Google Online Security Blog
Follow
Tracking the Cost of Quantum Factoring
Google Quantum AI is working on building quantum computers that can solve previously unsolvable problems, but this also means that large-scale quantum computers could break current public key cryptography algorithms. To address this, Google has been working with the US National Institute of Standards and Technology (NIST) to develop and transition to post-quantum cryptography (PQC) that is resistant to quantum computing attacks. A recent study demonstrated that a quantum computer with 1 million noisy qubits could break 2048-bit RSA encryption in one week, a 20-fold decrease from previous estimates. This underscores the importance of migrating to PQC standards in line with NIST recommended timelines. The reduction in physical qubit count comes from better algorithms and better error correction. The security implications of quantum computers are significant, particularly for encryption in transit and digital signatures. Google has started encrypting traffic with PQC algorithms and has added PQC signature schemes in Cloud KMS. The NIST internal report recommends deprecating vulnerable systems after 2030 and disallowing them after 2035. Google's work highlights the importance of adhering to this recommended timeline. The transition to PQC is complex, but necessary to prevent "store now, decrypt later" attacks.