[IPsec] New Liaison Statement, "LS on ITU-T SG17 work on quantum-safe PKI"

Liaison Statement Management Tool <lsmt@ietf.org> Wed, 13 September 2017 15:25 UTC

Return-Path: <lsmt@ietf.org>
X-Original-To: ipsec@ietf.org
Delivered-To: ipsec@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 4F7D513305E; Wed, 13 Sep 2017 08:25:01 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Liaison Statement Management Tool <lsmt@ietf.org>
To: David Waltermire <david.waltermire@nist.gov>, Tero Kivinen <kivinen@iki.fi>, Russ Housley <housley@vigilsec.com>
Cc: David Waltermire <david.waltermire@nist.gov>, IP Security Maintenance and Extensions Discussion List <ipsec@ietf.org>, Limited Additional Mechanisms for PKIX and SMIME Discussion List <spasm@ietf.org>, Russ Housley <housley@vigilsec.com>, Scott Mansfield <Scott.Mansfield@Ericsson.com>, Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>, Tero Kivinen <kivinen@iki.fi>, itu-t-liaison@iab.org, Eric Rescorla <ekr@rtfm.com>, jean-paul.lemaire@univ-paris-diderot.fr
X-Test-IDTracker: no
X-IETF-IDTracker: 6.61.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <150531630127.30557.5933470261200873062.idtracker@ietfa.amsl.com>
Date: Wed, 13 Sep 2017 08:25:01 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/R5kCtOsRu7M7eLI4n_f_1sNJbdM>
Subject: [IPsec] New Liaison Statement, "LS on ITU-T SG17 work on quantum-safe PKI"
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2017 15:25:01 -0000

Title: LS on ITU-T SG17 work on quantum-safe PKI
Submission Date: 2017-09-13
URL of the IETF Web page: https://datatracker.ietf.org/liaison/1541/

From: Jean-Paul Lemaire <jean-paul.lemaire@univ-paris-diderot.fr>
To: David Waltermire <david.waltermire@nist.gov>,Tero Kivinen <kivinen@iki.fi>,Russ Housley <housley@vigilsec.com>
Cc: David Waltermire <david.waltermire@nist.gov>,IP Security Maintenance and Extensions Discussion List <ipsec@ietf.org>,itu-t-liaison@iab.org,Limited Additional Mechanisms for PKIX and SMIME Discussion List <spasm@ietf.org>,Russ Housley <housley@vigilsec.com>,Scott Mansfield <Scott.Mansfield@Ericsson.com>,Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>,Tero Kivinen <kivinen@iki.fi>,Eric Rescorla <ekr@rtfm.com>
Response Contacts: jean-paul.lemaire@univ-paris-diderot.fr
Technical Contacts: 
Purpose: For information

Body: ITU-T Study Group 17 is pleased to inform you that in our August/September 2017 meeting we agreed to start work on the inclusion of a proposal to include optional support for multiple public-key algorithms in Recommendation ITU-T X509 | ISO/IEC 9594-8.

The industry is preparing ICT systems to be resistant to attacks by large-scale quantum computers in addition to more sophisticated attacks by conventional computing resources. Proposed was an optional feature to the X.509 certificate that provides a seamless migration capability to existing PKI systems, and is completely backwardly compatible with existing systems.

While public-key key establishment algorithms are typically negotiated between peers and are generally fairly simple to update, the authentication systems typically rely on a single digital signature algorithm which are more difficult to update. This is because of the circular dependency between PKI-based identity systems and the dependent communication protocols. In order to update a PKI system, one would typically need to create a duplicate PKI system that utilizes a new digital signature algorithm and then migrate all the dependent systems one by one.

This proposal eliminates the need to create such duplicate PKI systems by adding optional extensions to contain alternate public key and alternate signature, and a method for the CA to sign certificates using a layered approach to ensure that every attribute is authenticated by both signatures. The resulting certificate, while containing new quantum safe public key and signature, can still be used by existing systems relying on the classic public key and signature.
Attachments:

    sp16-sg17-oLS-00068
    https://www.ietf.org/lib/dt/documents/LIAISON/liaison-2017-09-13-itu-t-sg-17-ipsecme-lamps-ls-on-itu-t-sg17-work-on-quantum-safe-pki-attachment-1.pdf