Implementing Post-Quantum Algorithms in IT Infrastructure

Explore top LinkedIn content from expert professionals.

Summary

Implementing post-quantum algorithms in IT infrastructure means updating encryption methods to protect data from quantum computers, which could break current security systems. Post-quantum algorithms are new cryptographic techniques designed to withstand future quantum attacks, ensuring sensitive information stays secure.

  • Inventory your assets: Start by mapping all the hardware, software, and cryptographic protocols in your infrastructure to identify what needs upgrading or replacing.
  • Plan phased migrations: Build a roadmap to pilot and gradually roll out post-quantum solutions, prioritizing systems that safeguard long-lived or critical data.
  • Engage with vendors: Reach out to technology partners about their post-quantum readiness and demand clear timelines for support, so your supply chain isn’t left vulnerable.
Summarized by AI based on LinkedIn member posts
  • View profile for Dr. Robert Campbell, FBBA

    IBM Quantum-Safe Executive | PQC, AI Security & Federal Cryptographic Modernization | OpenAI Trusted Access for Cyber (TAC) Participant | Daybreak Blue Access | Former Naval Cryptology Officer | FBBA

    29,550 followers

    🚨 NEW PEER-REVIEWED RESEARCH: PQC Migration Timelines Excited to share my latest paper published in MDPI Computers: "Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks." The transition to Post-Quantum Cryptography (PQC) represents a watershed moment in the history of our digital civilization. Organizations planning for a 3-5 year "upgrade" will fail. The reality is a 10-15-year systemic transformation. Key Contributions: 📊 Realistic Timeline Estimates by Enterprise Size: Small (≤500 employees): 5-7 years Medium (500-5K): 8-12 years Large (>5K): 12-15+ years ⚠️ Critical Finding: With FTQC expected 2028-2033, large enterprises face a 3-5 year vulnerability window—migration may not complete before quantum computers break RSA/ECC. 🔬 Novel Framework Analysis: Causal dependency mapping (HSM certification, partner coordination as critical paths) "Zombie algorithm" maintenance overhead quantified (20-40%) Zero Trust Architecture implications for PQC 💡 Practical Guidance: Crypto-agility frameworks and phased migration strategies for immediate action. Strategic Recommendations for Leadership: 1. Prioritize by Data Value, Not System Criticality: Invert the traditional triage model. Systems protecting long-lived data (IP, PII, Secrets) must migrate first, regardless of their operational uptime criticality, to mitigate SNDL. 2. Fund the "Invisible" Infrastructure: Budget immediately for the expansion of PKI repositories, bandwidth upgrades, and HSM replacements. These are long-lead items that cannot be rushed. 3. Establish a Crypto-Competency Center: Do not rely solely on generalist security staff. Invest in specialized training or retain dedicated PQC counsel to navigate the mathematical and implementation nuances. The talent shortage will only worsen. 4. Demand Vendor Roadmaps: Contractual language must shift. Procurement should require vendors to provide binding roadmaps for PQC support. "We are working on it" is no longer an acceptable answer for critical supply chain partners. 5. Embrace Hybridity: Accept that the future is hybrid. Design architectures that can support dual-stack cryptography indefinitely, viewing it not as a temporary bridge but as a long-term operational state. 6. Implement Automated Discovery: You cannot migrate what you cannot see. Deploy automated cryptographic discovery tools to continuously map the cryptographic posture of the estate, identifying shadow IT and legacy instances that manual surveys miss. The quantum clock is ticking. Start planning NOW. https://lnkd.in/eHZBD-5Y 📄 DOI: https://lnkd.in/ejA9YpsG #PostQuantumCryptography #Cybersecurity #QuantumComputing #PQC #InfoSec #NIST #CryptoAgility

  • View profile for Jen Easterly

    CEO, RSAC | Former Director, CISA | Cyber + AI | Leader | Speaker | Innovator | Optimist | #MoveFast&BuildThings

