# IAB Workshop on Accelerating the Deployment of Post-Quantum Authentication 
(pqws)

Workshop webpage: https://datatracker.ietf.org/group/pqws/about/

## Executive Summary

The IAB is hosting a workshop for implementers, operators and protocol 
designers to help facilitate the acceleration of the deployment of post-quantum 
signatures and authentication. The workshop will (tentatively) be held in 
Prague, Czechia on October 11-12 to co-locate with the 2026 OpenSSL conference. 
The goal of the workshop is to document deployment experience, challenges, and 
the open questions that remain.

## Call for Papers

### The problem

Post-quantum key establishment is now widely deployed across the Internet. 
Post-quantum authentication is the harder half, and it lags. The signatures and 
public keys are large, several kilobytes for ML-DSA [FIPS204] and SLH-DSA 
[FIPS205] signatures larger still, whereas the elliptic-curve mechanisms in use 
today take a few dozen bytes. Authentication uses them in many places at once, 
and there is no single switch to throw, because the work is spread across 
certificates, the public-key infrastructure, the hardware that holds keys, 
identity tokens, and firmware and software signing, some of it validated 
offline or years later.

The first algorithms and specifications are arriving, but adoption is barely 
underway: a 2025 survey of more than a thousand security leaders found only 5% 
had deployed any quantum-safe encryption [PQREADY], and authentication lags 
even that. The people who will have to close the gap, certificate authorities, 
vendors of hardware security modules (HSMs), trusted platform modules (TPMs), 
secure elements and smartcards, identity providers, firmware and software 
signing teams, and operators of regulated, constrained, or long-lived systems, 
are mostly not the people who participate in standardization. Without a shared 
picture of what impedes deployment and where the open problems lie, 
post-quantum authentication will fragment. This workshop brings deployment 
experience together with the people working on the approaches and the relevant 
standards, to produce a clear, sourced snapshot of what is blocking deployment 
and where the open problems are.

### In and out of scope

In scope is the deployment of post-quantum authentication: signatures, 
certificates, tokens, the hardware that holds keys, and the practice around 
them. The proposed approaches, including hybrid and composite signatures, 
Merkle Tree Certificates, and KEM-based authentication, are examined as far as 
their deployment implications are concerned. The workshop is not intended to 
compare, recommend, or converge on any particular approach, nor to select or 
standardize algorithms. Post-quantum key establishment is not itself in scope; 
it appears only as a source of lessons that carry over to authentication.

### What to submit

We are looking for short position papers (1-2 pages PDF) on real experience 
with post-quantum authentication. The most common kind describes a specific 
deployment problem: what is being deployed or planned, which element is 
blocked, what can be worked around and at what cost, and what cannot with 
current specifications, tools, hardware, or practice. The paper does not need 
to be reporting a blocker. We also want researchers with relevant results, 
measurements of where deployment stands today, regulatory and policy 
constraints, and honest accounts of migrations that were attempted and ran into 
trouble. Give the figures that support your point, such as sizes, timings, 
throughput, memory, or validation timelines, and say where you think follow-up 
should occur. Lessons from post-quantum key-establishment deployment are 
welcome where they carry over to authentication, though key establishment is 
not itself a topic for this workshop.

Examples of topics we want to hear about, not an exhaustive list:

* Certificates, PKI, DNS: chain and handshake size, path validation across 
mixed chains, transparency, and revocation growth.  
* Keys and hardware: HSM, FIPS 140-3, and PKCS#11 readiness, and the management 
of stateful hash-based keys, IoT/constrained devices.  
* Identity and tokens: post-quantum signatures in JOSE and COSE tokens and the 
systems built on them, such as OAuth, verifiable credentials, and WebAuthn.  
* Software and firmware signing: package, container, and firmware size limits, 
offline verification, and long-lived or archival validation.  
* The approaches in practice: where hybrid and composite signatures 
[COMPOSITE], Merkle Tree Certificates [MTC], and KEM-based authentication 
[AUTHKEM] fit and where they break, migration strategies.

