Next-Generation SPIFFE/SPIRE Identity Management Systems with Post-Quantum Cryptography Algorithms
Feb 14, 2025ยท
,,,,,ยท
1 min read
Lucas Cupertino Cardoso
Marco Marques
Pedro Correia
Henrique Cochak
Charles Miers
Marcos Simplicio Junior
Image credit: UnsplashAbstract
Quantum transition reached a new level of importance since NIST standardized post-quantum cryptographic algorithms in late 2024. Consequently, several studies addressed the required changes in existing technologies and systems embracing post-quantum algorithms to face an imminent quantum threat. Cloud-based environments are no different, especially when assuring correct authentication and authorization. We address the usage of post-quantum primitives embedded in identity-management systems, a crucial entity inside distributed systems. Our proposal is based on SPIFFE / SPIRE, an open-source framework for secure identity production, integrating post-quantum and classical primitives in a hybrid manner. Moreover, we discuss using X.509 certificates as part of our infrastructure and their performance, combining different digital signature algorithms.
Type
Publication
In the 25th IEEE international Symposium on Cluster, Cloud and Internet Computing
Click the Cite button above to demo the feature to enable visitors to import publication metadata into their reference management software.
Create your slides in Markdown - click the Slides button to check out the example.
Add the publication’s full text or supplementary notes here. You can use rich formatting such as including code, math, and images.