Hacker News

HTTPS e matla le e sebetsang hantle ea quantum-safe

Maikutlo

15 min read Via security.googleblog.com

Mewayz Team

Editorial Team

Hacker News

oache e ntse e ts'oana le mokhoa oa kajeno oa ho Encryption - 'me Likhoebo tse ngata ha li na Maikutlo

Nako le nako ha moreki a fana ka tefo, a saena ho dashboard, kapa a romella molaetsa ka sethala sa hau, HTTPS e lebela data eo ka mokhoa o khutsitseng e sebelisa li-cryptographic algorithms tse lutseng li tiile ka lilemo tse mashome. Empa phetoho ea litšisinyeho tsa lefatše e ntse e tsoela pele. Lik'homphieutha tsa Quantum - mechine e sebelisang fisiks e makatsang ea superposition le entanglement - ka potlako e atamela bokhoni ba ho senya metheo ea lipalo ea RSA, ECDSA, le Diffie-Hellman phapanyetsano ea bohlokoa. Tšokelo ha e sa le khopolo-taba. Ka 2024, NIST e phethetse litekanyetso tsa eona tsa pele tse tharo tsa post-quantum cryptography (PQC). Google, Cloudflare, le Apple li se li qalile ho sebelisa li-algorithms tse hanyetsanang le quantum tlhahiso. Bakeng sa khoebo efe kapa efe e fetisang lintlha tsa bohlokoa marang-rang - e leng khoebo e 'ngoe le e' ngoe ka katleho - ho utloisisa HTTPS ea quantum-safe ha e sa ikhethela. Ke tlamo ea ts'ebetso.

Hobaneng HTTPS ea Hona Joale e Tla Senya Tlas'a Tlhaselo ea Quantum

Kajeno HTTPS e its'etleha ho TLS (Transport Layer Security), e sebelisang asymmetric cryptography nakong ea ho ts'oarana ka matsoho ho theha lekunutu le arolelanoang lipakeng tsa moreki le seva. Tšireletseho ea ho ts'oarana ka letsoho ho itšetlehile ka mathata a lipalo ao lik'homphieutha tsa khale li ke keng tsa a rarolla ka katleho: factoring large integers (RSA) kapa computing discrete logarithms on elliptic curves (ECDH). Khomphutha e matla ka ho lekaneng e sebelisang algorithm ea Shor e ka rarolla ka bobeli ka nako ea polynomial, ea fokotsa se ka nkang k'homphieutha e kholo ea khale limilione tsa lilemo ho isa lihora kapa metsotso feela.

Boemo bo tšosang ka ho fetesisa ke leano la "kotulo hona joale, decrypt later" le seng le ntse le sebelisoa ke batšoantšisi ba naha. Bahanyetsi ba ntse ba hatisa sephethephethe se patiloeng kajeno ka sepheo sa ho se hlakola hang ha likhomphutha tsa quantum li se li holile. Lirekoto tsa lichelete, lintlha tsa tlhokomelo ea bophelo bo botle, thepa ea mahlale, likhokahano tsa mmuso - eng kapa eng e hapuoeng tseleng e se e hlaseleha habonolo. Setsi sa Ts'ireletso ea Naha se lemositse hore ts'okelo ena e fetela ho data efe kapa efe e tlamehang ho lula e le lekunutu ho feta lilemo tse 10, e kenyeletsang litaba tse bohlokoa haholo tsa khoebo.

Likhakanyo li fapana ho latela hore na komporo ea quantum e amanang le cryptographically (CRQC) e tla fihla neng. IBM's roadmap targets 100,000+ qubits by 2033. Google e bontšitse quantum liphoso tsa ho lokisa liphoso le Willow chip ho elella bofelong ba 2024. Le hoja CRQC e khonang ho senya 2048-bit RSA e ka ba lilemo tse 10-15 ho tloha moo, ho falla ho ea ho quantum-protocol e tlameha ho qala hona joale. ho phethela lits'ebetso tsa lefats'e ka bophara.

Maemo a Macha: ML-KEM, ML-DSA, le SLH-DSA

Ka mora ts'ebetso ea tlhahlobo ea lilemo tse robeli e kenyelletsang litlatsetso tse tsoang ho litsebi tsa "cryptographer" lefatšeng ka bophara, NIST e phatlalalitse litekanyetso tse tharo tsa post-quantum cryptographic ka Phato 2024. Litaelo tsena li etselitsoe ho hanana le litlhaselo tse tsoang ho likhomphutha tsa quantum le tsa khale, ho netefatsa ts'ireletso ea nako e telele ho sa tsotelehe hore na hardware ea quantum e tsoela pele kapele hakae.

ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism, eo pele e neng e le CRYSTALS-Kyber) e sebetsana le karolo ea bohlokoa ea phapanyetsano ea ho ts'oarana ka letsoho ha TLS. E nkela ECDH sebaka ka ho sebelisa boima ba lipalo ba mathata a marang-rang a hlophisitsoeng, a lulang a sa khonehe esita le bakeng sa lik'homphieutha tsa quantum. ML-KEM e sebetsa ka tsela e makatsang - boholo ba eona ba bohlokoa bo boholo ho feta ECDH (hoo e ka bang 1,568 byte bakeng sa ML-KEM-768 khahlano le 32 byte bakeng sa X25519), empa bokaholimo ba khomphutha bo fokola haholo, hangata bo potlakile ho feta ts'ebetso ea khale ea elliptic curve.

ML-DSA (Mojule-Lattice-Based Digital Signature Algorithm, eo pele e neng e le CRYSTALS-Dilithium) le SLH-DSA (Stateless Hash-Based Digital Signature Algorithm, eo pele e neng e le SPHINCS+) - e leng bopaki ba hore seva eo o hokelang ho yona ka nnete. ML-DSA e fana ka li-compact signatures tse loketseng lits'ebetso tse ngata, athe SLH-DSA e fana ka phokotso e hlokolosi e ipapisitseng le ts'ebetso ea hash, e fanang ka ts'ireletso e tebileng haeba menahano e thehiloeng ho lattice e ka fokola.

Mokhoa oa Hybrid: Tsela ea Pragmatic ho Tšireletseho ea Quantum

Ha ho moenjiniere ea ikarabellang ea ts'ireletso ea fanang ka tlhahiso ea phetoho ea bosiu bo le bong. Ho e-na le hoo, indasteri e kopane kamokhoa oa lebasetereo kopanyang algorithm ea khale le algorithm ea post-quantum ho ts'oarana ka letsoho e 'ngoe le e 'ngoe ea TLS. Haeba algorithm ea post-quantum e fetoha ho ba le ts'oaetso e sa tsejoeng, algorithm ea khale e ntse e sireletsa khokahanyo. Haeba k'homphieutha ea quantum e senya algorithm ea khale, algorithm ea post-quantum e tšoara mola. U lahleheloa ke ts'ireletseho feela haeba bobeli ba tsona li senyehile ka nako e le 'ngoe - boemo bo sa lebelloang ba linaleli.

Chrome le Firefox li se li ntse li tšehetsa phapanyetsano ea senotlolo sa X25519Kyber768 ka mokhoa o ikhethileng ho tloha qalong ea 2025, ho bolelang hore likhokahano tsa limilione tsa HTTPS letsatsi le letsatsi li se li bolokehile ka lehlakoreng la bohlokoa la phapanyetsano. Cloudflare e tlaleha hore ho feta 35% ea sephethephethe sa eona sa TLS 1.3 se sebelisa tumellano ea bohlokoa ea post-quantum. AWS, Microsoft Azure, le Google Cloud kaofela ba hlahisitse likhetho tsa TLS tse bolokehileng bakeng sa lits'ebeletso tsa bona tse laoloang. Phetoho e etsahala ka potlako ho feta kamoo likhoebo tse ngata li elelloang.

Litšenyehelo tsa ho fallela ho quantum-safe HTTPS li lekantsoe ka lihora tsa boenjiniere le linako tsa liteko. Litsenyehelo tsa ho se falle li lekantsoe ka ho sekisetsa ka ho sa feleng sephiring se seng le se seng seo khoebo ea hau e kileng ea se fetisa. Hybrid deployment e felisa tlhoko ea ho khetha pakeng tsa ts'ireletso le tlhokomeliso - o li fumana ka bobeli.

Dintho tsa Tshebetso: Latency, Bandwidth, le Handshake Overhead

E 'ngoe ea lintho tse neng li tšoenyehile ka mor'a quantum cryptography e ne e le ho senyeha ha ts'ebetso. Linotlolo tse kholo le mesaeno li bolela li-byte tse ngata terateng le ho ts'oarana ka matsoho butle. Ts'ebeliso ea 'nete lefatšeng ka bophara e bonts'itse hore lintho tsena li ka laoleha, empa ha se lefela.

