Development of 'Quantum PKI Studio', one-stop creation and verification from X.509 to PQC and hybrid certificates
The Electronics and Telecommunications Research Institute (ETRI) has developed an integrated research platform capable of testing and verifying a next-generation joint certificate system in advance, in preparation for the era of quantum computing.
ETRI announced on the 22nd that it has developed 'QuantumPKI Studio,' which can generate, analyze, and verify existing public key-based certificates, quantum-resistant cryptography (PQC) certificates, and hybrid certificate structures in a one-stop manner.
This platform widely supports RSA and ECC-based X.509 certificates and international and domestic quantum-resistant cryptographic algorithms.
As quantum computing technology advances, concerns are being raised that existing public-key cryptographic systems used for internet security, finance, and public services could be threatened in a quantum computer environment.
The international community, including the U.S. National Institute of Standards and Technology (NIST), is promoting the standardization of quantum-resistant cryptography, and domestically, the development and demonstration of Korean-type quantum-resistant cryptography (KPQC) are also underway.
In a public key infrastructure (PKI) environment based on joint certificates, the transition is not completed merely by replacing cryptographic algorithms; a comprehensive review of the structure and verification framework, including public key information, algorithm identifiers, extension fields, and compatibility with existing systems, is required.>
Quantum PKI Studio is a graphical user interface (GUI)-based verification platform implemented to review this transition process.
After generating a cryptographic key and issuing a certificate, the user can load a certificate they created themselves or an external certificate to check the structure and verification results.
ETRI explained that since the ASN.1 structure, raw data, extended fields, and digital signature verification status within the certificate can be analyzed on a single screen, it enables the visual diagnosis of certificate structures that were previously verified using command-line tools.
This platform can handle NIST standard and algorithms scheduled for standardization, as well as domestic KPQC series algorithms, in a single environment.
In addition, the hybrid certificate structures discussed during the transition period support: Composite, which combines existing cryptography and quantum-resistant cryptography into one certificate; Bind, which links existing certificates and quantum-resistant cryptographic certificates; and Chameleon, which includes reconstruction information in the base certificate.
ETRI stated that it expects this technology to serve as a verification foundation for preparing for the transition to quantum-resistant cryptography across the entire PKI, including joint certificates, Certificate Authorities (CAs), digital signature systems, Hardware Security Modules (HSMs), and certificate verification solutions.
Kim Gun-woo, a principal researcher at ETRI, stated, “The transition to quantum-resistant cryptography is not merely a matter of replacing cryptographic algorithms, but a complex issue involving changes to the entire certificate structure and verification system.” He added, “Quantum PKI Studio will serve as a research foundation capable of pre-examining and demonstrating international and domestic quantum-resistant cryptography and hybrid certificate structures.”
This achievement was developed as part of a project supported by the Ministry of Science and ICT and the Institute of Information and Communications Technology Planning and Evaluation (IITP), with participation from the Korea Internet & Security Agency, Korea Certification, Crypto Lab, Kookmin University, Hansung University, and Hanyang University ERICA Campus..