A Post-Quantum Evidence Layer for Incremental Migration of Legacy Digital Signature Systems

Resumo


Deployed digital-signature infrastructures cannot migrate atomically because cryptographic algorithms are coupled to certificates, policies, validation services, formats, and document workflows. This paper proposes an incremental migration model that introduces post-quantum protection first at the evidence layer. Before practical classical compromise, the target construction commits a document digest, its classical signature, validation material, recorded result, and policy to a Merkle root protected by a post-quantum timestamp token. The model defines a security and deployment boundary identifying which evidence must be captured and which guarantees survive without replacing the original signing infrastructure. Under correct intake validation, collision-resistant hashing, and a trusted timestamping service, it provides tamper evidence and existence-before-time for the captured validation state; it neither upgrades the original signature nor repairs evidence captured too late. A PreserveEU-based prototype evaluates a first implementation step by committing CMS bytes and generating local ML-DSA and SLH-DSA root tokens; enriched package encoding and independently operated post-quantum timestamping remain outside the implementation. Direct CMS measurements contextualize immediate signature-migration costs rather than providing an end-to-end deployment comparison. On the evaluated software-only host, ML-DSA provided the lowest post-quantum token latency and smaller records than the evaluated SLH-DSA variants, whereas SLH-DSA offered diversity from lattice-based assumptions at higher measured cost.

Referências

Adams, C., Cain, P., Pinkas, D., and Zuccherato, R. (2001). Internet x.509 public key infrastructure time-stamp protocol (tsp). RFC 3161.

Alnahawi, N., Westerbaan, B., and Stebila, D. (2023). On the state of crypto-agility. IACR Cryptology ePrint Archive. Report 2023/487.

Bernstein, D. J., Hülsing, A., Rijneveld, J., Niederhagen, R., Schanck, F. S., and Schwabe, P. (2019). The sphincs+ signature framework. IACR Cryptology ePrint Archive. Report 2019/1086.

Blazic, A. J., Saljic, S., and Gondrom, T. (2011). Extensible markup language evidence record syntax (XMLERS). RFC 6283.

Brînzea, A., Leancă, R.-A., Aciobăniţei, I., and Pop, F. (2025). Standard-compliant blockchain anchoring for timestamp tokens. Applied Sciences, 15(23):12722.

Clupek, V., Malina, L., and Zeman, V. (2015). Secure digital archiving in post-quantum era. In 2015 38th International Conference on Telecommunications and Signal Processing (TSP), pages 622–626. IEEE.

Driscoll, M. B., Wallace, C., Gray, J., and Housley, R. (2025). Terminology for post-quantum traditional hybrid schemes. RFC 9794.

Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schwabe, P., Seiler, G., and Stehlé, D. (2018). Crystals-dilithium: A lattice-based digital signature scheme. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018(1):238–268.

ETSI (2017). ETSI TS 119 122-3 V1.1.1: CAdES digital signatures; part 3: Incorporation of evidence record syntax mechanisms in CAdES. Technical report, ETSI.

ETSI (2021). ETSI EN 319 122-1 V1.2.1: CAdES digital signatures; part 1: Building blocks and CAdES baseline signatures. Technical report, ETSI.

ETSI (2024a). ETSI EN 319 102-1 V1.4.1: Procedures for creation and validation of AdES digital signatures; part 1: Creation and validation. Technical report, ETSI.

ETSI (2024b). ETSI EN 319 132-1 V1.3.1: XAdES digital signatures; part 1: Building blocks and XAdES baseline signatures. Technical report, ETSI.

ETSI (2024c). ETSI EN 319 142-1 V1.2.1: PAdES digital signatures; part 1: Building blocks and PAdES baseline signatures. Technical report, ETSI.

Fall, A. A. et al. (2025). Sok: Systematizing hybrid strategies for the transition to post-quantum cryptography. IACR Cryptology ePrint Archive. Report 2025/2052.