    127,645 followers

    🔐Word o’ the Day | Year | Decade: Crypto-agility, Baby! Yesterday morning, I did a fun fireside chat with Bethany Gadfield - Netzel at the FIA, Inc. Expo in Chicago. We talked about cyber resilience, artificial intelligence, Rubik’s cubes, and that thing called quantum! A question came up at the end, “What can firms actually do today to begin transitioning to post-quantum cryptography?” So thought I would take the opportunity to share my thoughts more broadly on this important, but not super well understood, topic: 1. Don’t wait. The clock for quantum-safe cryptography is already ticking. NIST released its first set of post-quantum standards last year (https://lnkd.in/esTm8uPw) and CISA put out a “Strategy for Migrating to Automated Post-Quantum Discovery and Inventory Tools” last year as part of its broader Post Quantum Cryptography (PQC) Initiative (https://lnkd.in/evpF4umv). h/t Garfield Jones, D.Eng.! 2. Inventory & prioritize. Map all cryptographic usage: what keys, certificates, protocols, and data streams exist today? Which assets hold long-lived value and are at risk of “harvest-now, decrypt-later”? Build a migration roadmap that prioritizes highest-risk systems (e.g., financial settlement platforms, inter-bank links, legacy encryption). 3. Establish crypto-agility. Ensure your architecture supports swapping algorithms, updating certificates, & layering classical + post-quantum primitives without a full system rebuild. This kind of flexibility is key for resilience. 4. Pilot and migrate. Use the new NIST-approved algorithms; experiment first on less time-sensitive systems, validate performance and interoperability, then scale to mission-critical applications. NIST’s IR 8547 report provides a framework for this transition. 5. Vendor & supply-chain alignment. Ask your vendors & service providers: “What’s your PQC transition plan? When will you support NIST-approved post-quantum algorithms? Are your update paths crypto-agile?” If the answer isn’t clear or (as a former boss of mine used to say) they look at you like a “pig at a wristwatch,” you’ve got a potentially serious third-party risk. 6. Board and Exec engagement. Position this not as an IT problem but a fiduciary risk and resilience imperative. The transition to quantum-safe cryptography is multi-year and multi-layered—waiting until it’s urgent means it will be too late.

  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 20,000+ direct connections & 55,000+ followers.

    55,102 followers

    NIST – Migration to Post-Quantum Cryptography Quantum Readiness outlines a comprehensive framework for transitioning cryptographic systems to post-quantum cryptography (PQC) in response to the emerging threat of quantum computers. Quantum technology is advancing rapidly and poses a significant risk to current public-key cryptographic methods like RSA, ECC, and DSA. This guide aims to assist organizations in preparing for and implementing PQC to safeguard sensitive data and critical systems. Key Points  The Quantum Threat Quantum computers are expected to disrupt cryptography by efficiently solving mathematical problems that underpin widely used encryption and key exchange methods. This would render current public-key systems ineffective in protecting sensitive data, emphasizing the need for cryptographic agility.  NIST PQC Standards NIST is spearheading efforts to standardize quantum-resistant algorithms through an open competition and evaluation process. These algorithms, designed to withstand quantum attacks, focus on two primary areas: 1. Key Establishment: Protecting methods like Diffie-Hellman and RSA key exchange. 2. Digital Signatures: Securing authentication processes.  Migration Framework The document provides a phased approach to migrating cryptographic systems to PQC: 1. Assessment Phase:    - Inventory cryptographic dependencies in current systems.    - Evaluate systems at risk from quantum threats based on sensitivity and lifespan. 2. Preparation Phase:    - Conduct pilot testing of candidate PQC algorithms in existing infrastructure.    - Develop a hybrid approach that combines classical and post-quantum algorithms to ensure interoperability during transition. 3. Implementation Phase:    - Replace vulnerable cryptographic methods with PQC in a phased manner.    - Ensure scalability, performance, and compatibility with existing systems. 4. Monitoring and Updates:    - Continuously monitor the effectiveness of implemented solutions.  Challenges in PQC Migration - Performance Impact: PQC algorithms often have larger key sizes, increased latency, and greater computational demands compared to classical algorithms. - Interoperability: Ensuring smooth integration with legacy systems poses significant technical challenges.  Best Practices - Use hybrid encryption to maintain compatibility while testing PQC algorithms. - Engage in collaboration with vendors, industry groups, and government initiatives to align with best practices and standards. Conclusion The transition to post-quantum cryptography is a proactive measure to secure data and communications against future threats. NIST emphasizes the importance of starting preparations immediately to mitigate risks and ensure a smooth, efficient migration process. Organizations should focus on inventorying dependencies, piloting PQC solutions, and developing cryptographic agility to adapt to this transformative technological shift.

