Back
Ronan Kelly
Chief Technology Officer of The EMEA & APAC Regions, ADTRAN HOLDINGS INC

Security considerations in a world of bandwidth & compute resource abundance - Ronan Kelly, Adtran

🎥 Apr 15, 2024 📺 Netnod AB ⏱ 30m 👁 40 views
Security considerations in a world of bandwidth & compute resource abundance - Ronan Kelly, Adtran Netnod Meeting 2024.
Watch on YouTube

About Ronan Kelly

Ronan Kelly, Chief Technology Officer for the EMEA and APAC regions at Adtran Holdings, has been a frequent speaker at industry conferences in 2023 and 2024, discussing the state of fiber broadband deployment, network security, and market consolidation. In a September 2024 interview, Kelly stated that the UK fiber buildout is continuing at a "record pace" and that subscriber additions are outpacing European peers at a similar stage of deployment, arguing that negative industry commentary is "not founded." He has also discussed the UK market's adoption of XGS-PON technology, describing it as the "most advanced fiber-to-the-home market in the Western world." Kelly has predicted that the highly fragmented UK market will consolidate down to roughly five major players, noting that rising interest rates have exposed weaknesses in some alt-net business models. Kelly has also focused on security implications of bandwidth abundance, stating in a 2024 presentation that consumers now have cost-effective access to more broadband capacity and compute resources than ever before, creating opportunities for both innovation and malicious actors. He has warned that quantum computers, while not "democratized" soon, will become accessible to powerful actors and pose a threat to current encryption methods, noting forecasts that quantum computers could crack RSA 4096 encryption by 2029. Kelly has highlighted Adtran's work on quantum-resistant cryptography and open, disaggregated network architectures, stating that the company deliberately moved away from vendor lock-in tactics to give customers more choice. He has also cited labor shortages as the number one risk to deployment targets, based on a poll of over 300 operator attendees at an Adtran event.

Source: AI-verified profile updated from Ronan Kelly's recent appearances. Browse all interviews →

Transcript (13 segments)
H
Host0:01
So the next speaker will be Per Nann, the CTO of Sunet. He's also on the board of the Fiber to the Home Council Europe, access networks, IPTV platforms, microwave radio, and SDN principles. His board-level experience includes Inex, the new IP agency, and he has served as president of the Fiber to the Home Council Europe. So please join me in welcoming Ronan to the stage.
R
Ronan Kelly0:35
Good evening everyone. I can barely hear myself back here, and I'm conscious that between myself and the next speaker, we stand between you guys and the bar, which is never a good place for us to be. So I'll run through this reasonably quickly. We're entering into a new era. For probably the first time ever, subscribers across the developed world can cost-effectively access more broadband capacity than they could ever possibly hope to consume. And in a similar fashion, they have availability through the cloud to more abundant and more numerous compute resources, again super cost-effectively, than ever before. With this comes fantastic opportunity for innovation on one side, but equally, as with every part of society, we have bad actors in the world as well, and fantastic opportunity for people to use these resources and potentially cause havoc with it. I'm delighted to say I recognize a few of the faces in the audience, but this audience here is quite a new audience for me in general. So I'm conscious that you probably don't know me. As mentioned earlier, I'm at Adtran, Chief Technology Officer for Europe, Middle East, and Africa. I have a curiosity: how many of you in the audience know who Adtran is? Maybe just bring your eyes up at what we do. Okay, so it's a reasonable mix. For those of you who don't know what we do, Adtran very much plays in the optical space. So we do fiber-to-the-home solutions, we do optical transport solutions, we do timing and sync solutions—we provide the timing and sync solution for that part—and we also do a raft of carrier-grade solutions as well as carrier-grade. But in addition to that, we have a side business called Adtran Network Security, and that business is focused on the most advanced encryption and decryption solutions that are embedded in the industry, through solutions that partake in quantum key distribution, etc. Part of what I want to touch on today is, as society is evolving and as we're moving forward with more and more ultra-high-capacity connectivity solutions, but also compute solutions, there are knock-on implications with regard to the security of networks as they evolve out there. So I want to touch on some of the key things that we need to give consideration to. I saw earlier one of the speakers asked for a show of hands for those that are involved on the security side of the industry, and I don't know if any of you guys are still in the room. Maybe just figure out if you are. There's a couple. Okay, I'm going to apologize to you. I'm not from the security side of the industry, okay? I'm an access guy. I've always been an access guy. But I was conscious we were going to have a mixed audience here today, and so some of the things I need to touch on, I need to explain in layman's terms for people that are not on the security side of the industry. If I make a ham-fisted job, I apologize for it, but I've run it past a few people and they seem to just try to get across one point, so hopefully it resonates.
