Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

OpenSSL says post-quantum security needs architectural changes

OpenSSL Corporation President Tim Hudson told TechRadar that businesses preparing for a post-quantum internet should plan for a PKI redesign, not simply upgrade a library or add bandwidth.

Key exchange is largely solved, but signatures remain a challenge. An ML-DSA-44 signature is 2,420 bytes with a 1,312-byte public key, compared with 64 bytes for ECDSA P-256. Including certificate-chain signatures and Certificate Transparency timestamps, a direct replacement could add 7KB to 10KB to each new connection. That can push handshakes beyond the roughly 14KB initial congestion window and QUIC’s anti-amplification limit, creating an extra round trip that particularly affects mobile, satellite, lossy, and constrained links.

Hudson recommended inventorying systems before procurement; discovery in a complex estate can take six to twelve months. He also said organizations should prioritize algorithm agility instead of products marketed as “quantum-safe.” Long-term confidentiality is urgent because recorded traffic may later be decrypted, while authentication is mainly a scheduling issue.

Critical assets include hardware roots of trust, firmware and code-signing keys, HSM-held material, PKI roots with twenty-year validity, and long-lived embedded or operational technology. Existing transition tools include hybrid key establishment in TLS 1.3, composite or dual certificate chains, OpenSSL’s Library provider architecture, PKCS#11 v3.2, and KMIP.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.