Skip to main content
Practical quantum computing is close. That brings opportunity, but also cybersecurity risks. Quantum cryptography expert Michele Mosca walks us through the state of the field.

Michele Mosca is a research associate faculty member at Perimeter Institute. He was one of the institute’s first researchers when it was launched 25 years ago. He is also a founder and former deputy director of the Institute for Quantum Computing at the University of Waterloo, where he is a mathematics professor. 

Mosca is a pioneer in the design of quantum algorithms, grappling with both the potential of quantum computers and the security challenges they pose. The first experimental implementation of a quantum algorithm on a physical system was achieved in 1998 by Mosca and Jonathan A. Jones at Oxford University. They successfully executed Deutsch's algorithm using a 2-qubit Nuclear Magnetic Resonance (NMR) quantum computer.

In 2018, Mosca devised a risk framework designed to help organizations determine when they need to transition to quantum-safe encryption. Mosca has also launched several start-ups based on his research, and currently leads the quantum-safe cybersecurity company, evolutionQ.

We sat down with Mosca to talk about the state of quantum computing, the development of quantum error correction codes, threats to national security in the quantum computing era, and how Perimeter Institute can play a role in both the development of quantum computers and in ensuring a quantum-safe future.

“We can use quantum computers to help us advance the great theoretical work we do here, and then it's a virtuous cycle, right? As we gain a deeper understanding of physics – discover new physics – that can potentially be harnessed and enhance quantum and other technologies. So there are all these different roles for Perimeter in this future, and obviously all our colleagues here are excited to be a part of that. 

— Michele Mosca

The following conversation has been edited for clarity and length:

 

Q: How far has quantum computing come since you began your research on quantum computing algorithms as a graduate student at Oxford University?

When I first started in the 1990s, I was one of the early skeptics of quantum computing because it just didn’t seem like it would ever be possible to correct the errors, given the inherent fragility of a quantum system.

But in 1996, researchers (including Peter Shor and A. Robert Calderbank along with, independently, Andrew Steane) discovered it was possible to write quantum error correction codes to deal with that fragility. Quantum computing went from being impossible, to *almost* impossible, which was a big conceptual leap. That’s when I joined the field. I realized, ‘we will eventually bridge this gap’ and be able to leverage noisier quantum systems by making them less noisy.

That was three decades ago. Since then, the lines have overlapped between what we need and what we have. We have validated that initial outrageous hypothesis from 1996. We now know that we can do quantum computing with much noisier systems and less control than we thought we needed in the 1990s. 

We are in a whole new era of quantum computing, and it’s just a question of which platform, which methods, and how quickly this will evolve.

Q: When do you anticipate that we will have practical quantum computers that can solve real-world problems that can’t be solved with the computers we have today?

I try to avoid guessing a date, because nobody can really say. But there is a likelihood, maybe a 20% likelihood, of a material economic impact — that is, real use cases and applications — within five years. Some serious colleagues would say it’s a 50% likelihood within five years. I would say the likelihood grows to more than 50% in 10 years. 

But that doesn’t qualitatively change what we need to be doing now. We are talking about a small number of years for when we might see a significant impact. So we need to be ready to leverage the benefits and also secure against the possible weaponization of these capabilities.

Q: Let’s talk about the benefits. What are the potential applications of quantum computing?

We are just starting to grapple with that question. It is like trying to ask, before we had the internet, what will the internet be useful for? Even when we had it, in the 1990s, we didn’t really know. The predictions we had then did not really capture everything we are using it for today. 

Notwithstanding that, we are optimistic that quantum computers will find use cases where we need to simulate a quantum mechanical system. In trying to simulate new materials or the properties of molecules, for example. These quantum mechanical properties are hard to simulate with the computer resources we have today, but these problems are really suitable for quantum computers. So, we can think about designing new materials or molecules or processes to help us capture, transport, and store energy, or more efficient ways to produce fertilizers. These are the sorts of problems that people are already exploring aggressively and will be able to explore even more once we have enough stabilized quantum bits available to us.

Q: But there are challenges in developing a stable quantum computer. We hear a lot about the “noise” problem that produces errors in quantum computing. Can you describe for us what the “noise” problem is, and how we can mitigate against it?

