News: 1691836029

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google Chrome to shield encryption keys from promised quantum computers

(2023/08/12)


Google has started deploying a hybrid key encapsulation mechanism (KEM) to protect the sharing of symmetric encryption secrets during the establishment of secure TLS network connections.

Devon O'Brien, technical program manager for Chrome security, [1]explained on Thursday that starting in Chrome 116 – [2]due August 15 – Google's browser will include support for [3]X25519Kyber768 , an alphanumeric salad that desperately needs a catchy name.

The unwieldy term is a concatenation of [4]X25519 , an elliptic curve algorithm that's currently used in the key agreement process for establishing a secure TLS connection, and [5]Kyber-768 , a quantum-resistant KEM that last year [6]won NIST's blessing for [7]post-quantum cryptography.

[8]

A KEM is a way to establish a shared secret value between two people so they can communicate confidentiality using symmetric key encryption. It's a precursor ritual to secure information exchange over a network. Unless you're a cryptographer or just love math, you're probably fine not knowing the technical details.

Waiting for that fusion-powered quantum computer on Mars

Google is deploying a hybrid version of these two algorithms in Chrome so the web goliath, users of its technology, and other network providers [9]like Cloudflare , can test quantum-resistant algorithms while maintaining current protections.

The Chocolate Factory is doing so because some day, many very bright people believe, quantum computers will be able to break at least some legacy encryption schemes. That belief is what motivated US technical agency NIST in 2016 to [10]call for future-proof encryption algorithms.

Useful quantum computers will be impossible without error correction [11]READ MORE

Quantum computers, though much discussed, have yet to demonstrate much practical value due to the need for extensive error correction and many times more qubits.

Google in 2019 said it had conducted an experiment that [12]demonstrated quantum supremacy – the idea that a quantum computer could outperform a classical one. But IBM researchers at the time said the same experiment "can be performed on a classical system in 2.5 days and with far greater fidelity." So it was not much of a win for quantum boosters.

[13]

[14]

In June this year, however, IBM researchers published [15]a study in Nature that claimed a 127-qubit processor set loose on a particular physics problem can, with sufficient error mitigation, outperform a classical computer. If confirmed by other researchers, the results suggest quantum computers have a path toward relevancy.

Key issue

"It’s believed that quantum computers that can break modern classical cryptography won't arrive for 5, 10, possibly even 50 years from now, so why is it important to start protecting traffic today?" said O'Brien.

"The answer is that certain uses of cryptography are vulnerable to a type of attack called [16]Harvest Now, Decrypt Later , in which data is collected and stored today and later decrypted once cryptanalysis improves."

O'Brien says that while symmetric encryption algorithms used to defend data traveling on networks are considered safe from quantum cryptanalysis, the way the keys get negotiated is not. By adding support for a hybrid KEM, Chrome should provide a stronger defense against future quantum attacks.

[17]

Google's early deployment of the technology also has practical value to network admins because the new hybrid KEM scheme adds more than a kilobyte of extra data to the TLS ClientHello message. When the internet giant conducted a similar experiment with [18]CECPQ2 , some TLS middleboxes couldn't handle the traffic because they had a hardcoded limit on message size.

"I think this is a nice development," said Matthew Green, a cryptography professor at Johns Hopkins University, in an email to The Register .

Any encrypted messages sent today could be stored until those computers are eventually built. By adding post-quantum encryption to today’s connections, that threat is eliminated

"Quantum computers are probably at least 15 years away, if not more. But in principle any encrypted messages sent today could be stored until those computers are eventually built.

"By adding post-quantum encryption to today’s connections, that threat is eliminated. Plus this gives us a very good opportunity to test out some of these new encryption systems long before they’re really needed."

Rebecca Krauthamer, co-founder and chief product officer at QuSecure, told The Register in an email that while this technology sounds futuristic, it's useful and necessary today for two reasons.

[19]

"First, data is being intercepted today for later decryption in what is referred to as a harvest now decrypt later attack," she said.

"There are many forms of data shared via browser-based communications that are valuable now, and will continue to be valuable into the future, including private email communications, electronic health records, bank account information, and more."

[20]A lone Nvidia GPU speeds past the physics-straining might of a quantum computer – in these apps at least

[21]Russia's tiny quantum computer is (probably) nothing to worry about

[22]Quantum computing is a different kind of computing, says AWS

[23]DARPA's quantum computing is powered by ... FOMO

Krauthamer said data that needs to be safeguarded in the future should be protected with quantum resilient cryptography today. She also pointed out that President Biden last year signed [24]H.R.7535 , The Quantum Computing Cybersecurity Preparedness Act, which requires US government agencies to begin moving toward quantum resilient cryptography.

"Google is making a fantastic step toward enabling users to protect their communications," she said.

