The software engineering community is facing challenges from quantum computers (QCs). In the era of quantum computing, Shor's algorithm running on QCs can break asymmetric encryption algorithms that classical computers practically cannot. Though the exact date when QCs will become "dangerous" for practical problems is unknown, the consensus is that this future is near. Thus, the software engineering community needs to start making software ready for quantum attacks and ensure quantum safety proactively. We argue that the problem of evolving existing software to quantum-safe software is very similar to the Y2K bug. Thus, we leverage some best practices from the Y2K bug and propose our roadmap, called 7E, which gives developers a structured way to prepare for quantum attacks. It is intended to help developers start planning for the creation of new software and the evolution of cryptography in existing software. In this paper, we use a case study to validate the viability of 7E. Our software under study is the IBM Db2 database system. We upgrade the current cryptographic schemes to post-quantum cryptographic ones (using Kyber and Dilithium schemes) and report our findings and lessons learned. We show that the 7E roadmap effectively plans the evolution of existing software security features towards quantum safety, but it does require minor revisions. We incorporate our experience with IBM Db2 into the revised 7E roadmap. The U.S. Department of Commerce's National Institute of Standards and Technology is finalizing the post-quantum cryptographic standard. The software engineering community needs to start getting prepared for the quantum advantage era. We hope that our experiential study with IBM Db2 and the 7E roadmap will help the community prepare existing software for quantum attacks in a structured manner.
翻译:软件工程社区正面临量子计算机(QC)带来的挑战。在量子计算时代,运行在QC上的Shor算法能够破解经典计算机实际上无法破解的非对称加密算法。尽管QC何时会变得对实际问题"危险"的确切日期尚不明确,但共识是这一天已经临近。因此,软件工程社区需要开始为软件抵御量子攻击做好准备,并主动确保量子安全。我们认为,将现有软件演化为量子安全软件的问题与Y2K漏洞非常相似。因此,我们借鉴了Y2K漏洞的一些最佳实践,提出了名为7E的路线图,为开发者提供一种结构化方法来应对量子攻击。该路线图旨在帮助开发者开始规划新软件的创建以及现有软件中加密机制的演进。本文通过一个案例研究验证了7E的可行性。我们的研究对象是IBM Db2数据库系统。我们将当前加密方案升级为后量子加密方案(使用Kyber和Dilithium方案),并报告了研究发现和经验教训。结果表明,7E路线图能够有效规划现有软件安全特性向量子安全的演进,但需要进行小幅修订。我们将IBM Db2的实践经验纳入修订后的7E路线图。美国商务部国家标准与技术研究院正在最终确定后量子加密标准。软件工程社区需要开始为量子优势时代做好准备。我们希望,通过IBM Db2的实证研究及7E路线图,能够帮助社区以结构化方式使现有软件做好应对量子攻击的准备。