Proposal: Misdirected Quantum Countermeasures (QKD substitution, unvalidated quantum-safe claims) - #20
Open
m-khan-97 wants to merge 1 commit into
Open
Conversation
A candidate entry covering countermeasures that address the wrong problem: QKD substituted for PQC, QRNG treated as a mitigation for the quantum threat to public-key cryptography, proprietary "post-quantum" algorithms with no public cryptanalytic record, and unvalidated vendor claims. Anchored on the published NCSC and NSA positions on QKD. Makes no claim about prevalence; the evidence tag records demonstrated for the guidance and emerging for the failure mode.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A candidate entry for Sprint 1 voting, submitted before the generative sprint
closes on 3 August.
The gap
Every current entry describes an organisation that has not yet migrated. None
describes one that believes it already has.
There is no mention of QKD anywhere in the ten entries, and procurement appears
only as mitigation advice inside QS04, QS05 and QS07 - never as a risk in its own
right. That leaves the failure mode where an organisation spends budget and
calendar on a quantum-branded product that replaces none of its quantum-vulnerable
algorithms, records the programme as progressing, and reaches a regulatory deadline
with the estate it started with.
Four substitutions are covered: QKD deployed in place of PQC, QRNG treated as
addressing the quantum threat to public-key cryptography, proprietary
"post-quantum" algorithms with no public cryptanalytic record, and unvalidated
vendor claims generally.
Why the evidence is strong
This is the rare platform-adjacent topic where national technical authorities have
already taken an explicit published position:
applications", that QKD does not provide authentication, and that PQC is the best
mitigation.
anticipate certifying such products.
Both are primary-source anchors, not research. The entry also leans on CMVP as the
independently checkable answer to "is this claim real", which makes the mitigation
verifiable in the sense #15 asks for.
There is a genuinely sharp technical point that I have not seen made in the list:
QKD does not authenticate, so a QKD link still rests on classical signatures. The
quantum channel protects key agreement while the trust anchor beneath it stays
quantum-vulnerable. That is the same layering error as QS01's RSA-wrapped AES, in a
product people are buying specifically to solve the problem.
On prevalence - deliberately not claimed
#12 correctly objected to QS06 asserting that something was "widely misimplemented"
without a citation. I have tried not to repeat that here. The entry claims that
NCSC and NSA considered the substitution likely enough to publish formal positions,
which is verifiable, and makes no claim about how often it happens. The evidence
tag says so explicitly: demonstrated for the guidance, emerging for the failure mode.
If reviewers think even that is too strong, the honest fallback is to present it as
a procurement-assurance risk anchored purely on the two agency positions.
Notes
proposals/per the sprint plan, using the structure from_template.mdplus the evidence tag proposed in Add proposals directory, evidence convention, and CONTRIBUTING #18. If Add proposals directory, evidence convention, and CONTRIBUTING #18 is not merged, this creates the
directory; the two do not conflict, since this touches no file that PR does.
Quantum Countermeasures" describes it, but alternatives worth considering are
"False Quantum Assurance" or "Unvalidated Quantum-Safe Claims".
address the wrong problem. It does not cover PQC deployed incorrectly, which is
QS06, nor the absence of any migration at all, which is QS01 to QS05.
offered as a candidate for it rather than as an argument to displace anything.