Paper 2026/2297

An Analysis of the ITU-T Multiple Cryptographic Algorithms X.509 Extensions for PQC Migration

Falko Strenzke, MTG AG
Abstract

The 2019 edition of ITU-T X.509 adds three certificate extensions, colloquially called the Catalyst extensions, that let a single certificate carry a second, alternative public key and issuer signature beside the native ones, as a backwards-compatible path for migrating a public-key infrastructure to post-quantum cryptography (PQC). This paper collects the known problems of this multiple cryptographic algorithms (MCA) mechanism and adds several findings of its own. The central and previously known weakness is that a quantum attacker who recovers a single traditional certification-authority key can replace any certificate in a chain by a traditional-only one that a relying party still accepts. We give a precise attack model with a sub-CA and an end-entity-forgery variant to emphasize the inherent problem. As an example, we verify empirically that the susceptibility to this downgrade attack is present in the wolfSSL cryptographic library as a natural consequence. Our further findings concern the construction itself and details of the specification. For one, we analyze the formal violations of EUF-CMA that arise due to the possibility of re-purposing the extension signature to the established signed data format in X.509, which is formally manifest as soon as the alternative key in the extension is also certified as a native key. We show that several further aspects in the ITU-T mechanism remain undefined, which potentially leads to divergent behaviour of clients, and point out that a certificate accepted on its alternative signature alone, as allowed per ITU-T specification, can be invalid under RFC~5280 and potentially exposes an application to arbitrary injected data and even modified signatures chaining it to a certificate chosen by a non-quantum attacker in the positively validated certificate chain.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
PQCX.509multi-algorithmdigital signature
Contact author(s)
falko strenzke @ mtg de
History
2026-10-04: approved
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2297
License
Creative Commons Attribution-ShareAlike
CC BY-SA

BibTeX

@misc{cryptoeprint:2026/2297,
      author = {Falko Strenzke},
      title = {An Analysis of the {ITU}-T Multiple Cryptographic Algorithms X.509 Extensions for {PQC} Migration},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2297},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2297}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.