{"id":17409,"date":"2023-11-13T16:32:38","date_gmt":"2023-11-13T21:32:38","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=17409"},"modified":"2025-03-21T14:07:07","modified_gmt":"2025-03-21T18:07:07","slug":"key-takeaways-from-the-second-pki-consortium-post-quantum-cryptography-conference","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/key-takeaways-from-the-second-pki-consortium-post-quantum-cryptography-conference\/","title":{"rendered":"Key Takeaways from the Second PKI Consortium Post-Quantum Cryptography Conference"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"from-how-specific-cryptographic-algorithms-work-to-how-countries-are-working-to-face-down-looming-quantum-threats-the-november-2023-conference-covered-many-topics-we\u2019ve-got-9-key-insights-and-takeaways-to-share\">From how specific cryptographic algorithms work to how countries are working to face down looming quantum threats, the November 2023 conference covered many topics. We\u2019ve got 9 key insights and takeaways to share&#8230;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In early November, public and private cybersecurity and cryptography experts worldwide gathered in Amsterdam to share their insights and updates about quantum-resistant (quantum-safe) cryptography at the <a href=\"https:\/\/pkic.org\/\">PKI Consortium<\/a>\u2019s latest conference. Some presentations focused on the technical details of PQC cryptographic algorithms and schemes, while others talked about the considerations surrounding the implementation of quantum-safe cryptography in specific environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The PKI Consortium is a non-profit organization comprising 100+ public and private member organizations (governments, certificate authorities, auditors, service providers, consultants, etc.) from around the world. This event marked the PKI Consortium\u2019s second PQC conference, the <a href=\"https:\/\/pkic.org\/events\/2023\/post-quantum-cryptography-conference\/\">first<\/a> of which was hosted in Ottawa in Ontario, Canada. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since we figured most of our readers didn\u2019t get to make the trip to the Netherlands or want to get up as early as 3 a.m. to tune in remotely, we\u2019ve put together a breakdown of some of the key takeaways and lessons we learned from this year\u2019s sessions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">What we&#8217;re hashing out&#8230;<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#from-how-specific-cryptographic-algorithms-work-to-how-countries-are-working-to-face-down-looming-quantum-threats-the-november-2023-conference-covered-many-topics-we\u2019ve-got-9-key-insights-and-takeaways-to-share\">From how specific cryptographic algorithms work to how countries are working to face down looming quantum threats, the November 2023 conference covered many topics. We\u2019ve got 9 key insights and takeaways to share&#8230;<\/a><ol><\/ol><\/li><li><a href=\"#an-overview-of-the-top-concerns-haunting-organizations-regarding-pqc-implementation\">An Overview of the Top Concerns Haunting Organizations Regarding PQC Implementation<\/a><ol><\/ol><\/li><li><a href=\"#top-9-takeaways-for-public-and-private-sector-stakeholders\">Top 9 Takeaways For Public and Private Sector Stakeholders<\/a><ol><li><a href=\"#1-we-need-to-stop-calling-it-\u201cpost-quantum\u201d-cryptography\">1. We Need to Stop Calling It \u201cPost-Quantum\u201d Cryptography<\/a><ol><\/ol><\/li><li><a href=\"#2-quantum-computing-is-something-to-start-planning-amp;-preparing-for-now-using-hybrid-cryptography\">2. Quantum Computing Is Something to Start Planning &amp; Preparing For Now Using Hybrid Cryptography<\/a><ol><\/ol><\/li><li><a href=\"#3-a-cryptographic-inventory-and-risk-analysis-are-the-first-steps-to-pqc-readiness-amp;-agility\">3. A Cryptographic Inventory and Risk Analysis Are the First Steps to PQC Readiness &amp; Agility<\/a><ol><li><a href=\"#where-does-pki-come-into-play-in-all-of-this\">Where Does PKI Come Into Play in All of This?<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#4-nist\u2019s-first-pqc-standards-are-coming-in-early-2024\">4. NIST\u2019s First PQC Standards Are Coming in Early 2024<\/a><ol><\/ol><\/li><li><a href=\"#5-being-crypto-agile-is-crucial-and-is-everyone\u2019s-responsibility\">5. Being Crypto-Agile Is Crucial and Is Everyone\u2019s Responsibility<\/a><ol><\/ol><\/li><li><a href=\"#6-by-and-large-cisos-won\u2019t-adopt-pqc-until-they-have-to\">6. By and Large, CISOs Won\u2019t Adopt PQC Until They Have To&nbsp;<\/a><ol><\/ol><\/li><li><a href=\"#7-take-a-stealth-approach-to-get-funding-and-support-of-your-pqc-initiatives\">7. Take a Stealth Approach to Get Funding and Support of Your PQC Initiatives<\/a><ol><\/ol><\/li><li><a href=\"#8-businesses-want-financial-incentives-to-become-early-adopters\">8. Businesses Want Financial