Paper 2025/2082
Integrating PQC in OpenSSL via Shallow Providers for Cryptographic Agility
Abstract
The emergence of Cryptographically Relevant Quantum Computers (CRQCs) threatens traditional cryptographic systems, necessitating a transition to Post-Quantum Cryptography (PQC). OpenSSL 3.0 introduced `Providers`, enabling modular cryptographic integration. This work presents the concept of a "shallow `Provider`", facilitating integration of external implementations, to achieve a higher degree of cryptographic agility. `aurora`, which we introduce as an instance of the "shallow `Provider`" methodology, integrates standardized PQC algorithms in TLS 1.3 for both key establishment and authentication, to support the PQC transition. It enhances cryptographic agility by allowing OpenSSL to dynamically adapt to evolving PQC standards and the rapidly evolving ecosystem of PQC implementations.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Published elsewhere. NordSec 2025
- Keywords
- OpenSSLshallow ProviderPost-Quantum CryptographyApplied CryptographySecure Internet Browsing
- Contact author(s)
-
akif mehmood @ tuni fi
nicola tuveri @ tuni fi - History
- 2025-11-13: approved
- 2025-11-11: received
- See all versions
- Short URL
- https://ia.cr/2025/2082
- License
-
CC BY-SA
BibTeX
@misc{cryptoeprint:2025/2082,
author = {Akif Mehmood and Nicola Tuveri},
title = {Integrating {PQC} in {OpenSSL} via Shallow Providers for Cryptographic Agility},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2082},
year = {2025},
url = {https://eprint.iacr.org/2025/2082}
}