Special Features

Cybersecurity Month

Crypto-apocalypse soon? Chinese researchers find a potential quantum attack on classical encryption

With an off-the-shelf D-Wave machine, but only against very short keys


Chinese researchers claim they have found a way to use D-Wave's quantum annealing systems to develop a promising attack on classical encryption.

Outlined in a paper [PDF] titled "Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage", published in the late September edition of Chinese Journal of Computers, the researchers assert that D-Wave’s machines can optimize problem-solving in ways that make it possible to devise an attack on public key cryptography.

The peer-reviewed paper opens with an English-language abstract but most of the text is in Chinese, so we used machine translation and referred to the South China Morning Post report on the paper – their Mandarin may be better than Google's ability to translate deeply technical text.

Between the Post, the English summary, and Google, The Reg understands the research team, led by Wang Chao from Shanghai University, used a D-Wave machine to attack Substitution-Permutation Network (SPN) structured algorithms that perform a series of mathematical operations to encrypt info. SPN techniques are at the heart of the Advanced Encryption Standard (AES) – one of the most widely used encryption standards.

The tech targeted in the attack include the Present and Rectangle algorithms, and the Gift-64 block cipher, and per the Post produced results that the authors presented as “the first time that a real quantum computer has posed a real and substantial threat to multiple full-scale SPN structured algorithms in use today.”

But the techniques used were applied to a 22-bit key. In the real world, longer keys are the norm and they'll be harder to discern.

The researchers argue that the approach they developed can be applied to other public-key and symmetric cryptographic systems.

The exact method outlined in the report does remain elusive, and the authors declined to speak with the Post due to the implications of their work.

But the mere fact that an off-the-shelf one quantum system has been used to develop a viable angle of attack on classical encryption will advance debate about the need to revisit the way data is protected.

It’s already widely assumed that quantum computers will one day possess the power to easily decrypt data enciphered with today’s tech, although opinion varies on when it will happen.

Adi Shamir – the cryptographer whose surname is the S in RSA – has predicted such events won’t happen for another 30 years despite researchers, including those from China, periodically making great strides.

Other entities, like Singapore’s central bank have warned that the risk will materialize in the next ten years.

Vendors, meanwhile, are already introducing “quantum safe” encryption that can apparently survive future attacks.

That approach may not be effective if, as alleged, China is stealing data now to decrypt it once quantum computers can do the job.

Or perhaps no nation needs quantum decryption, given Microsoft’s confession that it exposed a golden cryptographic key in a data dump caused by a software crash, leading a Chinese crew to obtain it and put it to work peering into US government emails. ®

Send us news
23 Comments

Trump administration wants to go on cyber offensive against China

The US has never attacked Chinese critical infrastructure before, right?

Blue Yonder ransomware termites claim credit

Also: Mystery US firm compromised by Chinese hackers for months; Safe links that aren't; Polish spy boss arrested, and more

China gorging on silicon before Uncle Sam slams the door

Chip imports up more than 14% this year in anticipation of fresh restrictions

China preps another rocket that Beijing hopes will become its workhorse

Long March-8A improves payload by forty percent and comes just a month after Long March 12 debut

China's homebrew Bluetooth alternative is on the march as Beijing pushes universal remotes

'Star Flash' is said to include 5G tech and leave rival wireless protocols struggling in the crack of a sofa

US reportedly mulls TP-Link router ban over national security risk

It could end up like Huawei -Trump's gonna get ya, get ya, get ya

How Chinese insiders are stealing data scooped up by President Xi's national surveillance system

'It's a double-edged sword,' security researchers tell The Reg

Supreme Court to hear TikTok's appeal against law that would force it to shut, or sell

Will consider free speech arguments just nine days before the clock runs out

Severity of the risk facing the UK is widely underestimated, NCSC annual review warns

National cyber emergencies increased threefold this year

China strikes back with Nvidia antitrust probe as US tightens tech chokehold

Beijing cites GPU giant's Mellanox merger conditions from four years ago

How Androxgh0st rose from Mozi's ashes to become 'most prevalent malware'

Botnet's operators 'driven by similar interests as that of the Chinese state'

UK ICO not happy with Google's plans to allow device fingerprinting

Also, Ascension notifies 5.6M victims, Krispy Kreme bandits come forward, LockBit 4.0 released, and more