Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Comment on Post-Quantum Signatures for JOSE and COSE by Post-Quantum Signatures for JOSE and COSE – Q-PrEP

Дата публикации: 03-07-2026 11:39:53

[…] Additional information in the blog here: https://self-issued.info/?p=2853 […]

Основное содержимое страницы с новостью.

Congratulations to Mike Prorock and Orie Steele on the publication of “ML-DSA for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE)” as RFC 9964! This is a major step forward towards enabling widely-available post-quantum signatures for the Internet and devices.

The abstract from the RFC is:

This document specifies JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE) serializations for the Module-Lattice-Based Digital Signature Standard (ML-DSA), a Post-Quantum Cryptography (PQC) digital signature scheme defined in US NIST FIPS 204.

As I discussed at TDI 2026 and will discuss tomorrow at EIC 2026, transitioning to post-quantum algorithms is a multi-step process:

  1. Developing PQ algorithms
  2. Creating standards for using PQ algorithms
  3. Updating software to use PQ standards
  4. Deploying the updated software in your environment

Mike and Orie successfully completed step 2 for JOSE and COSE signatures today!

The JOSE and COSE algorithm identifiers for ML-DSA were actually registered with IANA in July 2025, once it was clear that the document was stable. Some deployments already exist. For instance, Yubico has created prototype Yubikeys (hardware passkeys) supporting ML-DSA signatures. The algorithms are now recommended in the FIDO2 CTAP2.3 Server Requirements.

I played a few supporting roles progressing this spec. I co-chaired the COSE Working Group with Ivaylo Petrov where the work occurred. Ivo and I made a consensus call in May 2025 to standardize only one private key representation – the seed. (As I often advocate, “Standards are about making choices”.) And I requested early allocation of the algorithm identifiers with IANA in July 2025.

Orie said to me while the spec was in AUTH48 with the RFC Editor: “This may be one of the most consequential RFCs I ever create.” I completely agree! And special congratulations, Mike Prorock, on your first RFC!


Here’s a slide from my TDI 2026 presentation on what’s hard about deploying post-quantum cryptography. I’ll make the same case tomorrow at EIC.

What's Hard About Post-Quantum Cryptography

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1 Comment on Post-Quantum Presentation at TDI 2026 by Post-Quantum Signatures for JOSE and COSE – Mike Jones: self-issued 024.1320-05-2026
2 Comment on FIDO2 CTAP 2.3 standard and Server Requirements published by Post-Quantum Signatures for JOSE and COSE – Mike Jones: self-issued 025.7120-05-2026
3What the post-quantum executive order means for CISOs013.3109-07-2026
4 Comment on OpenID Connect RP Metadata Choices is an Implementer’s Draft by Final OpenID Connect RP Metadata Choices Specification – Mike Jones: self-issued 011.2301-04-2026
5Building a practical path to post-quantum cryptography012.8213-08-2026
6Cracking Encryption: The Quantum Threat0726-06-2024
7Post Quantum transaction signature (PQTS) Breakout #12031.920-07-2026
8OASIS Approves Two Public-Key Cryptography Standards to Advance Post-Quantum Security and Interoperability015.715-07-2026
9 Comment on How to Cite Infographics in APA, MLA and Chicago Style by "oppna ett binance-konto 013.4502-08-2026
10X-post: Hardening GitHub Actions workflows across the WordPress organisation09.8313-07-2026

Классификация: Мнения. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 22.46. Источник: self-issued.info.