Navigating an era of cryptographic uncertainty

A secure future might be the gift of true randomness 

    • Quantum computers now have a 50 per cent probability of breaking highly secure RSA-2048 keys by 2031.
    • Quantum computers now have a 50 per cent probability of breaking highly secure RSA-2048 keys by 2031. PHOTO: REUTERS
    Published Tue, Jun 27, 2023 · 05:50 AM

    THE emergence of Shor’s algorithm in 1994 might have suggested that in due course, the two main public encryption protocols – RSA and Diffie-Hellman – can be broken by powerful quantum computers. It’s been three decades since, and here we are at the brink of reality, where quantum computers have a 50 per cent probability of breaking highly secure RSA-2048 keys by 2031.

    Singapore has made strides in securing its digital infrastructure as the new partnership between Infocomm and Media Development Authority and telcos aims to revamp the existing network infrastructure to fend off mathematically sophisticated quantum attacks. The need for speed in execution and innovation in these technologies is clear – and urgent.

    Between smart devices, wearables, connected cars, smart homes, and industrial Internet sensors, it is expected that the volume of connected devices will reach 30 billion globally by 2030, according to Statista. The International Data Corporation predicts a deluge of resulting data creation and replication, reaching 181 zettabytes by 2025, from 64 zettabytes in 2020. All that data will need to be secured while racing against time, where the current public encryption protocols risk being breakable in less than a decade.

    The arrival of commercial quantum computers powerful enough to break public-key encryption will significantly threaten national security, financial stability, healthcare, and private data. A large-scale quantum computer could allow for the decryption of most common cybersecurity protocols and all previously recorded traffic, putting at risk our economic prosperity, national security, and much of our daily lives as we know it.

    This begs the question: Will the proposed quantum-resistant network protect Singapore’s digital infrastructure against quantum threats alone?

    The classical approach to this problem, described as post-quantum cryptography, uses classical protocols designed to be quantum attack-proof, replacing weak protocols such as RSA. However, to withstand the test of time, a combination of quantum networks-secure channels transmitting quantum information and quantum random number generators (QRNGs), which generate genuinely random keys to secure classical encryption, is essential.

    Build with a vision for decades

    Singapore is already witnessing the first wave of quantum security driven by the Singapore government’s funding and potential applications in critical sectors. The industry is also seeing a precipitation of adoption by private companies and growing penetration of QRNG chips in Internet of Things infrastructure and devices.

    As we head into 2030 and beyond, the sheer quantum computing power will need to protect newer or improved technologies such as repeaters, memories, and better error-correction algorithms, which minimise challenges such as signal losses or the ability to enable deployment across a broad network.

    All good things must end, and so does more than four decades of stability in the hands of RSA and Diffie-Hellman. As post-quantum cryptography and quantum communications replace today’s protocols, governments, businesses, and investors must gear up and prepare for a future that envisions a new level of secure data transfer.

    Realistically, quantum security is an additional form of security that must work alongside the current infrastructure. Organisations must consider how they will deploy, manage, and maintain conventional and post-quantum security on their systems. By understanding the specific secure-communications needs of each sector and the corresponding maturity of the technologies deployed, governments and businesses can stay ahead of the coming waves of secure quantum-communications adoption.

    The writer is VP and regional chief security officer, Asia-Pacific and Japan, at Palo Alto Networks