Quantum computing poses a looming threat to current authentication systems, with the potential to break widely used cryptographic algorithms. For banks and fintech companies, this risk is not just technical-it strikes at the heart of customer trust and regulatory compliance. The industry faces a race against time to prepare for “Q-Day,” when quantum attacks become a reality
The transition to post-quantum authentication (PQA) is both urgent and complex. Modern cryptographic methods such as hybrid algorithms and cryptoagility are essential to safeguard data now and in the quantum future. But the path to implementation is riddled with operational and compliance challenges.
Alejandro Leal, Senior Analyst at KuppingerCole, will explain why “Harvest Now, Decrypt Later” attacks demand proactive action. He will break down the evolving regulatory landscape, lay out the NIST standardization roadmap, and offer a realistic migration timeline to help organizations avoid brand-damaging breaches and compressed transition windows.
Petr Dvořák, Founder and CEO at Wultra, will share practical insights from deploying post-quantum authentication in banking environments. He will explore user migration strategies, hybrid cryptographic deployments, and how to deliver bulletproof security and a seamless user experience. Attendees will also learn how Wultra’s solutions align with regulations like PSD3/PSR1 and eIDAS 2.0.
Welcome to the webinar, Securing Authentication in a Post-Quantum Era. My name is Alejandro Leal, Senior Analyst with KuppingerCole, and today joining me is Petr Dvorak, the CEO of Wultra.
Hi Petr, how are you? Hi Alejandro, I'm great, I'm great and thank you for the invitation and thanks everyone for taking the time to attend the webinar. Happy to have you on board, I look forward to your part of the presentation, but before we begin with the webinar, I would like to remind the audience just a few things. There's no need to mute or unmute yourself, we are controlling this feature so all of you are muted centrally.
We will also be conducting two poll questions during the webinar and I encourage you to participate in this because we will be showing the results at the end and it's also a good way for me to understand the audience and we will be having a Q&A session at the end, so during the webinar anytime you can just enter questions by using the control panel and we will be recording the webinar so it should be available in the next few days on our website together with the slide decks.
So here's the agenda for today, I will be talking about how to prepare for Q day, then Petr will jump in and he will talk about post-quantum authentication and then at the end, as I said, we will be having some Q&A. So NIST, it's the National Institute of Standards and Technology. In the year 2016, they launched an initiative called the Post-Quantum Cryptography Project where they asked the top cryptographers of the world to submit proposals to propose algorithms that could facilitate the transition to a quantum-resistant feature.
So in 2016 and 2017, they received around 82 proposed algorithms from 25 different countries and in the next months, they were able to evaluate these proposals and they were able to then reduce the number of algorithms. So just a few years ago, in 2022, they selected four algorithms and with the finalized standards, then organizations can now to plan and implement systems that will keep their information secure from future quantum computers.
And the part of information security is important because we're not only talking about the immediate impact of Q day, which is something that I will talk in the next slide, but it's also important to mention that we're also talking about old data and old information that many organizations store. So whenever Q day occurs, it's not only about the immediate repercussions of that, but also about the old information that we have. So it's crucial to start thinking about Q day.
Q day, it's no longer science fiction, it's part of today's security roadmap. It's a reality in a very fast-moving world. We see things changing very rapidly and we need to act now to prepare for that. So Q day is the day when quantum computers will be able to crack encryption protocols that we rely on today when we use the internet. So as we move forward in this webinar, I want you guys to keep in mind these three dimensions. So there's the identity component, there's the compliance aspect, and there's also this concept of crypto resiliency or crypto agility.
So I want you to keep this in the back of your head as we move forward. So why is this relevant now? Why post-quantum authentication cannot wait? As mentioned, Q day is on the horizon and quantum computers will break RSA and ECC, which are the encryption protocols that we use today, and they form the core of modern digital authentication. So NIST is encouraging organizations to start planning now. And as we know, migration takes time. Many organizations are still relying on legacy systems. They are finding some difficulties in their hybrid environments.
