Three U.S. national cyber agencies this week published a joint factsheet to encourage organizations to plan early for the migration to post-quantum cryptography (PQC) standards, followed by the National Institute of Standards and Technology (NIST) releasing three draft PQC standards.
The development of building quantum computers has been steady over the past few years, NIST noted in the release. “The security of many commonly used public-key cryptosystems would be at risk if large-scale quantum computers were ever realized,” the institute warned. “In particular, this would include key-establishment schemes and digital signatures that are based on integer factorization and discrete logarithms (both over finite fields and elliptic curves).”
To address the risks, NIST initiated the public process of selecting quantum-resistant public-key cryptographic algorithms for standardization in 2016. Out of 82 submissions received, 26 were shortlisted for the second round in 2019 based on rigorous evaluation.
In the summer of 2022, NIST announced the selection of four schemes for standardization:
- CRYSTALS–KYBER for general encryption, used to protect information exchanged across a public network
- CRYSTALS–Dilithium, FALCON and SPHINCS+ for digital signatures, often used for identity authentication during a digital transaction or to sign a document remotely
The first three algorithms are based on a family of math problems called structured lattices, while SPHINCS+ uses hash functions as a backup to avoid relying only on the security of lattices for signatures, NIST noted.
Based on these algorithms, the institute is currently requesting public comments on three draft PQC standards, including the following:
- Module-Lattice-based Key-Encapsulation Mechanism Standard (ML-KEM), derived from CRYSTALS-Kyber (FIPS 203)
- Module-Lattice-based Digital Signature Standard (ML-DSA), derived from CRYSTALS-Dilithium (FIPS 204)
- Stateless Hash-Based Digital Signature Standard (SLH-DSA), derived from SPHINCS+ (FIPS 205)
A fourth standard derived from Falcon is expected to be released soon, according to the institute. “In the future, NIST intends to develop a FIPS specifying a digital signature algorithm derived from FALCON as an additional alternative to these standards.”
NIST expects to finalize its PQC standards by 2024. Quantum computer experts noted the draft release is a turning point as these standards are expected to become the global benchmark for quantum-resistant security measures.
“Previously, a key barrier to adoption and migration to post-quantum cryptography has been confidence in exactly how and when the new algorithms will be finalized,” PQShield Founder and CEO Ali El Kaafarani said. “NIST’s new draft standards provide this assurance and a framework that allows everyone to move forward.”
A unified call for quantum readinessU.S. President Joe Biden signed the Quantum Computing Cybersecurity Preparedness Act into law this January to address the migration of federal agency systems to PQC that can better resist attacks from quantum computers.
To help agencies and other public and private organizations prepare for the post-quantum world, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and NIST jointly released a factsheet this week, entitled "Quantum-Readiness: Migration to Post-Quantum Cryptography (PQC)."
This document focuses on educating organizations — especially those that support critical infrastructure—about the risks and impacts of quantum capabilities.
Cyber agencies noted early planning for PQC migration is necessary as threat actors could conduct an attack called “hack now, decrypt later” or “catch now, break later” in which attackers try to capture encrypted data, especially in transit, and store it with the understanding that once specific algorithms that can attack some of today’s cryptography have been implemented, they can then decrypt that data.
Governmental agencies and corporations are urged to follow these five steps:
- Establish a quantum-readiness roadmap by first establishing a project management team to plan and scope the organization’s migration to PQC.
- Conduct an inventory of existing cryptographic systems and assets.
- Create a phased migration plan that prioritizes sensitive and mission-critical assets.
- Engage with technology vendors to discuss post-quantum strategies.
- Understand and assess how vendors in their supply chain will be migrating to PQC.
“Post-quantum cryptography is about proactively developing and building capabilities to secure critical information and systems from being compromised through the use of quantum computers,” NSA Cybersecurity Director Rob Joyce said in a statement. “The transition to a secured quantum computing era is a long-term intensive community effort that will require extensive collaboration between government and industry. The key is to be on this journey today and not wait until the last minute.”
Comments