Skip to content

Quantum computers could be a cybersecurity nightmare. This researcher is helping fend off that risk

Northeastern professor Yunsi Fei will be working on making post quantum cryptography systems more resilient to cyberattacks.   

Professor Yunsi Fei works on a technical computer fuction.
Yunsei Fei said quantum computers pose a risk to our security. Researchers like herself are working to mitigate their risk. Photo by Matthew Modoono/Northeastern University

In the next five to 10 years quantum computers are predicted to be capable of decrypting everything from personal health records to national defense contracts. 

That’s because these machines are poised to be extremely adept at breaking encryption codes. The mathematical algorithms found throughout the web help keep our precious data safe from hackers, explained Yunsi Fei, a professor of electrical and computer engineering at Northeastern University. 

It would take upwards of a million years for today’s computers to solve the mathematical formulas underlying today’s encryption techniques, she said. But quantum computers could solve them in a fraction of the time.  

The Boston Consulting Group, a global management consulting firm, estimates that “quantum computers have a better than 50% likelihood of breaking widely used cryptographic algorithms by 2035.”

To safeguard against this, governments and developers throughout the world have begun the process of developing new post-quantum cryptography (PQC) algorithms and techniques. In June, the White House even issued an executive order on the development of PQC technologies. 

Yunsi Fei poses for a portrait.
Yunsi Fei, professor of electrical and computer engineering, will work to make a well-known post quantum cryptography algorthom more resilient to cyberattacks. Photo by Matthew Modoono/Northeastern University

The order directs federal agencies to dedicate time and resources to accelerate the transition to PQC technologies, highlighting their importance for preserving “critical infrastructure and (the) digital economy” against potential quantum computing threats.    

Now Fei, with the support from the National Science Foundation, will spend the next few years improving the resilience of a post-quantum computing encryption standard against a few of the most common ways hackers could intercept these systems in the future. 

“If quantum computers come out within the next five years, we cannot wait until then to start looking for alternative algorithms,” she said. 

PhFor the three-year project, Fei and collaborators at Tufts University will work with the PQC algorithm known as CRYSTALS-Kyber. The algorithm was selected by the U.S. National Institute of Standards and Technology, which develops national guidelines and standards used in the sciences and technology fields, to serve as the eventual replacement for current encryption systems. 

CRYSTALS-Kyber was developed by the computer company IBM in the early 2010s. Companies from Amazon Web Services to Cloudflare have integrated the technology and its updated versions into its operations. 

But while advanced, these systems are still ripe for attack. Specifically, Fei will work to make the systems more resilient to two types of cybersecurity threats — side channel and fault attacks.

Side channel attacks involve hackers collecting basic information from an encrypted device, such as its power consumption levels, electromagnetic frequencies, and time of use, in order to gain access to a system, explained Fei. 

A fault attack is where a hacker deliberately introduces disruptions into a system to create errors. This might look like interfering with the systems through disrupting power voltage,and causing temperature changes within the system. 

To actually improve these systems in their testing, Fei and her colleagues will essentially work as professional hackers, she said. 

“We don’t want people to eavesdrop on our conversations or discover our passwords,” Fei said, in describing the significance of the research. “This is really the foundation for confidentiality and privacy. We want to protect those.”  

The researchers will conduct this work in three-tracks. 

For the first track, they will work to understand how these systems are vulnerable to side channel attacks, by testing the Kyber algorithm on real hardware to determine how much information it “leaks.” From there, they will work to develop code to address this issue.   

For the second track, they will investigate fault attacks, using a similar approach, intentionally introducing physical errors into the systems to see how they respond to try and come up with workable solutions.   

And lastly they will develop dedicated hardware systems to put solutions into practice. 

“At the end of the day, we are using our expertise and our hacking capabilities to protect the system,” she said. “We have an ethical hacking mentality to find specific vulnerabilities. 

Northeastern Global News, in your inbox.

Sign up for NGN’s daily newsletter for news, discovery and analysis from around the world.