What is Quantum Safe?
Summary
Introduction to Quantum Safe Cryptography
As quantum computers become more and more powerful, they have the potential to completely reshape the cybersecurity landscape. In this video, we're going to talk about what it means to become quantum safe and discuss terms like quantum safe cryptography. But before we dive into that, let's first take some time to do a quick recap on classical cryptography.
Classical Cryptography Recap
Most of our modern encryption protocols are based on a combination of symmetric and asymmetric encryption. Let's start by talking about symmetric encryption. We're going to use a classic example of Alice, who wants to send a secure message to her friend Bob. In order to do this, she first needs to encrypt her message, which she can do using a secret key. She can then securely send her message to Bob, who can decrypt that message using the same secret key.
Asymmetric Encryption Explained
Asymmetric encryption works in a very similar way, but instead of Alice and Bob using the same secret key, Alice will have a public key and Bob will have a private key. These keys are different; one is mathematically derived from the other. In a nutshell, anyone could possibly access that public key, but only the private key can be used to decrypt the message. Most of our most popular cryptographic algorithms include examples such as RSA, Diffie-Hellman, and Elliptic Curve Cryptography. These are all asymmetric encryption algorithms, and they are based on three different types of mathematical problems: factorization, discrete logarithm, and elliptic curve discrete logarithm.
Quantum Computing Threat to Cryptography
These cryptographic algorithms work so well because the mathematical problems they're based on are very difficult to solve, but their solutions are very computationally easy to check. For example, if we wanted to crack RSA, we would need to factorize a 2048-bit integer, which serves as the public key. Using a classical computer, this could potentially take millions of years, but quantum computers are different. When quantum computers reach full maturity, they have the potential to solve factorization and discrete logarithm problems much, much faster.
Introduction to Quantum Safe Algorithms
Instead of relying on these classical cryptographic algorithms that have served us well up until now, we need to start thinking about quantum safe cryptographic algorithms. Quantum safe algorithms are based on mathematical problems that neither classical nor quantum computers can solve efficiently. They're normally based on geometric problems rather than numerical ones. One example is mathematical problems that are based on lattices.
Understanding Lattices
Let's have a quick review on lattices. Lattices could be very simple—just a grid of points with lines in between them that can represent vectors. This is just a simple two-dimensional lattice, but lattices could have many more dimensions, and they can also vary in size. They could even be of infinite size. We can use a range of different lattice-based problems to develop quantum safe cryptographic algorithms.
Short Vector Problem Example
One example is the short vector problem. The short vector problem works like this: let's say we have a very small, simple lattice like this, and we can draw some lines in between them that represent the vectors between each of the points. The way that I've drawn it out here is what is known as a short basis. But I could draw this exact same lattice in a slightly different way, and you can see here how the vectors in between each of the points are much longer. We would call this a long basis. The short vector problem is as follows: let's say we have a point in the middle of this lattice, or if we were representing it, this could look like that. To solve this problem, we want to find the closest points to A on this lattice. If we're given a short basis, it can be quite easy to see where the shortest vectors are between the points. But if we're only given a long basis, this becomes much more complicated. You can imagine this problem would get even more difficult if we increase the size of the lattice and add many more dimensions. This is quite a simple example, but it really highlights the key point of lattice-based problems, which is that the larger and more complex the lattice, the more difficult it is to solve mathematical problems based on them, and the more difficult it would be to crack algorithms that are based on those problems.
NIST Standards and IBM's Role
It might still be many years before quantum computers can crack algorithms like RSA, but it also takes a really long time for teams and organizations to adopt and deploy new cryptographic standards. The National Institute for Standards and Technology says it can take anywhere from 5 to 15 years to implement new cryptographic standards. As you can imagine, it takes time to train developers and cybersecurity professionals, as well as to implement the new standards. But NIST has been researching different standards already since 2016. In July of 2022, they identified four different standards that organizations can start looking into to become quantum safe. Three of those were developed by IBM. They include the CRYSTALS-Dilithium digital signature algorithm, as well as the Falcon digital signature algorithm, and lastly, the CRYSTALS-Kyber public key encryption algorithm. IBM is already helping organizations become quantum safe. In 2022, as well as announcing these cryptographic standards from NIST, they also launched the first quantum safe system with the launch of their Z16 platform. They also offer the IBM Quantum Safe Program, which aims to educate and provide strategic guidance to organizations that are looking to become quantum safe, with individualized programs to help organizations better understand their exposure to cryptographic attacks. If you and your team or your organization are ready to start becoming quantum safe, check out the links in the description to all the things that I mentioned in this video. Remember to subscribe, and leave any questions that you have in the comments. I hope you found this content helpful, and thank you very much for watching.