首页|迈向量子安全:后量子密码迁移研究与思考

迈向量子安全:后量子密码迁移研究与思考

扫码查看
量子科技的飞速发展使得大规模量子计算机的实现只是时间问题,一些量子算法的提出(如Shor、Grover、Simon)使得对现代密码体制(公钥密码和对称密码)实施量子计算攻击成为可能,从而严重威胁经典密码的安全。为提升密码系统抵抗量子计算攻击的能力,以格密码为代表的后量子密码(PQC)算法得到广泛关注和研究。从经典密码算法到PQC的迁移是密码系统实现量子安全的有效路径。首先,该文调研了NIST,ETSI及其他组织和学者提出的PQC迁移路线,总结起来,就是以NIST为代表的替换方案、以ETSI为代表的二次加密方案以及其他混合加密方案三种迁移路线;其次,针对PQC迁移过程,从迁移目标、迁移准备、迁移实施三个环节介绍了迁移策略;此外,为了促进PQC迁移的顺利高效实施,提出了需要考虑的迁移评估要素,包括资源投入、时间成本、业务风险、维护成本、用户体验、商业影响六个方面;最后,提出PQC迁移下一步研究方向。总之,文中工作将为PQC迁移的方案设计和高效实施提供有益参考。
Toward Quantum Security:Research and Reflections on Post-quantum Cryptographic Migration
The rapid development of quantum technology brings the realization of large-scale quantum computers just a matter of time,and the proposal of some quantum algorithms(e.g.,Shor,Grover,Simon)makes it possible to implement quantum computing attacks on modern cryptosystems(public-key cryptography and symmetric cryptography),which seriously threatens the security of classical cryptography.In order to enhance the ability of cryptosystems to resist quantum computing attacks,post-quantum cryptography(PQC)algorithms,represented by lattice cryptography,have received extensive attention and investigation.The migration from classical cryptography algorithms to PQC is an effective path for cryptosystems to realize quantum security.Firstly,we investigate the PQC migration routes proposed by NIST,ETSI,and other organizations and scholars,which are summarized as three migration routes,namely,the substitution scheme represented by NIST,and the double encryption scheme represented by ETSI,and other hybrid encryption schemes.Secondly,for the migration process of PQC,we introduce the migration strategy from the three aspects of migration target,migration preparation,and migration implementation.In addition,in order to promote the smooth and efficient implementation of PQC migration,we propose the migration evaluation elements to be considered,including six aspects of resource investment,time cost,business risk,maintenance cost,user experience,and business impact.Finally,we propose the future research direction of PQC migration.Overall,the work in this paper will provide a useful reference for the scientific design and efficient implementation of PQC migration.

post-quantum cryptographymigrationinformation securitysystem securitynetwork security

冯艺萌、刘昂

展开 >

北京电子科技学院,北京 100070

北京邮电大学 网络空间安全学院,北京 100876

后量子密码 迁移 信息安全 系统安全 网络安全

中央高校基本科研业务费资金资助中央高校基本科研业务费资金资助

32820230153282023051

2024

计算机技术与发展
陕西省计算机学会

计算机技术与发展

CSTPCD
影响因子:0.621
ISSN:1673-629X
年,卷(期):2024.34(5)
  • 45