mnemonic security podcast

Proofing for Quantum

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 27:49

In this episode, we’ll explore what quantum computing might mean for the world of security in the future, and the concrete measures the banking sector is taking to prepare for it.

Robby is joined by Ulf Larsson, Security CTO at the SEB Group, a leading financial services group in the Nordics, to discuss the work he’s been doing on the potential impact quantum computing will have on his sector, what it can do with our ability to protect data, and preparing his bank to be quantum safe by 2030.

They discuss the concrete tasks security teams have in front of them already now, how banks are working together to secure the financial eco-system, and the ongoing development within this field by tech companies and consultancies. 

Send us Fan Mail

Speaker

From my headquarters in Oslo Norway, and on behalf of our host Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

By now we know that a quantum computer is fast, expensive, and a few years away from breaking our current implementations of encryption. Apparently, some scientists also believe that quantum computers open a portal to an extra time dimension, but I'll leave that for another episode someday. Regardless of which dimension quantum takes us to in the future, the security team has a concrete task to complete here in the now. Classify the crypto in use, assess its risk and where it's deployed, and build a plan to migrate to so-called quantum-safe algorithms. Today's guest makes it sound simple and problem-free. And here are some of his thoughts on how you can make that a reality in your own environment. Ulf Larsson, welcome to the podcast.

Ulf Larsson

Thank you so much, and thank you for having me. It's a great pleasure being here.

Robby Peralta

We have the honor of seeing you on stage here soon at the uh the mnemonic C2 Summit. Yeah. Where you will be our quantum guy.

Ulf Larsson

That's correct. There's a lot of stuff to go through, but we have done some uh really good job the last uh year and a half.

Robby Peralta

That's good to hear because uh everybody's heard of quantum before, but you've actually done a project, you've actually done things about it. It's it's so it's not so it's more tangible now.

Ulf Larsson

It is, and and I think we need to differentiate. We have one part that is talking about quantum computing, the processing large data sets uh to predict uh trends, etc. etc. And then we have the other ones uh the team that worries more about what can a quantum computer potentially do with the existing ability to protect data, and I mean the latter one, like preparing the bank for for uh being quantum safe, so to say. Quantum safe, yeah.

Robby Peralta

Because you you because you are the security CTO of SCB, yeah, uh, like corporate banking, investment banking. So I'm pretty sure there's a lot of people in SCB that are interested in quantum for other reasons, but you're interested in the protecting the bank from quantum, I guess.

Ulf Larsson

That's my part. Uh we took a decision it's a little bit more than a year ago that let's at least start to understand the uh transformation we need to do to continue to protect our data and also digital identities. So these are the two groups that we we focus on to be um quantum safe.

Robby Peralta

Cool. Uh to be quantum safe. I know it's a very ignorant question, but what is so important about the data that needs to be protected?

Ulf Larsson

First and foremost, uh it's it's our data. It's you as a customer, it's me as a customer, it's our position, it's our holdings, uh, a lot of uh privacy data associated my account and and uh uh the type of uh transaction I perform, etc. etc. And that that scales throughout all the uh customer segments, a normal user as I am to uh uh high-scale uh enterprises. So the data is both a regulatory aspect, we need to prove and report that we have data in order, so to say. And to be able to do that, we need to take a step back and look at requirements for us to protect the data by encryption. We log uh activities, we we monitor deviations, um, we have a strict control over who have access to data and so forth. So it's very much based on the compliance aspect, both from regulators and our internal need to fulfill, we are in a good shape to protect the data.

Robby Peralta

I can see the sensitivity of what I'm buying and how much money I have in my account and stuff, but there there is more at play than just that, right? Like if you were to actually you you played onto um like not being able to trust the data. Like if uh if I could just give myself a bunch of money, that'd be horrible for you, but great for me. But I guess there's uh there's a lot more to it than people I guess would think for protecting the data.

Ulf Larsson

Yeah, then and exactly, because every transaction, how are we sure that Robby is Robby and Robby will send money to uh Ulf uh and that is an okay transaction, or if it's not an okay transaction, because suddenly you are in another country. So someone has hijacked your credentials and and uh managed to log into your account, etc., etc. We have protection for that as well, the uh trust of who is logging on uh to what account, etc. So exactly that there's so many dimensions of accessing the data, changing the data, create new data, analyze the data, and so forth that we need to have control over.

Robby Peralta

So this isn't like new for you, all this protecting this data. They have a group security CTO, so obviously you have their stuff in order. But I guess my question is what is the difference with quantum computing and all the processes you have now? I'm thinking of like encrypting data at rest, data in flight. You probably have all that in place, and the quantum aspect just makes all of that obsolete, or like do you have to build everything all over again, or is it just like parts?

