Post-Quantum Cipher Suite Risk Analysis and Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network and data security technologies are unable to effectively identify and remediate cipher suite deployments that are not post-quantum computing safe, posing a risk to classical cryptography systems.
Innovation Solution
A computer-implemented method and device that analyze a target to determine its cipher suite deployments, generate a cipher suite dependency graph, and classify the target as post-quantum computing safe or unsafe, with the capability to remediate unsafe cipher suites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If classical cryptography techniques (RSA, ECC, AES) are used to protect systems and data, then current security standards are maintained and compatibility with existing systems is ensured, but security is weakened against quantum computing attacks
Solution Approach 1:
The system performs preliminary analysis of cipher suite deployments before quantum computing attacks can occur. By proactively scanning, identifying, and remediating unsafe cipher suites using classical cryptography, the system prepares security defenses in advance, allowing organizations to upgrade to post-quantum safe configurations before quantum computers become a practical threat.
2Reliability
If comprehensive analysis of all cipher suites is performed to ensure post-quantum safety, then security coverage is improved, but computational resources and time required for analysis increase
Solution Approach 1:
The analysis system segments the comprehensive cipher suite security assessment into manageable components: individual cipher suite identification, dependency graph generation, and rule-based safety evaluation. This segmentation allows the system to analyze each cipher suite independently using predetermined rules, reducing the overall computational burden while maintaining complete security coverage across all deployed cipher suites.
Data Source
AI summary
A method to identify and remediate unsafe cipher suite deployments. The method includes identifying a target to be analyzed, determining a collection of cipher suites used by the target, generating and displaying a cipher suite dependency graph for the target based on the collection of cipher suites, and classifying the target as being one of post-quantum computing safe and post-quantum computing unsafe based on the cipher suite dependency graph and based on a predetermined rule for each cipher suite in the collection of cipher suites. A cipher suite hosted by a target can be remediated to convert the target to a post-quantum computing safe state.


