Review of cryptographic agility technology for post-quantum cryptography migration
Online published: 2026-05-29
Copyright
Cryptographic technology serves as the foundational supporting technology for cyberspace security. The rapid advancement of quantum computing poses a severe security threat to traditional cryptographic systems, making post-quantum cryptography (PQC) migration an effective pathway for safeguarding cyberspace security. As a core enabler of this migration process, conducting research on cryptographic agility technology is of significant practical importance. Against this backdrop, this paper conducts a systematic review of cryptographic agility technology from the perspectives of definitions and connotations, technological breakthroughs, scenario-based applications, and governance policies. It synthesizes the viewpoint that cryptographic agility is not merely algorithm replacement but a security technology at the architectural level; It investigates the security of cryptographic agility, summarizes updatable functional modules based on the universal composability security framework, and refines key agility technologies for cryptographic protocols, software, and hardware; It analyzes its specific applications in domains such as the domain name system, aviation, and industry, and explores relevant strategic frameworks and technology maturity models; It refines the design paradigms for cryptographic agility and provides an outlook on its future research directions to offer theoretical and technological insights for PQC migration.
Liu Yutong , Chen Qi , Ding Yan , Sun Jianwei . Review of cryptographic agility technology for post-quantum cryptography migration[J]. Journal of Cybersecurity, 2026 , 4(2) : 100 -114 . DOI: 10.20172/j.issn.2097-3136.260408
表 1 密码敏捷在协议上的实现Table 1 Implementation of cryptographic agility in protocols |
| 协议名称 | 密码敏捷设计的技术路线 |
| TLS 协议 | 采用ECDHE与抗量子KEM混合架构,客户端通过扩展消息适配能力,服务器动态选择兼容方案,过渡阶段保留传统套件,实现平滑迭代[23] |
| TLS 协议 | 设计安全抽象层集中管理密码功能,解耦协议状态机与密码原语,替换密码原语仅需修改 SAL 层代码[24] |
| TLS 协议 | 基于 XtM、dualPRF 等组件化组合器集成经典与抗量子 KEM,可有效嵌入现有 TLS 架构[25] |
| TLS 协议 | 复用并扩展 TLS 协商机制,基于 liboqs 库提供统一接口,通过底层模块化设计实现上层算法快速替换[26] |
| TLS 协议 | 采用混合模式集成传统与抗量子密码算法,扩展枚举值与 OID 适配证书,借助传输控制协议分段适配超长报文,结合网络条件优化算法选择 [27] |
| TLS 协议 | 依托 liboqs 库与 OQS-OpenSSL 构建适配体系,支持 TLS 1.2/1.3 版本适配,可切换多种算法模式、动态调整安全等级参数,通过扩容系统适配大尺寸算法[28] |
| TLS 协议 | 提出 TLS 量子脆弱性自动化检测框架,通过流量解析提取密码信息,建立三级安全评估标准[29] |
| IKEv2 协议 | 新增独立抗量子密钥组件与标准化通知消息,支持多 PPK 配置与工作模式切换,采用分阶段升级策略,实现增量部署与业务平滑过渡[30] |
