Securing Systems with Blockchain and Post-Quantum Cryptography — with David Carvalho and David Holtzman of Naoris Protocol
42m 46s
The transcription discusses a decentralized physical infrastructure AI system improving in different environments and storing data securely using post-quantum cryptography. It introduces the NAIR protocol aiming to decentralize and enhance security through blockchain and AI technologies. The conversation delves into the intersection of post-quantum security, blockchain, and AI, highlighting the importance of quantum resistance and post-quantum cryptography in distributed computing. The speakers emphasize the need for transitioning to post-quantum safe protocols due to the impending threat of quantum computing, with a focus on proof of security and integrity mechanisms in digital systems. Discussions also touch on the potential migration of post-quantum technologies to existing blockchain systems and the importance of enhancing security in the face of evolving threats.
Transcription
6617 Words, 38287 Characters
(upbeat music)
- So we have a decentralized physical infrastructure AI
that's like on the whole environment
or in a collection of environments, learning and improving.
And all of that data is actually written
to the chain and protected at post-quantum level.
So even if your systems are not at post-quantum level,
the truth about them is.
- Imagine a mesh network of AI powered nodes
that could validate the security
of your organization's systems and applications.
It's a clever use of blockchain
to add security to real-world devices.
And best of all, it will feature post-quantum cryptography.
Learn how this technology could simplify security
and if it may even prevent killer robots
in this episode of the post-quantum world.
I'm your host, Konstantinos Karagiannis.
I lead quantum computing services at Protivity
where we're helping companies prepare
for the benefits and threats of this exploding field.
I hope you'll join each episode
as we explore the technology and business impacts
of this post-quantum era.
Our guests today are bringing the NAIR
as protocol to the world.
We have David Carvalho, the founder
who was an ethical hacker for 20 years.
I put in some decades doing that as well.
And we have David Holtzman, chief strategy officer
who created a little something called DNS,
you might have heard of,
and worked at the NSA and IBM.
So welcome, guys.
- Thank you, glad to be here.
- Yeah.
- Yeah, great.
And you guys both know a lot about information security
and you're working at the intersection of AI,
blockchain and post-quantum security.
So we'll kind of touch on all that.
This is the post-quantum world.
So we will have to say a few things about the PQC aspects.
We'll get to all that.
But first, David C.
Let's start with what the NAIR protocol is at a high level.
- Sure.
So NAIR protocol has the objective of basically
taking away the single point of failure principle
that every device, every application, every service,
every process is in reality right now in the world.
So every device, every application, every system,
every server is a single point of failure
from a risk perspective, from a hacking perspective,
from a tampering perspective, to everything it is connected
to, everywhere in the world for everything, right?
And so decentralization comes in
and that was kind of like an obvious marriage for us.
So bringing in technologies like, you know,
DLT, blockchain, cybersecurity together,
some of the most mature areas in cybersecurity, AI,
and in this case, post-quantum technologies
just made a lot of sense to mitigate future threats
and current threats.
So our objective is to use blockchain technology
to fix that problem, which is really nobody's fault.
That's just how the internet's made.
But to create kind of like a, you know, a primitive,
let's say, a baseline that ensures in a highly
cryptographical, resilient environment,
trust and assurance across devices, across networks,
backed by a decentralized group of validators
under what we call a decentralized proof of security
consensus mechanism.
So in other words, it's kind of like creating a hive mind
of systems checking each other, kind of like watching,
acting like watchdogs, making sure that they're all
in a trusted state using very advanced mathematical
algorithms that are very hard to break,
and therefore bring a lot of resilience to the space.
So the more it grows, the harder it is to break.
While right now, the more it grows,
the more points of failure you have.
So that's kind of like our main initiative.
And since then we have branched into, you know,
post-quantum capabilities or quantum safe,
quantum resistant capabilities,
decentralized physical infrastructure and other areas.
- Okay, so for people listening who just get
a basic idea of blockchain down,
in reality you have like a distributed ledger
and this ability to check what transactions have occurred,
and that's how blockchain transactions occur.
In this case, you have all these devices
that now are a distributed like mesh of devices
that are aware of each other.
