Q-Day: The Accelerating Cyber ICBM

25 Nov 2024

Recently available information suggests that Q-Day i.e., the day when quantum computers will have sufficient processing capability (generally considered to be 4,096 qubits) to unravel even lengthy complex passcodes in a matter of minutes, if not seconds- will occur much sooner than common estimates have contemplated. Years ago, it was already estimated that quantum computers will operate at 1,000,000 times or more the speed of classical computers.  IBM recently confirmed that it expects to have a 4,158-qubit quantum computer (which it calls Kookaburra) operational in 2025. IBM, “Expanding the IBM Quantum roadmap to anticipate the future of quantum-centric supercomputing (Updated 2024)”, available at https://www.ibm.com/quantum/blog/ibm-quantum-roadmap-2025.

Chinese sovereign-controlled research laboratories are likely to be equally close to or ahead of that schedule. Notably, one Chinese research lab announced last month that its researchers had hacked a military grade algorithm using a D-wave quantum computer. See, e.g., P.R. Mishra, China hacks military-grade encryption using quantum computer, poses threat to West, Interesting Engineering, October 11, 2024.  Although it is difficult to fully verify the accuracy of what the Chinese researchers have reported, the most important aspect of this announcement is the admitted intent to attack RSA and AES-256 using quantum computers.  RSA 2048 is the public-key cryptographic system that employs a key size of 2048 bits for secure data transmission and that protects a significant portion of internet communications, including e-commerce transactions and online banking. AES-256 is a symmetric-key algorithm for encrypting electronic data specified by the National Institute of Standards and Technology (NIST) and is widely used in government and military applications.   “The research team, led by Wang Chao from Shanghai University, found that D-Wave’s quantum computers can optimize problem solving in a way that makes it possible to attack encryption methods such as RSA.” G. Swain, Chinese Researchers break RSA encryption with a quantum computer, in CSO, October 14, 2024.

Providing more detail of their recent successes, the Chinese researchers wrote, “Using the D-Wave Advantage, we successfully factored a 22-bit RSA integer, demonstrating the potential for quantum machines to tackle cryptographic problems…  This is the first time that a real quantum computer has posed a substantial threat to multiple full-scale SPN-structured algorithms in use today.”  These researchers did not just stop at RSA.  “They also attacked algorithms crucial to the Advanced Encryption Standard (AES), including Present, Rectangle, and the Gift-64 block cipher.” Id.  While AES-256 is often labeled as military-grade and considered the most secure encryption standard available, the study suggests that the quantum computers may soon threaten such security.  M. Swayne, Chinese Scientists Report Using Quantum Computer to Hack Military-Grade Encryption, in the quantuminsider.com, October 11, 2024.

Notably, these developments will benefit the same government that has been positioning itself for a large-scale cyber war on the United States Government and U.S. civilian infrastructure for years.  As FBI Director Wray noted in a speech earlier this year, Chinese government-linked hackers have burrowed into U.S. critical infrastructure and are waiting “for just the right moment to deal a devastating blow.” C. Bing, FBI says Chinese hackers preparing to attack U.S. infrastructure, Reuters, April 18, 2024.  “An ongoing Chinese hacking campaign known as Volt Typhoon has successfully gained access to numerous American companies in telecommunications, energy, water and other critical sectors, with 23 pipeline operators targeted, Wray said in a speech at Vanderbilt University.”   Id.   Of concern to the U.S. Department of Defense, the Chinese Communist Party wants to prevent the United States from being able to get in the way of a potential future “crisis between China and Taiwan by 2027”, Director Wray noted.  Id.

Although there have been many widely-expressed opinions that “Q-Day” is anywhere from 3 to 10 years away,  the recent developments in the U.S. and China described above suggest that such opinions represent wishful thinking.  Unfortunately, the timetable recently published by  NIST for moving government agencies off of current types of encryption onto what they hope will be quantum-resistant encryption by 2035 reflects the outer edge of that wishful thinking; “analysts urge enterprises to move much more quickly, given that state actors are expected to achieve quantum at scale by 2028.”    E. Schuman, NIST publishes timeline for quantum resistant cryptography, but enterprises must move faster, in CSO, November 13, 2024.  In light of typical government and private enterprise timelines for consideration and large-scale, comprehensive adoption of newer quantum-resistant technology, even the 2028 prediction would require the commencement of that timeline in 2025 in order to safely provide adequate time for consideration, budgeting, architecture and integration analysis and design, order, delivery, installation and implementation of such technology.