"At QuSecure we are working from a parallel angle allowing organizations and governments to enable quantum resilient encryption for their own data and that of their users. We will sometimes hear our clients asking if it's already too late to deploy this kind of technology to protect their data if some of it has already been harvested. The answer is absolutely not, but we cannot wait any longer."

There was no press release when the team at Bletchley Park cracked the Enigma

Second, said Krauthamer, the arrival of capable quantum computers should not be thought of as a specific, looming date, but as something that will arrive without warning.

"There was no press release when the team at Bletchley Park cracked the Enigma code, either," she said.

"Revealing these developments would have shifted the balance of power. If you've created an incredibly powerful tool, you don't show your hand, whether you're working for good or bad. This principle is going to apply to whoever achieves a cryptographically relevant quantum computer. It's a game where keeping the upper hand means keeping secrets.

"This means that we can’t know when it will come online, but it will likely happen without our knowledge, and it’s imperative we deploy this defensive technology today to not be caught flat footed." ®

Get our [25]Tech Resources



[1] https://blog.chromium.org/2023/08/protecting-chrome-traffic-with-hybrid.html

[2] https://chromiumdash.appspot.com/schedule

[3] https://www.ietf.org/archive/id/draft-tls-westerbaan-xyber768d00-02.html

[4] https://www.rfc-editor.org/rfc/rfc7748

[5] https://pq-crystals.org/kyber/index.shtml

[6] https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms

[7] https://www.theregister.com/2022/07/05/nist_quantum_resistant_algorithms/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNespeA9UKt1AOsBa9CTLwAAAJc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[9] https://blog.cloudflare.com/experiment-with-pq/

[10] https://www.nist.gov/news-events/news/2016/12/nist-asks-public-help-future-proof-electronic-information

[11] https://www.theregister.com/2020/12/09/quantum_computing_correction/

[12] https://www.theregister.com/2019/10/22/ibm_poopoos_google_quantum_claims/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNespeA9UKt1AOsBa9CTLwAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNespeA9UKt1AOsBa9CTLwAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.nature.com/articles/s41586-023-06096-3

[16] https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNespeA9UKt1AOsBa9CTLwAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[18] https://www.chromium.org/cecpq2/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNespeA9UKt1AOsBa9CTLwAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[20] https://www.theregister.com/2023/05/03/quantum_reality_check/

[21] https://www.theregister.com/2023/07/20/russias_tiny_quantum_computer_is/

[22] https://www.theregister.com/2022/12/05/quantum_computing_aws_interview/

[23] https://www.theregister.com/2023/02/02/darpa_quantum_microsoft/

[24] https://www.congress.gov/bill/117th-congress/house-bill/7535/text

[25] https://whitepapers.theregister.com/



Dinanziame

Thus making quantum computers even more useless.

Alien Doctor 1.1

"X25519Kyber768, an alphanumeric salad that desperately needs a catchy name."

How about "Ruff-Diamond?"

Alien Doctor 1.1

If you don't know that, you're either not british or too bloody young to be here.

Teaser......Diffie/Helman might be more secure than described......

Anonymous Coward

Quote: "...symmetric encryption algorithms used to defend data traveling on networks are considered safe from quantum cryptanalysis, the way the keys get negotiated is not..."

Is this statement true? As I understand it, the Diffie/Hellman process:

(1) Ensures that secret keys are calculated on the end point as needed....but are never stored and never transmitted across a network

(2) Network traffic DOES contain D/H tokens, but these tokens reveal NOTHING about the secret key agreed between the two parties

(3) Decent D/H implementations use a completely different random key (and different D/H tokens) for each and every transaction

....so, the assertion about "keys get negotiated" not being safe is likely not true.

....and isn't the use of the phrase "quantum cryptanalysis" simply a teaser......with no relevance at all to actual practice in defining secret keys?

sitta_europea

Quoting Matthew Green, a cryptography professor at Johns Hopkins University,

"... in principle any encrypted messages sent today could be stored until those computers are eventually built. By adding post-quantum encryption to today’s connections, that threat is eliminated."

Correction. That threat is eliminated if it's done properly. Sadly our record on doing things properly on the Internet is somewhat less than stellar.

"Krauthamer ... also pointed out that President Biden last year signed H.R.7535, The Quantum Computing Cybersecurity Preparedness Act, which requires US government agencies to begin moving toward quantum resilient cryptography."

But she failed to point out that none of this would stop a bunch of spotty teenagers from compromising any number of large US corporations, which they did by simply going around all the fences.

None of this high-tech stuff will ever stop them.

That's good

DS999

Because I plan to be using the same password at The Register in 15 years and I don't want someone capturing a session where I'm logging in this year and decrypting it to steal my account in 2038!

Re: That's good

sitta_europea

"... I don't want someone capturing a session where I'm logging in this year and decrypting it to steal my account in 2038!"

I feel sure you didn't choose that year by accident...

A definition of teaching: casting fake pearls before real swine.
-- Bill Cain, "Stand Up Tragedy"