Skip to content
Tech

Why can I not migrate a credential I issued last year to quantum-safe signatures?

78

기회

NIST finalized ML-DSA and ML-KEM in 2024, giving new systems a clear cryptographic target, but every verifiable credential already in circulation is signed with ECDSA or EdDSA. There is no technical path to upgrade an issued credential to a new signature scheme without revoking and reissuing it, which requires simultaneously coordinating every issuer and every holder. Long-lived credentials in government, healthcare, and education are precisely the documents an adversary archives today to decrypt when quantum capability matures. On top of the key-migration problem, ML-DSA signatures are roughly five times larger than Ed25519, which breaks the compact presentation formats that selective-disclosure implementations currently depend on. The cryptography has a standardized roadmap; the credential lifecycle does not.

μ™œ μ€‘μš”ν•œκ°€

Without a migration path for already-issued credentials, the post-quantum transition will force simultaneous mass-reissuance crises at governments and health systems worldwide.

기회 평가 방식

기회 μ μˆ˜λŠ” 츑정값이 μ•„λ‹Œ 제 주관적 ν‰κ°€μž…λ‹ˆλ‹€. μ–Όλ§ˆλ‚˜ λΆˆνŽΈν•œμ§€, μ–Όλ§ˆλ‚˜ 자주 λ°œμƒν•˜λŠ”μ§€, ν˜„μž¬ 해결책이 μ–Όλ§ˆλ‚˜ λΆ€μ‘±ν•œμ§€λ₯Ό λ°˜μ˜ν•©λ‹ˆλ‹€. μ μˆ˜κ°€ λ†’μ„μˆ˜λ‘ λ§Œλ“€ κ°€μΉ˜κ°€ 더 λ†’λ‹€κ³  μƒκ°ν•©λ‹ˆλ‹€.

심각도8/10

λ°œμƒν–ˆμ„ λ•Œ μ–Όλ§ˆλ‚˜ 큰 λΆˆνŽΈμ„ μ΄ˆλž˜ν•˜λŠ”μ§€.

λΉˆλ„6/10

μ‹€μ œλ‘œ μ–Όλ§ˆλ‚˜ 자주 μ ‘ν•˜κ²Œ λ˜λŠ”μ§€.

곡백 μ˜μ—­8/10

ν˜„μž¬ 이λ₯Ό ν•΄κ²°ν•  λ§Œν•œ 도ꡬ가 μ–Όλ§ˆλ‚˜ λΆ€μ‘±ν•œμ§€.

ν•΄κ²°ν•  κ°€μΉ˜ μžˆλŠ” 더 λ§Žμ€ λ¬Έμ œλ“€