  • View profile for John Bruggeman CISSP

    vCISO at CBTS and OnX. I make Cybersecurity and Cyber risk understandable, CISSP, Advisory Board, Speaker, Treasurer InfraGard Cincinnati

    4,461 followers

    I've given talks about Post Quantum Cryptography the past few years and pretty much everyone has appreciated the heads up, for those that haven't made it to a talk here are the highlights of what you need to do to prepare for Quantum Computers. 1) Build organizational readiness: • Educate and align the C-suite on the urgency of quantum risk and make the business case for a multi-year investment, i.e. get budget. • Identify personnel responsible for migration execution across different teams, i.e. assign a point person for this project. 2) Discover what you have and assess if the systems are ready: • Get an inventory of you hardware and software assets to identify encryption protocols and categorize them (PQ ready, depreciated, really old). • Assess whether hardware assets have sufficient compute to support PQC algorithms (most systems will but the OS might not be ready) • Figure out which systems will require upgrades or replacements. • Identify vendors and partners that you use and discuss their PQC roadmaps, migration support capabilities. [This one is key, talk to your vendors, find out what they are doing, or not doing!] 3) Begin getting Quantum ready • Buy the hardware / software and replace or upgrade whatever does not support PQ cryptography • Test things! Run proof-of-concept deployments in controlled environments (i.e. your test environment) and use a hybrid approach that combine current and post-quantum algorithms. 4) Deploy Quantum ready solutions • Roll out your solutions / new hardware & software in phases, starting with your high priority systems (Duh). • Ensure configurations enforce quantum-safe algorithms by default and automatically block deprecated algorithms when possible (this will be harder than you might think). • Update your security policies to manage both current and quantum-safe network traffic as you transition. • For the old stuff you can't get rid of, use proxy solutions to make IoT devices (like hospitals, manufacturing, etc.) quantum-ready until they can be updated directly. Last but not least, be prepared to change encryption schemes going forward, what we call, Crypto Agility. 5) Keep patching your stuff • Now that you have a list of your hardware and software and what kind of encryption is uses, do this: • Monitor your inventory for vulnerabilities or new threats. Keep in mind that PQ standards are new and they will likely change over time. • Establish a process to replace or update vulnerable algorithms There, you've now just read my talk, but you missed all my jokes and fun stories, but you got the details / important take aways. 😃 😁 😀 If you want the Internal Control Questionnaire (#ICQ) I put together for some auditor friends, message me here and I'll send it to you.

  • View profile for Rich Campagna

    SVP Products, Palo Alto Networks

    18,617 followers

    Quantum computing is moving from "science fiction" to "business reality" faster than most predicted. Two recent papers have fundamentally shifted the timeline for when we need to care about Quantum-Safe security: 1️⃣ The "10,000 Qubits" Milestone: New research shows that we can execute Shor’s algorithm—the math that breaks today’s encryption—with far fewer resources than previously thought. By using reconfigurable atomic qubits, the hardware requirements for cracking RSA-2048 have dropped by nearly 20x. 2️⃣ The "9-Minute" Crypto Warning: Google’s latest whitepaper highlights a terrifying reality for digital assets. Under advanced quantum scenarios, the encryption protecting a cryptocurrency wallet could be cracked in under 10 minutes. This puts billions in "dormant" assets at immediate risk of "at-rest" attacks. The Bottom Line: The "Q-Day" window is shrinking. It’s no longer about if a quantum computer can break your encryption, but when your current migration timeline will run out. How do we respond? We can't just flip a switch on "Q-Day." For many organizations, becoming quantum safe is a multi-year journey. This is where Palo Alto Networks Quantum-Safe Security comes in. Instead of a manual, multi-year overhaul, we provide a path to Agentic Resilience: - Continuous Discovery: It automatically maps your "cryptographic bill of materials" (CBOM), identifying exactly where vulnerable RSA and ECC algorithms are hiding in your network. - Risk Prioritization: It correlates your encryption strength with business criticality, telling you exactly which high-value assets need to move to Post-Quantum Cryptography (PQC) first. - Real-Time Remediation: For legacy systems that can’t be easily upgraded, a "Quantum-Safe Proxy" re-encrypts vulnerable traffic into post-quantum algorithms (like ML-KEM) at the network edge. The transition to a quantum-safe future is a marathon, but the starting gun has already fired. Learn how to take your first steps at the link in the comments.

