Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition

被引:0
|
作者
Baseri, Yaser [1 ]
Chouhan, Vikas [2 ]
Ghorbani, Ali [2 ]
Chow, Aaron [3 ]
机构
[1] Univ Montreal, Dept Comp Sci & Operat Res, Montreal, PQ, Canada
[2] Univ New Brunswick, Canadian Inst Cybersecur CIC, Fredericton, NB, Canada
[3] Scotiabank, Toronto, ON, Canada
关键词
Quantum security; Risk assessment; Quantum-safe migration; STRIDE threat analysis; CYBERSECURITY;
D O I
10.1016/j.cose.2024.104272
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rise of large-scale quantum computing poses a significant threat to traditional cryptographic security measures. Quantum attacks, particularly targeting the mathematical foundations of current asymmetric cryptographic algorithms, render them ineffective. Even standard symmetric key cryptography is susceptible, albeit to a lesser extent, with potential security enhancements through longer keys or extended hash function outputs. Consequently, the cryptographic solutions currently employed to safeguard data will be inadequately secure and vulnerable to emerging quantum technology threats. In response to this impending quantum menace, organizations must chart a course towards quantum-safe environments, demanding robust business continuity plans and meticulous risk management throughout the migration process. This study provides an in-depth exploration of the challenges associated with migrating from a non-quantum-safe cryptographic state to one resilient against quantum threats. We introduce a comprehensive security risk assessment framework that scrutinizes vulnerabilities across algorithmic, certificate, and protocol layers, covering the entire migration journey, including pre-migration, through-migration, and post-migration stages. Our methodology links identified vulnerabilities to the well-established STRIDE threat model, establishing precise criteria for evaluating their potential impact and likelihood throughout the migration process. Moving beyond theoretical analysis, we address vulnerabilities practically, especially within critical components like cryptographic algorithms, public key infrastructures, and network protocols. Our study not only identifies potential attacks and vulnerabilities at each layer and migration stage but also suggests possible countermeasures and alternatives to enhance system resilience, empowering organizations to construct a secure infrastructure for the quantum era. Through these efforts, we establish the foundation for enduring security in networked systems amid the challenges of the quantum era.
引用
收藏
页数:31
相关论文
共 50 条
  • [1] Navigating quantum security risks in networked environments: A comprehensive study of quantum-safe network protocols
    Baseri, Yaser
    Chouhan, Vikas
    Hafid, Abdelhakim
    COMPUTERS & SECURITY, 2024, 142
  • [2] ESPQ: Quantum-Safe Encapsulation Security Payload
    Khorkheli, L.
    Bourne, D.
    Satrya, G. B.
    2024 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING, BLACKSEACOM 2024, 2024, : 263 - 267
  • [3] Challenges in the Transition towards a Quantum-safe Government
    Kong, Ini I.
    Janseen, Marijn M.
    Bharosa, Nitesh N.
    PROCEEDINGS OF THE 23RD ANNUAL INTERNATIONAL CONFERENCE ON DIGITAL GOVERNMENT RESEARCH, DGO 2022: Intelligent Technologies, Governments and Citizens, 2022, : 282 - 292
  • [4] The Quantum-Safe Revolution
    Faugere, Jean-Charles
    Perret, Ludovic
    INFORMATION SECURITY APPLICATIONS, WISA 2016, 2017, 10144 : 258 - 266
  • [5] Advancing Network Security with Quantum-Safe System Integration
    Mao, Jianzhou
    Xu, Guobin
    Sakk, Eric
    Wang, Shuangbao
    2024 33RD INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, ICCCN 2024, 2024,
  • [6] Quantum-safe encryption
    Floeter, Rouven
    ABB Review, 2018, (03): : 62 - 63
  • [7] Navigating Through the Unknowns-Organizational Readiness Assessment Model for Quantum-Safe Transition
    Kong, Ini
    Janssen, Marijn
    Bharosa, Nitesh
    ELECTRONIC GOVERNMENT, EGOV 2024, 2024, 14841 : 438 - 453
  • [8] Quantum-Safe Internet of Things
    Chattopadhyay, Anupam
    Bhasin, Shivam
    Gueneysu, Tim
    Bhunia, Swarup
    IEEE DESIGN & TEST, 2024, 41 (05) : 36 - 45
  • [9] Quantum-safe Trust for Vehicles
    Gardiner, Michael
    Truskovsky, Alexander
    Neville-Neil, George
    Mashatan, Atefeh
    Queue, 2021, 19 (02): : 93 - 115
  • [10] Quantum permutation pad for universal quantum-safe cryptography
    Kuang, Randy
    Barbeau, Michel
    QUANTUM INFORMATION PROCESSING, 2022, 21 (06)