And if something bad is going on,
the other ones could be like, well,
we don't trust you anymore, right?
Is that kind of it in a really high level nutshell?
- That's right, even between networks that you don't,
you don't control, let's say.
So let's say you want to access an API that you don't control.
How do you know that the system that contains the API
or the API itself is not tampered with?
If it is, you probably don't want this data.
So what you said is right, except the blockchains
pretty much operate under a principle
that very much focuses on smart contracts and crypto.
And so basically the environment that it operates on,
is about 0.5% of the world economy.
So the cryptographic space or the crypto space,
DeFi and so on in blockchains,
in this case, it's about bringing blockchain
to the real world.
It's about bringing blockchain to enhance the baseline,
let's say, create security and assurance
and resilience by default in existing centralized spaces,
thereby decentralizing their capability to trust each other.
- Okay, yeah, before we dig into a little bit of that,
David H, you I guess have traditionally been involved
in very traditional security, right?
Web 2, I guess you could call it over the years.
- Web 1.
- Yeah, Web 1, right?
Yeah, Web 1 into 1 too, for sure Web 1.
So how, what made you feel compelled to move
into this like new kind of approach?
- As soon as I heard about it, I was really excited
because I guess philosophically,
I'm kind of an anarchist at heart.
And I've always been very, very concerned
about any centralized authentication mechanisms.
I mean, I've been doing this for 35 years
and it seems that the internet started off
more or less decentralized
and as commercial entities got in,
they kept trying to centralize it,
usually under the guise of authentication
and then cryptographic authentication.
The problem with that is it leads
to monopolistic behavior.
I was in a company that was a monopoly,
network solutions where I worked at,
we had the contract for the entire domain name system
and up until '97, '98, you couldn't even sell a domain name
unless you went through us.
And now it's ICANN, so it's the same idea.
I'm also worried about governments
and I like the idea of having a system
where the way David's designed it with the resolvers,
it could be in a different network,
you don't really know what network they are.
It's very, very hard to corrupt any potential resolver.
And I guess the last point is that I'm really excited about,
David said this, I just wanna stress this,
with conventional two web two kind of authentication,
the more nodes you add, the weaker the network gets,
the more vulnerable it gets.
In this kind of setup, it's the exact reverse
because now you have more resolvers
and the network becomes more robust.
And if you look at data breaches today,
I went back and look the other day,
almost every major data breach
that we name at a company like Equifax or AT&T,
it really wasn't them, it was a third party they hired
for point of sale or credit cards or something
and it weakens the entire system.
So that's why I'm excited by it.
- Sounds good, yeah.
And before we dig into some of the ways that this works,
'cause it's a little hard to visualize,
I mean, for me it's easy to visualize,
but some people don't really think about this stuff.
I was involved in smart contracts kind of early,
I gave the first talk at DEF CON on how to hack that
back at DC 25, so yeah, I'm interested in all that.
But to take it to like a quantum place for a sec,
there were claims of quantum resistance
that first caught my eye
and why I wanted to have you guys on the show.
So maybe you could both take a stab at explaining
how this is quantum resistant
and what ways that like PQC aspect comes in to this.
I can maybe take a swab at that.
So basically we went and we started operating
with a number of former NATO leaders
that operating obviously in the hardest
to defend the environments that are
and probably the highest, most important targets
under their supervision, let's say.
So one of the interesting mandates that they suggested
for us was to actually bring a consensus mechanism up,
which are called DPOSAC, decentralized proof of security
that uses post quantum capabilities,
post quantum cryptography principles actually operate.
So that means both the caching, the keys, everything
is actually following the best practice defined by NIST, right?
Under one of the winners of the competition
for the post quantum algorithms
that absolutely just finished recently.
That was a multi year competition.
And in this case, we worked together with various universities.
So both in the US and also in Europe to do research
around those and actually make it work.
So we wrote a paper that was chosen
by the IEEE Foundation,
probably the biggest engineering group in the world.
And we went to Cape Town in South Africa to present it,
went by 12, was well received.
And that was in October last year,
but we are already working on that for about three years.
