Protecting Whakapapa Across Time: Towards Quantum-Safe Architecture
There is a particular difficulty in preparing for quantum computing: some of the decisions that matter most need to be made before the technology capable of exploiting them exists.
This is becoming increasingly relevant to my own work. My focus in the quantum space is moving further into questions of infrastructure, future telecommunications architecture and remote sensing, and those areas are reinforcing something I have been thinking about throughout Quantum Ake. Quantum readiness cannot simply mean acquiring access to quantum computation when sufficiently useful machines become available. We also need to consider the architecture within which those machines, networks, sensors, data and increasingly capable artificial intelligence will operate.
Cybersecurity provides perhaps the most immediate example.
Much of the concern centres on the prospect that sufficiently capable quantum computers could eventually undermine widely used public-key cryptographic systems. We do not yet have a cryptographically relevant quantum computer capable of doing this at the necessary scale, and forecasts about when one might exist vary considerably. The architectural problem, however, exists now. Information encrypted today can be intercepted and retained for later decryption, commonly described as harvest now, decrypt later – meaning the relevant risk horizon is determined not only by when quantum capability arrives, but by how long the information must remain protected.
That distinction matters.
Health and genomic information, state information, commercial intellectual property, research, infrastructure data, geospatial and sensing information, iwi records, whakapapa and mātauranga can have useful or sensitive lives extending far beyond the systems in which they were originally collected. For some classes of information, confidentiality measured in months or a few years may be sufficient. For others, the obligation may extend across generations.
This is why I think our conversation needs to move beyond post-quantum cryptography towards quantum-safe architecture.
Post-quantum cryptography is essential. International standards now provide organisations with concrete cryptographic mechanisms with which to begin migration. But replacing one algorithm with another does not, by itself, create a quantum-safe system. Architecture requires us to understand where cryptography exists across an organisation, how identities are established, where keys are managed, how devices authenticate, what happens at the edge of a network, how software and hardware dependencies enter the supply chain, what metadata is retained, where data moves, and how rapidly cryptographic mechanisms can be replaced when circumstances change.
This becomes particularly important as our infrastructure becomes more distributed and intelligent.
Future telecommunications networks will increasingly interact with cloud and edge computing, AI, autonomous systems, advanced sensing and potentially quantum communications and computing resources. Remote sensing adds another layer: information may originate across satellites, aircraft, drones, terrestrial sensors or other distributed systems before moving through networks, analytical platforms and decision environments. Protecting the final database is therefore insufficient. Trust has to be considered across the entire information pathway, from the point of observation through transmission, computation, interpretation, storage and eventual use.
The question is not simply whether information is encrypted. It is whether the architecture itself can sustain trust.
That requires crypto-agility: the ability to identify and replace cryptographic mechanisms without rebuilding entire systems. It requires strong provenance so that information can be traced to its source and changes can be understood. It requires resilient identity, authentication and key-management systems. It requires scrutiny of hardware, software and vendor dependencies. It requires careful consideration of metadata, because protecting the contents of a communication while exposing who communicated, when, from where and how frequently may still reveal significant intelligence.
It also requires governance. People who understand this space, not just big names with big ideas.
Data integrity is sometimes treated as a technical property: information is complete, accurate and unaltered. I think the coming convergence of AI, advanced sensing and quantum technologies requires a wider conception. We will increasingly need to establish not only whether information has changed, but where it originated, under whose authority it was collected, what transformations have been applied to it, what other information has been combined with it, and whether its current use remains consistent with the conditions under which it was entrusted.
Artificial intelligence makes this particularly urgent. The sensitivity of a dataset can no longer be judged solely by what the dataset visibly contains. Increasingly capable analytical systems can combine seemingly innocuous information and infer characteristics, relationships or patterns that were never explicitly recorded. Future computational capability may reveal further knowledge that neither the collector nor the person or community represented in the data could reasonably have anticipated.
This raises an uncomfortable governance question: how do we give meaningful consent to future uses that do not yet exist?
For Māori, that question has another dimension. Data relating to tangata, whenua, whakapapa, taonga and mātauranga carries relationships that cannot be adequately described through ownership alone. It has provenance. It exists within whakapapa. Authority and obligation may be collective rather than individual, and the responsibility attached to information does not necessarily disappear when the technology, institution or generation holding it changes.
This is where Māori Data Sovereignty and quantum-safe architecture begin to intersect in ways I think deserve considerably more attention.
He mihi nui ki a koutou katoa e whakapau kaha ana i te ao o te rangatiratanga raraunga Māori mō tātou.
If data has whakapapa, provenance is not simply a technical audit trail. If information has been entrusted under particular relationships and conditions, access control is not simply an administrative permission. If information may affect generations who were not present when it was collected, retention is not simply a storage decision. Architecture begins to embody governance, whether we acknowledge it or not.
The same applies to sensing infrastructure. The ability to observe more of our physical world, with increasing resolution and frequency, creates extraordinary opportunities across environmental management, climate resilience, infrastructure, agriculture, emergency management and the stewardship of whenua and wai. It also creates questions about who observes, what is collected, who interprets the resulting information, where it resides, and who possesses the authority to determine its future uses.
Quantum technologies will not create all of these questions. Many already exist. What quantum does is change the scale, capability and time horizon against which we must answer them.
This is why I am becoming increasingly interested in quantum readiness as an architectural discipline rather than a technology programme. A genuinely quantum-safe architecture would need to consider cryptography, networks, compute, sensing, data, identity, provenance, interoperability, infrastructure resilience, governance and the capacity to evolve as both threats and technologies change.
It would also need to acknowledge uncertainty. We do not know precisely when cryptographically relevant quantum computing will arrive. We do not know which quantum modalities will ultimately dominate. We cannot know all of the capabilities that future AI systems will possess. Good architecture therefore cannot depend upon predicting the future correctly. It must be capable of adapting when our predictions are wrong.
There is a whakapapa to information: where it came from, the relationships within which it was created, the transformations it has undergone and the obligations that travel with it. Increasingly, I think there is also a whakapapa to infrastructure. Every architectural decision inherits what came before it and constrains what becomes possible after it.
In Post 5, I argued that the future is already being architected. The next question is whether we are building architecture capable of protecting what we intend to carry into that future.
Quantum-safe architecture is therefore not simply preparation for a more powerful computer. It is preparation for a world in which computation, sensing and intelligence become considerably more capable, while trust must continue to endure across changing technologies and generations.
Perhaps that is the deeper challenge before us: not merely ensuring that our information survives the quantum era, but ensuring that its integrity, authority and whakapapa survive with it.
Haere whakamua.