Microsoft tests post-quantum interoperability- SiliconANGLE

AI Staff Writer

Transforming Post-Quantum Readiness through Collaboration

As the transition to post-quantum security moves from planning to implementation, ensuring interoperability extends beyond the efficacy of individual algorithms. With testing now critical, it serves as the bridge connecting technical standards to deployable protections. Microsoft Corp. is actively involving certificate authorities in this essential process, emphasizing that readiness should align with operational needs, according to Karina Sirota Goodley, Microsoft’s senior security product manager.

Goodley articulated Microsoft’s approach, stating, “Our focus is not merely to develop a cryptographically interesting solution and subsequently seek a viable use case. Instead, we prioritize real-world customer and business challenges, aiming to understand operational constraints and create solutions that function seamlessly across platforms, protocols, certificate authorities, devices, and existing infrastructures. In the journey towards post-quantum adoption, practical interoperability and measurable risk mitigation take precedence over merely achieving cryptographic novelty.”

In a discussion at DigiCert Inc.’s World Quantum Readiness Day, Goodley spoke with Lakshmi Hanspal, the chief trust officer at DigiCert. Their conversation highlighted Microsoft’s collaborative testing initiatives with certificate authorities, including DigiCert. The emphasis was on the role of suppliers in facilitating a smooth migration to post-quantum cryptography.

Initiating Controlled Testing for Post-Quantum Interoperability

Microsoft’s Trusted Root Program is currently conducting a post-quantum cryptography pilot aimed at Transport Layer Security (TLS) outside production and public trust environments. The initiative includes seven participating certificate authorities, with DigiCert as a key player. Goodley noted that this pilot allows certificate authorities to assess issuance and compatibility within the confines of the Microsoft platform, a crucial step in ensuring the entire cryptographic chain functions effectively.

Goodley emphasized the importance of recognizing vendor dependencies as part of the readiness program, rather than viewing them as challenges to be tackled later. Early coordination can uncover compatibility issues and deployment limitations, she stated. Her advice to industry players is clear: “Address post-quantum cryptography (PQC) migration as a priority before it becomes an issue for your customers. Delivering crypto agility, transparency, and standards-based interoperability should be the norm, so customers aren’t required to become cryptography experts to navigate the quantum transition.”

If the industry can simplify processes and unify on interoperable implementations, it can significantly accelerate readiness for the quantum era, surpassing the advancements any single organization could achieve independently.

[gspeech type=full]

Share This Article
Leave a comment