The noise problem for quantum computers is really the same noise problem we have in classical communications. If we are in a noisy environment, or we are speaking to each other at a distance, we might not be able to hear each other. So, you might ask me to repeat myself. In a sense, you are using repetition or redundancy to correct that problem. Even when we speak, if I misspeak or I don’t pronounce something correctly, the brain, consciously or subconsciously, does this. It will decide (based on past information available to it), “well, obviously, he meant to say this.”

An entire discipline that we call error correction has been developed over many decades to deal with noise in classical computers. It involves looking at what errors have likely occurred and introducing some redundancy, or repetition. It’s never perfect, but you can reconstruct the communication if you understand what errors occurred and correct for that. 

With quantum communication, the challenge is that you can’t really use the same methods that we use in classical computers, because the laws of physics say you can’t copy quantum states. When you look at a quantum state, you destroy its quantumness. So the old methods of classical error correction can't possibly work, right? Except we discovered that you can do it if you do it very deliberately. 

That’s part of the secret sauce: you make sure you interact with the system very deliberately, and only learn what error occurred and don't learn anything else. Over the last 30 years, we have engineered technologies and algorithms (quantum error correction codes) to probe states in order to learn what error occurred, and then correct the error without learning anything else about the quantum state. It’s really fascinating stuff, and this has already moved from a theory to being deployed in commercial platforms.

Q: Let’s talk about the dangers. Could practical quantum computers break the cryptography that we use on the internet today? Can it be a threat to national security?

As with any new capability, adversaries will try to weaponize it for themselves. It's a tool for us, but to them, it can be weapon for compromising their adversaries. This was one of the things that brought great attention to quantum computing from the very beginning, when Peter Shor realized quantum computers could break some of the fundamental encryption codes we use to protect the internet and other global telecommunications — the so-called public key cryptography.

Humans have been doing cryptography more or less the same way for centuries, millennia even, for transmitting shared secrets. If you and I want to share a secret, we exchange a secret key in advance. 

When the internet came along, public key cryptography became the most practical way to secure billions of endpoints around the world. It gave us an automated way to authenticate who we're talking to, so that at least I know it's you who sent the message, and also a way to extract a secret key.

Public key cryptography has enabled the past 30 years of economic growth, because it turned the internet into a trustworthy system, or at least relatively trustworthy system, compared to what it would have been without cryptography. It enabled us to do it at a much lower cost, with much greater scalability than old school methods.

But just as we were starting to use public key cryptography, Peter Shor showed that quantum computers would break the deployed ways of achieving public key cryptography. That is when we realized, ‘it'll take time to fix this, so we need to get ahead of this.’

Today, we’re only a small number of years away from a high likelihood of having cryptographically relevant quantum computers that can compromise these codes and unleash all sorts of potential harm to the digital economy and to individuals. 

But we’ve done a lot of work, even if we’ve been pushed kicking and screaming into it, and despite the market forces, to create classical cryptographic codes that are resilient to quantum enabled attacks. 

There is still a lot of work to be done. We are not out of the woods yet in terms of mitigating known threats. But the important thing is that this has shone a light on the fragility of the digital economy. That gives us a chance to fix it, to make it more resilient, while we still have time.

Q: Is Canada prepared for that future? Are our governments and businesses ready?

Canada has been a global leader in articulating the problem, developing solutions, and coordinating with the global community. We are world-renowned in our understanding of this problem and creating solutions, and have the support of the government through, for example, the Canadian Forum for Digital Infrastructure Resilience. I chair the Quantum Readiness Working Group, which has developed best in class global best practices in preparing for this future. 

But our adoption rate is probably not best in class; it's maybe middle of the road. I would say we are not far behind, but we are not far ahead either. We have a chance to accelerate that in terms of adopting these best practices and deploying the solutions. There is still an opportunity for Canada to emerge as a leader in protecting our critical infrastructures against both the known quantum threats and the emerging unexpected surprises of the future. 

We're seeing strong signals coming from our national strategies and defense strategies. Canadians, both in academia and industry, are ready to step up and enable Canada to be quantum ready in every way, in leveraging quantum capabilities, securing against quantum attacks, and exporting those solutions around the world. We are certainly keen to partner with government and industry leaders to make that happen.

