In an open and collaborative move to address cryptographic security challenges posed by quantum computing, the Linux Foundation announced the launch of the Post-Quantum Cryptography Alliance (PQCA). The founding members of this initiative include Amazon Web Services (AWS), Cisco, IBM, IntellectEU, NVIDIA, QuSecure, SandboxAQ and the University of Waterloo.

Quantum computing holds the promise of solving complex problems much faster than current technologies, while its advancement poses a potential threat to existing cryptographic systems. To address this, PQCA partners with the founding members to drive the advancement and adoption of post-quantum cryptography (PQC).

“Open and collaborative initiatives addressing post-quantum cryptography will help to accelerate innovation through collective expertise, ensure the broad adoption of secure standards, and enhance global digital security against quantum threats,” Douglas Stebila, associate professor of cryptography in the Department of Combinatorics and Optimization at the University of Waterloo, told SDxCentral. “By pooling resources and knowledge, we foster an environment of transparency and trust, essential for developing robust, quantum-resistant cryptographic solutions.”

The alliance brings together industry leaders, researchers and developers to produce high-assurance software implementations of standardized algorithms and support the continued development and standardization of new post-quantum algorithms.

PQCA advocates for open standards and interoperability frameworks with the PQC community by encouraging vendors to adopt standard protocols and interfaces for compatibility, Stebila said.

“The alliance will promote interoperability testing and certification programs to ensure that PQC implementations from different vendors can seamlessly interoperate and serve as a platform for knowledge sharing and best practices, enabling vendors to exchange insights and collaborate on interoperability challenges,” he added.

In addition, PQCA also seeks to be the central foundation to support organizations and open source projects aligning with the U.S. National Security Agency (NSA’) Cybersecurity Advisory concerning the Commercial National Security Algorithm Suite 2.0.

PQCA supports post-quantum cryptography transitions across industries

The post-quantum work over the past decade by PQCA's founding members, including industry leaders, technology giants and academic institutions, laid the foundation for the alliance.

Several members have played major roles in the PQC standardization to date, including as co-authors of the first four algorithms selected in the National institute of standards and technology (NIST) Post-Quantum Cryptography Standardization Project — CRYSTALS-Kyber, CRYSTALS-Dilithium, Falcon and SPHINCS+, according to Stebila.

“Moving forward, founding members of the PQCA will engage in various technical projects to achieve its objectives, including developing open source software for evaluating, prototyping and deploying new post-quantum algorithms,” he said. “By providing these publicly available software implementations, the foundation seeks to facilitate the practical adoption of post-quantum cryptography across different industries worldwide.”

Moreover, PQCA will collaborate with federal government agencies and NIST to advance the adoption of PQC and contribute to standardization efforts. “Active engagement in the standardization process with NIST will enable coalition members to contribute their technical expertise and industry insights to develop robust, interoperable PQC standards,” Stebila said.

PQCA will also team up with MITRE’s Post-Quantum Cryptography Coalition (PQCC) to drive progress toward the understanding and adoption of PQC technologies, he added.

The Open Quantum Safe project

One of the PQCA's launch projects, the Open Quantum Safe (OQS) project, is one of the leading open-source software projects devoted to PQC.

Founded at the University of Waterloo in 2014, the project is designed to support the NIST PQC standardization project, emphasize research and evaluation over immediate production use and advocate for hybrid cryptography as a transitional security measure, according to Stebila.

“The Open Quantum Safe project is an initiative focused on developing and prototyping quantum-resistant cryptography, featuring open-source libraries for cryptographic algorithms and prototype integrations with existing applications,” he said. “The project offers prebuilt, executable software packages for experimentation and developer software for application development, and aims to provide solutions for high-security environments as the field matures.”