Softline IT

Quantum-resistant cryptography: When should Ukrainian businesses start preparing for the post-quantum era?

The era of post-quantum threats: Why Ukrainian businesses should act today

In the modern landscape of cyber threats, Ukrainian businesses are confronting a new challenge: the threat posed by quantum computers. While commercially available quantum computers capable of breaking modern cryptography are not yet a reality, the "store now, decrypt later" principle is already being employed by sophisticated cybercriminals and state-sponsored actors. They are collecting encrypted data today, anticipating the moment when quantum machines will enable its decryption, thereby compromising the confidentiality of information that should remain protected for decades.

For Ukrainian businesses, particularly in the context of targeted attacks on critical infrastructure, ignoring post-quantum risks can have catastrophic consequences. Data transmitted or stored today may contain trade secrets, customer personal data, financial information, or state secrets. If this data is intercepted now and decrypted in the future, it could lead to significant financial losses, reputational damage, and business disruption.

Assessing current cryptographic infrastructure: The first step towards quantum resilience

Preparation for the era of post-quantum threats begins with a thorough inventory and assessment of the current cryptographic infrastructure. This includes identifying all systems that utilize cryptography: VPN connections, TLS protocols, digital signatures, and data encryption systems. Most modern systems rely on public-key algorithms (RSA, ECC) and symmetric algorithms (AES).

IT infrastructure leaders must conduct an audit to determine which of these algorithms may be vulnerable to quantum attacks. This will help identify critical data and systems that require priority protection and migration to quantum-resistant solutions. The assessment should also include an analysis of dependencies on third-party vendors and their readiness to transition to post-quantum cryptography.

Quantum-resistant cryptography standards and solutions: An overview for Ukrainian businesses

The U.S. National Institute of Standards and Technology (NIST) is actively working on the development and standardization of quantum-resistant cryptography (PQC) algorithms. In July 2023, NIST finalized the first three PQC standards, the result of a multi-year international competition 1.

  • FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard, known as CRYSTALS-Kyber. Designed for establishing encrypted sessions and data protection.
  • FIPS 204: Module-Lattice-Based Digital Signature Standard, known as CRYSTALS-Dilithium. Provides authentication and data integrity.
  • FIPS 205: Stateless Hash-Based Digital Signature Standard, known as SPHINCS+. Used for digital signatures, offering an alternative security approach.

These standards represent different approaches to ensuring quantum resilience, primarily based on lattice problems and hash functions. The choice of a specific algorithm depends on performance requirements, key and signature sizes, and application specifics.

Transition roadmap: Strategies for implementing quantum-resistant algorithms

The transition to quantum-resistant cryptography is a complex process that requires careful planning. A phased roadmap is recommended:

  1. Assessment and pilot projects: Start with an audit, identify the most critical systems and data. Develop pilot projects to test new PQC algorithms in non-critical environments.
  2. Hybrid solutions: In the initial stages, it is advisable to implement hybrid cryptographic solutions that combine classical and quantum-resistant algorithms. This provides protection against existing threats while preparing for future quantum attacks.
  3. Phased integration: Gradually integrate new algorithms into existing systems and applications, starting with less sensitive areas. This minimizes risks and ensures business continuity.
  4. Monitoring and updates: Stay informed about the evolution of PQC standards and technologies. Be prepared to update and adapt systems.

Regulatory requirements and national context: What Ukrainian businesses need to know

The implementation of quantum-resistant cryptography in Ukraine must consider the national context and regulatory requirements in the field of cybersecurity and information protection. Existing laws, such as the Law of Ukraine “On the Fundamentals of National Resistance” and the Law of Ukraine “On Cybersecurity,” require businesses to ensure an adequate level of protection for confidential data and critical infrastructure.

IT department heads need to monitor government initiatives and recommendations regarding the implementation of post-quantum cryptography. Ensuring compliance with national standards and requirements is key to avoiding legal risks and maintaining trust with clients and partners. A proactive approach to PQC will allow Ukrainian businesses not only to protect their assets but also to meet future regulatory expectations.

Pros and cons of early PQC adoption

  • Pros: Data protection against future quantum attacks; compliance with future regulatory requirements; increased customer trust; competitive advantage.
  • Cons: Significant initial investment; complexity of integration with existing infrastructure; potential compatibility issues; need for staff training.

Softline IT assists in planning and implementing solutions in cybersecurity, IT consulting, and system integration: from current state audit to an agreed change plan.

Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.

Sources used

  1. 01csrc.nist.govPost-Quantum Cryptography
  2. 02chdtu.edu.uaПерспективи впровадження квантової криптографії в інформаційно-комунікаційних системах сектору безпеки й оборони України - Repository at ChSTU
  3. 03forklog.com.uaЩо таке постквантова криптографія (Post-Quantum Cryptography)? - ForkLog UA
Tags