Capgemini-未来加密_为什么后量子密码学是新的网络安全议程的首要任务(英)-2025_87页_9mb
报告摘要
Future Encrypted: Summary
Core Content
This report highlights the growing importance of quantum-safe cryptography (PQC) in the cybersecurity agenda due to the rapid advancement of quantum computing. Traditional encryption methods such as RSA and ECC are vulnerable to quantum attacks, which could break current cryptographic systems and expose sensitive data that is now being intercepted. The concept of "harvest-now, decrypt-later" attacks underscores the urgency of transitioning to quantum-safe measures before quantum computers become powerful enough to do so.
The report emphasizes that quantum safety is not just a technical concern but a strategic imperative, driven by regulatory mandates, customer expectations, and competitive advantage. Organizations must adopt a long-term, strategic approach to ensure crypto-agility—the ability to adapt and implement new cryptographic solutions swiftly.
Main Points
- Quantum computing threatens to break current encryption standards, making post-quantum cryptography essential for long-term security.
- 70% of organizations surveyed are either working on or planning to implement quantum-safe solutions within the next five years.
- 30% of organizations still underestimate the threat, risking future data exposure and regulatory penalties.
- Only 16% of early adopters and 11% of the overall sample are considered "quantum-safe champions," highlighting the need for mature governance and technical execution.
- NIST has standardized three post-quantum algorithms (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+), and NSA recommends phasing out RSA and ECC by 2030 and 2035, respectively.
- The European Union recommends transitioning to PQC by the end of 2026, with critical infrastructures to be updated by 2030.
Key Recommendations
To ensure quantum readiness, organizations should:
- Conduct quantum risk assessments to identify and prioritize sensitive assets.
- Create awareness and governance to integrate quantum safety into strategic decision-making.
- Plan for a phased transition to PQC, starting with targeted pilots and scaling across the enterprise.
- Focus on crypto-agility to allow for quick adaptation to evolving standards and threats.
- Ensure system protection by applying quantum-safe controls to both edge devices and legacy systems.
- Invest in capacity development to sustain PQC adoption without compromising system performance.
- Strengthen collaboration by including quantum-safe clauses in supplier contracts and fostering cross-industry partnerships.
Quantum-Safe Solutions Overview
The following are key quantum-safe solutions currently in development or use:
| Solution | Example | Maturity | Use Case |
|---|---|---|---|
| Post-Quantum Cryptography (PQC) | CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ | Commercially emerging | Secure key exchange, digital signatures |
| Quantum Key Distribution (QKD) | N/A | Emerging | Secure key distribution, eavesdropping detection |
| Fully Homomorphic Encryption (FHE) | N/A | Emerging | Encrypted data processing |
| Quantum Random Number Generators (QRNG) | N/A | Emerging | Enhancing encryption randomness |
| Hardware Security Modules (HSMs) | N/A | Mature | Secure key management and operations |
Sectoral Adoption Trends
- Defense leads with 90% of organizations planning to adopt PQC within the next five years.
- Banking follows with 86%, and aerospace with 83%.
- Consumer products and retail lag at 48% and 49%, respectively.
Strategic Importance
- 61% of early adopters believe quantum computers will break current encryption methods within the next decade.
- 57% of early adopters are preparing for Q-Day regardless of when quantum computing becomes mainstream.
- 71% of early adopters cite "futureproofing against quantum attacks" as a key driver for PQC adoption.
- 75% of executives emphasize the importance of industry-wide collaboration in addressing quantum-related security risks.
Time is Running Out
- The threat of quantum computing is imminent, with Q-Day expected within 5–10 years.
- 62% of early adopters believe the industry is reaching a consensus on PQC as the primary quantum-safe approach.
- 70% of early adopters view PQC transition as essential for maintaining competitiveness and data security.
Conclusion
The transition to quantum-safe cryptography is no longer optional—it is a strategic necessity. Organizations must act now to secure their digital assets, comply with regulations, and maintain stakeholder trust. With NIST and NCSC leading the charge, and major cloud providers and tech firms already implementing PQC, the time to prepare is now.
试读结束,高清完整版pdf/doc/ppt,请点下载