Quantum computing's escalating ability to break today's encryption algorithms prompts urgent shifts in internet security protocols. Tim Hudson, President of OpenSSL Corporation, outlines the challenges and strategic responses necessary for businesses to adapt to a post-quantum world.

  • Quantum threats require architectural changes, not just bandwidth upgrades.
  • Hybrid post-quantum key exchange is already in use, but post-quantum signatures remain challenging.
  • Businesses must inventory cryptographic assets and prioritize agility over fixed 'quantum-safe' algorithms.

What happened

Quantum computing is advancing toward a capability where it can break commonly used encryption methods in hours or days, drastically shortening the time needed to decrypt data previously considered secure. This development threatens the foundation of internet security, compelling cybersecurity communities to develop and deploy post-quantum cryptographic solutions. OpenSSL, a major open-source cryptographic library, is actively working on integrating post-quantum cryptography into everyday online interactions to safeguard billions of connections.

Current efforts have successfully implemented hybrid post-quantum key agreements in popular browsers and content delivery networks, enabling users to benefit from quantum-resistant exchanges without disruption. However, while key exchange protocols have seen progress, post-quantum digital signatures remain an unresolved challenge due to the substantial increase in data size and complexity they introduce.

Why it matters

The introduction of post-quantum encryption methods significantly increases handshake data sizes during secure connections, potentially causing network congestion, increased latency, and degraded performance—especially affecting mobile, satellite, and bandwidth-constrained environments. The problem isn’t merely bandwidth capacity but the architectural limits within protocols like QUIC that regulate connection amplification and initial congestion thresholds.

Addressing these issues requires fundamental redesigns of the public key infrastructure (PKI), such as implementing Merkle Tree Certificates and new trust anchor negotiation methods. These changes aim to streamline certificate chains and reduce handshake overhead rather than simply improving network pipes or upgrading cryptographic libraries. This architectural approach is crucial for maintaining efficiency and security in an increasingly post-quantum internet environment.

What to watch next

Businesses and organizations should prioritize creating detailed inventories of their cryptographic assets—a 'cryptographic bill of materials'—to understand their exposure and prepare migration plans. This discovery and scoping phase can take six to twelve months and is becoming a regulatory expectation. Without proper inventory and planning, budgeting an effective quantum-safe migration is impossible.

Investment focus is shifting towards agility in cryptographic infrastructure to enable seamless algorithm updates and adaptability rather than buying fixed 'quantum-safe' solutions that may become obsolete. Organizations that build flexible environments capable of adjusting to evolving post-quantum standards will better withstand future threats as quantum cryptography continues to evolve.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings