Skip to content

[Topic] Post-quantum supply chain transparency as part of Business Operations #4

Description

@mkurzman

Topic Title

Post-quantum supply chain transparency as part of Business Operations

Topic Overview

Transparency about (directly or indirectly) used algorithms in the supply chain is crucial to identify potential threats by cryptography that may be broken by quantum computing.

Problem Statement or Opportunity

NIST has finalized its first set of FIPS standards (FIPS 203, 204, 205) to replace legacy public-key encryption with lattice-based and hash-based algorithms to defend against future quantum attacks. These standards, including ML-KEM and ML-DSA, are designed for key exchange and digital signatures, with adoption recommended immediately for infrastructure protection. [1]
The SPDX project has started to collect and identify algorithms with unique identifiers in the cryptographic-algorithm-list [2]. Additionally there is already Open Source tooling available to detect cryptographic algorithms in source code [3].

Organizations need transparency about
1.) Direct area: the algorithms used in their products to be able to judge potential impact of quantum computing
2.) Indirect area: the algorithms used in the development- and manufacturing environment along the supply chain
and plan respective mitigation scenarios.

Potential Outcomes

  • Future project proposal and changes to the specs

Topic Maturity

Early Idea

Topic Champion

No response

References

[1] https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved
[2] https://github.com/spdx/cryptographic-algorithm-list
[3] https://github.com/scanoss/crypto-finder

Metadata

Metadata

Assignees

No one assigned

    Labels

    topicTopic for the Study Group backlog

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions