bk99.de entertain the web since 1997

RFC 9958: Post-quantum cryptography for practitioners

Summary

RFC 9958 explains to engineers the properties, transition risks and deployment patterns of post-quantum cryptography. Cryptographic migration starts long before quantum attacks are practically available. Harvest-now-decrypt-later makes data that must stay confidential for a long time relevant today.

Ideas

  • Quantum attacks threaten today’s public key methods to different degrees.
  • Hybrid methods combine classic and new algorithms.
  • Larger keys and signatures change protocol limits.

Remarks

  • RFC 9958 is an informational document and not an Internet Standard.

Recommendations

  • Take inventory of cryptographic dependencies and data retention periods.
  • Test hybrid methods for size, latency and interoperability.

References

Read the RFC at the RFC Editor

Search the Web Archive