Unfortunately, there is another obstacle to timely implementation of technologies that will reliably defend against quantum computer-based cyberattacks;  while they are major, laudable improvements over older cryptographic paradigms, at least three of the four NIST-approved post-quantum cryptography (PQC) algorithms ultimately may prove inadequate to stop quantum computer-based cyberattacks for more than a short duration based on recent information about quantum algorithms.   It has already been recognized that the mathematical faculties of the HHL quantum algorithm could undermine the security foundations of lattice-based cryptography.  M. Swayne, Is Q-Day Closer than We Think? IBM Researchers Say Hybrid Quantum-AI May Pose Near-Term Threats, in thequantuminsider.com, March 26, 2024.  Three of the four NIST-approved algorithms for quantum resistance are lattice-based: CRYSTALS-Kyber (FIPS 203), intended for general encryption; CRYSTALS-Dilithium (FIPS 204), intended to protect digital signatures; and FALCON (soon to be FIPS 206, intended to be released late this year), also intended to protect digital signatures.  See NIST Releases First 3 Finalized Post-Quantum Encryption Standards, NIST News, August 13, 2024[1].

The advent of sophisticated artificial intelligence algorithms undoubtedly will enhance and expedite the destructive capabilities of quantum computers.   “The cyber-world faces the worst nightmare with the advent of AI and quantum computers. Together with Quantum Artificial Intelligence (QAI), they pose a catastrophic threat to modern cryptography. It would also increase the capability of cryptanalysts manifold, with its built-in persistent and extensive predictive intelligence.”  S. Harris et al., Cryptography: Against AI and QAI/Odds in Cornell University’s arXiv 2309.07022.

Further, the PQC algorithms reportedly appear to be inadequate to stop Harvest Now, Decrypt Later (HNDL) data thefts.

Alternative quantum-safe, post-PQC cyber security technologies have become available, including one time pad-based systems, a version of which our company, QD5, now offers after multiple years of development.   This approach was discussed and the topic of interviews in a Reuters publication last December.    See D. Lague, U.S. and China race to shield secrets from quantum computers in Reuters Special Report, December 14, 2023.  However, various governmental and corporate bureaucratic obstacles, processes and budget prioritizations prevent such systems from being widely, timely and adequately tested, approved, and deployed within the foreseeable timeframe of quantum computer-based cyberattacks; the additional testing, comparison, approval and adoption of such newer technologies in light of those typical processes and timeframes of U.S. Government agencies and large, critical infrastructure enterprises could add two years to the currently likely timeframe of two to three years for widespread adoption of PQC methodologies by enterprises that have not yet implemented any such methodology. These aggregate timeframes could result in widespread implementation, integration and fully operational condition of post-PQC quantum-safe technologies in 2029 or 2030- potentially two years too late, based on what now appears to be the likely timeframe for large-scale deployment and utilization of destructively-programmed quantum computers.

Lest the extent of delay in the approval and implementation process under current bureaucratic budgeting and decision-making timeframes be doubted, the duration of the process for NIST to request, initially approve and finally release standards for PQC algorithms has been a recent reminder: a call for submissions in 2016; receipt of submission of sixty-nine (69) algorithms in November 2017; selection of four (4) algorithms in 2022; and publication of the standards for three ) of them in  2024-an 8-year process.   In view of the perceived speed of development of quantum computing  capabilities during the period 2016-2019 and of the effects of COVID in 2020-2022, this timeframe may have been understandable; however, in light of recent quantum computer developments described above and the adversarial focus on critical cybersecurity and infrastructure functionality described above and below, a similar timeframe for approval of post-PQC cryptography standards would appear contrary to the national interest.  NIST is continuing to evaluate two other sets of algorithms as potential backup standards, one set of three algorithms for general encryption based on a different type of math problems than the general purpose algorithm in the finalized PQC standards, and a second set of algorithms for digital signatures.  See NIST News, August 13, 2024, supra.

Somewhat surprisingly, at a Homeland Security & Defense Forum earlier this year, it became apparent to several attendees that although aware of and concerned about the quantum threat, the U.S. Government does not appear to have developed a sufficiently clear, agreed and expedited path to build adequate quantum-safe cyber protections for all of its agencies nor for critical infrastructure within a foreseeable timeframe for future quantum computer-driven attacks (which will be made more virulent by combining AI with quantum technology).  QD5’s experience has been that interagency disagreements over apparently conflicting priorities have introduced some paralysis for a significant part of this year.  Retired military and government personnel have acknowledged privately that bureaucratic red tape and excessive regulation are major impediments (frequently 2-year impediments) to moving with adequate speed to test and acquire new quantum-safe technologies capable of shoring up cyber defenses against predictable future quantum-based cyber attacks that the current PQC algorithms may not withstand for long. Many private entities are in denial while hoping to avoid the need to invest the capital required to shore up their cybersecurity defenses, until and unless a major incident occurs that will force them to address the issue. In the meantime, they seem content to use only somewhat secure solutions.  Many corporate in-house software architects are resistant to suggesting any overhaul of the systems that they built at material cost already.  The problem is that once quantum computer attacks start, they can move so quickly with such nationwide and system-wide attacks at such speeds that it will be too late to respond before significant damage may already have occurred en masse (such as frozen electric power grids, stolen military secrets, and stripped bank accounts).

