Advancing Our Amazing Bet on A... Note

Advancing Our Amazing Bet on Asymmetric Cryptography

Google has implemented hybrid post-quantum key exchange (Kyber) in Chrome to mitigate the risk of future quantum computers decrypting encrypted traffic. Launching this draft version aligns with Google's strategy of prioritizing post-quantum cryptography deployment in vulnerable systems. Chrome's post-quantum strategy focuses on quantum-resistant key exchange in HTTPS and increased agility in certificates from the Web PKI. The urgency of migrating to post-quantum cryptography for key exchange is greater than for authentication due to the threat of "store-now-decrypt-later" attacks. However, post-quantum cryptography is larger than pre-quantum algorithms, causing transmission delays and noticeable latency, particularly on Android. The size issues are even more significant for post-quantum authentication, which requires transmitting large keys and signatures. To address these challenges, Google proposes a multi-certificate deployment model and introduces the "Trust Expressions" proposal for trust anchor negotiation in TLS, which would allow for seamless addition and removal of post-quantum authentication methods.