Quantum Security Overview: The Cryptography Challenge
Quantum computing presents a major challenge to traditional cryptography, threatening to break widely used encryption methods. Andrew Lord dives into how quantum computers could undermine current security systems and what’s being done to mitigate the risk. Learn about Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD), two critical approaches to safeguarding data in the quantum era. Gain insights into how organisations are preparing for the shift to quantum-resistant security.
Presented by Andrew Lord, Senior Manager, Optics and Quantum Centre of Excellence. Recorded live at Networking Field Day 37 in San Francisco, CA on March 19, 2025. Watch the entire presentation at https://techfieldday.com/appearance/bt-presents-at-networking-field-day-37/ or visit https://techfieldday.com/event/nfd37/ or https://BT.com/ for more information.
Transcript
Um, so my name is Andrew Lord. Um, I work for bt Senior Manager of the Optical and Quantum Group, uh, in research in bt. Uh, and, um, really happy to, to speak at this, uh, this event.
And this particular section, section two, is focused on quantum cryptography and, um, what this threat to security, uh, for quantum and what do we do about it? So, I'm actually not gonna talk about quantum for a few minutes. Okay?
So put your quantum hats to one side and let's think about a completely different space. So, Tom, um, you're sitting there and I'm gonna send you, well, I'm not, I'm gonna pretend to send you some secure data. Okay?
Um, how do I get this data to you? Security, Tom? Um, I need to encrypt it.
Okay? So I need to lock the data up so that someone in the middle can't even, if they can read it, they can't make any sense of it. Locking up data involves a key.
I want to send data to you. Uh, I need to lock it up using a key. Now that whole process happens all the time, every day.
Um, and the common protocol for locking up data is known as a ES 2 56. Um, this is a protocol is symmetric protocol, and it's a key that enables me to lock up data and you, Tom, to unlock the data with the same key. Okay?
Now you're probably screaming at me. Well, how do I get that key? Andrew, you, you haven't solved the problem, you just moved it.
Um, I can see how you are now getting encrypted data to me, but how do you get the key to me? And key distribution is a, is a really significant, uh, big topic that we need to address. Let's just think out of the box, how do I get some keys to Tom?
Uh, I might put a whole load of keys in a suitcase pad, lock it to somebody and fly them to, to in California. And if you're smiling, that, that happens all the time, right? That is a very common way of doing key distribution, uh, for situations where you need absolute guarantee.
Um, other, there are other ways of distributing keys is in secrets and things, but actually the main method is much more prosaic than that. It uses the network itself to distribute keys, and we distribute keys using other keys. Okay?
So, um, we use a key to distribute a key. Now, I know this is confusing, so I wanna spend a few minutes 'cause clarifying it, 'cause it's really important for the next section of this call. Um, keys to distribute keys that this whole area is known as public key cryptography.
PKC. If you Google that, you'll find millions of hits. PKC is a method for me to get a key to toll, and it uses another key, but actually it doesn't just use one key.
It uses a pair. And this pair of keys is a private and a public key that go together. The private key, um, is owned by Tom.
He doesn't let anyone see it, but his public key is public. So I get hold of it, I get his public key, which every anyone can have. And I use it to encrypt a secret key and then send it to Tom.
And Tom uses his private key to unlock that secret key. Then we both have a secret key, the same secret key that we can use to transmit data. I'm just gonna say that again because it, it, I think it helps to, to go through this twice this complex.
We're gonna, we're gonna distribute key, we gonna do it by setting up, um, public key cryptography between us. Tom has a private key and a public key. I use his public key to encrypt this secret key, send it to Tom, and he uses the private key to un decrypt it.
You can't decrypt it any other way. Public keys don't decrypt. They only encrypt that they only go one way, and that's crucial.
But the public and private key are completely linked. They're repair. It's just that if you have the public key, it's very hard to work out what the private key is.
Probably billions of years of computer time, or at least it was until quantum computers came along. That problem of finding private keys from public keys suddenly got a lot easier. And they got easier because quantum computers, um, take advantage of something called Shaw's algorithm to cut through, uh, that, that whole problem.
Now, what is Shaw's algorithm? And then don't worry because this is a two hour talk, which I'm not gonna do right now, is highly complex, but you can see there, um, actually top right, um, you can see, uh, a what are we seeing here is a quantum computer. Um, and it's processing a public key to make a private key, okay?
And this in principle will break keys when the quantum computers are strong enough, but they're not strong enough yet. But it is motivating the whole of the security industry to get that act together to the point where, um, now nine or so years ago, NIST launched a competition to find new codes that were not susceptible. Uh, now these new codes are called post quantum cryptography, PQC, in other words, codes that we don't believe could be broken by shores algorithm or anything else.
