AT&T PQC

AT&T, Palo Alto Networks Introduce Quantum-Ready SASE Architecture to Address Future Encryption Risks

AT&T Business and Palo Alto Networks have introduced a quantum-ready secure access service edge (SASE) architecture designed to help enterprises prepare for the eventual threat that quantum computers could pose to today’s encryption standards, according to an AT&T blog post.

The companies said the new Quantum-Resilient SASE Fabric integrates post-quantum cryptography (PQC) into cloud-delivered networking and security services, allowing organizations to begin adopting quantum-resistant protections without replacing existing network infrastructure.

The announcement reflects a broader movement across the cybersecurity industry as telecommunications providers, cloud companies and security vendors begin incorporating quantum-safe encryption into commercial products. While cryptographically relevant quantum computers capable of breaking widely used public-key algorithms do not yet exist, governments and security experts have increasingly warned organizations to begin migration efforts now because sensitive data stolen today could potentially be decrypted years later once sufficiently powerful quantum computers become available.

The concept, often referred to as “harvest now, decrypt later,” has become one of the primary drivers behind early adoption of post-quantum cryptography, particularly among organizations that manage information with long confidentiality lifetimes, including governments, financial institutions, healthcare providers and critical infrastructure operators.

According to the companies, the new offering combines AT&T’s global network infrastructure with Palo Alto Networks’ Prisma SASE platform, embedding quantum-resistant cryptography into both networking and security services rather than treating it as a separate security layer.

SASE architectures combine wide-area networking and cloud-based security services into a unified platform, allowing organizations to secure users and applications regardless of location. The approach has become increasingly common as enterprises support hybrid workforces and distribute applications across cloud environments.

The companies said in the post the quantum-ready platform uses hybrid cryptographic techniques that combine traditional encryption with post-quantum algorithms. This allows systems to remain compatible with today’s infrastructure while introducing protections intended to withstand future attacks from quantum computers.

Rather than replacing existing encryption outright, hybrid key exchanges use both conventional public-key cryptography and quantum-resistant algorithms simultaneously. If one algorithm were eventually compromised, the second continues protecting encrypted communications.

Palo Alto Networks said its implementation follows Internet Engineering Task Force standards for hybrid cryptography, including RFC 9370, RFC 9242 and RFC 8784.

The companies also said control-plane communications within the platform have been migrated to Transport Layer Security (TLS) 1.3, the latest version of the internet security protocol used to encrypt communications between systems.

According to the announcement, all operational telemetry and network metadata are also encrypted using TLS 1.3 while allowing customers to keep operational data within selected geographic regions to satisfy data residency requirements.

One of the central features highlighted by the companies is what they describe as crypto-agility — designing systems so cryptographic algorithms can be updated through software rather than hardware replacement.

That capability has become increasingly important as governments finalize migration guidance following the publication of the first standardized post-quantum encryption algorithms by the National Institute of Standards and Technology (NIST). Because cryptographic standards will likely continue evolving over the coming years, many organizations are emphasizing infrastructure that can adopt new algorithms without requiring large-scale equipment replacement.

The companies said software updates will allow future cryptographic algorithms to be deployed across the platform as standards mature.

The announcement also addresses hardware security.

Palo Alto Networks said its Prisma SD-WAN ION appliances include Secure Boot technology and Trusted Platform Module (TPM) 2.0 hardware, creating a hardware root of trust that helps verify system software has not been altered before devices start operating.

The TPM stores cryptographic keys and device credentials while Secure Boot verifies that only trusted firmware, operating systems and applications are executed during startup.

Beyond cryptography itself, the companies emphasized operational simplicity.

According to AT&T, organizations increasingly operate across multiple transport technologies, including fiber, 5G, Multiprotocol Label Switching (MPLS) networks and public internet connections. Applying consistent security policies across those different network types has become a growing challenge as enterprise networks become more distributed.

The companies said the new platform enables organizations to apply post-quantum protections consistently regardless of the underlying transport network.

They also said newly deployed branch offices can automatically receive quantum-ready security policies using zero-touch provisioning, reducing manual configuration requirements as organizations expand.

The announcement further positions the platform as helping organizations prepare for evolving cybersecurity regulations.

The companies cited Europe’s Network and Information Security Directive 2 (NIS2) and Digital Operational Resilience Act (DORA), along with U.S. guidance including the National Security Agency’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), as examples of regulatory frameworks increasingly encouraging or requiring stronger cryptographic protections.

While most existing regulations stop short of mandating immediate deployment of post-quantum cryptography, many governments have begun publishing migration roadmaps encouraging organizations to inventory cryptographic assets, develop transition plans and begin adopting quantum-resistant technologies over the remainder of the decade.

Another area of focus is securing remote locations with the companies indicating that enterprises increasingly operate from distributed environments including retail stores, regional offices, warehouses, healthcare clinics and mobile workforces connected over 5G networks.

To secure those environments, the platform uses a hybrid public key infrastructure that issues both classical and quantum-resistant digital identities for connected devices.

According to the AT&T post, maintaining dual credentials allows organizations to preserve compatibility with existing infrastructure while establishing a migration path toward fully quantum-resistant authentication in the future.

The announcement also highlights Service Provider Interconnect technology that directly connects Palo Alto Networks’ security platform with AT&T’s private network backbone.

According to the companies, routing traffic directly through the provider network rather than relying solely on encrypted tunnels over the public internet helps maintain network performance while implementing stronger cryptographic protections.

Reducing latency has become an important consideration for organizations adopting more advanced encryption because stronger cryptographic operations can introduce additional computational overhead.

The launch reflects growing commercial momentum around post-quantum cybersecurity as vendors increasingly transition from research announcements toward deployable enterprise products.

Over the past year, telecommunications providers, networking companies, cloud providers and cybersecurity firms have announced post-quantum VPNs, quantum-safe key exchanges, cryptographic inventory tools and hybrid encryption products aimed at helping organizations begin what is expected to be a years-long migration.

Security experts generally expect the transition away from RSA and elliptic curve cryptography to resemble previous internet-wide cryptographic upgrades, such as the migration to TLS 1.3, but on a significantly larger scale because public-key cryptography is embedded throughout enterprise infrastructure.

Leave a Comment

Your email address will not be published. Required fields are marked *