And as the time passed, and as we talked to the generals
that are advisors and so on across various countries
in Europe, they just kept saying every year
that this is a bigger and bigger problem.
And we don't know how to deal with it.
And obviously, if you look at the investment amounts
that come into this, and I'm sure we'll speak
about this later, everybody that has critical data
to protect or mission critical environments
is very focused on that as one of the kind of like shiny
objects in coming, we can see it coming.
So post quantum cryptography for us was obvious,
kind of like as an X step to do.
So right now we are in full production
with a post quantum chain that is the first one operating
at that level with about 7,000 transactions per second.
And it includes all the capabilities that we said before,
distributed computing, distributed processing
under our protocol.
And it does that so it kind of like levels up blockchain
to the next cryptographic level,
but it also levels up centralized machines
to the next trust level.
So the way this works actually is that the protocol
it supports this distributed computing
and distributed storage.
So even if you have like, it doesn't matter
if you have like one of these or a server
or a Raspberry Pi or like, you know, a $1 IoT device,
it's probably be able to run a node,
which is quite interesting because you can like enforce
things that you can never enforce in IoT.
And as you know, when they don't have any enforcement
of anything.
So that is exciting for us and our partners.
- So it's lightweight, and this leveled up quantum
resistant version, which is like smaller in building,
would that also be able to run on like cell phones
and things like that?
- Absolutely, absolutely.
Both at hardware level for key distribution and PKI,
all the way to, you know, in hardware security modules
so on, all the way to software level, very likely.
And if it is on a network that is discoverable,
it will use computing power from other devices
to, for example, derive keys and things like this,
which is quite exciting because if it was only in one device,
it probably wouldn't be able to do anything with it.
- It is very lightweight and it's highly portable,
which I think is really critical now
because of all the different IoT devices,
none of which get any upgrades or maintenance
as far as I can tell.
- With the quantum resistant version is the goal
to then ultimately replace to make all of the protocol
devices running, be running that version going forward?
Sort of like as a parallel of what we're facing right now
in InfoSec in general, right?
Everyone wants to do this migration now
to be compatible with the new NIST ciphers.
- To tell the truth, I think we have been helped by,
by NIST, about two weeks ago,
they have come out and said,
oh, you know, we have chosen the winner
and the winner is one of the ones that we use
from the competition.
And as they believe, like we believe,
like the intelligence spaces were connected to
and militaries were connected to believe,
that as soon as you have a quantum computer,
you can have qubits or a quantum singularity
or call it whatever you want in the short term,
everything that secrets gonna be broken by that actor.
And that includes blockchains, that includes,
RSA, AES, you know, insert acronym here,
any lead to curve-based photography,
which is really everything.
Then they said that it is going to be mandatory from now
for any federal agency or entity, for example, in the US,
to follow post-quantum principles
across their infrastructure and their stack.
So there's a big effort on that side.
And we know from, you know, other contacts that we have,
that's going to be mandated and the regulation as well,
from a privacy, for privacy reasons,
because for example, with quantum capabilities,
a foreign actor or a state actor,
as David was talking about,
we'll be able to do pretty aggressive attacks on anything
and just really destroy privacy across the board
for whole countries or the whole world at the same time.
- Let me add something onto that too,
because one of the things that we've heard,
we talked to a lot of governments and government agencies.
And one of the things they're afraid of,
it's probably not all that obvious,
but it's store and break kind of stuff.
So when they're dealing with government or military,
it's just as bad if they get broken two years from now
or three years from now.
So the sooner they switched it,
this kind of quantum proof cryptography,
the better they are,
because there's a lot of hell to pay
in the future at some point.
- Yeah, the harvest now to cripple later threat.
- Yeah, that's right.
Which is kind of funny because it almost doesn't,
it almost makes, what can I say,
the whole quantum stuff not matter
and at the same time matter.
Like it doesn't matter if quantum computer is here now,
but in two years or three,
what matters is that the harvest now
and the cripple later is gonna happen.
And in two years, your stuff is gonna be the crypt.
And nobody changes keys, right?
So whatever you have there,
in two years, you're just gonna have more, right?
