All right, all right. Thank you for being here. I'm having a great week, I hope you too.
And first, I will try to make this work, congrats. You made it to Friday.
I did too, so I'm happy. And I want to start by saying that, so it's not a surprise, I will talk about post-quantum cryptography as well, and I will talk about PQCA at an identity conference. So why? And I want to start by trying to explain this. So who I am, my name is Bertrand, I do some running, I play the guitar, but I do identity as a living. That's what pays the bills for 20 years. I'm really passionate about this, I'm an IDPro member, you should too. And as for cryptography, well, I surf online, and I do shop online as well. So I'm not an expert.
But I've done some things, I've hashed passwords with really old mechanisms, I've decrypted tokens, I've signed tokens manually first, and then I learned to use software to do this. It seems that for something like 10 years, I did nothing around them. So I'm not an expert on cryptography, I will not tell you, I'm not a mathematician, I'm not a cryptographer, I learned about algorithm in Wikipedia, and that's about it. But I do want to focus today on the impacts of the quantum threats, the quantum computing threats on our identity infrastructure.
Brian made a good job to tell you about the whole quantum threat, and what you should do about inventorying applications, data protection, et cetera. I will focus on the identity elements on this. And of course, I will start with why we are not doing anything right now. So we know that we don't know. We don't know when quantum computing will be ready to break current cryptography, and the estimates vary between those timelines, and there are only probabilities. And the human is famous for being very bad at probabilities and risk assessments based on probabilities.
So that's probably why no one's doing anything now. But we know for certain the impact, what will break, we know how this is going to unfold. We know that we will break RSA and ECC at the mathematical level, therefore the algorithm that we use today to encrypt or sign some data are at risk. And we know that identity for a large part is based on digital signature mainly, a bit of encryption as well, but digital signature is probably the most problematic. And NIST has made a standardized new algorithm due to that. So we have solutions to this.
We have algorithms that run on current computers, classical computers, that are quantum safe, that are not threatened by quantum algorithm. And from this, okay, emissions are here, not there. And we have several jurisdictions, several legislation around the world, guidelines that are slightly different, but they do all converge that high risk system, high critical risk system must be migrated before 2031. And we know it will take years, so we have only five years to do this, and I don't know if you were there when you had to migrate MD5 to SHA-1, to SHA-2.
If you remember the previous slide, it took me more than 10 years to migrate my hashing algorithm for passwords. So I imagine for a company. And I do think, but maybe I'm biased because I'm doing identity as a living, that we're the most important cross-duty. So asymmetric cryptography is broken by quantum computing. So that means that all of our trust anchors or all of our certificate authorities and root CAs are going to be broken down. That means that everything that we do with identity providers, federation, those two is broken.
And that means that all the applications that are using now for what we're very happy to have applications doing federation, 10 years ago it was a wish, today it's a reality, but it's going to be broken. So identity is only as strong as its trust anchor, is only as strong as the underlying cryptography that we are using for this. And to repeat maybe some things that Brian said before me, he told about some lies that we tell ourselves. I will tell you about uncertainties maybe that are a bit similar to what he was saying. So algorithm, we have those. They have been certified.
Of course, we don't have 40 years of crypto analysis on this like we do for RSA and ECC, but we do have validated algorithm, quantum safe validated algorithm. The question now is who's going to adopt them? The West will adopt the NIST algorithm, China, Russia have their own algorithm that they are trying to also to standardize. And I do think that we have already enough to start thinking about quantum. Brian agrees on when quantum computing is going to be a problem. Jurisdiction are trying to be, sorry, more precise.
Is there a, yeah, yeah, I'm sorry, there's, yeah, yeah, yeah, yeah, yeah, yeah, yeah, yeah. So we are going to, we're waiting for regulations to actually be there and penalties and to be there.
Recently, when I talk with clients, I sometimes have the question like, okay, what's the penalty? What is the fine for this? There's no fine. I don't care. So I do think that when we will have this information, we will maybe be able to move forward. Here's the question about hybrid versus pure PQC. So are we going to encrypt with a RSA, then encrypt again with a quantum safe algorithm to be sure that none of the current threats and the future threats can actually decrypt the data. Same for signature.
There's a real question whether we have sufficient knowledge about the new algorithm, the new quantum safe algorithm. So the debase right now is that in the U.S. originally, pure PQC was the main trend. It's not so clear anymore. There's a clear trend in Europe from Germany and French cybersecurity agency that will require hybrid encryption or hybrid signature for the first short term migrations. And we always have the questions about what protocols are ready.
