[saag] PQC Dialogue with Government Stakeholders - Recording , Transcript, and Slides
John Mattsson <[email protected]>
| Newsgroups | gmane.ietf.saag,gmane.ietf.pqc |
|---|---|
| Message-ID | <GVXPR07MB96788027762C7CC5B53364B28996A@GVXPR07MB9678.eurprd07.prod.outlook.com> |
Hi, Thanks to everybody that participated in the side-meeting! The meeting was a great success with well over 100 participants from governments, industry, and academia. The goal of the meeting was to promote open dialogue and understanding between technical experts and government officials regarding the transition to PQC. EU, Sweden, Germany, UK, US, and Canada all presented their plans for PQC timelines and algorithm recommendations. My feeling is that people were very happy with the meeting, and I have already received questions if I can help to arrange follow-up meetings. Recording, transcript, and slides from the meeting are now available [1-2]. Shortly after the meeting, UK NCSC published their timelines as promised [3]. The European commission will soon publish their timelines [4]. US timelines can be found here [5-8]. Government timelines and algorithms recommendations from Canada, Germany, France, and China can be found here [9-18]. If I missed something important, just send a reply and let the list know. Cheers, John Preuß Mattsson Expert Cryptography and Security Protocols, Ericsson My personal summary: * John Preuß Mattsson presented that IETF is essential for PQC migration in many industries including critical infrastructure such as 5G and 6G mobile networks. * The European Commission will publish PQC timelines in mid-May 2025 and technical recommendations in mid-May 2026. Transition for ”Harvest now, decrypt later” should be done by the end of 2030 and in general, the whole transition by the end of 2035. The recommendations are for public administration and critical infrastructure, not national security. The roadmap will be divided into different sectors. Not legally binding but might become law in the future. * UK NCSC will publish broad recommendations in March 2025. For government use, critical infrastructure, and the everyday citizen. Approves all NIST algorithms and highlights ML-KEM-768 and ML-DSA-65. PQC only is the end goal but use hybrids if that speeds up migration. * German BSI recommends hybridization of lattice-based algorithms and that will likely be a requirement for common criteria certification in Europe. The SOGIS group will soon publish an updated ACM document with PQC. BSI still recommends FrodoKEM for more conservative applications. * US NIST provides recommendations for non-classified systems. Cryptographers and industry globally have participated in the NIST PQC project. FIPS 203, 204, and 205 published. Draft speciation of FN-DSA expected in 2025. NIST has started specification of HQC but it will take some time. NIST will follow deployment of Classic McEliece and see if it gets widespread use. NIST has received very promising algorithms in the ramp-on signature project and recently published a report. NIST recommend everyone to move to PQC by 2035, PQC only or hybrid are both fine. * Canada Cyber Centre has published PQC guidance for government use and critical infrastructure. Partners with NIST on the cryptographic module validation program. Recommends NIST PQC standards. PQC only or hybrid are both permitted. Concerned that specifications on PQC in IETF protocols are not progressing to RFCs fast enough. * Very strong agreement that PQC is the priority. BSI says QKD is not mature and even long-term the only possible use case would be defense-in-depth in niche application. UK NCSC and NIST does not endorse QKD. Sweden says that QKD will never be useful. * Several industries express that the lack of technical PQC recommendations or conflicting recommendations from governments are a problem. Discussion on the huge costs of migrating existing infrastructure. * Tanja Lange states that it is surprising that recommendations to do hybrids is not included in the first document from the NIS corporation group. Without technical recommendations it is unclear what people should migrate to. Discussion about the use of hybrid cryptography, with some advocating for pure post-quantum migration and others highlighting the benefits of hybrids in certain scenarios. Deidre Connolly strongly encourages people to consider pure PQC. BSI states that they recommend hybrids for everything except for hash-based signatures. * Discussion about paywalled standards. EU and US courts have decided that access to standards referenced by law is a human right. [1] PQC Dialogue with Government Stakeholders – Recording, summary, and transcript https://ietf.webex.com/recordingservice/sites/ietf/recording/1e87f518ecb1413b9357e607cf825642/playback [2] PQC Dialogue with Government Stakeholders – Slides https://emanjon.github.io/Slides/2025%20PQC%20side-meeting.<https://emanjon.github.io/Slides/2025%20PQC%20side-meeting.pdf>pdf<https://emanjon.github.io/Slides/2025%20PQC%20side-meeting.pdf> [3] UK NCSC, Timelines for migration to post-quantum cryptography https://www.ncsc.gov.uk/guidance/pqc-migration-timelines [4] European Commission, NIS Cooperation Group https://digital-strategy.ec.europa.eu/en/policies/nis-cooperation-group [5] US NSA, “The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ” https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF https://en.wikipedia.org/wiki/Commercial_National_Security_Algorithm_Suite#/media/File:CNSA_2p0_timeline.png [6] US NIST, Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved [7] US NIST, Post-Quantum Cryptography https://csrc.nist.gov/projects/post-quantum-cryptography [8] US NIST, IR 8547, ”Transition to Post-Quantum Cryptography Standards” https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf [9] Canada Cyber Centre, Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information https://www.cyber.gc.ca/en/guidance/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111 [10] Canada Cyber Centre, National Quantum Strategy roadmap: Quantum communication and post-quantum cryptography https://ised-isde.canada.ca/site/national-quantum-strategy/en/national-quantum-strategy-roadmap-quantum-communication-and-post-quantum-cryptography [11] German BSI, Cryptographic Mechanisms: Recommendations and Key Lengths https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TG02102/BSI-TR-02102-1.html?nn=916626 [12] German BSI, Post-Quantum Policy & Roadmap of the BSI https://pkic.org/events/2023/pqc-conference-amsterdam-nl/pkic-pqcc_stephan-ehlen_bsi_post-quantum-policy-and-roadmap-of-the-bsi.pdf [13] French ANSSI, “Guide des Mécanismes cryptoraphiques” https://cyber.gouv.fr/sites/default/files/2021/03/anssi-guide-mecanismes_crypto-2.04.pdf [14] French ANSSI, ANSSI views on the Post-Quantum Cryptography transition https://cyber.gouv.fr/sites/default/files/document/follow_up_position_paper_on_post_quantum_cryptography.pdf [15] French ANSSI, ANSSI plan for post-quantum transition https://pkic.org/events/2023/pqc-conference-amsterdam-nl/pkic-pqcc_jerome-plut_anssi_anssi-plan-for-post-quantum-transition.pdf [16] Europe, SOGIS Group, supporting documents https://www.sogis.eu/uk/supporting_doc_en.html [17] China ICCS, Call for Comments on Submission Requirements for Public-Key Cryptographic Algorithms https://niccs.org.cn/en/notice/ [18] German BSI, French ANSSI, Dutch and Swedish NCSA, ”Position Paper on Quantum Key Distribution” https://www.forsvarsmakten.se/contentassets/f7199ed1b90f41529b76970bdb5fce1c/position-paper-on-quantum-key-distribution.pdf _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]