Site navigation

NCSC: How to Secure Data From Quantum Computer Attacks

Michael Edgar

,

Quantum computer NCSC
The UK’s National Cyber Security Centre (NCSC) releases comprehensive guidance on post-quantum cryptography migration. 

In a bid to help organisations transition to post-quantum cryptography (PQC), the NCSC has provided key insights into how security leaders can do this within enterprises. 

PQC refers to the process of implementing cryptographic algorithms and systems that are resilient to attacks from quantum computers. As it stands, quantum computers have the potential to break widely used encryption methods such as those based on integer factorisation and discrete logarithms, much faster than classical computers. 

The new guidance suggests the following: 

  • PQC Upgrades in Technology Refresh Cycles: Organisations are encouraged to plan PQC upgrades to coincide with regular technology refresh cycles.
  • NIST-Selected Algorithms for General Use: The ML-KEM (Kyber) and ML-DSA (Dilithium) algorithms, chosen by NIST for standardisation, are suitable for general-purpose use. These algorithms offer an acceptable level of security for personal, enterprise, and Official-tier government information.
  • Recommended Security Levels: The NCSC recommends ML-KEM-768 and ML-DSA-65 as they provide suitable levels of security and efficiency for most use cases.
  • Use Final Standards: Operational systems should exclusively use implementations based on final standards.
  • Hybrid Key Establishment Scheme: Combining a PQC key establishment algorithm with a traditional key establishment algorithm for a PQ/T hybrid key establishment scheme should only be considered as an interim step towards full PQC adoption.

Recommended


Although viable quantum computers are still a number of years away from practical use, lawmakers and industry bodies have been diligently preparing for the upcoming threat. 

The NCSC emphasised the potential threat from cryptographically-relevant quantum computers (CRQC), which could encrypt data collected and stored by attackers in the past. This would present a concern for organisations looking for long-term cryptographic protection for its high value data. 

Quantum computers could also be used to forge digital signatures, allowing attackers to impersonate private key owners and tamper with digitally signed information, according to the NCSC.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data