To achieve long-term data protection in todays fast-changing and uncertain world, companies need the ability to respond quickly to unforeseen events. Threats like quantum computing are getting more real while cryptographic algorithms are subject to decay or compromise. Without the ability to identify, manage and replace vulnerable keys and certificates quickly and easily, companies are at risk.
So, what do we mean when we talk about crypto-agility? Fundamentally, you will have achieved crypto-agility when your security systems are able to rapidly deploy and update algorithms, cryptographic primitives, and other encryption mechanisms. Going a step further, it means you have achieved complete control over cryptographic mechanisms your public key infrastructure (PKI) and associated processes and can quickly make whatever changes are needed without intense manual effort.
The replacement of manual processes with automated ones is critical to keeping up with accelerating change. As computing power and security technologies continue to evolve at a faster and faster pace, your existing cryptographic infrastructure is destined to become obsolete in a few years unless you can keep it upgraded to the latest technologies. Notably, threats continue to evolve as well.
Moreover, as the world transforms to depend on digital systems more fully, weve embedded cryptography deeply into virtually every communication system in the world. Its no longer possible for cryptography to remain isolated from other critical systems. The vast interdependent nature of modern systems makes it imperative that IT teams have the ability to respond quickly or face the risk of major outages and disruption.
Cryptographic standards like RSA, ECC, and AES that are in broad use today are constantly being updated with more advanced versions. Eventually governing bodies like NIST get in the act and mandate the use of the latest standards, with browser and cloud providers often raising the bar as well. To avoid becoming non-compliant, you must have the ability to quickly upgrade all your systems that rely on deprecated cryptography.
A robust, cryptographically agile infrastructure also brings other long-term benefits and plays a critical role in preventing security breaches. Achieving crypto-agility will make your operations teams more efficient, and eliminate unnecessary costs such consulting fees, temporary staff, fines, or remediation costs.
Such scenarios can unfold when a bad actor gains admin access, for instance, and may or may not have issued certificates. This uncertainty means that certificates from the impacted certificate authority (CA) can no longer be trusted and all certs from that CA must be revoked and re-issued. Without crypto-agility and a clear understanding of your potential exposure, youre looking at a costly all-hands-on-deck response to track and update hundreds or thousands of certs. And, of course, anytime you have humans involved with security response, youre opening yourself to human error and further compromise and outages.
The looming threat of quantum computing some say we could see 100,000x faster quantum computers as soon as 2025 represents another compelling reason to focus on improving your crypto-agility. While all crypto algorithms are breakable on paper, the incredible computing power required for such a feat does not currently exist. That could change with quantum computers which one day will be able to break most existing algorithms and hash function in minutes or hours.
To avoid the doomsday scenario where every system in the world is potentially exposed to compromise, work is already underway toward quantum-safe cryptography. However, given how little we know about quantum computing and the inability to perform real-world testing, its safe to assume there will be considerable give and take before quantum-safe algorithms are widely available.
In the meantime, your cryptography, certificate management and key distribution systems must be agile enough to adapt to this very real emerging threat. The table below presents a scenario of the time and expense involved with swapping out existing cryptography for quantum-safe cryptography. In this scenario, with incomplete or partial automation most enterprises would be looking at a 15-month vulnerability period compared to just six days when a fully automated solution has been put in place.
A comparison of quantum doomsday mitigation scenarios
Crypto-agility is a complex topic at scale and working towards it requires a multifaceted approach. Changes need to be made to security setups in organizational policy, operating methods, and core technology and processes. Your PKI may need to be upgraded and enhanced to support rapid swaps of cryptography, and software development procedures may need to be revamped to incorporate a nimbler approach to cryptography as opposed to being bolted on top of finished software.
The first step toward true crypto-agility is to understand the extent of your cryptographic exposure. This is accomplished by tracking down every digital certificate deployed across the organization and capturing details including algorithms and their size, the type of hashing/signature, validity period, where its located and how it can be used.
Once you have a complete inventory, youll then need to identify the vulnerable certificates by the type of cryptography in use and look for anomalies and potential problems. These can include certificates that use wildcards or IP address, certificates located on unauthorized or unintended systems as well as certificates abandoned on deprecated systems.
Finding your certificates and vulnerability isnt enough by itself to deliver crypto-agility youre still looking at the aforementioned 15-month-long process if you need to swap everything out manually.
Here are three pillars of crypto-agility that will put your organization on the right path toward withstanding whatever the future holds:
#1 Automate discovery and reporting. At the push of a button, you should be able to produce a full report of all your cryptographic assets. This will allow you quickly identify vulnerable cryptography and to report anomalies. There are any number of tools available to help you do this, but ideally certificate reporting should just be incorporated into an automated PKI solution.
#2 Automate PKI operations at scale. The ideal solution here is a fully automated Certificate Management Systems (CMS) that will manage the entire lifecycle of a certificate from creation to renewal. When the CMS is used to create a certificate it should have all the data it needs to not only monitor the certificate for expiration but automatically provision a replacement certificate without human intervention.
