Skip to content
Tech

Why can I not migrate a credential I issued last year to quantum-safe signatures?

78

機会

NIST finalized ML-DSA and ML-KEM in 2024, giving new systems a clear cryptographic target, but every verifiable credential already in circulation is signed with ECDSA or EdDSA. There is no technical path to upgrade an issued credential to a new signature scheme without revoking and reissuing it, which requires simultaneously coordinating every issuer and every holder. Long-lived credentials in government, healthcare, and education are precisely the documents an adversary archives today to decrypt when quantum capability matures. On top of the key-migration problem, ML-DSA signatures are roughly five times larger than Ed25519, which breaks the compact presentation formats that selective-disclosure implementations currently depend on. The cryptography has a standardized roadmap; the credential lifecycle does not.

重要な理由

Without a migration path for already-issued credentials, the post-quantum transition will force simultaneous mass-reissuance crises at governments and health systems worldwide.

機会をどう評価するか

Opportunity Scoreは測定値ではなく、私自身の見解です。どれほど痛みを伴うか、どれほど頻繁に影響を与えるか、そして今日時点で解決策がいかに少ないか。スコアが高いほど、構築する価値が高いと私は考えています。

深刻度8/10

それが現れたときにどれほどの痛みをもたらすか。

頻度6/10

実際にどれほど頻繁に人々がそれに直面するか。

ホワイトスペース8/10

今日時点で、それに対する優れたツールがいかに少ないか。

解決する価値のある問題をもっと見る