This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com

Microsoft 敦促进行威胁建模,为后量子密码学迁移做准备

Microsoft 敦促进行威胁建模,为后量子密码学迁移做准备 Petri IT Knowledgebase

Petri IT Knowledgebase

Publisher

Aug 17, 2026 at 1:30 PM UTC · Updated 3 天前 · 2 分钟阅读

Microsoft 敦促进行威胁建模,为后量子密码学迁移做准备
Image via Petri IT Knowledgebase

核心要点:

  • 威胁建模可以帮助组织发现未记录的加密依赖项。
  • Microsoft 建议将 TLS 1.3 作为采用后量子密码学的基础。
  • 企业应评估加密敏捷性,并准备采用 ML-KEM、ML-DSA 和更强大的加密标准。

Microsoft 正敦促各组织利用威胁建模来发现可能随着量子计算发展而变得脆弱的加密依赖项。该公司强调,尽早识别这些风险可以帮助企业为向抗量子安全的转变做好准备,并避免在过渡期间发生代价高昂的中断。

过渡到后量子密码学 (PQC) 的最大挑战之一是,许多组织对加密在其系统中的使用方式缺乏全面的了解。加密功能可能嵌入在操作系统、第三方软件、云服务、硬件或定制应用程序中,这使得它们难以识别和评估。Microsoft 指出,用抗量子替代方案替换易受攻击的算法需要组织发现这些依赖关系,评估其风险,并确定如何在不中断现有操作的情况下迁移它们。

根据 Microsoft 的说法,威胁建模可以通过使组织能够检查资产、数据流、信任边界和安全控制来缩小这一差距,从而发现可能未记录的加密依赖项。它提供了一种结构化的方法来分析系统设计,识别潜在的安全威胁,并确定降低这些风险所需的保护措施。

PQC 迁移的关键步骤有哪些?

为了支持后量子密码学规划,安全团队需要详细检查其加密环境。这包括识别正在使用的算法、协议、密钥大小和安全配置,了解谁负责管理加密组件,评估现有的实现是否可以在没有重大中断的情况下升级,并审查加密密钥是如何生成、存储、轮换和退役的。

组织还应评估敏感数据是否可能暴露于未来的“现在收获,以后解密”攻击中,即今天收集的加密信息一旦强大的量子计算机问世,就可能被解密。

TLS 1.3 成为后量子安全的基础

Microsoft 敦促各组织评估现有的加密机制是否具有抗量子性,并为升级易受攻击的技术提供了路线图。该公司详细介绍了一些迁移步骤,包括从 1.2 迁移到 TLS 1.3,以及采用将传统加密与 ML-KEM 相结合的混合 TLS 1.3 密钥交换机制。

还建议用 ML-KEM 替换 RSA 和基于椭圆曲线的密钥建立方法,并向更强大的安全标准(如 AES-256、SHA-384)和后量子数字签名算法(如 ML-DSA 和 SLH-DSA)过渡。这些变化可以帮助组织加强防御,并为量子安全的未来做好准备。

Microsoft 强调 TLS 1.3 是采用 PQC 的基本要求。旧版本的 TLS 不支持量子弹性连接所需的混合后量子密钥建立机制。

Microsoft 指出,对于使用 Azure PaaS 服务的组织,云提供商通常在责任共担模型下管理具备 PQC 能力的基础设施的实施。然而,客户将负责了解其依赖关系并设计具有加密敏捷性的应用程序,这将允许在未来以最小的中断进行加密更改。

Microsoft 计划过渡 其关键产品和服务到后量子密码学,到 2029 年,由于日益增长的量子计算风险。该公司表示,组织应首先建立加密算法、协议、资产和依赖项的详细清单,以识别漏洞并规划迁移。

Sourced by

Originally reported by Petri IT Knowledgebase

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

0

Applause

Was this article helpful?

Article Intelligence

Topics

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium

Keep Reading

相关报道