Bakeng sa phapanyetsano ea bohlokoa, ML-KEM-768 e eketsa hoo e ka bang 1.1 KB ho ts'oarana ka letsoho ea TLS ha e bapisoa le X25519 feela. Ka mokhoa oa lebasetere (X25519 + ML-KEM-768), kakaretso ea kakaretso e ka bang 1.2 KB. Ho marang-rang a sejoale-joale, sena se fetolela keketseho e sa tsotelleng ea latency - hangata e ka tlase ho millisecond e le 'ngoe ho likhokahano tsa Broadband. Lintlha tsa tlhahiso ea Cloudflare ha lia ka tsa bontša tšusumetso e lekantsoeng linakong tsa mojaro oa maqephe bakeng sa basebelisi ba bangata. Leha ho le joalo, ho marang-rang a thibetsoeng (lihokelo tsa sathelaete, lisebelisoa tsa IoT, libaka tse nang le li-bandwidth tse fokolang), karolo e ka holimo e ka kopanngoa, haholo-holo ha liketane tsa setifikeiti le tsona li na le li-signature tsa post-quantum.

💡 DID YOU KNOW?

Mewayz replaces 8+ business tools in one platform

CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.

Start Free →

Masaeno a netefatso a hlahisa phephetso e kholoanyane. Mesaeno ea ML-DSA-65 e ka ba 3.3 KB ha e bapisoa le li-byte tse 64 bakeng sa ECDSA-P256. Ha setifikeiti se seng le se seng sa ketane se na le signature ea post-quantum, ketane e tloaelehileng ea litifikeiti tse tharo e ka eketsa 10 KB kapa ho feta ho ts'oarana ka letsoho. Ke ka lebaka lena indasteri e ntseng e hlahloba mekhoa e kang khatello ea setifikeiti, Litifikeiti tsa Merkle Tree, le ntlafatso ea boemo ba TLS ho boloka boholo ba ho ts'oarana ka matsoho bo sebetsa. Likhoebo tse tsamaisang liforomo tse nang le lits'ebetso tsa lefats'e - haholo-holo tse sebeletsang basebelisi ba mebaraka mebarakeng e ntseng e hlaha - li lokela ho tšoaea litlamorao tsena ka hloko.

Seo Likhoebo li Lokelang ho se Etsa Hona Joale: Lethathamo le Sebetsang la Phalliso

Ho falla ha Quantum-Safe ha se ketsahalo e le 'ngoe empa ke ts'ebetso ea mekhahlelo. Mekhatlo e qalang ho etsa lethathamo la litšepiso tsa eona tsa cryptographic kajeno e tla be e le maemong a betere ho feta a emetseng litaelo tsa taolo. Mona ke moralo o sebetsang oa ho qala phetoho:

  1. Etsa lethathamo la li-cryptographic. Hlalosa tsamaiso e 'ngoe le e 'ngoe, protocol, le libuka tse sebelisang RSA, ECDSA, ECDH, kapa Diffie-Hellman. Sena se kenyelletsa litlhophiso tsa TLS, liheke tsa API, li-VPN, ho saena khoutu, ho encryption database, le likhokahano tsa mokha oa boraro.
  2. Beha lintho tsa bohlokoa ho latela kutloisiso ea data le nako e telele ea bophelo. Litsamaiso tse sebetsanang le lintlha tsa lichelete, lirekoto tsa tlhokomelo ea bophelo bo botle, litokomane tsa molao, kapa lintlha tsa botho tse lokelang ho lula e le lekunutu ka lilemo li lokela ho falla pele. "Kotulo hona joale, hlakola hamorao" e etsa hore liphiri tsa nako e telele e be tsa bohlokoa ka ho fetisisa.
  3. Lumella hybrid post-quantum TLS libakeng tse shebaneng le sechaba. Haeba lisebelisoa tsa hau li le ka morao ho Cloudflare, AWS CloudFront, kapa li-CDN tse tšoanang, e ka 'na eaba u se u ntse u khona ho kena ho quantum-safe key exchange. E lumelle ka ho hlaka 'me u netefatse ka lisebelisoa tse kang Qualys SSL Labs kapa sehlopha sa teko sa Open Quantum Safe project.
  4. Ntlafatsa lilaeborari tsa li-cryptographic. Netefatsa hore tekhenoloji ea hau e sebelisa lilaeborari tse tšehetsang ML-KEM le ML-DSA — OpenSSL 3.5+, BoringSSL, liboqs, kapa AWS-LC. Tobetsa ho liphetolelo tse kenyelletsang tšebetso ea ho qetela ea NIST, eseng liphetolelo tse ngotsoeng.
  5. Teko ea ho lumellana le ho fokotseha ha ts'ebetso. Ho ts'oarana ka matsoho ho hoholo ho ka sebelisana hampe le li-middlebox, li-firewall, le li-balancers tsa thepa ea lefa tse behang meeli ea boholo ho TLS ClientHello melaetsa. Google e ile ea kopana le sena nakong ea ho qala ha Kyber mme ea tlameha ho kenya tšebetsong litharollo.
  6. Theha leano la crypto-agility. Etsa mekhoa e le hore li-algorithms tsa cryptographic li ka fetoloa ntle le ho ngola khoutu ea kopo hape. Sena se bolela ho tlosa lits'ebetso tsa crypto ka morao ho li-interfaces tse lokisehang le ho qoba khetho ea algorithm e thata.