So it's important to ask, where does your organization stand today? So that leads me to the first poll question. How ready is your organization for Q day? The option one is haven't started yet. Option two, inventory is in progress. Option three, running pilots. And the last option, you are already using PQC in production. I will give you a few seconds and then we'll move forward. But another thing to keep in mind is that I'm aware that many of the members of the audience, some of you may not be familiar with post-quantum cryptography.
So you may be representing an organization that is doing something completely different. But regardless of that, Q day and quantum computers is something that will affect the way we operate digitally, our businesses, and even our private lives. So without further ado, I would like to have a brief introduction of encryption. And as we know, encryption is a process of converting data or information into a code to prevent unauthorized access. So we can trace it back to Roman times. Almost 2000 years ago, the first recorded use of Cypher was by Julius Caesar during his campaigns in Gaul.
He used that to protect critical military information during his private correspondence. And if we look at the development, we see some improvements during the Renaissance with Giovanni Bellazzo. But perhaps the most important example is the Enigma machine. There's been novels and movies about this event. So the Enigma machine was used by Nazi Germany, especially during World War II, even though it was created following World War I. And it was in 1939 when British and Polish researchers, they were able to crack the code.
And that proved to be significant during World War II because they were able to access critical information from Nazi Germany that proved to be critical during the battles and the course of the war. In the post-war, we see the publication of A Mathematical Theory of Communication by Claude Shannon, which is a foundational text in IT. In the 70s, with Diffie and Hellman, we see the first method of security exchange.
Then, also in the 70s, the RSA algorithm, which is still used today. Then the AEC standardization in the early 2000s. And as I mentioned earlier, the NIST Peak Issue Project begins.
And today, we are waiting for Q&A to happen. It's on the horizon. And NIST and many other institutions are actively recommending businesses to stay tuned, to start preparing for what's going to happen at some point. So post-quantum cryptography is the use of cryptographic algorithms that will be able to address both the challenges of classical computers, as well as quantum computers. So the aim is to facilitate the transition to a quantum resistant future.
So again, quantum computers are a reality. And we know that organizations are still struggling with different things, from IT complexity, to hybrid environments, to legacy systems. And all of that can limit crypto agility. Quantum computing is not the only problem. If we look back at these three dimensions that I first showed, there are identity problems to be solved. There are compliance things to consider. And there's also the problem of business continuity. So as you prepare to develop a crypto agility architecture in your organization, it could lead to an easier transition.
Luckily, there are institutions like NIST that are already developing quantum resistant algorithms. And we also have vendors that are working on solutions to increase crypto agility. So communication between vendors and organizations is going to be very important. And not only with them, but also with us industry analysts, because it's going to be a global problem. And global challenges require global solutions. So having this communication and raising awareness, for example, with a webinar like this, is in my opinion, a step forward.
Because one of the problems that I see is that it sounds very futuristic when we talk about post-quantum cryptography or quantum computers. So some people may not consider it too seriously. So raising awareness for me, I think it's critical. So if we follow the recommendations by NIST, they finally selected four algorithms in 2022. If we look at Kyber, it's more for encryption. Deleteum is for digital signatures, which is quite relevant for financial institutions. But if we look at what's ahead, there's still things to work on.
There's compliance, there's integration, and of course, industry adoption, which usually takes some time. So perhaps a more realistic, let's say, migration timeline could be something like this. So how can organizations prepare by 2030? So with the finalized encryption protocols by NIST, organizations today can start preparing by looking at their inventory and to see if they have any relevant cryptographic dependencies. They should be able to map out all their use cases and how vulnerable their cryptography is used in their organization.
Then in a year or two, they can start with hybrid pilots, especially by testing post-quantum algorithms in safe environments, and of course, without disrupting production and business processes. And this could help organizations explore how to address different challenges in different scenarios, like compatibility, logging, and incident response.
