[00:01.210 --> 00:11.910] Today topic is like quantum computing and how it's maybe going to impact the application security and how we can prepare for that. [00:12.110 --> 00:15.650] Like maybe it's like organization wise or like maybe individually also. [00:15.970 --> 00:18.250] Let's see like how exactly things will. [00:19.510 --> 00:21.850] Yeah, let's get started. [00:22.010 --> 00:31.190] Before that, I would like to thank the whole committee, volunteers and everyone giving me this opportunity to talk here. [00:32.130 --> 00:38.570] And organizing this wonderful HOPE conference because this is my maybe second or third. [00:38.710 --> 00:45.410] Once I went near the Penn Station, then after that online and this is maybe the third time I'm coming to the HOPE. [00:45.530 --> 00:46.750] It's a wonderful community. [00:46.930 --> 00:47.990] Thanks for everything. [00:49.490 --> 00:52.590] And myself is Shesha. [00:52.950 --> 00:54.850] It's a long name, so you can call me Shesha. [00:55.310 --> 00:59.730] I have like around 15 years of experience in application security, mostly. [00:59.730 --> 01:01.490] not into the other areas. [01:01.810 --> 01:03.050] So yeah. [01:04.150 --> 01:05.930] And it's a quick disclaimer. [01:06.210 --> 01:11.750] So yeah, most of this quantum computing or like whatever I have done, this is my own learning. [01:12.370 --> 01:19.250] And like the interest because I did my bachelor's in science and math, physics and chemistry. [01:19.870 --> 01:24.050] So quantum computing slides related to the quantum mechanics. [01:24.050 --> 01:28.690] That's where it triggered me the interest and started looking into that. [01:29.030 --> 01:32.610] And I tried to relate that into the application security. [01:32.790 --> 01:35.010] There is some relevance. [01:35.190 --> 01:39.990] So that's the reason I dig dive a little bit more into that and try to learn. [01:40.150 --> 01:42.150] So that's why we are here today. [01:43.090 --> 01:50.110] And the agenda is going to be like first initially, I'll just try to tell very little bit about quantum computing. [01:50.230 --> 01:54.450] I don't want to go very deep because it's a huge area to explore. [01:54.690 --> 01:57.730] Still a lot of scientists and researchers are working on it. [01:57.730 --> 01:59.710] But we'll see like what is quantum computing. [01:59.950 --> 02:01.910] Pretty basics, not not very deep dive. [02:02.090 --> 02:09.290] Then how it's going to how that quantum computing is threatening the at least the cryptography area. [02:09.530 --> 02:17.450] So the next one is going to be like at least I'll give like a little bit worry about what is encryption and what kind of encryptions are there. [02:17.650 --> 02:23.510] And based on that we'll try to correlate how quantum computing is going to impact the encryption area. [02:23.730 --> 02:29.830] So after that, how that cryptography is there in application security if quantum computing is impacting. [02:29.850 --> 02:34.010] So that's the way how I outline the agenda for today. [02:34.730 --> 02:36.270] And let's see like how it goes. [02:36.530 --> 02:38.090] So before getting started. [02:38.410 --> 02:44.030] So how many people are here working in security or like computer security? [02:44.250 --> 02:45.430] Oh bunch. [02:45.950 --> 02:47.450] So I need to be a little bit careful. [02:48.850 --> 02:57.230] Okay, so next maybe like I want to be made more interactive or else like yeah, people may sleep. [02:58.350 --> 03:06.130] So you are going to hear these words randomly between here and there in the next 40-45 minutes. [03:06.750 --> 03:13.070] like quantum computing, cryptography, application security or else like post-quantum cryptography. [03:13.250 --> 03:18.410] So don't get bored by just hearing those four words, but because that's the main agenda. [03:18.930 --> 03:19.770] So sorry about that. [03:20.830 --> 03:23.410] So yeah, what is quantum computer? [03:23.530 --> 03:24.990] Anybody has seen that here? [03:26.850 --> 03:27.950] Oh, that's cool. [03:28.330 --> 03:28.790] There are a lot of people. [03:29.050 --> 03:30.850] Did you guys see in physical? [03:32.590 --> 03:33.490] Oh, that's great. [03:34.350 --> 03:38.970] I mean, I expect one or two, but a lot of people saw that in person. [03:39.110 --> 03:39.430] That's great. [03:39.650 --> 03:41.010] Maybe touch physically. [03:42.130 --> 03:43.450] Oh, that's that's even there. [03:43.690 --> 03:44.270] That's nice. [03:44.410 --> 03:46.070] So I need to be very careful if I'm done. [03:48.810 --> 03:50.030] Is it looks like that? [03:51.190 --> 03:52.130] Quantum computer? [03:54.370 --> 03:55.270] I like this. [03:56.930 --> 03:58.530] Yeah, those are channelets. [03:59.450 --> 04:02.750] But those are pretty much similar to that. [04:04.350 --> 04:05.650] Oh, it's coming again. [04:07.430 --> 04:12.410] Yeah, this is one of the channel, not channelets, sorry, quantum computer. [04:14.650 --> 04:23.910] Yeah, even though like it looks like Chandler, but whatever we see the threads or whatever people will call in the gold colors. [04:24.250 --> 04:25.850] Those are like cooling systems. [04:26.270 --> 04:29.890] But the quantum chip will be like very small. [04:30.070 --> 04:35.530] It may be like our iPhone, but everything will be like the Chandler structure, whatever we call it. [04:35.530 --> 04:35.650] Right. [04:35.710 --> 04:37.470] So that is mainly used for the cooling. [04:37.710 --> 04:42.590] So we'll see like why we want that kind of structure for quantum computer. [04:42.930 --> 04:45.490] Mostly I'll try to explain it in a simpler way. [04:46.210 --> 04:53.310] And then we'll jump on to the maybe these images you could have seen in like maybe IBM. [04:53.910 --> 04:55.990] If you watch like whenever the IBM come up with that. [04:56.170 --> 05:08.950] And then after that, maybe Google come up maybe last year with the Velochip because it has computated some, I think, probabilistic in five minutes, which the classic computer will take a lot. [05:08.950 --> 05:12.970] But like maybe millions, not millions, they say like septillions or something. [05:13.170 --> 05:17.550] It's it's a long zeros and one in the left, not the right. [05:17.730 --> 05:24.110] So yeah, let's see before going to a little bit more into the quantum computer. [05:24.370 --> 05:29.350] First, like most of the people here use the classical computer, like because it's classical. [05:29.350 --> 05:37.810] Like means what we are using at least like maybe 30 to 40 years, like whether it's handheld device or like in your lab or like maybe in your iPad. [05:37.990 --> 05:39.810] So those are kind of like classical computers. [05:40.090 --> 05:44.310] Mostly they work with the bits like zero and one. [05:44.610 --> 05:49.950] And mostly they like what we call it. [05:50.050 --> 05:55.490] Usually they'll just take like one value and just keep it like zero and one, whether it's true or false. [05:55.490 --> 06:00.970] Or else if you ask a question, or else if you want to do some calculations, it's everything will happen in the zero and ones. [06:01.190 --> 06:03.370] But that's mostly in the back end. [06:04.570 --> 06:05.890] And just give me a second. [06:06.030 --> 06:07.610] I will try to turn off the... [06:07.610 --> 06:08.350] Yes. [06:09.950 --> 06:10.390] Yeah. [06:11.830 --> 06:15.330] Next is like, okay, that's like classical computer. [06:15.490 --> 06:17.490] So then what about the quantum computer? [06:18.230 --> 06:22.610] So what are the, like how exactly the quantum computer works? [06:22.710 --> 06:24.730] It uses a qubits like quantum bits. [06:24.730 --> 06:27.510] It's not like typical zero or one. [06:27.650 --> 06:30.470] So usually, as I said, like everything will happen in the zero or one. [06:30.590 --> 06:32.490] Like if you ask a question, it's true or false. [06:33.030 --> 06:38.790] Or like in any calculations, like even if you are doing any GPU intensive task, still they use the zeros and ones. [06:38.950 --> 06:43.090] But maybe because of the more processing power, it will do that. [06:43.530 --> 06:46.770] But the way how quantum computers works is slightly different. [06:46.890 --> 06:48.050] They won't use the bits. [06:48.210 --> 06:49.210] They use qubits. [06:49.390 --> 06:50.740] They will call it as quantum bits. [06:51.640 --> 06:53.060] They use like... [06:53.060 --> 06:53.940] Like usually like... [06:54.900 --> 06:57.700] It's like similar to zero or one, but it's not like... [06:57.700 --> 07:01.240] It won't be consistently where zero or one it will be like... [07:01.240 --> 07:05.780] It's kind of a pendulum which will rotate from here to there or something like that. [07:05.920 --> 07:10.020] Maybe it may exist in the both state at the same time. [07:11.140 --> 07:13.160] So this is like how typical... [07:13.560 --> 07:16.360] Like if you see the left side, this is like classical computer. [07:16.620 --> 07:20.740] So where we see like this NAND switch, like all the gates and everything will be there. [07:20.880 --> 07:24.560] But if you move on to the quantum computer, it's slightly different. [07:24.760 --> 07:31.380] Like maybe you can see this A and that's kind of like the qubit. [07:31.580 --> 07:34.400] The way how they represent, it's kind of like A plus zero or one. [07:35.040 --> 07:35.940] So something like that. [07:35.940 --> 07:37.320] So that's a slight difference. [07:37.500 --> 07:44.680] So like maybe it's a huge difference between the classical and quantum computer. [07:44.840 --> 07:47.880] So what is the main advantage of quantum computers? [07:48.040 --> 07:53.040] Because everyone is thinking more about the quantum computers or like everyone is talking about that. [07:53.140 --> 07:58.040] So how it provide more power or like more advantages. [07:58.040 --> 08:02.080] It's not like power because how we can say is like it's classical computers. [08:02.120 --> 08:05.200] Usually how people will tell is like it's like a race car. [08:05.320 --> 08:06.480] If you take, it's just an example. [08:06.600 --> 08:09.240] If you say like a race car, a Lamborghini or a F1 race car. [08:09.700 --> 08:15.820] So it will go super fast by calculating the, by utilizing the power, what it has in GPUs or CPUs. [08:16.420 --> 08:21.520] But if you take the same car and if you keep it in the water, it may not go that much fast. [08:21.520 --> 08:25.720] Because the landscape is different because, because it is designed to run on the Earth. [08:25.900 --> 08:29.720] So similarly to that, classical computers in that, if you say in a car. [08:29.960 --> 08:35.380] So quantum computers, it's kind of like boat or like steam or like whatever we use in the water. [08:35.380 --> 08:38.140] So it's kind of a different terrain or different landscape. [08:39.420 --> 08:44.620] So it has its own advantages and classical computers has its own advantages. [08:44.620 --> 08:52.880] But at the end of the day, if you, if real quantum computers comes into the existence and it get its own power, it will try to solve the challenges. [08:53.560 --> 08:58.480] Which classical computer is getting little bit delayed and getting troubled. [08:58.680 --> 09:00.840] So that's where the minor advantage is there. [09:01.060 --> 09:05.660] So how the quantum computing is getting advantages like? [09:06.980 --> 09:13.440] Let's see like how it is like the mainly that because it uses the quantum properties, which we'll see in the next few slides. [09:13.440 --> 09:18.360] Like if you select superposition and entanglement and quantum tumbling. [09:18.800 --> 09:23.400] So a superposition and entanglement is the major properties. [09:24.120 --> 09:33.620] By using that, the computer like the scientists and researchers trying to solve the problems, which classical computers are taking years to do that. [09:33.680 --> 09:42.200] As I mentioned earlier, like Google Willowchip has done the calculations in five minutes, which classical computers are taking a longer time. [09:42.200 --> 09:45.460] Like septillion or whatever the number, number of years. [09:45.820 --> 09:51.580] So by using these kind of properties, the quantum computers are going to take the advantages. [09:52.020 --> 09:53.540] So the main advantage is... [09:53.540 --> 09:55.520] Can you turn on the subtitles, please? [09:55.920 --> 09:57.100] I did it. [09:57.520 --> 09:58.100] Oh, on? [09:58.600 --> 09:58.880] On. [09:59.120 --> 09:59.400] Okay. [10:00.400 --> 10:00.700] All right. [10:01.000 --> 10:01.320] No, no. [10:01.940 --> 10:04.280] Now I thought it may be disturbing you guys. [10:04.400 --> 10:04.840] So that's right. [10:05.980 --> 10:06.500] Okay. [10:06.740 --> 10:07.200] Now it's good. [10:08.980 --> 10:09.460] Yeah. [10:10.600 --> 10:11.080] Yeah. [10:11.620 --> 10:15.920] So how these two properties are going to help is like the main is like quantum bits. [10:16.100 --> 10:24.840] Like how the bits are like zeros and ones, how they can exist in the multiple states simultaneously by taking that as an advantage. [10:24.840 --> 10:26.860] Because if you select, if you want to calculate anything. [10:26.860 --> 10:32.040] So classical computer has to be, exist in the state and then only it has to move on. [10:32.180 --> 10:35.320] Usually it will do like stuff in this simultaneously. [10:36.340 --> 10:37.860] So that's the classical computer. [10:38.000 --> 10:44.960] But because of this, the quantum bits property, which can exist in multiple states at the same time. [10:45.100 --> 10:50.720] So by calculating the, whatever the, like whatever is requirement. [10:50.980 --> 10:51.800] So it's going to be helpful. [10:51.980 --> 10:53.180] So let's see like how it is going to help. [10:53.180 --> 10:53.480] Okay. [10:53.900 --> 10:56.360] The core concepts, like, as I mentioned in the previous slide. [10:56.500 --> 10:59.440] So the core concepts will be like superposition. [10:59.880 --> 11:03.700] So that's going to be the main core concepts for the quantum computer. [11:04.040 --> 11:07.000] So the particle exists in multiple states in simultaneously. [11:07.200 --> 11:08.120] We can see in the next slide. [11:08.220 --> 11:11.620] So how, how we can imagine that, how we, how it is possible. [11:11.920 --> 11:14.500] So next one is like entanglement. [11:14.500 --> 11:26.220] So it's kind of like entanglements, like if you see like two particles, if one particle changes, like, like suppose if it is one particle is showing upward, upward. [11:26.620 --> 11:30.780] Then another particle without knowing that it can show into the downward. [11:30.960 --> 11:35.020] So it's like kind of like, if you see in the physics, so there will be like neutrons or protons, right? [11:35.140 --> 11:37.560] So how they do the spending and directions. [11:37.560 --> 11:43.980] So by looking at one particle itself, we can decide the, what exactly the next particle is doing. [11:44.200 --> 11:47.720] So that's the advantage of the quantum computer. [11:47.960 --> 11:49.560] So that that's kind of like entanglement. [11:51.620 --> 11:52.980] So, so what will happen? [11:53.560 --> 11:55.020] This entanglement will happen. [11:55.200 --> 11:58.800] Usually what people will think, so, okay, that particle is next to each other. [11:58.800 --> 12:08.280] So that's why they know it's not like, it's not like they're very next to each other, even though if they are very far itself, like even though if it is in another continent or like maybe another planet. [12:08.280 --> 12:13.480] So still it has that connection between those two particles. [12:13.620 --> 12:15.980] So by using that, we use the quantum computer. [12:16.140 --> 12:18.720] So, so let's see like the core principle. [12:18.940 --> 12:21.880] So what are the like superposition and next one is entanglement. [12:22.540 --> 12:23.200] So little bit detail. [12:23.320 --> 12:28.560] So how, so just to get everyone picture, because I know few people are already aware of quantum computers. [12:28.560 --> 12:32.280] But for the noise, I like the new, new folks. [12:32.440 --> 12:34.640] So I'll try to explain a little bit in time. [12:34.940 --> 12:38.600] So if you see like usually like if some spinning coin is there. [12:38.700 --> 12:43.220] So usually what we'll say like whenever someone spins, we'll say like head or tail, but whenever it is spinning. [12:43.660 --> 12:47.580] So there are like both possibilities, like 50, 50 percent. [12:47.760 --> 12:50.300] Sometimes when it is slowing down, it may get like 70, 80. [12:50.540 --> 12:53.640] So based on that, that is called like superposition. [12:53.780 --> 12:58.300] So if you see in the next, the below one itself, like it is just spinning over there. [12:58.300 --> 13:00.680] So it's until it come to certain stage. [13:00.840 --> 13:05.460] Or else like if we can measure at that point, we don't know which, what is the exact position. [13:05.640 --> 13:08.740] So that's the advantage of the quantum bits. [13:09.060 --> 13:13.560] So it can exist in the multiple states, all possible states. [13:13.720 --> 13:18.200] Like maybe here, I'm just talking about only one quantum bit. [13:18.200 --> 13:26.820] But suppose if we have like 50 quantum bits, so like 50 zeros and ones, but we can calculate on based on like what exactly is happening. [13:26.980 --> 13:40.480] So what exactly scientists are trying to do, if you want to solve the bigger problems, they're trying to get the millions of qubits running at a time to calculate these probabilities to get the solution for different. [13:40.480 --> 13:48.080] So not only for security side or like cryptography side, they want to solve the challenges, which classical computers are not able to. [13:48.140 --> 13:49.520] That's I have mentioned that. [13:49.680 --> 14:01.420] So let's see, like maybe we can see like what kind of challenges quantum computers can help if researchers or scientists can build the quantum computer, which can use the millions of qubits. [14:01.420 --> 14:05.020] Currently, I think they have like around 100 only that's we'll see in the next slide. [14:05.200 --> 14:12.820] So probabilistic nature as we say, like like still until we measure it, we don't know the exact position. [14:13.020 --> 14:13.960] It's a zero or one. [14:14.060 --> 14:15.460] It may be triangle in between them. [14:15.620 --> 14:21.960] So next one is like measurement impact. [14:22.100 --> 14:27.660] So as I mentioned earlier, so so the main advantages is like computational power. [14:27.660 --> 14:40.380] Of course, GPUs or Nvidia, whatever, they have the bigger computational power, but still like if you see like 20 years back, the computation power, everyone select 200, like 256 MB RAM should be fine. [14:40.500 --> 14:50.500] But now people are going for the 48 MB RAM also is not sufficient because it's like all the programs are everyone is like memory hungry or GPU hungry. [14:50.500 --> 14:59.320] So that's the reason even though if it is current GPU has enough power, but still we want more power to solve few challenges. [14:59.600 --> 15:06.440] So so that's the reason quantum computing will use this parallel computing in the solving it. [15:06.540 --> 15:09.380] So next one is the quantum entanglement. [15:09.620 --> 15:19.680] So as I mentioned, like the state of the between the two particles, which can be measured even though they are not near as well. [15:19.680 --> 15:21.000] So that's the quantum entanglement. [15:21.180 --> 15:22.480] I touched a little bit there. [15:22.580 --> 15:24.160] So let's move on to the next one. [15:24.460 --> 15:29.200] So so we have seen a little bit advantages of the quantum computing so far. [15:29.300 --> 15:36.940] So but people may ask like why scientists started because maybe it has started like 1980s or 1990s long the time. [15:37.080 --> 15:43.560] But why scientists or everyone is taking time to build the quantum computers, which has more power? [15:43.560 --> 15:47.680] Or like maybe as I said, like it has currently like 100 or 150 qubits only. [15:47.760 --> 15:50.920] Why don't we scale up to the one million or like more than that? [15:51.080 --> 16:08.240] So but the major challenge is like error correction because the particles, whichever is, it's very small and it has the disadvantages of like if you see like any small environmental changes going to impact the particle state. [16:08.240 --> 16:08.240] Right. [16:08.420 --> 16:15.920] So that's going to be very challenging for the scientists or researchers who wants to develop the quantum computers. [16:16.200 --> 16:17.620] So they're trying to come up with that. [16:17.760 --> 16:20.680] And the next one is going to be like temperature. [16:20.680 --> 16:28.720] So it should be like near the absolute zero, not not zero foreign heat or zero centigrade. [16:29.020 --> 16:32.760] It's they wanted the zero absolute zeros. [16:32.900 --> 16:34.980] That's going to be like Kelvin or milliKelvin itself. [16:35.200 --> 16:39.380] So that's going to be very challenging because it's colder than the outer surface. [16:39.540 --> 16:43.840] So it's very challenging that to replicate in the lab area. [16:43.840 --> 16:52.440] So that's the reason most of the people could have seen the quantum computers in the IBM research centers or Microsoft or whoever is trying to do. [16:52.560 --> 16:52.620] Right. [16:52.720 --> 16:57.060] So that's going to be very challenging, maintaining the temperature, even the program. [16:57.400 --> 17:05.480] Programming is not super critical because there are some interpreters which can convert the programming, whatever we have developed into the quantum. [17:05.480 --> 17:10.960] But still it is in the earlier stages, but compared to the previous ones, those are the major challenges at least. [17:11.080 --> 17:16.570] So if you see the timeline currently, theoretically, they started developing in the 1980s. [17:18.300 --> 17:20.900] Then 1990s, Shor algorithms come up. [17:21.020 --> 17:23.460] So that we'll talk in the later little bit more detail. [17:23.740 --> 17:26.200] So this is also kind of a theoretical. [17:26.560 --> 17:33.300] But if Shor algorithm will say like if we have enough quantum computers which can break the encryption. [17:33.300 --> 17:34.560] So that's the other one. [17:35.980 --> 17:39.000] Then 2010s, like 50 qubits has been developed. [17:39.160 --> 17:39.400] 2020. [17:39.900 --> 17:41.260] So it is kind of... [17:41.260 --> 17:45.720] Nowadays, I think Google or someone, they have shown like error prone has been reduced. [17:46.760 --> 17:48.640] And yeah, let's see like... [17:49.540 --> 17:51.720] So what is the quantum threat timeline? [17:51.920 --> 17:54.300] So how it is going to threat the... [17:55.460 --> 17:57.340] At least the encryption area. [17:57.520 --> 18:00.440] So the present day, like at least like 50 to 100 qubits are there. [18:00.440 --> 18:05.640] Maybe by three to five years, we may get more qubits, five to 10 years, which... [18:05.640 --> 18:07.560] Like it's based on like how faster. [18:07.740 --> 18:13.880] But actually the development and everything is happening at the exponential speed compared to the... [18:13.880 --> 18:16.840] Like what exactly the researchers thought initially. [18:17.020 --> 18:21.520] But even initially, researchers thought like to break an issue or algorithm or something. [18:21.520 --> 18:25.160] They may need maybe suppose like 100 millions of qubits. [18:25.360 --> 18:31.740] But the coming down, the estimates are coming down and the rapid development is going a little bit faster. [18:31.740 --> 18:34.020] So there will be a overlap in that. [18:34.180 --> 18:41.520] So there are chances like we may get the good quantum computer, which can break the encryption. [18:42.300 --> 18:44.460] So in maybe 10 or 15 years. [18:44.680 --> 18:46.740] So that's the reason we had to be... [18:46.740 --> 18:48.760] Like a lot of organizations are they... [18:48.760 --> 18:51.600] Like maybe we don't know like threat organizations or threat actors. [18:51.980 --> 18:54.300] Started harvest now or like decrypt later. [18:54.460 --> 18:59.020] Because what they're trying to do is like any sensitive transactions between the countries or between the banks. [18:59.160 --> 19:00.940] So they're trying to get it, store it. [19:01.060 --> 19:05.080] Maybe once the quantum computers comes to the picture. [19:05.080 --> 19:07.140] So they try to decrypt and they'll try to get it. [19:07.140 --> 19:08.880] So that's a major threat exactly happening. [19:10.660 --> 19:11.100] Okay. [19:11.360 --> 19:12.440] Let's leave like... [19:13.160 --> 19:15.140] Like cyber security a little bit aside. [19:15.380 --> 19:20.320] And let's say like how the quantum future will be like how it is going to help. [19:20.580 --> 19:25.140] So what exactly they're trying to do is like they're trying to help the... [19:25.760 --> 19:27.540] Maybe I'll go on to the next slide. [19:27.740 --> 19:29.140] So that has the... [19:29.680 --> 19:31.780] Yeah, if you see the first side. [19:32.000 --> 19:32.680] So that's cryptography. [19:32.960 --> 19:34.280] We talk a little bit now. [19:34.280 --> 19:38.400] So the next one, how it is going to help fully is the scientific research. [19:38.600 --> 19:42.040] If you select molecular modeling, because obviously are the... [19:42.040 --> 19:45.720] Like if you see the molecular level, it's a little bit tough to... [19:45.720 --> 19:53.460] Tough for the classical computers to calculate or like do the probabilistic for the molecular level. [19:53.620 --> 19:54.300] So it's going to be difficult. [19:54.400 --> 20:00.020] But quantum computers, since it has that qubit nature, which can exist in multiple states at that time. [20:00.020 --> 20:06.960] So that can help in the molecular modeling or like material science or even in the drugs. [20:07.340 --> 20:08.880] It means like for the... [20:08.880 --> 20:14.180] Any kind of a disease which they can try to find out the medicine or something like that. [20:14.340 --> 20:14.560] So... [20:15.280 --> 20:20.440] So such kind of helpful features are there with the quantum computers. [20:20.680 --> 20:25.120] So that's the main reason why researchers are more interested to come up with that. [20:25.120 --> 20:26.900] So not just for breaking the encryption. [20:27.400 --> 20:31.900] So the main reason is like few areas in the challenges what we have like currently. [20:32.060 --> 20:37.240] Maybe if you see like any farming areas or like maybe medicines which we want... [20:37.240 --> 20:39.120] The scientists want to... [20:39.120 --> 20:41.340] Usually they do the trial and error methods, right? [20:41.400 --> 20:42.660] So they don't want to do it for... [20:42.660 --> 20:49.740] They don't want to take a longer time because they don't have enough resources to test it in the lab itself and do it in the... [20:49.740 --> 20:53.640] So such kind of things definitely quantum computers is going to be helpful. [20:54.880 --> 20:55.240] So... [20:56.240 --> 20:57.160] So the... [20:57.160 --> 21:03.380] How it is going to be like simulating the complex like quantum system like molecules or materials. [21:03.380 --> 21:09.800] It will try to do because of that medicine discovery or drug discovery or material science or chemistry in that area. [21:09.980 --> 21:10.740] So it is going to be helpful. [21:11.060 --> 21:11.120] Okay. [21:11.900 --> 21:20.580] If you see in the machine learning, obviously a lot of people will ask whether quantum computers can help for the machine learning or AAML, whatever we call nowadays. [21:20.720 --> 21:20.800] Right? [21:20.880 --> 21:28.460] So obviously it may help because if you see in cybersecurity, so we want to read the patterns from the attackers or the attackers. [21:28.480 --> 21:29.880] They try to change the... [21:29.880 --> 21:35.280] They will try to obfuscate the attacks and they will try to change the attack pattern. [21:35.280 --> 21:39.200] So that patterns, it's not easily measured by us. [21:39.420 --> 21:41.980] So definitely quantum computers are going to be helpful. [21:43.160 --> 21:43.560] Okay. [21:43.960 --> 21:48.000] We learn a little bit, maybe in the first 20 minutes about the quantum computers. [21:48.500 --> 21:51.500] Maybe you guys understood a little bit and that's what I hope. [21:51.620 --> 21:52.380] Let's move on to cryptography. [21:53.040 --> 21:59.020] So I hear like, I mean, at least few hands rise when I ask the question about like how many works in security. [22:05.280 --> 22:08.940] That's like what is cryptography means encryption. [22:09.240 --> 22:15.920] So encryption is like in one shot, like you will take a plain text and convert into the ciphertext. [22:16.040 --> 22:21.460] If you want to send some message to someone, someone should not in the middle, someone should not be read. [22:21.540 --> 22:21.680] Right? [22:21.780 --> 22:25.080] So that's we call it converting the plain text to the ciphertext. [22:25.500 --> 22:26.780] Ciphertext is called as encryption. [22:27.000 --> 22:32.740] So for that we use the key because by using that key, only the third parts, it can decrypt it. [22:32.740 --> 22:40.260] But over the years that it has developed because of the complications and man in the middle or like whatever then. [22:40.800 --> 22:43.900] So basically we use like two types of encryption. [22:44.140 --> 22:47.280] Maybe you guys could have here like symmetric and asymmetric. [22:48.040 --> 22:54.880] The name itself will see like symmetric is like which use the same key for encryption and same key for the decryption. [22:55.080 --> 23:00.560] So what we do, like suppose if you want to send some message to the someone in England. [23:00.560 --> 23:04.540] So what you have to do, like you have to share the key first, then only they can decrypt it. [23:04.600 --> 23:07.940] But that's not feasible for everyone like all the time. [23:08.080 --> 23:08.140] Right? [23:08.220 --> 23:08.640] So obviously. [23:08.800 --> 23:12.760] So that's the reason they come up with the concept called asymmetric encryption. [23:12.940 --> 23:18.600] So where you need to share the key all the time because you can share only your public key. [23:19.060 --> 23:24.200] And if someone is encrypting or someone is sending data to you, so they can use your public key and send it back. [23:24.200 --> 23:26.660] Since you only have the private key, you can decrypt it. [23:27.300 --> 23:29.400] And so that's called asymmetric. [23:29.580 --> 23:31.720] So I don't want to spend too much time there. [23:31.820 --> 23:51.840] But if you see like the major impact from the quantum computer on what we are going to talk in next five, ten minutes is like going to be in the asymmetric encryption algorithms, which currently we are using, which are prone to like, which has a weaknesses based on based on that quantum computers can may break it in future. [23:54.560 --> 23:54.640] Okay. [23:55.800 --> 24:09.360] So encryption at web applications that we see in the next slides, but I'll try to summarize a little bit because if you see like web application or any mobile application or any application, obviously they may use the HTTPS, you could have seen in the browser URL bar. [24:09.540 --> 24:20.880] So for that, they use in a combination of symmetric and asymmetric in a such a way to provide better security instead of just randomly use symmetric or asymmetric. [24:21.420 --> 24:37.000] The researchers are like open-source community or whoever they come up with a better solution to use in a way like by using asymmetric, exchange the symmetric key and there onwards try to use the symmetric key for further communication in the HTTPS connection. [24:37.160 --> 24:37.780] That's yeah. [24:39.820 --> 24:42.100] So that's encryption one more one. [24:42.320 --> 24:43.060] I'm coming back. [24:43.320 --> 24:44.780] So this is asymmetric. [24:44.900 --> 24:53.460] As I mentioned, like we are going to talk a little bit more in the asymmetric key because that's where quantum computing is becoming a risk for the encryption. [24:54.040 --> 24:55.640] So this is the one area. [24:55.640 --> 25:09.100] So this is a major area at least like so asymmetric key cryptography, as I mentioned, like if you see like in the first slide for the encryption, we use the recipient's public key because recipient is what really he will publish his public key. [25:09.360 --> 25:14.640] Whoever wants to send a message to him will use his public key and can encrypt it and send it back to him. [25:14.740 --> 25:16.680] Obviously, he won't lose. [25:16.820 --> 25:19.500] Obviously, we hope he won't lose his private key. [25:19.760 --> 25:24.920] If he didn't lose it, obviously, he's the only person who can read it back what we have sent it. [25:24.920 --> 25:28.820] So that's how this entire asymmetric key cryptography works. [25:29.240 --> 25:33.080] So the major algorithms are like RSA, DSA, Diffie-Hellman or ECC. [25:33.400 --> 25:36.420] So now let's see like how RS algorithm works. [25:36.600 --> 25:44.580] And I won't take too much time here because RS algorithm is at least a little bit complex for my mind. [25:44.580 --> 25:47.160] But I'll try to explain a little bit easily. [25:48.500 --> 25:52.580] So if you see like the M is like the message which you want to send it to the someone. [25:53.380 --> 25:58.760] And by using this simple mathematical calculation, so we'll get back the M. [25:58.940 --> 26:01.860] So by using like exponential on top of that and something like that. [26:02.100 --> 26:04.240] And N is like one of the modulus of N. [26:04.380 --> 26:06.100] So and we are getting back the same M. [26:06.100 --> 26:06.960] So by using this. [26:07.200 --> 26:11.560] So what RSA means like three researchers are the three scientists. [26:11.860 --> 26:14.220] They have come up with this pretty good algorithm. [26:14.500 --> 26:22.420] It's so how they what they have done is like they'll take a message and they use the exponential component and D and they do the N and this is M right. [26:22.500 --> 26:26.740] So what they have done is like they try to do split it into such a nice way. [26:26.740 --> 26:30.400] One is they use it for the encryption and another one used for the decryption. [26:30.580 --> 26:32.860] So if you see like this is the X is the cipher text. [26:33.140 --> 26:34.560] What we have talked so far, right? [26:34.900 --> 26:37.680] We'll take the plain text and convert into the cipher text. [26:37.840 --> 26:39.800] So here M is the plain text. [26:40.060 --> 26:42.780] Okay, here like M is the message that we can call it as plain text. [26:42.980 --> 26:51.440] So we are taking the plain text and converting back to the cipher text and we are decrypting back to the plain text, the receiver. [26:51.660 --> 26:55.920] So this is how high level the RSA algorithm works. [26:56.060 --> 26:56.140] Okay. [26:56.740 --> 27:02.520] So here, we are not sharing the same key and also we are using the two difference. [27:02.680 --> 27:04.440] We see here E is one and D is one. [27:04.920 --> 27:07.860] So without knowing these two, they may not get back that. [27:08.080 --> 27:15.000] So now we have understood a little bit about the encryption types, asymmetric asymmetries. [27:15.160 --> 27:21.300] And I have mentioned a few times like how quantum computers are going to impact that. [27:21.300 --> 27:26.980] So if you see the first side, asymmetric cryptography, sorry. [27:27.560 --> 27:32.040] So RSA is mainly depends on the difficulty of factoring. [27:32.120 --> 27:32.940] If you see that modulus. [27:33.220 --> 27:43.200] So the P, like if you say, if you take a large prime number, so how it works is like they will try, like we need to calculate two prime numbers, which can come up with the large prime number. [27:43.300 --> 27:46.820] So based on that computational factorization. [27:47.080 --> 27:48.800] So mainly depends on that. [27:48.800 --> 27:56.860] So, but difficult, like based on that difficulty till or no one able to solve it, because the classical computers will take years to solve it. [27:58.500 --> 28:01.600] But the way how the classical computer works in such a way. [28:01.700 --> 28:05.940] So it's difficult for the classical computers, but the way how quantum computers works, right? [28:06.460 --> 28:09.440] This factoring becomes slightly easier. [28:09.700 --> 28:14.220] If you have the probability calculation, so they can try to break it. [28:14.220 --> 28:23.960] So that's way how RSA or else like maybe another algorithms are vulnerable to the post-quant like quantum computing attacks. [28:24.160 --> 28:24.240] Okay. [28:24.740 --> 28:32.060] So if you see like this asymmetric mainly is mainly is vulnerable to the Shor's algorithm. [28:32.380 --> 28:37.780] And if you see like symmetric key cryptography is like Grover's algorithm. [28:37.920 --> 28:48.360] Grover's algorithm is slightly different because if you see in Shor's, it tries to calculate the factors, two factor primes in a faster way. [28:48.500 --> 28:51.160] But in the Grover's algorithm, it's like a search. [28:51.420 --> 28:58.240] Like maybe if you see like it's pretty good at the searching the index, which is not indexed. [28:58.280 --> 29:00.040] So it is non-index search items. [29:00.180 --> 29:02.420] It can do the search very fast. [29:02.560 --> 29:07.980] So by using that, it can break the AES or like even the hashing as well. [29:07.980 --> 29:16.780] So if you are trying a little bit, like if you find a little bit tough with that, so I'll try to explain like in a different way. [29:17.220 --> 29:21.880] So if you see like a cryptography algorithm, so AES, like it's a symmetric key. [29:22.240 --> 29:23.800] The main purpose is like for the encryption. [29:24.100 --> 29:27.440] So it's a larger keys are required. [29:27.580 --> 29:31.060] So if you want to move on to the quantum computer, so impact from the... [29:31.060 --> 29:34.980] So we need to increase the AES, like maybe 256, 512 or more than that. [29:34.980 --> 29:43.700] But even the SHA hashing also, because hashing also it's kind of like, maybe you could have here in the rainbow tables or few other, right? [29:43.800 --> 29:48.540] So how people try to build the rainbow tables and try to search for the matches. [29:48.740 --> 29:51.980] Similar to that, Grover algorithm will help this searching quicker. [29:52.320 --> 29:55.660] So that will even SHA or AES are vulnerable to that. [29:55.760 --> 30:01.300] So that's the reason we want to move on from them or else try to protect the existing algorithm. [30:01.300 --> 30:11.360] So, and if you see here, ECDSA are like at least asymmetric or not secure against the quantum computers. [30:11.600 --> 30:21.000] At least maybe SHA or else like AES, we can use the larger keys or like maybe move on to the SHA, 512 or like other SHA algorithms. [30:21.220 --> 30:22.100] So that those are helpful. [30:22.380 --> 30:22.480] Okay. [30:23.500 --> 30:36.480] Even if you see like most of the cryptocurrencies, maybe if anybody is interested in the area, they use heavily ECDSA or like ecliptic or digital signature algorithm for their calculations. [30:36.980 --> 30:37.440] Okay. [30:39.000 --> 30:47.000] So, so yeah, we have seen like a few things like how it can break the symmetric or asymmetric algorithms, right? [30:47.280 --> 30:51.120] So now let's try to see like what it will break in real world. [30:51.120 --> 31:00.700] So we, we have just seen one part of the like symmetric, arithmetic, or RSA, or, um, uh, easy, like electric or cryptography, right? [31:00.800 --> 31:02.480] So how, what exactly it is going to impact? [31:02.640 --> 31:08.160] Because if you see like these encryption algorithms are used in the HTTPS connections, right? [31:08.240 --> 31:13.860] As I mentioned, so obviously it is going to break the, uh, SSL or like TLS traffic. [31:14.020 --> 31:18.700] Of course, SSL is no one using, but for namesake, we'll try to use the both words combinationally. [31:18.700 --> 31:23.580] But we can read it as TLS and, uh, uh, certificate or PKI. [31:23.840 --> 31:29.480] Like, um, if you see like, uh, digital, uh, certificates, which we are sharing, right? [31:29.540 --> 31:40.240] So those are going to be impacted with this quantum computers, even as I mentioned, like blockchain or any cryptocurrencies also, if they're using ECDSA or any, any other algorithms. [31:41.080 --> 31:53.520] I quickly touch on the, how cryptography is using in the application security, but I, I could have touched high level, but let's see like how exactly cryptography is used in, uh, application like, uh, apps. [31:53.640 --> 31:58.500] Like, like if you see in the browser, if you enter the HTTPS URL, what will happen? [31:58.640 --> 32:07.460] So, so what is, how exactly that entire connection is secure is like by using the symmetric and asymmetric encryption, which I have mentioned earlier, right? [32:07.600 --> 32:13.920] So it tried to use in a combination in a, uh, clever way to protect the entire connection. [32:13.920 --> 32:30.200] First, they use the asymmetric encryption to exchange the, uh, session key or like, um, uh, secure key between those two parties who wants to connect it, whether it's a browser or like whether it's, it's your mobile app or like any, if, if you are using any other, [32:30.200 --> 32:33.320] the client also, like not only the, uh, browser. [32:33.580 --> 32:35.920] So they use in a such a way to protect it. [32:36.040 --> 32:42.400] So symmetric is like another, it's the same key which use, which we use the asymmetric key to exchange between those two parties, right? [32:42.480 --> 32:45.800] By using that, uh, they start the, doing the encryption. [32:46.040 --> 32:50.780] So if you want to learn a little bit more, these are the few areas which we can learn more. [32:51.300 --> 32:52.780] I just kept it as a reference. [32:52.940 --> 32:56.820] So if you see like this, I, like most of the people could have used the wireshark. [32:57.120 --> 33:02.120] Maybe I don't know whether people are nowadays using it or not, but wireshark is like, which we can capture the packets. [33:02.920 --> 33:09.280] So what I did, like, I tried to capture the packets in the first few milliseconds, whenever I hit any google.com or anything. [33:09.460 --> 33:11.040] So these are the initial connections. [33:11.220 --> 33:12.920] So if you see this red box, right? [33:13.280 --> 33:17.140] So this is where exactly this entire encryption part lives. [33:17.560 --> 33:19.900] So I try to highlight a little bit more in the next slide. [33:20.180 --> 33:23.240] So if you see this one, so these are, we'll call it as cipher suites. [33:23.420 --> 33:25.900] So these are the cipher suites supported by the browser. [33:26.380 --> 33:32.360] So by, uh, telling the server, these are the cipher suite, which we can use to make our connection more circuits. [33:32.540 --> 33:39.940] So like TLS, ECDHA or AES, and like you can see a bunch of certificates, which browser supports based on the server configuration. [33:39.940 --> 33:47.620] Server will use that and try to exchange the certificate and key session key or other stuff to make the connection circuit. [33:47.780 --> 33:54.020] So, so far we have seen quantum computers on how it is going to impact the encryption algorithms, right? [33:54.120 --> 33:58.020] So those algorithms you can see here itself, ECDSA or RSA, AES. [33:58.020 --> 34:00.340] So obviously this is the HTTP. [34:00.660 --> 34:02.720] And so that's how it's going to impact. [34:02.880 --> 34:15.700] So because the first few milliseconds, if someone can break our connection and they can get back the keys, obviously they are going to decrypt your traffic, whether it's a sensitive or non-sensitive or transactions or whatever is happening. [34:15.880 --> 34:15.960] Okay. [34:16.680 --> 34:32.920] So yeah, obviously like not only at the transit level, even the encryption used at the different layers, because if you select data at rest also, like maybe whether at least server side companies will store your credit card information or like your passwords or whatever. [34:33.080 --> 34:34.560] So obviously those are at the rest. [34:34.740 --> 34:40.860] Even not only in the server side, obviously encryption is required in most of the times if you want to protect something. [34:41.000 --> 34:48.720] So even if it's in the mobile side, if you want to protect any data, so you may use the key store or like any key chains, right? [34:48.880 --> 34:51.700] So on the iOS or Android world. [34:51.840 --> 34:54.520] So they also use encryption to protect the data. [34:54.520 --> 35:02.040] So if quantum computer can break those keys, so obviously anybody can get back your sensitive data. [35:02.220 --> 35:06.380] So even in like, we have seen like in the transit and in the storage. [35:06.560 --> 35:11.420] So even in the authenticity, like authentication as well, cryptography is there. [35:11.540 --> 35:17.400] So everywhere, like most of the times, whenever you want to protect anything, cryptography is the important one. [35:17.400 --> 35:20.600] So quantum computers are going to impact them. [35:20.820 --> 35:24.700] So that's my reason why like obviously it's not now. [35:24.840 --> 35:25.600] So maybe in the future. [35:25.680 --> 35:33.000] So we have to be careful and we have to lay out the plans to protect against the attacks. [35:33.320 --> 35:33.400] Okay. [35:33.860 --> 35:42.920] So, so we have seen so far like few cryptography or like few areas, right? [35:43.000 --> 35:46.640] So what are the strengths and limitations of this current cryptography? [35:46.900 --> 35:50.640] It's so everything is based on computational difficulty. [35:50.640 --> 35:59.480] As we have seen RSA, it's mainly prime factor or as discrete logarithms for the Diffie-Hellman or a few other algorithms, right? [35:59.540 --> 36:01.940] So everything is based on the computational difficulty. [36:01.940 --> 36:09.480] But if someone can break that, obviously we, like our encryption or like our traffic is in the danger. [36:09.620 --> 36:18.920] So it's, it's efficient in classical environments, but limited resistance against the quantum attack. [36:19.080 --> 36:21.620] So next we'll see like quantum computing versus cryptography. [36:21.740 --> 36:29.560] I talked a little bit, but let's see a little bit more in detail, like how quantum computer can break the encryption, any idea? [36:31.980 --> 36:33.400] So we have red reds. [36:33.540 --> 36:36.860] That means at least we have saw few slides, right? [36:36.980 --> 36:40.300] This is just for, this is not in real. [36:40.460 --> 36:43.380] So if you see like, maybe anybody saw this? [36:48.230 --> 36:49.890] It's a XKCD comic. [36:50.230 --> 36:51.090] So it's pretty good one. [36:51.170 --> 37:12.910] So if you see like we are using the 4096 bit RS algorithm key to break your laptop or whatever, but it's not, obviously it's not required super GPU power to break that encryption because you can need, just need a hammer to ask the guy to give back the key so we can easily break it. [37:13.090 --> 37:15.390] So not exactly like this. [37:15.790 --> 37:16.230] Okay. [37:17.010 --> 37:19.970] So how exactly quantum computer can break the encryption? [37:20.210 --> 37:29.650] So it takes the advantage of the, as we talked earlier, like it takes the advantage of the superposition and entanglement when, while doing the calculations, right? [37:29.950 --> 37:32.730] So which classical computer may not do that. [37:32.870 --> 37:34.030] So breaking the encryption. [37:34.270 --> 37:39.550] So the Shor algorithm, as we talked, as we discussed earlier, right? [37:40.710 --> 37:43.070] So it can break in hours itself. [37:43.330 --> 37:54.350] Usually like in the next slide, I kept like how much time typically classical computers need to break a 2048 bit RS algorithm. [37:54.530 --> 37:56.970] It may take 10 to 10 to the power of 20 years. [37:57.130 --> 37:58.390] It's not like 10 to 20 years. [37:58.950 --> 38:00.590] It take like 10 to the power of 20 years. [38:00.590 --> 38:01.410] It's very long. [38:01.690 --> 38:08.950] So and but because of that advantages from the quantum computer, it may take like hours or minutes to break it. [38:09.090 --> 38:18.010] So ECC discrete logarithm also, it's like it's infeasible in the classical time, but quantum time, it may be feasible. [38:19.610 --> 38:37.810] Even like Grover's algorithm, I think I touched a little bit about the Grover algorithm, which can help to speed up the search in the unstructured database, because obviously like in the SHA or like in the hashing or in symmetric encryption, we need the quicker way to search for the results. [38:37.970 --> 38:40.770] So that's where Grover algorithm will help us to. [38:42.150 --> 38:51.790] So suppose attacks on errors, because if it is happening, what will happen is like how attack can happen is like as I think we we touched a little bit like harvest now on decupletor. [38:51.850 --> 39:05.010] Maybe suppose if if you are doing any sensitive transaction between the nations or between the banks, so they can harvest now on decupletor whenever we get the quantum computer. [39:05.150 --> 39:07.770] So that's one long-term confidentiality risk. [39:08.150 --> 39:13.710] Look, as we know, like security is confidentiality, integrity, and authenticity, like availability, right? [39:13.890 --> 39:16.110] So it's going to be like confidentiality risk. [39:16.290 --> 39:27.370] Even for the mobile authentication itself, like forging the digital signature, if quantum computers can break it, so someone can easily bypass your face ID or some other. [39:27.490 --> 39:34.910] Because even though face ID is like, but at the end of the day, on the mobile, they will use different techniques to encrypt the data on the device, right? [39:35.010 --> 39:37.190] So obviously, it's going to be impact there as well. [39:37.330 --> 39:39.570] And it's going to impact the blockchain on crypto. [39:41.990 --> 39:48.190] So this is also like slide, which like I just summarized here, breaking the modern apps. [39:48.290 --> 39:49.770] So what exactly that is condoled. [39:49.850 --> 40:02.510] So next is like, so far, we have seen like maybe 40 minutes and like maybe next 10, 15 minutes, I will try to summarize how we can protect against these attacks, at least in the application security world. [40:02.690 --> 40:06.330] So there are advantages with the quantum computers, which we saw. [40:06.490 --> 40:11.110] So that's good for in another areas, but not for security side, at least. [40:11.550 --> 40:14.470] Okay, but we'll try to protect obviously at the end of the day. [40:14.790 --> 40:16.450] So what is post quantum cryptography? [40:16.650 --> 40:39.150] So we try to like not we means researchers or scientists try to come up with the algorithms or like the techniques which are resistance to the quantum computer test, because the main advantage for the quantum company, which has the state or like superposition and entanglements, right? [40:39.650 --> 40:42.330] Based on that, it tried to calculate. [40:42.510 --> 41:00.470] So to provide, I like to better, to provide better algorithms for that researchers are coming up with the algorithms which are resistant to that, because even though it's tried to calculate in that way, they try to trick it or they try to provide the algorithms which are not vulnerable or which are [41:00.470 --> 41:02.390] not prone to the attacks for them. [41:02.590 --> 41:04.650] So that's the way how they are trying to do that. [41:04.810 --> 41:09.670] So for that, NIST has started this pretty much long, like maybe more than a decade. [41:09.890 --> 41:19.170] So they started asking the researcher or academia people to come up with the algorithms which can protect against the quantum attacks. [41:19.350 --> 41:26.390] So what they did, like they come up with the like researchers or academia people will come up with a lot of submissions like around 80. [41:26.390 --> 41:33.250] Then they try to like, I think they did like two, three rounds of evaluations. [41:33.370 --> 41:36.270] And once they evaluated, they come up with the final list. [41:36.410 --> 41:41.130] So they want to see like any known attacks on those algorithms as well. [41:41.230 --> 41:42.050] So they try to summarize. [41:42.330 --> 41:45.570] I think last year, they come up with the pretty good solid ones. [41:46.270 --> 41:55.430] So when it comes to the, like what exactly researchers has done or like how, whatever the algorithms are like, whatever the techniques they have submitted, right? [41:55.490 --> 42:03.870] At least we can categorize it into the four post-quantum cryptography algorithms like lattice-based, code-based, multivariant, hash-based. [42:04.470 --> 42:08.730] So these are slightly different compared to what we have seen. [42:08.830 --> 42:18.970] Like we, at least in this last 40 minutes, I heavily talked about symmetric, asymmetric, RSA, or DES, or AES, or whatever. [42:19.170 --> 42:20.370] Those are symmetric and asymmetric. [42:20.370 --> 42:30.890] These are slightly different because those are heavily depends on the prime numbers, factorization, logarithms, right? [42:31.110 --> 42:33.330] So, so, but these are slightly different. [42:33.510 --> 42:40.630] If you select lattice-based, it's like, maybe it's kind of like, it's like multi-dimensional. [42:40.630 --> 42:42.050] It's not like two, three dimensions. [42:42.250 --> 42:43.330] So based on the lattices. [42:43.570 --> 42:46.390] So they try to increase the lattices and try to change it. [42:46.550 --> 42:51.910] And they'll try to derive the key from the lattice and try to feed it to the algorithm. [42:52.170 --> 42:56.910] And it will provide the better, uh, resistance against the, uh, quantum computers. [42:57.090 --> 43:05.710] It's, it's not easy for the quantum computers as well to, uh, calculate the key or like guess the key or decrypt the, uh, encrypted data. [43:05.890 --> 43:10.330] So that's how lattice-based, uh, algorithm will try to protect. [43:10.470 --> 43:12.830] So even code-based, it's, it's slightly like error. [43:13.110 --> 43:20.850] Like code-based, like sometimes if I remember correctly, it's kind of like error-based, um, uh, algorithm, which try to protect even hash-based. [43:20.990 --> 43:24.130] So hashing is, as most of the people, it's, it's similar to that. [43:24.270 --> 43:25.230] It's maybe slightly different. [43:25.610 --> 43:32.910] Uh, hash-based is like, it's like one-way, uh, uh, uh, function, which converts the, uh, message to the fixed length, right? [43:33.010 --> 43:36.950] So similar to that hash-based algorithms, they trend, they come up with that. [43:37.170 --> 43:42.790] So at least the leading algorithms will be like crystals, kyber, uh, and crystal-t-lithium. [43:42.950 --> 43:50.430] So these are the two, uh, uh, types of, uh, leading algorithms, which are, uh, uh, research are proposing. [43:50.890 --> 44:00.730] So what, like, okay, researchers are coming up with the pretty good algorithms and everyone is, um, excited about to move on to that and try to protect agrariness. [44:01.010 --> 44:04.610] Maybe in the next five to ten years, we have the, uh, path, right? [44:04.750 --> 44:15.790] So how, how, like, what, what are the major challenges or like, how applications can easily, like, let me ask, we can, your application easily move on to the new algorithm? [44:15.990 --> 44:16.490] I don't think so. [44:16.630 --> 44:34.390] Like, most of the applications currently, uh, easily can be converted into another, um, algorithm, because we have seen, like, if you see, like, maybe 10, 15 years back, Oracle Poodle attack, whenever it come up again as SSL v3 or like, maybe TLS 1.0 or few algorithms. [44:35.050 --> 44:45.230] So it became very tough to move out of that SSL v3 protocol itself, like it, because there are legacy systems, which are pretty much depends on that. [44:45.350 --> 45:01.290] So if you see, like, if, if we have, like, just move on from just one version of, uh, SSL or TLS becoming a little bit challenging, but if you want to move on from entire suite of algorithms to the new suite of algorithms, algorithms, it's not easy because we have to, [45:01.470 --> 45:15.890] like, we have legacy systems, we have fresh systems, and we have to make integration in such a way where systems won't break, because as you have seen, like, entire, most of the, uh, most of the connections are depends on the HTTPS, right? [45:15.890 --> 45:17.430] whatever we are doing in nowadays online. [45:17.610 --> 45:21.630] So obviously it's not easy to, uh, change for move forward. [45:21.790 --> 45:21.890] Okay. [45:22.430 --> 45:38.210] So, yeah, what even federal is mandating that even banking systems are planning for that even a lot of I would like it's people are trying, but yeah, it's not easy to, um, the future safeguarding data in a quantum. [45:38.330 --> 45:41.470] So though, how we can protect the data and for the future. [45:41.490 --> 45:45.130] So we need to bring the awareness to the, in the organization. [45:45.130 --> 45:59.410] So if you see, like, maybe whether it's SRE or devops or like server side system administrator or whoever, because as a security person, we interact in a day like in different departments, if you see, like, even though nowadays departments are shrinking up, [45:59.790 --> 46:11.710] maybe SRE or devops may be doing the most of the stuff, but still administrative tasks, we need to teach them or like, we need to, uh, engage them or like, we need to keep on pushing them. [46:11.710 --> 46:18.610] So this is happening maybe in five or 10 years to, we, we, we need a proper, um, roadmap for that. [46:18.730 --> 46:24.730] And we need the collaboration with the, um, like government or industry or academy or people. [46:24.930 --> 46:28.230] So to see like, how exactly, what exactly new things are coming up. [46:28.650 --> 46:38.490] And we, we need a lay, we need to lay down a, maybe seven to 10 years plan to see like, obviously it's not easy to, uh, get it. [46:39.070 --> 46:53.390] So, so these are the, like, I think I touched a little bit about the post-mountain cryptography, a little bit, what are the different algorithms and how, uh, how they can provide the resistance against the, uh, quantum computers. [46:53.750 --> 46:58.730] So if you see like lattice base, it has a high dimensional as, as it's kind of a lattice, which has high dimensional. [46:58.910 --> 47:00.070] It's not like three, four dimensions. [47:00.230 --> 47:09.790] We can use larger dimensions as well to, uh, do the calculations, which are prone, like, which are, uh, resistant against the, uh, quantum computer. [47:09.950 --> 47:12.930] So next is like, hash based or code based or multivariant. [47:13.130 --> 47:17.590] So these are the different, uh, post quantum, uh, cryptography algorithms. [47:18.030 --> 47:20.250] So quantum safe migration strategy. [47:20.250 --> 47:25.550] So maybe obviously we need a strategy because it's not like just a one year, two year plan. [47:25.670 --> 47:31.010] We need like maybe five to 10 years plan and try to, uh, first cryptography, uh, inventory. [47:31.190 --> 47:41.490] Like we will try to, in, in our organizations, obviously there are several servers or systems which are very old, maybe mine frame, or maybe even a few other servers which are very old, right? [47:41.550 --> 47:44.270] So we need the inventories where the cryptography is touching. [47:44.450 --> 47:53.370] So maybe just for not only for communication between the browser and server, maybe internal communications will be there even for the storing the passwords on few other areas. [47:53.510 --> 47:55.290] So we need the inventory of that. [47:55.290 --> 47:57.310] So if we can get that, that that would be great. [47:57.330 --> 48:15.010] And we have to evaluate the, uh, risk assessment, how, how exactly it's going to be impacted if, if, um, if, uh, the encryption is going to be breaking like next five to 10 years, what kind of mission critical applications are like crown jewels usually people call it. [48:15.130 --> 48:18.590] So those kind of applications are those kind of data, how we can product it. [48:18.970 --> 48:30.330] And we need to come up with kind of a, come up with, uh, kind of algorithms, uh, or else like maybe if you want to implement any kind of a, uh, system or something. [48:30.510 --> 48:36.290] So what you can do like crypto agility, uh, frameworks, kind of something like that, uh, we can come up. [48:36.370 --> 48:39.090] So where we can do is like, you can just plug and play kind of stuff. [48:39.250 --> 48:47.850] Like instead of just, uh, completely depending on, uh, like developing in the application, we, it's, it's easy to switch the crypto. [48:48.010 --> 48:53.170] You can just change the word from RSA to maybe if it is, uh, some other algorithm. [48:53.390 --> 48:55.290] So you could just switch the easily. [48:55.430 --> 49:01.190] It's not, we should not be like, um, very, uh, resistance to the change. [49:01.370 --> 49:14.890] So we, we had to come up with the kind of a algorithms or again, such a applications, which are, um, uh, useful for the quick changes like crypto agility changes or like maybe hybrid approach. [49:15.030 --> 49:20.990] Uh, maybe you can use like both like hybrid approach, like deploy classical plus post quantum algorithms together. [49:21.150 --> 49:27.670] If you want to switch, so just drop the classical algorithms and just try to use the post quantum algorithms itself. [49:27.870 --> 49:29.150] So that's another one. [49:29.530 --> 49:31.430] So we have seen few challenges. [49:31.430 --> 49:42.130] So I try to summarize what kind of challenges mostly like, uh, performance impact is going to be huge because sometimes, uh, post quantum cryptography keys may be a little bit longer. [49:42.130 --> 49:47.790] Sometimes they may require, uh, they may require like kind of KB kilobytes of keys. [49:47.990 --> 50:01.130] So that's a little bit challenging to maintain and, uh, uh, do the signatures and exchange between the, because if you see like usually the key will be like very small, like 2056 or something, but if you need like kilobytes and more than that, it's a bit, [50:01.130 --> 50:02.470] uh, complicated. [50:02.790 --> 50:10.630] So even integrity, uh, integration complexity also there, even standards also need to be verified thoroughly. [50:11.050 --> 50:25.810] And, uh, like obviously once they come up, obviously like, uh, in any cryptography or like in a, um, encryption algorithms, only the key should be secure, but we, we, we have to see like whether the algorithms are going to provide the better security or not, [50:25.950 --> 50:31.310] because if algorithm itself has any weakness, so the key won't protect the, uh, uh, data. [50:32.290 --> 50:40.670] So the action plan for AppSec teams, like maybe any, uh, security team mostly is like, uh, educate your organization. [50:40.670 --> 50:51.670] So try to keep on telling the words, like what exactly coming up and how security team or like maybe administrative teams can, uh, plan accordingly. [50:51.670 --> 50:57.510] And if they keep on listening to something, so at least they can, okay, something coming up, we should be careful, something like that. [50:58.630 --> 51:00.150] Update the security requirements. [51:01.550 --> 51:10.530] Maybe if we have any security strategy or plans, we can try to upgrade the requirements to include the, uh, post-quantum cryptography as well. [51:10.590 --> 51:10.690] Okay. [51:10.870 --> 51:18.730] Even on top of that, if you are evaluating any vendors, you can keep on asking the vendors, what is your plan for post-quantum cryptography? [51:19.650 --> 51:20.410] What will happen? [51:20.550 --> 51:24.170] Like, what are your plans for your cryptography standards in the next five to ten years? [51:24.210 --> 51:27.030] You can ask the questions to the your vendors as well. [51:27.670 --> 51:36.830] Uh, maybe you can engage with the standard bodies and, uh, next one is like, it's kind of like quick checklist. [51:36.830 --> 51:42.250] I just come up with like, um, maybe just try to summarize, uh, everything, whatever we have done. [51:43.130 --> 51:59.130] So awareness and education, that's important because as you know, like if you are into security or also you could have seen like RSA, ECC and, but maybe if people are not into security, they may not know that's on what, how exactly quanta computers going to impact the, uh, the security of the connection.uh, the security of the connection. [52:02.590 --> 52:08.570] So that's, we need to, we need to provide the better awareness and dedications to the, uh, other teams. [52:09.010 --> 52:09.090] Okay. [52:09.490 --> 52:16.190] Cryptography inventory, if you can come up with like all of your inventory in your organization or like, uh, that would be great. [52:16.370 --> 52:24.470] So then it's easy for the, uh, whenever we need to change it, it's, it's going to be easy to find the, uh, important assets and try to change it. [52:24.850 --> 52:30.430] And if you know the key sizes, algorithms, what exactly they're using and what kind of certificate type. [52:30.530 --> 52:31.450] So that's also helpful. [52:32.050 --> 52:35.910] And the, the most important one part will be the risk assessment. [52:36.190 --> 52:40.410] So which are your mission critical applications, how you want to protect it. [52:40.670 --> 52:46.830] So the migration plan, once we have everything, we'll try to do the migration plan and what happens and we'll, we need to do the migration plan. [52:47.210 --> 52:51.630] Definitely required years of efforts to move from one algorithm to another. [52:52.210 --> 52:53.090] It's not easy task. [52:54.030 --> 52:56.590] I think, uh, yep, we're almost done. [52:57.570 --> 52:57.870] Yeah. [52:58.150 --> 52:58.490] Thank you. [53:14.800 --> 53:16.020] Do you want to jump in? [53:16.940 --> 53:26.760] So, so one question then, if, what's the first steps that you'd recommend an organization taking today? [53:27.220 --> 53:37.900] And another way of saying that is like, I think a lot of the things are like, well, you know, make sure you can use larger key sizes, tell all your developers, they should be ready to switch anytime or in five or 10 years. [53:38.820 --> 53:41.100] And a lot of developers are like product managers. [53:41.120 --> 53:49.420] If I go to them and say like, every time we're building something that touches cryptography, you need to make it ready to switch at some point with something that's in draft status. [53:49.540 --> 53:51.240] They're going to say, you're not going to need that. [53:51.440 --> 53:53.840] I can't justify putting that in my product cycle. [53:53.840 --> 53:55.440] And I think people come back to me when it's real. [53:56.260 --> 53:59.680] What should people be doing as like very first step? [53:59.840 --> 54:02.660] And maybe even a better way of asking that is like, so you're at Adobe, right? [54:03.300 --> 54:16.680] Like, what are the first things that you've done at Adobe to proof for post quantum future, like have been practically able to get into the development pipeline and security actionability pipeline to like move forward on this? [54:16.780 --> 54:22.200] Because like, it's really hard to just say like, I'm going to educate my entire organization on post quantum crypto. [54:22.820 --> 54:24.980] And they're like, this seems so far away. [54:25.180 --> 54:29.060] I can't, I need to focus on my challenges today, not in 10 years. [54:29.660 --> 54:29.860] Yeah. [54:30.880 --> 54:31.560] I'll come here. [54:31.820 --> 54:32.180] Yeah, definitely. [54:32.460 --> 54:42.960] It's, it's not easy to ask because yeah, as you mentioned, like product team and everyone, obviously they lost, like we have a lot of sprints, like we have a lot of features, which we want to focus. [54:43.100 --> 54:58.820] We don't want to focus for the next five or 10 years, but um, yeah, it's definitely, it's a challenging to convince them, but, um, maybe if they can come up with like, what kind of assets are like, uh, inventory they are currently using, we can keep it as a side and keep on updating, [54:59.620 --> 55:00.860] uh, whenever they changes. [55:01.000 --> 55:05.120] Because if you see like, obviously with the AI, everything is changing very fast. [55:05.360 --> 55:09.200] We, we don't know what will happen in, whether the product still exists or don't exist. [55:09.200 --> 55:09.900] We never know. [55:10.200 --> 55:19.680] So, but still like, if you see like, it's a big organization, it's better to, uh, uh, communicate with all the teams and try to come up with the, like, what kind of algorithms they can see. [55:19.840 --> 55:32.840] If the directly product team is not providing, maybe you can check in the logs or like few other areas where the product, the connections are like, the major traffic is coming up and what kind of connections are going on and out. [55:33.020 --> 55:33.720] So that may help. [55:34.900 --> 55:36.940] Hey, we got a combo question from the chat. [55:37.140 --> 55:39.640] Um, is the goal to have widespread adoption? [55:39.960 --> 55:47.180] And if so, in regards to momentum, uh, would there be any problem with widespread adoption? [55:47.680 --> 55:51.980] And, and will momentum, will momentum be a problem like in terms of a roadblock? [55:52.400 --> 55:54.840] Example, um, imperial versus metric? [55:55.920 --> 55:57.420] Uh, no, I missed the question. [55:57.540 --> 55:57.840] Can I, can I? [55:58.580 --> 56:01.940] Uh, so will, is the goal to have widespread adoption? [56:02.340 --> 56:07.580] And will momentum be a problem with widespread adoption in terms of- Gold hack? [56:37.960 --> 56:42.640] Goal Because it has dependency on the several. [56:42.900 --> 56:46.720] Because if you break the connection, so obviously it's going to impact everyone. [56:46.840 --> 56:57.500] So we need to do kind of proper validations in the earlier stages itself instead of just... It is just not like switching the gates from one gate to another gate. [56:57.580 --> 57:04.480] Obviously we need several time to validate properly and test it whether it's going to impact how many customers. [57:04.640 --> 57:08.640] Because if we have very old legacy systems, so it's not that much easy to... switch back. [57:09.380 --> 57:13.260] Whenever like, okay, like if you see like next year, like now we have like another four months. [57:13.420 --> 57:16.280] Maybe from January onwards, if you want to change it, it's not easy. [57:16.380 --> 57:21.860] Like if someone comes up and says like, okay, from January onwards, we are not using AES or RSA. [57:22.020 --> 57:25.560] So it's not easy to just go ahead and do that. [57:25.620 --> 57:29.240] So we had to do several evaluations and risk assessments. [57:32.160 --> 57:33.240] Thank you for your talk. [57:33.860 --> 57:38.740] Some of us in this room believe that the NSA has influence over NIST. [57:39.340 --> 57:50.740] And that the timeline for NIST adoption of standards will be manipulated so that NSA has ample opportunity for harvest now decrypt later before the standard is adopted. [57:51.240 --> 58:17.380] So it would seem to make sense for people who are working in this field to, even before a NIST standard is adopted, set up a hybrid system that combines one layer of classical encryption, plus several layers of immature quantum-resistant encryption. [58:18.120 --> 58:23.180] So I was wondering what you would think is the best way to do that in detail. [58:23.180 --> 58:36.920] And also, I want to ask, are your concerns about quantum encryption completely transferable to the risk that somebody might develop an efficient algorithm for all NP-complete problems? [58:39.980 --> 58:50.440] It depends, because if you see like, usually like, at least in the encryption world, right, so whatever the algorithm researchers are coming up, right, they will post the algorithm outside. [58:50.580 --> 58:54.300] It's like, it's not like their secrets are, so only the secret is the key. [58:54.300 --> 59:03.960] So obviously, if the algorithm is outside, so anybody can see, like, it's not like, we can feed the back door into that and nobody can find it. [59:04.060 --> 59:15.360] Because if the algorithm and the code is outside, it's not easy to, like, it's not like any organization can force it, like they can do kind of a back door, but we never know. [59:15.480 --> 59:18.100] So obviously that's, yeah, it depends. [59:23.820 --> 59:24.600] Talk. [59:24.600 --> 59:25.620] Thank you.