{"id":115,"date":"2024-06-17T10:31:30","date_gmt":"2024-06-17T05:01:30","guid":{"rendered":"https:\/\/musikaar.com\/blog\/?p=115"},"modified":"2024-07-23T10:34:30","modified_gmt":"2024-07-23T05:04:30","slug":"post-quantum-cryptography","status":"publish","type":"post","link":"https:\/\/musikaar.com\/blog\/cybersecurity\/post-quantum-cryptography\/","title":{"rendered":"Post-Quantum Cryptography"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">Challenge<\/h1>\n\n\n\n<p>Keeping information safe is one of the biggest challenges we face today and one of the tools we have at our disposal is encryption. Traditionally, industry and individuals have relied upon encryption algorithms like RSA, DSA and ECC. But these algorithms relied upon the assumptions that it would take enormous compute power to calculate all the variables needed to defeat the encryption. However, with advent of Quantum Computers it is matter of time before traditional cryptographic algorithms are torn apart and their encryption rendered meaningless. And that begs the question what this future would hold for enterprises that are fighting ever growing threats to keep information safe.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">PQC (Post Quantum Cryptography) Readiness<\/h1>\n\n\n\n<p>Government agencies like NIST, ENISA &amp; self-governed bodies like Post-Quantum Cryptography Alliance have acknowledged the problem. They are also working on proposing new cryptographic solutions and algorithm(s) that are ready for Post Quantum era. Any proposed algorithm(s) must satisfy two criteria: a) it must be quantum-resistant b) current devices and infrastructure must be able to use those new algorithm(s) without the need for increase in compute power or time.\u00a0\u00a0<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Where do we stand today?<\/h1>\n\n\n\n<p>NIST already working on various new methods which in theory can withstand Quantum Computers. Here are those methods Module-Lattice-Based Key-Encapsulation Mechanism Standard, Module-Lattice-Based Digital Signature Standard, Stateless Hash-Based Digital Signature Standard, We Need to understand that the this is still in progress, it will take couple of years to find better Solution.&nbsp;<\/p>\n\n\n\n<p>There is broad consensus that industries will have to work together to find practical solutions, PQCA (Post Quantum Computing Alliance) is testament to that. PQCA is founded by Linux Foundation, which is led by industry leaders like Google, IBM, AWS, Cisco etc.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">What can we do now?<\/h1>\n\n\n\n<p>Given that this is a completely new era of computing it stands to reason that these solutions will take time to materialize. Naturally, one might ask: Is there anything that an average organization can do in mean time to prepare for this Post Quantum Cryptography world?&nbsp;&nbsp;<\/p>\n\n\n\n<p>The surprising answer is \u2013 Yes! Organizations must find out what information is being encrypted and how is it encrypted. Current compliance mandates which focus on information security require that valuable information is being encrypted but there was never a need to build an inventory. This would change going forward. We will see different solutions emerge over next few years that focus on discovering and cataloguing the encrypted information.<\/p>\n\n\n\n<p>As its already clear PQC is in development, we don&#8217;t know what future holds, one thing we are sure is to get ready for adoption for new Post Cryptography Algorithms. What we can do today is Inventory certificate by algorithm type, country of origin and detect if certificates are not expired. Above gathered info will help us analyze, prioritize and mitigate any current vulnerability, also help us plan for future. <strong>Musikaar <\/strong>has core expertise in security domain, and we are fortunate to have exposure to one of the aspects of PQC readiness. Our engineers are helping teams build and validate the new capabilities in existing endpoint management solutions. These solutions scan, analyze and catalogue cryptography data scattered across the enterprise infrastructure.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">References<\/h4>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.enisa.europa.eu\/news\/enisa-news\/post-quantum-cryptography-anticipating-threats-and-preparing-the-future\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.enisa.europa.eu\/news\/enisa-news\/post-quantum-cryptography-anticipating-threats-and-preparing-the-future<\/a>&nbsp;&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.linuxfoundation.org\/press\/announcing-the-post-quantum-cryptography-alliance-pqca\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.linuxfoundation.org\/press\/announcing-the-post-quantum-cryptography-alliance-pqca<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/NIST_Post-Quantum_Cryptography_Standardization\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/en.wikipedia.org\/wiki\/NIST_Post-Quantum_Cryptography_Standardization<\/a>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Challenge Keeping information safe is one of the biggest challenges we face today and one of the tools we have at our disposal is encryption. Traditionally, industry and individuals have relied upon encryption algorithms like RSA, DSA and ECC. But&#8230; <a class=\"more-link\" href=\"https:\/\/musikaar.com\/blog\/cybersecurity\/post-quantum-cryptography\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"[]"},"categories":[17],"tags":[15,12],"class_list":["post-115","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","tag-cybersecurity","tag-quality-assurance"],"_links":{"self":[{"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/posts\/115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/comments?post=115"}],"version-history":[{"count":8,"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/posts\/115\/revisions"}],"predecessor-version":[{"id":124,"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/posts\/115\/revisions\/124"}],"wp:attachment":[{"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/media?parent=115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/categories?post=115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/musikaar.com\/blog\/wp-json\/wp\/v2\/tags?post=115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}