migrate to post-quantum signatures

Designs and implements crypto‑agile transitions to replace or augment existing digital signature schemes with post‑quantum algorithms, including inventorying current signature usages, selecting algorithms and parameters, planning key rollout and backward‑compatible verification, and integrating signing and verification code. Builds and evaluates end‑to‑end post‑quantum signing systems and processes—generating and verifying post‑quantum digital signatures, testing interoperability and security properties, detecting tampering, and measuring operational characteristics such as signing latency by message or file size.

migratetopost-quantumsignatures

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.74
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

A Survey of Post-Quantum Cryptography Support in Cryptographic Libraries

Aug 22, 2025
NA
Nadeem Ahmed
🏛️ Univ. of Maryland Baltimore County

Quantum computing poses an existential threat to public-key cryptography, necessitating timely adoption of NIST-standardized post-quantum cryptographic (PQC) algorithms—Kyber, Dilithium, FALCON, and SPHINCS+. Method: This paper systematically evaluates PQC support across nine major open-source cryptographic libraries—including OpenSSL and Bouncy Castle—through rigorous analysis of official documentation, release notes, and real-world deployment practices. Contribution/Results: We identify substantial disparities in implementation completeness, API maturity, and production readiness: only a minority offer stable, production-grade integrations, while most remain experimental or unimplemented. To address this gap, we propose the first multi-dimensional PQC support assessment framework, quantitatively pinpointing key standardization bottlenecks. Based on empirical findings, we recommend three actionable strategies: phased migration, cross-library interoperability coordination, and development of standardized PQC testing benchmarks. Our results provide evidence-based guidance for library developers, standards bodies, and system deployers navigating the transition to quantum-resilient cryptography.

Assessing implementation status of NIST-selected post-quantum cryptography standardsEvaluating PQC algorithm support in major cryptographic librariesIdentifying performance and security challenges in quantum-resistant transition

Must-Read Papers

Most classic and influential ideas
View more

Quantum Disruption: An SOK of How Post-Quantum Attackers Reshape Blockchain Security and Performance

Dec 15, 2025
TM
Tushin Mallick
🏛️ Northeastern University | Ripple Inc

Quantum computing poses a systemic threat to classical cryptographic primitives underpinning blockchain systems—namely digital signatures, key exchange, and hash-based structures—necessitating migration to post-quantum cryptography (PQC). However, direct PQC integration faces architectural bottlenecks, including severe key size inflation and prohibitive computational overhead. Method: We conduct the first architecture-level analysis of PQC migration in blockchains, revealing it is not “plug-and-play” but requires co-design of consensus logic and incentive mechanisms. We propose a four-dimensional evaluation framework—assessing vulnerability, feasibility, performance, and ecosystem impact—and empirically evaluate CRYSTALS-Dilithium and Falcon via cryptographic analysis and protocol modeling. Contribution/Results: In PoS blockchains, PQC signatures reduce TPS by 40–70% and increase storage overhead 3–8×. Critically, merely replacing cryptographic primitives is insufficient for long-term security; robust migration demands coupling PQC with state compression and lightweight verification paradigms.

Analyzes quantum threats to blockchain cryptographic primitivesAssesses performance and security impacts of quantum-resistant replacementsEvaluates post-quantum adaptations in decentralized blockchain systems

This study addresses the vulnerability of widely deployed elliptic curve digital signatures in blockchain systems to quantum attacks and evaluates the practical viability of post-quantum alternatives. We present a unified blockchain prototype that, for the first time, enables end-to-end performance comparison of multiple lattice-based post-quantum signature schemes—including CRYSTALS-Dilithium, Falcon, Hawk, and the emerging HAETAE—under real-world conditions. Through comprehensive benchmarking of critical metrics such as key generation, signing and verification times, and key and signature sizes, we quantitatively assess the computational overhead and storage requirements of each scheme in blockchain contexts. Our empirical findings provide actionable insights and deployment guidance for transitioning to quantum-safe blockchain infrastructures.

blockchaindigital signatureslattice-based cryptography

This study addresses the severe threat posed by quantum computing to conventional public-key cryptography, particularly undermining the security of key authentication and digital signatures in X.509-based Public Key Infrastructure (PKI). The work systematically analyzes the integration requirements of NIST-selected post-quantum cryptographic algorithms into X.509 certificates, Certificate Revocation Lists (CRLs), and the Online Certificate Status Protocol (OCSP). It presents the first comprehensive framework for structural and protocol-level adaptations necessary to support these algorithms within existing PKI components. Through rigorous compatibility and performance evaluations, the study identifies viable migration pathways and provides concrete technical guidance and standardization recommendations for transitioning to a quantum-resistant PKI.

