Āé¶¹“«Ć½

Encryption meant to protect against quantum hackers is easily cracked

Rainbow, an algorithm that was supposed to protect data from hacking by quantum computers, has been defeated using a standard laptop
R17CX7 Blockchain technology concept. 3d illustration.
Encrypted data might be vulnerable to quantum computer hackers
SERGII IAREMENKO/SCIENCE PHOTO LIBRARY/Alamy

ONE of three cryptography algorithms vying to become aĀ global standard against the looming security threat posed byĀ quantum computers has beenĀ cracked in a weekend usingĀ aĀ standard laptop. The algorithm is now widely believedĀ to be unfit for purpose.

A range of algorithms forĀ encryption – the process ofĀ bundling data up into impenetrable files for safe transmission – are currently verified and approved as secure byĀ the US National Institute of Standards and Technology (NIST), and consequently they are used around the world. But these algorithms are set to be made obsolete in coming years by the arrival of quantum computers.

Once developed, these machines promise to vastly exceed the power of classical computers at certain types of problems. One example is quicklyĀ finding the prime factorsĀ that serve as the multiplicative building blocks ofĀ aĀ number – forĀ instance, 3 and 7Ā areĀ the primeĀ factors of 21. This seemingly innocuous ability will fundamentally break encryption currently used in email, banking and cryptocurrencies.

A total of 69Ā algorithms believed to be resistant to the increased code-breaking ability of quantum computers were submitted toĀ . These have now been whittled down toĀ four finalists for the task of encryptionĀ and three for signing signatures, which are used to verify identity, for example when making a financial transaction.

Rainbow is one of the final three signature algorithms. A signature scheme is used to mark a message using a secret key known only to that person. It can then be verifiedĀ as a legitimate message byĀ a recipient using the sender’s public key, which is made availableĀ to everyone.

at IBM Research Zurich in Switzerland was able toĀ take a Rainbow public key andĀ discover the corresponding secret key in just 53Ā hours using aĀ standard laptop. This weakness would allow an attacker to falsely ā€œproveā€ they are someone else.

Join us for a mind-blowing festival of ideas and experiences. Āé¶¹“«Ć½ Live is going hybrid, with a live in-person event in Manchester, UK, that you can also enjoy from the comfort of your own home, from 12 to 14 March 2022..

Beullens says that this kind ofĀ attack, detailed in a published by the International Association for Cryptologic Research, makes Rainbow ā€œuselessā€ as a method to verify messages. He had previously developed less serious attacks against Rainbow, to which the creators responded by increasing the complexity of the private andĀ public keys at the expense ofĀ efficiency, he says.

ā€œI think my previous attack wasĀ also quite serious, and IĀ thinkĀ it was already obvious thatĀ Rainbow was not going to beĀ standardised,ā€ says Beullens. ā€œThe common feeling among cryptographers seems to be that [the other two finalists in the signature competition] are muchĀ more secure.ā€

Current algorithms use public keys, secret keys and signatures that are just a handful of bytes, allowing cryptography to be added onto all sorts of protocols without much additional overhead.

at Cambridge Quantum says that while all cryptographic algorithms can eventually be broken, there are varying levels of efficiency. Some algorithms require more data to store a public key and secure private key, while others do it using less. Rainbow had already been one of the less efficient algorithms, he says.

ā€œWe want to change as little of our cryptography infrastructure as possible. So, things like secure internet connections, they can’t easily cope with incredibly large public keys,ā€ says Jones. ā€œRainbow already had larger keys. So in that sense, it was already perhaps not the strongest candidate.ā€

at NIST told Āé¶¹“«Ć½ that the attack against Rainbow had been verified and that it is now unlikely to be chosen as the final signature algorithm when a decision is made later this month. Unfortunately, it has already seen limited real-world use, including by a cryptocurrency called .

Topics: quantum computing / security