Orange
– Getty Images

Orange Business is delivering post-quantum cryptography (PQC) secured networking across its global network in a new partnership with Cisco.

Launched this week as part of Orange’s Quantum Defender suite, PQC-secured WAN services are available to Orange Business customers, with all core routing traffic protected using quantum-safe encryption, as running on Cisco 8000 Series Secure Routers, and delivered over a standard multiprotocol label switching (MPLS) network architecture. SD-WAN services, meanwhile, are targeted for commercial availability in the third quarter.

The Cisco solutions mark the first PQC services within Orange’s Quantum Defender line, which includes a Paris-exclusive quantum key distribution (QKD) network, as distributed using QKD technology from Toshiba. In an interview with SDxCentral, Frank de Jong, program director of quantum safe networks at Orange, explained why Cisco was chosen as its inaugural partner.

One reason is history: the two firms have a relationship dating back 30 years which has resulted in Orange's deployment of 400,000 Cisco routers to date. Orange was also the first global telecom operator to deploy Cisco Catalyst SD-WAN (formerly Viptela), with more than 70 SD-WAN clients currently signed to Orange Business.

“We thought their plans and their portfolio was, let's call it, ‘the most mature’ at the moment,” de Jong explained. “Of course, we wanted to do it with all our suppliers, but, you know, we do not have the resources to do everything at the same time.”

The quantum safety lead added that early field trials are underway on the SD-WAN phase of the implementation, with official software from Cisco becoming likely available in August.

“[PQC] in our flexible VPN service will most probably be available earlier. But by the end of this year, we will have post-quantum cryptography enabled into our SD-WAN service as well," de Jong said. "At this point in time, Cisco says we have the core routing software more or less ready, and they're now working on getting it implemented in the SD-WAN software.”

For the next stage of Orange’s PQC ambitions, de Jong said the company wouldn’t be waiting until year end before working on its next iteration with a new supplier.

“So as soon as one of the other suppliers comes up with a software that is, let's call it considered stable enough to run in an operational network, then we will start doing that with them as well," de Jong said.

That shortlist includes Orange partner Palo Alto Networks, who last year updated its PAN-OS firewall operating system with quantum-ready features.

“What we've done is put all of them on our list, and we had several calls with all of them, asking: ‘Where are you right now? When do you think your software is going to be ready for launch?’ We could have started with one vendor at first, for example, and then we would launch a little later in the market, and then do Cisco afterwards. Instead we said, Cisco is the first, so let's go and do that with Cisco," de Jong said of the process. “We believe post-quantum security is so important that we wanted to get to the market as quickly as possible.”

Hybrids and harvests

The exec also illustrated that SD-WAN clients still early in their Orange contracts will have the chance to migrate their infrastructure to the new setup now as opposed to waiting for contract renewal, or vice versa, with contract fees to see a modest price increase.

“Because they may or may not require new hardware to be installed on the routers, as PQC algorithms are much more processor intensive," de Jong explained. "We are expecting that every new customer, every new network that we will be deploying, will most probably be already PQC-enabled. I cannot see a reason why you would choose a non-PQC enabled network if you were to deploy something new.”

In the view of Orange Business, customers need to act now to prevent harvest-now, decrypt-later attacks, where data intercepted today could be decrypted in the future once quantum computing becomes readily available. That harvesting threat related to the so-called Q-Day event has been cited as the impetus for PQC solutions from the likes of Citrix, Nokia, and Fortinet.

Cisco itself has been working on prototype backbones for networked quantum data centers, such as Quantum Alert, a demo that uses entangled photons to detect eavesdropping attempts. It employs quantum networking to create a communication channel where any interception becomes immediately detectable because of the delicate nature of quantum states.

That solution sees Cisco following a hybrid approach of combining classical and post-quantum cryptography, a standard in the industry despite the likes of the National Security Agency (NSA) advocating enterprises to adopt pure PQC for stronger security. This contrasts with hybrid algorithms mandated by the U.S. National Institute of Standards and Technology (NIST) for U.S. agencies to adopt by 2035 in order to meet minimum safety regulations ahead of Q-Day, which is likely to occur around the same time.

When asked if such conflicting advice is confusing to Orange’s European-centric customer base, de Jong remarked the entire discussion about QKD, PQC, and the different kinds of algorithms in the PQC stack is “very confusing” to clients.

“But what I see is that most of our customers that come to us to say, ‘Okay, I trust you guys to make the right selection in all of this,’” de Jong said.