- Yeah, what's the shelf life of your secret
and how important is,
which of the finalists from NIST
actually is in the quantum resistant protocol you're using?
- It's the deletion phase one, yeah.
- Okay, and so you built the new version
of the solution around that.
You're saying that that's post-quantum,
kind of like some experimental post-quantum blockchains exist.
Do you then think that this approach
could be easily migrated out to the world?
Because right now,
obviously one of the biggest problems with blockchain
is so many of them are not post-quantum safe.
And how are we gonna make that switch?
Do you have any thoughts about any way
that the rest of the industry can learn from this
and kind of start a migration in that sense?
- Yeah, that's really interesting.
So we're talking to really big players
in the blockchain industry,
like I'm talking to like top 10 about that problem
because they see that.
And we have a number of potential solutions to that
that go through that pass through, for example,
post-quantum rollups to quantum backups of chains
and other things that I cannot speak about right now,
but they are quite exciting.
And I think they're just logical.
Nobody that has assets wants them at risk,
but then that goes for like the whole crypto world, ETFs,
the whole $116 trillion banking system
we have so on and so forth.
So it doesn't really matter if you're in Web 2 or Web 3.
The point is that it just makes sense
to move into validation structures
that first of all exist.
In most cases, they don't exist.
And if they exist, they exist centrally,
which means they're easily manipulatable,
so you cannot trust them for really everything.
And I'm talking about like, say for example,
for example, SMTP, the Simple Mail Transfer Protocol.
I send you an email, it's plain text.
Like me and David were playing about,
joking about that the other day.
And that's been around for eons, right?
Really, I mean technology eons.
And it needs a bridge with Web 3, in my opinion, right?
But lots of things that need a bridge for post-quantum,
a bridge for decentralization,
call it whatever you like, like a transparent connection,
right?
They don't need to be destroyed 'cause they're important.
But there needs to be a plug into something better
that allows them to continue to live.
Otherwise, it just gets worse.
And like I said, people are aware,
critical entities, highly regulated spaces are aware.
The quantum difficulty,
and I'm sure David will want to talk about this,
is no longer kind of like an innovation problem
or is like, you know, theoretical problem,
it's an engineering problem.
So you just need to throw at it enough engineers
and enough money, just like with, you know,
putting a man in the moon sort of thing.
And it will be solved.
And there's constant innovations about that.
And let me tell you, adversaries, be they who they are,
they will want you to think that nothing's happening.
That's the advantage while they're actually running.
So--
- That's the APT model.
- Absolutely, but the definition of state level.
- Yeah, yeah.
That's to get in and just like exist and persist.
So what we're protecting here right now
before the post-quantum is fully rolled out
is this validation or this like proof of,
I guess, what's the word I'm looking for?
Like proof of security, proof of integrity, right?
These are the things you guys have called it.
And in the future with quantum,
we'll also be protecting that
because with a quantum computer,
you'll be able to attack an assist system
like this if it doesn't have post-quantum
and then be able to tell the network,
everything's fine, you know, basically.
So you'll be able to manipulate of the encryption.
So let's just key in the audience a little bit
on these proof of concepts.
So in Ethereum, there's proof of state,
proof of work, those kinds of principles.
And then now we have these proof of security things.
So did you want to talk just like a little bit
about how they're similar, how they're very different
just to give everyone idea of how it works?
- Sure, I mean, in many ways they're similar.
In other ways, they extend what exists
to fundamentally new areas.
So they really, the biggest difference I would say,
for example, compared to proof of state
is that of course this is like a, you know,
a Byzantine falter on the tolerance system
that is custom and it does all these things.
But it does all these things not over, you know,
smart contract that has been called by, you know,
a system with the key.
It does all these things using smart contracts maybe,
but it does that over the systems themselves.
So the systems themselves, the data, the applications,
the processes, the services, the operations,
any sort of like digital proof that you want to create
of any digital process that's, you know,
really running digitally on the server somewhere
is actually provable and transparent if you want,
anywhere in the world for anybody, right?
And if you think about it, you're really creating
the capability for machines to trust each other, right?
And for you to trust the process that you have no access to.
