Understanding Cryptography in the Quantum Era

Across the globe, scientists are racing to create next-generation devices known as quantum computers. These machines hold the potential to achieve feats far beyond the reach of traditional computers, such as breaching the security protocols that protect sensitive electronic data. In response, NIST is spearheading a worldwide initiative to develop protective measures against such threats through its Post-Quantum Cryptography (PQC) project. This article addresses key questions about this emerging technology and NIST’s role in advancing it.

What are post-quantum encryption algorithms?

Encryption algorithms are essential for safeguarding confidential digital information—ranging from emails to medical records and financial documents—from unauthorized access. These algorithms have successfully protected data from attacks by conventional computers for decades. However, the advent of quantum computers could potentially unravel these safeguards, putting our digital secrets at risk.

To address this challenge, encryption methods need to be developed that can withstand attacks from both today’s conventional computers and the quantum computers of the future. These advanced methods are known as post-quantum encryption algorithms.

What is quantum computing?

Quantum computing operates on principles vastly different from those of traditional computing. By exploiting the peculiarities of quantum mechanics—such as the ability of quantum bits (qubits) to exist in multiple states simultaneously—quantum computers can perform calculations that are currently impractical for classical computers.

If sufficiently advanced quantum processors are developed, they could evaluate many possible solutions to a problem at once, rapidly identifying the correct answer. This ability to simultaneously process multiple possibilities is something that conventional computers struggle with.

Why pursue quantum computing if it poses such risks?

Quantum computers have the potential to revolutionize many fields. They could facilitate breakthroughs in drug development, molecular simulations, and solving complex logistical problems like the “traveling salesman” challenge, which involves finding the most efficient route through multiple destinations.

The field of quantum computing is still emerging, with significant technical challenges to overcome before powerful quantum machines become a reality. Despite these hurdles, the potential impact of quantum computers on current encryption methods is significant enough that proactive measures are necessary.

How does current encryption work, and how might a quantum computer break it?

Today’s encryption often relies on the difficulty that conventional computers have with factoring large numbers. For instance, encryption schemes typically involve selecting two large prime numbers, multiplying them to get an even larger number, and then relying on the fact that it’s much harder to reverse the process and determine the original primes.

A sufficiently advanced quantum computer could bypass this difficulty by analyzing all possible prime factors at once, solving the problem much faster than a conventional computer. Such a quantum device could potentially crack current encryption methods in a matter of days or hours, rather than billions of years.

Why is post-quantum encryption necessary, and how do PQC algorithms function?

To protect against the eventual threats posed by quantum computers, it’s crucial to move away from existing encryption algorithms. Post-quantum encryption algorithms are designed to withstand attacks from both traditional and quantum computers by relying on mathematical problems that are difficult to solve for both types of machines.

These algorithms address two primary functions: general encryption (securing data such as passwords over networks) and digital signatures (verifying identities). NIST has selected four algorithms for initial standardization, with three based on structured lattices and one utilizing hash functions. These methods are thought to be resistant to quantum attacks.

Why is it important to develop post-quantum encryption now, even if quantum computers aren’t here yet?

Planning ahead is critical. Historically, it takes 10 to 20 years from the standardization of a new algorithm to its full integration into information systems. Given that predictions for the advent of powerful quantum computers vary, it is prudent to start developing and implementing post-quantum encryption to mitigate the risk of future threats. Data encrypted today could still be vulnerable to future quantum-based attacks through a strategy known as “harvest now, decrypt later.”

What is “harvest now, decrypt later”?

Some data remains valuable for years. Even if quantum computers can’t break current encryption methods today, capturing and storing encrypted data for future decryption with quantum technology could be advantageous. This concept underscores the urgency of adopting post-quantum encryption methods sooner rather than later.

How did NIST select and design the algorithms it is standardizing?

NIST launched the Post-Quantum Cryptography project in 2016, calling for submissions of algorithms that would be resistant to both classical and quantum attacks. After a thorough and transparent evaluation process involving global cryptographic experts, NIST has chosen several algorithms for standardization. These algorithms will be tested across various devices, including those with limited computational power, to ensure broad applicability.

Why is NIST leading the development of PQC standards?

With decades of experience in cryptographic standards, NIST plays a crucial role in developing and promoting encryption technologies. The agency’s open and collaborative approach brings together industry, government, and academic experts to create practical security solutions. Once completed, the post-quantum encryption standards will be available for free public use and adopted by federal agencies.

What steps can be taken now to prepare for the era of quantum computing?

Organizations should assess their encryption-dependent systems and prepare to update them with post-quantum algorithms. This includes informing tech departments and vendors about the upcoming changes. For more information on transitioning to post-quantum cryptography and participating in the development of guidelines, visit NIST’s National Cybersecurity Center of Excellence project page.

How does post-quantum cryptography differ from quantum cryptography?

Although the terms are similar, post-quantum cryptography and quantum cryptography serve different purposes. Post-quantum cryptography focuses on creating encryption methods resistant to quantum attacks, often using established mathematical techniques. Quantum cryptography, however, leverages principles of quantum physics to develop new forms of secure communication. Both approaches aim to protect against future threats, but they utilize different methods and technologies.

More Articles & Posts