[ad_1]
We have all been spoiled for 40 years. We drank the elixir that is RSA which heals all ailments. RSA solves the problem of electronic communications security. It allowed data to be encrypted between a sender and a recipient without prior exchange of secret information. Not only that, it made it possible to apply digital signatures to data to prove its integrity and support non-repudiation. All we had to decide was the length of the key, which increased over decades as computing power increased to thwart brute force attacks.
This golden age of cryptography is coming to an end. The hardness problem underlying RSA can be solved by a sufficiently large quantum computer, which could exist as early as 2026, but most likely will be in the early 2030s. The same is true for elliptical curve cryptography. It is not very far.
Unfortunately, to deal with this situation our lives will become much more complicated. There is no single algorithm that is quantum resistant and can replace RSA. We are faced with a range of relatively immature algorithms with various strengths and tradeoffs. We will have to choose between encryption speed, decryption speed and key size. Starting next year, NIST is expected to certify a number of quantum resistance algorithms. Industry will need to determine where to use each one.
There are several implications that we must start to consider. The first is that we are going to deploy a range of algorithms for different use cases. We will need to look at our requirements for our applications and choose the algorithm that works best. For IoT applications, the size of the key will be important. For code signing, the signature validation speed will be critical. Suppliers will have to decide which algorithms they will support, are you prepared to have your input into those decisions?
The issue of crypto agility will become critical. Given the speed at which quantum resistant algorithms will need to be deployed, they will not have undergone the analysis and validation that preceded the standardization and deployment of previous algorithms. It is likely that some of these will prove to be less secure than expected, which may require rapid replacement to keep business applications secure. It will therefore be more important than ever to maintain an inventory of your crypto park and the organizational and technical infrastructure to quickly replace crypto.
Although quantum resistance algorithms are untested, we predict that a hybrid model will prevail in which the old and new crypto will be combined to provide the classical strength of current algorithms enhanced by quantum resistance algorithms. This can be done in a number of ways, which NIST is currently evaluating. As with any new standard, interoperability will take time. The fact that we will be living with a number of quantum resistance algorithms along with backward compatibility considerations will likely create additional interoperability issues.
My take is to see how organizations have struggled with relatively straightforward crypto updates such as the migration from SHA-1 to SHA-2. This was difficult and took much longer than it should have (introducing company level risks into the process). It was a walk in the park compared to the transition to quantum resistant crypto. I advise you to start your planning now to establish your crypto inventory and assign ownership of the initial planning activities.
To learn more about Post Quantum security, watch our video.
The post The end of the golden age of crypto? first appeared on Entrust Blog.
*** This is a syndicated Security Bloggers Network blog from Entrust Blog written by Ian Wills. Read the original post at: https://www.entrust.com/blog/2021/10/the-end-of-the-golden-age-of-crypto/
|
Sources 2/ https://securityboulevard.com/2021/10/the-end-of-the-golden-age-of-crypto/ The mention sources can contact us to remove/changing this article |
[ad_2]