Incentives to Become Early Adopters<\/a><ol><\/ol><\/li><li><a href=\"#9-pqc-progress-requires-significant-collaboration-between-global-regions-and-industries\">9. PQC Progress Requires Significant Collaboration Between Global Regions and Industries<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#final-thoughts-on-the-insights-shared-at-the-pkic-pqc-forum\">Final Thoughts on the Insights Shared at the PKIC PQC Forum<\/a><ol><\/ol><\/li><\/ol><\/div>\n\n\n<span style=\"--tl-form-height-m:149.594px;--tl-form-height-t:120.9844px;--tl-form-height-d:120.9844px;\" class=\"tl-placeholder-f-type-shortcode_18369 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"an-overview-of-the-top-concerns-haunting-organizations-regarding-pqc-implementation\">An Overview of the Top Concerns Haunting Organizations Regarding PQC Implementation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before we dive into all of the top takeaways from this year\u2019s conference, let\u2019s quickly go over some of the key challenges that industry experts say organizations face when preparing for post-quantum cryptography.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, this is only a handful of the challenges that public and private sector organizations may experience in the journey to a post-quantum world. Now, it\u2019s time to explore some of the takeaways global industry leaders shared during the 2023 PQC conference.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"top-9-takeaways-for-public-and-private-sector-stakeholders\">Top 9 Takeaways For Public and Private Sector Stakeholders<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"1-we-need-to-stop-calling-it-\u201cpost-quantum\u201d-cryptography\">1. We Need to Stop Calling It \u201cPost-Quantum\u201d Cryptography<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Using a term like \u201cpost-quantum cryptography\u201d doesn\u2019t drive home the urgency of transitioning from quantum-insecure to quantum-resistant cryptography. The actual verbiage is still contested within the industry, though, as some experts refer to it as <em>PQC<\/em> while others call it \u201cquantum-resistant\u201d or \u201cquantum-safe\u201d cryptography.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chris Hickman, Chief Security Officer at <a href=\"https:\/\/www.keyfactor.com\/\">KeyFactor<\/a> who presented and participated in one of the conference\u2019s panel discussions, described the term \u201cpost-quantum\u201d cryptography as the biggest disservice industry professionals did to themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis is an evolution of security, and we really need to start thinking of it in those terms,\u201d said Hickman, who said that organizations need to start thinking through the security needs regarding these vastly different technologies now and not when quantum computers are widely available. He pointed out that the industry has been relying on the same technologies for several decades and that enough is enough. \u201cWhat else has lasted for 40 years in IT, period? Not a lot. Security-wise, not a lot.\u201d<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cSo, I think, yeah, things are going to take on their own life cycle and their own trajectory because organizations are going to start to realize that this is simply an evolution. This is the next step.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>No, we\u2019ve never been through this; yes, it\u2019s going to be painful. Are we going to stumble along the way? Organizations will stumble along the way, that\u2019s without question. But the thing that we can do here is help explain the best ways to do that, the ways to mitigate the risk, how to look at it from risk management standpoint. I think that\u2019s a very smart way to look at it.\u201d <\/em><\/p>\n<cite><strong>\u2014 Chris Hickman, Chief Security Officer at KeyFactor<\/strong><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Hickman\u2019s sentiments are shared by other industry experts, including Tim Hollebeek, <a href=\"https:\/\/www.digicert.com\/\">DigiCert<\/a>\u2019s Industry Technical Strategist. <a href=\"https:\/\/www.linkedin.com\/posts\/timothy-hollebeek-505b814_heres-another-one-post-quantum-cryptography-activity-7107732767337021441-wC1V\/\">He recommends<\/a> referring to it as \u201cquantum-safe cryptography\u201d instead.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe problem with the term post-quantum cryptography is that it is easy to misunderstand as something you don\u2019t need to do until cryptographically relevant quantum computers (CRQCs) arrive, which that\u2019s the exact opposite of true.