  • View profile for Roman Kruglov

    Cloud & Infrastructure Leader | Cloud Strategy & Architecture | Cybersecurity, Zero Trust & AI | Building Secure, Resilient Enterprises | Board Advisor

    2,372 followers

    Quantum computing will shred RSA and ECC like tissue paper, yet many are still treating the migration to Post-Quantum Cryptography as a "later" problem. ⬇️ On August 13, 2024, NIST finalized the first three PQC standards, signaling that the era of "Harvest Now, Decrypt Later" has met its match. Whether you are managing service account sprawl or securing cloud ecosystems, these standards are ready for immediate use to prevent your digital keys from shattering. The New Standards Framework NIST has provided three primary tools to secure our infrastructure against quantum threats: ➡️ FIPS 203 (ML-KEM): Derived from CRYSTALS-Kyber, this is the primary standard for general encryption. It is built for speed and uses small encryption keys that are easy to exchange. ➡️ FIPS 204 (ML-DSA): Based on CRYSTALS-Dilithium, this serves as the primary standard for digital signatures. ➡️ FIPS 205 (SLH-DSA): Utilizing the Sphincs+ algorithm, this acts as a stateless hash-based backup for digital signatures in case lattice-based methods prove vulnerable. A Practical Migration Path Migrating isn't just a technical swap; it's a strategic shift toward "antifragile" identity. You can begin strengthening your enterprise posture today by following these steps: ✔️ Inventory Your Endpoints: Identify where legacy RSA and ECC are buried in your stack. ✔️ Test in Hybrid Mode: Use a combination of classical and PQC algorithms to ensure stability. ✔️ Update Your Stack: Leverage tools like liboqs or OpenQuantumSafe to update your TLS 1.3 implementations. We often delay security updates because we fear downtime or "friction," but quantum doesn't negotiate. Adopting these standards now is how we stay one step ahead of state actors and safeguard the future of our data.

  • View profile for Mary Lacity

    David D. Glass Chair and Distinguished Professor of Information Systems

    8,150 followers

    IS YOUR ENTERPRISE READY FOR "Q-DAY"? "Q-day" (or Quantum Day) is the point in time when quantum computers become powerful enough to break the public-key encryption (like RSA or ECC) that currently secures global digital, financial, and government infrastructure. Our current best estimates is that Q-Day will happen by 2029! Huge thanks to Dr. Rob Campbell, FBBA. , IBM Global Quantum-Safe Executive and IBM Quantum Ambassador, for guest lecturing to our University of Arkansas ­- Sam M. Walton College of Business EMBA students. His insights into the "Quantum-Safe" transition provided a crucial roadmap for how leadership must navigate the next few years of cybersecurity. Here's what we learned: Adversaries are currently collecting encrypted data to store and decrypt once quantum computers are powerful enough to calculate private keys—a strategy known as "Harvest now, decrypt Later". Because enterprise cryptographic migrations can take 5 to 15+ years, many large organizations will still be in transition when quantum computers become capable of breaking current encryption. What enterprises can do NOW: Dr. Campbell emphasized that Post-Quantum Cryptography (PQC) is a leadership issue, not just a technical one. To preserve trust and resilience, leaders should authorize these "low-regret" actions immediately: - Inventory cryptographic dependencies: identify what you have before you plan what to change. - Prioritize high-value data: Focus on data with the longest confidentiality horizons, not just the most "critical" systems. - Invest in crypto-agility: Design systems for the permanent ability to swap algorithms without rebuilding the entire architecture. - Pilot PQC today in non-mission critical systems: PQC standards were finalized by NIST in 2024 and are ready for deployment on classical computers now. Enterprises can learn in these lower risk systems. - Communicate metrics to boards in non-technical jargon. Dr. Campbell noted, the question is whether we manage this change deliberately now or inherit it under pressure later. He stressed the importance of wide-spread education. To that end, Professor Daniel Conway will be offering the Walton College's first Quantum Computing class this fall! Adam Stoverink, Ph.D.; Shaila Miranda; Brian Fugate; Brent D. Williams; James Allen Regenor, Col USAF(ret) #QuantumSafe #PQC #CyberSecurity #Leadership #EMBA #DigitalTransformation #RiskManagement

Explore categories