Sitemap
Press enter or click to view image in full size

Member-only story

It Has Taken Us Nearly Five Decades, But Finally, We Have Security/Trust-by-Design: Meet PQ3

4 min readFeb 22, 2024

--

Since the creation of the Diffie-Hellman method in 1976, we have advanced our cybersecurity. So, after nearly five decades, it seems that we are finally getting to the point when we can properly say that we are building systems which are secure and trusted by design. We now see end-to-end encryption, digital signing, key exchange and secure enclaves coming to the fore.

Yesterday, Apple announced that they were upgrading iMessage with PQ3, and which is a quantum-robust method. Why? Shor showed that all our existing public key and key exchange methods can be cracked with the advent of quantum computers. This is supported as E2E (end-to-end) communications and replaces RSA and ECDSA for digital signing and ECDH for key exchange. Apple, too, has excellent security, and where secret symmetric and asymmetric keys are stored in a secure enclave on the device, and support rekeying at defined time intervals. While quantum computers at scale are a few years off, this protects against Harvest Now, and Decrypt Later.

In Figure 1, Apple outlines that applications such as Skype and WeChat have no E2E by default. At Level 2 we see E2E supported by default but use existing public key cryptography. At Level 3, we see the integration of the PQXDH (Post Quantum Key Exchange — Diffie…

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.