\u201d&nbsp;<\/em><\/p>\n<cite><strong>\u2014 Tim Hollebeek, Industry Technical Strategist at <\/strong><a href=\"https:\/\/www.digicert.com\/\"><strong>DigiCert<\/strong><\/a><\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"2-quantum-computing-is-something-to-start-planning-amp;-preparing-for-now-using-hybrid-cryptography\">2. Quantum Computing Is Something to Start Planning &amp; Preparing For Now Using Hybrid Cryptography<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A theme that was repeated throughout the two-day conference is that you can (and should) start planning and preparing for PQC rather than waiting. If you wait, you\u2019ll already be too late. While saying companies should start planning and preparing is all well and good, but it leaves us with two important questions:<\/p>\n\n\n\n<ol style=\"list-style-type:1\" class=\"wp-block-list\">\n<li>How do we start preparing?<\/li>\n\n\n\n<li>And how soon do we need to do so?<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">One of the things highlighted by many speakers was having a hybrid quantum security strategy. The benefit of using PQC hybrid algorithms in your approach is that they still support the \u201cclassical\u201d algorithms that are necessary to fight modern threats while also using PQC algorithms to protect data against \u201charvest now, decrypt later\u201d attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means bad guys would have to break two cryptosystems in order to compromise data. This protects you while in the transition period when we\u2019re not sure about whether the new PQC algorithms will work as intended. (After all, we\u2019ve seen a number of NIST candidate algorithms being broken over the past several years using modern computers.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll talk more about the answer to the first question in just a moment. But as far as the answer to question #2 is concerned: start planning now. Quantum computers are becoming more advanced, and companies are working on \u201cnoise reduction\u201d to help facilitate more powerful machines that require fewer qubits to operate. So, what does this mean for organizations with regard to when they need to start getting their ducks in a row?<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>&#8220;The main thing is, don\u2019t wait. Well, we <strong>do<\/strong> want you to wait for the final standards. So, you can test out the algorithms now. You can get ready. Wait for the final standards to begin actually putting these into products. But for planning purposes, don\u2019t wait to think about your migration \u2013 start getting ready for that.\u201d <\/em><\/p>\n<cite><strong>\u2013 Dustin Moody, Mathematician &amp; Project Lead, Post-Quantum Cryptography at the <\/strong><a href=\"https:\/\/nist.gov\/\"><strong>National Institute of Standard and Technology (NIST)<\/strong><\/a><\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"3-a-cryptographic-inventory-and-risk-analysis-are-the-first-steps-to-pqc-readiness-amp;-agility\">3. A Cryptographic Inventory and Risk Analysis Are the First Steps to PQC Readiness &amp; Agility<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">By and large, organizations are clueless about where and how they\u2019re using cryptography within their networks and IT infrastructure. In some cases, the uses are internal; other times, they\u2019re provided through third-party services and software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the key thing to remember is that if you don\u2019t know what cryptographic assets you have or where they are, then you can\u2019t identify your risks, and if you can\u2019t do that, then you don\u2019t know what you need to mitigate them.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Creating an inventory of cryptographic assets and vulnerabilities.<\/strong> This involves using automated scanning tools and manual scanning methods to catch what they miss.<\/li>\n\n\n\n<li><strong>Perform quantum risk analysis on top of your standard risk analysis.<\/strong> This will provide you with greater insights into the PQ vulnerabilities within your network and IT environment.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The next step is to prioritize where you want to start taking action and make preparations for \u201cQ Day.\u201d But how do you do that if you don\u2019t know where your organization currently stands? This question is one Tom Patterson, Quantum Security Global Lead at <a href=\"https:\/\/www.accenture.com\/\">Accenture<\/a>, says he wants to help organizations globally figure out via a Quantum Security Maturity Index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patterson said the concept is similar to the Capability Maturity Model Integration (CMMI) in that it gives company boards and executives a way to measure where they are and see how far they still have left to go. If they\u2019re at level 2 and want to be at level 3, what money and time would they need to invest?