PMMP -- PQC Migration Management Process

Nils von Nethen,Alex Wiesmaier,Nouri Alnahawi,Johanna Henrich
2023-10-12
Abstract:Organizations have to plan on migrating to quantum-resilient cryptographic measures, also known as PQC. However, this is a difficult task, and to the best of our knowledge, there is no generalized approach to manage such a complex migration for cryptography used in IT systems that explicitly integrates into organizations' steering mechanisms and control systems. We present PMMP, a risk-based process for managing the migration of organizations from classic cryptography to PQC and establishing crypto-agility. Having completed the initial design phase, as well as a theoretical evaluation, we now intend to promote PMMP. Practitioners are encouraged to join the effort in order to enable a comprehensive practical evaluation and further development.
Cryptography and Security
What problem does this paper attempt to address?
The main issue discussed in this paper is about how to effectively manage the migration process from traditional encryption methods to Post-Quantum Cryptography (PQC). Specifically, the paper proposes a new framework called the "PQC Migration Management Process" (PMMP), which aims to help organizations achieve this complex technical transition. The main issues pointed out in the paper include: 1. **Technical Challenges**: The development of quantum computers poses a threat to existing encryption algorithms, especially for asymmetric encryption schemes. 2. **Lack of Universal Methods**: Currently, there is no universally applicable method to manage this complex encryption migration process, particularly in terms of integrating with an organization's decision-making mechanisms and control systems. 3. **Risk Management and Time Planning**: A schedule based on organizational risk assessment needs to be defined to ensure timely migration and avoid future quantum computer attacks. 4. **Resource and Technical Preparedness**: Organizations need to assess whether their existing IT infrastructure and human resources can support the implementation of PQC. 5. **Third-Party System Compatibility**: Communication partners also need to upgrade their encryption accordingly to maintain system interoperability and security. To address the above issues, PMMP proposes a risk-based process designed to guide organizations through the transition from traditional encryption to PQC step by step, while ensuring sufficient security and agility throughout the process. Additionally, PMMP considers situations where direct migration is not possible and provides corresponding bridging solutions. Finally, the framework suggests integrating the migration to PQC into existing information security management systems, such as the Information Security Management System (ISMS) under the ISO 27001 standard.