Beyond Classical Cryptography: Building Quantum-Resistant Cloud Native... Andrés Vega & Hugo Landau
Andrés Vega, Hugo Landau
KubeCon + CloudNativeCon Europe 2025 · Session
Overview
This talk, presented by Andrés Vega and Hugo Landau, delves into the critical and increasingly urgent need for quantum-resistant cryptography within cloud-native environments, specifically focusing on the Spiffy and Spire projects. While initially intended as an end-user story, the speakers adapted their presentation to address widespread skepticism and lack of understanding regarding quantum computing threats and their implications for current cryptographic systems. The core message is clear: despite the absence of a cryptographically relevant quantum computer today, the "store now, decrypt later" (SNDL) attack model necessitates immediate action to future-proof sensitive data.

Key moments
- 0:00 Introduction and bank heist vs. forklift job analogy
- 2:40 Quantum computers, qubits, and Shor's algorithm threat
- 3:50 Lattice-based cryptography and NIST PQC standardization
- 5:40 Quantum computing reality and 'harvest now, decrypt later' threat
- 6:50 Actionable advice: Who needs to prepare for quantum threats
- 7:10 PQC algorithms improve classical crypto security flaws
Beyond Classical Cryptography: Building Quantum-Resistant Cloud Native...
Speakers: Andrés Vega; Hugo Landau
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=LEiFzJnqU-E
Overview
This talk, presented by Andrés Vega and Hugo Landau, delves into the critical and increasingly urgent need for quantum-resistant cryptography within cloud-native environments, specifically focusing on the Spiffy and Spire projects. While initially intended as an end-user story, the speakers adapted their presentation to address widespread skepticism and lack of understanding regarding quantum computing threats and their implications for current cryptographic systems. The core message is clear: despite the absence of a cryptographically relevant quantum computer today, the "store now, decrypt later" (SNDL) attack model necessitates immediate action to future-proof sensitive data.
The speakers emphasize that the shift to post-quantum cryptography (PQC) is not merely a theoretical exercise but a practical imperative for organizations dealing with long-lived, confidential data in sectors like healthcare, finance, and defense. They highlight the vulnerabilities of traditional cryptographic primitives, such as RSA and elliptic curve cryptography (ECC), to quantum algorithms like Shor's algorithm. The talk demonstrates a tangible path forward by showcasing how Spiffy and Spire, foundational projects for dynamic, verifiable service identities, can be augmented with NIST-standardized PQC algorithms to secure cloud-native communications, even at the granular level of a service mesh.
Ultimately, Vega and Landau provide a compelling case for cryptographic agility and proactive migration strategies. They illustrate how, by integrating PQC into core infrastructure components like Spire and leveraging service mesh technologies like Cilium and Envoy, organizations can achieve robust, quantum-resistant security without requiring application-level changes. The presentation serves as both an educational primer on the quantum threat and a practical guide for cloud-native practitioners on how to begin the journey toward a quantum-safe future, underscoring the collaborative efforts within the open-source community and with government partners.
Background
▶ Watch: Introduction and bank heist vs. forklift job analogy (0:00)
The looming threat of quantum computers to contemporary cryptography is the primary impetus behind this discussion. Current encryption standards, including RSA and elliptic curve cryptography (ECC), rely on the computational difficulty of problems like factoring large numbers or solving discrete logarithms. However, quantum computers, operating on qubits rather than classical bits, possess the theoretical capability to execute algorithms like Shor's algorithm, proposed in 1994, which can solve these problems in polynomial time, rendering much of today's internet security obsolete.
While large-scale quantum computers capable of breaking modern cryptography are not yet widely available, the "store now, decrypt later" (SNDL) attack model presents an immediate risk. Adversaries can harvest encrypted data today, store it, and decrypt it retroactively once sufficiently powerful quantum computers emerge. This is particularly concerning for data requiring long-term confidentiality, such as healthcare records (50+ years), financial transactions, or national defense secrets. Experts surveyed by the Global Risk Institute place the likelihood of a cryptographic breakthrough within the next decade at around 30%, a significant enough probability to warrant proactive measures.
