Quantum computing: a new horizon for the data economy, privacy and cybersecurity
The advent of the quantum computing era is set to revolutionize the data economy, privacy and cybersecurity. As with all revolutions, it will bring both significant opportunities and also challenges. Although in view of its technical complexity the subject may seem remote, advances in quantum computing concern society as a whole, and professionals in particular, across all areas of the technology industry, including, of course, the legal profession.
Quantum computing is one of the numerous practical applications arising from advances in quantum physics. Since the beginning of the twentieth century, thanks to the discoveries of some of history’s most renowned scientists such as Max Planck, Albert Einstein, Erwin Schrödinger, Werner Heisenberg or Niels Bohr, this area of physics has led to unprecedented advances in our understanding of the physical world and how it works.
This newsletter is not intended to provide a detailed account of the principles of quantum physics. That task belongs to the field of physics itself. However, to provide context for the following sections, it is appropriate to offer a brief introduction to the main principles of quantum theory that make quantum computing possible and consequently, the forthcoming revolution in the data economy.
In essence, quantum theory explains, with remarkable accuracy, the way in which particles, particularly subatomic particles (such as electrons), behave. Studying the matter at this scale has revealed that its behavior does not always conform to what is expected or observed in larger objects.
- In the macroscopic world, with the appropriate calculations, it is possible to determine where a ball will land when it is thrown at a certain speed and angle and is subject to a certain degree of air resistance. In other words, “large” objects follow rules that strike us as intuitive and are consistent with the observations of everyday life to which we are accustomed.
- However, things are not quite so straightforward in the quantum world. Various quantum phenomena give rise to conclusions that seem impossible, yet have been verified with a degree of precision that leaves little room for doubt. For example, a particle may exist in what is known as a “superposition of states”, which, in simple terms, means that it can occupy two different states simultaneously.
Simplifying matters further, one might say that, while an ordinary switch such as the kind found in any home can only be either on or off, a quantum switch can exist in both states simultaneously (on and off), without actually being defined as on or off until it is observed. It is only then, when measuring or observing its state, that the switch is completely on or completely off.
These discoveries, together with other phenomena such as quantum entanglement and quantum teleportation, form part of the theoretical framework of what is known as quantum physics.
Quantum computing is, therefore, the application of these discoveries to the field of computing.
How does quantum computing differ from traditional computing?
As some readers may have guessed, the switch example used above was not chosen by chance.
As we said, in the classical world a switch can only be either on or off. In the quantum world, it could be said that a “quantum switch” exists in a superposition of the on and off states until it is measured. It is only when measured that the superposition “collapses” into one of the two possible states: on or off. This ability to keep multiple possibilities open simultaneously is one of the pillars on which quantum computing relies to solve certain problems with a level of efficiency beyond the reach of conventional computers.
Based on this phenomenon of supervision of states (and others that we will not be discussing here) quantum computing replaces traditional bits, which are similar to traditional switches that are either on (1) or off (0), with “qubits”, or quantum bits, which can exist in a superposition of the on and off states simultaneously. As a result, computing power increases exponentially:
- Two conventional bits can only represent one of four possible states at any given time (00, 01, 10 or 11).
- Two qubits, by contrast, can represent all four of these potential states simultaneously, as they exist in a state of superposition. As more qubits are added, this advantage grows exponentially. With 10 qubits, it is possible to operate across 1,024 possible states, with 50 qubits, computational capabilities comparable to those of today’s most powerful supercomputers could be achieved for certain tasks, with 300 qubits, the number of simultaneous states could exceed the number of atoms in the observable universe.
How these computational capabilities are harnessed falls within the remit of other fields of scientific and technical knowledge. However, for the purposes of this article, it is sufficient to understand that quantum computing performs computations using qubits, taking advantage of superposition (as well as other properties of the quantum world, such as quantum entanglement). In this respect, quantum computing will enable certain operations to be optimized, significantly outperforming in certain aspects, the most powerful supercomputers currently available.
What impact will this technology have in the field of data economy, privacy and cybersecurity?
Quantum computing can significantly outperform traditional computing in certain types of problems, particularly those for which suitable quantum algorithms exist.
For example, through the well-known Shor’s algorithm, quantum computing can factor large numbers into their prime factors with unparalleled efficiency. These types of calculations, which are practically impossible using traditional computing, can have an enormous impact on the data economy, privacy and cybersecurity, as outlined below:
-
Data economy: given that quantum computing enables more complex calculations to be performed at greater speed, its potential impact on the data economy is enormous. Let us consider the possibilities for pattern detection or operational optimization.
- Potentially, quantum computing could speed up the training of AI models, which fundamentally rely on data.
- It could optimize the distribution routes of logistics operators, calculating the most efficient routes for the distribution of products or merchandise. This could lead to significant optimization in the area of online sales for example.
- Another of the most promising use cases lies in science and research. The use of these technologies could be decisive in the development of new medicines and the simulation of complex molecular structures.
