General methods for migration of cryptographic algorithms (ITU-T X.506)

Abstract

Recommendation ITU-T X.506 | ISO/IEC 9594-13 establishes the background for the necessity for establishing crypto agility in the light of coming quantum computers but also when currently used cryptographic algorithms are considered unsafe. It does not alone describe WHY migration is required but also specifies in detail HOW migration is performed. It defines principles for how public-key certificates, attribute certificates and communication protocols can be prepared for migration and it provides tools for how migration can be established. The considerations on migration of public-key certificates are consistent with the approach specified in Rec. ITU-T X.509 | ISO/IEC 9594-8. The approach taken for migration of communication protocols is consistent with the one taken for public-key certificates to allow for a consistent migration strategy. Recommendation ITU-T X.506 | ISO/IEC 9594-13 is technically aligned with IEC TR 62351-90-4 for the electrical power industry.

ICT rolling plan topic
Cybersecurity/Network and Information security
Quantum Technologies, Cybersecurity/Network and Information security
SDO
ITU-T
Involved fellows
Standard/Working group
Standard

Involved fellows

Erik Andersen	 profile image
Erik Andersen
Denmark

Role: moderator