Post-Quantum Cryptography: The Core of Zero Trust for Navy Cyber Defense

0
22

Key Takeaways

  • Zero trust and post‑quantum cryptography (PQC) are complementary: zero trust establishes “who or what should be trusted now,” while PQC ensures that trust can survive a quantum‑capable adversary.
  • Quantum computers threaten today’s public‑key encryption, making legacy perimeter‑based security and static encryption potentially obsolete, especially for long‑lived DoD systems.
  • Defense‑department assets that remain in service for decades require PQC‑protected identities, authentication, and data to prevent future exposure.
  • Zero trust depends heavily on cryptographic mechanisms (PKI, digital certificates, access tokens, TLS); breaking those mechanisms would undermine the entire zero‑trust framework.
  • Quantum computing can also enhance capabilities such as user‑entity behavior analytics and cyber situational awareness, but those benefits must be protected with quantum‑safe cryptography.
  • Agencies should adopt a quantum‑ready zero‑trust architecture that integrates PQC and quantum key distribution into requirements, training, and program planning, prioritizing legacy and OT systems.
  • Success hinges on shared language between IT and operational communities, targeted training, and clear business cases to secure funding from resource sponsors.

Introduction: Convergence of Zero Trust and Quantum‑Resistant Cryptography
The Department of Defense is increasingly viewing zero trust architecture and post‑quantum cryptography not as separate initiatives but as converging strategies for a future‑proof cyber posture. As War Department officials prioritize building systems capable of operating in a quantum era, experts stress that the two approaches must be aligned to maintain security today and tomorrow. This convergence recognizes that zero trust’s reliance on strong identity and access controls can only be sustained if the underlying cryptography resists quantum‑computer attacks.

Defibaugh’s Perspective on Zero Trust and PQC
Steve Defibaugh, former command information security officer at Naval Installations Command and deputy CISO within Naval Sea Systems Command’s Cyber Engineering and Digital Transformation Directorate, articulated this relationship during a July 16 webinar. He explained that zero trust answers the immediate question of “who or what should be trusted right now,” whereas post‑quantum cryptography addresses the longer‑term concern: “Can the cryptographic mechanisms used to establish that trust survive a quantum‑capable adversary?” His framing highlights the need to view zero trust as a dynamic, continuously validated process that must be underpinned by quantum‑safe cryptographic foundations.

Quantum Computing Threat to Classical Cryptography
Defibaugh warned that quantum computers, once matured, could solve certain mathematical problems—such as integer factorization and discrete logarithms—far faster than classical computers, jeopardizing today’s public‑key encryption standards (e.g., RSA, ECC). Although current quantum hardware remains limited by challenges like temperature sensitivity and error rates, the long‑term risk is real enough that agencies should begin preparing now. He emphasized that quantum computing will not replace classical computing outright; rather, the two will coexist, making it essential to protect classical‑computing assets with quantum‑resistant safeguards.

Implications for Long‑Lived Defense Systems
The threat is particularly acute for the Defense Department because many fielded combat systems remain in service for decades, not years. Defibaugh noted, “There are fielded combat systems that exist not in the matter of years, but in the matter of decades,” arguing that PQC resistance is vital to safeguarding the data, logistics, and acquisition information tied to these long‑lived assets. Without quantum‑safe cryptography, adversaries could harvest encrypted traffic today and decrypt it later when quantum capabilities mature, exposing sensitive mission data for extended periods.

How Zero Trust Relies on Cryptography
Zero trust architecture depends heavily on cryptographic functions to perform identity authentication, secure public‑key infrastructure (PKI), issue digital certificates, generate access tokens, and encrypt data and communications via transport layer security (TLS). Defibaugh highlighted that ICAM (Identity, Credential, and Access Management) relies on PKI credentials and digital certificates for authentication; if those cryptographic underpinnings are broken by quantum computers, the identity pillar of zero trust “starts to crumble.” Consequently, a zero‑trust model that does not incorporate PQC cannot guarantee the continuous verification and least‑privilege access it promises.

Quantum Computing as a Dual‑Edged Sword
While quantum computing poses a cryptographic threat, Defibaugh also pointed out its potential to strengthen certain defensive capabilities. He cited the DOW Zero Trust Design Process Guide, which notes that quantum technology can enhance user and entity behavior analytics, cyber situational awareness, and automation orchestration. However, these same advancements require quantum‑safe cryptographic protections to prevent adversaries from exploiting the very capabilities they enable. Thus, quantum computing is both a risk and an opportunity, necessitating a balanced approach that secures its benefits while mitigating its dangers.

Recommendations for Agencies: Building Quantum‑Ready Zero Trust
To address these challenges, Defibaugh urged agencies to adopt a quantum‑ready zero‑trust architecture that explicitly incorporates post‑quantum cryptography and quantum key distribution (QKD) into modernization requirements, training programs, and project‑management planning. He recommended prioritizing legacy and operational technology (OT) systems for PQC integration based on their cyber protection condition status or relevance to mission operational plans, cautioning that system owners may inflate priorities tied to funding interests. By embedding PQC early, agencies can avoid costly retrofits and ensure that new acquisitions are quantum‑resistant from the outset.

Human, Organizational, and Funding Considerations
Defibaugh stressed that technical solutions alone are insufficient; the human and organizational dimensions are critical for successful adoption. He advocated for a shared language between IT and operational communities to bridge cultural gaps and accelerate understanding of quantum risks and solutions. Training programs should raise awareness of PQC fundamentals and zero‑trust principles across both domains. Furthermore, engaging directly with resource sponsors to articulate clear, cogent business cases is essential for securing budget allocations. Defibaugh described his own recurring efforts within the Navy’s budget process to demonstrate how PQC‑enabled zero trust protects mission systems, identities, and data against increasingly sophisticated adversaries, thereby aligning cybersecurity investments with broader mission objectives.


Prepared as a concise yet comprehensive summary of the source material, adhering to the requested length, structure, and stylistic guidelines.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here