The Future of Quantum Security with Forrester’s Andras Cser
The commercial availability of quantum computers that are capable of compromising traditional asymmetric cryptography is still five to 10 years away. But security and risk (S&R) professionals must assess and prepare for the impact of quantum security. Here, Forrester’s Andras Cser will discuss the governance, strategy, architecture, and impacts of quantum security in the short, medium, and long term
Transcript
This is Textron tv. Hi everyone, it's Alan Shimmel, and we're back here on Textron tv. You know, by the time you watch this, I'll probably be out in San Francisco at the RSA conference where, you know, the world gathers the talk security.
But one of the, you know, besides ai, which everyone's talking about, one of the hot topics in security is the future of what we call quantum security, right? A lot of people were very afraid of quantum, frankly, you know, was it gonna break all of our encryptions in our RSA encryption and, and so forth? Um, it's, it happens to be an area where NIST got involved.
The, uh, industry has gotten involved. We have some quantum proof algorithms, but there's more to quantum security than that. I want to introduce you to Andres Chair.
Andre is the vice president, principal analyst at Forester covering this topic. Let's welcome to Tech Drunk tv. Hi, Andre, welcome and thanks for being here.
Absolutely. Thanks, Alan for having Me. My pleasure.
Yeah, really good to be here. I'll be at the RSA as well next week. So interested part as Will likely seeing me there.
We, that's all. Again, We'll be, we'll, we're a broadcast alley all week, you know, in, over in Moscone West, so if you find yourself over there, come by and say hello. Yeah.
Oh, definitely. I shall do that. Okay.
I definitely, myself, I look, I'm an analyst here at Forrester. I look at, um, encryption, cloud encryption technologies. So that's, and then cloud security on a broader scale, identity and access management, mainly, uh, the customer facing side of things that also has a lot of authentication use in public key infrastructure, or PKI as well as fraud management.
So definitely, uh, agencies to quantum, quantum, uh, quantum security, quantum, uh, uh, safe quantum proof encryption. Sure. Okay.
So a lot of questions, uh, from all sorts of end users on the topic, and they're definitely happy to kind of share some of what, what we're telling our, our customers here on these advisors. Sure. So, Andrew, as I mentioned in the opening for once, it seemed like we got out ahead of an issue, right?
And over the last couple years, NIST has spearheaded, uh, a move towards enabling, you know, as they call it, quantum proof algorithms, which should theoretically protect, you know, our encrypted data in a, in a quantum world. Um, Absolutely. What, what's your thoughts on that?
So, it is absolutely great, right? I mean, this is a great first statute of the national standards. Uh, body in the US obviously has done this, and there's other agencies, uh, other similar kinds of agencies with similar mandates globally that have done similar things.
The fun part is that not a, not mess, the approved, that sanctioned algorithms are not necessarily the same, right? So there's this slight differences between countries as to what the country's national standards body regulator thinks will be the nirvana and the best kind of quantum safe encryption mechanism that quantum computers won't be able to, uh, break, uh, hopefully, right? So that's, there's some fragmentation already.
Google has also been kind of announcing their own algorithm, right? That that's another kind of thing, a little bit of a, of a monkey wrench and, and, uh, and a machinery. Uh, hopefully these, you know, uh, you know, kind of standards, wars or encryption, standard kind of algorithm, uh, disagreements, wars and con, you know, contention will settle and, you know, the world will settle on, you know, a a handful of technologies, right?
So that's, that's all good. Um, the other aspect that is gen generally problematic is basically just, you know, the sheer, uh, kind of adoption, right? Of, of, you know, currently or, or quantum vulnerable, you know, encryption.
So this is mainly asymmetrical cryptography, RSA, uh, elliptical curve cryptography, the diffi Hellman set of methods. These are the prob the highest adopted, big largest footprint, uh, encryption mechanisms that will be, uh, you know, kind of impacted by, by, you know, quantum computers. The, the question is when, right?
I mean, everybody asks that question. It's, it's basically the next 10 years, it's about 50% right? That this will happen.