First of all, let's get a feel for where we're at in regard to fiber-to-the-home coverage in Europe. This is data that's collected every year on behalf of the Fiber to the Home Council Europe, which is an industry lobby group, if you will, for all the fiber operators and fiber equipment vendors in Europe. This data is collected by an organization called IDATE. Essentially, where we've gotten to within Europe now at this point in time is very, very narrowly shy of 65% of European households can now access a dedicated full fiber connection into their premises if they choose to do so. Within the next four years, we estimate that that figure will be as high as 95% of European households will have access to a full fiber connection. The knock-on implication of this is, as we get more and more fiber built out there, and particularly in areas where we've got what I describe as infrastructure-based competition—whether it's multiple fibers being available to each premise or whether it's other mediums such as cable with DOCSIS 4.0, etc., that are multi-gig capable—we start to see a lot of competition between carriers, and that starts to put a lot of downward pressure on price points. But it also causes the marketers within those operators to start to offer more and more capacity. We saw this play out with the mobile space, where we've now got to the point where you can get as many minutes as you want everywhere in the world and as much data as you can eat for pretty much a fixed fee in most of the market. In a similar fashion, what you see is just a sample of the sort of value that is available in these markets across Europe. What you can see now is gigabit connectivity for most premises—whether it's a household, whether it's an enterprise, or a small business—it's coming in at somewhere between 25 and 50 euros per month. If you think about that as exceptional value, you know, a few years ago you would chew through 25 megabits very, very quickly. So the utility you get for that spend is amazing. However, that's not the best value that's available. If you look at the Italian market, for example, as seen up there, they're doing five gigabits per second at 15.99. In the UK market, we see services now as high as 8 gigabits per second being made available. Or in the Swiss market, most of the big operators in the Swiss market now are doing 10 gig symmetric services, and they're doing them in the range of 49 to 59 Swiss francs, so around 50 euros per month. Again, exceptional value, very, very affordable. I was just back in the US last week meeting with Google Fiber, and they've just launched a service there into the US marketplace offering 20 gigabit per second symmetric for $204 or $250 per month. So again, massive amounts of capacity being put into the marketplace for very, very little money. Now you probably ask yourself who the hell needs 20 gigabit per second, particularly in the consumer space. If we look back 14 years ago, we asked the very same question as to what was Google thinking when they launched 10 gigabit per second into the consumer space for $79 per month. Today they still charge $79 per month, so they've managed to avoid the race to the bottom because they used the first-mover advantage in getting that gigabit connectivity out there. What we've also seen now is in the US market, you see it on the pie chart behind me, the percentage of households that now use what I describe as very low capacity broadband—so up to sort of 100 meg per second—in the North American market is now 10% of households. It's a tiny portion. Over 33% of the households are now taking gigabit-plus service rates. So if you think about that, that's 40 million households in America that have a gigabit into them at this point in time. It's a huge amount of capacity into a huge amount of houses, with a huge amount of people who haven't got a clue how to secure that sort of capacity and lock it down.