By 2028, 2029, we can expect some gradual rollout of PQC and crypto agile architectures, and a good way to start would be to first focus on high-priority systems. And as I mentioned in the previous slide, it will be very important to have clear communication with vendors and partners to understand the roadmap, to understand their vision for PQC, and also to fully understand how the organization can transition and make this as easy as possible without disrupting any business processes. So by 2030, we can expect, hopefully, a complete migration to quantum-resistant authentication.
And this should, in a way, replace all the vulnerable public key algorithms with NIST-approved PQC across the organization. So if we look back at this identity problem, you know, many people have talked about passwords being dead for decades, and we still see the use of passwords everywhere. Even if 502 and passkeys are gaining ground, I'm actually, I've been following the developments around passkeys for the past couple of years, and I'm actually optimistic about how fast organizations are adopting this.
But if you look at the research that we do at Coping.org, we always try to emphasize that passwords are here to stay, that it's going to take years, if not decades, to completely get rid of them. So that's a major issue. And if we think about it from this quantum perspective, quantum threats will break the foundations of identity. They can break the cryptographic backbone of authentication methods like certificates, like MFA tokens, and digital signatures. So if you're paying attention to these developments, then you will realize that cryptogility is a new imperative.
To future-proof identity systems, you must support and upgrade post-quantum cryptography. So what do we mean by cryptogility? I think there are five areas that we can focus on. I know I'm running out of time, so I will try to keep this brief, but there's the area of flexibility. So how easy it's going to be to swap encryption algorithms without any major code changes. Then there's the hybrid compatibility. In our latest research on access management, we saw a trend that even though organizations are adopting cloud solutions, there's still need for on-prem support.
Some industries, in some scenarios, they still require support for on-prem. So that hybrid compatibility area is very important to keep in mind. There's also the modular architecture and, of course, governance and automation. So policies, tools, and how to manage those updates. And as we know, it's also about lifecycle management. So the creation, the rotation, and revocations of keys is going to be crucial for security. So some final takeaways here. I would like to have a sort of call to action because Q day may come sooner than expected.
It's not only about regulatory pressure, but it's also about brand trust. So there's no room for delay for your organization because your competition may be moving ahead. And once you realize that Q day is on the horizon, then it could be too late for you. So you have to start small, but you have to act now. And you need to start focusing on agility by communicating clearly with your team members, with your employees, with your partners. So everyone is aware of the issues ahead. Then here in Europe, there's the regulatory drivers. So the EU Cyber Resilience Act, NIS2, DORA.
These are crucial because some of the auditors will ask you, so what's your quantum readiness plan? And another aspect for European organizations is how dependent are you on non-European technologies? I was recently at a conference in Poland, and there was a very good presentation that said that 80% of digital technologies in Europe are imported. So moving forward, as we reach Q day, your organization is to also evaluate that aspect if you are based in Europe. Thank you very much for the great introduction, Alejandro. And I will maybe start just by briefly introducing Votra and what we do.
So we are an authentication-focused company, leaders in post-quantum authentication, who primarily work with financial services, but also governments or digital identity providers. So essentially any high-stake authentication situations. That's basically one of the reasons why we might be ahead in this post-quantum area over what is generally available on the market at this moment. We are based in the Czech Republic in Prague and currently have something over 50 people in our team.
So since we primarily focus on financial services, I will maybe give you some background into what our customers are doing. So a typical bank in the European Union currently struggles with two main topics. One is how to deploy artificial intelligence efficiently and ethically, and the second is basically compliance, primarily PSD3, PSR1, the European ID wallet, and similar types of regulation. And what we are currently doing is that we are trying to convince the banks that they should also focus on something called post-quantum cryptography.
And it's not an easy sell, but eventually we managed to win over our customers' hearts and brains and convince them that they should probably look into it in a bit more detail. So post-quantum cryptography is basically a bunch of cryptography focused on methods that secure against attacks by quantum computers. That's our shorthand definition of this segment. And what it means practically, it's a completely different mathematics behind this cryptography. It is not just extending RSA or extending cryptography.