In response to this impending threat, the National Institute of Standards and Technology (NIST) has spearheaded a multi-year standardization process for post-quantum cryptography (PQC). This initiative aims to identify and standardize new mathematical algorithms that are resistant to both classical and quantum attacks. The third round of this process, culminating recently, selected Kyber (ML-KEM) for key establishment and Dilithium (ML-DSA) for digital signatures as federal information processing standards (FIPS 203 and FIPS 204, respectively). These algorithms are primarily based on lattice-based cryptography, which constructs security around the presumed difficulty of solving certain problems in high-dimensional lattices, such as the Learning With Errors (LWE) problem, an NP-hard problem.
Beyond the quantum threat, the speakers also highlight the inherent challenges and subtle implementation flaws in classical cryptography. Even robust algorithms can be undermined by poor implementations, leading to vulnerabilities like timing side-channel attacks, weak subgroup attacks, or off-curve inputs. The new generation of PQC algorithms, often formally specified and verified, can mitigate these issues through features like constant-time implementations and deterministic functions (e.g., SHAKE), which reduce reliance on perfect randomness and provide vetted parameters, thus preventing common misconfigurations. This diversification of mathematical problems and improved implementation rigor offers benefits even if a cryptographically relevant quantum computer never materializes. Governments, including the UK's GCHQ and the US NSA (with CNSA 2.0), have already begun legislating and advising on the migration to quantum-resistant cryptography, recognizing the substantial time investment required for such transitions.
Key Findings
▶ Watch: Lattice-based cryptography and NIST PQC standardization (3:50)
The talk presents several crucial findings regarding the state and future of quantum-resistant cryptography, particularly within cloud-native ecosystems:
- Immediate Threat of "Store Now, Decrypt Later" (SNDL): The most significant and immediate threat posed by future quantum computers is the ability for adversaries to capture encrypted data today and decrypt it later. This makes the adoption of post-quantum secure key exchange mechanisms a critical, high-priority action now to future-proof systems, even before quantum computers become widely available.
- NIST Standards Provide a Viable Path: The NIST standardization of Kyber (ML-KEM) for key establishment and Dilithium (ML-DSA) for digital signatures offers a concrete, vetted foundation for building quantum-resistant systems. These lattice-based algorithms are robust candidates for replacing vulnerable classical cryptography.
- Spiffy/Spire as a PQC Enabler: The Spiffy and Spire projects, designed for dynamic, verifiable service identities and workload attestation, have been successfully adapted to integrate PQC. This demonstrates a practical and scalable path for securing cloud-native communications with quantum-resistant algorithms without requiring applications to be PQC-aware.
- Hybrid Key Exchange for Robustness: The integration of Kyber X25519 hybrid key exchange into the TLS stack used by Spire is highlighted as a prudent strategy. This approach hedges against the possibility that either the classical (X25519) or the quantum-resistant (Kyber) algorithm might later be found insecure, providing a "belt-and-suspenders" level of security.
- Go Ecosystem's Role in Practical Adoption: The mainline shipping of hybrid key exchange mechanisms for TLS with Go 1.23 significantly lowers the barrier to entry for PQC adoption within the vast Go ecosystem, which underpins much of Kubernetes and cloud-native software. This allows many systems to gain PQC benefits simply by upgrading their Go runtime.
- Layered Security with PQC-Secured mTLS: By integrating PQC into the underlying mTLS communication, combined with service mesh technologies like Cilium and Envoy, organizations can implement fine-grained, Layer 7 network policies on top of quantum-resistant communication. This creates a powerful, multi-layered security posture where application-level security is built upon a quantum-safe transport layer.
