Organizations have to plan on migrating to quantum-resilient cryptographic measures, also known as PQC. However, this is a difficult task, and to the best of our knowledge, there is no generalized approach to manage such a complex migration for cryptography used in IT systems that explicitly integrates into organizations' steering mechanisms and control systems. We present PMMP, a risk-based process for managing the migration of organizations from classic cryptography to PQC and establishing crypto-agility. Having completed the initial design phase, as well as a theoretical evaluation, we now intend to promote PMMP. Practitioners are encouraged to join the effort in order to enable a comprehensive practical evaluation and further development.
翻译:组织必须规划向量子弹性密码措施(即PQC)的迁移。然而,这是一项艰巨的任务,据我们所知,目前尚无通用的方法能够管理IT系统中密码学应用的这种复杂迁移,并能明确整合到组织的指导机制和控制体系中。我们提出了PMMP,一种基于风险的过程,用于管理组织从经典密码学到PQC的迁移,并建立密码敏捷性。在完成初始设计阶段以及理论评估后,我们现计划推广PMMP。鼓励从业者加入这一工作,以实现全面的实践评估和进一步开发。