Q: Alongside quantum computing, we are also entering era of artificial intelligence (AI). How will these technologies, which are different, play into each other and change the future?

We are proud of Canada's role in AI. It's yet another globally impactful technology and capability where we have played a disproportionately strong role. We are proud of all our colleagues who've enabled that.

How quantum and AI will interact is sometimes oversimplified, but one direction is clear. AI is certainly helping us design new quantum technologies at the hardware level as well as software techniques, and it will help us find use cases. So, it's definitely a great accelerator of quantum-enabled value creation at many different levels. We need to embrace that, and we are embracing that. 

The reverse (how quantum computers help develop new AI) is less clear, but AI is one of the many potential use cases where there could be positive disruption. Quantum algorithms could potentially  help the fundamental machinery and capabilities of AI.

Sometimes people conflate the two and think that when quantum hits AI, we will have AI on steroids. We don’t know that yet, but it is one potential use case, and where else but in Canada should we be studying that possibility?

There can be a really rich interplay between these two. It's not symmetrical, but again, the fact that Canada is a world leader in both of these areas is really a great opportunity. I know my colleagues in AI and our colleagues in quantum would love to seize those together.

Q: What role do you see Perimeter Institute having in all of this? Where do we fit into the future of quantum computing?

Perimeter plays a really critical role at several different levels. 

The science we do at Perimeter is part of what has enabled quantum computing to reach the point where it is today. 

Fundamental advances in physics can make quantum computing platforms more efficient or help discover new platforms. There always a continual enhancement from the foundations. Remember the electromechanical computers from decades ago? Well, we didn't stop innovating — we went to vacuum tubes and transistors, to the computers we have today. That will happen with quantum technologies of all sorts. The fundamental advances in physics, the materials, the algorithmics, will continue to fuel that process, and Perimeter plays a vital role there. 

Perimeter has also played a critical role in communicating what this is to a broad audience, enabling them to appreciate it and make smart policy and investment decisions. 

We also play an important role in training the next generation of scientists. Some of them go off to industry and some stay in research. The ones in industry are also translators of the capability into actual value creation. 

Another place where Perimeter will continue to play an important role is that we use computers to validate hypotheses. A lot of the exciting hypotheses we come up with at Perimeter can be tested much more effectively if we have a quantum computer.

We can use quantum computers to help us advance the great theoretical work we do here, and then it's a virtuous cycle, right? As we gain a deeper understanding of physics – discover new physics – that can potentially be harnessed and enhance quantum and other technologies. So there are all these different roles for Perimeter in this future, and obviously all our colleagues here are excited to be a part of that.

Q: How do you see the future of quantum computing?

The future of quantum computing is something we can shape. 

Societies around the world need to shape it and not just be helpless bystanders. Enabling the technology is an effort that needs a lot of hard work by many different stakeholders, including scientists and researchers, but also industry and policymakers. 

Then there's making sure it's harnessed in a productive way for the good of humanity. So all the different business models and all the geopolitical considerations are in the hands of people around the world who will need to make wise decisions that really advance the human condition. We can attract the resources and have the right rewards and incentives for everybody to play their part.

It’s an exciting time to be working in this field, and there's a lot of important work to be done, both at the technology level as well as the policy and commercialization level.

I'm quite optimistic. I know there's a lot of challenges, but I think a lot of people around the world are excited about all the value creation capability and want to enable it to create a better world for humanity.

This is part two of an ongoing series about the Future of Physics. Read part one here, and stay tuned for more!

About PI

Perimeter Institute is the world’s largest research hub devoted to theoretical physics. The independent Institute was founded in 1999 to foster breakthroughs in the fundamental understanding of our universe, from the smallest particles to the entire cosmos. Research at Perimeter is motivated by the understanding that fundamental science advances human knowledge and catalyzes innovation, and that today’s theoretical physics is tomorrow’s technology. Located in the Region of Waterloo, the not-for-profit Institute is a unique public-private endeavour, including the Governments of Ontario and Canada, that enables cutting-edge research, trains the next generation of scientific pioneers, and shares the power of physics through award-winning educational outreach and public engagement. 

For more information, contact:
Communications & Public Engagement
Media Relations