Technical Deep Dive
▶ Watch: Quantum computing reality and 'harvest now, decrypt later' threat (5:40)
The technical heart of the presentation lies in demonstrating how Spiffy and Spire can be leveraged and augmented to incorporate post-quantum cryptography (PQC), thereby securing cloud-native workloads against future quantum threats. Spiffy provides a framework for dynamic, verifiable identities for every service, moving away from static API keys or long-lived certificates. Spire, its reference implementation, acts as a control plane for issuing, renewing, and revoking these short-lived credentials, governed by policy and tied to trusted runtime signals. This inherent agility and focus on short-lived identities already align well with cryptographic best practices.
Spiffy and Spire rely heavily on existing cryptographic primitives, primarily TLS (Transport Layer Security), specifically mutual TLS (mTLS), for secure service-to-service communication. This involves asymmetric cryptography for key exchange mechanisms (like elliptic curve Diffie-Hellman) and X.509 certificates for authentication, which contain digital signatures. Additionally, JWT (JSON Web Token) tokens can also be used for identity verification. The fundamental problem is that the key exchange mechanisms and signature algorithms used in these standards are vulnerable to Shor's algorithm on a cryptographically relevant quantum computer.
The speakers detail their approach to retrofitting Spire with PQC algorithms:
- Prioritizing Key Exchange: Recognizing the immediate threat of the "store now, decrypt later" (SNDL) attack, the highest priority was placed on securing the key exchange component of the TLS stack. An attacker capturing today's encrypted traffic can retroactively decrypt it if the key exchange is vulnerable. To counter this, Spire was integrated with Kyber X25519 hybrid key exchange. This hybrid approach combines a classical key exchange (X25519) with a quantum-resistant one (Kyber 768), providing a hedge against potential weaknesses in either algorithm. This ensures that even if one algorithm is compromised (either by a quantum computer or a classical attack), the other provides a fallback, maintaining forward secrecy.
- Augmenting Signatures: While less urgent than key exchange (as signature compromise typically requires an active attack to impersonate a service), the signature algorithms in X.509 certificates also need to be quantum-resistant. For this, Spire was augmented with Dilithium 3 signatures, which form the basis of ML-DSA (Multivariate Lattice-based Digital Signature Algorithm), a NIST-adopted standard. This ensures that the identities themselves, and the trust anchors verifying them, are quantum-safe.
The integration extends beyond just Spire itself. The solution leverages a service mesh architecture, using Cilium as the Container Network Interface (CNI) and Envoy as the proxy. This allows for secure cross-cluster communication where HTTP requests made over mTLS can be audited and inspected at Layer 7. Critically, the PQC-secured mTLS communication happens transparently at the network layer (node-to-node), meaning the application itself does not need to be aware of or implement quantum-resistant algorithms. This separation of concerns is vital for broad adoption and minimizes application development overhead.
The broader ecosystem plays a crucial role. The Go programming language, widely used in cloud-native development, has shipped mainline hybrid key exchange mechanisms for TLS with Go 1.23. This means that many Go applications can gain PQC benefits for their TLS connections simply by upgrading their Go runtime. For PQC signatures, the project adopted Cloudflare's Circle library, which pioneered Dilithium 3 signatures, demonstrating the importance of community contributions and open-source libraries in accelerating PQC adoption.
Demo / Proof of Concept
▶ Watch: Actionable advice: Who needs to prepare for quantum threats (6:50)
The talk included a live demonstration showcasing the practical implementation of quantum-resistant cryptography within a cloud-native environment. The setup consisted of a three-node Kubernetes stack running Cilium as the CNI.
The demonstration began by showing a simple test application deployed in a default Kubernetes namespace, featuring a "demo pod worker" and a "demo echo server." An HTTP request from the worker to the echo server successfully returned a diagnostic result, illustrating basic communication. The crucial part of the demo then showed an attempt to make a different HTTP request to the echo server, which resulted in "access denied."