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">His company is working with organizations across the world in multiple sectors to create standardized definitions relating to PQC adoption and maturity. The PQC journey the company has outlined currently has eight PQC maturity tiers that are part of Accenture\u2019s program:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"460\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/accenture-presentation-quantum-defense-maturity-levels-1024x460.png\" alt=\"A screenshot from an Accenture slideshow that shows an example of eight maturity tiers outlined for the financial sector\" class=\"wp-image-17412\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/accenture-presentation-quantum-defense-maturity-levels-1024x460.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/accenture-presentation-quantum-defense-maturity-levels-300x135.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/accenture-presentation-quantum-defense-maturity-levels-768x345.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/accenture-presentation-quantum-defense-maturity-levels-1536x691.png 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/accenture-presentation-quantum-defense-maturity-levels-2048x921.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot from Tom Patterson\u2019s presentation at the PKI Consortium on behalf of Accenture.<\/em><\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"590\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/quantum-maturity-index-domains-levels-accenture-1024x590.png\" alt=\"A screenshot from an Accenture slideshow that shows eight index domains and levels, as presented by Tom Patterson\" class=\"wp-image-17413\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/quantum-maturity-index-domains-levels-accenture-1024x590.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/quantum-maturity-index-domains-levels-accenture-300x173.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/quantum-maturity-index-domains-levels-accenture-768x442.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/quantum-maturity-index-domains-levels-accenture.png 1129w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A second screenshot from Tom Patterson\u2019s (Accenture) presentation at the PKI Consortium\u2019s PQC Conference.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cI\u2019m just trying to drive the process so that there\u2019s standardized definitions about adoption and maturity,\u201d said Patterson. \u201cIf you can\u2019t measure it, you can\u2019t protect it.\u2019\u201d<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"where-does-pki-come-into-play-in-all-of-this\">Where Does PKI Come Into Play in All of This?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s a good question \u2014 one Patterson hopes organizations will help him answer. After all, having a robust and PQC-safe PKI requires more than just swapping out a few existing assets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cBecause PKI is so robust in its current state, you can\u2019t just tinker with it,\u201d says Tom Patterson. Instead:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cWe talk about how it is highly sophisticated and highly integral to their operations today, and just changing over from one HSM to another, and from one piece to another, from one certificate to another certificate. That\u2019s not the answer. That\u2019s not how it\u2019s going to work.<\/em>&#8220;<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Changing the underlying foundation of internet security \u2014 all of the technologies, protocols, policies, and other components that make up public key infrastructure (PKI) \u2014 is a process Patterson says will take place over \u201cmany years going forward.\u201d But if an agreed-upon maturity index is created through collaboration across organizations in various sectors, it\u2019ll improve the overall quantum defenses of the world as a whole.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He put out a call for \u201cvolunteers\u201d of sorts; organizations that want to participate in the process and help identify areas and specific steps to build out. Accenture is planning to unveil the results of this collaborative effort to the world at the World Economic Forum in January 2024.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\" id=\"4-nist\u2019s-first-pqc-standards-are-coming-in-early-2024\">4. NIST\u2019s First PQC Standards Are Coming in Early 2024<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Since 2016, the National Institute of Standards and Technology (NIST) has been engaged with the cryptographic community in a \u201ccompetition\u201d to create quantum-resistant cryptographic algorithms. (This isn\u2019t a new approach, as RSA and other algorithms have been created in similar scenarios.) Although <a href=\"https:\/\/www.thesslstore.com\/blog\/nist-announces-2024-timeline-for-first-standardized-post-quantum-cryptography-pqc-algorithms\/\">NIST has released drafts of the first three PQC algorithms<\/a> for public comments, the federal standards organization is looking to publish the first official PQC standards early next year (2024).