Securing Identity Information and Authentication in a Post-Quantum Era
Combined Session
Friday, May 09, 2025 10:30—11:30
Location: B 09
Log in to download presentations
Friday, May 09, 2025 10:30—11:30
Location: B 09
Watch the video
As the European Digital Identity Wallet (EUDIW) ecosystem is being developed, most components are being built using well-established classical cryptographic algorithms. However, the emerging threat of quantum computing attacks on some of these classical cryptographic schemes poses a significant risk to the EUDIW’s privacy and authenticity objectives.
In this presentation, we will explore whether the EUDIW is prepared for the post-quantum era. We will examine the key components of the digital identity ecosystem to identify which parts need to be upgraded to achieve quantum resistance.
We will also assess the current state of crypto-agility and relevant specifications. Additionally, we will share practical experiences of implementing post-quantum cryptography (PQC) signature algorithms for the issuer signature of long-term credentials.
Watch the video
The talk will introduce Post-Quantum Cryptography (PQC) starting from the NIST's algorithm and implementation and standardization efforts of PQC into digital identity and document digital signature, specifically:
- Quick review of the NIST's standardized PQC algorythms: FIPS-203, FIPS-204, FIPS-205, Falcon, their story and implementations
- PQC W3C-VCs: summary of W3C's efforts on standardizing quantum-safe verifiable credentials, based on https://w3c-ccg.github.io/di-quantum-safe/
- PQC experiments with EUDI-ARF: summary of the current EUDIW standardization situation and paths toward implementing quantum sage credentials
- PQC document digital signatures (*AdES): status on standardization of the european document signature standards as well as the ongoing global hybrid X.509 standardization effort
- PQC zero knowledge proof: summary of the current research in PQC ZKP, primarily experimental work, based on QUBIP's work
Watch the video
Quantum computers are evolving faster than expected, posing an imminent threat to the foundations of authentication in digital banking. The conventional cryptography that secures millions of customer transactions today will be obsolete in the post-quantum era.
Banks that delay migration to post-quantum authentication (PQA) and miss Q-Day — the moment when quantum computers are powerful enough to break today’s cryptography — will face a business continuity emergency. Migrating users to quantum-resistant authentication is not a simple update in the background. It requires strategic planning, precise UX design, and proactive execution. The longer banks postpone the transition, the higher the costs, operational risks, and likelihood of security failures.
The industry must act now! Join us as we break down:
- How quantum threats will impact digital banking authentication
- Why leading market analysts position post-quantum cryptography among top strategic tech trends in 2025
- Why banks must start migration projects by 2026 to transition on time
- What the best migration paths to PQA look like (without disrupting users)