| IKEv2 协议 | 采用安全强度规范作为算法选型依据,通过转换标识扩展密钥交换方案,创新槽位机制支持多方案混合协商,结合分片技术与API适配长期演进[31] |
| Signal 协议 | 拆解双棘轮机制为 CKA、FS-AEAD、PRF-PRNG 组件,通过标准化接口解耦,各组件可独立适配传统或抗量子密码算法,替换时避免大幅修改核心逻辑[40] |
| Signal 协议 | 拆分密码模块为经典与抗量子实例,统一符号体系与接口,密钥发布阶段生成混合密钥束,设计 X3DH 协商与双棘轮机制[41] |
| ACNP 协议 | 可跨 TCP/IP 协议栈任意层级部署,通过三步协商(初始密钥交换→算法列表交互→确认)完成流程,采用标准化消息格式,超时触发自动重协商机制[42] |
| ACAP 协议 | 基于 SIGMA 协议架构设计,通过 2 轮交互,完成密钥交换与算法协商,按优先级序列选择双方共同支持的密码算法[43] |
| 认证协议(RADIUS) | 明确安全服务、向后兼容、互操作性等实现规范,指定强制启用的密码算法抵御版本降级攻击,建议部署自动化密钥管理机制[44] |
| 认证协议(PKINIT) | 新增错误响应字段返回支持算法列表,构建 KDF 标准化双向协商流程,通过 OID 标识传递新增算法[45] |
| 认证协议(RPKI) | 采用 “父 CA 先迁移、子 CA 后跟进” 的自上而下流程,定义五大里程碑形成迁移闭环,维护新旧算法映射关系,分阶段调整验证策略[46] |
| 认证协议 | 扩展属性证书功能,通过 subjectAltPublicKeyInfo 扩展项承载多类抗量子公钥,新增3种验证策略扩展,实现动态调整[47] |
| 认证协议 | 划分 CA 证书三态(活跃 / 待用 / 过期),通过链接证书传递新算法参数,支持算法参数灵活配置,实现证书策略差异化部署[48] |
表 2 密码敏捷协议方案比较分析Table 2 Comparative analysis of cryptographic protocol agility schemes |
| 方案 | 适用场景 | 兼容性 | 部署成本 | 时间复杂度 | 空间复杂度 | 性能开销 | 迁移难度 |
| 文献[24] | 低功耗物联网设备 | 高 | 中等 | 中等 | 低 | ||
| 文献[25] | 混合密钥交换 | 高 | 高 | 小 | 中等 | ||
| 文献[26] | 云服务与远程管理 | 高 | 低 | 中等 | 低 | ||
| 文献[27] | 高性能网络协议库 | 高 | 低 | 中等 | 中等 | ||
| 文献[29] | 密码敏捷性实时监测 | 高 | 低 | 小 | 低 | ||
| 文献[30] | 静态VPN链路 | 高 | 中等 | 小 | 低 | ||
| 文献[31] | 混合密钥交换 | 中等 | 高 | 中等 | 中等 | ||
| 文献[40] | 异步通信 | 高 | 低 | 小 | 低 | ||
| 文献[41] | 加密邮件 | 高 | 中等 | 大 | 中等 | ||
| 文献[43] | 计算资源受限设备 | 高 | 低 | 小 | 低 | ||
| 文献[44] | RADIUS | 高 | 中等 | 小 | 高 | ||
| 文献[45] | PKINIT | 高 | 中等 | 小 | 低 | ||
| 文献[46] | RPKI | 高 | 高 | 中等 | 高 | ||
| 文献[47] | 工业控制系统 | 高 | 低 | 中等 | 低 | ||
| 文献[48] | 智能交通系统 | 中等 | 高 | 中等 | 中等 |
表 3 硬件与软件的密码敏捷实现Table 3 Hardware and software implementations of cryptographic agility |
| 设计思路 | 密码敏捷设计的技术路线 |
| 专用密码处理器统一化设计 | 设计统一NTT多项式乘法器与Keccak适配模块,同时支持Dilithium与Saber算法[49] |
| 三层抽象体系 | 采用三层抽象体系(中间表示、标准化接口、参数化硬件模型),通过调整映射或参数完成算法更换[51] |
| 异构算法运算同质化 | 通过超级蝶形单元硬件设计,实现格基与编码基密码系统硬件共享[50] |
| 传统硬件复用 | SIKE与ECDH共用核心硬件部件,匹配设计专属参数实现同一硬件上两种算法快速切换[52] |
| 算法运算转化 | 通过“克罗内克替换+环拆分”技术转化格基密码运算,复用AES与SHA-256协处理器[53-54] |
| 配置映射解耦 | 规避硬编码设计模式,依托内置的抽象类与配置映射机制,使应用程序代码改动较少的前提下,实现密码算法及其实例的灵活切换[5] |
| 插件架构设计 | 采用插件架构拆分密码功能为独立模块,配合接口设计,实现算法平滑切换[55] |
| 浅层提供程序 | 通过“浅层提供程序”方案,以可加载模块形式联动外部密码库,屏蔽接口差异。依赖上层API的应用,通过调整配置完成算法更换[56] |
| 模块差异化升级 | 针对不同模块设计差异化升级策略。消息与团队模块分别按用户配置、管理员设置调整算法,实现密码组件平滑替换[57] |
| 接口协议融合 | 融合TLS与POSIX套接字API,应用可平滑替换底层TLS版本、密码库或抗量子变体[58] |
| 接口统一抽象 | 构建密码接口统一抽象层,应用通过标准化接口调用密码功能,降低对特定密码库API的依赖[59] |
表 4 密码敏捷软硬件方案比较分析Table 4 Comparative analysis of hardware and software schemes for cryptographic agility |
| 1 |
冯艺萌, 刘昂. 迈向量子安全: 抗量子密码迁移研究与思考[J]. 计算机技术与发展, 2024, 34 (5): 103- 108.