Certificate RevocationPost-Quantum CryptographyPublic Key Infrastructure

A Scalable Framework for Post-Quantum Authentication in Public Key Infrastructures

Apr 16, 2025
AT
Antonia Tsili
🏛️ National and Kapodistrian University of Athens | Eulambia Advanced Technologies

This work addresses the scalability and post-quantum (PQ) migration challenges of public key infrastructure (PKI) under quantum computing threats. Methodologically, it proposes a hierarchical certificate authentication framework compatible with both classical and NIST-standardized post-quantum cryptographic (PQC) algorithms—SPHINCS⁺, Falcon, and Dilithium—featuring a lightweight client adaptation mechanism, cross-algorithm rapid switching protocol, certificate isolation architecture resilient to cross-trust-chain attacks, and automated issuance/verification workflows. Key contributions include: (i) the first scalable, hierarchical certification authority (CA) model supporting cryptographic agility; (ii) substantial reduction in client-side cryptographic overhead; and (iii) empirical evaluation of performance–security–scalability trade-offs for all three PQC algorithms under 10,000 concurrent connections, demonstrating a viable pathway for large-scale, smooth PKI transition to quantum-resilient cryptography.

Assesses performance trade-offs in large-scale deploymentsEnsures crypto-agility with classical and PQC algorithmsEvaluates post-quantum authentication scalability in PKI

Applied Post Quantum Cryptography: A Practical Approach for Generating Certificates in Industrial Environments

May 07, 2025
NR
Nino Ricchizzi
🏛️ Lucerne University of Applied Sciences and Arts | Hamm-Lippstadt University of Applied Sciences

Industrial post-quantum cryptography (PQC) migration faces a critical gap in the X.509 certificate ecosystem: lack of lightweight, command-line-driven tooling for hybrid and composite certificates. Method: This paper designs and open-sources the first modular CLI tool supporting both ML-DSA and SLH-DSA, built atop Bouncy Castle and fully compliant with X.509 standards. It enables unified generation and verification of classical, hybrid (Catalyst), composite, and partial-chameleon certificates, operating headlessly on resource-constrained platforms. Contribution/Results: The tool fills a major void in the open-source ecosystem—unlike OpenSSL and other existing solutions, it provides native CLI support for PQC hybrid and composite certificates. Experimental evaluation confirms its feasibility within industrial certificate workflows, delivering a reusable, extensible infrastructure to bridge the gap between PQC standardization and real-world deployment.

Challenges in integrating post-quantum cryptography into industrial certificate managementLack of open-source tools for hybrid and composite certificate generationNeed for PQC-compatible X.509 workflows in constrained industrial systems

Latest Papers

What's happening recently
View more

This work addresses the limitations of current cryptographic APIs, which are tightly coupled to specific algorithms and lack policy-driven control and key migration capabilities, thereby hindering smooth transitions to post-quantum cryptography. To overcome these challenges, the paper proposes a novel API architecture designed for cryptographic agility, grounded in five core principles: abstraction, stability, temporal flexibility, separation of concerns, and extensibility. By introducing scoped intent vocabularies and abstract policy interfaces, the design decouples algorithm selection from key management. Leveraging Protocol Buffers schemas alongside stable key identifiers and evolvable operations—such as rotation, transformation, and migration—the approach transforms algorithm updates into operational procedures that require no application code changes, significantly enhancing the feasibility and efficiency of migrating systems to post-quantum cryptographic standards.

algorithm migrationcryptographic agilitycryptographic API

This work addresses the limited visibility into TLS configurations within heterogeneous environments—a critical barrier to the secure and efficient deployment of post-quantum cryptography (PQC) in financial institutions. The authors propose an enterprise-grade framework for automated parsing and standardization of TLS configurations, which constructs a unified, auditable inventory of cryptographic assets. By doing so, it shifts the primary bottleneck of PQC migration from the algorithmic layer to the operational layer. The framework supports MLKEM and hybrid key exchange schemes, demonstrating effectiveness across 8,443 real-world Nginx configurations. Already deployed in production at financial institutions, it achieves zero application-layer modifications and incurs only manageable performance overhead, thereby substantially enhancing the operational feasibility and regulatory compliance of PQC transitions.

Hybrid PQC DeploymentOperational CryptographyPost Quantum Cryptography

This work addresses a pervasive structural flaw in hybrid X.509 certificate validation—namely, that successful binding does not necessarily imply successful authentication. In practice, validators often base acceptance decisions solely on classical validation paths, causing post-quantum evidence to be effectively excluded from the final authentication outcome and thereby introducing security downgrade risks. To rectify this, the paper introduces the first precise semantic criteria for hybrid validation, develops a formally derived validator model with policy-parameterized reference contracts, and conducts systematic empirical evaluation across eight validation stacks, nine operational modes, and six certificate schemes via multi-stack compatibility testing and cross-scheme analysis. The findings reveal that nearly all implementations default to ignoring post-quantum evidence; even when post-quantum signatures are supported, their verification results are not mandatorily bound to the ultimate authentication decision.

classical downgradehybrid authenticationpost-quantum migration

Hot Scholars

FK

Fatih Kaleoglu

Quantum Cryptography Researcher
quantum cryptographypost-quantum cryptography
BX

Bin Xiao

Meta GenAI
Computer VisionVision and LanguageMachine LearningHuman Pose Estimation
CY

Chansu Yu

Cleveland State University
Mobile computingQuantum computingCybersecurity