The Defence Acquisition Council last week approved the installation of the Defence Forces Secure Access Card system. It will replace the existing paper-based identity cards, passes, and permits with an interoperable radio frequency identification-based smart card system. Implying that the system will eventually digitalise the identification system making it more robust and fake proof, it’s a step in the right direction indeed. However, any new introduction of technology has a flip side, unless it’s safeguarded with equal zeal.
Every individual today possesses two identities: a physical identity and a digital one. A military commander can currently enter a defence headquarters, network centre, or war room using biometrics or physical verification by presenting a valid identity card. Login into machines still requires standard passwords.
However, as technology advances, physical identity will be entirely replaced by digital identity. And, if an adversary interferes with your digital identity, you can be barred from entering any sensitive installation even though you are otherwise authorised — you simply become no one, ceasing to exist digitally. In essence, you have been murdered digitally.
China’s long game
As military and civilian infrastructure increasingly relies on biometric authentication and digital credentials, adversaries with the capability to compromise or spoof these systems can bar authorised personnel from defence headquarters, network centres, or war rooms despite physical authorisation. The future warfare will increasingly focus on cloud computing, AI, and quantum technology to process vast amounts of battlefield data within seconds, enabling faster command decisions and resource allocation. In a hypersonic warfare environment, where missiles travel at 2 km/second, even minutes of delay in the OODA (Observe-Orient-Decide-Act) loop can spell disaster. If digital identity systems fail or are compromised during conflict, the resulting decision-making paralysis could be catastrophic.
The PLA’s concept of “cognitive domain operations” explicitly targets the mental space where individuals and organisations make decisions. At the heart of China’s quantum preparation lies the Harvest Now, Decrypt Later (HNDL) strategy — a patient, long-game approach where adversaries intercept and store encrypted communications today, intending to decrypt them when cryptographically relevant quantum computers become available. This is not theoretical: cybersecurity and intelligence communities broadly acknowledge that sophisticated nation-state actors, particularly China, are actively collecting encrypted traffic for future decryption. The convergence of cognitive warfare and quantum decryption creates a novel vulnerability: digital identity erasure.
Closer to home, Operation Sindoor has been examined extensively through the lens of kinetic action. The aircraft that took to the skies, the drones and missiles deployed, the specialised weapons employed, and the targets struck or destroyed have all been dissected with forensic attention. Yet, alongside the visible thunder of explosions, another battle unfolded in silence — largely unseen, but no less consequential: the cyber war. Between 7 and 10 May, the period during which Operation Sindoor was conducted, a series of cyberattacks sought to probe and disrupt India’s digital nervous system.
The National Investigation Agency (NIA) has since conducted searches at multiple locations across the country in connection with a cyber-terrorism case involving attempted distributed denial-of-service attacks on a large number of Indian government websites, as well as efforts directed at critical information infrastructure during the operation.
This dimension of conflict deserves the same national attention and seriousness that is accorded to conventional military action. In cyberspace, the vulnerability of the public is inseparable from the resilience of the state; ordinary citizens, institutions, and strategic systems are all part of the same battlespace. Cyber interference has moved far beyond the theft of data or the temporary disruption of services. It can penetrate command networks, distort information, paralyse decision-making, and, in the most consequential sense, render soldiers ineffective before they ever confront the enemy.
Also read: India’s Javelin deal with the US makes sense—only if it remains a stopgap, not a strategy
PQC, the only credible shield
India’s National Quantum Mission (NQM), approved in April 2023 with a budget of about Rs 6,000 crore spanning 2023-24 to 2030-31, aims to harness quantum technologies. It must accord equal weightage to post-quantum cryptography (PQC) as it does to quantum technology development. PQC — encryption techniques resistant to future quantum computer attacks — represents the only credible shield against HNDL and digital identity compromise. The US Customs and Border Protection addressed the HNDL threat in November 2024, stating: “PQC addresses the ‘harvest now, decrypt later’ threat, where adversaries may be collecting encrypted data now with plans to decrypt it once quantum computing becomes sufficiently advanced.”
Institutionalising PQC across defence, power grids, banking, and urban infrastructure is not optional — it is existential. The dangers of Q-Day must be thwarted before they surface. India’s National Quantum Mission would do well to prioritise PQC research, standardisation, and deployment with the same urgency as quantum computing and communications development.
The cue is clear: China is playing a multi-decade game of quantum chess, harvesting encrypted data today for decryption tomorrow. India must respond with equal strategic patience and technological rigour, creating a credible shield against digital murder before the first quantum key turns.
Air Marshal GS Bedi (Retd) is a Distinguished Fellow at the Centre for Aerospace Power and Strategic Studies (CAPSS) and the Centre for Land Warfare Studies (CLAWS). Views are personal.
(Edited by Aamaan Alam Khan)
