3 ms·
> The first—which they say is a sort of stage 0 because it does not describe a true quantum internet—is a network that enables users to establish a common encry
by CiPHPerCoder 8y ago
> The first—which they say is a sort of stage 0 because it does not describe a true quantum internet—is a network that enables users to establish a common encryption key, so that they can share their (classical) data securely. The quantum physics occurs only behind the scenes: the service provider uses it to create the key. But the provider also knows the key, which means that users have to trust it.
I don't like where this is going.
> In stage 1, users will start getting into the quantum game, in which a sender creates quantum states, typically for photons.
Okay, it's going exactly where I thought I was going!
----
At the risk of falling victim to the Gell-Mann effect, I'm going to call bullshit on this article.
It's overwhelmingly likely that quantum cryptography will not be the next iteration of network security technology in the real world. Rather, the focus is on what's called post-quantum cryptography. Despite what you might think, these are not two points on a timeline.
Post-quantum cryptography refers to asymmetric cryptography features that are secure even in the presence of practical quantum computers. It's not a stage that exists after quantum cryptography. There's no "intermediate" stage in which we use quantum physics itself for encryption.
There will likely be a transition, wherein today's elliptic curve cryptosystems are used in addition to a post-quantum cryptosystem (e.g. ECDH + RLWE), until industry-wide confidence is gained in the security of the latter. I expect a lot of interesting attacks to be found in PQ algorithms during that time, and eventually we'll settle on constructions that are secure without pre-quantum cryptography.
Note: Symmetric cryptography is largely unaffected by quantum computers. You essentially halve the security levels (nitpick: which is an exponent, so you'll effectively be taking the square root of the possible values rather than just "halving it", which would just shave off one bit).
Quantum key distribution and other entangled photon madness? I doubt we'll see widespread deployment of this.
EDIT: I see this article isn't the author's first inaccurate foray into this topic. They might want to consult a cryptographer before publishing bunk science. https://www.scientificamerican.com/article/the-quantum-internet-has-arrived-and-it-hasn-rsquo-t/ https://www.scientificamerican.com/article/the-quantum-inter...
- zamadatix 8y agoOn the trend of "stuff that actually matters for post-quantum cryptography" is there anything usable on the public key side? Symmetric cryptography is pretty limited in it's real world application scope.
- CiPHPerCoder 8y agoThis might answer your question: https://csrc.nist.gov/projects/post-quantum-cryptography/round-1-submissions https://csrc.nist.gov/projects/post-quantum-cryptography/rou... I would argue that nothing in this sector is "production-ready". For key exchange, SIKE looks promising (especially with the prospect of a non-interactive version). For signatures, the SPHINCS variants are also promising. Gravity-SPHINCS is more intriguing to me than SPINCS+, but, they're both good forks of an already good design.
- krastanov 8y agoI think you are conflating two similarly named topics, or at least missing the point of why one of them is useful. At the risk of saying stuff you already know (do check the last paragraph for something you might not): Quantum key exchange (only one of the applications of "quantum internet") is completely orthogonal to post quantum encryption. Quantum key exchange is a way to distribute keys, which will be used in some symmetric encryption scheme that runs on classical computers. That scheme has security that does not depend on any "difficulty" conjectures. It is "information theoretically perfect" modulo implementation bugs. (Assuming Schroedinger's equation is not wrong). This does not require the creation of a quantum computer. Actually it is much easier and already done in labs. Post quantum encryption is just the name for asymmetric encryption algorithms that run on classical computers and are difficult to break on both classical and quantum computers. Even though quantum key exchange is an exciting application of "quantum internet", way more interesting would be its use for the establishment of globe spanning entangled states. This can be used for the creation of sensors that surpass the diffraction limit and other practical "science stuff".
- bloomer 8y agoNo. I think that is the exact point he was making that quantum key distribution is orthogonal to post-quantum cryptography and that the consensus is that poat-quantum cryptography will actually be used while quantum key distribution is basically an academic exercise because it doesn't have practical utility for the problem it is attempting to solve.
- krastanov 8y agoI am confused. How is "security that does not depend on any 'difficulty' conjectures / information theoretically perfect" not of practical utility?
- NoKnowledge 8y agoThe so called quantum key-exchange requires a shared secret, so it is actually doing key-expansion. Besides that it has practical problems in side-channel protection and cannot achieve a high enough bandwidth to be of interest in most practical settings.