Quantum
– Getty Images

At some point in the future, asymmetric cryptography may be rendered useless, as quantum computing will be able to decrypt everything. That is, unless the cryptography is using some form of quantum-safe algorithm.

But how can quantum-safe cryptography get onto existing routers and networking gear today? That's a challenge that San Mateo, Calif- based startup QuSecure set out to solve. Today QuSecure launched its QuProtect Core Security platform designed to bolster router-to-router communications on Cisco hardware against looming quantum threats.

Rather than requiring a full firmware upgrade, which can be a complicated process, QuProtect Core Security simplifies the upgrade process, providing an essential layer of protection for Cisco routers capable of running IKEv2 and Internet protocol security (IPSEC), while leveraging the innovative Cisco Secure Key Integration Protocol (SKIP).

“When we set out to build QuSsecure, we got initial funding from the U.S. government to to start working on it and what we understood at the time, especially from early customers, was that it had to be something that was or legacy compatible,” Rebecca Krauthamer, co-founder and chief product officer at QuSecure, told SDxCentral.  “Our mission in life is to protect all digital communications and enable you to have a single pane of glass to look at all your communications and where that encryption is happening.”

Bringing quantum-safe encryption to Cisco with QuProtect Core

QuProtect Core is what Krauthamer described as a great entry point for networks to enable quantum-same encryption.

Router-to-router communications often occur over networks that organizations don't fully control, making them vulnerable to the store-now-decrypt-later-threat model. In that threat model the hypothesis is that all data sent across a link is now being stored, in the hope that a future quantum computer will be able to decrypt it all. Krauthamer said that the router encryption patch has the clear benefit of providing an easy starting place for quantum-proofing, and works with existing Cisco infrastructure – making it a very compelling first use case for QuProtect Core.

The technology specifically protects router-to-router communications for Cisco devices that support the SKIP protocol. She explained that QuProtect Core uses an orchestrator as a quantum-safe encryption key distribution center to communicate with agents sitting on the Cisco routers. The orchestrator distributes encryption keys to the agents using the SKIP protocol. Admins can configure the encryption settings and key rotation frequency through a console interface.

QuSecure worked together with Cisco to help enable the QuProtect Core model using the Cisco SKIP protocol. SKIP was developed by Cisco for cryptographic key distribution. Using SKIP allows QuProtect Core to distribute encryption keys between routers in a flexible way without requiring specific router firmware/software versions, as the protocol provides forward compatibility.

Cryptographic agility is ‘key’

A critical concept in the QuSecure implementation is that of cryptographic agility.

As the final standards for post-quantum cryptography are still being determined, Krauthamer said that it's important to have algorithms that are not just based on one type of math. Rather it's critical to have multiple options.

“So that whatever we're facing, whether it's the unknown unknowns about quantum or artificial intelligence, or wherever we're going, if one of the encryption algorithms should be broken, not all of the math will be broken,” she said. “You can have redundancy of cryptographic algorithms.”