Transcript
differentiate ourselves, right? Unlike traditional algorithms where it's like, okay, you increase the cipher sizes, change the cipher, crypto agility allows us to switch. And the reason why that's super important, and you mentioned ML, when NIST was going through and validating and making recommendations for FIPS 203, 204, and 205, there was an algorithm called Psyche. And it's really easy to remember, because if anyone was growing up in the 90s, we were all like Psyche, when you used to like fake someone out. It's really easy to remember, Psyche made it through three rounds, and then they were able to actually crack it with like a single core CPU. Oh, you just never know. And if we trace that philosophy back to Psyche, what we're even seeing today with HQC, which is another algorithm that uses a different mathematic computation. So KEM uses lattice, whereas HQC uses error correcting codes. NIST understands that if these mathematical calculations somehow get cracked, there needs to be a failsafe. So that's why crypto agility is super important. So when we were implementing PQC, we kind of saw the writing on the wall, even though HQC was one of those things that was still kind of not completely approved, and it's still not. It's probably going to end up being approved this year, or maybe early next year. They understood that when Psyche got cracked, they probably need a failsafe, and it needs different mathematical proofs. NIST is kind of doing the work to do that. And then if you've been watching the news, there's even another nine algorithms that they're kind of going through and putting them through its paces. So NIST is going to continually do that. So fast forward to what we implemented. We implemented MLKEM. We implemented MLDSA. And then we have a couple other algorithms that are not super optimized, but they're possibilities for us to switch to. And then we even have the ability to switch to HQC, just in case. So again, as these algorithms are being used to protect our pipelines and making sure that if data was exfiltrated, they are completely quantum resistant to today's standards. If those were to get cracked at some future point, for us, it's a flip of the switch. We can switch algorithms. Because of crypto agility and the way our encryption framework works, you would be able to re-encrypt the data with the new ciphers right out the gates. We're looking at that as fully protecting our customers' base, not only for today, but also for tomorrow. And then keep a close eye on what NIST is doing, so that as these changes in the landscape happen, whether they be more secure, or maybe there's optimizations that are made. Because again, you're going to need some compute, you're going to need some networking package changes like MTUs. Those things are going to happen. We continue to keep a finger on the pulse, just so that we can provide not only that optionality, but the best balance of security and performance for our customers to meet all their different needs.