Ulf Larsson

No, I think it's it's important to understand first and foremost, how do we protect data today? And we look at data at rest uh in our storage, data that we move or transform that can be a domestic or cross-border payment, for example. So if we start with that, we we look at okay, Robby, what is the the methodology uh to protect that, uh encryption methodology to encrypt that? So there is a certain standard for doing that, all right. The good. So there is a a uh uh different methodology for data at rest and and uh data in transit. And we know that these are you can see them as having different strengths, right? So if you classify the data and say that it it can be medium sensitive or highly sensitive, we have this uh confidentiality, integrity, and availability one-to-four rating, and that drives also the uh non-functional requirements. But uh, to avoid to be too boring about this, we need to understand this is how we protect data today when we store and move it. If there is a quantum computer, almost like the a nation state threat actor who gets an understanding of running a quantum computer that can decrypt it methodology that that is in use, that would be a bad situation to be in, right? Yeah, absolutely. So actually, there are three proven uh algorithms now posted by NIST. So these one we we can start to test, but you know, we cannot necessarily be be uh nervous about oh, we need to apply and test and validate this. If if we take a step back again and look at okay, so we we know the scope is data address, data in motion, and digital identities. Good. So where do we have this, right? So we need to look at the IT asset involved, and then we realize oh, that is too much, we cannot fix everything. So we we need to have a little bit of of uh thinking and and uh make a a risk evaluation, which are the first ones. Yeah, yeah, yeah, exactly. So you can start to group them. So that is basically the the approach that we have taken uh the uh so far.

Robby Peralta

Yeah, so interesting. Uh I would assume that so data classification, uh that's been a thing for a long time, right? Like what's important, where's it at? You were probably in a good position due to GDPR and other billions of requirements you have, right? So that part was kind of was that done already, or did you have to revisit that project with the new lens?

Ulf Larsson

See, many of these um uh uh data that has GDPR and data privacy attributes, we constantly need to uh re-evaluate. But if we make it super simple, to achieve a quantum safe uh position, it is very much a lifecycle management and planning effort that we we know the scope, we have made a risk evaluation, and these are the IT stuff we need to uh lifecycle from a non-quantum safe methodology to protect data to a quantum safe. Yeah.

Robby Peralta

Well, that's great. It doesn't sound too complex when you say it like that.

Ulf Larsson

I mean, you can either have a problematic approach to life and say it would be a very hard day today, Robby. And you you you haven't even started. Or you can say, you know, it would be a great day. And I uh I mean if we have this pragmatic approach, as we have done, we we um formed a a uh group of true experts in this area, they made their first approach and evaluation of the complexity, and you know, it boiled down to a couple of things. You need to have a a good organization readiness in place so we don't make this one-off effort to to be quantum safe, and then poof, now we're done, and then it fades again. So there's a a third-party SaaS application that enters our environment that is not quantum safe, or we introduce a digital identity solution in a um application that is not, etc. So we are most likely end up in a situation where we will spend the majority of the time to teach, educate the organization that this is just another aspect of protecting the data that we need to understand. And if you work with uh application development, this is what it means for you. If you work with identities, this is what it means for you, and and so on. So I think it's it's really to be able to break it down into uh uh minimal viable products. This is what we talk about, we know the full scope, but let's take these uh small slices and find the proof for us to progress.

Robby Peralta

Every security topic, it's never really the technology that's a problem, it's it's the culture and getting people to understand, like hey, there's one more thing you have to worry about, and sort of uh not making them hate you, and also then them just getting them on your side and being able to okay. There's yeah, one more thing, and how do I involve this? Uh I really like your quote there. This could either be a great day or it could be fucked from the beginning.

Ulf Larsson

Yeah, you summarize it in in a great way, absolutely. And and uh when you get really the response back from the organization that uh okay, we as you said in the beginning, we have formed a project around this, we have involved the management, and uh we also have our executives that is uh deeply uh interested. Of how do we go along uh with this one, and and uh uh so just having that um preparation, give it the time to to communicate, etc. Now we are in a position where we can start to communicate a little bit more in details that you know this year we will most likely present the following. We will look at some some timeline. We have actually developed without going into too many boring details, a timeline that spans from today up to end of December 2030, and that is because of uh regulators have communicated that uh in some geographies they want us to be quantum safe, and that is 2030. So having that we we were able to backtrack, okay. So, what do we need to do in in 2029, 28, 27, or 27 will most likely be a lot of testing, 26 would be a lot of LCM, just to get us up to a baseline to be able to start a test, etc. etc. And another aspect which which uh the team and I uh personally find very important is to you need to know the stuff, right? You need to understand what are we talking about, how how will this affect us, and also follow the development. So both the the good part of it, uh how we will continue to protect data, etc. etc. But also the development of a quantum computer that might be able to decrypt the existing methodology.

