메뉴
BL
Ars Technica 35일 전

미 행정명령, 양자 내성 암호화 이행 기한 대폭 단축

IMP
8/10
핵심 요약

미국 백악관은 대규모 양자 컴퓨터 공격에 대비하기 위해 고가치 자산 시스템의 양자 내성 암호화(PQC) 도입 기한을 2030~2031년으로 최대 5년 앞당겼습니다. 이는 적성국가가 당장 가로챈 데이터를 훗날 양자 컴퓨터로 복호화하는 위협에 대응하고, 관련 업계 전반의 보안 전환 시기를 앞당기는 중요한 정책 조치입니다.

번역된 본문

미국 연방정부는 군사, 은행, 정부 기관 및 전 세계 대부분의 개인이 보유한 수십 년 치의 기밀을 보호하기 위해, 정부 기관과 조직이 양자 컴퓨터 공격을 견딜 수 있는 새로운 양자 내성(post-quantum) 암호화 시스템을 도입해야 하는 기한을 대폭 단축했습니다. '고도화된 암호 공격으로부터 국가 보장(Securing the Nation against Advanced Cryptographic Attacks)'이라는 제목의 이번 행정명령은 '고가치 자산(high-value assets)' 및 '고영향 시스템(high-impact systems)'을 위한 컴퓨팅 시스템이 2030년 12월 31일까지 양자 후 암호학적 키 설정 체계(post-quantum cryptographic key establishment schemes)로 전환하고, 2031년 12월 31일까지 양자 안전 디지털 서명 체계(quantum-safe digital signature schemes)로 전환할 것을 요구합니다.

중대한 위협 사전 차단 많은 조직에게 있어 약 5년가량 앞당겨진 이번 새로운 기한은, 암호학적으로 의미 있는 양자 컴퓨터를 구축하는 데 필요한 자원과 비용이 이전의 일반적인 추정치보다 훨씬 적다는 최근 연구 결과가 발표된 직후에 나오게 되었습니다. 이에 대응하여 구글(Google), 클라우드플레어(Cloudflare) 및 기타 기업들 역시 최근 취약한 시스템에서 벗어나는 타임라인을 2029년으로 앞당겼습니다.

이번 행정명령은 "특히 적대국의 손에 들어간 대규모 양자 컴퓨터의 등장은 널리 사용되는 암호 보안 시스템에 중대한 위협이 될 것"이라고 밝혔습니다. 또한 "현재 우리 국가에 대한 지속적인 사이버 활동은 적성국가가 현재 미국의 정보를 수집한 뒤, 대규모 양자 컴퓨터가 가동되면 나중에 이를 복호화(decrypting it later)할 수 있는 위험을 초래한다"고 경고했습니다.

미국 국가안보국(NSA)이 2022년에 발표한 일정에 따르면, 해당 기관의 권한 아래 있는 국방 및 정보 시스템만을 포함하는 '국가안보시스템(National Security Systems)'은 2030년에서 2033년 사이에 양자 준비(quantum-ready)를 완료하도록 명령을 받았습니다. 대부분의 다른 조직들은 2035년까지 전환을 완료해야 했습니다. 그러나 이제는 그중 많은 조직이 훨씬 더 빨리 전환해야 할 의무가 생겼습니다.

2015년부터 2022년까지 마이크로소프트(Microsoft)의 양자 후(post-quantum) 전환을 감독했으며 현재 파카스터 컨설팅 그룹(Farcaster Consulting Group)에서 일하고 있는 암호학 엔지니어 브라이언 라마키아(Brian LaMacchia)는 아스(Ars)와의 인터뷰에서 다음과 같이 말했습니다. "따라서 이 새로운 고가치 자산 및 고영향 시스템 범주에 속하는 모든 시스템의 경우, 전환 타임라인이 (2035년에서 2030/2031년으로) 4~5년 단축되었습니다. 이는 이러한 시스템의 전환 타임라인을 상당히 단축하는 것이며, 3월 말/4월 초에 구글과 클라우드플레어가 발표한 유사한 일정 수정과 맥락을 같이합니다."

또한 이 명령은 다음과 같은 내용을 포함하고 있습니다:

  • 관리예산처(OMB) 소장과 국가사이버국장이 주도하는 범정부 차원의 전환 조정 프로세스를 수립합니다. 각 연방 기관은 양자 전환 진행 상황을 보고할 책임자를 지정해야 합니다.
  • 국무장관에게 미국 국립표준기술연구소(NIST), 국방부, 국토안보부(DHS), 국가사이버국장, 국가정보국장(DNI)과 협력하여 "핵심 국가의 외국 정부 및 산업 그룹을 파악하고 참여시켜 NIST가 표준화한 PQC(PQC) 알고리즘으로의 전환을 독려"하도록 지시합니다.
  • 암호화 시스템의 모든 구성 요소, 라이브러리 및 모듈을 나열하는 CBOM(암호학적 자재 명세서, Cryptographic Bill of Materials) 출시와 관련된 가이드라인을 NIST와 사이버보안및인프라보안청(CISA)이 발행하도록 지시합니다.
  • '해당 계약자(Covered contractors)'가 동일한 양자 준비 기한을 충족하고 취약점 공개 정책을 구현하도록 요구하는 것을 목표로 하는 것으로 보이는 새로운 조달 규칙을 수립합니다.

부즈 알렌(Booz Allen)의 수석 양자 과학자인 조던 케니언(Jordan Kenyon)은 아스(Ars)에 "핵심 인프라 소유자와 운영자는 이제 PQC 마이그레이션 계획 수립을 위한 지원을 기대할 수 있을 것"이라고 말했습니다. "해당 계약자들은 2030년 말까지 FIPS(연방정보처리표준)에서 요구하는 PQC 호환 알고리즘을 통합하고, (취약점 등의) 보고서를 제출하도록 하는 제안된 규칙에 따른 향후 요구 사항에 직면할 수 있습니다."

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav The White House is drastically shortening the deadline for government agencies and organizations to adopt new quantum-resistant encryption systems that will withstand attacks that use quantum computers, as the federal government seeks to protect decades’ worth of secrets belonging to militaries, banks, governments, and most individuals on Earth. The executive order, titled Securing the Nation against Advanced Cryptographic Attacks , requires computing systems for “high-value assets” and “high-impact systems” to transition to post-quantum cryptographic key establishment schemes by December 31, 2030, and to quantum-safe digital signature schemes by December 31, 2031. Heading off a significant threat The new deadline, which for many organizations is about five years sooner than the previous one, comes on the heels of recent research showing that the resources and cost for building a cryptographically relevant quantum computer are far less than previous consensus estimates. In response, Google, Cloudflare, and other companies recently tightened their timelines for moving off vulnerable systems to 2029. “The advent of large-scale quantum computers, particularly in the hands of adversaries, will pose a significant threat to widely used cryptographic security systems,” Monday’s executive order stated. “Ongoing cyber activity against our Nation also presents the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational.” Under a timeline the National Security Agency published in 2022, “National Security Systems”—a class including only defense and intelligence systems under the authority of the agency—were under orders to be quantum-ready between 2030 and 2033. Most other organizations had until 2035 to complete the transition. Now, many of them will be required to transition much sooner. “So, for any system that falls into this new bucket of high-value assets and high-impact systems, their transition timelines just got shortened by 4-5 years (from 2035 to 2030/2031),” Brian LaMacchia, a cryptography engineer who oversaw Microsoft’s post-quantum transition from 2015 to 2022 and now works at Farcaster Consulting Group, told Ars. “That is a significant shortening of the transition timeline for these systems, and it follows similar timeline revisions from Google and Cloudflare that we saw announced back in late March/early April.” The order also: Establishes a government-wide transition coordination process to be led by the Director of the Office of Management and Budget and the National Cyber Director. Each federal agency will designate a point person responsible for reporting quantum transition progress to them. Directs the Secretary of State to work with the National Institute of Standards and Technology, the Department of Defense and Homeland Security, the National Cyber Director, and the Director of National Intelligence to “identify and engage foreign governments and industry groups in key countries to encourage their transition to PQC algorithms standardized by NIST.” Directs NIST and the Cybersecurity and Infrastructure Security Agency to issue guidance on the release of a CBOM (cryptographic bill of materials), which lists all components, libraries, and modules in an encryption system. Establishes new procurement rules that appear to be aimed at requiring “covered contractors” to meet the same quantum-readiness deadlines and implement vulnerability disclosure policies. “Critical infrastructure owners and operators can now expect support in developing their PQC migration plans,” Jordan Kenyon, senior quantum scientist at Booz Allen, told Ars. “Covered contractors could face future requirements from proposed rules to incorporate PQC compliant algorithms required by FIPS by the end of 2030 and incorporate reports of cryptographic vulnerabilities in their disclosures.” FIPS is short for Federal Information Processing Standards, a set of standards shepherded by NIST for use in computer systems of non-military US government agencies and contractors. No one knows when a cryptographically relevant quantum computer will arrive. Experts have made wide-ranging guesses for more than three decades. A key barrier is creating a system with the required number of qubits—the quantum equivalent of a bit in classical computing—that operates correctly even in the presence of errors that occur when they interact with their environment. In March, researchers said they discovered a way to break ECC-256, used to secure the bitcoin and ethereum blockchains, using only 30,000 physical qubits in 10 days. That same month, a Google research team said it developed two quantum circuits that could solve the elliptic-curve discrete logarithm problem using roughly 500,000 physical qubits, half of what the same team estimated last June was needed to break 2048-bit RSA, which has a much larger key size. In 2012, most estimates were that breaking a 2048-bit RSA key would require a billion physical qubits. By 2019, the estimate was lowered to 20 million physical qubits. The steady march of progress, as demonstrated by these latest research papers, is prodding organizations with the most to lose to err on the side of Q Day—the day a cryptographically relevant quantum computer arrives—coming sooner rather than later. Two of the most widely used public key cryptography algorithms—RSA and elliptic curve cryptography—are based on factoring composites, which are the product of two or more primes, and the discrete logarithm, respectively. These mathematical problems are simple to solve in one direction and nearly impossible in the other. A quantum computer with sufficient resources can run Shor’s algorithm to solve these problems in polynomial time, specifically cubic time , far faster than the exponential time provided by today’s classical computers. The post-quantum algorithms replacing RSA and elliptic curve cryptography are based on problems that quantum computers have no advantage over classical computers in solving. Contrary to what many people assume, substituting quantum vulnerable algorithms for PQC ones is anything but a drop-and-replace exercise. Public key sizes for ML-KEM—one of the replacements for RSA—are roughly three times bigger. The difficulty and scale of the work ahead is the reason the federal government is taking the move so seriously. Separately, the White House published a second executive order directing the federal government, in partnership with private industry, to support quantum computing. Among other things, it established a “national effort” to develop the world’s first quantum computer powerful enough to “initiate the era of quantum-enabled scientific discovery.” Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 7 Comments