Search papers, labs, and topics across Lattice.
This paper introduces Quantum Cloud Guard (QCG), a novel three-layer architecture designed for small and medium-sized enterprises (SMEs) to protect cloud data against quantum threats. By employing client-side hybrid post-quantum encryption and self-hosted key management with verifiable signatures, QCG ensures that sensitive data remains secure even in the face of potential quantum decryption capabilities. The architecture demonstrates efficient performance, with key generation and cryptographic operations executed in milliseconds, while effectively filtering out 98.8% of attack traffic.
Quantum Cloud Guard enables SMEs to secure their data against future quantum threats without needing extensive cryptographic expertise or infrastructure.
Harvesting ciphertext from cloud storage needs no quantum computer; decrypting it later does. That gap is the harvest-now-decrypt-later exposure: anything protected by RSA or ECDH today that must stay secret for decades is already compromised. Small and medium-sized enterprises are least able to respond: they neither run the infrastructure on which their data sits on nor employ a cryptographer. Bespoke migration suits firms with security budgets; a managed key service relocates trust rather than removing it. The obstacle is architectural, not cryptographic. We present Quantum Cloud Guard (QCG), a software-only three-layer architecture. No prior SME-oriented system combines its three elements: client-side hybrid post-quantum encryption, self-hosted key custody with client-verifiable ML-DSA-87 signatures on served keys, and an integrated application-layer abuse-prevention gateway. Files never leave the client: each is sealed under AES-256-GCM, its key wrapped to an ML-KEM-1024 public key from the enterprise's key service. The enterprise alone administers it; it signs every key with ML-DSA-87, so a client that pinned it detects substitution. Separating key custody from data custody is the point: a provider holding both can read the data. On a 24 MHz STM32F407, ML-KEM-1024 key generation takes 40.8 ms and decapsulation 44.0 ms; on the server every post-quantum operation stays sub-millisecond, signing adding 0.24 ms per request. The service runs on a 4.49 EUR/month virtual server. Under sustained flooding, the in-process gateway Sentinel Gate rejected 98.8% of attack traffic while a legitimate client's median latency moved from 621 to 625 ms. Being single-source, this shows filtering effectiveness, not DDoS resilience.