Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition

被引:0
|
作者
Baseri, Yaser [1 ]
Chouhan, Vikas [2 ]
Ghorbani, Ali [2 ]
Chow, Aaron [3 ]
机构
[1] Univ Montreal, Dept Comp Sci & Operat Res, Montreal, PQ, Canada
[2] Univ New Brunswick, Canadian Inst Cybersecur CIC, Fredericton, NB, Canada
[3] Scotiabank, Toronto, ON, Canada
关键词
Quantum security; Risk assessment; Quantum-safe migration; STRIDE threat analysis; CYBERSECURITY;
D O I
10.1016/j.cose.2024.104272
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rise of large-scale quantum computing poses a significant threat to traditional cryptographic security measures. Quantum attacks, particularly targeting the mathematical foundations of current asymmetric cryptographic algorithms, render them ineffective. Even standard symmetric key cryptography is susceptible, albeit to a lesser extent, with potential security enhancements through longer keys or extended hash function outputs. Consequently, the cryptographic solutions currently employed to safeguard data will be inadequately secure and vulnerable to emerging quantum technology threats. In response to this impending quantum menace, organizations must chart a course towards quantum-safe environments, demanding robust business continuity plans and meticulous risk management throughout the migration process. This study provides an in-depth exploration of the challenges associated with migrating from a non-quantum-safe cryptographic state to one resilient against quantum threats. We introduce a comprehensive security risk assessment framework that scrutinizes vulnerabilities across algorithmic, certificate, and protocol layers, covering the entire migration journey, including pre-migration, through-migration, and post-migration stages. Our methodology links identified vulnerabilities to the well-established STRIDE threat model, establishing precise criteria for evaluating their potential impact and likelihood throughout the migration process. Moving beyond theoretical analysis, we address vulnerabilities practically, especially within critical components like cryptographic algorithms, public key infrastructures, and network protocols. Our study not only identifies potential attacks and vulnerabilities at each layer and migration stage but also suggests possible countermeasures and alternatives to enhance system resilience, empowering organizations to construct a secure infrastructure for the quantum era. Through these efforts, we establish the foundation for enduring security in networked systems amid the challenges of the quantum era.
引用
收藏
页数:31
相关论文
共 50 条
  • [41] Quantum-safe cryptography: crossroads of coding theory and cryptography
    Jiabo Wang
    Ling Liu
    Shanxiang Lyu
    Zheng Wang
    Mengfan Zheng
    Fuchun Lin
    Zhao Chen
    Liuguo Yin
    Xiaofu Wu
    Cong Ling
    Science China Information Sciences, 2022, 65
  • [42] A Matrix Multiplication Approach to Quantum-Safe Cryptographic Systems
    Lizama-Perez, Luis Adrian
    CRYPTOGRAPHY, 2024, 8 (04)
  • [44] Aggregable Confidential Transactions for Efficient Quantum-Safe Cryptocurrencies
    Alupotha, Jayamine
    Boyen, Xavier
    Mckague, Matthew
    IEEE ACCESS, 2022, 10 : 17722 - 17747
  • [45] Integrating and Evaluating Quantum-safe TLS in Database Applications
    Tueno, Anselme
    Boehm, David
    Choe, Shin Ho
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXVI, DBSEC 2022, 2022, 13383 : 259 - 278
  • [46] Experimental Integration of Quantum Key Distribution and Post-Quantum Cryptography in a Hybrid Quantum-Safe Cryptosystem
    Garms, Lydia
    Paraiso, Taofiq K.
    Hanley, Neil
    Khalid, Ayesha
    Rafferty, Ciara
    Grant, James
    Newman, James
    Shields, Andrew J.
    Cid, Carlos
    O'Neill, Maire
    ADVANCED QUANTUM TECHNOLOGIES, 2024, 7 (04)
  • [47] HQsFL: A Novel Training Strategy for Constructing High-performance and Quantum-safe Federated Learning
    Yu, Bo
    Shen, Huajie
    Xu, Qian
    He, Wei
    Mao, Wankui
    Zhang, Qing
    Zhang, Fan
    PROCEEDINGS OF THE 19TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ACM ASIACCS 2024, 2024, : 512 - 521
  • [48] Quantum-Safe Metro Network With Low-Latency Reconfigurable Quantum Key Distribution
    Tang, Xinke
    Wonfor, Adrian
    Kumar, Rupesh
    Penty, Richard, V
    White, Ian H.
    JOURNAL OF LIGHTWAVE TECHNOLOGY, 2018, 36 (22) : 5230 - 5236
  • [49] Towards a quantum-safe 5G: Quantum Key Distribution in core networks
    Atutxa, Asier
    Sanz, Ane
    Sasiain, Jorge
    Astorga, Jasone
    Jacob, Eduardo
    COMPUTER COMMUNICATIONS, 2024, 224 : 145 - 158
  • [50] Establishment and performance evaluation of quantum-safe 5G fronthaul optical architecture
    Tian, Yuyuan
    Xin, Fengming
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 110