Technology Now

Are we prepared for the deployment of a functional quantum computer? This week, Technology Now is returning to the topic of post quantum cryptography. We ask why the deadline for migrating to PQC enabled systems has been moved up, we discover what a quantum computer actually needs to be cryptographically relevant, and we pose the question: when it comes to migrating your systems to quantum resistant forms of encryption, could it already be too late for some people to start?

This is Technology Now, a weekly show from Hewlett Packard Enterprise. Every week, hosts Michael Bird and Sam Jarrell look at a story that's been making headlines, take a look at the technology behind it, and explain why it matters to organizations.

Creators and Guests

MB
Host
Michael Bird
SJ
Host
Sam Jarrell

What is Technology Now?

HPE news. Tech insights. World-class innovations. We take you straight to the source — interviewing tech's foremost thought leaders and change-makers that are propelling businesses and industries forward.

NIGEL EDWARDS
cryptographic algorithms are based on hard mathematical problems, and the security depends on the hardness of those mathematical problems so that you can, execute a function to encrypt or sign something.
and actually, reversing that without. The correct keys becomes very hard. recovering. The keys is mathematically intractable. and though there are algorithms which in theory could recover the keys and break the cryptography, they would take too long to run on the most powerful supercomputer we have available today.

MICHAEL BIRD
I mean, what are we talking about?

NIGEL EDWARDS
Millions or billions of years.

SAM JARRELL
Goodness. Well, I can say confidently that they are safe from me breaking the security because I am not great at math and I certainly would not be able to keep up with, uh, what a supercomputer can achieve. And it's good to put a number actually on quite how secure the algorithms currently are. We say they're pretty much unbreakable, but billions of years on the most powerful supercomputer in the world, like wow.

MICHAEL BIRD
Yeah. It's, it is quite something, isn't it? And as you might have guessed, that was our guest for today's episode, Nigel Edwards. And
we are returning to the topic of post Quantum Cryptography or PQC to get an update on how things have changed in the past year.
I’m Michael Bird.

SAM JARRELL
I'm Sam Jarrell

MICHAEL BIRD
And welcome to Technology Now from HPE.

SAM JARRELL
why exactly are we returning to a topic we have covered before on the show? Michael? Could it have something to do with the near weekly articles about a new quote, breakthrough in quantum computing?

MICHAEL BIRD
It does seem like the progress is accelerating and with the knock on impact of a quantum computer on our security infrastructure, it is pretty important to keep up to date with the latest security landscape.

SAM JARRELL
This security landscape would, I assume be having to respond to any developments in the quantum computing world. I mean, if there's effectively
an inbuilt deadline by which any sort of quantum secure algorithms would have to be ready to be deployed by

MICHAEL BIRD
Yeah, and as you'll hear in my chat with Nigel, that deadline is closer and approaching faster than originally expected. But it's not just software, which is threatened. Some hardware can have security physically baked into the silicon, and in cases like that, a simple update to the security might not really be enough.

SAM JARRELL
Because you would need to fully replace the hardware.

MICHAEL BIRD
Among other things. Yes. So, so this week we are hearing from Nigel Edwards, who is director of the security lab at HPE Labs. we chatted a little under a year ago about PQC. So the first thing I wanted to know is what's changed since we last spoke.


NIGEL EDWARDS
So, a couple of things I think have caught my eye over the last, 12 months or so. So, my colleagues, who are researching quantum computing, together with their colleagues in the Quantum Scaling Alliance, published a white paper on how to build a quantum supercomputer. So they're working with, companies some of the top, academic institutions as well, outlining, how you would go about.

Producing a, quantum computer built of quantum processing units. and then, secondly, just recently a significant white paper was published by a couple of the US government research labs, the National Energy Research Scientific, computing Center or nersc. And the, Lawrence Berkeley National Lab, published a survey of the academic literature on quantum computing.

And what they've seen is that, there's a constant trend of the amount of resources required, to apply to quantum algorithms, being reduced. and also, they looked at what the claims are being made by the vendors of quantum computing devices. Some of them are claiming that over the next 10 years there will be a 1 billion factor of, improvement. So if anything, there's an acceleration of progress, that's occurred over the last 12 months.

