Vietnam prepares for the post-quantum cryptographic era

Experts assess that quantum computing can reduce the safety of many security algorithms, so Vietnam needs to prepare a roadmap to transition to post-quantum cryptography standards.

“Digital signatures and digital trust infrastructure have become the backbone of the digital economy,” Ms. To Thi Thu Huong, Director of the National Electronic Authentication Center (NEAC), commented at a conference organized by this unit on the morning of July 21 in Hanoi.

Public key infrastructure (PKI), digital signatures and trust services are the foundation for authenticating electronic identities, ensuring data integrity and legal validity of electronic transactions. According to Mr. Lackern Xu, solution engineering manager of DigiCert company, PKI is present in most daily digital activities, from technology car booking, airport check-in, wifi connection to online payment.

“Public key infrastructure is no longer simply a security function but has become an essential infrastructure for every business, government agency and every country,” he said.

 

Ms. To Thi Thu Huong, Director of the National Electronic Authentication Center. Image: Trong Dat

However, according to Ms. Huong, quantum computing is creating “a major turning point of the era”, directly affecting traditional security models and digital trust foundations. “Previously considered impenetrable cryptographic systems like public key infrastructure that we consider trustworthy today are at risk of being broken tomorrow if prompt action is not taken,” said the NEAC Director.

Sharing the same opinion, Mr. Hoang Nguyen Van, Deputy Director of Digital Transformation Innovation (VIDTI), said that “it is impossible to wait until quantum computers appear before converting to post-quantum cryptographic standards”.

According to him, what is worrying is the “Harvest now, decrypt later” attack strategy (collect first, decrypt later), in which encrypted data can be collected and stored now to wait for decryption when quantum technology is strong enough. Medical, financial, banking or customer data all have a long life cycle and are easily targeted.

Deputy Director of VIDTI assessed that whether a sufficiently powerful quantum computer appears in 2029, 2030 or later, building a roadmap for transitioning to post-quantum cryptography standards needs to start now. The transformation cannot be done all at once but requires a suitable roadmap. The first step is for organizations to determine which systems are using which algorithms, and which systems need to be prioritized for conversion first. Many countries are implementing hybrid cryptography, combining current algorithms with post-quantum algorithms in the transition period, instead of replacing them all at once.

 

Cryptographic standards workshop for trusted services towards the post-quantum era organized by NEAC, on the morning of July 21. Image: Trong Dat

From a management perspective, Ms. Huong recommended that organizations providing trusted services, businesses and data centers proactively research and prepare public key infrastructure and specialized security devices to be ready to meet post-quantum cryptography standards.

She proposed “taking a leapfrog in standards”, accessing international standards early for synchronous translation. The NEAC Director also recommended building a roadmap to evaluate the compatibility of Vietnam’s trusted service system with the world, creating a premise for the recognition of cross-border digital trusted services in the future.

By the end of June, Vietnam issued nearly 32 million digital signature certificates, bringing the popularization rate of digital signatures among the adult population to 45.62%, along with billions of electronic transactions performed. According to NEAC, the development of reliable services is a testament to Vietnam’s digital transformation efforts.

Previously, in mid-June, Google warned that Q-Day, the day quantum computing can break encryption forms being used in information technology, could take place in 2029, 6-15 years earlier than previous predictions. If this estimate is correct, governments, businesses and organizations will not have much time left to prepare new encryption systems to protect data.

“Q-Day is when the world has a quantum computer capable of breaking the cryptographic system in use. That is a turning point,” Michele Mosca, CEO of cybersecurity company EvolutionQ, told CNN. Mosca is a co-author of the “Quantum Threat” report, published annually by the Global Risk Institute in Canada since 2019.

When a quantum computer breaks traditional cryptography, sensitive data such as financial transactions, medical records, emails or accounts protected by today’s popular algorithms can be opened. Experts say that in recent years, hacker groups have “stockpiled” encrypted data files with the intention of decrypting them when quantum computers are capable.

By Editor