And note my careful, uh, phrasing there, we don't believe will be because you, you try proving that very difficult. So we, we are in a world now where, um, we're worried about quantum computers. We're concerned that at some point they will undermine security.
Um, people could even hack into your data now, not encrypt, not decrypt it yet, but just wait. And when a quantum computer comes along, they'll break it. So, so there's a concern now that we're sending data that is potentially in future decryptable and the two solutions.
One is, uh, to find a new algorithm, PQC, and that's a very big topic. I'm not talking about that. But you can see at the bottom there a timeline, uh, of, of plans for introducing ptc.
Very important. We all hope that, that that carries on or using quantum to fight quantum, something called PKD. And I wanna spend the rest of, um, this second section looking at sending keys in a completely different way, not using algorithms at all.
So I'm flick to the next slide. I is this, this, this slide called what is quantum key distribution? Sounds like I'm getting a, a bit of latency in, in it updating.
Um, hopefully you're getting that slide, Tom, When you advance and then move back, it seems to fix it on our end. Tom, I'm gonna now send you some keys in a different way. I'm gonna send them on single photons of light, um, these little red circles, one at a time.
Um, and I'm gonna send them from me to you. And each of these photons is in two states. It's an up and a down state.
It hasn't decided what it is yet because you haven't looked at it. It's fuzzy. Just like those atoms on the very first slide, send them to you one at a time, and as you detect them, you will measure them and you will generate some keys, okay?
And we have a conversation between us and to decide which of those photons are used to make keys. And this is a completely different way of distributing secrecy. Um, and all I really wanna point out here is there's two reasons why this is at least in principle.
Um, hack free or, or can't be. Uh, decrypted can't be broken. The first reason is this, these red circles are single photo, okay?
So, um, if someone was to hack or tap into this fiber and steal a photon, it won't get through. So Tom, if someone steals one of those photons, you don't get it. And so therefore it can't become part of your key because you haven't received it.
So stealing doesn't work. And by the way, you can't steal half a photon. You either steal all of it or none of it.
That's the thing about photons. So they, it's indivisible. So what if the hacker was a really, really clever and had a massive quantum physics department in the university and decided instead of stealing, he was just gonna measure it and then let it carry on on its way, or maybe extract it, reproduce it, and put it back so that no one would know.
Now, quantum physics doesn't let you do that. Quantum physics forbids you from cloning. There's a no cloning theorem in quantum physics, but there's the quantum particles.
You can't copy them. If you copy them, you change them, and the change is immediately detectable. Now, this is, um, crucial and and fundamental to a lot of what I'm talking about.
I'm relying on quantum physics to make my security here completely, um, unhackable by definition. So it's provable. Um, it's not something that I hope or, or that, that I'm, I'm just, I don't have a strong enough computer yet.
This is in principle, always gonna be unbreakable. Um, because just trying to interfere with this process will change it in a detectable way. An alarm will go off and it's, it's broken.
Now, just to put a caveat on that, we need to make sure that when we build these things, they're secure. Um, so, so just taking the idea is one thing, but to actually implement it probably is important. Well, what have we been doing about this?
So I'm very keen to commercialize this. Um, we've been working at this for many years there. And, um, the, the timeline in BT is culminated in trial, started in 2022 based in London.
So we have a commercial oriented quantum trial in London. We, we, um, worked on, uh, QKD Quantum many, many years ago, but it was way ahead of its time. Um, more recently, um, we've been building research connections and in the last three, four years, we have now a commercial trial in London.
And I'm gonna spend the next three slides talking about that, uh, and talking about some of the customers that, that are on that trial. And then I'm gonna be honest about how it's working and how it's not working because, you know, it could go better. And I'm gonna pose some questions about this whole industry and, and, um, where we are.
And I'm gonna, yeah, gonna be honest. Um, so this is our trial launched three years ago. Um, it's in conjunction with Toshiba.
I would describe as best in class QKD. Um, so we have the equipment and it's installed in regular BT exchange buildings in London. If I took you to see it, it would look just like any other telecoms equipment.
Okay? It, it's, um, built into our regular alarming and monitoring service. So if it breaks, um, our network operations center hears about it.
So this in all respects ready to go that this could be used to build a QKD commercial proposition. Nothing's stopping it. Um, currently the phase we're in is trials with the major customers.
Uh, I'm gonna talk about those, uh, in a minute as well as a bit, a bit of a deep dive in terms of the technology. 'cause the technology is really, really fascinating. This is the, um, kind of detail topology, uh, of the trial.