So it's not a, like, uh, there's no Y 2K like kind of deadline, right? Uh, the 1st of January, 2000, the whole world will come to an end if we don't do something that's one. And two, you know, when a, a national security agency has a quantum computer, you're not gonna be able to maybe even read about it on, you know, in, in, in the media, right?
They'll probably keep it hush hush for as long as possible. Oh, it makes you think they don't have one already. Exactly.
Yeah. Right. Exactly.
Right. So, so that is entirely possible. Um, so, so basically these are some of the challenges.
And then there's, um, you know, beyond the, the adoption, right, is, is basically the, the speed with which companies can actually implement data discovery, data prioritization, and what we call crypto agility. So crypto agility in, in essence, is basically a huge undertaking, and it really means, you know, in simple terms, moving away from the current hardcoded, you know, algorithms and, and all infrastructure software libraries, et cetera, such that the algorithms are readily replaceable and pluggable without having to rip apart the software or the library itself, right? So it's a lot more modular, you know, plugable architecture and infrastructure for cryptography that, you know, we would definitely wanna see out there and, and going there is, like I said, it's just because of the, the breadth and depth of in-house developed software and commercial off the shelf software from vendors.
That's a huge under ticket. Sure. I mean, to me it sounds like it's going to be a race to the, to the bottom, so to speak, of how fast can we upgrade, you know, so always the same story, Greenfield, those are easy.
We'll build them with quantum proof algorithms from the get go, and they're fine. It's the brownfield the dirty stuff that we, we need to update hundred percent and how fast, and there's so much of it, as you say, how fast can we update it versus how fast can the, the bad guys infiltrate it using quantum? And, and, and that's really the point, you know, when be, if it's nation states that we're talking about a China or Russia, even Iran or you know, North Korea, they may have a nor a quantum computer in order to break, you know, older algorithms, older encryption much sooner than let's say, you know, gangs, your typical cyber threat gangs, you know, I mean, getting a hold of a quantum computer is gonna be outta their touch, I would imagine for a long time.
Yes, hundred percent. And, and the speed with which these algorithms can be broken to. So it's like how soon and, and basically how fast the, the decryption will happen.
And anyway, keep in mind Alan, right, that, um, there's a lot of harvest now, decrypt later, you know? Yes, there is, right? So the, so there's a lot of, um, you know, data that's been already communicated in an encrypted, you know, Salted To talk to be, you know, basically, but encryption, encrypted ma you know, fashion over the internet, which is sensitive, difficult, you know, kind of really confidential, uh, et cetera to be protected.
And, you know, obviously everybody has been able to harvest these, these data pieces, and once the, the, the quantum computers are there, you can actually decrypt this, uh, these data pieces. So, and, and obviously, you know, there's data that is more likely to change, right? Like o over a period of, of years, right?
Like next two to three years, like stock prices will likely change. Mm-hmm. Right?
And, and, uh, you know, national headline news headlines will likely change, and there's, there's a lot of volatile, you know, data pieces, but you know, some of the highly confidential pieces of information as to how to build like a nuclear warhead, right? Or how to, you know, where the, where the silos are for, for, for ICBMs, right? These things will not change, right?
So, and it is really difficult to kind of change all, all, all this information. So, um, part of the, um, part of what will have to happen, right? To kind of curb the impact of, of, you know, decrypting the harvested.
Now the kind of data is gonna be, you know, in addition to all these problems of crypto jewelry library replacements, uh, you know, retroactive work is gonna be data decos, right? So basically disinformation and spreading, you know, conflicting updated information pieces around, you know, all these previously static kind of data pieces that will confuse the adversaries, right? So that even if they're able to decrypt that data, they'll be able to kind of not necessarily make a decision as to which, you know, kind of encrypt them then that by them decrypted data is, is the, is the truth or the most UpToDate version, right?
So there's definitely that piece there as well, which is, which is not an interesting, uh, you know, kind of conversation we have with, with the organizations. It, it, it's interesting times. Um, yeah, we were talking offline, I told you I was, we did a story on Textron Gang the other day where a company out of Australia, uh, using, uh, quantum developed a, uh, sort of like an alternative GPS obviously not using GPS using quantum instead a system for navigation 10 times, 10 x more accurate than GPS and spoof proof and, and you know, interference proof.
