Jiran Jigyosecurity announced on August 25 that it has integrated post-quantum cryptography (PQC) based on standards from the U.S. National Institute of Standards and Technology (NIST) into its core security solutions, including email, document, mobile, and content disarm and reconstruction (CDR) products.
The company implemented PQC by focusing on areas requiring secure communication and key exchange, considering the communication structure and security characteristics of each product. Along with the application of PQC to individual products, it has established a system that allows for a gradual transition to next-generation cryptographic systems based on a hybrid structure and crypto agility.
Recent advancements in quantum computing technology have raised concerns about the security of existing public key cryptography, highlighting the need for a transition to PQC. In particular, the 'HNDL' attack, which involves preemptively acquiring encrypted data for future decryption using quantum computers, is identified as a significant threat. This has led to calls for proactive transitions in cryptographic systems, especially for data requiring long-term protection.
NIST is set to finalize ML-KEM, ML-DSA, and SLH-DSA as PQC standards in 2024. In South Korea, the K-PQC national competition is underway, with algorithms for domestic standardization expected to be selected by 2025.
The application method has been tailored to the operational environments of each solution. The email security product 'Spam Sniper' has integrated NIST standard-based PQC into its secure communication environment, while the document security product 'DocuOne' has adopted a hybrid approach based on ML-KEM for key exchange during TLS communication. The mobile security product 'Mobile Keeper' has transitioned its key exchange system for authentication and end-to-end data encryption between mobile devices and MDM servers to the NIST PQC standard.
The CDR-based malware response product 'Sanitox' has strengthened its security framework, focusing on transmission, API linkage, and integrity verification before and after file disarmament. Notably, it has enhanced the security communication and signing/verification systems applied during the storage, transmission, and download processes after safe file generation, increasing the confidentiality, integrity, and authentication levels throughout the entire process of delivering disarmed files to customers and associated systems.
To ensure service continuity during the PQC transition, Jiran Jigyosecurity has adopted a hybrid structure that allows for the coexistence of existing cryptographic methods and PQC. This enables a gradual transition of cryptographic systems while maintaining interoperability in environments where associated systems do not yet support PQC.
Additionally, a common cryptographic interface that is not dependent on specific algorithms or libraries has been implemented to secure crypto agility. By managing algorithm identifiers, parameters, and certificate/key policies based on established settings, the system is designed to allow for the addition or replacement of relevant cryptographic technologies as needed for future changes in cryptographic standards or the application of new algorithms.
Considering global interoperability and applicability, the company prioritizes support for NIST standards while ensuring scalability to accommodate future domestic cryptographic standards and certification requirements within the same structure.
Lee Sang-jun, Chief Technology Officer of Jiran Jigyosecurity, emphasized the need to prepare for the introduction of PQC by considering the data retention period and the time required for transitioning cryptographic systems, rather than waiting for the commercialization of quantum computers. He explained that since currently collected encrypted data could potentially be decrypted by future quantum computers, proactive measures should be taken, starting with data that will be stored for extended periods.
Lee stated, "The timing for transitioning to PQC should be based on the lifespan of the data that needs protection and the time required for system transition, rather than the commercialization of quantum computers."
Cho Won-hee, CEO of Jiran Jigyosecurity, remarked, "The application of PQC is a proactive step in preparing the cryptographic systems of our core security products for future changes in the cryptographic environment. We will continue to support our customers in responding stably to the evolving cryptographic landscape based on our key product lines for email, documents, and mobile security."
Meanwhile, the movement to adopt PQC is expanding into major industries in South Korea. The Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) have broadened their PQC pilot transition project, which was previously focused on the medical, energy, and administrative sectors, to include telecommunications, finance, transportation, defense, and space sectors this year. The feasibility of applying PQC is being verified across major infrastructures, including the National Science and Technology Research Network (KREONET), financial payments, and transportation, defense, and satellite communications.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.