You can see there's three nodes, uh, two red ones, uh, in London and one in Lau SL is near London. And it represents the data center district, data centers community. Um, and, and we are very keen on data centers for QKD as as we'll be apparent, uh, in a minute.
So what about customers? So we have, um, a major bank, HSBC. We have, um, a professional services company, EY Ston Young.
We're partnering with Toshiba AWS and Equinix. Equinix, if you haven't heard of them, run data centers and cloud. Um, so it is quite a team, uh, and the, the thesis is that we really want to explore, um, customers wanting to do secure backup to the cloud to do secure financial transactions, to make sure their customer data is secure, um, et cetera.
So a a whole range of kind of use cases associated with, with this trial. And someone, uh, earlier asked about, um, companies, I think this, this set of companies is good, uh, and gives us some leverage to, um, explore the art of the possible, but I would like more customers. Um, and there, there is definitely capacity for, for more on this.
Okay. The, the trial itself is very, um, commercially ready. So it's, um, you can plug and play.
It has, um, access to, um, customers, um, communications rooms. So we have five are going right the way into HS BBC central office in Canary Wharf in London. Um, carries quantum all the way through the network.
Um, it's completely managed using software defined networking. Uh, we plan to extend this through satellite QKD in a couple of years so that we have global QKD connectivity. Um, and at the moment that the objective of the trial is, is not does the physics work, we know that, um, it's um, what are the use cases, what's the appetite, uh, what could be charged for it?
Um, and, and, and how do we see this progressing into something that's part of BT business as usual. Andrew, a question for you on one of those items. So a couple slides ago, and you don't need to go back to it, especially with our slide issues, you seem to imply that quantum key distribution was highly dependent on optical photonic transmission.
But you did just note here that you were looking at satellite quantum key distribution. So it's not tied to photons in fiber. You can do this key distribution over other media.
It's tied to photons. Yeah. Okay.
And photons, I can see sometimes I can, yeah, The photons don't need to be in fiber. Got it. But they need, they need to be photons and, and the photons need to have enough energy, um, so that it can't be radio.
So I can't do QKD to my mobile phone, um, because there's no actual light photons. It's radio, they're still photons, they're radio waves, but the radio waves are, are, are too low in energy per photon. So there's a lot of physics here.
Um, short story is, um, you, it needs to be light photons of some of some form. Now that they can be in fiber, they could be free space, they could be between satellites, but they have to be optical photons. And it is not a quantum distribution method because the photons are observable and are unchanged upon observed being observed.
That's what stops it being hacked. Yeah, right. Um, so in built in this system in an alarm, and if someone did that, if someone were to intercept in the middle of this system, an alarm will go off saying this, this photon has physically changed, it was in this state and now it's in this state.
How, how is that someone has changed it? So if someone were to measure a photon that we weren't expecting someone that, you know, shouldn't be, we can detect that. So we're detecting premature quantum physics, if you like Um, this picture here then is, is a detail of, um, the design.
And I'm not gonna go through it, but I, I did want to go a bit deeper to show that it's just not, it's not just boxes connected. There's a lot of thought and engineering and architecture that's gone into turning QKD into a full solution that's really important. Um, so regular networking skills, you know, companies that know how to make networks are important.
Um, it's not just physics. The QKD sits at the bottom, but there's loads of other stuff. There's a key management service, KM S's, there's, um, data coming in that's being encrypted.
There's WDM, this is combining wavelengths. So there's lots of different colors of light all being combined onto the same fiber. Um, and this is just the, the first level of detail.
There's many levels underneath this. So I, I do wanna get across the impression that this is, you know, the physics works, but there's still some work to do in terms in terms of engineering. Um, this is a, a very quick slide just to showcase Equinix, um, data center company who, um, we are now building QKD connectivity between two of their data centers.
One in slur, one in central London for the purpose of them offering it to their customers. Now, if, if they have a customer that has data that is so sensitive that it should be quantum secured, they will be able to, um, in, in the next month or two when, when we finally, um, complete the connection, be able to use our, our QKD data. So we're very excited about, um, this, this extension of the trial with, uh, okay, so I'm gonna, um, go to some of my learnings.
This is where I'm gonna be honest. Um, and you know, there's no point in me, um, glossing over some of the problems. I'm gonna be honest about it.
The good news is it works. Um, and we've been really pretty pleased with the trial. I don't have any real, um, issues with the performance of the trial at all.
Um, it doesn't break. It works well. It does what it says.
We would love more customers, so why haven't we got them? This is interesting because I present quantum to customers with talks like this every week. Literally, uh, customers come to BP all the time saying, tell us about quantum.
