Shaping a Quantum-Resistant Future: Strategies for Post-Quantum PKI

πŸ“… 2024-06-26
πŸ›οΈ International Symposium on Computers and Communications
πŸ“ˆ Citations: 2
✨ Influential: 0
πŸ“„ PDF

career value

194K/year
πŸ€– AI Summary
This study addresses the severe threat posed by quantum computing to conventional public-key cryptography, particularly undermining the security of key authentication and digital signatures in X.509-based Public Key Infrastructure (PKI). The work systematically analyzes the integration requirements of NIST-selected post-quantum cryptographic algorithms into X.509 certificates, Certificate Revocation Lists (CRLs), and the Online Certificate Status Protocol (OCSP). It presents the first comprehensive framework for structural and protocol-level adaptations necessary to support these algorithms within existing PKI components. Through rigorous compatibility and performance evaluations, the study identifies viable migration pathways and provides concrete technical guidance and standardization recommendations for transitioning to a quantum-resistant PKI.

Technology Category

Application Category

πŸ“ Abstract
As the quantum computing era approaches, securing classical cryptographic protocols becomes imperative. Public key cryptography is widely used for signature and key exchange but it’s the type of cryptography more threatened by quantum computing. Its application typically requires support via a public-key certificate, which is a signed data structure and must therefore face twice the quantum challenge: for the certified keys and for the signature itself. We present the latest developments in selecting robust Post-Quantum algorithms and investigate their applicability in the Public Key Infrastructure context. Our contribution entails defining requirements for a secure transition to a quantum-resistant Public Key Infrastructure, with a focus on adaptations for the X.509 certificate format. Additionally, we explore transitioning Certificate Revocation List and Online Certificate Status Protocol to support quantum-resistant algorithms. Through comparative analysis, we elucidate the complex transition to a quantum-resistant PKI.
Problem

Research questions and friction points this paper is trying to address.

Post-Quantum Cryptography
Public Key Infrastructure
Quantum Threat
X.509 Certificate
Certificate Revocation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Post-Quantum PKI
X.509 certificate adaptation
quantum-resistant algorithms
Certificate Revocation List
OCSP
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
G
Grazia D'Onghia
Politecnico di Torino, Dip. di Automatica e Informatica, Torino, Italy
D
D. Berbecaru
Politecnico di Torino, Dip. di Automatica e Informatica, Torino, Italy
A
A. Lioy
Politecnico di Torino, Dip. di Automatica e Informatica, Torino, Italy