Palo Alto Networks headquarters in Silicon Valley
– Sundry Photography/Getty Images

Palo Alto Networks, a major player in the traditional cybersecurity industry, is leaning into quantum security. The vendor has started to implement quantum-resistant capabilities across its technologies while partnering with federal agencies and other industry peers for post-quantum cryptography (PQC) migration.

The security vendor introduced its post-quantum VPNs last November. The support enables its customers to configure quantum-resistant internet key exchange protocol version 2 (IKEv2) VPNs, which is based on the RFC 8784 standard to maximize interoperability with other vendors' equipment and with future standards.

These quantum-resistant VPNs are designed to prevent attackers from recording critical encrypted key material and from decrypting the data even if they successfully steal the encrypted data.

In addition, Palo Alto Networks launched new capabilities to discover the PQC algorithms and hybrid PQC algorithms (classical and PQC algorithms combined) used within the customers’ network as part of its PAN-OS 11.1 Cosmos release last year. The capabilities aim to address the misuse of the early post-quantum technology.

Currently, no firewall can perform SSL decryption on a PQC tunnel and inspect its contents, which potentially allows malicious actors to transmit malware or steal and exfiltrate information without security administrators noticing.

With the new quantum security feature, Palo Alto Networks added PQC signature information into its firewalls to detect, block and log the use of PQC and hybrid PQC algorithms in TLSv1.3 sessions. The vendor also allows customers to add policies to their firewalls to restrict where PQC can be used.

Beyond these two moves, Palo Alto Networks aims to tightly integrate post-quantum security and upcoming PQC standards into its existing security products to help customers avoid an entirely new learning curve of implementing PQC, without the need for additional software or hardware.

Palo Alto Networks participates in federal agencies’ quantum security projects

This year, the U.S. National Institute of Standards and Technology (NIST) is expected to finalize a seven-year endeavor to publish the PQC standards. Last year, U.S. President Joe Biden signed the Quantum Computing Cybersecurity Preparedness Act into law to address the migration of federal agency systems to PQC that can better resist attacks from quantum computers.

Amidst this backdrop, Palo Alto Networks last month participated in a White-House-organized roundtable on PQC, where it joined government and industry counterparts to deliberate on quantum readiness strategies for federal agencies and critical infrastructure operators.

The vendor also joined NIST’s National Cybersecurity Center of Excellence (NCCoE) Migration to Post-Quantum Cryptography project, along with NIST, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and over 30 industry peers.

This public-private partnership aims to work on a series of NIST blueprints to “help organizations tackle common quantum security use cases, like conducting baseline cryptographic inventories, prioritizing which high-value digital assets require PQC protections, and ultimately implementing validated PQC security solutions that demonstrate core attributes, like multi-vendor interoperability, crypto-agility and alignment to open standards,” according to a blog post from Palo Alto Networks.

PQC security capabilities should be open-standards-based

Palo Alto Networks emphasized the importance of embracing comprehensive PQC security capabilities that are based on open standards, integrate with existing cybersecurity technologies to avoid overhauling existing infrastructure, support scalable and customized deployment only when the high-value asset requires PQC security, and are agile enough to rapidly change to different cryptographic algorithms with minimal disruption to operations.

The company noted many PQC technologies rely on proprietary technologies, which might lead to multivendor interoperability challenges and force organizations to manually build complex integrations. That’s why PQC security capabilities should be built on open standards, such as the cryptographic standards being developed by NIST. Without an open-standards-based, multi-vendor, end-to-end quantum secure tunnel, the system might be exposed to the “harvest now, decrypt later” attacks.