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two experts from NIST \u2014 Dustin Moody, Mathematician &amp; Project Lead, Post-Quantum Cryptography and Bill Newhouse, Cybersecurity Engineer &amp; Project Lead, National Cybersecurity Center of Excellence (NCCoE) \u2014 shared the ongoing process regarding the selection of PQC algorithms. Their update offered insights into the NIST PQC standardization process, how it\u2019s coming along, and practices to make migrating from quantum-vulnerable public-key cryptography to quantum-resistant cryptography a bit easier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a quick timeline of the NIST PQC process:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"531\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/timeline-nist-quantum-standards-initiative-1024x531.png\" alt=\"A screenshot of the NIST PQC standards competition timeline that was shown during a presentation by Dustin Moody and Bill Newhouse\" class=\"wp-image-17414\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/timeline-nist-quantum-standards-initiative-1024x531.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/timeline-nist-quantum-standards-initiative-300x155.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/timeline-nist-quantum-standards-initiative-768x398.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/timeline-nist-quantum-standards-initiative.png 1069w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot from the \u201cStatus Update from NIST\u201d presentation by Dustin Moody and Bill Newhouse (NIST).<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As of the writing of this article:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>NIST has completed four evaluation rounds for cryptographic algorithms.<\/li>\n\n\n\n<li>NIST opened a request for public comments in August (which are open until Nov. 22, 2023) on the first three drafts of the Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography:<ul><li><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/203\/ipd\">FIPS 203<\/a>: ML-KEM (Kyber)<\/li><\/ul><ul><li><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/204\/ipd\">FIPS 204<\/a>: ML-DSA (Dilithium)<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/205\/ipd\">FIPS 205<\/a>: SLH-DSA (SPHINCS+)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Additional signature schemes are still being considered.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This \u201csmall call\u201d for additional signatures, ideally based on code-based algorithms rather than lattice problems, aims to create greater diversity amongst the pool of PQC algorithms. The idea here is to have additional general-purpose signature schemes and those that have faster verification and shorter signatures for different use cases.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"5-being-crypto-agile-is-crucial-and-is-everyone\u2019s-responsibility\">5. Being Crypto-Agile Is Crucial and Is Everyone\u2019s Responsibility<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.digicert.com\/faq\/vulnerability-management\/what-is-crypto-agility\">Crypto-agility<\/a> is described by Germany\u2019s Federal Office for Information Security (BSI) as <a href=\"https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/EN\/BSI\/Publications\/Brochure\/quantum-safe-cryptography.pdf?__blob=publicationFile&amp;v=4\">a principle of keeping cryptographic mechanisms \u2018as flexible<\/a> as possible in order to react to developments, implement upcoming recommendations and standards, and possibly replace algorithms in the future that no longer guarantee the desired level of security.\u2019\u201d This also entails being able to use existing secure hardware and systems to meet the needs of new cryptographic algorithms and protocols without hindering performance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what do the experts say about crypto-agility in terms of what it represents and how it should be perceived?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cCrypto-agility begins with agile standards,\u201d said Jaime Gomez Garcia, Head of Quantum and Architecture at the Crypto and Blockchain CoE, <a href=\"https:\/\/www.santander.com\">Banco Santander<\/a>, who emphasized that it\u2019s constantly adapting and changing through collaboration. \u201cOur new cryptography standard isn\u2019t built as a Word document; it is built on GitHub.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bill Newhouse from NIST describes crypto-agility as a dream for public and private sector organizations alike. \u201cIt\u2019s a desire, and some of you have mapped out schemes to support this within your technologies to support this.