MICHAEL BIRD
Yeah, because last time I think we talked about there being, a timeline for an organization should start to think about it. But I think that was something like 2030, 2035.
But are you saying that timeline that organizations need to be

NIGEL EDWARDS
So, the three key dates that we had, 12 months ago looking at the recommendations from various government agencies around the world was have your plans in place by, 2028.

And then for your high priority systems, complete the migration by January the first, 2031. And then all migrations by, January the first, 2035, 2035 is now looking, maybe a little bit too late in my view. and I would, for all systems, be looking to get it done, in the early thirties.

MICHAEL BIRD
And do you think organizations will have it all done by the 2030, early 2030s?

NIGEL EDWARDS
I think there will be challenges. and I think organizations need to prioritize. I think the advice on that is not to change the strategy you need to inventory your systems, inventory, your services, and then focus on the ones that are top priority on which your business, depends.
systems that are, manipulating or managing. sensitive data such as personal information, financial systems, telecommunication systems, systems with medical records on all of those are high priority.

MICHAEL BIRD
So, what physical qualities are needed to make a quantum computer cryptographically relevant?
Like, why aren't we worried today?

NIGEL EDWARDS
today, there just isn't enough power in, the, quantum computing devices. and, the engineering challenges, are to create, A, sufficient number of logical qubits.
So, perhaps the most famous quantum vulnerable algorithm is RSA. So, to factor a, 2K RSA key you need. Roughly, 2000, logical qubits

MICHAEL BIRD
hi, voiceover michael here. For those who haven't come across the concept of a logical qubit before, it's basically a type of quantum error correction. A physical qubit is the actual thing which is in the quantum computer whereas a logical qubit is created using multiple physical qubits which all work together to simulate a perfect qubit without errors. It's more resilient to noise than the physical qubits. Anyway, back to Nigel.

NIGEL EDWARDS
Now, a logical qubit is not the same as a physical qubit, and the challenge, is, quantum noise. The more, physical qubits you put together, the more noise you generate.
And then you have to use quantum error corrections. and then using quantum error correction to create that noise becomes more and more challenging.
So there will be a,cliff edge, like once that golden number is achieved, then particular RSA keys can be, can be guess will be, will be correct. And, some of the technology, vendors working on quantum computing devices are are saying exponential growth, right?

So it's, the equivalent of Moore's Law. But in the quantum computing space, and some folks are predicting, an increase of, a billion over the next 10 years. in the number of, logical quantum bits that are available. So that rate of progress is pretty much as soon as a 2K key, is successfully factored.

Then 3K and 4K keys are gonna fall very, very quickly after that, which basically means that RSA is no longer viable

MICHAEL BIRD
So how is the industry responding to. These changes, of the impending, cryptographically relevant quantum computer

NIGEL EDWARDS
we are, working on deploying post quantum cryptographic algorithms. So these algorithms were standardized by NIST. Earlier this decade,
The standards were published in 2024. and we are, working on applying these, in our software stacks, our firmware stacks and making changes to silicon. the long pole in the tent are the changes required to silicon because you cannot, instantly change silicon to handle new cryptography, chip designs and, and changes to chips a typical life cycle is two years. In some cases it can be meant as many as four years. So, if a standard is published, then it's not reasonable to expect that to appear next year. Or even possibly the year after. in silicon,

MICHAEL BIRD
So, what's the impact then? we have to redesign every single component or, every single chip

NIGEL EDWARDS
it's not a, complete redesign, but we need to make. Certain changes to the chips. So, so particular when you look at, um, how, uh, firmware it's required for the processor, for example, an X 86 processor to execute X 86 instructions so that firmware is verified by keys that are fused into the silicon to ensure, for example, it's genuine firmware
These keys are your classical keys such as RSA or E-C-D-S-A keys. They need to be changed to use, these post quantum cryptographic algorithms which have been standardized by the national Institute of Standards and Technology Organizations.

MICHAEL BIRD
And so, does every single component have to be updated at the same time? Or can you, can you sort of piecemeal as you go along?

NIGEL EDWARDS
so the approach that we are taking. in HPE is to, be able to offer our customers, PQC configurations with our, newer products, PQC enabled configurations. we know that not all components, that are available will be PQC, enabled, but we are working with our supplier partners, so that there will be a network controller, a storage controller that we can source that will be PQC enabled together with PQC enabled processes so that the components that matter inside that server, for example, will be PQC enabled.

MICHAEL BIRD
I think you, talked both about PQC enabled and PQC capable hardware. what is the difference

NIGEL EDWARDS
so we tend to think of it at, a product level rather than specific hardware PQC enabled means all the cryptography. In that server, is running the PQC algorithms. PQC capable means it's capable of running those algorithms, but it might not be enabled, but it could be enabled in the future, by configuration changes and possibly software and firmware upgrades.

MICHAEL BIRD
So, how should an organization then be preparing for this transition?
Like, should they be buying. The correct hardware today or is it more of a planning phase at the moment?

NIGEL EDWARDS
so today, the hardware is not available. there is not, A PQC enabled, processor available
and, so right now my advice would be to start planning. you need to know the critical systems because this is not going to be a, just a turn of a switch, right? You need to understand how you're going to upgrade your systems when the upgrade is planned.
and you need to, look at how you're gonna refresh the hardware. Look at how you're gonna refresh the software stacks as well.

MICHAEL BIRD
this conversation has been quite hardware focused, but presumably that has a knock on impact to the software that you're running.

NIGEL EDWARDS
The operating systems will have to change. the services running on the operating systems will have to change, Some, changes are being made to software. a, well-known web browser, for example, already has some PQC algorithms running in it,
Software, is a little different to hardware because software can be upgraded in the field. hardware. it's much harder to upgrade in the field and much more expensive. It's not a question of patching.
You've gotta open up the chassis and pull out the components.
and to upgrade a current generation server to A PQC enabled server that would require, changing the motherboard.

MICHAEL BIRD
we've talked a little bit about, some of the practical points, but I mean, just dive a little bit into PQC, maybe a bit of a PQC 1-0-1. Like why is it resistant to a quantum computer and maybe how does that compare to why RSA is vulnerable to a quantum computer or other encryption methods like RSA?

NIGEL EDWARDS
cryptographic algorithms are based on hard mathematical problems, and the security depends on the hardness of those mathematical problems so that you can, execute a function to encrypt or sign something.
and actually, reversing that without. The correct keys becomes very hard. recovering. The keys is mathematically intractable. and though there are algorithms which in theory could recover the keys and break the cryptography, they would take too long to run on the most powerful supercomputer we have available today.

MICHAEL BIRD
I mean, what are we talking about?

NIGEL EDWARDS
or billions of years.

MICHAEL BIRD
Yeah, that's too long.

NIGEL EDWARDS
and the problem is that quantum computers are completely different model of computation to current hardware. and that allows them to run algorithms.
in a reasonable amount of time on a quantum computer where it's not possible realistically to run it on a classical computer.
And so what that means is we have to find new algorithms which are based on problems for which there are no known quantum algorithms. and so this is,
what the, cryptographic academic community have been doing. And what NIST have been, evaluating proposals from the community over more than a decade, uh, to, determine the algorithms which are best suited to protect us, from the threat of a quantum computer.
So the algorithms they standardized, there is no known, algorithm which will run on a quantum computer. that will, compromise the security,

MICHAEL BIRD
but I suppose compared to encryption methods like RSA that have been around for decades,
and a very widespread in their use, A PQC algorithm, is maybe less stress tested,
Like, how do you make sure that actually those algorithms or those encryption methods are actually good encryption methods.

NIGEL EDWARDS
So there is a school of thought, that the new algorithms, some of which were only standardized in 24, they're not battle hardened. They're not, sufficiently, field tested, whereas we understand very well.
RSA, for example, which has served us for multiple decades, and we know the properties of that. and, there are some eminent people and there's even some, EU government institutions that, are, saying that you cannot discount the possibility of there being either. A flaw in the algorithms, and almost certainly will be flaws in implementations of the algorithms.
so the strategy that we are adopting in HPE is, to sign, software and firmware with both a, classical RSA or E-C-D-S-A key as well as with one of the newer quantum algorithms. Yeah. And what that does is it extends until somebody has a cryptographically relevant quantum computer.
If there were to be a flaw in one of the new PQC algorithms, then provided there is no, cryptographically relevant quantum computer, we still have security. Meanwhile, analysis on the new algorithms, and the implementation of those new algorithms will, will continue.
we're not throwing away the classical algorithms. We are using those as well as the new algorithms to, provide, the best possible security.