It is really based on different mathematical principles that have to be studied, designed, tested, and implemented, and have to be placed eventually. So cryptography is actually in the backbone of everything our customers do. It is invisible, but it's always there. So if you look at the typical banking ecosystem, the impact of quantum computers is really vast. Customer authentication is just one of the problematic areas whenever our customers do payments or blockchain deployments, digital signatures with PDF contracts, HSM, for example, things like VPN connectivity, they are impacted.
What does it mean? A bank or any large organization will eventually have to replace almost every piece of running software which is currently running in the organization. So maybe the task is large, but we have enough time. Unfortunately, that's not the case. As Alejandro already mentioned, there is strong regulatory pressure. We actually talked to some of the agencies, and the main reason for the regulatory pressure is to ensure that the migration will happen on time. They do not claim that quantum computers will be here by 2030.
They just want to make sure that if they show up in 2035, everyone is ready. And so NIST essentially outlined this timeline, and all European cybersecurity agencies generally signed a memorandum committing to the same timeline.
Now, what does the timeline mean practically from the customer's perspective? I actually peeked at the poll that I saw in the questions, and most of the companies currently haven't started budgeting and even any activities related to post quantum cryptography. So if I can have one thing, you should probably start doing that, because otherwise, everything will be way too late. Then the next year, everyone will be doing RFIs and market reviews, essentially assessing the impact on different systems and selecting discussions with specific vendors. Then there is RFP and project setups running.
So you will have to choose your approach and essentially conduct RFPs. Then you have to run the projects, essentially perform the migration of the legacy solutions to solutions with more modern cryptography. And then there is some deprecation, basically just shutting down systems that are no longer safe. So we like to say that unless you start in 2026, there is not much of a chance that you will make the migration in time. Organizations are typically slow in performing projects with impact on end users. So some of the solutions will fall under this timeline, which is not really fast.
It's not even doable much faster. So this was like the official timeline, but then you look at what Big Tech is doing. And every month, you have a new announcement. We can see a new announcement from Google, Microsoft, Facebook, IBM, any companies regarding quantum computing in some specific domain, specific vertical. I always adjust this presentation by the latest one, which I picked from IBM. IBM essentially has a roadmap to fault-tolerant quantum computer by 2029, which is actually shorter than 2030.
I like to say that our biggest enemy is a smart guy at a Big Tech company who solves a problem, right? That's something that can happen. The timeline is kind of outside of our control. And even if you think that 2029 is still doable, we get to what Alejandro was talking about, that asymmetric encryption is already vulnerable. Attackers can use an approach called harvest now, decrypt later, basically collecting the data now and decrypting them when they are in possession of quantum computer. So if we put this into this very basic chart, you might be encrypting data very securely today.
But over time, this encryption loses its strength. And eventually, all the data will be visible in the plain text to somebody with a quantum computer if they manage to record them earlier in advance. So what does it mean for authentication? Whenever you have some persistent credentials sent over HTTPS, these credentials might be recorded and decrypted later. So for example, if you decide to switch to a quantum safe TLS option, you should probably also ask your customers to change passwords.
If you ask your customers to enroll into Google Authenticator, there is this initialization key that people typically just scan with the phone, and the Authenticator is very easily initialized. And so anybody with access to this key can actually reinitialize the same Google Authenticator. And then things like recovery codes, various API keys displayed in the web application, for example, or refresh tokens traveling in an encrypted channel. So asymmetric encryption, HTTPS, is affected.
And anything that is basically transferred as a persistent credential over HTTPS will have to be basically regenerated. So that's asymmetric encryption. What people do not talk about so much is that quantum computers can also affect digital signatures performed with algorithms such as RSA or ECDSA with elliptic curves. And this is not an imminent issue today, but it's a few days sensitive issue. So if you look at it practically, again with this chart, you currently sign data using a certain type of signature.
And if you keep up with what is currently possible to break, and if you always replace it on time, then you should be fine. The problem is that if you miss it once, you might have a bit of a problem.