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The overarching idea that many presenters reiterated is that everyone needs to keep cryptographic agility in mind when evaluating solutions. But Robert Hann, Global Vice President of Sales, Cryptographic Center of Excellence at Entrust, says that being crypto-agile is more than having the right tools in place:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cCrypto-agility is not just about tech; it involves people and processes. It\u2019s a process of change, and many organizations aren\u2019t good at changing cryptography because we\u2019ve never had to try. We haven\u2019t really been tested hard. We now are about to, so you\u2019ve absolutely got to build that in, in the solutions you buy, the software you develop.\u201d<\/em> <\/p>\n<cite><strong>\u2014 Robert Hann, Global Vice President of Sales, Cryptographic Center of Excellence at Entrust<\/strong><\/cite><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"6-by-and-large-cisos-won\u2019t-adopt-pqc-until-they-have-to\">6. By and Large, CISOs Won\u2019t Adopt PQC Until They Have To&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s no secret that organizations are seemingly dragging their feet when it comes to dedicating the time, people, and resources to preparing for the quantum threats to come. But when you consider the high amounts of stress and short tenures of most CISOs, it\u2019s easy to see why they view quantum threats as things to put off until \u201clater,\u201d even though they\u2019re not. Banco Santander\u2019s Garcia says that there\u2019s a growing need for a change of mindset and approach.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In his presentation on Comparing Strategies for Quantum-Safe Cryptography Adoption in Organizations, Garcia cited <a href=\"https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/EN\/BSI\/Crypto\/Marktumfrage_EN_Kryptografie_Quantencomputing.pdf\">research from KMPG and Germany\u2019s (BSI)<\/a> that shows the overwhelming majority of CISOs are waiting to take any real action until there are standards (89%) or regulatory requirements (96%) in place that force their hands. People are burned out on the \u201csky-is-falling\u201d messages they\u2019ve been hearing for decades.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cPeople are going to act when they\u2019re required to act. My conclusion is that risk-based messages do not work. They have not worked so far, and they will not work because we are talking about a threat that happens far in the future. So, we need to explain in a different way why things need to be done now.\u201d <\/em>&nbsp;<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">So, what\u2019s the alternative? Garcia pointed to an executive action that came out of the U.S. White House as an example (a memorandum on \u201c<a href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2022\/11\/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf\">Migrating to Post-Quantum Cryptography<\/a>\u201d). The document breaks down specific requirements that must be met within set periods. For example: \u201cWithin 30 days of the memorandum, agencies will designate a cryptographic inventory and migration lead for their organization.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The point is to create a sense of urgency and to show a way forward by outlining the preparatory steps that must be outlined within a limited period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider the high levels of stress amongst CISOs for all of the urgent items on their to-do lists that have short timespans. It\u2019s understandable (in some ways) why quantum preparations aren\u2019t at the top of the list. After all:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>94% of CISOs admit to being <a href=\"https:\/\/go.cynet.com\/ciso-stress-survey\">stressed at work<\/a>, and 65% say it compromises their job capabilities;<\/li>\n\n\n\n<li><a href=\"https:\/\/go.cynet.com\/hubfs\/Cynet%20-%20Implications%20of%20Stress%20on%20CISOs%202023%20Survey%20Report.pdf\">Three in four (77%) CISOs<\/a> admit that job-related stress is taking a toll on their physical and mental health; and<\/li>\n\n\n\n<li>CISOs are in their roles for a <a href=\"https:\/\/www.heidrick.com\/-\/media\/heidrickcom\/publications-and-reports\/2023-global-chief-information-security-officer-survey.pdf\">median period of 4 years<\/a> \u2014 meaning they\u2019ll be out of their roles significantly sooner than quantum computers are expected to arrive.