Building a practical path to post-quantum cryptography
Building a practical path to post-quantum cryptography
构建后量子密码学的实用路径
Sponsored Provided by Intel 由英特尔赞助提供
Quantum computing has alternated between breakthrough darling and overhyped promise in technology circles. Its powerful new capabilities come with a threat to break current cryptography, but for business leaders navigating the noise, the signal should be clear: post-quantum cryptography (PQC) is a manageable evolution, not a crisis. The mathematics behind today’s encrypted digital transactions may yield to quantum computers one day, but the transition to quantum-resistant algorithms is neither sudden nor insurmountable. For executives concerned about disruption, cost, or complexity, a structured and phased approach exists with trusted technology partners like Intel that are already beginning to deliver the infrastructure to make it possible. 在科技圈中,量子计算一直在“突破性的宠儿”和“被过度炒作的承诺”之间摇摆不定。其强大的新能力伴随着破解现有密码学的威胁,但对于在噪音中寻找方向的商业领袖来说,信号应该是明确的:后量子密码学(PQC)是一种可控的演进,而非一场危机。当今加密数字交易背后的数学原理终有一天可能会被量子计算机攻破,但向抗量子算法的过渡既非突如其来,也非不可逾越。对于担心业务中断、成本或复杂性的高管而言,通过英特尔等值得信赖的技术合作伙伴,可以采取结构化和分阶段的方法,这些合作伙伴已经开始提供实现这一目标所需的基础设施。
A natural evolution, not a cliff edge
一场自然演进,而非悬崖边缘
The “quantum threat” narrative often swings between two extremes: imminent catastrophe or distant irrelevance. The reality occupies a more pragmatic middle ground. Quantum computers are highly specialized accelerators that exploit quantum physics to solve specific hard problems. They have the potential to crack modern encryption, but they will not replace classic servers overnight, nor will they instantly break every encryption protocol on the internet. What they will do is gradually shift the security landscape, much as previous cryptographic transitions have done over the past three decades. 关于“量子威胁”的叙述往往在两个极端之间摇摆:迫在眉睫的灾难或遥不可及的无关紧要。现实则处于一个更务实的中点。量子计算机是利用量子物理学来解决特定难题的高度专业化加速器。它们有潜力破解现代加密技术,但不会在一夜之间取代传统服务器,也不会瞬间破坏互联网上的每一个加密协议。它们所做的是逐渐改变安全格局,正如过去三十年中历次密码学转型所做的那样。
In late 2024, the Global Risk Institute, a Toronto-based financial services think tank, surveyed 32 quantum computing experts on when a quantum computer could break a 2048-bit RSA key within 24 hours. An average of optimistic and pessimistic estimates from the experts gave it an even 50-50 probability of reaching this code-breaking milestone by 2040. This timeline, uncertain but measurable, creates space for deliberate planning rather than emergency reaction. The near-term focus should be on “harvest now, decrypt later” scenarios, where adversaries collect encrypted data today and then hold it for future decryption later when that capability becomes possible. This is particularly applicable for information requiring confidentiality beyond 10 years. For most enterprises, this can be a manageable risk when addressed through methodical modernization. 2024 年末,总部位于多伦多的金融服务智库“全球风险研究所”(Global Risk Institute)调查了 32 位量子计算专家,询问量子计算机何时能在 24 小时内破解 2048 位 RSA 密钥。专家们的乐观和悲观估计平均显示,到 2040 年达到这一破解里程碑的概率为 50-50。这个虽不确定但可衡量的时间表,为深思熟虑的规划留出了空间,而不是采取紧急反应。近期的重点应放在“先获取,后解密”(harvest now, decrypt later)的场景上,即对手在今天收集加密数据,并在未来具备解密能力时再进行解密。这尤其适用于需要超过 10 年保密期的信息。对于大多数企业而言,通过有条不紊的现代化改造,这是一种可控的风险。
Government signals as confidence builders
政府信号作为信心建立者
The U.S. government has issued new directives for National Security Systems (NSS), which would likely be first on the list for potential quantum attack. Beginning in January 2027, new NSS acquisitions must be capable of supporting Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requirements for PQC algorithms standardized by the National Institute of Standards and Technology (NIST) and selected by the National Security Agency, the U.S. intelligence agency responsible for signals intelligence and information assurance. Implementation for new systems (with certain exceptions) is then required by 2031, with 100% adoption targeted by 2035. For commercial enterprises, these timelines are not mandates, but could be signposts. They indicate where vendors, standards bodies, and auditors are headed, providing a reference architecture for responsible stewardship. Organizations can borrow this discipline without necessarily copying the exact timelines, using government guidance to calibrate their own risk tolerance and investment cadence. 美国政府已针对国家安全系统(NSS)发布了新指令,这些系统很可能是潜在量子攻击的首要目标。从 2027 年 1 月开始,新的 NSS 采购必须能够支持商业国家安全算法套件 2.0(CNSA 2.0)的要求,这些要求针对的是由美国国家标准与技术研究院(NIST)标准化,并由负责信号情报和信息保障的美国情报机构——国家安全局(NSA)所选定的 PQC 算法。新系统(除某些例外情况外)必须在 2031 年前完成实施,目标是在 2035 年实现 100% 采用。对于商业企业而言,这些时间表并非强制要求,但可以作为路标。它们指明了供应商、标准机构和审计机构的发展方向,为负责任的管理提供了参考架构。组织可以借鉴这种纪律,而不必完全照搬时间表,利用政府指导来校准自身的风险承受能力和投资节奏。
