Now Is the Time to Plan for Post-Quantum Cryptography – DARKReading
RSA CONFERENCE 2022 Even the most future-facing panels at this year's RSA Conference are grounded in the lessons of the past. At the post-quantum cryptography keynote "Wells Fargo PQC Program: The Five Ws," the moderator evoked the upheaval from RSAC 1999 when a team from Electronic Frontier Foundation and Distributed.net broke the Data Encryption Standard (DES) in less than a day.
"We're trying to avoid the scramble" when classical cryptography techniques like elliptic curve and the RSA algorithm inevitably fall to quantum decrypting, said Sam Phillips, chief architect for information security architecture at Wells Fargo. And he set up the high stakes encryption battles often have: "Where were all the DES implemented? Hint: ATM machines."
"We had to set up teams to see where all we were using[was DES] and then establish the migration plan based upon using a risk-based approach," Phillips said. "We're trying to avoid that by really trying to get ahead of the game and do some planning in this case."
Phillips was joined on stage by Dale Miller, chief architect of information security architecture at Wells Fargo, and Richard Toohey, technology analyst at Wells Fargo.
Toohey, a doctoral candidate at Cornell University, handled most of the technical aspects of quantum computing during the panel.
"For most problems, if you have a quantum calculator and a regular calculator, they can add numbers just as well," he explained. "There's a very small subset of problems that are classically very hard, but for a quantum computer, they can solve [them] very efficiently."
These problems are called np-hard problems.
"A lot of cryptography, specifically in asymmetric cryptography, relies on these np-hard type problems things like elliptic curve cryptography, the RSA algorithm, famously and when quantum computers are developed enough, they'll be able to brute-force their way through these," Toohey explained. "So that breaks a lot of our modern classical cryptography."
The reason why we don't have crypto-breaking quantum computers today, despite headline-making offerings from IBM and others, is because the technology to reach that level of power has not been accomplished yet.
"To become a cryptographically relevant quantum computer, a quantum computer needs to have about 1 to 10 million logical qubits, and those logical qubits all need to be made up of about 1,000 physical qubits," Toohey said. "Today, right now, the largest quantum computers are somewhere around 120 physical qubits."
He estimated that to even muster the first logical qubit will take three years, and from there it has to scale up to "a million or so logical qubits. So it's still quite a few years away."
Another technical challenge that needs solving before we get these powerful quantum computers is the cooling systems they require.
"Qubits are incredibly sensitive; most of them have to be held at very low, cryogenic temperatures," Toohey explained. "So because of that, quantum computing architecture is incredibly expensive right now."
Other problems include decoherence and error correction. The panel agreed that the combination of these issues means crypto-cracking quantum computers are eight to10 years away. But that doesn't mean we have a decade to address PQC.
The panel was named for the journalistic model of five questions that start with the letter "w," but that didn't come up until late in the audience Q&A portion.
"Sam was asking the what, the who, the why, the where, and the when," Miller said. "So I think we've covered that in our conversations here."
Most of the titular questions were somewhat vague and a matter of judgment. However, on the concept of when you should start planning for the post-quantum future, there was complete agreement: Now.
"You've got to start the process now, and you have to move yourself forward so that you are ready when a quantum computer comes along," Miller said.
Phillips concurred.
"There is not right now a quantum computer that is commercially viable, but the amount of money and effort going into the work is there to move it forward, because people recognize the benefits that are there, and we are recognizing the risk," he said. "We feel that it's an eventuality, that we don't know the exact time, and we don't know when it'll happen."
Toohey suggested beginning preparations with a crypto inventory again, now.
"Discover where you have instances of certain algorithms or certain types of cryptography, because how many people were using Log4j and had no idea because it was buried so deep?" he said. "That's a big ask, to know every type of cryptography used throughout your business with all your third parties that's not trivial. That's a lot of work, and that's going to need to be started now."
Wells Fargo has a goal to beready to run post-quantum cryptography in five uears, which Miller described as"a very aggressive goal."
"So the time to start is now," he said,"and that's one of the most important takeaways from this get-together."
Pivoting is a key marker of agility for the panel, and agility is vital for being able to react to not just quantum threats, but whatever comes next.
"The goal here should be crypto agility, where you're able to modify your algorithms fairly quickly across your enterprise and be able to counter a quantum-based attack," Miller said. "And I'm really not thinking on a day-to-day basis about when is the quantum computer going to get here. For us, it's more about laying a path and a track for quantum resiliency for the organization."
Toomey agreed about the importance of agility.
