Skip to main content
QUICK REVIEW

[论文解读] Post Quantum Cryptography: Readiness Challenges and the Approaching Storm

Matt Campagna, Brian LaMacchia|arXiv (Cornell University)|Jan 4, 2021
Quantum Computing Algorithms and Architecture被引用 6
一句话总结

本文指出,由于量子计算技术的不断进步,迫切需要全球范围向后量子密码学(PQC)过渡,因为这威胁到当前的公钥密码系统。本文概述了这一迁移的复杂性,强调了各利益相关方之间协调的挑战,并主张立即采取准备措施,以确保在广泛攻击变得可行之前,能够安全、有序且最小化中断地过渡到抗量子算法。

ABSTRACT

While advances in quantum computing promise new opportunities for scientific advancement (e.g., material science and machine learning), many people are not aware that they also threaten the widely deployed cryptographic algorithms that are the foundation of today's digital security and privacy. From mobile communications to online banking to personal data privacy, literally billions of Internet users rely on cryptography every day to ensure that private communications and data stay private. Indeed, the emergence and growth of the public Internet and electronic commerce was arguably enabled by the invention of public-key cryptography. The key advantage offered by public-key cryptography is that it allows two parties who have never communicated previously to nevertheless establish a secure, private, communication channel over a non-private network (e.g., the Internet). Recent advances in quantum computing signal that we are on the cusp of our next cryptographic algorithm transition, and this transition to post-quantum cryptography will be more complicated and impact many more systems and stakeholders, than any of the prior migrations. This transition represents a major disruption within the IT industry and will broadly impact nearly every domain of our digital lives, from global commerce to social media to government and more. Cryptographic algorithm transitions take time and involve an extensive coordination effort across many stakeholders who are involved in building and operating the world's compute infrastructure. By preparing now for the upcoming transition to these new algorithms, we can ensure a more orderly, less costly, and minimally disruptive changeover.

研究动机与目标

  • 分析量子计算对现有用于数字通信和基础设施的公钥密码学所构成的系统性风险。
  • 识别与以往密码学迁移相比,向后量子密码算法过渡所面临的独特挑战。
  • 强调全球IT与网络安全界必须主动准备,以确保向PQC的安全、有序且成本可控的迁移。

提出的方法

  • 本文综合密码学专家和行业利益相关方的见解,评估当前PQC标准化和部署准备情况的现状。
  • 评估在将全球系统升级为抗量子算法过程中涉及的技术、组织和政策挑战。
  • 作者采用基于风险的框架,评估当前密码学被量子攻击突破的时间表和影响。
  • 本文借鉴历史密码学迁移经验,对即将到来的PQC迁移的规模和复杂性进行建模。
  • 倡导开展协调一致的、多方利益相关者参与的规划,并提前采用标准化的PQC算法。

实验结果

研究问题

  • RQ1从当前公钥密码学向后量子替代方案过渡的主要技术与组织挑战是什么?
  • RQ2即将到来的后量子密码学迁移在规模和复杂性上与以往密码算法迁移有何不同?
  • RQ3推迟采用后量子密码学标准可能带来哪些潜在后果?
  • RQ4协调与标准化在确保PQC迁移安全高效方面发挥什么作用?
  • RQ5政府、产业界和学术界的利益相关方应如何主动为数字安全面临的量子威胁做好准备?

主要发现

  • 向后量子密码学的过渡将比以往任何一次密码学迁移都更加复杂且影响范围更广,几乎影响全球每一个数字系统。
  • 许多广泛部署的密码协议和系统容易受到大规模量子计算机的攻击,可能破解当前的公钥方案(如RSA和ECC)。
  • 量子威胁的时间表尚不明确,但正在逼近,因此必须立即采取行动,以避免临门一脚的混乱。
  • NIST的标准制定工作正在推进中,但在异构系统中部署仍需广泛协调与测试。
  • 主动准备可显著降低迁移成本,减少中断,并确保全球基础设施中数字安全的持续性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。