So I'm very happy that I did not hand over my slides until yesterday night because I was able to snoop in this new RFC, the 9964, which allows now to digitally sign with quantum safe algorithm, JSON and CBOR formats. So that means that this is the way, this page is the way to be able to do that with JOT tokens, which are the foundation of a lot of modern protocols that we use. So the algorithms are here, the protocols are here, well, the foundation protocols are here. So the target protocols are going to be here very soon.
And then we will see those in the software deployed by companies, provided by vendors and deployed by companies. So there are still questions, but none of them are a real reason to wait. And there's, it's already time to design and to do and to think about inventory or to think about where are the risks in the information system. So what am I talking about when I'm talking about identity? So you have a new employee and of course you will have a digital wallet and you will have a verifiable credentials here to onboard the user.
That verifiable credentials is digitally signed and the root CA can have a long lived expiration date. So it's going to be a problem. It is long lived by design. The issuers sending the key are very high value because they are going to sign millions of verifiable credentials. And so they are very critical to our trust framework in that space. And CryptoGDT will have to be built in the system itself to be able to rotate the key, to rotate the algorithms underlying these digital signatures.
Then from onboarding we go to provisioning classical, not really so much a problem except we use TLS for all those connections to the various systems and TLS with the current cipher suites is broken. So we have to update the cipher suites to make them quantum safe. That's probably the most exposed surface today but it's also maybe the easiest to migrate. We can already migrate TLS to a quantum safe algorithm. We can already encapsulate flows for legacy systems that are not able to be updated. So definitely here we can already do something concrete.
Then we move on to actually accessing the applications. So here we have a nice little dance where we use different means, different ways to authenticate and we have different protocols to do things. So what about PaaS keys? Well John Bradley did a very nice presentation yesterday. I invite you to review it and he mentioned that PaaS keys and some hardware PaaS keys were able to support MFDSA algorithms, the quantum safe digital signature algorithm. And it's not about migrating now. It's about thinking about do I have to source some hardware tokens if I'm sourcing them in 26?
Am I going to be able to use them in five years from now or will that be broken? So it's a real question about timing and timing of procurement, for instance, for hardware. And it would be a timing of crypto agility at the right time when all the software is ready. PKIs and smart cards for end users or for devices, IOTs, same question. Smart cards rely on sophisticated authorities that can live for decades. So trust and core have to be migrated. Smart cards are already available in the market.
Some are even certified and you can deploy hybrid certificates or pure PQC certificates to smart cards and authenticate with this today. And I see teams that manage PKI infrastructure already experimenting, already playing with this kind of stuff. Very few are production ready, of course. But there is room for experiment already on this side. Then we're going back to the protocols, SAML, OIDC, OAuth 2.0. We will have to patch it when they're ready. And some will not be ready. For instance, SAML will probably never have an update to be quantum safe.
So a lot of people say SAML is dying or is dead. I don't care. I'm going to bury it. And that's the right opportunity to do that. And lastly, it's not only about the protocols and the identity provider that you need to update. You have to understand that all the applications that are connected to the identity provider will need to be updated because they are verifying digital signatures. So you will have to update libraries embedded in them. Or you will have to update hard-coded digital signature verification stuff in there.
So you can start right now to make sure that you have a good inventory of all your applications, the protocols that they use, the ones that are using SAML. You probably need to review those first and find the right strategy to migrate them or to change them.
For OIDC, identify whether the vendor or the open source library that you use is going to have soon a quantum safe version available. So I want to finish with actually what's ahead of us. And I think I have plenty of time because I was supposed to, OK, the timing is really odd here. Sorry for this. I think we can already start to act. We can already do a number of things. We don't have to migrate everything now, but we have to lay the groundwork. We have to anticipate a number of things because it will take years to migrate.
And starting now, the planning and mapping and venturing is the thing to do. So you have to inventory your applications, inventory every trust anchors that you have in the information system, whether they are in the information system or distributed because you are, I don't know, maybe you're building some cars, maybe you're building some IOTs that are on the field in factories or in your customer's house. And this will be difficult to definitely address and to migrate. So anticipate now. Verify that the credential lifetimes that you use are compatible with your migration.
Anticipate that you will have to patch it or kill it for every part of your identity infrastructure, including the applications. And again, we will bury Samuel together, I hope, before I, yeah, we probably will.
