Transcript
we are here to talk about a very exciting topic, post-quantum cryptography. See, over the last few years, there are two big topics which we all hear. There isn't a conversation where AI doesn't come in, but we are starting to see quantum as another big topic of interest for our customers. And that's a space where we have been laying a lot of investments over the last few years in the research and in terms of the overall architecture and how we think about making our customers quantum safe and eventually become a trusted partner for them in the migration to the post-quantum era. And this is a space where a lot of advancements have happened in the industry over the last few years. And joining us is our Chief Scientist, Alex Lowe. You've spent a lot of time on these topics in many industrial events. Tell us a little bit about how is quantum computing accelerating and how is that changing? Thank you very much, Satish. So quantum computing itself is not a new concept. Quantum computing has been around as an idea for decades. However, until recently, it remained as a very theoretical physics subject. What we have seen recently is many organizations, both commercial and public entities, started to invest literally billions of dollars into quantum computing. The quantum computing promises us to give significant advantages in solving problems such as training of AI models, doing environmental studies, solving problems associated with big systems. However, as we know, quantum computing is also posing threats to cryptography. Many cryptographic algorithms that we use widely today will be trivially solved by sophisticated large enough quantum computer. Have you heard specific concerns from the customers regarding threats of quantum computing specifically for cryptography? Yes, absolutely. So what I've heard is just like AI, there's good side to it and people leveraging that for bad use as well. From a customer standpoint, this has definitely been a big conversation. What we have seen bubble up over the last year or so. I think we primarily see this for three different reasons. One is we are all aware of the big investments from large organizations in the quantum chips. Every time there is a new headline in the news, we often get this question from customers, when is the big Q&A coming up? That's the million dollar question which customers want to know, are we there yet? I think the investments in quantum computing, which they constantly see in the market, is driving this need for this conversation more. The second topic, what we often see is from the client side adoption. We have seen some of the mainstream browsers like Chrome have adopted the latest quantum key exchange algorithms over the last year. So as that picks up speed, customers have noticed that this is happening in my organization now, so they're starting to think about what does my migration path look like to the post-quantum world. The third point is really about the regulations. As Zscaler, we have many large 1,500 financial sector customers. What I'm starting to see is they have been asked by regulatory needs, they've been asked to put a formal process on their quantum migration plan. So things are picking up speed and rapidly evolving in this space. But there's a lot happening in the NIST space as well. And I know you actively participate in IETF, the Incoming Internet Architecture Board, and NIST as well. Tell us a little bit more about what does FIP 203 mean? What does the standard really mean? Look, before we dive into those lovely details of specific cryptographic standards and regulations, I would like to take a step back and cover a little bit on what exactly is the threat. There is a very common misconception that quantum computers will make all our current cryptography irrelevant, and that is not correct. Only two components of all the complicated cryptographic stack that we're normally using today will be affected by quantum computers. So one is key exchange, and the second one is digital signatures. Now, when it comes to key exchange, that is perceived as the more urgent problem. We don't yet know when large enough quantum computers that will be able to break modern cryptography arrive. Researchers are working hard on building large enough quantum computers, but there are many fundamental problems that they need to solve. There is a common guesstimate that quantum computers that would be large enough might arrive by 2030, but it could happen next year. It could happen by 2050. We don't know exactly when. Now, a specific problem when it comes to threats of quantum computers for key exchange is the so-called harvest-now-decrypt-later attack vector. So if an adversary would be able to capture communication that is strongly encrypted today, the adversary cannot do anything meaningful with this communication. They can store those packets for a long time, and once a large enough quantum computer will be available, as long as they have captured this initial key exchange, they will be able to open up that key exchange and decrypt the rest of the communication. So if the data that you're transmitting today over a strongly encrypted channel will still be relevant when a quantum computer arrives, then, of course, that will create threats to organizations. So let's say if you're transmitting financial information, medical records, or other regulatory sensitive or personally sensitive information that will still be very sensitive by when quantum computers arrive, whenever it happens to be, you certainly want to adopt post-quantum key exchange or key exchange algorithm that is as strong against