in Systems: Understanding Why Encryption Will Be Crucial

Aug 30, 2023 | min read
By

Leonardo Horvath dos Reis

Behind the scenes of technological evolution, a new chapter is unfolding: the era of quantum computing. The promise of computational superpower comes with a critical question: How do we protect our data in a world where conventional encryption can be easily challenged? The answer lies in "post-quantum cryptography," an approach that aims to keep our information secure despite the growing quantum threat.

The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST) have warned that quantum computing could enable the breaking of traditional cryptography and recommend the early planning of migration to post-quantum cryptographic standards, developing a "quantum readiness roadmap" prioritizing the organization's most critical systems, emphasized by the NSA.

The promise of quantum computing brings with it the shadow of a new challenge. This revolutionary technology has the potential to break security systems in a matter of hours. Imagine a scenario where quantum computing becomes widely accessible: malicious individuals could exploit this capability to commit various crimes. In fact, researchers from the Massachusetts Institute of Technology (MIT) state that a quantum system could decipher the encryption of a common personal computer in just eight hours. This scenario illustrates the urgent need to take measures to protect ourselves against the potential risks that quantum computing might bring.

What's the difference between a conventional computer and a quantum computer?

The fundamental distinction lies in the property called "superposition," present in quantum computers. This subatomic feature allows them to process a variety of information simultaneously. In contrast, traditional computers operate in binary language, composed of zeros and ones. For a simplified understanding, imagine that quantum computers can manipulate all possible combinations of zeros and ones at the same time while conventional PCs process one zero or one at a time. This gives quantum computers an exponential boost in terms of power and processing speed.

Currently, IBM possesses the most powerful quantum computer, known as "Osprey," with a processing power of 433 qubits, three times more than the previous machine "Eagle." The average production cost is estimated to be around 100 million dollars per unit.

What measures are being taken to enhance encryption?

On May 4 2022, the United States Department of State released a subsequent document known as National Security Memorandum 10 (NSM-10), with the goal of "Promoting U.S. Leadership in Quantum Computing and Mitigating Risks to Vulnerable Cryptographic Systems." This new technological approach paved the way for the development of post-quantum cryptography (PQC), a cryptographic method that employs principles of quantum mechanics to reinforce security. Additionally, PQC is being designed to become an accessible option on common computers, aiming to reduce cybercrime and comprehensively protect various types of data.

Meanwhile, computer experts are racing against time to replace RSA encryption and other standard approaches with post-quantum encryption solutions capable of resisting potential attacks from quantum machines. According to the NSA, the new post-quantum encryption model is scheduled to be published in 2024. These efforts demonstrate a strong commitment to adapting our security methods to imminent technological evolution.

Why is acting now necessary?

It is widely understood that many countries are investing in building quantum computers for defensive purposes. However, the growing interest from criminal organizations must also be considered. This could result in an unprecedented dominion literally at their fingertips, with all confidential and private information circulating the internet becoming accessible to any individual or entity with this kind of power. This includes national secrets, medical records, financial and banking details, as well as the ability to access critical infrastructures such as energy networks, satellite communications, and water supply. Therefore, taking action now is vital to protect us against potential threats and prepare countermeasures for sensitive systems and data.

What are the NSA guidelines while new standards are being established?

Establish a quantum readiness roadmap

Engage with technology vendors to discuss post-quantum roadmaps.

Current Cryptography Inventory: Start by creating a comprehensive inventory of all currently used cryptography systems. This includes identifying where encryption is applied, such as in applications, identity control, transport layers, and data storage. Having a full view will help understand the extent of necessary migration.

Prioritize Critical Systems: Once you have a clear inventory, prioritize the most critical systems that require a change in encryption. This will allow you to focus your efforts where protection is most urgent and essential for security.

Adopt the Zero Trust Architecture: Consider migrating to the Zero Trust architecture in your security solutions. This approach involves creating layers of security around each asset and user rather than blindly trusting a perimeter network. This helps minimize the risk of unauthorized access, even in internal environments.

Use Advanced Security Solutions: Implement security solutions to identify anomalies and block threats in real-time. Technologies like Endpoint Detection and Response (EDR) and Continuous Diagnostics and Mitigation (CDM) are examples of tools that can constantly monitor systems, identify suspicious activities, and take preventive or corrective actions.

Conclusion

In the midst of the impending quantum revolution, preserving the security of our data has become imperative. Post-quantum cryptography has emerged as the anchor to protect us in this evolving scenario. By following the recommendations of the NSA and adopting proactive measures, governments and businesses will be ahead of emerging threats from quantum computing. Migrating to new cryptographic standards, seeking post-quantum technology, and adopting robust security practices are fundamental steps to ensure that information remains confidential despite the most complex challenges. Therefore, taking action now is not just a choice, but a necessity in this digital evolution.

Sources

NSA: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3498776/post-quantum-cryptography-cisa-nist-and-nsa-recommend-how-to-prepare-now/

Forbes: https://www.forbes.com/sites/forbestechcouncil/2023/01/25/what-the-quantum-computing-cybersecurity-preparedness-act-means-for-national-security/?sh=4625aed9368a

Security Report: https://www.securityreport.com.br/computacao-quantica-e-seus-efeitos-na-criptografia/


Leonardo Horvath

Leonardo Horvath dos Reis

Senior Security Officer, CI&T