Defending Encryption: Quantum XChange at Cisco Live Amsterdam
Back to Blogs & Podcasts
08 Mar 2024
This is the third and final installment of the blog series sharing Quantum Xchange’s responses to the White House Roundtable on PQC.
On Jan. 26, 2024, Quantum Xchange joined the White House Office of Management and Budget (OMB), the White House Office of Science and Technology Policy (OSTP), and other members of the intergovernmental PQC Migration Working Group to discuss, debate, and prepare formal guidance for government agencies as they begin their efforts to replace legacy encryption with post-quantum cryptography (PQC).
Q: What additional costs should be anticipated as part of the PQC migration beyond what agencies already budget for as part of standard activities such as periodic technology refreshes?The migration to PQC is expected to go beyond the scope of standard technology refreshes, introducing new dimensions in cryptographic management and compliance that require investment in processes, staffing, and regulatory adjustments.
These changes represent a shift in how cryptographic risks are managed and will likely require a corresponding allocation of resources to effectively address these emerging challenges.
Adapting these frameworks to include cryptography will involve collecting and tracking data, as well as setting and implementing new business processes around cryptographic management. These changes are likely to incur additional costs.
Q: How can the PQC migration process be used to enhance cryptographic agility across a network?The enhancement of cryptographic agility during the PQC migration process can be achieved by mandating it through a combination of legislative action and standards development. Key aspects include:
Additionally, control over cryptographic agility requires support from vendors. This implies that vendors must be capable of providing solutions that are flexible and adaptable to evolving cryptographic standards.
The Forbes article, Enterprise Crypto-Agility Requires Policy Management, further emphasizes the importance of policy management in achieving crypto-agility. This piece explores the detailed strategies and considerations necessary for effective policy management in the context of cryptographic agility.
Overall, enhancing cryptographic agility during the PQC migration process involves a strategic blend of legislative action, process development, vendor collaboration, and the adoption of universal standards. This approach ensures a coordinated and comprehensive upgrade to cryptographic systems that are resilient, adaptable, and prepared for future challenges.
The mathematical problems underlying the current PQC candidates have not been extensively studied, and it is important to remember that in complex mathematics, breakthroughs and understandings can take centuries.
It is only a matter of time before new encryption standards are found to be weakened or broken, as has been observed with SIKE and KyberSlash.
Q: What topics have not been covered in these questions/the roundtable regarding PQC migration that should be taken into account?The migration to PQC requires not just a technological shift but also a paradigm shift in how cryptographic methods are developed, deployed, and managed.
The industry needs to be prepared for the rapid evolution and potential vulnerabilities of these new methods, and adopt strategies that incorporate diversity, agility, and a balance between proven and emerging technologies.
This includes mixing asymmetric key technology with symmetric key technology and transmitting keys through out-of-band channels. Developing metrics and benchmarks to measure the diversification of cryptographic strategies is also crucial.
The industry must adapt by complementing and overlaying proven cryptographic methods with new ones, rather than outright replacement, fully expecting that new methods may be broken or compromised.
Don’t miss part 1 and part 2 of this informative series.
Explore Solutions with CipherInsights
[site_pqc_posts]
Have one of our experts show you how Phio TX protects your organization from threats today and the quantum future.
Request Request
a a
demo demo