So again, from the authentication perspective, what are the methods to be migrated by the Q-Day, which we do not know when it is really. Any past keys or FIDO2 deployment is currently based on digital signatures, typically with elliptic curve cryptography. Any certificate-based authentication such as PKI, X509, or MTLS, and of course even modern decentralized identity like wallets, verifiable credentials, verifiable presentation, or digital credentials API, or just JWTs, they are also impacted.
So anything that currently uses signature essentially with elliptic curve cryptography or RSA has to be migrated by Q-Day. Let me make a special note on digital signatures in the contracts where the signature was appended to, for example, a PDF file. This type of signature has to be augmented by a timestamp with the quantum safe algorithm underneath it.
Otherwise, the PDF contract will prove nothing, and you might even see people just showing up with contracts signed with RSA and claiming the contract is actually properly signed by your organization after the Q-Day. So these are two specific impacts. So from our perspective, that's primarily about explaining to the banks that they must change their current solution for customer authentication, because if they fail to do so before the Q-Day, it will have fatal consequences. Very practically, we typically like to say that this will lead to loss of transactions.
In other words, it means the systems will not work. They will have to shut them down until they fix it. So what we decided to do is to be a little bit ahead of time and coin this term called post-quantum authentication, which is authentication which is emerging quantum threats in all possible aspects and touch points. It is only part of the overall quantum problem, but the quantum problem is huge, since every piece of software is affected. It is not in the powers of a single company to solve the problem, and we decided to focus on the authentication problem.
So what it means practically is that it is quantum resistant in all possible aspects and touch points. So one thing is that you have multiple authentication methods. You might have mobile authenticator, hardware devices, passkeys, maybe chip cards. Every single method that you currently use must be evaluated for quantum readiness and updated or deprecated, depending on what you want to do with the specific method. So this is like a horizontal approach to the problem.
Then we also have a vertical approach to the problem, because even if you look at mobile authenticator, it has to be redesigned completely from ground up. Every single element of this system has to be updated. So for example, authenticator application itself cannot really use ECDSA for digital signatures or AES128 for encryption. It has to be updated. Network communication, similarly. Whenever the application talks to some back-end component, how does it happen is a legitimate question, and it has to quantum-safe.
Server-side components can, for example, issue digitally signed documents or digitally signed information for the mobile app, and this also has to be updated. And finally, database encryption. This is probably the easiest.
Typically, if you see somebody getting ready for quantum computers, that's the first step they would do, because it's really, really, really easy. And since we had to overhaul our system in those main areas, we also decided to update all the cryptographic primitives that are kind of auxiliary in the entire solution. So just to remind what we are talking about, we are not talking about some revolutionary user experience change or new type of authentication. It is the same user experience, just with superior security.
Organizations will have to switch to quantum-resistant cryptography only so that we can use the services the same way as we currently do, which, quite frankly, isn't the best pitch for a board meeting, because we have to explain that we urge the organization to execute a very lengthy, complicated project with a very low benefit for the end user that would be visible, and it involves activity from the end users. But what we always end up saying is that this is non-negotiable. It is something that will have to happen.
Otherwise, the services that we use will no longer be trusted and will not work. And so it also presents an opportunity, actually, to modernize the systems, to basically look at what authentication mechanisms is the organization currently using, and maybe make it better, cleaner, better decomposed, things like that. Since we mostly talk to banks, what we cannot do is to push just post-quantum cryptography as a solution. The algorithms are just very new. They were standardized in August last year, so we cannot go to the bank and ask them to deploy basically a less-than-one-year-old algorithm.
So there are essentially two approaches. What we do is a hybrid scheme. We are augmenting elliptic curve cryptography with new crystals, a family of algorithms.
Currently, they are branded as MLChem and MLVSA. And as a result, we are basically saying we have a baseline of elliptic curve cryptography as a for today, but we are ready for the future. Another approach, for example, for elements that cannot be really extended in a hybrid scheme would be something we call hypercryptoagility, basically the ability to very quickly change underlying algorithms. This concerns, for example, PaaSKies or FIDO2 deployments, because PaaSKies and FIDO2 are very standardized.