The combination of this technology with the abundance of data available today could be revolutionary. In this regard, the growing role of data spaces could prove crucial in enabling information to be shared under the control of independent players, which would allow the optimization of this information through the use of quantum computing. -
Privacy: the impact of quantum computing on privacy and data protection stems largely from the security of personal data and individuals’ private lives, which could be affected by quantum computing attacks. This means that controllers and processors may be required to comply with substantially more demanding information security requirements.
In addition, the impact of this technology raises profound questions in the fields of privacy and data protection, some of which may still be difficult to envisage even today, since the implications for individuals’ fundamental rights will depend on how the tech is adopted. Some of the preliminary questions that arise are the following:- How should a controller manage a security incident in which a hacker steals an encrypted and inaccessible database, but manages to decrypt it in the future using quantum computing (harvest now, decrypt later)? The risk of HNDL is particularly serious in relation to sensitive personal data, trade secrets, health and financial information, children's data, defense-related information and any data that must remain confidential for many years.
- Will quantum computers become concentrated in a small number of countries, whereby access to them by European data controllers could entail international transfers of personal data outside the European Economic Area by controllers situated in Europe?
- What consequences will the use of quantum technologies (such as Quantum Key Distribution (QKD) for securing information) have for data protection? Will technologies of this kind, such as quantum communications, reduce the number of security incidents?
- How does the concept of superposition tie in with the notion of personal data? What type of information does a quantum computer process up until the moment of measurement and collapse? In a set of qubits in a state of superposition, can the qubits themselves constitute personal data, or do they acquire that status only upon measurement?
The answers to these and other questions, which have significant legal implications, will require close cooperation between technical teams and legal professionals capable of grasping and internalizing concepts as complex as those underpinning quantum physics. - Cybersecurity: discussions surrounding quantum computing often turn into discussions about cybersecurity. In simple terms, this is because the powerful calculation capabilities of quantum computing (for example through the factorization of large numbers into their prime factors using Shor’s algorithm), pose a direct threat to some of the pillars that form the basis of the most widely used public-key asymmetric encryption techniques underpinning the security of online communications, such as RSA-based systems.
In other words, sufficiently mature quantum computing technology could potentially undermine the majority of the present-day security measures that protect our digital information and communications. Although encryption measures remain resistant, for the time being, to this type of attack, the threat is already here, as cybercriminals may carry out harvest now, decrypt later attacks, with the intention of decrypting it in the future once quantum computing capabilities make this possible.
This is why it is important to recognize this reality without delay, so that solutions can be found sufficiently far in advance. Indeed, a number of organizations are already developing and publishing cryptographic standards designed to withstand attacks enabled by quantum computing capabilities. For example, the NIST (National Institute of Standards and Technology), a US State agency attached to the US Department of Commerce) has already approved post-quantum cryptography standards, namely FIPS 203, FIPS 204 and FIPS 205, which consist of classical cryptographic algorithms designed to protect against future attacks by quantum computers
Where are we now and when will quantum computing become a reality?
The short answer is that quantum computing already exists. Indeed, the concept of quantum computing began to take shape back in the 80s, due in part to another towering figure in physics in general, and quantum physics in particular: Richard Feynman, who argued that, if nature is quantum in nature, then the only way to simulate it is through quantum simulation. That is, quantum computers were needed to perform computations of “quantum” complexity.
Considerable progress has been made since then. Today, a number of organizations already have quantum computers capable of performing computations using qubits. However, it is true that quantum computing remains an emerging technology that is still far from reaching its full potential and, at present, has yet to achieve widespread adoption across the business community. Although the technology is useful for specific, tailored use cases, work continues on developing systems with broader applicability that are easier to access and operate.
Quantum computing is attracting substantial investment and huge growth in its capabilities is expected in the coming years. An exciting race is underway at present between some of the world's leading technology companies, to develop general-purpose quantum computers using different approaches and techniques to overcome the obstacles facing these technologies (i.e. the instability caused by qubit decoherence). The widespread maturity of quantum computing, once the technology achieves a sufficiently robust level of adoption, is expected towards the end of this decade or the beginning of the next, although any forecast in this area should be treated with caution.
Although this may seem a long way off, the existence of threats such as those described above and the complexity of the issues involved, means that preparations for that moment must begin now. Indeed, the state players are already working on these preparations, as is clear from the publication of the Spanish Quantum Technologies Strategy by the Ministry for Digital Transformation and the Civil Service, or the Quantum Europe Strategy published by the European Commission. The practical question that needs to be answered is: can my organization replace cryptographic algorithms, certificates, protocols, libraries and providers without having to rebuild its systems from scratch? The European roadmap for the transition to post-quantum cryptography precisely emphasizes the need for a coordinated transition and for stakeholders to be informed about the quantum threat to cryptography.
Quantum computing should not be seen only as a future technological promise. For many organizations, the effects of quantum computing will begin to be felt even before general-purpose quantum computers capable of breaking today's widely used cryptography come into existence. The risk of harvesting information today for decryption tomorrow, the need to inventory cryptographic assets, the transition to algorithms resistant to quantum attacks, and the review of contracts, systems and security policies, all make this a current data governance challenge. The question is therefore not just when will quantum computing arrive, but whether companies, the authorities and legal professionals will be ready when its effects stop being hypothetical.