Right, it's in the server that maybe you don't even,
you know, you might be consuming an API
that locks someone else.
But how do you know that the system that created the data
that sent the data to another system
that consumed it and transformed it
and then send it to the system that has the API?
How do you know that they're all trusted?
You have no idea, right?
Nobody has any idea, nothing is measured.
So in the end, the objective was to create
a hyper measured environment that is incentivized.
So the participants, the nodes, the validators
are actually incentivized to provide this service,
this value to the world that if you think about it,
it's quite powerful.
It really changes the way how you deal with risk
in probably other things as well.
- Well, that's a good point.
I mean, I used to run big data centers
and the metric that I managed to was network uptime,
you know, 99.9, 99.999, because it's all we had.
And we could measure that, we could hire people,
we could find people if they didn't produce.
But I think we're now in a world
where the measurement is actually based on security
and we have no idea how to measure that.
So when you talk to people who aren't technical,
they say, yes, I want security, like yes, I want privacy.
It's binary either you have it or you don't,
but it isn't, it's, you know, as we all here know,
it's a continuum.
And this allows us to really smoothly manage
that continuum of what trust and security means.
And there's an ancillary benefit from this,
and this is getting a little futuristic,
but we're about to move into the era of,
I would say, semi-sentient software,
or at least highly autonomous software.
And the kind of thing, the way Norris Protocol is working,
fits that model a lot better.
It's not a human being-centric thing.
It could, a semi-autonomous software entity
could easily start talking that way
and use relative trust in these--
- Yeah, and it sounds like there's some AI involved here,
right?
So with traditional smart contracts, code is the law.
And whatever conditionals they're gonna follow,
they're gonna act on them in a touring complete fashion,
even if it means you clean out billions of dollars
in funds like during an attack,
like the dollar or something like that.
So that's sort of like brainless following of,
quote, unquote, logic.
But when you add AI into the mix,
you can do a whole lot more, I'd imagine.
So what are these contracts doing?
Let's just walk through a very simple example.
It's kind of like a mesh, right, of these nodes.
And let's say someone attacks one of them.
What happens at that point?
- It's so interesting you asked this question.
David was just talking about that,
and you were also like, it is a mesh.
And there are smart contracts.
However, our consensus mechanism allow us
to do more than what David was saying.
So uptime, let's talk about blockchain validators.
Every blockchain validator that exists or minor
is managed by one thing.
Are you up?
If the answer is yes, then validators be validated.
That's what they do.
- You have no idea if it's a trust.
If it's a trust, it's a ugly, like an SMS relay.
Like you, of course it's a lot more complicated than that,
but the point is you have no idea if you can trust them.
Yeah, sure, it's decentralized, it's much better.
But for example, one of the mandates
that we had from former NATO leaders
to use these, for example, in defense environments
and to bring it blockchain environments
or decentralized systems to the real world
was to make sure that all the participants
are in a trusted state.
It sounds obvious, but that is not something that exists.
So we have actually to create the decentralized
group security to ensure that.
So that every participant that is in a green state
or trusted state and maintaining their integrity
and doing best practice so on in online
can validate and can participate.
And if they are not, if somehow, as you say,
one participant is hacked, something has been tampered with
or it's a time is not good or a number of other parameters
that, by the way, are completely custom,
then can be as complex or as simple as you want,
which gives you a lot of use cases, are broken.
It doesn't participate, it cannot participate.
You don't want a malicious actor.
So it's a lot harder for you to have like a 51% attack
and then any other kind of like traditional issues
that you would have in blockchains.
However, even if nothing of this was present
and I'm just going to defend blockchains in general,
this is really already without anything,
but we're adding a lot more already exponentially better
than what we have right now,
which is like, you know, you hack one
and you know, congratulations.
After a while, you can exfiltrate data
or ransomware the whole thing, right?
Really, whatever you want, generally,
if you're a capable attacker.
- Can you give us like a real world example
of maybe a customer, if you can't say the name, that's fine,
but of how this was implemented
and what particular way they chose,
'cause this could be flexible, right?
You could be protecting IoT devices like we talked about earlier,
you could be defending just about anything.