Feng Y M, Liu A. Toward quantum security: research and reflections on post-quantum cryptographic migration[J]. Computer Technology and Development, 2024, 34 (5): 103- 108.
|
| 2 |
王良成, 石元兵, 张舒黎, 等. 抗量子密码迁移研究[J]. 通信技术, 2023, 56 (8): 999- 1006.
Wang L C, Shi Y B, Zhang S L, et al. Research on post-quantum cipher migration[J]. Communications Technology, 2023, 56 (8): 999- 1006.
|
| 3 |
Alnahawi N, Schmitt N, Wiesmaier A, et al. On the state of crypto agility[J]. Cyber-Sicherheitist Chefinnen und Chefsache: Tagungsband zum 18. Deutschen IT-Sicherheitskongress. Ingelheim: SecuMedia, 2022, 18, 103- 126.
|
| 4 |
Lamacchia B A, Manferdelli J L. New vistas in elliptic curve cryptography[J]. Information Security Technical Report, 2006, 11 (4): 186- 192.
|
| 5 |
Sullivan B. Cryptographic agility[J]. MSDN Magazine, 2009, 24 (8): 75- 80.
|
| 6 |
Acar T, Belenkiy M, Bellare M, et al. Cryptographic agility and its relation to circular encryption[M]//Advances in Cryptology – EUROCRYPT 2010. Berlin, Heidelberg, Springer 2010: 403-422.
|
| 7 |
Badertscher C, Ciampi M, Kiayias A. Agile cryptography: a universally composable approach[M]//Theory of Cryptography. ChamSpringer Nature Switzerland 2023: 480-509.
|
| 8 |
Barker E, Chen L, Moody D, et al. Considerations for achieving crypto agility: strategies and practices[R/OL]. National Institute of Standards and Technology. (2025-03-05)[2026-01-12]. https://doi.org/10.6028/nist.cswp.39.ipd.
|
| 9 |
Barker E, Chen L, Moody D, et al. Considerations for achieving crypto agility: strategies and practices[R/OL]. National Institute of Standards and Technology. (2025-07-17)[2026-01-12]. https://doi.org/10.6028/nist.cswp.39.2pd.
|
| 10 |
Housley R. Guidelines for cryptographic algorithm agility and selecting mandatory-to-implement algorithms[J]. RFC7696, 2015, 1- 19.
|
| 11 |
Mehrez H A, Elomri O. The crypto-agility properties[C]//The 12th International Conference on Society, Cybernetics and Informatics, 2018: 99-103.
|
| 12 |
Heid K, Heider J, Ritscher M, et al. Tracing cryptographic agility in Android and IOS Apps[C]//Proceedings of the 9th International Conference on Information Systems Security and Privacy. SCITEPRESS - Science and Technology Publications, 2023: 38-45.
|
| 13 |
Computing Community Consortium. Identifying research challenges in post quantum cryptography migration and cryptographic agility[R]. Washington, DC: Computing Community Consortium, 2019.
|
| 14 |
Näther C, Herzinger D, Steghöfer J P, et al. Toward a common understanding of cryptographic agility: a systematic review[PP/OL]. V2. arXiv (2025-02-08) [2025-11-10]. https://doi.org/10.48550/arXiv.2411.08781.
