Quantum-Safe Cryptographic Operation Selection Under Enterprise Constraints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems are vulnerable to quantum attacks, and transitioning to Post Quantum Cryptography (PQC) algorithms is necessary, but existing methods fail to optimize this conversion considering enterprise constraints on time and memory requirements.
Innovation Solution
A method and system that analyze application pipelines to identify classical cryptographic schemes, map them to PQC schemes based on security levels and risk values, compute conversion limits, and iteratively select optimal PQC schemes to ensure security and resource efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If classical cryptographic schemes are converted to PQC schemes, then security against quantum attacks is improved, but execution time and resource usage increase
Solution Approach 1:
The system changes parameters by offering multiple PQC schemes with different security levels (e.g., NIST levels 1-5) and key sizes. Enterprises can select schemes that provide adequate security while optimizing execution time and resource usage based on their specific requirements, rather than using a fixed high-security configuration for all cases.
Solution Approach 2:
The system dynamically selects PQC schemes based on real-time factors including enterprise risk appetite, application criticality, and resource availability. The recommendation engine adapts security levels and algorithm choices according to the specific context of each enterprise and application, allowing flexible trade-offs between security and performance.
2Reliability
If high security level PQC schemes are selected, then quantum resistance is improved, but memory and computational resources increase
Solution Approach 1:
The system provides a range of PQC schemes with varying key sizes and computational requirements. For example, it offers schemes with different security levels (NIST levels 1-5) that correspond to different resource consumptions, allowing enterprises to parameterize their security posture according to available resources.
Solution Approach 2:
The system applies different security levels to different applications or data types based on local requirements. Critical applications receive higher security levels with corresponding resource allocations, while less critical applications use lower security levels that consume fewer resources, optimizing the overall system resource utilization.
3Measurement precision
If comprehensive analysis of all PQC schemes is performed, then optimal selection is improved, but conversion complexity increases
Solution Approach 1:
The system segments the complex selection process into distinct phases: initial assessment of enterprise requirements, filtering of suitable PQC schemes based on criteria like algorithm category and security level, detailed evaluation of candidate schemes, and final recommendation. This segmentation makes the overall complex process more manageable and systematic.
Solution Approach 2:
The recommendation engine acts as an intermediary that automates the complex analysis and selection process. It mediates between the enterprise's requirements and the available PQC schemes, performing comprehensive evaluations and presenting simplified recommendations, thereby reducing the complexity burden on the enterprise while maintaining high selection quality.
4Reliability
If PQC conversion is implemented across all applications, then overall security posture is improved, but implementation time and cost increase
Solution Approach 1:
The system recommends partial conversion strategies where enterprises can prioritize converting critical applications first rather than converting all applications simultaneously. It identifies and recommends PQC schemes for high-priority applications based on risk assessment, allowing enterprises to achieve significant security improvements in a phased manner rather than requiring complete conversion at once.
Solution Approach 2:
The system performs preliminary analysis and recommendation generation before actual conversion implementation. It assesses enterprise requirements, evaluates suitable PQC schemes, and provides a roadmap for conversion, allowing enterprises to prepare and plan conversions in advance, thereby reducing the time and complexity of actual implementation.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
The present disclosure paves way for transferring of application from classical cryptographic algorithms to post quantum cryptographic algorithms code, due to increased vulnerability to risks in classical cryptographic algorithm. Since Post Quantum Cryptographic (PQC) algorithms are more secure, they result in more execution time and resource requirements. Hence, it becomes necessary to select those PQC algorithms that satisfy enterprise constraints on time, computation cost and memory. Due to presence of various PQC algorithms and security levels with different key size and operations there is a requirement for recommender that can ensure optimal conversion from classical cryptographic schemes to PQC schemes at appropriate security levels. This lowers the risk and the selected PQC algorithms also satisfies the enterprise security requirements.