{"id":49844,"date":"2025-01-14T20:30:46","date_gmt":"2025-01-14T12:30:46","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/cyber-experts-assesses-the-impact-of-new-quantum-standards\/"},"modified":"2025-01-14T20:30:46","modified_gmt":"2025-01-14T12:30:46","slug":"cyber-experts-assesses-the-impact-of-new-quantum-standards","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/cyber-experts-assesses-the-impact-of-new-quantum-standards\/","title":{"rendered":"Cyber Experts Assesses the Impact of New Quantum Standards"},"content":{"rendered":"<\/p>\n<p>Quantum computing is set to impact space networks, and the past year saw a number of updates in quantum regulations. The U.S. Department of Commerce\u2019s <strong>National Institute of Standards and Technology<\/strong> (NIST) in August finalized a principal set of encryption algorithms designed to withstand cyberattacks from a quantum computer. The algorithms announced are specified in the first completed standards from NIST\u2019s post-quantum cryptography (PQC) standardization project, and are ready for immediate use.<\/p>\n<p><em>[This article was published exclusively for Space Security Sentinel, a new monthly newsletter at the intersection of cybersecurity and space. Subscribe to the newsletter here.]<\/em><\/p>\n<p>Roger Grimes, a data driven defense evangelist at <strong>KnowBe4<\/strong>, a provider of security awareness training and simulated phishing platforms, spoke with <em>Space Security Sentinel<\/em>, calling this standards a \u201csignificant\u201d step forward. Grimes pointed to the fact that the U.S. government has been saying organizations need to prepare for the coming post-quantum crypto migration since 2016, but he believes most organizations really couldn\u2019t start anything until the \u2018official\u2019 post-quantum cryptography standards were defined and released.<\/p>\n<p>\u201cNow that this has happened, every organization needs to get a move on. Every organization needs to start with creating an official project, assigning resources, and taking a data protection inventory designed to determine what does and doesn\u2019t need upgrading and replacing. This one step \u2014 the data protection inventory \u2014 will likely take most organizations over a year to perform,\u201d he adds.<\/p>\n<p>With work now on standards making tangible progress, what does this mean to companies in the satellite\/aerospace sector? Grimes believes trying to meet NIST\/FIPS compliance in most companies will impact every bit of software, hardware, and firmware. \u201cGet started defining and resourcing an official project team, and get started on the data protection inventory, if you haven\u2019t already,\u201d he advises.<\/p>\n<p>Grimes believes the impact on satellite companies could significant given the unique dynamics of how the technology is used and acquired. \u201cIt is difficult to update\/replace cryptography in the aerospace industry, especially for things built 10 or more years ago. All space\/satellite items should start being built with crypto-agility in mind, which is the ability to more easily upgrade\/replace existing cryptography with newer cryptography far more easily than it is mostly done today,\u201d he says.<\/p>\n<p>Even though things are changing in satellite, and satellites are being launched and acquired in shorter time frames, there are still long timelines compared to most communications technologies when being implemented. Grimes believes in most cases companies here are severely behind other sectors.<\/p>\n<p>Grimes explains: \u201cThey use a lot of cryptography, but most of it is embedded in hard-to-upgrade firmware, lacks appropriate CPU and memory-handling requirements for the newer cryptography algorithms, and is way, way harder to replace\/upgrade than it needs to be. Anyone thinking the satellite or aerospace industry is cutting-edge in cryptography isn\u2019t spending a lot of time looking outside that industry.\u201d<\/p>\n<h3><strong>Quantum Era<\/strong><\/h3>\n<p>The quantum era is no longer a far off era \u2014 it is here. With the U.S. government talking of a target of organizations using post-quantum cryptography by 2030, we are set for a number of developments in the second part of the decade. However, despite new standards and progress by NIST, Grimes believes things still need to move faster.<\/p>\n<p>\u201cI\u2019m in the minority of quantum computing\/cryptography followers who think that is a date way, way too far off. I think the \u2018quantum crypto break\u2019 has already happened and we just don\u2019t know about it, or will absolutely happen years ahead of 2030,\u201d he says. \u201cOf course, I\u2019ve been saying that since 2019, but I can\u2019t look at all the progress we\u2019ve made publicly and think that the US government hasn\u2019t beat what we know publicly by at least a few years. And I wouldn\u2019t count China out, although they seem to be concentrating more on quantum-protected networks versus attacking traditional quantum-susceptible crypto.\u201d<\/p>\n<p>When looking to the future, Grimes believes that sufficiently-capable quantum computers will be capable of quickly decrypting traditional quantum-susceptible cryptography that is used by much of the world, including RSA, Diffie-Hellman, Elliptical Curve Cryptography, El-Gamal, and symmetric key sizes smaller than 192-bits. He talks about how most of the world runs on these ciphers, including most Wi-Fi, HTTPS, smart cards, banks, credit cards, and cryptocurrencies.<\/p>\n<p>\u201cIf we don\u2019t get our cipher infrastructure moved to quantum-resistant ciphers before sufficiently-capable quantum computers are generally available, anyone using quantum-susceptible cryptography will be at great risk of having their encrypted data and authentication compromised,\u201d he says.<\/p>\n<h3><strong>Nation-State Attacks<\/strong><\/h3>\n<p>CyberSat was a first of its kind event that bought members of the satellite and cybersecurity communities together. Much has changed since the event launched in 2017. Nation-state attacks on satellite infrastructure is now a very real and likely scenario. Grimes admits that nation-state attacks have certainly become far more normalized over the last decade. He points to the fact that only a few years ago, nation-state attacks were rare and only used against traditional nation-state targets such as, politicians, media, military, and subcontractors etc.<\/p>\n<p>\u201cToday, the average nation-state target is a regular organization that, years ago, would not have to have&nbsp;worried about it. That is not true any longer,\u201d he says. \u201cYou can assume that every sufficiently-capable nation-state has many ways to take down or harm existing satellite technologies. I think it\u2019s foolish to wait to hear of an attack or attempted attack to be announced publicly. No, you have to assume that your adversaries have far more advanced capabilities than are currently known and adjust and defend accordingly. But, yes, I think as cyberwarfare has moved from the realm of something we just worried about to what is just normal in today\u2019s kinetic and non-kinetic conflicts, satellite technologies will increasingly be targeted. It would be foolish to think otherwise.\u201d<\/p>\n<p>In terms of overall trends in cybersecurity, Grimes says AI will become more prevalent, \u201cWhile we certainly see AI-enabled attack technologies taking a bigger role over time, it\u2019s the traditional types of attacks (e.g., social engineering, unpatched software, misconfiguration, etc.) that will stay the main things to worry about over time. AI will enhance those attacks, but not focusing on the traditional things and ways of attack would be foolish as well. The more things change, the more they stay the same,\u201d he says.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quantum computing is set to impact space networks, and the past year saw a number of updates in quantum regulations. The U.S. Department of Commerce\u2019s National Institute of Standards and Technology (NIST) in August finalized a principal set of encryption algorithms designed to withstand cyberattacks from a quantum computer. The algorithms announced are specified in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":49845,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-49844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/49844"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=49844"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/49844\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/49845"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=49844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=49844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=49844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}