Xsette Quantum-Resistant Encryption Methods

Explore top LinkedIn content from expert professionals.

Summary

Xsette quantum-resistant encryption methods refer to new cryptographic techniques designed to protect sensitive data from future threats posed by quantum computers, which can break many of today’s standard encryption algorithms. These methods use algorithms that have been tested and approved by organizations like NIST, ensuring information stays secure both now and when quantum computing becomes mainstream.

  • Upgrade encryption systems: Start transitioning your security infrastructure to include post-quantum cryptography algorithms, such as ML-KEM and ML-DSA, to future-proof your data.
  • Assess data sensitivity: Identify which information needs long-term protection and prioritize quantum-resistant encryption for those critical assets.
  • Monitor compliance updates: Stay informed about evolving regulatory standards requiring post-quantum cryptographic solutions so your business remains secure and compliant.
Summarized by AI based on LinkedIn member posts
  • View profile for Benjamin Scott, M.S.

    Director, Critical Infrastructure & Operational Technology, US Public Sector at Fortinet | OT Cybersecurity Evangelist | Ohio Cyber Reservist | Adjunct Professor

    30,371 followers

    Quantum computing is advancing rapidly, bringing unprecedented processing power that threatens traditional encryption methods. The "collect now, decrypt later" strategy underscores the urgency of preparation, adversaries are already harvesting encrypted data with the intent to decrypt it once large-scale quantum computers become viable. Fortinet is leading the way in quantum-safe security, integrating NIST PQC algorithms, including CRYSTALS-KYBER, into FortiOS to safeguard data from future quantum-based attacks. "A recent real-world demonstration by JPMorgan Chase (JPMC) showcased quantum-safe high-speed 100 Gbps site-to-site IPsec tunnels secured using QKD. The test was conducted between two JPMC data centers in Singapore, covering over 46 km of telecom fiber, and achieved 45 days of continuous operation." "The network leveraged QKD vendor ID Quantique for the quantum key exchange, Fortinet’s FortiGate 4201F for network encryption, and FortiTester for performance measurement." This is not just a theoretical concern, organizations are already deploying quantum-safe encryption solutions. As quantum computing capabilities advance, organizations must adopt quantum-resistant security architectures and take proactive steps now to safeguard their sensitive information against future quantum-enabled attacks. These proactive methods include: -adopting hybrid cryptographic approaches, combining classical and PQC algorithms, ensuring interoperability and a phased transition -implementing crypto-agile architectures, for seamless updates to encryption mechanisms as new quantum-resistant standards emerge -leveraging PQC capable HSMs and TPMs -evaluating network security architectures, such as ZTNA models -ensuring authentication and access controls are resistant to quantum threats. -identifying mission-critical and long-lived data, that must remain secure for decades. -implementing sensitivity-based classification, determine which datasets require the highest level of post-quantum protection. -conducting risk assessments to evaluate data exposure, storage locations, and current encryption standards. -transitioning to quantum-resistant encryption algorithms recommended by NIST’s PQC standardization efforts. -establishing data-at-rest and data-in-transit encryption policies, mandate use of PQC algorithms as they become available. -strengthening key management practices -developing GRC frameworks ensuring adherence to post-quantum security. -implementing continuous cryptographic monitoring to detect and phase out vulnerable encryption methods. -enforcing regulatory compliance by aligning with emerging PQC standards. -establishing incident response plans to handle quantum-driven cryptographic threats proactively. Fortinet remains committed to pioneering quantum-safe encryption solutions, enabling organizations to stay ahead of emerging cryptographic threats. Read more from Dr. Carl Windsor, Fortinet’s CISO!

  • View profile for Vaughan Shanks

    Helping security teams respond to cyber incidents better and faster | CEO & Co-Founder, Cydarm Technologies