When we think of hazards in society, quite often we think of radioactive risks, we think of biological risks, we think of chemical risks. But when I look at a country like Sweden or any of the digitally advanced societies that are out there, so much of the national infrastructure, so much of the systems that the citizens within those societies interact with on a day-to-day basis, are predicated on the digital infrastructure being available and operating as it should do. Yet very few people ever think about, in the scheme of national risks, what happens if the digital infrastructure goes down. I've been talking to a few people about this recently, and some of the doomsday-type scenarios: if the digital system went down completely and people couldn't get money out of the banks and the electrical grid went down, you're probably two or three days away from anarchy in any modern society nowadays. So the importance of these digital systems is really, really critical. As we march towards that 95% and onwards towards 100% full fiber being available, what we will see is all the traditional copper mediums will get switched off, just because of the energy inefficiency that goes with them. So cable will go away over time, twisted pair is already going away, and we'll become full fiber societies. And there are some challenges with that, because quite often most people in society—those that work in fiber are probably aware of this, but most people don't work in fiber, most people are just consumers of the services that go over it—fiber itself, from a physical security point of view, is not a particularly secure medium. If I want to feed off the data that's going through a fiber pair, all I have to do is bend it, and a certain percentage of the light will leak out of that pair. I've drawn it out kind of illustratively behind me there. You can see the micro-bend being put on the yellow fiber, and you can see the red light leaking out of it. Any of you who've ever worked with a fiber tester can see this yourselves. It's very, very simple to do. We can put basically a bending coupler onto that to reflect that light then off to another fiber pair and feed that into a system that will pull in that information that's going through it. We have a partner—Adtran is a partner in Germany, TÜV and TÜV SÜD actually have a demonstration lab that shows this, where they've got a video feed running across a fiber, they put a micro-bend coupler onto it, and they put the video feed into a separate system, and they can watch the video on three screens rather than two, just by showing this micro-bend capability on it. Now there are some solutions that are available within the industry that help with this. Things like bend-insensitive fiber can minimize the amount of leakage you get when you put those bends on the fiber. There are other benefits that go with that, that you can deploy in more difficult scenarios, but it does improve the security a little bit. Similarly, there are fiber monitoring solutions, so that if somebody does introduce a micro-bend onto the fiber, you can pick up on that and you can detect where on the fiber it is and dispatch a crew to try and work out what's going wrong. But the problem is, we've got hundreds of millions of kilometers of fiber already deployed around the world today, and none of it—or a very, very tiny percentage of it—is built with bend-insensitive fiber, and very little of it has these fiber monitoring solutions available on it today. So the bulk of these fibers that are going to cover off 95% of European households in the next four years will not have any of that capability built into it. So physically, it's insecure. I think that's one of the points that was raised earlier: whether you were inside the network or outside of the network, it's all irrelevant. Just work on the assumption that everybody's inside the network and work on the fact that it is insecure.