This denial was not due to traditional network segmentation but rather a Cilium Network Policy that had been configured. The policy restricted HTTP requests based on their URL structure, allowing only specific paths while denying others. This highlighted the ability to impose fine-grained Layer 7 policy on network traffic.
The key takeaway from this part of the demo, as emphasized by Hugo Landau, was that this entire communication, including the Layer 7 policy enforcement, was occurring over post-quantum secure mTLS (mutual TLS). This security was provided by the Envoy service mesh, ensuring that node-to-node communication was quantum-resistant without the application itself needing to be aware of or modified for PQC.
Further into the demo, the speakers delved into the underlying mechanisms. They showed how Cilium interacts with Spire to obtain authentication certificates for workloads. Each workload is assigned a numerical identity, which Spire then uses to issue an X.509 SVID (Spiffy Verifiable Identity Document). This SVID is then used for mTLS communication.
A particularly insightful moment was when an X.509 SVID for the echo server demo was queried from the Spire server and decoded. The output clearly showed a Spiffy identity for the echo workload. More importantly, it revealed that the signature algorithm used was Dilithium 3. The demonstration machine's version of OpenSSL did not recognize this algorithm, displaying raw data, which underscored the bleeding-edge nature of the implementation and the ongoing need for broader tool support.
Andrés Vega also mentioned that the support for Kyber and Dilithium is configured within the Spire server and Spire agent configurations, indicating that the PQC capabilities are integrated at the core of the Spire infrastructure. While a live edit of the configs wasn't shown due to time, the implication was clear: PQC is an configurable option within Spire.
Defensive Implications
▶ Watch: PQC algorithms improve classical crypto security flaws (7:10)
The insights from this talk provide a clear roadmap for defenders to prepare for the quantum threat and enhance overall cryptographic resilience:
- Prioritize Quantum-Resistant Key Exchange Immediately: The "store now, decrypt later" (SNDL) attack model means that data encrypted today is vulnerable to future quantum computers. Defenders must prioritize implementing post-quantum secure key exchange mechanisms, especially hybrid key exchanges like Kyber X25519, in all systems where data requires long-term confidentiality. This is the most urgent step to future-proof past and present communications.
- Embrace Cryptographic Agility: Organizations need the capability to easily swap out algorithms, ciphers, and protocols. This means designing systems that are not hard-coded to specific cryptographic primitives. Tools like Spiffy and Spire, with their emphasis on dynamic, short-lived identities and centralized policy control, inherently support this agility, making transitions to new cryptographic standards much smoother.
- Automate Key Management and Crypto Processes: Manual processes are a major source of error and vulnerability. Defenders should strive to eliminate human involvement in key management, certificate rotation, and cryptographic configuration. Automation, coupled with robust visibility and observability, builds confidence in the safety and effectiveness of cryptographic changes, facilitating faster adoption of new standards.
- Limit Key Lifespan and Practice Regular Rotation: Even with strong algorithms, long-lived keys increase exposure. Implementing policies for short-lived credentials and frequent, automated key rotation reduces the attack surface. This practice not only limits the damage from a compromise but also keeps systems operationally prepared for cryptographic transitions.
- Address the Policy-Operations Disconnect: Auditors and compliance teams often treat key management as a rigid checkbox exercise, which can create a disconnect with operational realities. Defenders need to bridge this gap, ensuring that security policies are not only robust but also operationally feasible and integrated into automated workflows.
- Monitor PQC Negotiation Failures: As PQC algorithms are deployed, it's crucial to actively monitor TLS handshakes to ensure that the intended quantum-resistant key exchange mechanisms are actually being negotiated. Subtle implementation differences can lead to fallback to non-quantum-safe algorithms, creating a false sense of security. Telemetry and verification of negotiated ciphers are essential.
