Desafios Operacionais e Estratégias para Implantação de ICPs Pós-Quânticas em Escala Nacional
Resumo
Este artigo apresenta um estudo de caso técnico-estratégico sobre a preparação de uma Infraestrutura de Chaves Públicas (ICP) nacional e regulada para assinaturas digitais pós-quânticas. O estudo discute requisitos de migração, restrições operacionais, agilidade criptográfica, revogação, carimbo do tempo, HSMs, smartcards e conformidade normativa. Também avaliamos o impacto da substituição de assinaturas clássicas por ML-DSA a partir de volumes operacionais aproximados de uma cadeia real e de benchmarks em HSM. Os resultados indicam que a migração afeta não apenas os algoritmos criptográficos, mas também armazenamento, tráfego de rede, vazão de HSMs, interoperabilidade e governança. O trabalho contribui com evidências práticas e lições para ICPs que precisam planejar migrações pós-quânticas sob restrições de continuidade e conformidade.Referências
Adkins, H. and Schmieg, S. (2026). Quantum Frontiers May Be Closer Than They Appear. Google Blog, [link]. [Accessed 28-05-2026].
Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P., Green, M., Halderman, J. A., Heninger, N., Springall, D., Thomé, E., Valenta, L., VanderSloot, B., Wustrow, E., Zanella-Béguelin, S., and Zimmermann, P. (2015). Imperfect forward secrecy: How Diffie-Hellman fails in practice. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS ’15), pages 5–17. ACM.
AlFardan, N., Bernstein, D. J., Paterson, K. G., Poettering, B., and Schuldt, J. C. N. (2013). On the security of RC4 in TLS. In 22nd USENIX Security Symposium (USENIX Security 13), pages 305–320, Washington, D.C. USENIX Association.
Alnahawi, N., Schmitt, N., Wiesmaier, A., Heinemann, A., and Grasmeyer, T. (2023). On the state of crypto-agility. Cryptology ePrint Archive, Paper 2023/487.
Barker, E., Chen, L., Cooper, D., Moody, D., Regenscheid, A., Souppaya, M., Newhouse, W., Housley, R., Turner, S., Barker, W., and Kent, K. (2025). Considerations for Achieving Crypto Agility: Strategies and Practices. NIST Cybersecurity White Paper 39, DOI: 10.6028/NIST.CSWP.39. [Accessed 28-05-2026].
Bernstein, D. J. and Lange, T. (2017). Post-quantum cryptography. Nature, 549(7671):188–194.
Brasil (2001). Medida provisória nº 2200-2, de 24 de agosto de 2001. Diário Oficial [da] República Federativa do Brasil.
De Feo, L., Kohel, D., Leroux, A., Petit, C., and Wesolowski, B. (2020). Sqisign: Compact post-quantum signatures from quaternions and isogenies. In Moriai, S. and Wang, H., editors, Advances in Cryptology – ASIACRYPT 2020, pages 64–93, Cham. Springer International Publishing.
Heninger, N., Durumeric, Z., Wustrow, E., and Halderman, J. A. (2012). Mining your Ps and Qs: Detection of widespread weak keys in network devices. In Proceedings of the 21st USENIX Security Symposium (USENIX Security 12). USENIX Association.
Housley, R., Polk, W., Turner, S., and Polk, T. (2008). Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. RFC 5280. Internet Engineering Task Force (IETF).
Instituto Nacional de Tecnologia da Informação (2024). gov.br. [link]. [Accessed 14-07-2025].
Instituto Nacional de Tecnologia da Informação (ITI) (2026). Instrução normativa ITI nº 35, de 30 de janeiro de 2026. Diário Oficial da União, Brasília, DF. Acessado em: 5 de agosto de 2026.
Kotzias, P., Razaghpanah, A., Amann, J., Paterson, K. G., Vallina-Rodriguez, N., and Caballero, J. (2018). Coming of age: A longitudinal study of TLS deployment. In Proceedings of the 2018 Internet Measurement Conference (IMC ’18), Boston, MA, USA. ACM.
Moody, D., Perlner, R., Regenscheid, A., Robinson, A., and Cooper, D. (2024). Transition to post-quantum cryptography standards. Technical report, National Institute of Standards and Technology.
National Institute of Standards and Technology (2022). NIST Transitioning Away from SHA-1 for All Applications. [link]. [Accessed 28-05-2026].
Nelson, D. B. (2011). Crypto-Agility Requirements for Remote Authentication Dial-In User Service (RADIUS). RFC 6421.
NIST (2024a). Module-lattice-based digital signature standard. DOI: 10.6028/NIST.FIPS.204. [Accessed 14-07-2025].
NIST (2024b). Module-lattice-based key-encapsulation mechanism standard. DOI: 10.6028/NIST.FIPS.203. [Accessed 14-07-2025].
NIST (2024c). Stateless hash-based digital signature standard. DOI: 10.6028/NIST.FIPS.205. [Accessed 14-07-2025].
Shor, P. (1994). Algorithms for quantum computation: discrete logarithms and factoring. In Proceedings 35th Annual Symposium on Foundations of Computer Science, pages 124–134.