Thankfully, we do have encryption with most of the fiber-to-the-home technologies. With pure native Ethernet, we don't, but when we use things like active Ethernet for point-to-point fiber-to-the-home services, we have 128-bit AES encryption built in. In a similar fashion, with GPON technology, which is the most ubiquitous fiber technology deployed in the world today—there's over 300 million households today serviced globally with GPON—with that technology, we've got 128-bit encryption just in the downstream direction, because it was felt the light in the downstream direction on a PON network, if you look behind me there, the bottom connection there—I'll get out of the way of it so you can see it—light goes down one fiber, goes into what we call a passive optical splitter, and that same light then gets sent down to every household that's connected into that splitter. So inherently, it was deemed to be insecure, so they thought, 'Hmm, might be a good idea to encrypt this stuff.' So they did introduce 128-bit encryption in the downstream direction. But because of what I showed on the previous slide, subsequent PON standards like the 10 gig XGS-PON and the new 50 gig symmetric PON standard that's making its way through into the industry at the moment now have bidirectional encryption involved in them, and they've also stepped up the ante now where it's 256-bit encryption, which just means it's going to take longer for it to be hacked. With encryption, you've got to exchange encryption keys so that you know what way to encrypt the data that you're sending down, and the receiving party knows how to decrypt the data when they do receive it. Now you can go down the model of pre-shared keys. In its most basic form, that could be somebody handing off an envelope with an algorithm to say, 'This is how you do it.' The problem with that is it doesn't scale very well, it's very expensive to distribute keys, and it's inherently fraught with security risk, because who's to say that the key that you sent out there physically didn't get intercepted along the way and somebody else has a copy of it? There are a lot of public key exchange mechanisms available where over public mediums like the internet, we can use things like Diffie-Hellman and RSA to securely be able to pass a key between two entities so that they can then encrypt either on an asymmetric basis—each one is using a different key—or on a symmetric basis where they both got the same key. To do it in very simple terms, just so you can get a feel for how that might work over a public network: if we've got Alice and Bob, which are your classic names that crop up in every encryption example that's out there, if Alice wants to send Bob a sensitive message that she wants nobody else to read, she'll put it into a container, she'll put a lock on the container, and she'll send it over to Bob. Bob can then put a lock on that container and send it back over to Alice, and Alice can remove her lock and send the container back over to Bob. In that scenario, Bob can remove the second lock off it, and now he has access to the information that was inside. This is the basic principle: it has never traversed the public medium in an unlocked status or an unencrypted status, in our terminology. Now that was the very, very simple—you know, 'for dummies' or for me, to be honest with you—overview of key exchange and how we can pass keys securely between entities over a non-secure medium.
But when we start to look at the more realistic mechanisms that are being used out there, this is an example where there are two primes being used to make a key. These are the sorts of scale of the prime numbers that are used. They're combined, they're multiplied together to make an individual key. Two very, very large numbers will create a key value that we refer to as n, and that key value gets shared as part of the key exchange process. Now if somebody wants to be able to decrypt your information, they have to be able to reverse engineer n using factorization to get back to the two original numbers. So if you remember the size of the two original numbers that then went in to make that very large number, trying to guess that, trying to reverse engineer that, would be very, very difficult for anybody to try and work out. That example there is a 496-bit example of an RSA key length. To give you a feel for if a traditional computer was trying to crack that, a classical computer is typically doing it in an in-series type approach, where you're trying every path that's available: 'Is it this? No. Okay. Is it that? No. Is it that? No.' And that can take a long, long time to go through every variable that's available out there. To put it in perspective, a 2048-bit integer key could take up to 4.7 billion CPU years to crack. So hence, we tend to look at RSA encryption as being pretty secure. It takes a long, long time for classical computers to be able to break that encryption. But the challenge we've got is quantum computers are coming over the horizon, and quantum computers approach things slightly differently. Now when people think about quantum computers, and particularly in the context of security, a lot of people gravitate towards cracking the data itself, the encrypted data. But the primary focus for quantum computers is not to focus in on the data; it's to try and capture the key exchanges and focus in on cracking the key exchanges. Because once I can crack the key exchanges, I can get the key, and then I can decipher all the data that's involved in that. So it's really the focus in on that piece of things, as opposed to taking massive volumes of data and trying to crack all that data—that would still take, even for a quantum computer, a huge amount of time.
If we do a comparison between a classical computer and a quantum computer, with a classical computer we typically have two states for every bit: a zero or a one. Whereas with a quantum computer, a quantum computer uses what they call qubits. With a qubit, a qubit can basically see each state simultaneously through what they call superposition. With a classical computer, if I've got a zero and a one, I've basically got two unique values involved in that. Whereas the same equivalent number in qubits, I would have four unique values within that. To give it a slightly better feel for how this starts to scale, if I take three bits, for example, with three bits I can get two to the power of three, or eight unique values, on a classical computer, and it can digest them, if you will, one at a time in series effectively. Whereas with a quantum computer, I still get two to the power of eight, but the quantum computer can process the eight values simultaneously at the same time. So this is where you start to get the exponential with it. The larger the number of bits that you're processing in one single chunk, a quantum computer can do that in parallel. To give it a sense of scale, 300 qubits can simultaneously address more values than there are particles in the universe. So from a processing power point of view, massive, massive potential for processing power. In the context of trying to crack an algorithm based on taking guesses with regard to what the encryption key was, etc., you can see very quickly you can move through it much more rapidly. So to go back to our maze example, it's a scenario like this where basically you can come up with a hundred different options, or a thousand different options, or a thousand million different options at the exact same time to work out what your path is going forward.
