|
||
Cybersecurity agencies from the Group of Seven are urging governments and businesses to begin preparing now for the migration away from public-key cryptography vulnerable to future quantum computers, warning that the transition will require years of coordinated work across digital infrastructure.
The G7 Cybersecurity Working Group’s September 3 call to action says organizations should treat the quantum threat as a near-term security problem rather than wait for a cryptographically relevant quantum computer to emerge. The group includes national cybersecurity authorities from the G7 countries, with participation from the European Commission and support from ENISA.
The immediate risk includes data being collected today for decryption later. The agencies highlight “harvest now, decrypt later” attacks, in which adversaries retain encrypted information until sufficiently capable quantum computers become available. They also warn that quantum attacks on public-key cryptography could undermine authentication, allowing attackers to impersonate trusted parties or forge digitally signed information.
The group recommends a phased, risk-based migration. Organizations should inventory where cryptography is used, identify critical systems and long-lived sensitive data, map dependencies, establish governance and budgets, and build cryptographic agility so algorithms can be replaced without redesigning entire systems. The September appeal builds on more detailed G7 migration guidance published earlier this year.
For Internet infrastructure, the problem extends well beyond encrypted web traffic. Public-key cryptography underpins authentication and signatures across TLS and certificate infrastructures as well as DNSSEC and the Resource Public Key Infrastructure used in routing security. The IETF’s RFC 9958, published in June, says protocols and infrastructure using today’s public-key algorithms will need to transition to post-quantum alternatives.
That transition is already reaching Internet standards work. An active DNSSEC proposal is examining how to accommodate post-quantum signatures without imposing their substantially larger sizes throughout signed DNS zones. Separate RPKI experiments are testing post-quantum and composite signatures and measuring their effects on certificates, route-origin authorizations, repositories and distribution mechanisms. Both remain works in progress rather than deployed standards.
TLS migration has moved further ahead. In August, the IETF published RFC 10024, defining three hybrid post-quantum/traditional key-agreement mechanisms for TLS 1.3 that combine ML-KEM with conventional elliptic-curve exchanges. Work on post-quantum certificate authentication continues separately.
The G7 agencies do not specify when a quantum computer capable of defeating today’s public-key systems will arrive. Their argument is instead that uncertainty about that date does not remove the migration deadline: cryptographic inventories, standards, software upgrades and interdependent infrastructure transitions have to be completed before such a machine becomes operational.
Sponsored byCSC
Sponsored byRadix
Sponsored byDNIB.com
Sponsored byVerisign
Sponsored byWhoisXML API
Sponsored byIPv4.Global
Sponsored byVerisign