MICHAEL BIRD
Nigel, thank you so much for your time. It's been absolutely a pleasure interview

NIGEL EDWARDS
It’s been a pleasure. Thank you.

SAM JARRELL
Wow. the fact that we've already moved The safe migration date of 2035, closer to 2031, and it's been a year since you last talked to him. That's a massive acceleration. That makes me wonder if like in a year from now he'll be like, oh yeah, actually it's next year.

MICHAEL BIRD
Yeah. they are predicting a 1 billion factor improvement over 10 years.
I mean, it was serious a year ago and it was serious now. the fundamental factor here is that once there is a cryptographically relevant quantum computer, our traditional methods of encryption no longer work.

SAM JARRELL
Yeah. I highly doubt most organizations have really grasped that for many of them, it is too late. and they'll be playing a lot of catch up too. Get their hands on what they need to upgrade their systems and, this is gonna change the game. 'cause once the tech is out there, nefarious folks are going to start figuring out how it ticks for themselves.
this is a massive cybersecurity gap for everybody.

MICHAEL BIRD
It sort of feels a bit like the millennium bug Y2K, but we don't actually know when the date is.

SAM JARRELL
it's a little bit scary to me. but like he said, there are things you can be doing right now. You can be planning right now on, on what you will need to do. And I found it quite interesting that he even mentioned that there's already a well-known web browser that's running quantum algorithms.
So people are doing some things right.

MICHAEL BIRD
Yeah. And so I think that's the thing. once there is a cryptographically relevant quantum computer, processes would need changing.
if you think of things like banking apps presumably would need updating. any sort of applications that use, cryptography. there's gonna be a serious amount of work, which will be required. Of course, we've been using RSA or classical algorithms for years.
Whereas the post quantum cryptography algorithms, They are really near infancy, maybe five, 10 years old. To some extent. They haven't really been stress tested because they aren't the algorithms in use, they haven't had as much widespread use.
So this concept of locking a door with two padlocks, seems like a very sensible thing to do

SAM JARRELL
I'll be interested to see, once they are able to start stress testing these things, can you imagine being the folks who have the job of trying to break them? I imagine people will be working on breaking them right away. Both governments, institutions, bad actors, all kinds of different folks.
we've mentioned how quick this deadline is coming up, but do you think the average consumer has any idea this change is coming and well, what would you tell them? Like it basically update your browsers and don't worry.

MICHAEL BIRD
I'm so glad you asked because, um, the last thing I wanted to ask Nigel was this, as consumers, how should we be responding to the threat, posed by a cryptographically relevant quantum computer? Like, you know, to your point, do we need to change our browser? Do we need to change our phones? So I thought Nigel's answer was really interesting.

NIGEL EDWARDS
you need to keep your software up to date. there are some web browsers out there that are deploying these new algorithms and they're protecting against, the so-called harvest now decrypt later attack,
So already some web browsers are protecting that. So you need to keep your software up to date and then, over time, as you buy new phones, buy new computers, the reputable vendors will be ensuring that those have the new PTC algorithms. Inside them.
I think if we do our job properly in the industry, and well, you won't know that that is actually, taking place.

SAM JARRELL
Okay that brings us to the end of Technology Now for this week.

Thank you to our guest, Nigel Edwards

And of course, to our listeners.

Thank you so much for joining us.

MICHAEL BIRD
If you’ve enjoyed this episode, please do let us know – rate and review us wherever you listen to episodes and if you want to get in contact with us, send us an email to technology now AT hpe.com and don’t forget to subscribe so you can listen first every week.

Technology Now is hosted by Sam Jarrell and myself, Michael Bird
This episode was produced by Harry Lampert and Izzie Clarke with production support from Alysha Kempson-Taylor, Beckie Bird, Alissa Mitry, and Janessa Ayache. Our theme music was composed by Greg Hooper.

SAM JARRELL
Our social editorial team is Rebecca Wissinger, Judy-Anne Goldman and Jacqueline Green and our social media designers are Alejandra Garcia, and Ambar Maldonado.

MICHAEL BIRD
Technology Now is a Fresh Air Production for Hewlett Packard Enterprise.

(and) we’ll see you next week. Cheers!

SAM JARRELL
Bye y’all