Is it all doom and gloom? This is the worrying bit. With all of this, when we look at quantum computers, we have a challenge with the qubits, and that is around their stability. Qubits can be interfered with very, very easily. All it takes is a stray photon to interact with a qubit, and all of a sudden the state that it was set to will change to something else. So effectively, what they're doing in quantum computers is utilizing sampling, where you'll have multiple physical qubits, and those physical qubits then, by taking sampling across them, will form a logical qubit. The logical qubit is the value that you're trying to—if you will—it's the error-corrected value that you should utilize coming out as an output out of the quantum computer. Where the state of the art is currently at the moment, you're typically looking at for every single logical qubit, you require roughly about 100 physical qubits to get you to a state where you've got a reasonable degree of reliability that you can count on for processing information. Now where this becomes important is when we start to apply a quantum computer to cracking the RSA encryption technologies that we have. Depending on the complexity of the key—whether it's a 1024-bit key, a 2048-bit key, or a 4096-bit key—you can see on the chart behind me there where it shows that for a 4096-bit key, I would need in the range of about 9,000 logical qubits, or to put that in perspective again, the multiplier of 100, I'd need the bones of about a million physical qubits to be able to do that. Now if we look at the trajectory with regard to the evolution of quantum computers that's being forecasted at the moment, to do a million qubits—and to be quite honest with you, even to do 200,000 qubits, which is what we would need to crack RSA 1024 in about 50 hours of compute time—we're really looking about 2028 before we believe we'll have that sort of capability available within a quantum computer. Very quickly after that, by the time you get to 2029, you'll have that up to the million physical qubits that you would need to do RSA 4096. So again, arguably a very dim picture that we're painting with regard to the security of data transfers as we go forward in the world. But it's important not to lose heart with this, because remember, quantum computers—you can't go down to your local electrical store and pick one up. These are very, very sophisticated scientific instruments. They're not PCs like we know computers. So there's a very limited number of people that have access to this technology and the capabilities that it delivers. But also, it comes with an absolutely massive cost as well. Now I'm conscious from one of the speakers earlier that they talked about state actors being involved in espionage, etc. So unfortunately, some of those bodies who do have access to massive resources with regard to capital, etc., to fund these projects, some of those aren't necessarily always the best actors in society. So we shouldn't ignore it.
To that end, NIST as an organization for the last number of years—I think it's like five or six years—have been running a post-quantum encryption standards project. From that, there have been a number of candidates that have been brought forward that will allow for encryption that will stand up to quantum compute hacking attempts, effectively, if you will. Some of those approaches that they're using: you've got the lattice-based approach, and there are two projects as part of that, Kyber and Dilithium. One is around the key encapsulation method, and the other is focused around digital signature algorithms. With that, there's also a hash-based quantum encryption approach called Sphincs. Those three are the three prime candidates that are being pushed forward by NIST. But then there are other approaches as well. So you have the McEliece cryptosystem, you have the Niederreiter cryptosystem, and then you have the QC-MDPC encryption system, plus multivariate and the supersingular isogeny, which I'm not even going to attempt to try and explain what that's about. Very quickly, you'll understand when you start to delve into this area of research, there are a lot of rabbit holes that you can go down very, very quickly, and none of them are uncomplex, put it that way.