And so as a result, until recently, you were actually unable to specify a quantum-resistant algorithm for PaaSKies, for example. Since April this year, so it's very new, you can actually specify a dilithium algorithm. So you can work with FIDO2 or PaaSKies through authenticators supporting dilithium algorithms, but that's not a hybrid scheme. So if there is an issue with dilithium implementation in your system, you need to be very quickly able to switch it to a different algorithm. So these are the two approaches that we would advise to deploy.
If you have authentication under control, go for a hybrid scheme. And it also tells us one more thing, because in five years of time, elliptic curve cryptography will not really do much. It will be deprecated. So we will have to do this change again. So cryptoagility in general is a pretty good idea anyway. So what is the problem in the migration challenge? We typically hear that we don't need to, and I think it will just somehow happen, our vendors have it under control. But in case of authentication, that's not really the case. Suppose that you have registered a PaaSKie with RSA algorithm.
You cannot really magically turn it in dilithium PaaSKie. You cannot just take the same key and somehow change it. So it requires active users re-enrollment.
Now, the re-enrollment must be done before the Q day, because if it isn't, then the authentication doesn't make any sense. That's kind of the point of this entire discussion. And as a result, you might be in the need to mobilize your vendors. And if you wait too long, everybody will be asking and your vendors just won't have any time for specifically your project. They will be doing something else for someone else. So starting ahead of time is a good idea. And the second thing that I would like to tell you is that there are some inevitable steps that you would have to do anyway.
For example, you need to update the backend components, because if your backend components currently do not support dilithium signatures, then how do you make them support it? You have to update. Then you have to buy or update the authenticators. For example, if you plan a major purchase of USB 502 sticks, don't do it. Maybe wait a bit. Then you would need to adjust the changes in APIs, basically do the integration again or at least refresh it, and then design and implement scenario for user migration, just so people can switch from the legacy authentication to post quantum authentication.
So we have identified three migration strategies for switching from legacy authentication to post quantum authentication. First one is using the existing authentication element. Essentially, you can still use electric cryptography today to enroll, for example, FIDO2 authenticator, which is quantum resistant. This is very fast and cost effective from the organization perspective. It is also quite convenient for end users, but it must be done before the due date.
Otherwise, your existing authentication wouldn't be a sufficient proof. Now, the second approach is full identity verification. For example, in-person verification at the branch or some online identity verification through scanning personal ID or making a selfie scan. Note that if you use physical documents, this should also be quantum ready. And this approach with full identity verification is suitable, for example, if you miss the due date, that's something that you would have to do then. It is very useful for high security scenarios or for small user bases.
And finally, you could outsource this activity of enrolling to quantum resistant authentication to some third party, such as usage of QTSP or EUID wallet, things like that. Now, if you look at the authentication cost compared to identity verification cost, it would be approximately, you know, the identity verification would be 20 to 40 times more expensive. What we typically see on the market is that authentication costs 0.05 euros per transaction, you know, slightly more, slightly less, doesn't really matter. While identity verification would be somewhere around 2 euros.
So, if you are a small organization with 500 users or 500 customers, of course, you can go through full identity verification. It is not so complicated, not so expensive. You might have the process completely under control. But if you are a retail bank with 5 million users, this already makes a big difference. And to the last step, or last option, sorry, using third party provider, unfortunately, we currently do not see anyone actually deploying quantum safe cryptography for digital identity in practice.
So, we are a little bit ahead of time, as I mentioned. So, this was essentially everything from me. I will just recap what is the urgency. The Q day is approaching. There is no question about if it is happening. The question is when. And we might all be very unpleasantly surprised because there are smart people now equipped with AI who can really easily put information together and maybe make some breakthrough. As a result, regulatory pressure is rising, not only by a government agency, but also by consultants, by other authorities.
You need to switch just because even if you don't have a tool, it could lead to typical rushed projects that would disrupt your end users. And of course, we are here to help you. And that was everything from my side. Thanks for the attention.