So can you give like one example of how it was implemented
and then what happens basically at the end
to just let everyone understand how AI comes in?
Like, does it reach out to some centralized AI
for decision or something like that?
And then that should just kind of cement.
- Yeah, I'll talk to you about that as well.
So there's an AI system that we have
that's called Swarm AI.
It's a consensus-based AI ecosystem
that basically gathers data and learns from edge computing.
We wrote a paper as well with a couple of universities
that actually got published and we reviewed
in a nice journal in Germany about IoT
some months back about exactly this
and how it uses the consensus mechanism for that
and so on and so forth.
So I won't go into details of clients,
but I will tell you like a real-world situation
with the proper obfuscation points.
So you have an environment that have a collection of devices
like your routers, you have antennas, you have drones,
you have 5G things, 5G IoTs,
you have servers in the cloud, you have virtual systems,
you have dockers, you have all these things locally
in the cloud as well,
and your infrastructure is distributed around the world.
Sounds like a normal company.
So a normal company is already decentralized,
they just don't know it.
So we're allowing for them to actually leverage
that capability to defend themselves
and what happened in this case,
this was actually, I cannot talk about real-world attacks
and mitigation for obvious reasons,
but I can talk about examples that we have actually,
attacks that we have done on infrastructures.
So I'm talking about an attack, for example,
on a robotic arm that was in one of the company's networks
that is part of the whole mesh that is the company.
And this robotic arm was running an embedded Linux version,
and the piece of malware that was put there,
we made it FUD or fully undetectable
by using a crypto for $0, that's how hard it is.
That we got from the dark web, randomly.
We got various, but this one worked better.
We tested it on VirusTotal and it was like,
there's nothing here, okay, let's try it.
So there was a number of vulnerabilities on the box.
So we did some remote code execution,
dropped the malware, we executed it with a remote timer
in kind of like cron, basically.
So we better just change that and it got executed.
And the machine got tempered with obviously,
the robotic arm started going crazy in the real world
and just trying to destroy the things around it.
And systems that were, for example, in other continents
that were part of the same peer-to-peer mesh
that actually knew how that system should look
and should behave and so on and so forth,
didn't accept that change.
So they acted on it.
We had a smart contract that isolated that environment
and didn't want the potential threat,
didn't allow the potential threat to propagate
and allowed, for example, for forensics to happen.
But we went a little bit further on the second level
'cause we did it various times
and we created what we call backup nodes
that are basically what they sound like.
They are validated trusted nodes
that backup critical audience of data
that you can define could be like specific folders
or whatever.
And if any of these things get tempered with,
the system gets automatically reset
and isolated under consensus and then turned on again.
So what happens is that the robot was going crazy
and then after a while, it's checked again,
it's rebooted and it checked again to be in a good state.
Everything that was malicious was substituted
or deleted, the malicious files that were modified,
that were actually malicious movements for the robot
were substituted with the original ones
and everything was back to normal.
And this happened in about like two minutes,
but the initial detection and reaction
was like 10 milliseconds locally on the network.
So they detected it first
and then the global detection happened
about one second later across all clouds.
And what happened is that the SWARMA AI
has learned about this potential threat and what it does.
And it shared that across the rest of the ecosystem.
So say, if there was another similar system
in a different country that potentially was using the protocol,
potentially on a different network
and potentially on a different company,
they could actually be protected against that
even though they have no idea
that that has happened somewhere else.
And one of the biggest issues that we have, for example,
and I'm just going to focus on cyber
even though we're getting into the world
of decentralized infrastructure
and like this decentralized physical infrastructure,
deep in and things like this,
I have no doubt this is going to be the biggest idea
in blockchain in the next years.
This is a deep in situation.
So we have a decentralized physical infrastructure AI
that's like on the whole environment
or in a collection of environments,
learning and improving.
And all of that data is actually written to the chain
and protected at post-quantum level.
So even if your systems are not at post-quantum level,
which they should be eventually into the future,
with post-quantum keys, securing like SSH and SSL
and all these things, even if they are not,
the truth about them is,
so you actually know what is instead of not knowing
or guessing because right now the time
for detection of any threat is about 279 days, I think,
in the US, the rest of the world is way more.
