0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
An Analysis of the ITU-T Multiple Cryptographic Algorithms X.509 Extensions for PQC Migration
- 1.ITU-T X.509 '캐탈리스트' 확장의 PQC 마이그레이션 다운그레이드 취약점 정리
- 2.CA의 기존(고전) 키 하나만 복구돼도 체인 전체를 고전 전용으로 위조 가능
- 3.wolfSSL 라이브러리에서 실제 다운그레이드 공격 성립을 실증
- 4.확장 서명 재사용으로 EUF-CMA 위반 등 명세 미정의 동작 다수 발견
왜 중요한가?
PKI를 PQC로 전환하는 표준 호환 경로로 꼽히는 메커니즘 자체에 구조적 다운그레이드 위험이 있다는 지적으로, 채택하려는 인증기관·라이브러리 개발자들이 완화 정책을 선제 적용해야 함을 시사한다.
언급 프로젝트
본문 미리보기
The 2019 edition of ITU-T X.509 adds three certificate extensions, colloquially called the Catalyst extensions, that let a single certificate carry a second, alternative public key and issuer signature beside the native ones, as a backwards-compatible path for migrating a public-key infrastructure to post-quantum cryptography (PQC). This paper collects the known problems of this multiple cryptographic algorithms (MCA) mechanism and adds several findings of its own. The central and previously kno
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



