Nigel Edwards
π€ SpeakerAppearances Over Time
Podcast Appearances
The standards were published in 2024.
We are working on applying these in our software stacks, our firmware stacks, and making changes to silicon.
The long pole and the tent are the changes required to silicon because you cannot instantly change silicon to handle new cryptography.
Chip designs and changes to chips, a typical life cycle is two years.
In some cases, as many as four years.
So if a standard is published, then it's not reasonable to expect that to appear next year or even possibly the year after in silicon.
It's not a complete redesign, but we need to make certain changes to the chips.
So in particular, when you look at how firmware is required for the processor, for example, an x86 processor to execute x86 instructions.
So that firmware is verified by keys that are fused into the silicon to ensure, for example, it's genuine firmware.
These keys are your classical keys, such as RSA or ECDSA keys.
They need to be changed to use these post-quantum cryptographic algorithms, which have been standardized by the National Institute of Standards and Technology Organization.
So the approach that we are taking in HPE is to be able to offer our customers PQC configurations with our newer products, PQC enabled configurations.
We know that not all components that are available will be PQC enabled.
But we are working with our supplier partners so that there will be a network controller, a storage controller that we can source that will be PQC enabled together with PQC enabled processors so that the components that matter inside that server, for example, will be PQC enabled.
So we tend to think of it at a product level rather than specific hardware.
PQC enabled means all the cryptography in that server is running the PQC algorithms.
PQC capable means it's capable of running those algorithms, but it might not be enabled.
But it could be enabled in the future by configuration changes and possibly software and firmware upgrades.
So today the hardware is not available.
There is not a PQC enabled processor available.