So in our case, that was reduced to 10 milliseconds
under this principle.
So this is one of the use cases of the,
let's say the primitive we have created at Norris Perical.
There's many more.
- Is it safe to say that this might be able
to catch zero days just because there's an anomalous behavior
on one node that was attacked
and then the other nodes could say,
we don't know what this is.
There's no number associated with vulnerability,
but we know that we don't like this behavior
and we're not gonna let that change happen to us.
Is that kind of the idea?
- That's a very good point because changes,
as you say, changes are, they assume integrity, right?
And integrity can even be pushed at post-quantum level.
So integrity is pretty close to
mathematically perfect as we know it, right?
If it is or it isn't, there's nothing in the middle, right?
And under the decentralized validation structure,
that gets very powerful.
Obviously, blockchains are perfect at this.
That's what they do already, right?
So we have extended that from Bitcoins and Spark contracts
into data and systems and applications and services, right?
Which is the rest of the digital infrastructure globally.
So yes, your searching is, I would say, is correct.
Having said that, to be fair,
there's probably thousands of different ways
to skin a rabbit in terms of like zero days.
There's exploits that have nothing to detect,
there's so on and so forth,
but eventually something has to happen somewhere.
Otherwise, the attacker is doing nothing else
but wasting their time.
- Absolutely.
So you're able to take this technology
and make it post-quantum.
So what kind of advice would you give to anyone else
operating in this space for what you've learned
and what you've accomplished?
What should they be doing to try and make that migration too?
If they're currently working on some kind of blockchain
or some kind of technology in that space,
what should they be doing in the short term
now that we know that the threat's expanded?
- I can maybe speak about all the environments
that you have had contact to recently,
and I'm talking about like, web three spaces.
So the problem is all the same, banking, ports and rail,
other critical infrastructure, nation-state agencies,
central banks, so on and so forth.
They just need to start with, they just need a plan.
They just need, for example,
to follow the strategic European data protection initiative
on post-quantum, for example,
there's one in the US as well,
that basically allows them or helps them create the framework
that allows them to manage their own structures.
So prepare their libraries, prepare their systems,
prepare their policies for transformation, right?
Which in the end, it's not really painful,
it's not like, yes, it's kind of like taking
some hundreds of COVID shots for systems,
but it's something that is much better than the alternative,
which is, Harvest now in the Crip later,
and all your secrets being revealed,
your five-year plans, your IP, so on and so forth.
And I'm sure David has something to say on that too, David.
- Well, I would just add to that.
I worked in big companies,
and large enterprises move very slowly at adopting
even incremental changes in their base software.
I can only imagine how they're gonna deal with this stuff,
'cause this is not incremental.
This is gonna be significantly different
than how they do things.
So I would advise anybody that they should be starting
pilot programs now and evaluating things like us,
and maybe our competitors,
and start coming up with solutions,
and how they're gonna integrate it into their enterprise.
- And is that gonna look like, sorry, go ahead.
- No, I was gonna ask it if there's a way for people
to see like a demo of maybe the regular,
the post-quantum version, whatever,
just so they can understand
how easy it is to implement something like this.
- Yeah, so we have, basically we have that available
for a number of reasons.
We don't show that yet publicly,
because we are not public yet.
But we should be in the end of quarter three,
quarter four, if everything goes well,
also assuming that the market goes, gets better.
Then actually these days,
I mean, both markets, the real world and the crypto.
And the companies, institutions,
the companies that like to partner, et cetera,
they can contact us and will basically open up our doors
and integrate with them,
and work to fix their problems in a very,
either in a very custom way
or help them build on our chain,
or integrate their existing software or systems
in our chain, which is actually quite easy.
In most cases, it's kind of like just a,
wrapping code around something.
- Yeah, so with that call to action,
I'll thank you guys for your time.
And I'll definitely be linking everything
about the Neorus protocol in the show notes.
Thank you.
- Thanks so much, Konstantinus.
It was a pleasure to be here.
- Thank you.