|
| 15 |
Wiesmaier A, Alnahawi N, Grasmeyer T, et al. On PQC migration and crypto-agility[PP/OL]. V1. arXiv(2021-06-17) [2025-11-10]. https://doi.org/10.48550/arXiv.2106.09599.
|
| 16 |
Resilience Forum on Cyber. Cryptographic agility and interoperability: proceedings of a workshop[M]. Washington, D. C.: National Academies Press, 2017.
|
| 17 |
Sikeridis D, Ott D, Huntley S, et al. ELCA: introducing enterprise-level cryptographic agility for a post-quantum era[EB/OL]. [2026-05-08]. https://eprint.iacr.org/2023/1539.
|
| 18 |
Sanon S P, Schotten H D. Quantum-ready mobile communications: cryptographic agility for mobile networks in the quantum era[C]//Proceedings of the 2025 IEEE 26th International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM). Piscataway: IEEE Press, 2025: 287-292.
|
| 19 |
Dowling B, Hansen T B, Paterson K G. Many a mickle makes a muckle: a framework for provably quantum-secure hybrid key exchange[M]//Post-Quantum Cryptography. ChamSpringer International Publishing, 2020: 483-502.
|
| 20 |
Valbusa F, Krenn S, Lorünser T, et al. Seamless post-quantum transition: agile and efficient encryption for data-at-rest[C]//Proceedings of the 22nd International Conference on Security and Cryptography. SCITEPRESS - Science and Technology Publications, 2025: 759-764.
|
| 21 |
Canetti R. Universally composable security: a new paradigm for cryptographic protocols[C]//Proceedings 42nd IEEE Symposium on Foundations of Computer Science. Piscataway: IEEE Press, 2001: 136-145.
|
| 22 |
徐开勇, 袁庆军, 谭磊, 等. 密码服务API通用可组合框架[J]. 密码学报, 2017, 4 (4): 405- 412.
Xu K Y, Yuan Q J, Tan L, et al. The universally composable framework of cryptographic service API[J]. Journal of Cryptologic Reseatch, 2017, 4 (4): 405- 412.
|
| 23 |
Campagna M, Crockett E. Hybrid post-quantum key encapsulation methods (PQ KEM) for transport layer security 1.2 (TLS)[R/OL]. Internet Engineering Task Force. (2019-05-07)[2026-01-12]. https://datatracker.ietf.org/doc/html/draft-campagna-tls-bike-sike-hybrid-01.
|
| 24 |
Scott M. On TLS for the Internet of things, in a post quantum world[EB/OL]. (2023)[2025-10-08]. https://eprint.iacr.org/2023/095.
|
| 25 |
Bindel N, Brendel J, Fischlin M, et al. Hybrid key encapsulation mechanisms and authenticated key exchange[M]//Post-Quantum Cryptography. ChamSpringer International Publishing, 2019: 206-226.
|
| 26 |
Crockett E, Paquin C, Stebila D. Prototyping post-quantum and hybrid key exchange and authentication in TLS and SSH[EB/OL]. (2019) [2025-10-08]. https://eprint.iacr.org/2019/858.
|
| 27 |
张枫, 潘天雨, 赵运磊. TLS1.3抗量子安全迁移方案、实现和性能评测[J]. 密码学报, 2022, 9 (1): 143- 163.
Zhang F, Pan T Y, Zhao Y L. Design implementation and performance evaluation of migrating post-quantum safe schemes to TLS1.3[J]. Journal of Cryptologic Research, 2022, 9 (1): 143- 163.
|
| 28 |
Van H M, Van A N, Attema T, et al. Towards quantum-safe VPNs and Internet[EB/OL]. (2019)[2025-10-08]. https://eprint.iacr.org/2019/1277.
|
| 29 |
Cho S, Hyoung Y, Kim H, et al. Toward crypto agility: automated analysis of quantum-vulnerable TLS via packet inspection[M]//Security, Privacy, and Applied Cryptography Engineering. ChamSpringer Nature Switzerland, 2026: 114-133.
|
| 30 |
Fluhrer S, Kampanakis P, Mcgrew D, et al. Mixing preshared keys in the internet key exchange protocol version 2 (IKEv2) for post-quantum security[R]. RFC, 2020, 8784: 1-16.