I hope, right? And crypto agility is a concept that works well. We push for it a lot in data protection regarding post-consumer cryptography migration. But it's the case also for the identity infrastructure. Digital signing will need hybrid signature first. We'll need to be able to update the protocols and then underlying algorithms that we use. So you definitely have to do this. So this will start with the identity provider and then follow up in all the applications as well. Thank you very much, everyone. And I need to thank you.
Thank you, Bertrand. I've been told that you have to catch up your flight. So you don't have... I can take some questions. No problem.
Oh, so great. Any question, Mathieu?
Yeah, have there been any estimates as to the current cost or potential future cost of the appropriate quantum computer? Are we talking billions of dollars, millions of dollars, thousands? I'm just trying to get a sense for how much resources are required. So I think it is Boston Consulting Group, they estimated that this is going to be between 2.5 and 5% of your IT budget. I meant the computer itself.
Oh, the computer, the quantum computer. It will be billions of dollars. It will be only nation state actors first. It will maybe be quantum computing as a service at some point. Probably the access to those machines will be very strict. I think Ingo Schubert touched on this yesterday afternoon, saying that there will be very strict export regulations around this kind of chip. So I think we have some time before the organized crime had access to a quantum computer. But depending on your threat model, maybe you're already concerned about this, specifically in the defense sector.
So we also have quite some information about how Google or Microsoft are advancing on this. They communicate a bit on this. We don't have so much information for other countries. And maybe other countries will have quantum computing ready before the West. So that can also be something to take into consideration in a threat model regarding external adversaries coming in to decrypt your data or impersonate your users, if we're talking about identity. And another question for you. What do you reckon with data at rest and digital archives that are heavily depending on XML signature?
Do you reckon to wait for the vendors? As we heard before, it's not worth waiting for the vendors. But if you're running an archive with XML signatures in millions of documents that will need to be actually re-signed or maybe reformatted to something like JSON web signature, or what do you recommend?
OK, so the question around digital signature of documents and specifically XML signature. So there is no plan right now to update XMLSEC to do a quantum safe computing, quantum safe digital signature on those. That's why some will probably not be updated. That's why effectively if you do have some business data that you are signing for archives, legal archives reasons like digital contracts that you have, the plan is probably to sign them to subsign, oversign, to wrap them around a quantum safe signature, but probably to treat them as a blob inside a newer format that will be available.
But that's definitely the thing. And so we're dealing with clients that are starting to plan their PQC migration and data protection is the first risk because it's now decrypted, but definitely the trust now forged later is also a risk that you have to anticipate. And that's definitely the case for things like digital contracts. So that's part of the inventory as well. Do you have any business use case somewhere in a company that relies on a digital signature? And this is not so easy to answer from an IT perspective.
My experience is that you have to go and see the business guys to make sure that you understand their processes and you understand whether they have sometimes legal obligations to do that. That's the case for maintenance in the aviation space, for instance, aviation industry, for instance, digital signature are required in that case for the maintenance of aircraft. That's a nice use case to have a look at. I can tell you. Any other question for Bertrand? Yeah.
Bertrand, thanks for the presentation. Very interesting. That may be a collateral subject, but I came from a lot of, you know, the conference talking about AOD wallets. We are going to deploy things. I have heard nothing about post-quantum AOD wallets to be deployed in the next year. So do you have any knowledge, standards, initiatives on that topic? So I have a physical ID card with a chip on this, which is both a contact and contactless chip. And it is valid until 2033.
And 2033, maybe there will be a quantum computer at this point. So there is definitely a problem with physical and digital credentials in the wallet, because from this document or from my passport, which is also NFC chip enabled and I can prove my identity, that digital signature is also not quantum safe. From this derives what we currently put into our wallets. So I think that the different countries, the 27 countries that are working on each on their own wallets, so to say, they are taking this into account.
They know that what they rely on as the initial source of truth is currently still valid. But at some point it will not be acceptable anymore. And they will and they are planning to include into the verifiable credential format quantum safe signature. So this is planned, but this is definitely not ready. I also have on my phone France Identité, which is the French wallet, which is also live. But I know that the verifiable credentials in there are not signed with the quantum safe algorithm yet.
But it's easier to update a verifiable credential on my phone rather than do the same with a chip that will not be updated, with a passport that will not be updated until it expires. And my passport also expires after the possible Q-day. So there is definitely a risk on this and probably states will have to take this into account and force some updates or stop accepting digital environment, remote digital environments for VCs and do face to face. That's also a possibility for a time period. Any last question for Bertrand?
OK, thank you very much. Thank you very much.