Thank you, Petr. That was a very good presentation. I think that you touched on all the points that I covered in my part of the presentation.
So, hopefully, the audience also got some relevant information on that. Now, we should have some time for Q&A. But before that, I would just like to remind the audience that on our website, you can find more information on the current trends and authentication, as well as some research on post-quantum.
You know, at Copenhagen, we do research webinars, and we also have events revolving around IAM and cybersecurity. We'll be having an Impact Day in Munich in September, and in Frankfurt in November.
So, yeah, that's all from our side. And now, we can check the questions, because I see that there's some of them. Yeah.
So, there's one that has four votes. And the question is, as ID is shifting increasingly to biometric solutions, like passkeys, is that any more or any less vulnerable to pure key computers? I think you briefly talked about the importance to have this hybrid authentication, but maybe you can...
Yeah, sure. That's actually one of the things that we find quite amusing, because we always discourage our customers from using passwords and SMS OTPs. But these are actually, in a sense, less affected by quantum computers than modern authentication methods like passkeys or certificates. It is because passkeys and certificates use digital signatures at their core, while passwords generally use hashing or symmetric cryptography, for example, where the impact of quantum computing is actually lower. I think that passwords, for example, are primarily affected on transmission.
That's the main point of attack through quantum computer. And this is a problem of TLS, and TLS is notoriously crypto-agile. You can very easily switch cryptographic seals. You can actually already deploy quantum-ready algorithms in a typical TLS system. You have vendors making announcements about it. So as long as the web browser supports it and the backend server supports it, you can run quantum-resistant TLS today. So I would say that modern methods are more affected by quantum computers than the legacy methods. Maybe we will all end up fighting quantum computers with sticks and clubs.
I hope not. Thank you, Pedro. That was a very good answer. The next question is, what if we miss the Q day? Do we have any options to respond quickly after this happens? I'd say that the immediate consequences would be broken encryption, compromised authentication, the harvest now, the crypt later would succeed. So I guess there are some weak band-aid options like a revocation and certification reassurance or cryptographic upgrades, isolation of network segmentation. But I think preventing this from happening is the most important thing. Preemption is critical. But what's your take on this?
Exactly. I fully agree. I think that missing a Q day is a major problem because then your systems cannot be trusted. Basically everything breaks if you miss the Q day in migrating the systems. So of course you can do some quick fixes. You will have a ship that's leaking and you will be fixing the biggest holes. That will be the problem under pressure because typically you will be under pressure from regulators, you will be under pressure from users. It will be a bit of a nightmare.
So what we are actually seriously discussing with some of the customers, if something happens, for example, I don't know, in three days, you know, somebody announces we have a quantum computer, we have to shut everything down. That's basically the answer to it. Okay. Hopefully that's not going to be a scenario happening soon. That's why I feel like NIST's approach and generally the agency's approach, they are pushing a little bit ahead of time. That's nice. Okay. Another question is about, is there any proof that the new algorithms are actually secure?
Yeah, that's a very good question and the answer is not really. Because if you think about it, even our legacy algorithms do not have any formal proof of correctness. Even RSA or elliptic cryptography. With new algorithms from quantum safe cryptography, that's basically the same situation. We don't know how to break them. RSA and elliptic cryptography are broken because we can run a short algorithm on a quantum computer. We know some attack vector. We don't know it yet. And hopefully it will stay like that. There are reasons to believe that the algorithm is secure.
It has been studied by mathematicians quite intensively. But as a story, we actually have been watching quantum computing since 2018. And as a company who built systems on elliptic cryptography primarily, we were very excited about Cyc algorithm. This was actually NIST's candidate of round three. So they made it to round one, round two. They went to round three. And there was quite a bit of excitement. We actually implemented our Java implementation. We were listed on Cyc's website. So we were really excited that we are visible.
And then mathematicians looked at it and realized this is familiar. We know it from somewhere else. And they found like projection from one problem that can be solved very quickly into the underlying algorithm of Cyc with supersingular elliptic, supersingular isogenies, basically extension of elliptic curves. And they managed to break the algorithm in one hour on a classical computer. So this algorithm is no longer listed. So this can happen essentially with anything. Mathematicians are wizards to me. I don't have the intelligence they have. And they are troublemakers for us.
Yeah, indeed. There's one more question before we take a look at the poll results. So the question is, people have been talking about Q-Day for some time now. How can we be sure that the timing is happening right now? If I can add something to that, if we look at what's going on right now with the AI race, it seems to me that this technological competition is something that is just happening so fast. And Google just really unveiled their AI chip. You talked about IBM. But we can also have some surprise like DeepSeek from China. They're also investing a lot on these technologies.
So it's not only the, let's say, geopolitical situation or the technological advancements that we see today. But what's your take? Why now?
Yeah, so AI is actually a pretty good comparison because if you think about AI, you know, three, four years ago, it was basically a joke of every presentation. Whenever anyone mentioned AI, the first follow-up question was, and how many interns do you employ to do the AI, right? That was basically the situation back then. Then ChatGPT came along and everybody realized, well, we can now talk to a computer, right? So that's pretty staggering. And in quantum computing, I think the big change actually started around the year 2017 when private sector decided to enter the topic of quantum computers.
Before that, it was very academic. It was basically university research. Typical success was about having one qubit or two qubits.
In 2017, companies like Google, IBM, and Microsoft entered the race. And you can essentially see that they are increasing the number of qubits similarly to more so. So every year, you can see like doubling the computational power of quantum computers. So NIST's timeline actually pretty much follows the idea that we will have twice as strong or twice as many qubits in a quantum computer every year. And how much time we need to basically have a problem with quantum computers. So I think that we do not have any. So until recently, we were not sure.
But currently, we don't have any question about if quantum computers are real, if they will happen. They will. Okay.
Well, I think now it's time to talk a little bit about the poll results. So the question was, how ready is your organization for Q Day? It turns out that 81% of the people that responded to this question answered that they haven't started yet. 13% are looking at their inventory. Apparently, 6% they're running pilots, and 0% are already using in production. Are you surprised?
No, I'm actually happy that somebody responded that they are already using it in production. Because typically, if I go to a conference and talk about this subject, and then I ask to raise hands, you know, nobody raises hands. So I'm happy that somebody from the audience is already running pilots, or maybe even in production. Making a catalog of cryptographic algorithms is something that should be on a priority list of essentially everyone. I would say that the poll results are surprising only because I saw somebody already doing it.
But the fact that most of the people didn't isn't really surprising. But I hope that this means that we convinced how many 86% or 81% to start. Yes. And if we look at the other question, what's holding you back? 53% they say that it's a lack of awareness or urgency. 18% about budget and resource constraints.
Again, 18% is about technical challenges for integration, and 12% because they have no vendor strategy. Yeah, I think that awareness is the biggest problem that we actually encounter ourselves.
Typically, we have a lot of discussions about misconceptions. And that's common on the market.
Like, exactly, there are no quantum computers, it is too far away, things like that. Typically, we are able to dissolve these discussions, just by showing what's happening. But it is kind of, you know, not a common knowledge that we always have to flip into some action, some discussion.
Yeah, that could be another good topic for another webinar, talking about the misconceptions. Because as I said, also, it sounds like a very futuristic topic. It sounds very cool. But it sounds like it's not here yet. But as we can see, thanks to this webinar, it's something that requires urgency. And we encourage organizations to take that seriously. And we want to thank you, Petr, for such a very cool webinar for such an engaging topic. And if you have any final words?
Yeah, I mean, I would like to thank you again for inviting me and everyone else for participating. I hope that the content was valuable, and that you will start thinking about how to deploy quantum resistance algorithms in your authentication systems.
Of course, we are always available to help. Thank you so much, Petr. And thank you to the audience for participating. Have a great day. Thank you. All right. Thank you.
See All Locations
See All Locations