Direkt zur Hauptnavigation springen Direkt zum Inhalt springen
Program eLSA Symposium '26

The Post-Quantum Transition in Open Source and embedded Software

Clemens Lang - Red Hat GmbH

Physicists are working to build bigger and bigger quantum computers. Computer Scientists are developing better algorithms for quantum computers to break cryptography. Three-letter agencies could target encrypted connections today through "harvest now; decrypt later" attacks. At the same time, the EU mandates quantum-safe software/firmware updates by 2030. Should we all panic, or is all of this irrelevant because nobody will ever build a working quantum computer?

Transitions will take a while, starting with standardization, implementation, and finally deployment. Major protocols like TLS and SSH are leading, but even they only started addressing PQ authentication recently. We’ll cover the state of the art of a few protocols and their open source implementations and provide an outlook for niche protocols and use cases.

Finally, many PQC algorithms use more memory and CPU cycles compared to their classic counterparts, which is problematic for constrained embedded systems. Which alternatives exist for such use cases and how realistic is it to meet deployment deadlines with them? What first steps should your organization take on their transition to post-quantum cryptography?

 

Short Bio:

Clemens Lang has been part of the Red Hat Crypto Team since January 2022 and currently represents the Distributions community on the OpenSSL Foundation Business Advisory Committee. Prior to his work at Red Hat, he took care of open source packaging, over-the-air updates and security of infotainment systems at BMW. Clemens has also contributed to the MacPorts project since Google Summer of Code 2011.