    12,958 followers

    Last week #NIST released three post-#quantum #encryption standards. Why is this significant? Put simply, from a practical standpoint: risk management and compliance. First, on risk management: experts now say that quantum computing is less than a decade away. Quantum computers are expected to have the power to search large keyspaces very quickly, which means they will be able to decrypt current encryption. Moreover, it is entirely plausible that encrypted information recorded today is being stored for decryption when quantum computing becomes available. If you speculatively apply quantum-resistant encryption to your data now, you will reduce the risk of an adversary being able to successfully exploit your data when they have access to quantum computing. Second, on compliance: NIST is the governing body for standards in the USA, and many other nations take their encryption standards from NIST, as they do not have resources at the same scale as NIST. You can be certain that NIST-approved post-quantum algorithms will start being mentioned in various compliance checklists, as is the case currently with algorithms such as AES-256 and SHA-256. Note well that these algorithms have #FIPS numbers associated with them - meaning "Federal Information Processing Standard". Briefly, the approved algorithms are: 🔒 ML-KEM, for encrypted key exchange, as FIPS 203 🔒 ML-DSA, for digital signatures, as FIPS 204 🔒 SLH-DSA, for stateless hash-based digital signatures, as FIPS 205 There is a fourth algorithm, FN-DSA, also used for digital signatures, that is expected to be released in the next year.

  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 19,000+ direct connections & 54,000+ followers.

    54,290 followers

    Apple Deepens Its Post-Quantum Security Strategy With Open-Source Release Apple has taken another significant step toward quantum-resistant cybersecurity by publishing portions of its post-quantum cryptography implementation on GitHub. The move expands the company’s ongoing effort to protect iPhone, Mac, and other Apple platforms against future quantum computing threats that could eventually break many of today’s encryption methods. Apple’s post-quantum journey began publicly with the introduction of the PQ3 protocol for iMessage in iOS 17.4. PQ3 added quantum-resistant protections not only when conversations begin but also throughout ongoing communications as encryption keys are refreshed. The goal is to defend against “harvest now, decrypt later” attacks, where adversaries collect encrypted data today in hopes of decrypting it once sufficiently powerful quantum computers become available. The newly released GitHub repository includes source code from corecrypto, Apple’s foundational cryptographic library used throughout its security ecosystem. Corecrypto supports encryption, digital signatures, hashing, secure random number generation, and numerous security functions across Apple devices and services. By releasing the code, Apple enables researchers and security experts to review, test, and validate its implementations. The repository contains implementations of the NIST-standardized post-quantum algorithms ML-KEM and ML-DSA, which Apple selected as part of its quantum-resistance strategy. It also includes testing frameworks, performance evaluation tools, build targets, and formal verification resources designed to help validate the correctness and security of the cryptographic implementations. The decision to open-source these components reflects a long-standing principle in cryptography: security is strengthened through public scrutiny. Allowing independent experts to examine the code helps identify weaknesses, improve confidence, and accelerate broader industry adoption of quantum-resistant technologies. Key Takeaways: Apple has released portions of its post-quantum cryptography code through GitHub, including implementations of ML-KEM and ML-DSA. The effort builds upon the PQ3 protocol introduced for iMessage and demonstrates Apple’s continued investment in preparing for future quantum computing threats. The open-source release enables independent review, testing, and validation by the global security community. The broader implication is that the transition to post-quantum cryptography is moving from theory to deployment. As quantum computing advances, organizations worldwide are beginning to replace traditional cryptographic systems with quantum-resistant alternatives. Apple’s actions highlight how major technology providers are actively preparing for a future in which information security must withstand both classical and quantum attacks. Keith King https://lnkd.in/gHPvUttw

  • View profile for Christian Scott

    🔐 CEO @ Tantalum Security - Cybersecurity Leader, Researcher, Educator & International Speaker

    11,356 followers

    💡 Wow! This past week marked a major leap forward in rolling out post-quantum cryptography algorithms to protect against “store now, decrypt later” attacks with major updates in OpenSSL 3.5.0 & OpenSSH 10.0 ⬇️ 🔐 What is a “Store Now, Decrypt Later” attack? It’s a forward-looking threat, where adversaries capture encrypted data today and hold onto it, waiting until large-scale quantum computers are powerful enough to break current encryption algorithms (like RSA & ECC) using Shor’s algorithm and decrypt the data. This is particularly dangerous for sensitive long-term information like financial records, important intellectual property and national security data. 🛡️ Why last week’s updates matter: Both OpenSSH and OpenSSL took big steps in implementing post-quantum cryptography (PQC), algorithms designed to remain secure even against quantum computers. 🧩 OpenSSH 10.0 Highlights (https://lnkd.in/gP5q3q7M): • 🚫 Deprecated outdated DSA & classic Diffie-Hellman key exchanges. • 🔐 Default key exchange now uses MLKEM-768, a quantum-safe and NIST-standardized algorithm. • 🔒 Isolated the SSH authentication process into a separate memory space using ssh-auth, mitigating the impact of login-related vulnerabilities like Terrapin or RegreSSHion. 🔐 OpenSSL 3.5.0 Highlights (https://lnkd.in/gmtgVVzv): • ✅ Adds support for three newly standardized PQC algorithms: ML-KEM (Key Encapsulation), ML-DSA (Digital Signatures) & SLH-DSA (Hash-Based Signatures). • 🔄 Sets AES-256-CBC as the new symmetric default over older, weaker ciphers. • 📅 This is a Long-Term Support (LTS) release, supported through 2030. Kudos to the maintainers and contributors pushing these critical projects forward. The future of secure communication just got a lot more resilient. 😁 #CyberSecurity #PostQuantumCryptography #OpenSSL #OpenSSH #QuantumResistant #StoreNowDecryptLater #Encryption #Infosec #TechLeadership #PQC #NIST

  • View profile for Nicolas Fillon

    Principal Field Application Engineer @ STMicroelectronics | Electrical Engineering

    16,315 followers

    X-CUBE-PQC: STM32 Post Quantum Cryptographic firmware library software expansion for STM32Cube With the advent of quantum computers, traditional asymmetric cryptographic algorithms such as RSA, ECC, DH, ECDH, and ECDHE become vulnerable. In response, NIST has selected a new set of algorithms designed to be resistant to quantum computing attacks. The STM32 post-quantum cryptographic library package (X-CUBE-PQC) includes all the major security algorithms for encryption, hashing, message authentication, and digital signing. This enables developers to satisfy application requirements for any combination of data integrity, confidentiality, identification/authentication, and nonrepudiation. It includes both the PQC Leighton-Micali signature (LMS) and the extended Merkle signature scheme (XMSS) verification methods, which are used mainly for secure boot code authentication. It also includes the ML-KEM lattice-based algorithm, which can replace the current use of key exchange mechanisms to establish a secret key between two parties. ML-DSA is included for digital signatures. ML-DSA can replace ECDSA, EdDSA, and RSA-PSS in protocols, for instance in high-level applications as a method of authentication, of attestation, or both. https://lnkd.in/gTjstZfm

  • View profile for Jaime Gómez García

    Global Head of Santander Quantum Threat Program | Chair of Europol Quantum Safe Financial Forum | Quantum Security 25 | Quantum Leap Award 2025 | Representative at EU QuIC, AMETIC

    18,185 followers

    📌 European Union Agency for Cybersecurity (ENISA)'s European Cybersecurity Certification Group Sub-group on Cryptography published their "Agreed Cryptographic Mechanisms". The document covers cryptyographic primitives (algorithms), constructions (encryption, signatures, etc), TLS, RNGs and key management. It's purpose is to "specify which cryptographic mechanisms are recognised agreed, i.e., ready to be accepted by all national cybersecurity certification authorities (NCCAs)". Some highlights from a quantum-safety perspective: 👉 Recommends hybridization to "provide assurance against the quantum threat as well as assurance against security issues that might affect the newer standardized post-quantum mechanisms" 👉 Symmetric 🏷️ Supports Triple-DES until 2027, despite it is disallowed by NIST already 🏷️ Recommends >192-bit parameters when quantum resistance is desired 👉 Hashes & MAC 🏷️ Recommends >384-bit output sizes when quantum resistance is desired 👉 Asymmetric 🏷️ Classical / Quantum-vulnerable 🤔 Parameters approx. under 128-bit security (RSA2048, DH-2048, DSA-2048) are accepted until end of 2025! 💣For RSA, it specifies: "A later acceptability deadline for user/data authentication with this particular algorithm may be set on a national level." Minimum ECC key size is at 256 bits, so it doesn't include that end of life deadline. 🏷️ Post-quantum #PQC 🔖 Lattice cryptography (ML-DSA, ML-KEM) should not be used in standalone mode. Always in hybrid mode with a strong classical algoritm. 🔖 ML-DSA and ML-KEM are recommended on level 3 and 5 parameters. Level 1 is no recommended. 🔖 Hybridization of Hash-based signature schemes is optional. SLH-DSA is supported under Level 3 and 5 parameters. 🔖 Frodo-KEM is supported under Level 3 and 5 parametersand in hybrid mode. 👉 Deterministic RNGs 🏷️ Recommended that the min-entropy of the seed is at least 188 bits This document is interesting and clarifying, but I see two issues: 1. I haven't seen a timeline to deprecation of quantum-vulnerable cryptography in general. I think that's needed and National Institute of Standards and Technology (NIST) has done well in announcing it (in draft form for now) under NIST IR 8547. 2. A deadline on 2025 for 112 bit classical crypto, like RSA-2048 seems too strict for me. New norms should avoind being challenged by reality. No other organism has gone that close and I don't think the world will stop using RSA-2048 in 2026. https://lnkd.in/dUi46V3s #cryptography #quantum #postquantum

  • View profile for Prof Bill Buchanan OBE FRSE

    OBE | Fellow, Royal Society of Edinburgh | Old World Breaker, New World Creator | One of the World’s Top 2% Scientists for 2025/career (Stanford/Elsevier Top 2% Scientists) | Principal Fellow, HEA | Living by the sea

    52,600 followers

    Energy Consumption of Post Quantum Cryptography: Dilithium and Kyber Beat Our Existing TLS 1.3 Performance Like it or not, our existing public key methods will be easily cracked by quantum computers. We must thus look to new quantum robust methods to provide our key exchange, digital signing and public key encryption methods. Thus, TLS 1.3 and above will have to migrate away from anything that uses RSA and ECC, and towards quantum robust methods, such as with lattice techniques. For this, NIST recently started the standardization of Kyber for key exchange and public key encryption and for Dilithium in digital signatures. There will be others coming along behind them, though, possibly with Bike, FrodoKEM and Falcon for key exchange and Sphincs+ for digital signatures. But, there’s a feeling that Post Quantum Cryptograph (PQC) will not be as fast and be more costly for energy consumption than our existing public key methods. Now, a relatively new paper puts this fear aside and shows that the best PQC methods can beat our elliptic curve and RSA methods for a TLS 1.3 handshake. https://lnkd.in/e3RUG7_u

  • View profile for Terrence A. Thomas

    Founder, President & CEO

    2,174 followers

    "Experts have warned for years that the development of quantum computers could undermine the encryption that currently secures everything from our private messages to our banking details... ...Now Google has put some of that work into practice, in Chrome. The new technology includes new cryptography that should be resistant to attempts to break it with future quantum computers. It does so by integrating a technology known as X25519Kyber768, a long name for what is actually a hybrid of two cryptographic algorithms. Tying the two together means that data is protected both by an existing secure algorithm and one that is protected against quantum computers."

  • View profile for Aviral Srivastava

    Security Engineer @ Amazon | Pwnie Awards 2026 Nominee | AI Infrastructure Security | Vulnerability Research | RSA Security Scholar

    13,031 followers

    Recently many of us might have hear about the risk that modern cryptography face because of quantum computers and their computational capabilities. There we have seen new guidelines being released and many people talk about the need to develop quantum ressilent algorithms. But what are they ? Let's have an overview of some of such algos, what it is and how it works. It might be a bit complicated but I will try my best to help you understand. 1. Lattice-Based Cryptography: Utilizes complex lattice structures in high dimensions. Its security is rooted in the hardness of lattice problems like the Shortest Vector Problem, which are not efficiently solvable by quantum algorithms. Used in secure key exchange and encryption schemes. 2. Hash-Based Cryptography: Employs cryptographic hash functions, which are inherently resistant to quantum attacks due to their reliance on problems like pre-image resistance. This approach is pivotal in constructing secure, quantum-resistant digital signatures. 3. Code-Based Cryptography: Centers on the difficulty of decoding randomly generated linear codes, a problem not efficiently tackled by quantum algorithms. It’s primarily applied in robust encryption systems. 4. Multivariate Quadratic Cryptography: Based on solving systems of multivariate quadratic equations, known to be NP-hard. This complexity offers a strong defense against quantum computational attacks. Key Insights: *These algorithms leverage mathematical problems that are currently intractable for quantum computers. *Their development is critical for ensuring security in the face of advancing quantum computing capabilities. *This area is rapidly evolving, necessitating ongoing research and adaptation. #QuantumResilience #AdvancedCryptography #Cybersecurity #QuantumComputing #Encryption

Explore categories