#3 Be nimble. At an organization and management level, your IT organization from DevOps through to day-to-day operations staff need to be ready for threats and change. You should carefully evaluate and rethink all aspects of your PKI to identify areas that may lock you into a particular vendor or technology.
The risk of having a slow-to-respond cryptographic infrastructure is increasingly daily, not only as digital transformations increase our dependency on inter-connected systems but as external threats and technology evolve with increasing pace. Looming above it all is the threat of quantum computing. Put it all together and its clear that the time to automate your PKI and move toward crypto-agility is at hand.
Read more here:
The crypto-agility mandate, and how to get there - Help Net Security
- Mathematician breaks down how to defend against quantum ... - Phys.Org [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Here Is Everything You Need to Know About Quantum Computers - Interesting Engineering [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Quantum Computing Market Forecast 2017-2022 | Market ... [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- What is Quantum Computing? Webopedia Definition [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Quantum computing is about to disrupt the government contracts market - Bloomberg Government (blog) [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Scientists: We Have Detected the Existence of a Fundamentally New State of Matter - Futurism [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- What Sorts Of Problems Are Quantum Computers Good For? - Forbes [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- quantum computing - WIRED UK [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Inside Microsoft's 'soup to nuts' quantum computing ramp-up - Computerworld Australia [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Molecular magnets closer to application in quantum computing - Next Big Future [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- The Bizarre Quantum Test That Could Keep Your Data Secure - WIRED [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- IBM boosts power of quantum computing processors as it lays ... - www.computing.co.uk [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- IBM makes leap in quantum computing power - ITworld [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Toward mass-producible quantum computers | MIT News - MIT News [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Purdue, Microsoft Partner On Quantum Computing Research | WBAA - WBAA [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Tektronix AWG Pulls Test into Era of Quantum Computing - Electronic Design [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Google to Achieve "Supremacy" in Quantum Computing by the End of 2017 - Big Think [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Quantum Computing Becomes More Accessible - Scientific American [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Qudits: The Real Future of Quantum Computing? - IEEE Spectrum - IEEE Spectrum [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Alkermes and IBM's quantum computing. Who'll be the big winner? Malcolm Berko - Durham Herald Sun [Last Updated On: July 6th, 2017] [Originally Added On: July 6th, 2017]
- Quantum Computers Made Even More Powerful with New microchip generating 'Qudits' - TrendinTech [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Quantum Computing Record Broken - Wall Street Pit [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Technique for measuring and controlling electron state is a ... - UCLA Newsroom [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Quantum cheques could be a forgery-free way to move money - New Scientist [Last Updated On: July 10th, 2017] [Originally Added On: July 10th, 2017]
- Quantum-computer node uses two different ion species - physicsworld.com [Last Updated On: July 10th, 2017] [Originally Added On: July 10th, 2017]
- Quantum Computers vs Bitcoin How Worried Should We Be? - The Merkle [Last Updated On: July 10th, 2017] [Originally Added On: July 10th, 2017]
- Why you might trust a quantum computer with secretseven over ... - Phys.Org [Last Updated On: July 12th, 2017] [Originally Added On: July 12th, 2017]
- Physicists Take Big Step Towards Quantum Computing and ... - Universe Today [Last Updated On: August 1st, 2017] [Originally Added On: August 1st, 2017]
- Quantum Computing Market Worth 495.3 Million USD by 2023 | 08 ... - Markets Insider [Last Updated On: August 10th, 2017] [Originally Added On: August 10th, 2017]
- China uses a quantum satellite to transmit potentially unhackable data - CNBC [Last Updated On: August 10th, 2017] [Originally Added On: August 10th, 2017]
- Blind quantum computing for everyone - Phys.org - Phys.Org [Last Updated On: August 12th, 2017] [Originally Added On: August 12th, 2017]
- Quantum Computing Is Real, and D-Wave Just Open ... - WIRED [Last Updated On: August 12th, 2017] [Originally Added On: August 12th, 2017]
- Machine learning tackles quantum error correction - Phys.Org [Last Updated On: August 15th, 2017] [Originally Added On: August 15th, 2017]
- Quantum Internet Is 13 Years Away. Wait, What's Quantum Internet? - WIRED [Last Updated On: August 15th, 2017] [Originally Added On: August 15th, 2017]
- Physicists Have Made Exotic Quantum States From Light - Futurism [Last Updated On: August 16th, 2017] [Originally Added On: August 16th, 2017]
- $495.3 Million Quantum Computing Market 2017 by Revenue Source, Application, Industry, and Geography - Global ... - PR Newswire (press release) [Last Updated On: August 18th, 2017] [Originally Added On: August 18th, 2017]
- How quantum mechanics can change computing - The Conversation US [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- Introducing Australia's first quantum computing hardware company - Computerworld Australia [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- IEEE Approves Standards Project for Quantum Computing ... - insideHPC [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- Commonwealth Bank investing in Australia's first quantum computer company - Which-50 (blog) [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- How quantum mechanics can change computing - San Francisco ... - San Francisco Chronicle [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Quantum Computing Is Coming at Us Fast, So Here's Everything You Need to Know - ScienceAlert [Last Updated On: August 27th, 2017] [Originally Added On: August 27th, 2017]
- Quantum computing event explores the implications for business - Cambridge Network [Last Updated On: August 30th, 2017] [Originally Added On: August 30th, 2017]
- Microsoft's Aussie quantum computing lab set to scale up next-gen ... - ARNnet [Last Updated On: September 7th, 2017] [Originally Added On: September 7th, 2017]
- An Entirely New Type of Quantum Computing Has Just Been Invented - Futurism [Last Updated On: September 7th, 2017] [Originally Added On: September 7th, 2017]
- Microsoft just upped its multi-million bet on quantum computing - ZDNet [Last Updated On: September 7th, 2017] [Originally Added On: September 7th, 2017]
- Here's what quantum computing is and why it matters [Last Updated On: October 6th, 2017] [Originally Added On: October 6th, 2017]
- What will you actually use quantum computing for? | ZDNet [Last Updated On: October 11th, 2017] [Originally Added On: October 11th, 2017]
- Quantum Computing | Intel Newsroom [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- Intel Takes First Steps To Universal Quantum Computing [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- Qudits: The Real Future of Quantum Computing? - IEEE Spectrum [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- quantum computing - engadget.com [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- Quantum computing - news.microsoft.com [Last Updated On: November 1st, 2017] [Originally Added On: November 1st, 2017]
- IBM's processor pushes quantum computing ... - engadget.com [Last Updated On: November 16th, 2017] [Originally Added On: November 16th, 2017]
- Yale Professors Race Google and IBM to the First Quantum ... [Last Updated On: November 16th, 2017] [Originally Added On: November 16th, 2017]
- Quantum Computing Is the Next Big Security Risk | WIRED [Last Updated On: December 8th, 2017] [Originally Added On: December 8th, 2017]
- Microsoft offers developers a preview of its quantum ... [Last Updated On: December 12th, 2017] [Originally Added On: December 12th, 2017]
- New silicon structure opens the gate to quantum computers [Last Updated On: December 14th, 2017] [Originally Added On: December 14th, 2017]
- Quantum Computing Explained | What is Quantum Computing? [Last Updated On: December 21st, 2017] [Originally Added On: December 21st, 2017]
- What is Quantum Computing? | SAP News Center [Last Updated On: December 23rd, 2017] [Originally Added On: December 23rd, 2017]
- Is Quantum Computing an Existential Threat to Blockchain ... [Last Updated On: December 25th, 2017] [Originally Added On: December 25th, 2017]
- IBM puts its quantum computer to work in relaxing, nerdy ASMR ... [Last Updated On: January 8th, 2018] [Originally Added On: January 8th, 2018]
- Quantum computing is going to change the world. Here's what ... [Last Updated On: January 8th, 2018] [Originally Added On: January 8th, 2018]
- The Era of Quantum Computing Is Here. Outlook: Cloudy ... [Last Updated On: January 26th, 2018] [Originally Added On: January 26th, 2018]
- What is quantum computing? - Definition from WhatIs.com [Last Updated On: February 5th, 2018] [Originally Added On: February 5th, 2018]
- Senate bills would make quantum computing a priority [Last Updated On: June 10th, 2018] [Originally Added On: June 10th, 2018]
- Two Quantum Computing Bills Are Coming To Congress [Last Updated On: July 5th, 2018] [Originally Added On: July 5th, 2018]
- Quantum Computing Market Research Report- Forecast 2022 | MRFR [Last Updated On: August 1st, 2018] [Originally Added On: August 1st, 2018]
- What Is Quantum Computing? The Complete WIRED Guide | WIRED [Last Updated On: August 22nd, 2018] [Originally Added On: August 22nd, 2018]
- Quantum Computing | USRA [Last Updated On: August 30th, 2018] [Originally Added On: August 30th, 2018]
- The quantum computing race the US cant afford to lose [Last Updated On: September 3rd, 2018] [Originally Added On: September 3rd, 2018]
- The reality of quantum computing could be just three years ... [Last Updated On: September 12th, 2018] [Originally Added On: September 12th, 2018]
- US takes first step toward a quantum computing workforce ... [Last Updated On: September 17th, 2018] [Originally Added On: September 17th, 2018]
- China bet big on quantum computing. Now the ... - money.cnn.com [Last Updated On: September 17th, 2018] [Originally Added On: September 17th, 2018]
- China bet big on quantum computing. Now the US races to ... [Last Updated On: October 26th, 2018] [Originally Added On: October 26th, 2018]
- A new type of quantum computer has smashed every record ... [Last Updated On: December 21st, 2018] [Originally Added On: December 21st, 2018]
- IBM unveils its first commercial quantum computer [Last Updated On: January 9th, 2019] [Originally Added On: January 9th, 2019]
- IBM thinks outside of the lab, puts quantum computer in a box [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Quantum Computing | The MIT Press [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- CES 2019: IBM's Q System One Is the Rock Star Quantum ... [Last Updated On: January 13th, 2019] [Originally Added On: January 13th, 2019]