"Whether it's a quantum computer or new developments in classical computing, we don't want to be put in a position where it takes us 10 years to do any kind of cryptographic transition," he said. "We want to be able to pivot and adapt to the market as new threats come out."
Because there will be computers that can break current cryptography techniques, organizations do need to develop new encryption methods that stand up to quantum brute-force attacks. But that's only the half of it.
"Don't just focus on the algorithms," Phillips said. "Start looking at your data. What data are you transiting back and forth? And look at devaluing that data. Where do you need to have that confidential information, and what can you do to remove that from the exposure? It will help a lot not only in the crypto efforts, but in terms of who has access to the data and why they have to have access."
One open question loomed over the discussion: When would NIST announce its picks for the new standards to develop for post-quantum cryptography? The answer: Not yet. But the uncertainty is no cause for inaction, Miller said.
"So NIST will continue to work with other vendors and other companies and research groups to look at algorithms that are further out there," he said. "Our job is to be able to allow those algorithms to come into place quickly, in a very orderly manner, without disrupting business or breaking your business processes and [to] be able to keep things moving along."
Phillips agreed. "That's one of the reasons for pushing on plug and play," he said. "Because we know that the first set of algorithms that come out may not satisfy the long-term need, and we don't want to keep jumping through these hoops every time somebody goes through it."
Toohey tied the standards question back into the concept of preparing now.
"That way, when NIST finally finishes publishing their recommendations, and standards get developed in the coming years, we're ready as an industry to be able to take that and tackle it," he said."That's going back to crypto agility and this mindset that we need to be able to plug and play. We need to be able to pivot as an industry very quickly to new and developing threats."
Here is the original post:
Now Is the Time to Plan for Post-Quantum Cryptography - DARKReading
- D-Wave enters agreement to sell up to $400M shares from time to time - Yahoo Finance - June 14th, 2025 [June 14th, 2025]
- IBM is building a large-scale quantum computer that 'would require the memory of more than a quindecillion of the world's most powerful... - June 14th, 2025 [June 14th, 2025]
- Prediction: This Quantum Computing Stock Will Surge in 2025 - The Globe and Mail - June 14th, 2025 [June 14th, 2025]
- IBMs Fault-Tolerant Quantum Computer Breakthrough: Exec More Comfortable Than Ever About 2029 Delivery - TechRepublic - June 14th, 2025 [June 14th, 2025]
- Protection against quantum computing threats now within grasp for companies and institutions - Orange - June 14th, 2025 [June 14th, 2025]
- Planckian Partners With University of Naples to Accelerate Next-Gen Quantum Processor - The Quantum Insider - June 14th, 2025 [June 14th, 2025]
- Bitcoin devs scramble to protect $2.2tn blockchain from looming quantum computer threat - dlnews.com - June 14th, 2025 [June 14th, 2025]
- Quantum Art to Advance Scalable Quantum Computing Through Logical Qubit Compiler and NVIDIA CUDA-Q Integration - The Quantum Insider - June 14th, 2025 [June 14th, 2025]
- Why Shares of D-Wave Quantum Are Sinking This Week - The Motley Fool - June 14th, 2025 [June 14th, 2025]
- Mind-Blowing Quantum Leap: IBMs Groundbreaking Fault-Tolerant PC Set to Revolutionize Tech by 2029Prepare for Unprecedented Computational Power -... - June 14th, 2025 [June 14th, 2025]
- Why it's time to move beyond qubits for assessing quantum progress - Diginomica - June 14th, 2025 [June 14th, 2025]
- Quantum Computers Pose a Grave Risk to The Future. Here's Why. - ScienceAlert - June 10th, 2025 [June 10th, 2025]
- Want to Invest in Quantum Computing? 3 Stocks That Are Great Buys Right Now. - Yahoo Finance - June 10th, 2025 [June 10th, 2025]
- At 40 ISC 2025 Continues to Connect the Dots - HPCwire - June 10th, 2025 [June 10th, 2025]
