Skip to content
Tech

Why can I not migrate a credential I issued last year to quantum-safe signatures?

78

Oportunidad

NIST finalized ML-DSA and ML-KEM in 2024, giving new systems a clear cryptographic target, but every verifiable credential already in circulation is signed with ECDSA or EdDSA. There is no technical path to upgrade an issued credential to a new signature scheme without revoking and reissuing it, which requires simultaneously coordinating every issuer and every holder. Long-lived credentials in government, healthcare, and education are precisely the documents an adversary archives today to decrypt when quantum capability matures. On top of the key-migration problem, ML-DSA signatures are roughly five times larger than Ed25519, which breaks the compact presentation formats that selective-disclosure implementations currently depend on. The cryptography has a standardized roadmap; the credential lifecycle does not.

Por qué importa

Without a migration path for already-issued credentials, the post-quantum transition will force simultaneous mass-reissuance crises at governments and health systems worldwide.

Cómo evalúo la oportunidad

La Puntuación de Oportunidad es mi propia lectura, no una medición: cuánto duele, con qué frecuencia aparece y qué tan poco existe para resolverlo hoy. Un valor más alto significa que creo que vale más la pena construirlo.

Gravedad8/10

Cuánto dolor causa cuando aparece.

Frecuencia6/10

Con qué frecuencia la gente se topa con ello.

Espacio en blanco8/10

Qué tan pocas herramientas buenas existen para ello hoy.

Más problemas que vale la pena resolver