- Now it's time for coherence.
The quantum executive summary,
where I take a moment to highlight some
of the business impacts we discussed today
in case things got too nerdy at times.
Let's recap.
Neorus protocol is a blockchain design
to protect network devices.
Typically, the larger a network becomes,
the larger the threat surface grows,
providing more potential points of failure.
With Neorus, the more nodes that come online,
the greater the protection,
including handling some devices
that have proved challenging to organizations in the past.
Each node validates that a device or application
is safe and maintains integrity.
Suppose bad behaviors detected, such as a hack.
In that case, the network will no longer trust the device
through consensus among the many other nodes.
This is similar to how our cryptocurrency blockchain
would not accept forged transactions.
One of the NIST PQC finalists,
Stylithium, is now being used
in a version of the Neorus protocol.
The hope is to add this post-quantum cryptography
to the main chain's proof of integrity
or validation of all devices.
Devices that run Neorus nodes can be servers
or lighter ones such as phones or IoT appliances.
However, nodes can also run on industrial systems,
which can potentially cause physical harm if hacked.
For example, the protocol can protect industrial robots.
This could prevent at least one kind of robot uprising
in the future.
While Neorus is still new,
the team has worked with high-profile environments.
Blockchain is a natural fit for validating devices
and launching with post-quantum cryptography as an option
is a terrific example of how PQC
is starting to appear across the industry.
Because so many blockchains are vulnerable
to quantum computers, I'd like to see more PQC development
in the distributed ledger technology space.
That does it for this episode.
Thanks to David Carvalho and David Holtzman
for joining to discuss Neorus protocol.
And thank you for listening.
If you enjoyed the show,
please subscribe to Partivities, the post-quantum world,
and maybe leave a review to help others find us.
Be sure to follow me on all socials at constanthacker.
That's constant with a K, hacker.
You'll find links there to what we're doing
in quantum computing services at Partivity.
You can also DM me questions or suggestions
for what you'd like to hear on the show.
For more information on our quantum services,
check out partivity.com or follow Partivity Tech
on Twitter and LinkedIn.
Until next time, be kind and stay quantum curious.
Podcast Summary
Key Points:
Decentralized physical infrastructure AI learning and improving in various environments.
Mesh network of AI nodes validating security with post-quantum cryptography.
NAIR protocol aims to decentralize and enhance security with blockchain and AI.
Discussion on post-quantum security, blockchain, and AI intersection.
Focus on quantum resistance, post-quantum cryptography, and distributed computing.
Summary:
The transcription discusses a decentralized physical infrastructure AI system improving in different environments and storing data securely using post-quantum cryptography. It introduces the NAIR protocol aiming to decentralize and enhance security through blockchain and AI technologies. The conversation delves into the intersection of post-quantum security, blockchain, and AI, highlighting the importance of quantum resistance and post-quantum cryptography in distributed computing.
The speakers emphasize the need for transitioning to post-quantum safe protocols due to the impending threat of quantum computing, with a focus on proof of security and integrity mechanisms in digital systems. Discussions also touch on the potential migration of post-quantum technologies to existing blockchain systems and the importance of enhancing security in the face of evolving threats.
FAQs
The objective of the NAIR protocol is to decentralize systems and applications to mitigate risks and create trust and assurance using blockchain, AI, and post-quantum technologies.
The NAIR protocol creates a decentralized proof of security consensus mechanism where systems check each other using advanced mathematical algorithms, ensuring resilience and trust across devices and networks.
Post-quantum cryptography in the NAIR protocol ensures data protection against future threats posed by quantum computing, making it quantum-resistant and enhancing the trust level of centralized machines.
The NAIR protocol supports distributed computing and storage, allowing devices of various types to run nodes, ensuring robustness and security even in IoT devices.
The NAIR protocol is exploring solutions such as post-quantum rollups and quantum backups for existing blockchains to facilitate migration to post-quantum safe systems, ensuring asset protection and network security.
The proof of security concept in the NAIR protocol extends existing blockchain principles to ensure provable and transparent systems, applications, and processes, enabling machines to trust each other and verifying digital processes globally.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.