- Vodafone teams up with Orca for quantum-powered network optimisation - Capacity Media - June 10th, 2025 [June 10th, 2025]
- IonQ goes quantum shopping: Buys Oxford Ionics for $1.075B - Silicon Canals - June 10th, 2025 [June 10th, 2025]
- Infleqtion Selected to Power the UKs Largest Quantum Computing Breakthrough - Business Wire - June 10th, 2025 [June 10th, 2025]
- BTQ Technologies Announces Strategic Partnership with QPerfect to Achieve Quantum Advantage Using Neutral Atom Quantum Processors - WV News - June 10th, 2025 [June 10th, 2025]
- Quantum computers are on the edge of revealing new particle physics - New Scientist - June 10th, 2025 [June 10th, 2025]
- Where Will IonQ Be in 5 Years? - The Motley Fool - June 10th, 2025 [June 10th, 2025]
- IonQ buys Oxford Ionics for $1.075B: 6 things to know about it - Tech Funding News - June 10th, 2025 [June 10th, 2025]
- IBM plans to build first-of-its-kind quantum computer by 2029 after 'solving key bottleneck' - Live Science - June 10th, 2025 [June 10th, 2025]
- IBM aims to build the worlds first large-scale, error-corrected quantum computer by 2028 - MIT Technology Review - June 10th, 2025 [June 10th, 2025]
- IBM announced that it will release a quantum computer that has solved the error problem by 2029. Qua.. - - June 10th, 2025 [June 10th, 2025]
- Vodafone aims to leverage quantum computer to streamline broadband installation routes - Telecompaper - June 10th, 2025 [June 10th, 2025]
- This tiny quantum computer could blow massive data centers out of the water with speed, power, and pure physics - TechRadar - June 1st, 2025 [June 1st, 2025]
- Where Will Rigetti Computing Be in 5 Years? - Yahoo Finance - June 1st, 2025 [June 1st, 2025]
- IonQ vs. Microsoft: Which Quantum Cloud Stock Is the Better Buy Today? - Zacks Investment Research - June 1st, 2025 [June 1st, 2025]
- Q1 2025 Quantum Technology Investment: Whats Driving the Surge in Quantum Investment? - The Quantum Insider - June 1st, 2025 [June 1st, 2025]
- Where Will Rigetti Computing Be in 5 Years? - The Motley Fool - June 1st, 2025 [June 1st, 2025]
- Our Online World Relies on Encryption. What Happens If It Fails? - Boston University - June 1st, 2025 [June 1st, 2025]
- Jim Cramer on D-Wave Quantum (QBTS): Of the Ones That Are Out There, This is the Best - Insider Monkey - June 1st, 2025 [June 1st, 2025]
- It Might Actually Be 20 Times Easier for Quantum Computers to Break Bitcoin, Google Says - Decrypt - June 1st, 2025 [June 1st, 2025]
- Want to Invest in Quantum Computing? 2 Stocks That Are Great Buys Right Now. - The Motley Fool - June 1st, 2025 [June 1st, 2025]
- IonQ vs. Microsoft: Which Quantum Cloud Stock Is the Better Buy Today? - Yahoo Finance - June 1st, 2025 [June 1st, 2025]
- CEOs who aren't yet preparing for the quantum revolution are 'already too late,' IBM exec says - Business Insider - June 1st, 2025 [June 1st, 2025]
- New quantum visualisation techniques could accelerate the arrival of fault-tolerant quantum computers - University of Oxford - June 1st, 2025 [June 1st, 2025]
- Marylands Quantum Capital Ambitions Rely on UMD Physicist Ronald Walsworth - Source of the Spring - June 1st, 2025 [June 1st, 2025]
- We asked an expert about quantum computer threat as Google and BlackRock ring the alarm - Crypto News - June 1st, 2025 [June 1st, 2025]
- Whats Happening With IONQ Stock? - Trefis - June 1st, 2025 [June 1st, 2025]
- New Startup Sygaldry Aims to Rethink AI Infrastructure With Quantum Hardware - The Quantum Insider - June 1st, 2025 [June 1st, 2025]
- Breaking encryption with a quantum computer just got 20 times easier - New Scientist - May 26th, 2025 [May 26th, 2025]
- D-Wave launches the Advantage2 quantum computer with more than 4,400 qubits - SiliconANGLE - May 26th, 2025 [May 26th, 2025]
- Nvidia in Talks to Invest in Quantum Startup PsiQuantum - The Information - May 19th, 2025 [May 19th, 2025]
- Quantum Computers Just Outsmarted Supercomputers Heres What They Solved - SciTechDaily - May 19th, 2025 [May 19th, 2025]
- Should You Buy IonQ Stock to Ride the Quantum Computing Revolution? The Answer May Surprise You - The Motley Fool - May 19th, 2025 [May 19th, 2025]
- D-Wave Quantum Stock Soaring On 509% Revenue Pop And Growth Prospects - Forbes - May 19th, 2025 [May 19th, 2025]