So, so they say, um, but again, you know, it's why we can't have nice things on the internet, right? If they're using it, the bad guys will be using it too. And yeah, That's, You know, how what you, you mentioned, you know, 50% in 10 years is what we can hope to upgrade to a quantum proof type of, uh, algorithm and so forth.
But, you know, when Forrester advising clients, where did they see the quantum adoption curve? Um, so, so basically we have, uh, uh, research on emerging technologies of which quantum computing and quantum security are part of, right? Um, you know, obviously with the current, you know, a hundred, 150, you know, non error corrected qubits, right?
It's still, you know, the early to talk about, you know, quantum computers that can do anything, um, really helpful. But the adoption of, so the appearance of quantum chips that, you know, will likely be horizontal, this horizontally scalable, right? That, that's definitely gonna be an interesting, the Microsoft, Google and other, you know, quantum chips that are, are definitely coming along, uh, we'll see horizontal scaling, right?
You know, and that that can, you know, lead to some, some advances. I mean, we've heard estimates that it takes about 10,000 error corrected qubits to be able to break the, you know, the asymmetrical encryption algorithms. Current chips are a hundred, you know, kind of non error corrected cubit.
So you take about 10 non error corrected cubit to get one, you know, error corrected qubit. So, you know, a hundred to thousand chips, right? In an array, right, is, is starting to kind of basically at, at a, at a point if you can use them in a cluster environment and in a grid, right?
To be able to kind of deploy them against, um, you know, these algorithms. So definitely, you know, the time is, is going to be, um, much, much shorter, uh, maybe than, than this 10 years, right? Or even five years because of all these advances and breakthroughs and, you know, kind of technology accelerated innovation that basically will have a positive feedback, you know, a loop impact on, on the technology.
So, so That's, you, you referenced Google and Microsoft, of course Google announced the quantum chip, I think called Willow, right? That yes. Called Willow that They're working on.
And then, you know, not to be outdone, Microsoft announced basically inventing a new state of matter for their new quantum chip that, you know, they think will have commercial application soon. Um, of course soon is relative. Uh, but Andres for people maybe who want to stay on top of what Forrester is saying in this, you know, burgeoning new era, how, you know, do you have any reports you can send them to recently?
That's All. So we, we actually have published, uh, the state of quantum security, uh, quantum security as well as the future of quantum security. Um, these are documents that we can, um, you know, definitely, you know, reference here.
And then we are also working on the architects architects guide to quantum security. That's gonna be the, the, the try as there's third piece, right? And this is, again, all part of Forrester's emerging technology, you know, report, uh, portfolio and coverage.
So, So I haven't checked yet, is there any quantum security sessions over at RSA? There are, there, there's definitely the innovation sandbox that's happening. There's a number of startup vendors that work in, you know, being able to create proxies of, of upgraded algorithms, encryption algorithms that are quantum safe and, and use them as shims between, you know, legacy vulnerable algorithms and network security, uh, PKCS and other areas, right?
So it's, the work has definitely begun, and the vendor investment and the venture capital investment has, has started to kind of prioritize the, these technologies. It, it again is, is basically the vast array of, of infrastructure that we have here, as well as, you know, the, the libraries and, and, and really commercial products, uh, that, that will have to be, uh, kind all looked at, investigated, upgraded, as well as the data, right? So, so basically, uh, discovering and prioritizing data is, is what we really tell people, you know, know what you need to protect, identify the top 10% most sensitive data and focus on the infrastructure that handles that data or stores that data or transmits that data and, and, and basically put your, uh, initial quantum save crypto agility efforts in, in, in that domain.
Absolutely. Andrew, we're about outta time. Hey, enjoy.
RSA do. Stop by and see us. Absolutely.
We'll put the link here for the, uh, Forrester reports in notes. Uh, thanks for coming on Text trunk tv. Appreciate it.
Absolutely. All right. My pleasure, Alan, keep talk.
You keep posted. Andre Char, vice President, uh, chair, vice President, principal Analyst Forster here on Tech Drug tv. We're gonna take a break.
We'll be right back.