[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 25 Jun 2025, at 09:20, Simo Sorce <[email protected]> wrote: > > For encryption there is an inherent need to do hybrid algorithms > because there is an ongoing need to protect content that is out of your > hands once it is transmitted, but signatures are checked at specific > points in time, can always be rechecked and require no hybridization, > because once broken the broken part is effectively useless. For document signatures, you have a point. For self-signatures it is more complex. You can only have one primary key per certificate, so in order to make a post-quantum safe certificate you need a composite primary key so that the certificate itself remains secure under both the PQ and ECC failure scenarios. Otherwise, we’re asking people to manage two sets of keys/certificates in parallel at all times, which is much more fragile from both an implementation and operational POV. Once we admit composite primary keys, it is conceptually easier to also define composite signatures so that we maintain a 1:1 mapping between key algorithms and signature algorithms. While this does not improve the security properties, it has the advantage of not requiring changes to the higher-level logic, meaning that it is harder for the application layer to screw it up. A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmhbt1EACgkQXB7EBNWQ Zin6tQ/8CIn9tPJhcmYsiM2iRthXQio+yItt2rdKGAiu3e8t4wsJENlfsITi8ddV gD4jDIvuENfi6N9CAy0kcAnUZSt+N3fIOGIfs0CN+aeUxM086U+je67QMfqjCwuR j6DyE3C9TgGe8yP6tt0voF8SS1L1Ok0KJmfHBLF4xPa2TZW+o72uJvdGrlA0jbo1 ahCN86m9HnXmG/zh38a9ry6OIWADJjPi8gUk+pBsyzfp255dL/UNCM5AkzNUoJJT o5jMq7GRFgCPayrjSPTotRrV8DWuyivYISiJM9dzqV1cole937Rmm6q7EZBhZcmq AiJVxIJArEtVkMN6DYeQw15PpQofUR/JFCXQizlZOy2LWPVV+pcSzZGMy0iXn4Co 7t0o6ZNcdeoMjboWas+VxKQJvNezVjv9cjdp5Zkxl4sDNzpm5fT3m01MAuCnLnvx 0HcrFsXyckQcuO5dJko7zxbXdNOJz94e8sF6XXzSOnaUByjYyGgkGgPyds2qaWTE Le95LrIWwhbath6KYHgjLSDD2k/zTbAfX2LszKG6ll+S8nu0v6HRk9xo6RMLn8ot 2ZOMv9TQ4KZUP2qwdcVuSGyOun4M2w5+KeKRRvlddiM49Nm/Sy9zf/HbItHcN9JW 0B5rfBV+/DMm1Oxy/V3zVNmKzq/1Yozqd6jMlWy6DNBtHFuS0q0= =rkS+ -----END PGP SIGNATURE-----