Post-Quantum Identity and Access Management for Enterprise Cloud Security
Main Article Content
Abstract
Quantum computing threatens the security of many currently used cryptographic primitives, an issue that is often underestimated in the field of identity and access management (IAM). The ramifications are tangible, especially for cloud IAM deployments. Quantum computers will quickly unravel the current commonly used public-key systems based on RSA and ECC that underpin the signing of access tokens, the establishment of secure channels, and the management of trust through PKI and other model. Post-quantum cryptographic (PQC) algorithms are in development and standardization to address this situation. However, care must be taken to adopt them in IAM layers and components without unduly disrupting service for end users and service providers.
Integrating quantum-safe methods into the IAM procedures of cloud IAM using PQC remains largely unaddressed. A reference architecture for cloud IAM is therefore proposed. The source of a service’s identity tokens becomes responsible for supplying a quantum-safe mechanism for generating and validating, rotating, and storing the tokens, and for supplying a mechanism to ensure quantum-safe long-term storage of the key material used to sign the tokens in conjunction with a usable PKI. Furthermore, although its implementation may not be apparent to end users, the enterprise service provider should ensure that it has a workable cross-ecosystem certificate agility policy and mechanism in place for a relatively unimpeded transition of the IAM service provider ecosystem to quantum-safe substitutes.


