Paper 2025/2082

Integrating PQC in OpenSSL via Shallow Providers for Cryptographic Agility

Akif Mehmood, Tampere University
Nicola Tuveri, Tampere University
Abstract

The emergence of Cryptographically Relevant Quantum Computers (CRQCs) threatens traditional cryptographic systems, necessitating a transition to Post-Quantum Cryptography (PQC). OpenSSL 3.0 introduced `Providers`, enabling modular cryptographic integration. This work presents the concept of a "shallow `Provider`", facilitating integration of external implementations, to achieve a higher degree of cryptographic agility. `aurora`, which we introduce as an instance of the "shallow `Provider`" methodology, integrates standardized PQC algorithms in TLS 1.3 for both key establishment and authentication, to support the PQC transition. It enhances cryptographic agility by allowing OpenSSL to dynamically adapt to evolving PQC standards and the rapidly evolving ecosystem of PQC implementations.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. NordSec 2025
Keywords
OpenSSLshallow ProviderPost-Quantum CryptographyApplied CryptographySecure Internet Browsing
Contact author(s)
akif mehmood @ tuni fi
nicola tuveri @ tuni fi
History
2025-11-13: approved
2025-11-11: received
See all versions
Short URL
https://ia.cr/2025/2082
License
Creative Commons Attribution-ShareAlike
CC BY-SA

BibTeX

@misc{cryptoeprint:2025/2082,
      author = {Akif Mehmood and Nicola Tuveri},
      title = {Integrating {PQC} in {OpenSSL} via Shallow Providers for Cryptographic Agility},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2082},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2082}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.