메뉴
BL
MIT Tech Review • 43일 전

양자 위협, 실용적인 양자 내성 암호(PQC) 전환 가이드

IMP
8/10
핵심 요약

양자 컴퓨팅의 발전이 기존 암호 체계를 위협하고 있지만, 이는 즉각적인 위기가 아닌 체계적인 준비가 가능한 보안 진화의 과정입니다. 특히 기밀 유지가 오래 필요한 데이터를 겨냥한 '수집 후 복호화(Harvest Now, Decrypt Later)' 공격에 대비하는 것이 핵심입니다. 인텔 등은 이미 양자 내성 암호(PQC)를 지원하는 인프라를 제공하며 기업의 안정적인 전환을 돕고 있습니다.

번역된 본문

스폰서 제공 (인텔)

기술 분야에서 양자 컴퓨팅은 혁신적인 대유행과 과장된 기대 사이를 오갔습니다. 이 강력하고 새로운 기술은 현재의 암호화 방식을 뚫을 수 있는 위협을 동반하지만, 이러한 소음 속에서 길을 찾아야 하는 비즈니스 리더들에게 분명한 신호는 다음과 같습니다. 양자 내성 암호(PQC, Post-Quantum Cryptography)는 관리 가능한 발전 과정이지, 위기가 아닙니다. 오늘날 암호화된 디지털 거래를 뒷받침하는 수학적 원리는 언젠가 양자 컴퓨터에 의해 무너질 수 있지만, 양자 저항 알고리즘으로의 전환이 갑작스럽거나 극복 불가능한 것은 아닙니다. 혼란, 비용 또는 복잡성에 대해 우려하는 경영진에게는 이를 가능하게 하는 인프라를 이미 제공하기 시작한 인텔과 같은 신뢰할 수 있는 기술 파트너와 함께 구조화되고 단계적인 접근 방식이 존재합니다.

급격한 단절이 아닌 자연스러운 진화 '양자 위협'이라는 내러티브는 종종 임박한 재앙이나 아득히 먼 미래의 일이라는 두 가지 극단 사이를 오갑니다. 하지만 현실은 더욱 실용적인 중간 지대에 있습니다. 양자 컴퓨터는 양자 물리학을 활용하여 특정 어려운 문제를 해결하는 고도로 전문화된 가속기입니다. 이들은 현대 암호화를 깨뜨릴 잠재력이 있지만, 기존 서버를 하룻밤 사이에 대체하지 못할 것이며 인터넷상의 모든 암호화 프로토콜을 즉시 파괴하지도 않을 것입니다. 이들이 할 일은 지난 30년 동안 이전 암호화 전환이 그래왔던 것처럼 보안 환경을 점진적으로 변화시키는 것입니다.

2024년 말, 토론토에 기반을 둔 금융 서비스 싱크탱크인 글로벌 리스크 연구소(Global Risk Institute)는 양자 컴퓨터가 24시간 이내에 2048비트 RSA 키를 뚫을 수 있는 시기에 대해 32명의 양자 컴퓨팅 전문가를 대상으로 설문조사를 실시했습니다. 전문가들의 낙관론과 비관론을 종합한 평균치에 따르면, 2040년까지 이 암호 해독 마일스톤을 달성할 확률은 정확히 50대 50인 것으로 나타났습니다. 이 불확실하지만 측정 가능한 시간표는 비상 대응이 아닌 신중한 계획을 위한 여유를 만들어 줍니다.

당장의 초점은 해커들이 오늘 암호화된 데이터를 가로채 뒀다가, 미래에 복호화 기술이 확보되면 그때 해독하는 '수집 후 복호화(Harvest Now, Decrypt Later)' 시나리오에 맞춰야 합니다. 이는 10년 이상 기밀성을 유지해야 하는 정보와 특히 관련이 깊습니다. 대부분의 기업에게 이는 체계적인 현대화를 통해 해결할 때 충분히 관리할 수 있는 위험입니다.

신뢰를 구축하는 정부의 가이드라인 미국 정부는 잠재적인 양자 공격의 1순위가 될 가능성이 높은 국가 안보 시스템(NSS)에 대한 새로운 지침을 발표했습니다. 2027년 1월부터 새로 도입되는 NSS 조달품은 미국 국립표준기술연구소(NIST)가 표준화하고, 미국 국가안보국(NSA)이 선정한 양자 내성 암호 알고리즘 요구사인 '상업용 국가 안보 알고리즘 제품군 2.0(CNSA 2.0)'을 지원할 수 있어야 합니다. (일부 예외를 제외한) 새로운 시스템에 대한 본격적인 구현은 2031년까지 의무화되며, 2035년까지 100% 도입을 목표로 하고 있습니다.

상업 기업에게 이러한 시간표는 의무 사항은 아니지만, 나아가야 할 방향을 알려주는 이정표가 될 수 있습니다. 이는 공급업체, 표준 기관 및 감사자들이 나아가는 방향을 나타내며, 책임감 있는 관리를 위한 참조 아키텍처를 제공합니다. 조직은 정확한 타임라인을 그대로 복사할 필요 없이 이러한 원칙을 차용하여, 정부의 가이드라인을 활용해 자체적인 위험 허용 범위와 투자 주기를 조정할 수 있습니다.

인텔의 역할: 전환을 위한 인프라 준비 완료 인텔은 제품군 전반에 양자 저항 기능을 제공하여 AI 혁신의 중심에 서 있습니다. 이는 단순히 목표에 불과한 로드맵이 아니라, 이미 출시 및 적용되기 시작한 기술입니다. 예를 들어, 인텔 제온(Xeon) 6 프로세서는 이미 양자 안전 메모리 암호화(AES-256) 및 프로세서 무결성을 보호하는 마이크로코드 서명을 통합하고 있습니다. 향후 플랫폼은 양자 내성 알고리즘을 더 많은 펌웨어 및 소프트웨어 서명, 장치 상호 연결, 증명(Attestation) 및 보안 부팅 기능으로 확장하여 가장 엄격한 정부 요구 사항에 부합할 것입니다.

원문 보기
원문 보기 (영어)
Sponsored Provided by Intel Quantum computing has alternated between breakthrough darling and overhyped promise in technology circles. Its powerful new capabilities come with a threat to break current cryptography, but for business leaders navigating the noise, the signal should be clear: post-quantum cryptography (PQC) is a manageable evolution, not a crisis. The mathematics behind today's encrypted digital transactions may yield to quantum computers one day, but the transition to quantum-resistant algorithms is neither sudden nor insurmountable. For executives concerned about disruption, cost, or complexity, a structured and phased approach exists with trusted technology partners like Intel that are already beginning to deliver the infrastructure to make it possible. A natural evolution, not a cliff edge The "quantum threat" narrative often swings between two extremes: imminent catastrophe or distant irrelevance. The reality occupies a more pragmatic middle ground. Quantum computers are highly specialized accelerators that exploit quantum physics to solve specific hard problems. They have the potential to crack modern encryption, but they will not replace classic servers overnight, nor will they instantly break every encryption protocol on the internet. What they will do is gradually shift the security landscape, much as previous cryptographic transitions have done over the past three decades. In late 2024, the Global Risk Institute , a Toronto-based financial services think tank, surveyed 32 quantum computing experts on when a quantum computer could break a 2048-bit RSA key within 24 hours. An average of optimistic and pessimistic estimates from the experts gave it an even 50-50 probability of reaching this code-breaking milestone by 2040. This timeline, uncertain but measurable, creates space for deliberate planning rather than emergency reaction. The near-term focus should be on "harvest now, decrypt later" scenarios, where adversaries collect encrypted data today and then hold it for future decryption later when that capability becomes possible. This is particularly applicable for information requiring confidentiality beyond 10 years. For most enterprises, this can be a manageable risk when addressed through methodical modernization. Government signals as confidence builders The U.S. government has issued new directives for National Security Systems (NSS), which would likely be first on the list for potential quantum attack. Beginning in January 2027 , new NSS acquisitions must be capable of supporting Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requirements for PQC algorithms standardized by the National Institute of Standards and Technology (NIST) and selected by the National Security Agency, the U.S. intelligence agency responsible for signals intelligence and information assurance. Implementation for new systems (with certain exceptions) is then required by 2031, with 100% adoption targeted by 2035. For commercial enterprises, these timelines are not mandates, but could be signposts. They indicate where vendors, standards bodies, and auditors are headed, providing a reference architecture for responsible stewardship. Organizations can borrow this discipline without necessarily copying the exact timelines, using government guidance to calibrate their own risk tolerance and investment cadence. Intel's role: Infrastructure ready for the transition Intel is at the heart of the AI revolution by delivering quantum-resistant capabilities across our product portfolio. This is not just aspirational roadmap language; it is starting to be shipping technology. For instance, the Intel Xeon 6 Processor already incorporates quantum-safe memory encryption (AES-256) and microcode signing to protect processor integrity. Upcoming platforms will extend post-quantum algorithms to more firmware and software signing, device interconnects, attestations, and secure boot functions, aligning with the most stringent government and industry directives. Post-quantum algorithms carry different key sizes and computational overhead than legacy methods. Intel addresses this through dedicated cryptographic accelerators, optimized libraries, and specialized CPU instructions that reduce latency and preserve service-level agreements. Technologies such as Intel QuickAssist Technology offload cryptographic workloads, enabling enterprises to adopt stronger algorithms without sacrificing performance. PQC is not a processor-alone problem. System builders and application owners must take a comprehensive view spanning solid-state drives, network interface cards, operating systems, hypervisors, applications, and connected services. Intel is delivering its pieces of the stack, while collaborating with ecosystem partners to ensure interoperability and smooth transition paths. A more in-depth discussion of post-quantum algorithms and attacks can be found in my recent blog posted on Intel’s Community forum: " Post-Quantum Crypto: Panic Like It's 1999? " A practical roadmap for enterprises The path forward does not require upheaval, just discipline. Organizations can follow a phased approach that mirrors patterns emerging in government and critical infrastructure sectors: Approach PQC as modernization, not mitigation. Frame the transition as an opportunity to strengthen cryptographic foundations, reduce technical debt, and improve system maintainability. Leverage trusted partners. Technology suppliers like Intel are already shipping quantum-resistant capabilities with performance acceleration. Evaluate platform readiness and vendor roadmaps as part of procurement decisions. Start with visibility. Cryptography is embedded throughout modern technology stacks: not just in database encryption settings but in data at rest, data in transit, digital signatures, code signing, device identity, password hashing, and software update mechanisms. Start by mapping where cryptographic assets live, what algorithms protect them, and which data sets have the longest confidentiality requirements. Protect long-lived data first. Not all cryptographic uses age at the same rate. Encryption protecting long-lifespan intellectual property, personal data, or state secrets faces more immediate attention than short-lived session keys or rotating certificates. Focus initial investments on high-value, long-retention data stores and the trust anchors (root certificates, firmware signing keys) that underpin system integrity. Design for evolution and agility. Post-quantum algorithms are not simple drop-in replacements. They carry different key sizes, performance characteristics, and integration requirements that ripple through protocols, APIs, and hardware. Design systems that can transition algorithms without business disruption: testing compatibility, ensuring vendor roadmaps align, and engineering for rotation. The bottom line Quantum computing will reshape cryptography, but despite what occasional click-bait headlines say, it will not upend business overnight. The transition to post-quantum algorithms is a measured, multi-year journey, one that organizations can navigate with confidence by partnering with capable technology providers, prioritizing long-lived data, and designing for agility. Leaders who approach this as an engineering evolution rather than a threat response will not only be ready for whatever timeline quantum delivers; they will emerge with more robust, transparent, and maintainable cryptographic foundations across their platforms. This content was produced by Intel. It was not written by MIT Technology Review’s editorial staff. Keep Reading Most Popular A startup claims it broke through a bottleneck that’s holding back LLMs Subquadratic has now shared more details about its new model. But some are still skeptical. By Will Douglas Heaven archive page A fundamental flaw leaves LLMs strikingly vulnerable to attack It makes it easy to trick them into doing things they shouldn’t, such as te