3 min

Alternatives to Quantum Cryptography

A new specialist book compares physical methods of data encryption and finds: Quantum cryptography is often not the best choice

Data security is becoming increasingly important in an ever more digitalised and interconnected world. Whether it be research data, medical information, or strategically important corporate and government data: The protection of sensitive information is a key prerequisite for modern communication and digital processes. Quantum cryptography (Quantum Key Distribution – QKD) is a frequently cited technique for encrypting data, in which great hopes for the future are placed and which is widely reported on. However, a newly published book based on a scientific study by two researchers of USTP – University of Applied Sciences examines, for the first time, various physical methods of data encryption in a comprehensive comparison and demonstrates: The much-discussed quantum cryptography is not the most sensible or cost-effective solution in many use cases.

With their book “Data Encryption at the Intersection of Mathematics and Physics – Comparing Physical Methods of Cryptography”, Ernst Piller and  Hubert Schölnast of USTP’s Institute of IT Security Research have issued a comprehensive and technology-neutral overview of physical methods of cryptography. The book has been published by Springer Nature and, for the first time, compares five different technologies in the field of physical cryptography in a scientifically sound, practice-oriented, and easily understandable manner.

The book focuses on the question of which technology is suitable for which purpose and what costs, assumptions, and risks are associated with it.

Computing Power as the Achilles’ Heel of Quantum Cryptography

The cryptographic methods widely used today are based on mathematical problems that attackers must solve in order to decrypt the data. While this is not possible with current computing power, things could change in the future. Furthermore, attackers may be aware of new, as yet unpublished methods for solving these mathematical problems.

Physical methods take a different approach: They utilise properties of physics to generate and distribute cryptographic keys. The book provides a technology-neutral, easily understandable, and scientifically sound comparison of five different technologies in physical cryptography. Among other things, Ernst Piller and Hubert Schölnast analysed quantum cryptography, radio signal-based key distribution, and memory key distribution. Criteria such as key rates, ranges, robustness, implementation effort, and costs are evaluated.

“Many discussions about quantum cryptography focus on theoretical security. In practice, however, costs, maintenance requirements, scalability, and specific use cases must also be taken into account. Our book provides, for the first time, a scientifically sound and technology-neutral basis for comparison,” explains author Ernst Piller.

Technical Challenges and High Costs

The analyses show that quantum cryptography involves technical challenges and high costs. Furthermore, attacks via indirect means – so-called side-channel attacks – are possible. According to Ernst Piller, attackers always exploit the weakest link in the security chain: “It’s like putting a great lock on your bike, but the chain is thin and weak. There are high hopes for quantum cryptography, and references to Einstein and Heisenberg are often cited. Unfortunately, however, quantum cryptography is of little practical use.”

At the same time, there are alternative methods which, in many fields of application, enable comparable levels of security at significantly lower cost. According to the authors, Memory Key Distribution in particular has the potential to securely transfer large quantities of key material, thereby enabling the use of a method that is provably 100 percent secure. This refers to the transport and storage of cryptographic keys using secure media such as smart cards or specialised portable storage devices.

The book is aimed at decision-makers in business, public administration, and politics who need to evaluate and select security solutions. “Rather than presenting any one technology as superior, it provides a sound basis for decision-making when selecting suitable cryptographic methods,” says Piller.

Book “Data Encryption at the Intersection of Mathematics and Physics – Comparing Physical Methods of Cryptography”

The book “Data Encryption at the Intersection of Mathematics and Physics – Comparing Physical Methods of Cryptography” has been published by Springer Nature and is also available free of charge in an open-access version. It presents the results of the ‘Kryptovergleich’ project which was funded by the Federal Ministry of Finance (BMF) as part of the KIRAS/K-Pass security research funding programme run by the Austrian Research Promotion Agency (FFG). The book, along with additional information forming an appendix to the book, is available on the Institute’s website at www.cryptography.study/phys.

Link to the book at Springer

Researchproject Quantum Cryptography

 

You want to know more? Just ask!
Mag. Hammer Mark

Mag. Mark Hammer

Section Head Press
FH-Prof. Univ.-Doz. Dipl.-Ing. Dr. Piller Ernst

FH-Prof. Univ.-Doz. Dipl.-Ing. Dr. Ernst Piller

Lecturer Department of Computer Science and Security
Dipl.-Ing. Schölnast Hubert, BSc

Dipl.-Ing. Hubert Schölnast , BSc

Junior Researcher Institute of IT Security Research Department of Computer Science and Security