
Undisclosed “legal issues” are preventing the US from announcing which cryptographic algorithms should be used as standard to protect data from future quantum computers. Meanwhile, security experts at Google warn that data being sent today is already at risk and that firms need to prepare themselves to adopt the new algorithms as soon they are announced.
Cryptography renders information unreadable by anyone without the correct decryption key, and modern security algorithms are based on mathematical problems deemed too hard to be cracked by even the fastest computers available today. But once a practical quantum computer is created, these algorithms will not just become easier to crack, but trivial. In theory, such a machine would immediately render emails, bank accounts and cryptocurrencies vulnerable to attack.
Because of this, since 2017, the US National Institute of Standards and Technology (NIST) has been testing 82 “post-quantum” algorithms believed to be resistant to the increased code-breaking ability of quantum computers, and whittling them down to the best few. In March this year, the group said that the final handful of winners would be announced later that month, but this deadline has since passed.
Advertisement
at NIST told 91av that the announcement is “no more than a few weeks” away and that legal issues – which he couldn’t disclose details of – were behind the delay, although he confirmed that a decision has been made behind the scenes.
But critics say a speedy announcement is vital so that companies can begin protecting themselves, and us. Researchers from Google and its spin-off company SandboxAQ, which has attracted , say that data is already at risk of so-called “store-now, decrypt-later” (SNDL) attacks, where information transmitted now is stored until a future quantum computer can be used to decrypt it. In an they add that computers, cars and large infrastructure projects are all being built today with outdated cryptography.
Google says companies need to act now, because sensitive information being sent today such as trade secrets, medical records and national security documents would still cause problems if revealed a decade from now by quantum hackers. “For those organisations that have not started integrating PQC [post-quantum cryptography] in their systems or even planning for it, we highly recommend starting their efforts now,” says the article. “The SNDL attack is already practicable, so in this context, such organisations are already late and at increasing risk.” The authors declined to be interviewed before publication.
Responding to the article, Moody says that companies should wait for an official decision before acting. “The risk of taking an algorithm that isn’t our final standardised version is you could end up with the wrong one, and then you end up with a product that isn’t interoperable with what everybody else will be [using],” he says. “And if you’re taking an algorithm that wasn’t on our shortlist, there could be security vulnerabilities.” One of the shortlisted algorithms was found to be relatively easy to circumvent with even basic hardware in March.
Moody says that although there have been large-scale cryptography upgrades in the past, there has perhaps never been one as urgent as post-quantum cryptography. “Part of that is because we don’t ever know when a quantum computer will be out there,” he says. “Someone could make a breakthrough next week. But then there’s also just the threat that you can be at risk even before a quantum computer comes along because someone could just hold on to your encrypted data and wait for a quantum computer. So the sooner you can transition, the better.”
Moody declined to elaborate on the nature of the legal issues, or which parties were involved in the delay, but says only that “there’s some lawyers involved and they’re taking a little bit longer to approve it than I would have predicted”.
Nature