- Leverage Ecosystem Updates and Open Source: Stay informed about and actively upgrade to software versions that include PQC support. The inclusion of hybrid key exchange in Go 1.23 and ongoing work in OpenSSL are significant enablers. Engage with open-source communities (like Spiffy/Spire, Cilium, Envoy) to share learnings and contribute to the development of quantum-resistant solutions.
- Plan for Performance Trade-offs: PQC algorithms generally involve larger key sizes and higher computational costs during cryptographic operations. While this may not be a bottleneck in all cloud-native environments (especially where TLS handshake overhead is "lost in the noise"), defenders should plan for potential impacts, particularly in high-throughput TLS termination points like load balancers.
Key Takeaways
- Immediate Threat: The "store now, decrypt later" attack model means that current asymmetric cryptography, especially key exchange, is already threatened by future quantum computers, necessitating urgent action.
- Prioritize Hybrid Key Exchange: Adopting hybrid key exchange mechanisms (e.g., Kyber X25519) is critical now to future-proof systems like Spiffy/Spire, hedging against potential vulnerabilities in either classical or quantum-resistant algorithms.
- Leverage NIST Standards: The NIST-standardized Kyber (ML-KEM) for key exchange and Dilithium (ML-DSA) for signatures provide a solid foundation for building quantum-resistant cloud-native infrastructure.
- Ecosystem Readiness: The Go 1.23 release, with mainline hybrid key exchange support for TLS, and ongoing work in OpenSSL are significantly easing the practical adoption of PQC for many cloud-native applications.
- Cryptographic Agility is Key: Building systems with cryptographic agility—the ability to easily swap algorithms, manage short-lived keys, and automate processes—is essential for a smooth and secure migration to a quantum-resistant future.
- Verify and Monitor: Implement robust monitoring to ensure that PQC algorithms are actually being negotiated in the field and that there are no silent fallbacks to non-quantum-safe alternatives due to implementation discrepancies.
About the Speaker(s)
Andrés Vega is an experienced professional and a contributor to the Spiffy and Spire projects. He has utilized Spiffy throughout the last decade of his career across various organizations, demonstrating a deep understanding of its practical applications in securing service identities. While he prefaced his talk by stating he is not a cryptographer, his year-long collaboration with Hugo Landau and the broader cryptography community has provided him with significant insights into the quantum threat and the intricacies of cryptographic systems.
Hugo Landau is a key figure in the cryptography community, leading the technical work on integrating post-quantum cryptography into Spiffy and Spire. His expertise lies in adapting existing cryptographic protocols, such as TLS and X.509 certificates, to incorporate new quantum-resistant algorithms. His work is instrumental in translating theoretical PQC advancements into practical, deployable solutions for cloud-native environments.
Together, Andrés and Hugo represent a collaborative effort between end-users and cryptographic experts. Their work is supported by the United States Department of Defense and partners at Dell Technologies Federal, highlighting the critical importance of their contributions to national defense and broader infrastructure security. They emphasize the value of open collaboration and shared learnings within the open-source community to accelerate the adoption of quantum-resistant technologies.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This talk isn't just another 'quantum-awareness' session; it's a critical, actionable deep-dive into how to actually deploy post-quantum cryptography in cloud-native environments today. The speakers cut through the hype to address the immediate 'store now, decrypt later' threat and provide a concrete path using Spire, Spiffy, and hybrid key exchange. This is real work, not just theory, and it's essential for anyone serious about future-proofing their infrastructure.
Heather Calloway (CISO) — STRONG ACCEPT
This talk effectively translates the abstract threat of quantum computing into a concrete, actionable imperative for security leaders. By focusing on the "store now, decrypt later" attack model, it establishes an immediate business risk that demands executive attention and proactive governance. The demonstration of integrating NIST-standardized post-quantum cryptography into cloud-native environments via Spiffy/Spire and hybrid key exchange provides a credible and practical path forward, moving beyond theoretical concerns to demonstrate operational solutions for critical infrastructure.