attacks from quantum computers as it is from classical computers as soon as possible. And that is one of the reasons why regulators started accelerating the pace and why we see adoption of post-quantum key exchange in modern web browsers. The second part of the problem that quantum computers will bring for modern cryptography is digital signatures. Digital signatures are everywhere. It's not just X.509 certificates that we use on public internet so that you know that you're connecting to a correct website. It's not only user certificates. Digital signatures are everywhere. When you unlock a modern car, you actually use elliptic curve signatures. When you're using credit card transaction, it's also authenticating using elliptic curve signatures and all of that would need to be replaced. The good news, it's not as urgent problem as it is for key exchange because there is no retrospective attack vector here. If I will be able to forge certificate and present myself to the world as Satish, if that certificate was valid 10 years ago and is no longer trusted, then well, there is no damage I really can do with that. Right now, the industry is very focused on adoption post-quantum key exchange as a priority to make sure that whenever quantum computer will actually arrive, all data that we're transmitting today will stay safe and secure. Does this reflect what you hear from customers? Do they express this concern when it comes to Harvest Now Decrypt Later attack vector? Absolutely. I think you kind of highlighted the key concerns about this. I think the fact that Harvest Now Decrypt Later doesn't necessarily require a quantum computer to be available today and then the notion of somebody harvesting your data today is what is top of mind in terms of quantum specific threats for our customers. See, in general, what we have seen is quantum cryptography, the whole conversation was very early in the primary conversations. Customers used to ask us, what is Zscaler strategy around this? I've seen the shift from there to this being part of the regulatory requirements, being an active requirement in the very early engagements about finding the right solution to enable them on zero trust journey. Another way of saying this is really, it has really come out of being in sci-fi homegrown science project to kind of really coming out and then being seen in the real world, right? So what we kind of see is different customers are at different places. Based on each vertical, we hear different things. But if I have to pick some three common themes on what we hear, what's top of mind, what is the problem they're trying to solve? I think the first problem is really about getting that visibility into what does my crypto inventory look like? You called about all of this current ciphers, right? The standard ciphers, whether it's RSA or elliptical curve, there are a lot of applications which use that today. Those are the mainstream encryption algorithms. But if Chrome and other browsers are starting to adopt this, they need to really understand and build that inventory in-house, essentially build that crypto bill of materials to get visibility into these are my applications. That's the question they're asking themselves. I need to get a good understanding of what does my crypto inventory look like? And then let me go through the journey of prioritizing the most important ones and start going on to the quantum PQC migration journey. So that's the first question. And the second question really comes back to harvest and decrypt later, right? So if somebody is really harvesting my data right now, how do I mitigate this? So the question really here is, do I have a security solution which can really talk the latest quantum ciphers, the ones which are the most, which are standardized by Nest? And at the same time, we often get this question about just like every other technology transition, we have seen this, whether it's from IPV4 to IPV6, it can take a long time. The concept of, are you as a security solution able to support the classic ciphers and then the quantum ciphers at the same time? So customers understand that this is going to be a long journey. So we have seen this play out very well, where for a large complex organization, trying to build a crypto inventory can take more than a year, right? So while doing that, how do I make sure that I am secure and I'm having inspection for security reasons done with the latest quantum ciphers and mitigate that harvesting threats? That's two. And then the third piece is, how do I make sure my secure connectivity from the get-go, from my client, from my end user device, or even from my branch location, going out in terms of Zscaler, these are all Zscaler customers, send the traffic to Zscaler, how do I make sure my first leg of communication is secure as well? I think we have made significant investments in the space. Last year, we announced the visibility aspect. We have many large customers who now have built crypto bomb and inventory based on the visibility, what we provide for all of the traffic without any additional configuration needed on their side, a centralized view into their crypto inventory. Now, what we are really excited about is the second phase of we as Zscaler Zero Trust Exchange talking and using the quantum safe algorithms, right? That means that between the client and the server, we start using on both ends, wherever the client and the server support, we can start using quantum safe algorithms and help mitigate the quantum, the harvest node decrypt threats. So a lot of interesting innovation happening in this space, really