So, um, i, I do this, um, so often and yet it doesn't translate yet into real customer attraction. It's still a reluctant there some good use cases. Uh, I would like more.
I'd like there to be more than just financial interest, but I think there is a lot of, um, scope overall management is, is fine needs doing, but we've done it. Um, what is the commercial viability? Uh, when, when you add satellite, I think it becomes a global quantum secure network.
That sounds compelling to me. Um, and I think probably the one thing that we still do need is the major telecom vendors, the Nokia, Cisco Siennas, um, huawe of the world start to integrate quantum into their own products, which would make it much easier for telecom operators to consume. So for sure, we still need some maturing in, in that part of the market.
But there's a problem here. It is this problem is, um, that people like nist, um, the National Cyber Security Center in the uk, the NSA, uh, um, many countries in the west still not convinced about DKD. They have issues with it.
Um, that their issues are around things like it's hardware. So it's expensive. Um, it doesn't get you all the way to your phone or your computer 'cause it's fiber as we talked about.
So it doesn't do the whole thing. So what's the point? Um, I have a much better solution with p qc, which I talked about.
So why would I need this anyway? Um, and finally, um, are you sure you're implementing it properly? I mean, we know the theory, but, but what about the box itself?
How do you make sure that the actual box that you bought from a vendor you've never heard of possibly is secure? Um, so we have a lot of industry questions that we are trying to answer because these, these problems are good ones, right? I I'm not criticizing this at all.
I'm saying this is a very hard-nosed reality of building a security product. This is what you're gonna get. And for sure, the, to this point, very physics-based quantum industry is having to learn to, to deal with some hard nosed security.
And this is a big part of the reason why it's not progressing. Uh, more quickly, Angela, a quick question on this. Yes.
So it, we've seen in many times in other key technology breakthroughs, there needs to be a compelling event. And I think there's enough of a quantum computing is not stable, practical and useful in production enough yet that I don't have a sufficient motivation to really focus on solving the issues at scale that you've talked about. What's it gonna take?
What's gonna be that compelling event that really drives, uh, some of these issues to conclusion? Well, obviously when someone makes a quantum computer that breaks RSA and suddenly all of our networks are undermined. Yeah.
Um, but that's too late. Way too late. The, um, rolling out a new security protocol is, is years for a big complex network.
It's five years or more. You probably have thousands of end devices that need upgrading. You can't do that instantly.
So, so it's really, it is a really good question because we are continually having the discussion. You need to think now, don't wait. Uh, you can't wait until that event happens because it's too late then.
Um, Totally agree with that. Uh, and, and the lag it takes to get new encryption schemes through NIST just in the US right? Um, and then deployment into hundreds of thousands, millions of devices that need to be protected, that's gonna take years and that needs to be well ahead of when RSA is actually broken.
Yeah. Now we know that, uh, and, and the people that, you know, care know about that, but it's trying to just get that mindset further down into, into the industry that, that's a battle of minds at the moment. Um, so, so yeah, I fully agree.
Uh, I just wanna flag this slide. It shows a, a project that we're working on to try to put our house in order. So this is all about, um, making sure that our own assurance, uh, and standardization, um, the conformance of QKD, uh, is done.
Because at the moment, you know, we might have a box that in principle is great physics, but if you go and buy it, how do you know that it's doing what we said it's doing? You've got no way of knowing and opening the lid isn't gonna help because it's tough physics in there. So, so that's, that's no help visit for, for me to say trust us.
We've got some really cool physics, but that doesn't help me sell anything at all, um, to a, an industry that is very security minded and very, um, risk averse. So this is the project where we're really trying to do that work of defining tests, um, to, to make sure that our own assurance that of our, of our own industry or our own technology is, is in place. We just want to put that out.
Um, so this concludes section two. This was the big section. The last two are are quicker, but this one, um, what have I said?
Quantum computers are gonna undermine cryptography. Um, we, new algorithms exist. They are starting to be rolled out.
That's gonna take years, but, but they exist. Quantum key distribution is another way of doing it. I think you could probably use both.
And if you are very risk averse, why not combine them? Um, it has some detractors though. It has its critics and they're very well known critics and that's not, that's one of the reasons why it's not making as much progress as, as it might.
Um, however, I think that will change. And I, I'm expecting to see, uh, as a volume wraps wrapped ramps up, we will see cost of the, that technology reducing. Um, however, I'm still worried that that in the end, QKD will end up at best being very niche.
And I don't want it to be niche for this reason because all, a lot of the technologies in QKD are gonna help me do what I want to do next. And that's section three and that's build a quantum network.