Vakarjuk, J., Snetkov, N., and Laud, P. (2024). Identifying obstacles of pqc migration in e-estonia. In 2024 16th International Conference on Cyber Conflict: Over the Horizon (CyCon), pages 63–81.
Weise, J. (2001). Public key infrastructure overview. Sun BluePrints OnLine, August, pages 1–27.
Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P., Green, M., Halderman, J. A., Heninger, N., Springall, D., Thomé, E., Valenta, L., VanderSloot, B., Wustrow, E., Zanella-Béguelin, S., and Zimmermann, P. (2015). Imperfect forward secrecy: How Diffie-Hellman fails in practice. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS ’15), pages 5–17. ACM.
AlFardan, N., Bernstein, D. J., Paterson, K. G., Poettering, B., and Schuldt, J. C. N. (2013). On the security of RC4 in TLS. In 22nd USENIX Security Symposium (USENIX Security 13), pages 305–320, Washington, D.C. USENIX Association.
Alnahawi, N., Schmitt, N., Wiesmaier, A., Heinemann, A., and Grasmeyer, T. (2023). On the state of crypto-agility. Cryptology ePrint Archive, Paper 2023/487.
Barker, E., Chen, L., Cooper, D., Moody, D., Regenscheid, A., Souppaya, M., Newhouse, W., Housley, R., Turner, S., Barker, W., and Kent, K. (2025). Considerations for Achieving Crypto Agility: Strategies and Practices. NIST Cybersecurity White Paper 39, DOI: 10.6028/NIST.CSWP.39. [Accessed 28-05-2026].
Bernstein, D. J. and Lange, T. (2017). Post-quantum cryptography. Nature, 549(7671):188–194.
Brasil (2001). Medida provisória nº 2200-2, de 24 de agosto de 2001. Diário Oficial [da] República Federativa do Brasil.
De Feo, L., Kohel, D., Leroux, A., Petit, C., and Wesolowski, B. (2020). Sqisign: Compact post-quantum signatures from quaternions and isogenies. In Moriai, S. and Wang, H., editors, Advances in Cryptology – ASIACRYPT 2020, pages 64–93, Cham. Springer International Publishing.
Heninger, N., Durumeric, Z., Wustrow, E., and Halderman, J. A. (2012). Mining your Ps and Qs: Detection of widespread weak keys in network devices. In Proceedings of the 21st USENIX Security Symposium (USENIX Security 12). USENIX Association.
Housley, R., Polk, W., Turner, S., and Polk, T. (2008). Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. RFC 5280. Internet Engineering Task Force (IETF).
Instituto Nacional de Tecnologia da Informação (2024). gov.br. [link]. [Accessed 14-07-2025].
Instituto Nacional de Tecnologia da Informação (ITI) (2026). Instrução normativa ITI nº 35, de 30 de janeiro de 2026. Diário Oficial da União, Brasília, DF. Acessado em: 5 de agosto de 2026.
Kotzias, P., Razaghpanah, A., Amann, J., Paterson, K. G., Vallina-Rodriguez, N., and Caballero, J. (2018). Coming of age: A longitudinal study of TLS deployment. In Proceedings of the 2018 Internet Measurement Conference (IMC ’18), Boston, MA, USA. ACM.
Moody, D., Perlner, R., Regenscheid, A., Robinson, A., and Cooper, D. (2024). Transition to post-quantum cryptography standards. Technical report, National Institute of Standards and Technology.
National Institute of Standards and Technology (2022). NIST Transitioning Away from SHA-1 for All Applications. [link]. [Accessed 28-05-2026].
Nelson, D. B. (2011). Crypto-Agility Requirements for Remote Authentication Dial-In User Service (RADIUS). RFC 6421.
NIST (2024a). Module-lattice-based digital signature standard. DOI: 10.6028/NIST.FIPS.204. [Accessed 14-07-2025].
NIST (2024b). Module-lattice-based key-encapsulation mechanism standard. DOI: 10.6028/NIST.FIPS.203. [Accessed 14-07-2025].
NIST (2024c). Stateless hash-based digital signature standard. DOI: 10.6028/NIST.FIPS.205. [Accessed 14-07-2025].
Shor, P. (1994). Algorithms for quantum computation: discrete logarithms and factoring. In Proceedings 35th Annual Symposium on Foundations of Computer Science, pages 124–134.
Vakarjuk, J., Snetkov, N., and Laud, P. (2024). Identifying obstacles of pqc migration in e-estonia. In 2024 16th International Conference on Cyber Conflict: Over the Horizon (CyCon), pages 63–81.
Weise, J. (2001). Public key infrastructure overview. Sun BluePrints OnLine, August, pages 1–27.
Publicado
01/09/2026
Como Citar
MILANEZ, Arthur G. C.; SOUZA, Victor L. de; PIERI, Giovani; MARTINA, Jean.
Desafios Operacionais e Estratégias para Implantação de ICPs Pós-Quânticas em Escala Nacional. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 456-471.
DOI: https://doi.org/10.5753/sbseg.2026.29368.