<\/li>\n<\/ul>\n\n\n<span style=\"--tl-form-height-m:905.547px;--tl-form-height-t:998.172px;--tl-form-height-d:998.172px;\" class=\"tl-placeholder-f-type-shortcode_18375 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\" id=\"7-take-a-stealth-approach-to-get-funding-and-support-of-your-pqc-initiatives\">7. Take a Stealth Approach to Get Funding and Support of Your PQC Initiatives<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the key challenges I\u2019d mentioned earlier when organizations face when planning for and implementing PQC-focused initiatives is that they often lack the financial support of their boards and c-suite execs. Although CISOs and other IT\/cybersecurity professionals largely agree that quantum cryptography represents an opportunity to invest in new technologies and divest legacy systems, many of their organizations\u2019 leaders don\u2019t necessarily share that same opinion when it comes to supporting PQ initiatives with the companies\u2019 checkbooks.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cMany organizations are struggling to justify a project with no end date. Most projects have a compelling event:<\/em> \u2018<em>I have to go live by January 2024.\u2019 PQ\u2019s different. We don\u2019t know when we don\u2019t have to be live; we know roughly that we have to be ready by, probably, 2028, 2027 if we want to be a couple of years ahead of our adversary.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201c[\u2026] so if it\u2019s that kind of timeline, try justifying that to a board member by saying \u2018I think it\u2019s near the end of the decade\u2019 and they say, \u2018well, this other project is going to generate us more revenue, reduce our risks more, and so on\u2019 and they\u2019ll put their money there.\u201d <\/em><\/p>\n<cite><em><strong>\u2014 Robert Hann, Global Vice President of Sales, Cryptographic Center of Excellence at Entrust<\/strong><\/em><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Even though boards often view quantum computing as a priority, protecting their organizations against quantum-based threats doesn\u2019t seem to garner as much interest.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, what\u2019s the solution? Hann suggests taking a stealthy approach: start combining key aspects of your organization\u2019s PQC initiatives into other more timely and profitable priorities your execs favor. For example, tie it in with your <a href=\"https:\/\/www.thesslstore.com\/blog\/the-rise-of-zero-trust-threats-are-no-longer-perimeter-only-concerns\/\">zero-trust<\/a> strategy or AI strategy. Doing this helps the board set the goals and priorities they think matter most while enabling you to do what needs to be done to prepare for the quantum threats to come.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"8-businesses-want-financial-incentives-to-become-early-adopters\">8. Businesses Want Financial Incentives to Become Early Adopters<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most interesting points discussed at the conference was brought up by one of the audience members during an open forum discussion by Anita Wehmann, Senior Advisor Information Security at the Ministry of the Interior and Kingdom Relations (BZK) of the Netherlands and Germain van der Velden: Being a \u201cfirst mover\u201d is a risky venture. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019re bound to make mistakes that will cost your business money. If organizations and businesses are expected to take on the risks associated with being early adopters, shouldn\u2019t there be some financial incentive(s) for them to do so?&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAs this is such a global problem, there needs to be at least some clear incentive for \u2018first movers,\u2019\u201d said the unnamed forum participant.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cI think we need to at least get some clarity on that \u2013 whether there will be possibilities to support each other also in the form of financial perspective. So, not only knowledge and things like that, but really, enterprises have a financial aspect as well. [\u2026] The financial part should not be forgotten if you want to enfold enterprises into this integration path.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Regarding the concept of being an early adopter, Wehmann separately brought up an interesting point and question in a panel discussion near the end of the two-day conference: If the expectation from governments and industry leaders is that critical infrastructure organizations be among early adopters of PQC, isn\u2019t that, in some ways, counterintuitive to critical infrastructure security?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Critical infrastructure organizations have a longstanding history of being risk-averse. But if those organizations are among the first adopters of PQC, then they\u2019ll be the ones making the mistakes that could have potentially devastating results.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It seems to be a <em>damned if you do, damned if you don\u2019t<\/em> kind of situation. But what\u2019s the solution? As of right now, no one seems to have a definitive answer.