|
| 31 |
Heider T. Towards a verifiably secure quantum resistant key exchange in IKEv2[D]. München: Ludwig Maximilian University of Munich, 2019.
|
| 32 |
Cohn-Gordon K, Cremers C, Dowling B, et al. A formal security analysis of the signal messaging protocol[J]. Journal of Cryptology, 2020, 33 (4): 1914- 1983.
|
| 33 |
Stebila D. Security analysis of the iMessage PQ3 protocol[EB/OL]. (2024) [2025-10-08]. https://eprint.iacr.org/2024/357.
|
| 34 |
Linker F, Sasse R, Basin D. A Formal Analysis of Apple's iMessage PQ3 Protocol[C]//34th USENIX Security Symposium (USENIX Security 25). Berkeley, CA: USENIX Association, 2025: 5015-5034.
|
| 35 |
Fiedler R, Günther F. Security analysis of signal’s $$\textsf{PQXDH handshake[M]//Public-Key Cryptography – PKC 2025. ChamSpringer Nature Switzerland, 2025: 137-169.
|
| 36 |
Brendel J, Fischlin M, Günther F, et al. Towards post-quantum security for signal’s X3DH handshake[M]//Selected Areas in Cryptography. ChamSpringer International Publishing, 2021: 404-430.
|
| 37 |
Meier S, Schmidt B, Cremers C, et al. The TAMARIN prover for the symbolic analysis of security protocols[M]//Computer Aided Verification. Berlin, HeidelbergSpringer, 2013: 696-701.
|
| 38 |
Schmidt B, Meier S, Cremers C, et al. Automated analysis of Diffie-Hellman protocols and advanced security properties[C]//Proceedings of the 2012 IEEE 25th Computer Security Foundations Symposium. Piscataway: IEEE Press, 2012: 78-94.
|
| 39 |
Kret E, Schmidt R. The PQXDH key agreement protocol[EB/OL]. (2024-01-23)[2026-01-12]. https://signal. org/docs/specifications/pqxdh.
|
| 40 |
Alwen J, Coretti S, Dodis Y. The double ratchet: security notions, proofs, and modularization for the signal protocol[M]//Advances in Cryptology – EUROCRYPT, 2019. ChamSpringer International Publishing, 2019: 129-158.
|
| 41 |
Stadler S, Sakaguti V, Kaur H, et al. Hybrid signal protocol for post-quantum email encryption[J]. Cryptology ePrint Archive, 2021.
|
| 42 |
Vasic V, Mikuc M. Security agility solution independent of the underlaying protocol architecture[C]//Proceedings of the First International Conference on Agreement Technologies (AT 2012). Dubrovnik, Croatia, 2012: 128-137.
|
| 43 |
Vasić V, Mikuc M, Vukovi M. Lightweight and adaptable solution for security agility[J]. KSII Transactions on Internet and Information Systems (TIIS), 2016, 10 (3): 1212- 1228.
|
| 44 |
Nelson D B. Crypto-agility requirements for remote authentication dial-In user service (RADIUS)[J]. RFC6421, 2011, 1- 12.
|
| 45 |
Hörnquist Å L, Zhu L, Cullen M, et al. Public key cryptography for initial authentication in kerberos (PKINIT) algorithm agility[J]. RFC8636, 2019, 1- 21.
|
| 46 |
Gagliano R, Kent S T, Turner S. Algorithm agility procedure for the resource public key infrastructure (RPKI)[J]. RFC6916, 2013, 1- 20.
|
| 47 |
Fries S, Falk R. Supporting cryptographic algorithm agility with attribute certificates[J]. International Journal on Advances in Security, 2024, 17(1&2): 92-98.
|
| 48 |
Ullmann M, Wieschebrink C, Kügler D. Public key infrastructure and crypto agility concept for intelligent transportation systems[C]//Proceedings of the Fourth International Conference on Advances in Vehicular Systems, Technologies and Applications (VEHICULAR 2015). Wilmington, DE: IARIA, 2015: 14-19.
