Open
Description
A workshop for Post Quantum Cryptography for XML Signature and XML Encryption Suites to discuss experiences and the next steps.
Problem:
- XML Signature and XML Encryption need support for new Post-Quantum algorithms.
Use cases and requirements:
- There is an issue regarding using SAML, e.g., in the US public sector and institutional environments, with various cryptographic requirements.
- SAML's group is no longer available. However, SAML uses XMLDSign for signatures, and we can work on this.
- Given the use-case of SAML, a potential solution would be to migrate to other technology.
- But, as the issue is on XML Signature and Encryption, people highlighted that this is also used in other contexts, so the scope is broader
Investigation:
- During some conversations, we noticed that not all people consider Post-Quantum Cryptography for integrity an imminent threat.
- Similar need for updates happened in the past, and a workshop in 2007 was organized to facilitate the discussion.
- We also have the RFC 9231 to update the XML Signature and Encryption algorithms XML Security URIs registry.
- There is already some research on Post-quantum XML and SAML Single Sign-On.
From IETF 121 Dublin with <3
[cc'ing @twhalen, @plehegar, @ianbjacobs, @martinthomson, @mnot, @OR13, @pamelatech, @ve7jtb, @hlflanagan]
Metadata
Metadata
Assignees
Type
Projects
Status
No status
Activity