The GSMA Post-Quantum Telco Network Taskforce is advocating the telecommunication industry "start planning, not panicking" for the transition to quantum-safe technology by focusing on implementing cryptographic agility and working closely with vendors and standards bodies.

Announced last September at the MWC Las Vegas 2022 event, the taskforce now has more than 45 members, Lory Thorpe, GSMA Post-Quantum Telco Networks Chairperson and Head of Telco Transformation Offerings for IBM Consulting, told SDxCentral. In addition to IBM and Vodafone as initial members, other participants include major operators in the United States, United Kingdom, Europe, Canada, and China; industry vendors like Nokia, Ericsson, and Samsung; and several security and quantum computing companies.

The taskforce aims to define post-quantum policy, regulation, and operator business processes within the telecom industry. The core objective of the taskforce is to ensure the implementation of the right requirements and standards in a timely manner to avoid being "late to the party." Thorpe explained the initial problem statement was “around how do we support the telco ecosystem to navigate the path to quantum safe."

“When you look at where cryptography is used in telco systems, it impacts basically all of the different systems. But it also then impacts all of the standards that underpin these systems as well,” she said. “We're advocating that people start planning, not panicking, but at least planning because … this isn't something that just happens overnight.”

Quantum computers pose a potential security threat in that they will be powerful enough to implement specific algorithms that can attack some of today’s cryptography, particularly public-key cryptography, Colin Soutar, managing director in Deloitte Risk & Financial Advisory, told SDxCentral in an earlier interview. One such algorithm is Shor’s algorithm, developed in 1994 by the American mathematician Peter Shor.

Another concern is an attack called “hack now, decrypt later” in which attackers try to capture encrypted data, especially in transit, and store it with the understanding that once Shor’s algorithm has been implemented, they can then decrypt that data, he said.

Post-Quantum Telco Network Impact Assessment Whitepaper

One of the first tasks for the taskforce is to publish the Post-Quantum Telco Network Impact Assessment whitepaper, an assessment of quantum-powered cyberthreats and potential solutions. The report examines dependencies and timelines for transitioning to quantum-safe technology, considering various aspects such as post-quantum cryptography (PQC) technology, standards, business processes, security, policy, and regulation.

“We tried to put this in the context of what are the business impacts because that is really the way that ultimately the operators are going to be assessing,” Thorpe said.

She emphasized the importance of planning and implementing crypto agility, which is “an intermediate step,” while waiting for standardized solutions. “We are not advocating to implement pre-standard solutions.”

The National Institute of Standards and Technology (NIST) last July revealed the first group of winners from its post-quantum cryptography competition and plans to publish its post-quantum cryptography standard by 2024. Meanwhile, several international and regional standardization institutes are also working on their own standards.

For post-quantum standards that are telco specific, the taskforce has issued liaison statements to multiple organizations, including the 3rd Generation Partnership Project (3GPP), the International Telecommunication Union (ITU), the European Telecommunications Standards Institute (ETSI), and the Internet Engineering Task Force (IETF) to align and orchestrate ongoing work in the area of quantum-safe technology, Thorpe noted.

Telcos’ Unique Role in Post-Quantum World

As a critical national infrastructure, the telecom industry, similar to the financial institutions, underpins other industries and is expected to play a unique role in the post-quantum world, Thorpe said. To continue to provide secure and reliable communication networks post-quantum, the industry requires common standards, policies, and communications across different networks and operators around the world, she added.

On the other hand, the evolution of quantum computers also brings business opportunities to the telcos.

“Enterprises are requesting, for example, quantum-safe services, so there is an opportunity for the telcos to ensure that the services that they're offering evolve them to be quantum-safe,” Thorpe said.

Examples of such services include quantum-safe VPNs, SD-WANs, connection between enterprise customers and hybrid cloud, IoT connectivity, satellite communications links, and data archive.

“These are all services that telcos have an opportunity but actually have ultimately a duty to offer to their clients because they want the services that they offer to continue to be secure,” she said.