Skip to Main Content Subscribe

Agencies Need to Quantum-Proof Their Software, Not Just Their Data

Share

Technology officials are urging agencies to get started now in protecting their data and their applications from potential quantum decryption.

2m read
Written by:
National security officials at the Billington Cybersecurity Conference stressed Tuesday that agencies take steps to begin their conversion to post-quantum-cryptography now.
National security officials at the Billington Cybersecurity Conference stressed Tuesday that agencies take steps to begin their conversion to post-quantum-cryptography now. Photo Credit: Oh Yes Communications

The threat of a quantum computer breaking the encryption of secure networks has been looming on the horizon for years, but some national security officials are calling on agencies to start taking proactive measures now to not only safeguard data, but their software as well.

“It’s one thing to lose some data, that’s bad, don’t get me wrong, it’s another thing if you start losing systems,” said Adrian Stanger, Cybersecurity Directorate Senior Cryptographic Authority at the National Security Agency at the Billington Cybersecurity conference on Tuesday.

Speaking on a panel about ongoing efforts to help secure networks from quantum threats, Stanger said concerns over the possibility of a quantum computer attaining enough power to crack the cryptographic code that safeguards sensitive data have understandably been driving the urgency to shift both government and industry systems to a post-quantum standing for years.

But converting to post-quantum cryptography (PQC) has to go beyond just data protection, he said, to ensure software applications and authentication processes are protected as well.

“Even if you may not be actively using cryptography in some systems, a lot of times that software is protected by a digital signature that a quantum computer could break,” he said. “So, this means not just looking at cryptography in the way your enterprise specifically uses it, but also working with vendors to make sure that their updates, their security patch updates, that all of that is protected by something that is quantum-resistant as well.”

Quantum computers process data through qubits, which can take the value of both 0 and 1 binary bits at the same time, increasing their compute power.

If a quantum computer can theoretically entangle enough qubits to outpace the processing power of a classical computer, the fear is that it will be able to crack the cryptographic algorithms currently used to encrypt most data.

While the threat is not yet present, it is critical enough that the National Institute of Standards and Technology has worked for more than a decade on developing standardized quantum-resistant algorithms to safeguard networks and to advise agencies on how to convert their cryptography while adversaries are presently capturing troves of data they hope to one day decrypt.

“There is some quantity of information that we can credibly deem is already lost at some future state,” said Victor Foulk, vice president at CGI Federal. “This is from a security perspective, most of us think about seeing a vulnerability come and then we have that gap. We’ll patch systems, we’ve got to operate systems to a particular vulnerability, this is imperfect. The vulnerability hasn’t arrived yet, but the information is already compromised in a future sense. That’s what is driving the sense of urgency.”

While agencies are on the clock to convert their data to quantum-resistant cryptography, Bill Newhouse, cybersecurity engineer at NIST’s National Cybersecurity Center of Excellence (NCCoE), stressed that chief information security officers need to lay the foundation by updating to the most recent cryptographic protocols before trying to tackle PQC.

“You can’t get to PQC without [Transport Security Layer] 1.3. That means if you are staying at 1.2 or 1.1, you are not going to benefit from the cryptography in your classical devices or any devices that would be resistant to attack from a quantum computer,” he said.

Newhouse pointed to NIST’s three PQC algorithms and the June executive order mandating high-value assets and high-impact systems convert to PQC by December 2030 as positive steps, but stressed that preparation has to extend to acquisition as well to ensure the technology being procured is prepared for PQC as well.

“The [Federal Acquisition Regulation] Council needs to update some things,” he said. “We don’t want to miss the opportunity now at the executive level to be telling everybody that all procurements need to say something about quantum readiness and the use of post-quantum cryptography through public key cryptography systems.”

And as agencies prepare for PQC conversion, Stanger stressed that agencies could get started today by inventorying their software programs and systems that will need conversion, updating to TLS 1.3, starting to budget and developing a logistical plan.

“We’re not really quantum-resistant until we’ve turned off all of the quantum-vulnerable cryptography as well,” he said. “So, it’s not just enough to migrate as in deploy, we also have to turn off the other stuff.”

Related Content