Submissions are due 4 September 2026 (AoE) via email to [email protected]. 
Decisions will be issued on a rolling basis as submissions arrive, with all 
outcomes communicated by 14 September 2026\. Submitters who need extra lead 
time for visas or travel approval should say so in their submission, and the 
Program Committee will prioritize their decisions.

### Who should participate

The people most needed are those who will deploy Post-Quantum Authentication 
and are not usually at the IETF: certificate authorities and trust-store 
operators, hardware and HSM vendors, identity providers, firmware and software 
signing teams, regulated-sector operators, and operators of constrained or 
long-lived systems.

### What the workshop produces

A report published on the IAB stream summarizing the submissions and the 
discussion. It is intended to document deployment experience, challenges, and 
open questions, not to recommend or converge on any particular approach, or to 
direct the work of IETF working groups or the IRTF. The workshop organizers may 
also propose a subsequent venue for follow-ups and next steps.

### Logistics

The workshop will be by invitation only. This is an in-person meeting. Remote 
participation may be offered at the Program Committee's discretion. Those 
wishing to attend should submit a "position paper". One or two pages in PDF is 
enough, relevant submitted position papers will be published on the workshop's 
datatracker page, and papers from people who do not plan to attend are also 
welcome. Submissions are inputs to the agenda, not talks, and not every 
submission will be presented. The workshop itself will be focused on 
discussions. Anyone may submit a short statement of interest in place of a full 
position paper, though position papers carry more weight in shaping the agenda. 
The Program Committee may also invite key participants directly, without a 
submission.

Accepted position papers will normally be published on the Datatracker before 
the workshop. Authors who would prefer that their paper not be published, or 
that specific material be handled without attribution, should indicate this at 
submission and note whether it affects what they would be willing to present 
during the workshop. If any discussion requires the Chatham House Rule, please 
indicate that during the workshop or to the respective session moderator in 
advance. The workshop will not have public recordings or minutes, however, 
collabrative notes (e.g., via HedgeDoc) will be maintained to assist in 
preparing the report and kept as a public reference, excluding any sections 
subject to the Chatham House Rule.

The IETF code of conduct, and the IETF anti-harassment policy apply. 
Contributions are subject to the IETF intellectual property policy.

* Paper submissions due by: 2026-09-11
* Invitations to attendees sent: rolling as submissions arrive; all outcomes by 
2026-09-18 
* Workshop date: 2026-10-11 (Sunday) and 2026-10-12 (Monday)  
* Workshop location: Prague  
* Program committee:  
  * Nick Sullivan (Cryptography Consulting LLC/IAB)  
  * Yaroslav Rosomakho (Zscaler/IAB)  
  * Suresh Krishnan (Cisco/IAB)  
  * Thom Wiggers (PQShield)  
  * Mike Ounsworth (Cryptic Forest Software)  
  * Hoss Shafagh (Netflix)  
  * Vladimir Soukharev (Keyfactor)  
  * Tim Hollebeek (DigiCert)  
  * Murugiah Souppaya (HP)

### References

* [FIPS204] NIST, "Module-Lattice-Based Digital Signature Standard," FIPS 204.  
* [FIPS205] NIST, "Stateless Hash-Based Digital Signature Standard," FIPS 205.  
* [COMPOSITE] "Composite ML-DSA for use in X.509 Public Key Infrastructure," 
draft-ietf-lamps-pq-composite-sigs.  
* [MTC] "Merkle Tree Certificates," draft-ietf-plants-merkle-tree-certs.  
* [AUTHKEM] "KEM-based Authentication for TLS 1.3," 
draft-celi-wiggers-tls-authkem.  
* [PQREADY] DigiCert, "2025 Quantum Readiness Study," Propeller Insights survey 
of 1,042 security leaders, May 2025, 
https://www.digicert.com/news/quantum-readiness-gap-a-digicert-study-on-quantum-safe-encryption.

_______________________________________________
IETF-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to