Инфраструктура и связь · 1 августа 2024 · 3 мин чтения

Post-quantum cryptography for cybersecurity

In Monitoring No. 2 we have already examined the trend towards standardization in the field of quantum technologies in some countries (USA, UK) with a focus on the security aspects of such technologies.

Из выпуска мониторинга No. 8, August 2024 · выпуск целиком, PDF · на сайте Института Гайдара

In Monitoring No. 2 we have already examined the trend towards standardization in the field of quantum technologies in some countries (USA, UK) with a focus on the security aspects of such technologies.

Cryptography is essential in the digital economy, protecting electronically stored and transmitted information such as emails, medical records and billing data. Cryptography is based on mathematical problems that are too difficult or impossible for conventional computers to solve. But with the advent of quantum computers, characterized by the power and speed of computation, many such problems become solvable, which jeopardizes both the confidentiality of personal information and the security of critical infrastructure, such as power supply. In this regard, the development and implementation of standards of post-quantum cryptography, i.e., based on tasks that are beyond the power of either conventional or quantum computers, is relevant - such a task, for example, is a learning-with-error (LWE) problem.

The US experience

In August 2024, the first 3 post-quantum cryptography standards were adopted in the US:1 1 on key-encapsulation for information transmitted over networks and 2 (primary and backup, based on a different mathematical2 approach) for digital signatures.

The National Institute of Standards and3 Technology (NIST) began developing postquantum cryptography standards in 2017 and selected options in 3 phases, including security assessments and performance benchmarking.

The technical solutions contained in the standards are resistant to attacks by quantum computers. For example, in the standard on key-4 encapsulation, the solution for establishing a secret key that can then be used for encryption and authentication is based on the computational complexity of a learning-witherror (LWE) problem.

Despite the fact that this is essentially a matter of preparing for future threats, in the U.S. as early as 2023, prior to the adoption of these standards, all organizations were encouraged to begin planning for the transition to post-quantum5 cryptography standards.

The EU experience

In contrast to the US, the EU is currently discussing more general parameters. In April 2024, the European Commission's recommendations for the transition to postquantum cryptography were adopted to define goals, milestones, and timelines for the6 formation of a joint roadmap.

In the mean time, at the level of member states (e.g., Germany, France, the Netherlands7 and Sweden ), data protection authorities are urging companies to take steps toward quantum-resistant encryption now. According to the agencies of these countries, the focus should be on post-quantum cryptography available on existing hardware, including using the standards developed by the US NIST.

Russia’s experience

Since 2019, the development of national standards for post-quantum cryptographic information protection in Russia has been carried out by working group 2.5 “Post-quantum cryptographic mechanisms” of the Technical Committee for Standardization “Cryptography8 and Security Mechanisms” (TC26). TC26 works under the direction of Rosstandart and the9 Federal Security Service of Russia.

In 2023, within TC26 a post-quantum electronic signature algorithm “Shipovnik” based on the problem of decoding a random linear10 code was developed, and in March 2024 - a post-quantum key-encapsulation scheme “Codium” for the protection of information transmitted in networks, including communications, based on the same class of11 mathematical problems. A draft standard using this scheme is being prepared.


From the monitoring issue No. 8, August 2024. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также