CASE STUDY
Protecting data

HOW
ARE QUANTUM TECHNOLOGIES PROTECTING DATA

Quantum technologies could affect data security in two important ways: by creating new approaches to protecting information, and by changing the security assumptions behind some of the encryption used today.

Most digital information is currently protected using cryptography – mathematical techniques that make data unreadable without the appropriate key and allow users to verify who they are communicating with. In the future, sufficiently powerful quantum computers could undermine some widely used forms of public-key cryptography. Quantum computers capable of doing this do not exist today, but organisations are already preparing, because replacing cryptography across large IT estates can take many years. The UK's National Cyber Security Centre (NCSC), for example, has set a target of 2035 for organisations to complete migration to post-quantum cryptography.

Quantum technologies can also offer new ways to protect information, including post-quantum cryptography, quantum communications and blind quantum computing.

WHAT MAKES QUANTUM SECURITY DIFFERENT?

Quantum computing changes both what computers may eventually be able to do and how we need to think about protecting information. Many of today's secure digital services rely on mathematical problems that are extremely difficult for conventional computers to solve. A sufficiently powerful, fault-tolerant quantum computer could solve some of these problems efficiently, making some current public-key encryption and digital-signature systems insecure. This is a future risk rather than a capability of today's quantum computers.

Fortunately, the solution does not depend on waiting for new quantum hardware. Post-quantum cryptography (PQC) uses new mathematical techniques designed to remain secure against both conventional and quantum computers and can run on conventional computing infrastructure. The transition to these technologies has already begun. Quantum physics itself also enables additional approaches to information security. Quantum communications could provide new mechanisms for distributing cryptographic keys and building secure networks, while techniques such as blind quantum computing could eventually allow sensitive calculations to be carried out using remote quantum computers without revealing the underlying information to the computer providing the service.

HOW WILL THESE TECHNOLOGIES BE USED?

Post-Quantum Cryptography

Post-quantum cryptography is likely to be one of the most significant near-term changes in information security associated with quantum computing. Future large-scale quantum computers could break some of the public-key cryptography currently used to secure websites, software, communications and digital identities. The principal response is therefore to replace vulnerable cryptographic methods with algorithms designed to resist both quantum and conventional attacks.

For most organisations, this will be a gradual technology transition rather than an emergency replacement programme. The NCSC recommends that organisations understand where vulnerable cryptography exists within their systems, prioritise important and long-lived information, develop migration plans and build cryptographic agility – the ability to change cryptographic technologies as standards and threats evolve.

Protecting Data Today from Future Attack

Some information needs to remain confidential for decades. This creates a potential risk sometimes described as "harvest now, decrypt later": an adversary could collect encrypted information today and retain it in the hope that future technology allows it to be decrypted. This does not mean that encrypted information is suddenly unsafe. The risk depends upon the type of cryptography being used, the sensitivity and lifetime of the information, and whether an attacker could realistically obtain and retain it.

However, organisations holding particularly sensitive or long-lived information (e.g., governments, critical infrastructure providers, financial institutions and healthcare organisations) have a reason to begin preparing for post-quantum security before cryptographically relevant quantum computers become available. The NCSC therefore recommends beginning migration planning well in advance of the arrival of such machines.

Blind Quantum Computing: Keeping Quantum Computations Private

As quantum computing develops, many organisations are likely to access powerful quantum computers remotely, in much the same way that organisations use cloud computing today. This raises an important question: how can an organisation use somebody else's quantum computer without revealing its sensitive information? Blind quantum computing is a potential answer.

Blind quantum computing is a family of techniques designed to allow a user to delegate a quantum computation to a remote quantum computer while keeping aspects of the computation private from the organisation operating that computer. Depending on the protocol, this can protect information about the user's data, the computation being performed and its results.

In the longer term, this could enable organisations to use specialist quantum computing services without having to disclose commercially sensitive, personal or nationally sensitive information to the quantum service provider. Blind quantum computing remains an active research field rather than a mainstream commercial service. Nevertheless, it illustrates an important possibility: quantum technologies could ultimately help protect not only data in storage and communications, but also data while it is being processed.

As quantum computing reshapes how data is secured, quantum communications will redefine how that data is transmitted and shared securely across networks.

You can find more information about this here:

BUILDING QUANTUM NETWORKS

WHY DOES THIS MATTER NOW?

The quantum computers that could threaten widely deployed public-key cryptography do not yet exist, so the issue is not an immediate cryptographic crisis. The challenge is that changing the cryptography embedded throughout governments, businesses and critical infrastructure is itself a major undertaking.

The NCSC's current roadmap illustrates the timescale involved: organisations should complete discovery and initial migration planning by 2028, undertake their highest-priority migrations by 2031, and aim to complete migration by 2035. At the same time, research into quantum communications and privacy-preserving quantum computation is opening up new approaches to securing information. Quantum technology therefore presents both a security challenge that organisations need to prepare for and an opportunity to develop new ways of protecting valuable data.

HOW WILL USE OF THIS TECHNOLOGY DEVELOP?
  • Protecting sensitive information using post-quantum cryptography.
  • Secure exchange of cryptographic keys using quantum communications.
  • Remote quantum computing while protecting confidential data through blind quantum computing.
  • Quantum-secure communications for critical national infrastructure.
  • Secure connections between future quantum data centres.
  • Quantum networking between distributed quantum computers.
  • Satellite-enabled quantum communications over very long distances.
  • Hybrid security architectures combining conventional cybersecurity, post-quantum cryptography and selected quantum technologies.

RESEARCH

Researchers worldwide are driving progress in this area with UK universities and industry playing an important role through the EPSRC-funded QCi3 Hub, QUSIT, QEPNT and IQN Hubs.