Daiwa and Deloitte break PQC implementation into manageable steps
PQC implementation becomes more manageable when organizations treat it as a migration program rather than a physics problem. As the post-quantum cryptography transition moves from discussion to implementation, organizations can test what is ready while planning around unresolved dependencies.
Even straightforward technical changes can take years once budgets, products and governance enter the picture. Practical tests and staged planning can narrow the problem and help demystify the process, according to Colin Soutar (pictured, center), managing director at Deloitte Touche Tohmatsu Ltd.
“I would take the word ‘quantum’ out of it,” he said. “I think that the misconception is that one needs to be an expert [or] have a background in physics to understand what’s needed here. There is a threat out there in the future … and the steps to mitigate that are generally known. Working through it again is relatively straightforward, albeit large and complex.”
Soutar and Sadaaki Yamazaki (right), senior security specialist for the Digital Solution R&D Department at Daiwa Institute of Research Ltd., spoke with DigiCert Inc.’s Tim Hollebeek (left), vice president of industry standards, at DigiCert’s World Quantum Readiness Day, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed ways to reduce technical uncertainty without understating the scale of enterprise migration. (* Disclosure below.)
PQC implementation starts with what is ready
Daiwa tested a hybrid approach in a development environment for Daiwa Securities’ online trading system. Its proof of concept used a post-quantum-enabled load balancer to measure Transport Layer Security performance under realistic conditions, Yamazaki noted.
“In our measurements, the average TLS handshake time increased by approximately 1.2 milliseconds,” he said. “In our environment, which operates in a high-bandwidth data center, the impact was negligible. However, PQC increased both message sizes and packet counts. Organizations operating over wireless networks or constrained bandwidth environments should carefully validate the impact in their own environments.”
Technical readiness also varies by cryptographic function. Federal Information Processing Standard 203, issued by the National Institute of Standards and Technology, is one building block in the phased approach Yamazaki described.
“We understand the attraction of doing everything at once, but key establishment and digital signature are at different stages of readiness,” he said. “For key establishment, ML-KEM has already been standardized, and hybrid key exchange such as X25519MLKEM768 is becoming available in products and platforms. This is also the part of TLS that can address the ‘harvest now, decrypt later’ risk, so there is a security benefit to adopting it earlier.”
Enterprise scale shifts the challenge to governance
At enterprise scale, PQC implementation also becomes a prioritization challenge. A complete inventory remains the goal, but starting there can delay progress when systems and ownership are widely distributed, according to Soutar.
“About two years ago, we actually started advocating not to do a full discovery in the first instance,” he said. “Ultimately, you will build towards that, but we think it’s much more important to iteratively tackle this, show some results as well [and] start to do discovery around your most critical assets or systems.”
Enterprise public key infrastructure extends across certificates, authentication, code signing, application programming interfaces, virtual private networks and cloud services. Those uses span infrastructure and applications managed by different parts of an organization, according to Yamazaki.
“The difficult part is not replacing a single algorithm,” he said. “The difficult part is identifying where cryptography is used, understanding dependencies and coordinating migration across the organization. From our perspective, technology is only part of the challenge. Governance and cryptographic inventory are likely to be the larger challenges.”
Register for free to watch the complete video interview, part of SiliconANGLE’s and theCUBE Research’s coverage of DigiCert’s World Quantum Readiness Day.
(* Disclosure: TheCUBE is a paid media partner for DigiCert’s World Quantum Readiness Day. Neither DigiCert, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Photo: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.