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"9-pqc-progress-requires-significant-collaboration-between-global-regions-and-industries\">9. PQC Progress Requires Significant Collaboration Between Global Regions and Industries<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/blog\/researchers-are-moving-up-the-clock-for-q-day\/\">Quantum readiness<\/a> requires the best and brightest from around the world to come together for this shared cause. There have been significant collaborations between various agencies and research institutes across Europe, as well as with North America (U.S. and Canada). But even with those collaborations, there are different perspectives in terms of how we should approach this overarching goal, and even which algorithms should be used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While many presenters agree that there\u2019s already good collaboration going on between different countries\u2019 cryptographic experts, there\u2019s always room for growth and improvement. We need to connect more, coordinate better, and share more information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every initiative is valuable and has its own merits. We agree on many points, but there are nuances where different countries differ in terms of prioritizations and approaches.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"594\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/pki-consortium-pqc-conference-panel-discussion-screenshot-1024x594.png\" alt=\"A screenshot of five panelists and a moderator who participated in a Q&amp;A panel on Global Perspectives on PQC Governance.\" class=\"wp-image-17415\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/pki-consortium-pqc-conference-panel-discussion-screenshot-1024x594.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/pki-consortium-pqc-conference-panel-discussion-screenshot-300x174.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/pki-consortium-pqc-conference-panel-discussion-screenshot-768x445.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/pki-consortium-pqc-conference-panel-discussion-screenshot.png 1223w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot from the PKI Consortium\u2019s Q&amp;A expert panel discussion on Global Perspectives on Post-Quantum Cryptography Governance. From left: J\u00e9r\u00f4me Pl\u00fbt, ANSSI; Andrea Garcia Rodriguez, Lead Digital Policy Analyst at European Policy Centre (EPC); Bill Newhouse, Cybersecurity Engineer &amp; Project Lead, National Cybersecurity Center of Excellence (NCCoE) at NIST; Stephan Ehlen, The Federal Office for Information Security in Germany (BSI); Anita Wehmann, Senior Advisor Information Security at the Ministry of the Interior and Kingdom Relations (BZK) of the Netherlands; and Ronald Cramer, Head of Cryptography Group at CWI (moderator).<\/em><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"final-thoughts-on-the-insights-shared-at-the-pkic-pqc-forum\">Final Thoughts on the Insights Shared at the PKIC PQC Forum<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We hope that you\u2019ve found this article useful. From a non-cryptographer perspective, it was interesting to hear the different perspectives and earnest discussions that took place. Although some of the presentations left me with more questions than answers \u2014 for example, the intricacies of lattice-based algorithms \u2014 it\u2019s opened up a wealth of information and ideas that I (and possibly you) had not considered. &nbsp;&nbsp; Did you attend the conference (either in person or remotely, like me) and have additional takeaways to share? If so, we\u2019d love for you to share them in the comments below!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>From how specific cryptographic algorithms work to how countries are working to face down looming quantum threats, the November 2023 conference covered many topics. We\u2019ve got 9 key insights and&#8230;<\/p>\n","protected":false},"author":17,"featured_media":17411,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16,10200],"tags":[13259,241,240],"class_list":["post-17409","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","category-monthly-digest","tag-pki-consortium","tag-post-quantum-cryptography","tag-quantum-computing","post-with-tags"],"views":10014,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/11\/pki-consortium-pqc-conference-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17409","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=17409"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17409\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/17411"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=17409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=17409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=17409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}