Geihs, M., Demirel, D., and Buchmann, J. (2015). On the security of long-lived archiving systems based on the evidence record syntax. In C2SI 2015, pages 27–44. Springer.

Gondrom, T., Brandner, R., and Pordesch, U. (2007). Evidence record syntax (ers). RFC 4998.

Housley, R., Fluhrer, S., Kampanakis, P., and Westerbaan, B. (2025). Use of the SLH-DSA signature algorithm in the cryptographic message syntax (CMS). RFC 9814.

Instituto Nacional de Tecnologia da Informação (2020). DOC-ICP-15: Visão Geral sobre Assinaturas Digitais na ICP-Brasil. Infraestrutura de Chaves Públicas Brasileira.

International Organization for Standardization (2025). Iso 14721:2025 space data system practices — reference model for an open archival information system (oais). International Standard. Identical in content to CCSDS 650.0-M-3, December 2024.

Joseph, D., Misoczki, R., Manzano, M., Campagna, M., Albrecht, M., Tang, A., Khovratovich, D., Schwabe, P., Stebila, D., and Hansen, R. (2022). Transitioning organizations to post-quantum cryptography. Nature, 605(7909):237–243.

Kusber, T., Schwalm, S., Korte, U., and Shamburger, K. (2021). Records management and long-term preservation of evidence in DLT. In Open Identity Summit 2021 (LNI P-312), pages 131–142. Gesellschaft für Informatik.

Moody, D., Perlner, R., Regenscheid, A., Robinson, A., and Cooper, D. (2024). Transition to post-quantum cryptography standards. NIST Interagency/Internal Report 8547 (Initial Public Draft), National Institute of Standards and Technology.

National Institute of Standards and Technology (2024a). FIPS 204: Module-lattice-based digital signature standard. Federal Information Processing Standards Publication 204, National Institute of Standards and Technology.

National Institute of Standards and Technology (2024b). FIPS 205: Stateless hash-based digital signature standard. Federal Information Processing Standards Publication 205, National Institute of Standards and Technology.

National Institute of Standards and Technology (2026). Algorithm registration — computer security objects register (CSOR). Web page. Accessed: 2026-03-10.

NIST (2026). Considerations for achieving cryptographic agility: Strategies and practices. Cybersecurity White Paper 39upd1, National Institute of Standards and Technology.

NIST NCCoE (2026). Migration to post-quantum cryptography. Web page. Accessed: 2026-03-11.

Ounsworth, M., Gray, J., Pala, M., Klaußner, J., and Fluhrer, S. (2026). Composite module-lattice-based digital signature algorithm (ML-DSA) for use in x.509 public key infrastructure. Internet-Draft draft-ietf-lamps-pq-composite-sigs-19, Internet Engineering Task Force. Work in progress.

PreserveEU (2025). ePreservation. PreserveEU. Project documentation describing the ePreservation architecture, XML Evidence Records, Merkle-tree preservation, and timestamp/hash-tree renewal workflows.

Salter, B. S., Raine, A., and Geest, D. V. (2025). Use of the ML-DSA signature algorithm in the cryptographic message syntax (CMS). RFC 9882.

Shor, P. W. (1994). Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings of the 35th Annual Symposium on Foundations of Computer Science (FOCS ’94), pages 124–134. IEEE.

Shostack, A. (2014). Threat Modeling: Designing for Security. John Wiley & Sons.

Thiel, C. and Thiel, C. (2021). Quantum computer resistant cryptographic methods and their suitability for long-term preservation of evidential value. In 34th Bled eConference, pages 481–493. University of Maribor Press.
Publicado
01/09/2026
DILLY, Gabriel; MARTINA, Jean Everson. A Post-Quantum Evidence Layer for Incremental Migration of Legacy Digital Signature Systems. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 32-47. DOI: https://doi.org/10.5753/sbseg.2026.27116.