Topic Title
Post-quantum supply chain transparency as part of Business Operations
Topic Overview
Transparency about (directly or indirectly) used algorithms in the supply chain is crucial to identify potential threats by cryptography that may be broken by quantum computing.
Problem Statement or Opportunity
NIST has finalized its first set of FIPS standards (FIPS 203, 204, 205) to replace legacy public-key encryption with lattice-based and hash-based algorithms to defend against future quantum attacks. These standards, including ML-KEM and ML-DSA, are designed for key exchange and digital signatures, with adoption recommended immediately for infrastructure protection. [1]
The SPDX project has started to collect and identify algorithms with unique identifiers in the cryptographic-algorithm-list [2]. Additionally there is already Open Source tooling available to detect cryptographic algorithms in source code [3].
Organizations need transparency about
1.) Direct area: the algorithms used in their products to be able to judge potential impact of quantum computing
2.) Indirect area: the algorithms used in the development- and manufacturing environment along the supply chain
and plan respective mitigation scenarios.
Potential Outcomes
- Future project proposal and changes to the specs
Topic Maturity
Early Idea
Topic Champion
No response
References
[1] https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved
[2] https://github.com/spdx/cryptographic-algorithm-list
[3] https://github.com/scanoss/crypto-finder
Topic Title
Post-quantum supply chain transparency as part of Business Operations
Topic Overview
Transparency about (directly or indirectly) used algorithms in the supply chain is crucial to identify potential threats by cryptography that may be broken by quantum computing.
Problem Statement or Opportunity
NIST has finalized its first set of FIPS standards (FIPS 203, 204, 205) to replace legacy public-key encryption with lattice-based and hash-based algorithms to defend against future quantum attacks. These standards, including ML-KEM and ML-DSA, are designed for key exchange and digital signatures, with adoption recommended immediately for infrastructure protection. [1]
The SPDX project has started to collect and identify algorithms with unique identifiers in the cryptographic-algorithm-list [2]. Additionally there is already Open Source tooling available to detect cryptographic algorithms in source code [3].
Organizations need transparency about
1.) Direct area: the algorithms used in their products to be able to judge potential impact of quantum computing
2.) Indirect area: the algorithms used in the development- and manufacturing environment along the supply chain
and plan respective mitigation scenarios.
Potential Outcomes
Topic Maturity
Early Idea
Topic Champion
No response
References
[1] https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved
[2] https://github.com/spdx/cryptographic-algorithm-list
[3] https://github.com/scanoss/crypto-finder