- Quantum Machines Launches Open-Source Framework that Cuts Quantum Computer Calibration From Hours to Minutes - The Quantum Insider - May 19th, 2025 [May 19th, 2025]
- Silicon qubits bring scalable quantum computing closer to reality - The Brighter Side of News - May 19th, 2025 [May 19th, 2025]
- Quantum Computers Are Here, but Are Cybersecurity Professionals Ready? - IoT World Today - May 19th, 2025 [May 19th, 2025]
- Quantum Computing Stock Tumbles After Last Week's 50% SurgeWatch These Key Levels - Investopedia - May 19th, 2025 [May 19th, 2025]
- Nvidia in talks to invest in PsiQuantum - Tom's Hardware - May 19th, 2025 [May 19th, 2025]
- Quantum computing: What is quantum error correction (QEC) and why is it so important? - Live Science - May 19th, 2025 [May 19th, 2025]
- Quantum Computing Roadmaps: A Look at The Maps And Predictions of Major Quantum Players - The Quantum Insider - May 19th, 2025 [May 19th, 2025]
- Quantum Computing Stock Surges as Firm Swings to Profit - Investopedia - May 19th, 2025 [May 19th, 2025]
- $850bn by 2040! Should I buy quantum computing stocks for my Stocks and Shares ISA? - Yahoo - May 19th, 2025 [May 19th, 2025]
- France, Germany, and the Netherlands Launch $33M Trilateral Quantum Initiative - The Quantum Insider - May 19th, 2025 [May 19th, 2025]
- Oxford Quantum Circuits Appoints Former GCHQ Director Sir Jeremy Fleming to Board - HPCwire - May 19th, 2025 [May 19th, 2025]
- Outside the Box: Socratic Machines and Quantum Ghosts - Fair Observer - May 19th, 2025 [May 19th, 2025]
- Preparing for the post-quantum era: a CIOs guide to securing the future of encryption - CyberScoop - May 19th, 2025 [May 19th, 2025]
- Quantum Computing First Quarter 2025 Earnings: EPS Beats Expectations, Revenues Lag - Yahoo Finance - May 19th, 2025 [May 19th, 2025]
- Nvidia in Talks to Invest in Quantum Computing Startup - The Information - May 19th, 2025 [May 19th, 2025]
- IonQ Stock Is Up 294% in the Past Year. Here's My Prediction For What Comes Next - The Motley Fool - May 19th, 2025 [May 19th, 2025]
- Does Billionaire Israel Englander Know Something Wall Street Doesn't? He Sold a Quantum Computing Stock Analysts Say to Buy. - The Motley Fool - May 19th, 2025 [May 19th, 2025]
- From R&D to ROI: The quantum computing revolution starts here - Techcircle - May 19th, 2025 [May 19th, 2025]
- How quantum computers could break RSA encryption and cure Alzheimer's - Interesting Engineering - May 19th, 2025 [May 19th, 2025]
- The race to perfect the quantum computer is on, and UC is helping America hold its lead - University of California - May 15th, 2025 [May 15th, 2025]
- Keysight Quantum Control System Embedded within Fujitsu and RIKENs World-Leading 256-Qubit Quantum Computer - Morningstar - May 15th, 2025 [May 15th, 2025]
- Keysight Technologies, Inc. Quantum Control System Embedded Within Fujitsu and Riken's 256-Qubit Quantum Computer - marketscreener.com - May 15th, 2025 [May 15th, 2025]
- The Worlds First Song Created by Artificial Intelligence Using a Quantum Computer Is HereIt Sounds Nothing Like What You Expect - The Daily Galaxy - May 11th, 2025 [May 11th, 2025]
- Regulation watch: how governments are dealing with the risks of quantum computing - Strategic Risk Global - May 11th, 2025 [May 11th, 2025]
- The age of the hype cycle: why science needs room to breathe - varsity.co.uk - May 11th, 2025 [May 11th, 2025]
- Quantums Double-Edged Sword: Balancing Risk and Readiness - InformationWeek - May 11th, 2025 [May 11th, 2025]
- The Computational Limit of Life May Be Much Higher Than We Thought - Yahoo - May 11th, 2025 [May 11th, 2025]
- BlackRock beefs up quantum compute threat warnings to Bitcoin investors - dlnews.com - May 11th, 2025 [May 11th, 2025]
- From false alarms to real threats: Protecting cryptography against quantum - cio.com - May 11th, 2025 [May 11th, 2025]
- Boosting quantum error correction using AI - Phys.org - May 11th, 2025 [May 11th, 2025]
- Laws governing finance and investment can help to protect society from dangers of quantum computing, study shows - Phys.org - May 11th, 2025 [May 11th, 2025]
- Quantum computing stocks jump after strong results from D-Wave Quantum (QBTS:NYSE) - Seeking Alpha - May 11th, 2025 [May 11th, 2025]
- Listen to the worlds first song made by a quantum computer and AI - The Next Web - May 10th, 2025 [May 10th, 2025]