Robby Peralta

Because at the end of the day, that's what you're protecting against. All these efforts are to protect yourself against some supercomputer that either the US or China or Russia are one of these uh scary uh yeah.

Ulf Larsson

Yeah. But but I think by the end of the day, um, Robby, I would say that regulatory compliance will demand us to be quantum safe before there is a threat actor uh getting the qubits ready to uh decrypt a encryption methodology or algorithm.

Robby Peralta

That'd probably be the first time ever that compliance is ahead of the actual threat. Which is great.

Ulf Larsson

Yeah, but uh we'll see. We'll see.

Robby Peralta

Uh so if I was to sum up the things you said, like uh one of the most important things, if not the most important, is just the communication part, right? Getting C-level, getting application people, getting everybody that needs to know about it, getting them informed. What is your lessons learned or tips and tricks that you have to share around that communication part? Like I assume that it wasn't just you having one-on-ones with all these people because uh you you wouldn't be able to have time for this podcast.

Ulf Larsson

If we start with who are the ones we need to really engage with, we look at three buckets. The first bucket is which is the infrastructure that will be affected, right? So, okay, we have the storage team, we have the data communication, the file transfer, etc., etc. etc. The second bucket is the application development and application maintenance team. All right, good. So then we know the magnitude, and the the third one, which I think is a little bit challenging for us, is the the um financial ecosystem. How do we test this together with other banks, other common payment function in the society, with customers, incoming, outgoing files that need to be quantum safe? But coming back to your question, so how do you go about with communication? You can have a great message or a great idea, but there's one thing that is super important that is timing. So if we go out too early, people will they wouldn't just be super stressed and they they look at the how do we get quantum safe here and now, and then there is nothing behind that, there's no support, etc. etc. So our approach is to see what is the education material, the videos, the documentation, etc., that we need to have in place, and and when do we need to have it in place. The other thing is to to use the communication channels we have throughout the year that now it's time, uh, a good time to send the first information broad to the organization. And then we'll be uh after that, we we can go back to the more uh little bit more targeted with schedule session with the uh developers, uh with the application maintenance team and so forth. But we we have extremely talented colleagues in the organization that are good at these types of adoption programs, how to get them uh get traction and and then and so forth.

Robby Peralta

It's always nice to wait for something in the news to happen, and then you keep like, yeah, oh cool, we actually thought about this, and there then could because then you have their attention, but also not very practical for always waiting for something really big and bad to happen so you could push it down on people because yeah.

Ulf Larsson

You need to be good at the topic, you need to understand what it means and what it doesn't mean. You need to look at the threat and translate that into the risk and look at the the environments you have that needs to be changed in one way or another. So that is one thing, and then really look at how will this impact and where in the organization. Start to to think through the the how do we reach out to these teams and when we do, what what is the the support they need. So some of it some and and and and then also start to to look further down that path, uh test and and validate the outcome of the test. I think the challenge here is the the difference of application technical platform to really, you know, if you have a an application in in an assembler or cobalt code versus something else in a source application or a web application, it differs how you protect in that program, uh have uh chosen to uh call for a library with the algorithm to protect data, etc. etc. So I think it's easy to underestimate the explore and discover application and and program coding that has been around for long. Like you said, it's a life cycle thing, you have to always uh Yeah, it very very much boils down to okay, how do we really move ourselves up to a version of data protection that can then be moved to a quantum-safe version? But you cannot take a too big leap that that will most likely uh jeopardize the functionality. You know, everything here that is uh you I mean it spans from from uh API calls to hard-coded in in uh application. Uh you you have you know, just imagine all the file transfers uh we do outgoing outbound, inbound throughout the day. That this I I think it's important also to have a good methodology to understand the volume of the things that need to be be changed, and already mentioned it it cannot be changed at the same time. You need to have a risk perspective on it.

Robby Peralta

And a lot of those times you can't do it anyway because it's some third party that you have to sort of whip in or threaten with your contract, right?

Ulf Larsson

Like and that's another aspect of it. So so how far out in our ecosystem do we need to go? So we have a a third-party vendor, we call them application A, and they have uh subcontractors that provide some with some you know technology building blocks for the application to use uh encryption for something, something. We look at where is the interface for us setting the requirements to to these uh third parties?

Robby Peralta

Yeah. How much of your time have you used on this? Like 100%, or is this just like one of the million projects you have going on?

Ulf Larsson

I I think I have a couple of these 100%. To be serious, Robby. I'm very much a advisor and supporting the team. The team sits with all the insight and expertise. It's fantastic to listen in what they have done in the discovery, the inventory, and so forth. These are the assets, this is the level we have for TLS, etc. etc. So it's it's it's super good.

