Networks such as the Internet are essential for our connected world. Quantum computing poses a threat to this heterogeneous infrastructure since it threatens fundamental security mechanisms. Therefore, a migration to post-quantum-cryptography (PQC) is necessary for networks and their components. At the moment, there is little knowledge on how such migrations should be structured and implemented in practice. Our systematic literature review addresses migration approaches for IP networks towards PQC. It surveys papers about the migration process and exemplary real-world software system migrations. On the process side, we found that terminology, migration steps, and roles are not defined precisely or consistently across the literature. Still, we identified four major phases and appropriate substeps which we matched with also emerging archetypes of roles. In terms of real-world migrations, we see that reports used several different PQC implementations and hybrid solutions for migrations of systems belonging to a wide range of system types. Across all papers we noticed three major challenges for adopters: missing experience of PQC and a high realization effort, concerns about the security of the upcoming system, and finally, high complexity. Our findings indicate that recent standardization efforts already push quantum-safe networking forward. However, the literature is still not in consensus about definitions and best practices. Implementations are mostly experimental and not necessarily practical, leading to an overall chaotic situation. To better grasp this fast moving field of (applied) research, our systematic literature review provides a comprehensive overview of its current state and serves as a starting point for delving into the matter of PQC migration.
翻译:互联网等网络对于当今互联世界至关重要。量子计算对这一异构基础设施构成威胁,因为它危及基本安全机制。因此,网络及其组件必须向后量子密码学(PQC)迁移。目前,关于此类迁移应如何构建及在实践中实施的知识尚不充分。我们的系统性文献综述针对IP网络向PQC的迁移方法展开研究,系统梳理了关于迁移过程及实际软件系统迁移案例的文献。在过程层面,我们发现现有文献对术语、迁移步骤和角色的定义既不精确也不一致。尽管如此,我们仍归纳出四个主要阶段及相应的子步骤,并将其与正在形成的角色原型进行匹配。在实际迁移案例方面,我们发现相关报告采用了多种不同的PQC实施方案和混合解决方案,涵盖各类系统类型的迁移。通过综合分析,我们注意到实施者面临三大主要挑战:PQC实践经验缺乏与高实现成本、对升级后系统安全性的担忧,以及系统高度复杂性。我们的研究结果表明,近期的标准化工作已推动量子安全网络向前发展。然而,现有文献在定义和最佳实践方面仍未达成共识。实施方案大多处于实验阶段且实用性不足,导致整体局面较为混乱。为更好地把握这一快速发展的(应用)研究领域,本系统性文献综述提供了该领域现状的全面概览,可作为深入探究PQC迁移问题的起点。