Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

France ANSSI Views on the Post-Quantum Cryptography Transition (2023 Follow-Up) - Mandatory Hybridation and Security Visa Phases

ANSSI views on the Post-Quantum Cryptography transition (2023 follow up), dated December 21, 2023, is the French national cybersecurity agency's updated…

What France ANSSI Views on the Post-Quantum Cryptography Transition (2023 Follow-Up) - Mandatory Hybridation and Security Visa Phases requires

ANSSI views on the Post-Quantum Cryptography transition (2023 follow up), dated December 21, 2023, is the French national cybersecurity agency's updated position on the post-quantum transition. It is an addendum to ANSSI's 2022 position paper and details recommendations on post-quantum algorithms and hybridation techniques. Its defining feature is that hybridation is not advisory but a condition of French security visa evaluation. ANSSI strongly emphasises the necessity of hybridation wherever post-quantum mitigation is needed, both in the short and medium term, on the reasoning that post-quantum algorithms have gained attention but are still not mature enough to solely ensure the security, several post-quantum schemes having suffered from classical attacks in recent years. It encourages all industries to include the quantum threat in their risk analysis and to define a progressive transition strategy, recommending hybrid post-quantum mitigation especially for security products aimed at offering a long-lasting protection of information until after 2030, or that will potentially be used after 2030 without updates. The security visa process gives the position its force. ANSSI follows a three-phase roadmap for delivering security visas. In the second phase, the cryptographic evaluation tasks of security visa evaluation comprise an analysis of all cryptographic algorithms including the post-quantum algorithms with mandatory hybridation, and the security visa report can mention the presence of state-of-the-art post-quantum protection. ANSSI accelerated the original agenda, with first phase-2 security visas for products implementing hybrid post-quantum cryptography expected around 2024-2025. The requirement differentiates by product type. For end products, meaning final products, any product that includes post-quantum mitigation shall implement hybridation, except where the quantum mitigation only relies on hash-based signatures such as XMSS, LMS or SPHINCS+, for which hybridation is optional. For intermediate products, meaning platform products that provide raw cryptographic functionality to an upper applicative layer, implementing post-quantum cryptography without hybridation can sometimes be relevant, but ANSSI evaluation teams will require an implementation of a hybridation mode for test purposes and the inclusion in the user guidance documentation of a recommendation to exclusively use the provided post-quantum algorithm in combination with a recognised classical algorithm as part of a hybridation mode. On algorithms, ANSSI traditionally does not provide a closed list of recommended algorithms, in order to avoid proscribing innovative state-of-the-art algorithms. Where CRYSTALS-Kyber, also called ML-KEM, is chosen, ANSSI recommends avoiding modification of the parameters of the standardised instance, using the highest NIST security level possible and preferably level 5 equivalent to AES-256 or level 3 equivalent to AES-192, using ephemeral keys as much as possible because systematic use of ephemeral private keys prevents many attacks such as decryption failure attacks, and using the actively secure IND-CCA version. On symmetric cryptography ANSSI is expressly more conservative than both NIST and BSI, encouraging parameters that ensure in practice at least the same security level as AES-256 for block ciphers and at least the same security level as SHA2-384 for hash functions. On combiners it warns that concatenating keys would not ensure security against passive attackers, and that xoring keys provides security against passive attackers but not against active attackers because of mix and match attacks, so a key derivation function is an essential building block.

Pillar: Aviation, Defense & Quantum · Authority: Agence nationale de la securite des systemes d'information (ANSSI), France · Version: 1.0.0 · Last updated:

Primary source: https://messervices.cyber.gouv.fr/documents-guides/follow_up_position_paper_on_post_quantum_cryptography.pdf

SHA-256 integrity: dbd95f021acf29fb86597e8b4e567d8d229142255e01f9899487fa9eaa3d79d9

Primary Citations — 10 traced to source

+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.