Quantum computing experts expect China and Russia to select encryption algorithms for post-quantum cryptography (PQC) standards based on the same mathematical problems as the U.S. and other western countries, while choosing a scheme that is slightly different.
The constant threat that quantum computing poses on classic cryptography is a global problem, Michael Osborne, CTO of IBM Quantum Safe noted during a recent virtual roundtable. Based on his observations, “the algorithms that [will be] standardized in China or in Russia or in wherever that they have been based on the same mathematical problems that quantum computers threaten.”
NXP cryptography researcher Joppe Bos said he expects other countries’ PQC selection will mirror what they did for classical cryptography. This model is that they defined different elliptic curves rather than the one standardized by the National Institute of Standards and Technology (NIST), whose primary focus is the U.S. government. “That is just a sign that they wanted to have something for themselves, and it's all based on the same heart mathematical problem,” Bos said.
Bos expects China to standardize PQC algorithms that are based on “very, very similar problems from exactly the same families” that are being considered for standardization by NIST.
“[Such as] lattice-based crypto or hash-based schemes, these are exactly the schemes these countries are looking at as well,” he added. “That gives a lot of confidence, fortunately, in the security of the schemes, but they might choose a scheme which is just slightly different or with different parameters.”
Lattice-based PQC is built on a family of math problems called structured lattices and Dustin Moody, post-quantum cryptography project lead at NIST, identified it as the best family that was being evaluated during the institution’s selection process. The institution also selected algorithms that use hash functions as a backup to avoid relying only on the security of lattices for signatures, NIST noted.
“An observation with China is actually they selected derivatives of at least two of the algorithms that were also selected. by NIST as their standard for cryptography in China. So essentially, they're aligning with the protection that we're also aligning with,” Osborne said. “It means they're also cognizant of the threat and also comfortable with the technology selections, or the mathematical problems that we're comfortable with.”
The Chinese Association for Cryptologic Research (CACR) held a post-quantum cryptography competition and announced its results in early 2020. The top winners were lattice-based Aigi-sig, LAC.PKE, and Aigis-enc. The last one is based on the asymmetrical learning with errors (LWE) problem.
PQC Standardization Progress: US vs. ChinaNIST initiated its post-quantum cryptography competition in 2016, announced the first group of winners in July of this year, and aimed to publish its PQC standard by 2024.
Meanwhile, CACR sent out a notice for its competition in 2018, and named the winners in 2020. China reportedly plans to start the PQC standardization process around this year and expects to begin the commercial migration around 2025.
“China’s certainly spending a lot of money they're investing a lot to develop their quantum technologies to build a quantum computer or to do other very interesting applications with quantum technologies. So the U.S. is definitely aware of that. China's certainly doing all they can to advance the state of the art for their own purposes. And that's another reason we need to have this quantum-resistant cryptography in place to protect against that,” Moody said during the virtual roundtable.
Will Non-Western Countries Adopt International PQC Standards?Laura Thomas, former CIA case officer and current chief of staff and VP of strategic initiatives at ColdQuanta, told SDxCentral that non-western countries are more likely to follow international standards set by the International Organization for Standardization (ISO) or the Internet Engineering Task Force (IETF).
“And if they do develop the standards outside of ISO or IETF, they're not going to be able to interact seamlessly with the rest of the world, and that will have to be a consideration that they make,” Thomas said.
On the other hand, NIST works with those international institutions. “To a large degree, these other standards organizations were very happy with what we were doing at NIST and wanted to wait for our process to finish before they selected algorithms themselves,” NIST's Moody said in an earlier interview, adding he expects NIST’s selections will be adopted by the international standards institutions and they likely will add other algorithms from other countries.
Comments