Bakeng sa sethala se joalo ka Mewayz se sebetsanang le lintlha tsa bohlokoa tsa khoebo ho limojule tse 207 tse kopaneng - ho tloha ho lirekoto tsa CRM le li-invoice ho isa ho moputso, HR, le analytics - boholo ba ho itšetleha ka mokhoa oa cryptographic bo bongata haholo. Mohala o mong le o mong oa API lipakeng tsa li-module, webhook e 'ngoe le e 'ngoe ho ea ho lits'ebeletso tsa motho oa boraro, karolo e' ngoe le e 'ngoe ea mosebelisi e nang le data ea lichelete kapa ea mohiruoa e emela sebaka sa encryption seo qetellong se tlamehang ho fetela ho maemo a sireletsehileng a quantum. Lipolanete tse nang le meralo ea ts'ireletso e bohareng li na le molemo mona: ho ntlafatsa lera la TLS le lilaebrari tse arolelanoang tsa li-cryptographic li ka senya ts'ireletso ho limmojule tsohle ka nako e le 'ngoe, ho fapana le ho hloka tokiso ea module-by-module.

Sebaka sa Taolo sa Naha se a Potlaka

Mebuso ha e emetse hore likhomphutha tsa quantum li fihle pele e laela hore ho nkeloe khato. United States 'National Security Memorandum NSM-10 (2022) e ile ea laela mekhatlo ea mmuso ho etsa lethathamo la litsamaiso tsa bona tsa cryptographic le ho theha merero ea ho falla. Quantum Computing Cybersecurity Preparedness Act e hloka hore mekhatlo e behe pele ho amoheloa ha poso ea quantum cryptography. Litaelo tsa ho itokisa ha palo ea CISA li khothaletsa ka ho hlaka phano ea lebasetere ho qala hang hang. Setifikeiti sa European Union sa cybersecurity se kenyelletsa litlhoko tsa kamora palo, mme balaoli ba lichelete ho kenyeletsoa Bank for International Settlements ba tšoaile kotsi e ngata tataisong ea bona ea bookameli.

Bakeng sa likhoebo tse sebetsang liindastering tse laoloang - lichelete, tlhokomelo ea bophelo bo botle, likontraka tsa mmuso, SaaS e sebelisang data e ngata - linako tsa ho latela melao li ntse li eketseha. Likhamphani tse amohelang HTTPS e sireletsehileng ea quantum li tla qoba ho qhekella ha litaelo li khanya. Habohlokoa le ho feta, ba tla khona ho bonts'a bareki le balekane hore boemo ba bona ba ts'ireletso ea data bo baka litšokelo tse hlahang, eseng tsa hajoale. Limmarakeng tsa tlholisano moo ho tšepana e leng khethollo, boemo bona ba ts'ireletso bo shebileng pele bo na le boleng ba 'nete ba khoebo.

Ho Aha Bokamoso bo Mameletseng, Ho tsukutlana ka letsoho le le leng ka Nako

Ho fetela ho quantum-safe HTTPS ke phetoho e kholo ka ho fetesisa ea li-cryptographic nalaneng ea Marang-rang. E ama seva se seng le se seng, sebatli se seng le se seng, sesebelisoa se seng le se seng sa mohala, API e 'ngoe le e' ngoe, le sesebelisoa se seng le se seng sa IoT se buisanang ka TLS. Litaba tse monate ke hore litekanyetso li phethetsoe, ts'ebetsong e ntse e hola, 'me sephetho sa ts'ebetso se bonahala se laoleha. Moetso oa hybrid deployment o bolela hore likhoebo li ka amohela khanyetso ea quantum butle butle, ntle le ho tela ho lumellana kapa ho ipeha kotsing e sa hlokahaleng.