excited for the big launch, which is coming up in a few weeks from now. So I think that's when we really talk about and want to really showcase how we can do things in action. That sounds really exciting. One area that I particularly like about Zscaler approach when it comes to visibility is that unlike traditional inventory solutions that just crawl through all the software on all the endpoints, probably missing something, probably building an inventory of some software that just lies dormant, Zscaler has access to the ground truth, to actual packets on the wire. So what is being used for communication and helping customers prioritize, not just some theoretical threats to some software that is not in action, but something that is being actively used for communication, especially when it comes to transfer of confidential sensitive data. When it comes to adoption of post-quantum key exchange, post-quantum ciphers, on one hand, we're in reasonably good place as an industry. There is now a very well-defined standard, originally finalist of NIST competition, so ML-CAM or FIPS-203, that is intended to essentially replace Elliptic Curve Diffie-Hellman key exchange, providing a way to establish a shared secret between two parties that would be as secure against attacks from classical computers as it is from attacks by quantum computers. However, many regulators and many industry bodies believe that this new ML-CAM algorithm is still quite young. It's 15 years old, the module lattices cryptography is about 15 years old, which is relatively young by cryptographic standards. So the way that industry recommends deployment of this algorithm is in so-called hybrid mode, when it is combined with classical Elliptic Curve Diffie-Hellman. So the attacker would need to crack both ML-CAM and Elliptic Curve Diffie-Hellman with fMRL key exchange, so that provides additional security guarantees for communicating parties that their data is staying confidential, even in the unlikely event that there is some flaw discovered in ML-CAM or in particular implementation of ML-CAM. And then one final note that I'd like to add here is when it comes to Zscaler approach and particularly because we are cloud service, we embrace cryptographic agility, meaning that if something happens in the regulatory space, if for example regulators will decide that we really need to drop this hybrid approach and go full speed ahead on ML-CAM or higher tier ML-CAM is required or there is a new exciting key exchange mechanism that is now recommended, we will be able to adapt very quickly because of our cloud scale and because of our software agility. Absolutely, I think these are a couple of points. What we are hearing from customers is the fact that there is no new crawling or new agents to be deployed to build that inventory, just because of the architectural advantage what we have with Zscaler being a service in the cloud. For all the inline traffic, we do this automatically, build a comprehensive report for them, makes it easier operationally. And number two is that the scale at which we can operate for them. Imagine trying to do this inspection with the latest quantum ciphers and doing the key exchange at that scale in trillions of transactions on a daily basis. That's the advantage both from simplicity standpoint and scale what we bring to the help our customers really have that simplified migration path and we become a trusted partners on their post-quantum migration journey. What makes Zscaler approach to post-quantum cryptography special? Yeah, I think there are quite a few things here. See at the core of it, I really believe that it's the Zscaler architecture which we have built this on really makes it very compelling and easy for customers to go on that migration journey. So when we launch the capability to do the discovery and build that visibility into their crypto inventory last year, we have received a tremendous positive positive feedback on how simple it was for a large enterprise to build the crypto inventory across all of their devices and users just over a period of few weeks. So I think that notion without having the requirement to install a net new agent or do the whole process of crawling across their organization infrastructure makes it very simple and easy for our customers to leverage it. And then the second piece is the scale at which we can do this, right? Imagine we're talking about large enterprises who have transactions in billions, how do we kind of handle at that scale while we are doing SSL inspection with the latest quantum safe ciphers? So I think that scale and simplicity is what our customers have really given a very positive feedback on and it's very interesting and where we are going from now here is we completely understand, as you were saying, it's a hybrid world which we're going to live in where there will be classic ciphers. Now RSA elliptical curve will continue to exist and the ML chem, the quantum key exchange algorithms. We want to give the flexibility to our customers. We have a wide range of customers across different verticals. We understand one size doesn't fit for all. We want to give the flexibility to our customers and to pick and choose what specific ciphers would they want to use for the inspection capabilities what we offer. I think that flexibility when you combine that with simplicity and scale just makes it very compelling and we really have invested in this space to make the become the trusted partner for our customers to take on that big journey of the post-quantum migration, right? We want to make that migration as simple and easy for them.