The potentially cataclysmic damage to the security and reliability of governmental and critical infrastructure databases, communications, and operability that could be instigated by fully developed and targeted quantum computing are highlighted by the increasing audacity and severity of numerous recent cyberattacks that  appear to have relied on technology that is less sophisticated than quantum computers:

  • July 2023 – Chinese espionage group Storm 0558 reportedly hacked into Microsoft cloud/emails storing US Government emails. McLaughlin, Microsoft says Chinese hackers breached email including U.S. government agencies in NPR, July 12, 2023.
  • January 2024 – Russian hackers reportedly accessed Microsoft source code repositories and HP Enterprise’s cloud-based systems. See S. Lyngaas, Russian hackers breach key Microsoft systems in CNN Business, March 8, 2024.
  • January 2024– FBI Director Wray tells the House Select Committee on the Chinese Communist Party, ““China’s hackers are positioning on American infrastructure in preparation to wreak havoc and cause real-world harm to American citizens and communities, if or when China decides the time has come to strike… The Chinese hackers are working “to find and prepare to destroy or degrade the civilian critical infrastructure that keeps us safe and prosperous.””  H. Rabinowitz and S. Lyngass,  FBI director warns that Chinese hackers are preparing to ‘wreak havoc’ on US critical infrastructure in CNN Politics, January 31, 2024.
  • February 2024 – ransomware cyberattack on UnitedHealth Group’s Change Healthcare is projected to produce costs and losses of $2.3-$2.45 billion this year. Bruce Japsen, UnitedHealth Group Cyberattack Costs to Hit $2.5 Billion This Year, Forbes, July 16, 2024.
  • June 2024 – ransomware cyberattack on CDK Global, a leading software provider to a reported 15,000 car dealerships, freezing its dealership management system for weeks and thus froze many of its client auto dealers’ maintenance and sales operations for weeks. See Brett Foote, CDK Cyberattack Cost Dealers Over $1 Billion: Report in Ford Authority, July 15, 2024.
  • October 2024 – The Wall Street Journal announced that AT & T and Verizon networks were hacked by a cyberattack tied to the Chinese government. See U.S. Wiretap Systems Targeted in China-Linked Hack in WSJ, October 5, 2024.
  • October 2024 – Chinese researchers confirm attempts to break AES-256 and RSA 2048 using a D-wave quantum computer, see above.
  • November 2024 – “Senate Intelligence Committee Chair Mark Warner says he’s stunned by the scope of China’s breach into the U.S. telecommunications system, which went further than was described by the Biden Administration.” S. Fitzgerald, Sen. Mark Warner Stunned by China’s Penetration of US Phones, Newsmax, November 22, 2024. “The Chinese hackers, which Microsoft named Salt Typhoon, have been able to monitor Americans’ cell phone calls and texts…”

 

In light of the need to expedite hardening U.S. government, critical infrastructure and enterprise systems with post-PQC technology that will be resistant to impending quantum-driven cyber attacks, as well as the foreseeably lengthy, bureaucratically-driven multi-year lead time for consideration, comparison, approval, and  messaging about such technology (and the need in each implementation case to architect the integration and adaptation of new technologies to  entities’ existing systems), the following solution elements at a minimum should be prioritized to expedite the implementation of truly durable quantum-resistant technologies that can prevent or substantially mitigate many of the potentially catastrophic consequences of Q-Day:

  • Move the U.S. Government and allied governments to update PQC standards rapidly with technology that is not lattice-based or based on potentially decipherable mathematical algorithms and instead is based on newer technology that presently appears un-hackable by any currently known technology (such as one-time pad based systems when properly architected and deployed, with zero trust principles applied), combined with artificial intelligence to recognize artificial intelligence attacks and quantum-based attacks, and other technological solutions that utilize quantum-based capabilities to defeat quantum cyber  attacks;
  • Eliminate or streamline governmental (including U.S. military) bureaucratic procedures, conflicting agency priorities, and timeframes for testing and contracting to acquire  new technology, or make special exceptions for cryptographic and cybersecurity solution testing and implementation;  and
  • Provide private corporations with significant tax credits and other incentives to invest in the deployment of new, post-PQC quantum-safe cybersecurity solutions.

    If these recommended steps are not undertaken within the next year, if appears likely that the U.S. Government and critical infrastructure enterprises, as well as banking and energy consumers, will learn a painful lesson that we have been two years behind the cryptographic and cybersecurity development, adoption and implementation trajectory that would best protect our society, security and daily life from the foreseeably destructive and disruptive consequences of quantum computers in the hands of hostile actors.

    Note: This paper’s contents include personal opinions of the author, Daniel P. Neelon, President and CEO QuantumSafe Data Systems Inc. (“QD5”)

    [1] The fourth, the Sphincs+ algorithm (FIPS 205), designed to protect digital signatures,  utilizes hashing techniques and is based on a different mathematical approach than the CRYSTALS-Dilithium algorithm, see id.; however, to the extent that it is still mathematically-based, there is a question mark about its eventual potential vulnerability to quantum computer compromise.