Intel’s role: Infrastructure ready for the transition
英特尔的角色:为转型做好基础设施准备
Intel is at the heart of the AI revolution by delivering quantum-resistant capabilities across our product portfolio. This is not just aspirational roadmap language; it is starting to be shipping technology. For instance, the Intel Xeon 6 Processor already incorporates quantum-safe memory encryption (AES-256) and microcode signing to protect processor integrity. Upcoming platforms will extend post-quantum algorithms to more firmware and software signing, device interconnects, attestations, and secure boot functions, aligning with the most stringent government and industry directives. 英特尔通过在整个产品组合中提供抗量子能力,处于人工智能革命的核心。这不仅仅是愿景路线图的语言,而是已经开始交付的技术。例如,英特尔至强 6 处理器(Intel Xeon 6 Processor)已经集成了量子安全内存加密(AES-256)和微代码签名,以保护处理器完整性。即将推出的平台将把后量子算法扩展到更多的固件和软件签名、设备互连、认证和安全启动功能,以符合最严格的政府和行业指令。
Post-quantum algorithms carry different key sizes and computational overhead than legacy methods. Intel addresses this through dedicated cryptographic accelerators, optimized libraries, and specialized CPU instructions that reduce latency and preserve service-level agreements. Technologies such as Intel QuickAssist Technology offload cryptographic workloads, enabling enterprises to adopt stronger algorithms without sacrificing performance. PQC is not a processor-alone problem. System builders and application owners must take a comprehensive view spanning solid-state drives, network interface cards, operating systems, hypervisors, applications, and connected services. Intel is delivering its pieces of the stack, while collaborating with ecosystem partners to ensure interoperability and smooth transition paths. A more in-depth discussion of post-quantum algorithms and attacks can be found in my recent blog posted on Intel’s Community forum: “Post-Quantum Crypto: Panic Like It’s 1999?” 后量子算法与传统方法相比,具有不同的密钥大小和计算开销。英特尔通过专用的加密加速器、优化的库和专门的 CPU 指令来解决这一问题,从而降低延迟并维护服务水平协议。英特尔 QuickAssist 技术等技术可以卸载加密工作负载,使企业能够在不牺牲性能的情况下采用更强大的算法。PQC 不仅仅是处理器的问题。系统构建者和应用程序所有者必须采取全面的视角,涵盖固态硬盘、网卡、操作系统、虚拟机管理程序、应用程序和连接的服务。英特尔正在交付其堆栈部分,同时与生态系统合作伙伴协作,以确保互操作性和平滑的转型路径。关于后量子算法和攻击的更深入讨论,可以在我最近在英特尔社区论坛上发布的博客中找到:《后量子密码学:像 1999 年那样恐慌?》(Post-Quantum Crypto: Panic Like It’s 1999?)。
A practical roadmap for enterprises
企业实用路线图
The path forward does not require upheaval, just discipline. Organizations can follow a phased approach that mirrors patterns emerging in government and critical infrastructure sectors: 前进的道路不需要剧变,只需要纪律。组织可以遵循一种分阶段的方法,借鉴政府和关键基础设施领域正在出现的模式:
- Approach PQC as modernization, not mitigation. Frame the transition as an opportunity to strengthen cryptographic foundations, reduce technical debt, and improve system maintainability.
- 将 PQC 视为现代化改造,而非单纯的缓解措施。 将转型视为加强密码学基础、减少技术债务并提高系统可维护性的机会。
- Leverage trusted partners. Technology suppliers like Intel are already shipping quantum-resistant capabilities with performance acceleration. Evaluate platform readiness and vendor roadmaps as part of procurement decisions.
- 利用值得信赖的合作伙伴。 像英特尔这样的技术供应商已经在交付具备性能加速的抗量子能力。在采购决策中评估平台就绪情况和供应商路线图。
- Start with visibility. Cryptography is embedded throughout modern technology stacks: not just in database encryption settings but in data at rest, data in transit, digital signatures, code signing, device identity, password hashing, and software update mechanisms. Start by mapping where cryptographic assets live, what algorithms protect them, and w
- 从可见性开始。 密码学嵌入在现代技术堆栈的各个环节:不仅在数据库加密设置中,还包括静态数据、传输中数据、数字签名、代码签名、设备身份、密码哈希和软件更新机制。首先要梳理密码学资产的位置、保护它们的算法,以及……