Robby Peralta

Yeah. Yeah, I would assume that uh you you need a lot of people on that technical team to to be able to understand all those. I don't even know which questions to ask you when it comes to the technical side of it because that's uh over my head. Or is that technical? Like you said, TLS and certificates.

Ulf Larsson

Those like two of the things that I would uh if I talk if I talk to them and they say no, Ulf, this is not complicated. It it boils down to a sound life cycle management, right? But both you and I know that things deviate over time, right? It it's like home. If you look at your garage, you're a little bit ashamed of the stuff that has grown in in the garage of a town. Whereas if you look in the living room, the living room is really a life cycle, you have the latest of the greatest, etc. etc. And it's the same. I mean, here you also can look at this uh uh security in depth, right? So so everything we expose to internet has to be super safe and quantum safe and safe, safe, safe. Whereas some other application way back may be priority number two.

Robby Peralta

But you can't throw it away for some reason, right? It's just there. Yeah. I'm just looking at the stock market of ours. I looked at like some of the company websites like quantum computing, you know, like Honeywell. I've been, I've seen uh a bunch of companies that I've obviously heard of. I know AWS, Microsoft, IBM, they're all in there. What is the future of quantum? Like uh what are your thoughts on that?

Ulf Larsson

Uh that is a super good question. If we look at the the need of uh using quantum compute to process large data sets for preventive analytics, et cetera, so we will also have most likely need uh in in some uh security areas, fraudulent behavior and and so on. I think we will see very few companies purchasing their own quantum compute. It's far too complicated just to run and maintain. So I think that would open up a market for quantum compute as a service, right?

Robby Peralta

Um it's gonna be just like the cloud in general.

Ulf Larsson

Yeah, so and and I I think that that is already business models that are uh not far away from from us to use. We I know there are um quite a lot of tests going on as well. So uh but then you look at the uh there is still uh quite challenging uh when it comes to the uh qubits required for this and the the accuracy. So when they get the qubits, the number of qubits, and they get the quality, we will have a completely different uh situation than than we see today. Today it's there's a lot of uh development left to reach that. So now I'm talking about the the ones you mentioned, uh the big players, right? The big players, yeah, really. But then you have a lot of these uh opportunistic consultancy firms uh approaching uh us and uh many other companies. And I don't know really what they approach us with because much of the um uh much of this uh quantum safe is not even tested, it's not validated, it's it's not necessarily ready to put in in into a fairly complex business model like a bank or financial institution. So I think what I'm trying to say is we need to be a little bit humble when it comes to yeah, we are a company, uh consultancy firm XYZ, and and we can do this and this and this. And and we evaluated that. If we bring in what can they help us with, versus uh let's be good at this by reading, educate ourselves to get our arms around this and create our own approach, and rather use then uh some of the big players as uh you know sounding board, are we going in the right direction? But I think from from a a pure quantum compute, there is a lot of things that that uh before it's commercially available, and you just uh click uh I want this number of qubits, I want it for this workload, I want it for this time. There's a bit to go by. But I think it's super inspiring to read the the development made by by, for example, Google and Microsoft. Uh IBM has been there for for you mentioned that they've been there uh very long, for example.

Robby Peralta

Yeah. Interesting. Uh it's um so yeah, security people, we're we need to make things quantum safe. So that's that's that's this scope of the conversation. But it will be interesting one day to hear like how the uh innovation process is going for what do we use a quantum computer for? Yeah. Uh like um you know, uh hackers are doing it to brute force things or whatever they're gonna be doing it for. But it'll be interesting to hear what the other industries are.

Ulf Larsson

I I'm thinking of like prediction and yeah, think think of the day, um Robby, when we talk about this quantum computer like any computer, right? The um Intel capacity in the ship. Uh we have talked about CPU uh uh cycles. So I think that there would be a scale where we just look at quantum as any other um computer but for a certain workload, whereas we have other AMD or Intel or whatever for other workloads.

Robby Peralta

So this will break Moore's law. Is Moore's law still like does that still work these days, or are we over that?

Ulf Larsson

Yeah, I try to ignore it. Uh I continue to uh ignore it. Uh but uh it's around.

Robby Peralta

Moore's old.

Speaker

Yeah.

Robby Peralta

Good man, though. He did a lot of great stuff for us. Well, um looking forward to seeing you here in May.

Ulf Larsson

Likewise.

Robby Peralta

Thank you so much for your time. And uh I will have more questions for you by the next time I see you. So uh in the in the meantime, take care and enjoy the lovely beginning of spring.

Ulf Larsson

The same. Thank you so much, Robby. It's a pleasure. Thank you.

Robby Peralta

Well, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.no. Thank you for listening. We'll see you next time.