Applied Post Quantum Cryptography: A Practical Approach for Generating Certificates in Industrial Environments

๐Ÿ“… 2025-05-07
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
Industrial post-quantum cryptography (PQC) migration faces a critical gap in the X.509 certificate ecosystem: lack of lightweight, command-line-driven tooling for hybrid and composite certificates. Method: This paper designs and open-sources the first modular CLI tool supporting both ML-DSA and SLH-DSA, built atop Bouncy Castle and fully compliant with X.509 standards. It enables unified generation and verification of classical, hybrid (Catalyst), composite, and partial-chameleon certificates, operating headlessly on resource-constrained platforms. Contribution/Results: The tool fills a major void in the open-source ecosystemโ€”unlike OpenSSL and other existing solutions, it provides native CLI support for PQC hybrid and composite certificates. Experimental evaluation confirms its feasibility within industrial certificate workflows, delivering a reusable, extensible infrastructure to bridge the gap between PQC standardization and real-world deployment.

Technology Category

Machine Learning: Quantum Machine LearningConstraint Satisfaction and Optimization: Solvers and ToolsApplication Domains: Security

Application Category

Security and Privacy: Applications of cryptographySystems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applicationsResponsible Web: Data and user privacy-enhancing technologies for the Web
๐Ÿ“ Abstract
The transition to post-quantum cryptography (PQC) presents significant challenges for certificate-based identity management in industrial environments, where secure onboarding of devices relies on long-lived and interoperable credentials. This work analyzes the integration of PQC into X.509 certificate structures and compares existing tool support for classical, hybrid, composite, and chameleon certificates. A gap is identified in available open-source solutions, particularly for the generation and validation of hybrid and composite certificates via command-line interfaces. To address this, a proof-of-concept implementation based on the Bouncy Castle library is developed. The tool supports the creation of classical, hybrid (Catalyst), composite, and partially chameleon certificates using PQC algorithms such as ML-DSA and SLH-DSA. It demonstrates compatibility with standard X.509 workflows and aims to support headless operation and constrained platforms typical of industrial systems. The implementation is modular, publicly available, and intended to facilitate further research and testing of PQC migration strategies in practice. A comparison with OpenSSL-based solutions highlights current limitations in standardization, toolchain support, and algorithm coverage.
Problem

Research questions and friction points this paper is trying to address.

Challenges in integrating post-quantum cryptography into industrial certificate management
Lack of open-source tools for hybrid and composite certificate generation
Need for PQC-compatible X.509 workflows in constrained industrial systems
Innovation

Methods, ideas, or system contributions that make the work stand out.

Integrates PQC into X.509 certificate structures
Develops Bouncy Castle-based tool for hybrid certificates
Supports ML-DSA and SLH-DSA PQC algorithms
๐Ÿ”Ž Similar Papers
No similar papers found.
๐Ÿ’ผ Related Jobs
No related jobs found.
N
Nino Ricchizzi
Lucerne University of Applied Sciences and Arts, Werftestrasse 4, Luzern, 6002, LU, Switzerland
C
Christian Schwinne
Hamm-Lippstadt University of Applied Sciences, Marker Allee 76-78, Hamm, 59063, NRW, Germany
J
Jan Pelzl
Hamm-Lippstadt University of Applied Sciences, Marker Allee 76-78, Hamm, 59063, NRW, Germany