Post-Quantum Cryptography: Building Resilience Against Tomorrow’s Threats

F5 DevCentral CommunityAbout 4 min readAug 18, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

  • Post-Quantum Cryptography (PQC): Encryption methods designed to be secure against attacks from quantum computers.
  • TLS 1.3: The latest version of the Transport Layer Security protocol, offering improved security and performance.
  • Cipher Suite: A set of cryptographic algorithms used for key exchange, encryption, and message authentication.
  • Cipher Rule: A specific configuration defining allowed cipher suites.
  • Cipher Group: A collection of cipher rules.
  • SSL Client Profile: A configuration object on the BIG-IP device that defines the SSL/TLS settings for a virtual server.
  • Virtual Server: A logical representation of a server on the BIG-IP device.
  • Handshake: The process of negotiating security parameters between a client and a server.

Configuring a Virtual Server for Post-Quantum Cryptography

The video demonstrates how to configure a virtual server on a BIG-IP device to support post-quantum cryptography (PQC) by enabling TLS 1.3 and using PQC-compatible cipher suites. The existing setup involves a web server behind a BIG-IP device, with a virtual server configured on port 443 using an SSL client profile with TLS 1.2 and standard classical handshakes. The goal is to modify this configuration to use PQC for the handshake process while maintaining the existing encryption for the traffic.

1. Enabling TLS 1.3:

To enable TLS 1.3, the process involves creating a cipher rule and a cipher group.

  • Creating a Cipher Rule:
    • A new cipher rule is created with default settings.
    • Post-quantum algorithms are added to the rule.
    • Default signature algorithms are included to select a range of cipher suites compatible with PQC.
  • Creating a Cipher Group:
    • A cipher group is created.
    • The previously created cipher rule is selected and added to the group.
    • This group now contains the PQC-compatible cipher suites.

2. Creating an SSL Client Profile:

A new SSL client profile is created based on the existing one to inherit settings like certificates.

  • Base Profile Inheritance: The new profile inherits settings from the existing profile, including the certificate (a standard Let's Encrypt certificate).
  • Advanced Configuration: The profile is switched to "Advanced" mode to allow modification of specific settings.
  • Enabling TLS 1.3 and Selecting the Cipher Group:
    • The "enabled options" are modified to explicitly enable TLS 1.3 (implicitly by disabling the older versions).
    • The newly created cipher group ("Arcadia group") containing the PQC cipher suites is selected.
    • Other settings from the base profile are retained.

3. Applying the New SSL Client Profile to the Virtual Server:

The newly created SSL client profile is applied to the virtual server.

  • Virtual Server Modification: The virtual server configuration is updated to use the "Arcadia TLS 1.3 PQC" SSL client profile.
  • Profile Replacement: The old SSL client profile is removed and replaced with the new one.

4. Verification:

After applying the changes, the configuration is verified by accessing the web server through the virtual server.

  • Page Refresh: The web page is refreshed.
  • TLS Version Check: The browser's developer tools are used to confirm that the connection is now using TLS 1.3.
  • Handshake Verification: While the encryption for the traffic remains the same, the handshake process is now using post-quantum encryption algorithms.

Notable Quotes:

  • "The difference when we moved to postquantum will be the handshake algorithm is going to be different."
  • "We're still using the same uh uh encryption for the traffic, but the handshake is now using the postquantum encryption."

Technical Terms:

  • SSL Client Profile: A configuration object that defines the SSL/TLS settings for a virtual server.
  • Cipher Suite: A combination of cryptographic algorithms used for key exchange, encryption, and message authentication.
  • Handshake: The process of negotiating security parameters between a client and a server.

Logical Connections:

The video follows a logical progression:

  1. Introduction: Explains the goal of configuring a virtual server for PQC.
  2. Prerequisites: Describes the existing setup with TLS 1.2.
  3. Configuration Steps: Details the process of creating a cipher rule, cipher group, and SSL client profile.
  4. Application: Shows how to apply the new profile to the virtual server.
  5. Verification: Demonstrates how to verify that the configuration is working correctly.

Synthesis/Conclusion:

The video provides a practical guide to configuring a BIG-IP virtual server to support post-quantum cryptography by enabling TLS 1.3 and using PQC-compatible cipher suites. The key takeaway is that while the encryption for the traffic can remain the same, the handshake process can be upgraded to use PQC algorithms, providing protection against future quantum computer attacks. The process involves creating a cipher rule and group with PQC algorithms, creating a new SSL client profile based on the existing one, and applying the new profile to the virtual server.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.