Cryptography-Cracking Algorithms Have Been Around for Decades
Even though a practical, consumer-facing quantum computer is still at least a few years away, quantum algorithms to crack encryption codes have been around for decades. The most prominent of them is Shor’s algorithm, developed by mathematician Peter Shor in 1994. According to Moody, if deployed on a large enough quantum computing system, it has the potential to quickly crack current public-key cryptographic. A second algorithm, created by computer scientist Lov Grover in 1996, can make brute force attacks on symmetric-key cryptography a lot faster.
Michele Mosca, a professor at the University of Waterloo and the co-founder of the university's Institute for Quantum Computing, brings up an even more daunting prospect: “There’s also the possibility that someone discovers a new quantum algorithm capable of breaking the cryptography replacing the systems that Shor’s algorithm threatens, except this time we may not have several decades of warning before deployment becomes possible.”
Bad Actors Harvest Data Now To Encrypt Later
Another factor that might keep a university IT manager up at night is that even though there isn’t a quantum computer capable of effectively running Shor’s algorithm yet, bad actors are out there preparing for that day by harvesting data now to decrypt later.
DISCOVER: Universities leverage quantum computing to advance research.
“Storage has become remarkably inexpensive. At the same time, several leading cryptologic agencies — the organizations responsible for protecting government information and conducting signals intelligence — have explicitly warned organizations to assume that harvest-now-decrypt-later is a real threat and to prepare accordingly,” says Mosca. “The nature of this attack is that adversaries don’t announce they’re doing it. Detecting a passive collection of communications flowing through systems outside your control is extremely difficult. Attribution is even harder.”
What Universities Can Do To Protect Sensitive Data
Any organization with sensitive data is vulnerable to this harvest-now-decrypt-later method, including universities, which have research data, personal student and faculty information, and other data that needs to be protected.
“We’re now reaching the point where there’s a material risk that critical digital systems won’t be upgraded to quantum-safe cryptography before quantum attacks become practical,” Mosca says. “If some organizations migrate to post-quantum cryptography while others don’t, the laggards may simply become more attractive targets.”
What can university IT organizations do to protect data now? One thing is to start testing and implementing post-quantum cryptography algorithms, part of an initiative developed by Moody and his team at NIST. These algorithms can be used on present-day classic computing systems.
UP NEXT: Quantum cryptography is the next wave of cybersecurity for higher ed.
“In 2016, we kicked off a large, international, competitionlike process to eventually standardize new cryptographic algorithms to replace the ones that would be broken by Shor’s algorithm,” he says. Of the 69 algorithms submitted, four were chosen and implemented in 2024. “Organizations and agencies are now transitioning to these algorithms, which will take some time because of the complexity of the migration,” he says
A thorough accounting of the systems in an organization that are using cryptographic security is also needed, says Moody, as well as making sure organizations can turn to people — either internal or external teams — who have training and knowledge in quantum algorithms.
For universities in particular, Mosca says that while they do a lot to protect their sensitive data, more can be done. “It also means ensuring the cryptography protecting research data and intellectual property remains trustworthy for as long as the research itself retains its value,” he says. “Research security isn’t just about controlling who can access discoveries today. It’s also about ensuring the cryptography protecting those discoveries remains trustworthy.”
