Post-quantum cryptography

All Member States should start transitioning to post-quantum cryptography by the end of 2026. At the same time, the protection of critical infrastructures should be transitioned to PQC as soon as possible, no later than by the end of 2030.

Source: https://digital-strategy.ec.europa.eu/en/news/eu-reinforces-its-cybersecurity-post-quantum-cryptography

What’s going on?

In the ’90s and early 2000 the internet was on the rise and first online banking and other systems started requiring encryption to keep information safe.

Going forward, the certificate key sizes started growing as the computers got faster and also the public key validity dropped drastically. One might recall the 512bit RSA keys and 5 year certificates.

Today the standard is 2048bit RSA (from since around 2015) with currently 200d validity and CA/Browser forum has stated (ref) that the certificate validity will drop to 47d by 15th of March 2029.

(We’ll discuss the certificate lifecycle management in another post soon)

Photo by <a href="https://unsplash.com/@andrewjoegeorge?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText">Andrew George</a> on <a href="https://unsplash.com/photos/man-in-black-suit-jacket-figurine-g-fm27_BRyQ?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText">Unsplash</a>

There are no quantum computers (yet)

(… for public use anyways.) When I was writing this, I could quickly find that currently the largest quantum computer has an array of 6100 qubits already, which was somewhat a surprise for myself (the one in Finland held 50 qubits).

Not diving in to details, but it’s clear that the situation develops quite fast and the EU policy dictating PQC requirement by 2030 tells a story. The current worry though is the “Harvest now, decrypt later” (HNDL, Wikipedia) where the data is just collected and once the quantum computers are within reach the data can be decrypted.

Call to action

As EU instructed, the Member States should start transitioning to PQC by the end of 2026, so all organizations should already have a plan how to move forward.

In our managed service (Instrument for Access) we’ve already transitioned several environments to PQC and working on with the remaining ones.

The “Security basics” series still applies and not being an easy or obvious target is something to aim for. Start reading from the first chapter Security basics, part 1 – Why?.

References

Citrix’ Steven Wright has written many great articles on securing your NetScaler deployment, here’s a few to start off wit: