SafeQuard: A suite of quantum-safe cryptographic tools to defend against harvest-now-decrypt-later attacks.
The Internet is the de-facto medium for many enterprises to carry out their business functions. By relying on public-key encryption to ensure confidentiality and authenticity of data, their employees and customers are able to use a variety of public channels via web browsers, emails and mobile apps to send and receive sensitive information.
However, this promise of confidentiality and authenticity is no longer possible with the advent of quantum computers. An attacker can collect the encrypted communications happening between the customers and financial institutions today (“harvest-now”), and use a quantum computer to decrypt the communications sometime in the near future (“decrypt-later”).
We expect sensitive data such as authentication credentials (passwords, biometric minutiae, authentication keys), transaction details (payee, account numbers, transaction values), emails (secret documents, customer agreements, product designs, financial reports) and customer information to be targeted by such attacks.
Use Cases
Identity credentials
In order to ascertain the identity of users connecting remotely to the transaction website, users will be asked to provide credentials in the form of secret passwords, facial/fingerprint or some biometric data, card PINs or answer personal questions which are private to the users. Biometric data and highly personalized information are unique to each user and if such information is harvested and decrypted by attackers, this will result in dire consequences for the users, the financial institutions involved, and even the industry at large since this effectively amounts to a system-wide “identity theft”. SafeQuard can be used to encrypt the identity / authentication credentials provided by the users, for safe transmission to the organization’s website.
Transaction data
Customers may effect purchases over the internet where payment information, such as credit card details, account numbers, payee name and addresses, are entered in the browser. Such information, if harvested and subsequently revealed, may allow the attacker to carry out fraudulent activities or blackmail the customer/organization. SafeQuard can be similarly used to encrypt payment information to ensure that the details cannot be revealed to attackers in the future.
Emails
SafeQuard encrypted email carries out enterprise-grade quantum-safe encryption on emails. It operates on both Microsoft365 (as an add-in) and Gmail (as a Chrome extension). Features include:
- Interoperable between Office365 and Gmail
- Automatic key management, no need for any key exchange or shared passwords between communicating parties
- End-to-end encryption NIST FIPS 203 PQC algorithm (MLKEM) to ensure long-term safety.
Online messaging
The online chat functionality on the Internet is convenient for customers to reach out to the enterprise for specific help. These could include problems relating to the account or specific transaction, or it could even be highly sensitive situations where fraud or whistleblowing is reported. Such chat messages should be end-to-end encrypted using SafeQuard to prevent hackers from exploiting such information
Windows CNG
pQCee’s crypto-agile Microsoft Windows CNG provider enables enterprises, governments, and regulated industries to adopt the latest post-quantum algorithms, meet national requirements, and integrate with advanced quantum hardware. More specifically, the solution enables seamless integration of customized algorithms and implementations into the Windows platform, including:
• Other NIST post-quantum algorithms such as XMSS and LMS
• Hybrid combinations of classical and post-quantum algorithms
• Country-specific post-quantum standards (e.g., Malaysia’s MySEAL, South Korea’s KpqC, China’s NGCC)
• Certified implementations under frameworks such as Common Criteria EAL and FIPS140 CMVP
• Hardware integrations with smartcards, USB tokens, HSMs, and TEEs
• Quantum technologies such as Quantum Random Number Generators (QRNG) and Quantum Key Distribution (QKD)
SafeQuard resources
Try it for yourself
Stop Harvest-now-decrypt-later threats today.