Se arolang mekhatlo e tla tsamaisa phetoho ena ka thelelo ho e tla qhekella ke ha e qala. Cryptographic agility - bokhoni ba ho fetola boemo ba ts'ireletso ea hau joalo ka lits'oso le maemo a fetoha - e lokela ho ba molao-motheo oa moralo, eseng mohopolo o mong. Bakeng sa liforomo tsa khoebo tse laolang palo e felletseng ea data ea ts'ebetso, ho tloha ho likhokahano tsa bareki le litšebelisano tsa lichelete ho ea ho lirekoto tsa basebetsi le liphaephe tsa analytics, lipalo tsa ho fumana tokelo ena li ne li ke ke tsa phahama. Bokamoso ba quantum ha se ntho e hole. Ke phalliso e qalang ka thomello e latelang.

Tlisa Khoebo ea Hao ka Mewayz

Mewayz e tlisa 207 business modules sethaleng se le seng — CRM, invoice, tsamaiso ea morero, le tse ling. Eba le basebelisi ba 138,000+ ba nolofalitseng tšebetso ea bona.

Qala Mahala Kajeno →

Lipotso Tse Botsoang Hangata

quantum-safe cryptography ke eng?

Quantum-safe cryptography (eo hape e bitsoang post-quantum cryptography kapa PQC) e bua ka mokhoa o mocha oa mokhoa oa ho boloka mokhoa oa ho sireletseha khahlano le litlhaselo tsa likhomphutha tsa khale le tsa quantum. Ho fapana le litekanyetso tsa hajoale joalo ka RSA, e itšetlehileng ka mathata a lipalo, likhomphutha tsa quantum li ka rarolloa habonolo, PQC e ipapisitse le liphephetso tse rarahaneng tsa lipalo tseo ho lumeloang hore li thata hore komporo efe kapa efe e ka robeha. Ho sebelisa li-algorithms tsena ho netefatsa hore likhokahano tsa hau tsa HTTPS li lula li sireletsehile ho isa nakong e tlang.

Ke hloka ho tšoenyeha neng ka kholiso ea ka ea hona joale ea HTTPS?

Kotsi ea hang-hang ke litlhaselo tsa "kotulo hona joale, decrypt later", moo bahanyetsi ba utsoang data e patiloeng kajeno ho e senya hamorao ha komporo e matla ea quantum e le teng. Le ha likhomphutha tse kholo tsa quantum li so fihle, ho falla ho ea ho maemo a sireletsehileng a quantum ho nka nako. Ho qala phetoho hona joale ho bohlokoa bakeng sa ho sireletsa lekunutu la nako e telele la data. Bakeng sa likhoebo tse hahang litsamaiso tse ncha, Mewayz e fana ka lithupelo tse fetang 207 mabapi le ts'ireletso ea bopaki ba nako e tlang ka $19 feela / khoeli.

Seabo sa NIST ke sefe ho quantum-safe cryptography?

Setsi sa Naha sa Maemo le Thekenoloji (NIST) esale se etsa ts'ebetso ea lilemo tse ngata ho tiisa quantum-safe cryptographic algorithms. Ka 2024, NIST e phethetse likhetho tsa eona tsa pele, e leng mohato oa bohlokoa bakeng sa barekisi le bahlahisi ho qala ho kenya ts'ebetsong litekanyetso tsena tse ncha ho software le hardware. Boemo bona bo tiisa tšebelisano 'me bo fana ka tsela e hlakileng, e hlahlobiloeng eo mekhatlo e lokelang ho e latela ha e ntlafatsa ts'ireletso ea eona.

Ho thata hakae ho ntlafatsa ho quantum-safe HTTPS?

Ntlafatso ke mosebetsi o moholo o kenyelletsang ho nchafatsa li-server, software ea bareki, le litifikeiti tsa digital. Ha se phetoho e bonolo feela; e hloka ho rera le ho etsa liteko ho netefatsa hore hoa lumellana. Leha ho le joalo, ho qala thuto ea sehlopha sa hau esale pele ho nolofatsa ts'ebetso. Li-platform tse kang Mewayz li fana ka litsela tse hlophisitsoeng tsa ho ithuta tse nang le li-module tse 207, e leng se etsang hore e khonehe ($ 19 / khoeli) ho etsa hore baetsi ba hau ba potlakele lintlha tsa ts'ebetsong le mekhoa e metle.

Try Mewayz Free

All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.

Start managing your business smarter today

Join 30,000+ businesses. Free forever plan · No credit card required.

Ready to put this into practice?

Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.

Start Free Trial →

Ready to take action?

Start your free Mewayz trial today

All-in-one business platform. No credit card required.

Start Free →

14-day free trial · No credit card · Cancel anytime