Quantum key distribution is deemed as one of the key methods for being able to securely pass keys that will be able to stand up to the activities of a quantum computer. But if you can't exchange the key in an easy fashion, if you've got to physically distribute keys, we're back to the same problem that we had before. So quantum key distribution is using a concept around quantum entanglement, basically. Quantum entanglement is where I've got two quantum bits that will mirror each other's state, and they can be geographically separated by tens, hundreds, thousands of kilometers, etc. And they've got a unique property that goes with them, which is basically you can't interfere or interact with those bits without breaking that state. So if I go back to the previous slide just very briefly, in a quantum key distribution system, you have your classical fiber for transmitting data—that's per normal, nothing unusual there. But then you have a separate optical channel for distributing the entangled photons to each end of the connection. In that scenario, that could be a fiber connection or it could be a free-space optic connection, but it is optical. If somebody comes along and tries to observe those keys that are being distributed across that via the entangled photons, the state of those photons will change. This is based on what's known as the no-cloning theorem. So essentially, you end up with a scenario like what's behind me there, where essentially if there are eavesdroppers along the line of the fiber path or the optical path that the entangled photons are being passed along, when they observe those photons, they will change the state of them. As part of the process then with quantum key distribution, we're passing photons with information in there, and as part of that, we're using the phase of the photons—whether they're vertical or horizontal, or whether they're negative 45 degrees or positive 45 degrees. For each bit, the sender will change the phase, but also the recipient needs to be changing their phases too to be able to intercept those photons when they arrive and make sure that they get through. The polarity of that, if you will, they will exchange between them what polarity they sent the data stream with and what polarity the receiver tried to apply to receive that data stream. Then when they juxtapose the two of those together, they will see where they had matches. Where they had matches, the bit—whether it's a one or a zero—should also match. And if it doesn't match, they know that somebody has interfered with the key exchange, and they know not to use it. So that keeps your key secure as you go forward.
In summary, quantum key distribution alone is not fundamentally secure. There is an approach that is widely identified as fundamentally secure called OTP, or one-time pad. So for the moment, the recommendation is you still have to focus in on things like physical security. Obviously, your key exchange needs to be very, very secure as part of things, and you need to focus in on secure encryption and authentication as part of it. But if something absolutely has to be secure and uncrackable, the only method that is available today within society, within industry, is the one-time pad approach. That's effectively where you're taking every single character and encrypting that with a matching character equivalent in your encryption algorithm. So effectively, you double up on the volume of data that you've got to send across, and you've got to change those keys every single time. So with OTP, you transform the encryption problem into a key exchange problem, because you've got to try and get those keys across for every packet that you're sending across the network. So in summary: first of all, fiber ubiquity really does need to be matched by ubiquity of mitigation techniques as well in the industry. Consumers are being enabled with what I describe as digital weapons of mass destruction—gigabit pipes into every single household as we go forward. And remember, it's only gigabit because that's what the technology is doing today. The fiber medium allows for much, much higher capacities than that. So we've got to plan for people who are not sophisticated in securing that sort of capacity. How do we deal with that when they become compromised? In the near term, AES and RSA secure mechanisms are good for the midterm, but we do need to keep an eye to the future with regard to what quantum is bringing over the hill, and the approaches that are being developed in the background to address the challenge as quantum computers become more ubiquitous. But closing point, I suppose, is quantum still has many, many hurdles to cross. It's not going to be democratized, I don't think, any time in our lifetimes. But it will make its hands into powerful actors across the globe, and we do need to be mindful of that as we go forward. Thank you.
H
Host29:43
Okay, is that a stretch or a question? It's a stretch. Okay, well you covered so much ground there, Ronan. Thank you so much, and perfectly on time. Thank you so. Once again, did you have a question? Sorry. Oh, sorry. There's lots of stretching going on. Once again, please join me in thanking Ronan for a fantastic presentation. We come to the last speaker of the day, and who better to finish out the first day than...
We come to the last speaker of the day, and who better to finish out the first day than...