Security for the Quantum Era: ... Note

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

Modern digital security faces threats from advancing quantum computing, which can potentially break current encryption methods. To address this, a multi-year migration to Post-Quantum Cryptography (PQC) is crucial, as spearheaded by the National Institute of Standards and Technology (NIST). Google has been preparing for this since 2016, and Android 17 is spearheading the initial implementation. Android 17 will begin a comprehensive architectural upgrade to incorporate the finalized NIST PQC standards throughout the operating system. This update will include the implementation of the Module-Lattice-Based Digital Signature Algorithm (ML-DSA) into Android Verified Boot and Remote Attestation. Android Keystore will be updated to support ML-DSA, allowing developers to use quantum-safe signatures within secure hardware. Android is extending its PQC protection to application signatures through hybrid signing on Google Play. Google Play will facilitate the generation of quantum-safe ML-DSA signing keys for apps, promoting a smooth transition for developers. Android's roadmap includes future integration of post-quantum key encapsulation for added security. This ensures the Android ecosystem remains resilient and protects against future quantum threats.