|
| 49 |
Aikata A, Mert A C, Jacquemin D, et al. A unified cryptoprocessor for lattice-based signature and key-exchange[J]. IEEE Transactions on Computers, 2023, 72 (6): 1568- 1580.
|
| 50 |
Ras A, Loiseau A, Carmona M, et al. PHOENIX: crypto-agile hardware sharing for ML-KEM and HQC[EB/OL]. (2025) [2025-10-08]. https://eprint.iacr.org/2025/781.
|
| 51 |
Pan T W, Dai T A, Yang J L, et al. Finesse: an agile design framework for pairing-based cryptography via software/hardware co-design[C]//Proceedings of the 52nd Annual International Symposium on Computer Architecture. New York: ACM, 2025: 65-77.
|
| 52 |
Azarderakhsh R, Elkhatib R, Koziel B, et al. Hardware deployment of hybrid PQC: SIKE+ECDH[C]//Security and Privacy in Communication Networks. Cham: Springer, 2021: 475-491.
|
| 53 |
Albrecht M R, Hanser C, Hoeller A, et al. Implementing RLWE-based schemes using an RSA co-processor[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018: 169-208.
|
| 54 |
Bos J W, Renes J, Van V C. Post-quantum cryptography with contemporary co-processors: beyond kronecker, schönhage-strassen & nussbaumer[C]//Proceedings of the 31st USENIX Security Symposium (USENIX Security 22). Berkeley, CA: USENIX Association, 2022: 3683-3697.
|
| 55 |
Lee K, Lee Y, Park J, et al. Security issues on the CNG cryptography library (cryptography API: next generation)[C]//Proceedings of the 2013 Seventh International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing. Piscataway: IEEE Press, 2013: 709-713.
|
| 56 |
Mehmood A, Tuveri N. Integrating PQC in OpenSSL via shallow providers for cryptographic agility[M]//Secure IT Systems. ChamSpringer Nature Switzerland, 2026: 23-42.
|
| 57 |
Von Arx T. Towards more cryptographic agility[EB/OL]. (2023-03-16)[2026-01-12]. https://blueprints.cryptpad.org/_assets/review/agility/main.pdf.
|
| 58 |
O'neill M, Heidbrink S, Whitehead J, et al. The secure socket API: TLS as an operating system service[C]//27th USENIX Security Symposium (USENIX Security 18). Berkeley, CA: USENIX Association, 2018: 799-816.
|
| 59 |
Cho J, Lee C, Kim E, et al. Software-defined cryptography: a design feature of cryptographic agility[PP/OL]. V2. arXiv (2024-09-01)[2025-11-10]. https://doi.org/10.48550/arXiv.2404.01808.
|
| 60 |
Heftrig E, Shulman H, Waidner M. Downgrading DNSSEC: how to exploit crypto agility for hijacking signed zones[C]//32nd USENIX Security Symposium (USENIX Security 23). Berkeley, CA: USENIX Association, 2023: 7429-7444.
|
| 61 |
Heftrig E, Shulman H, Waidner M. Poster: the unintended consequences of algorithm agility in DNSSEC[C]//Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2022: 3363-3365.
|
| 62 |
Müller M, Dejong J, Van H M, et al. Retrofitting post-quantum cryptography in Internet protocols: a case study of DNSSEC[J]. ACM SIGCOMM Computer Communication Review, 2020, 50 (4): 49- 57.
|
| 63 |
Varner K, Zaeske W, Friedrich S, et al. Agile, post-quantum secure cryptography in avionics[J]. CEAS Aeronautical Journal, 2026, 17 (1): 133- 163.
|
| 64 |
Frauenschläger T, Mottok J. Problems and new approaches for crypto-agility in operational technology[C]// Proceedings of the 12th European Congress Embedded Real Time Systems (ERTS 2024). Toulouse: SEE & 3AF, 2024.
|
| 65 |
Simoes M, Elmusrati M, Vartiainen T, et al. Enhancing data security against cyberattacks in artificial intelligence based smartgrid systems with crypto agility[PP/OL]. V1. arXiv (2023-05-19) [2025-11-10]. https://doi.org/10.48550/arXiv.2305.11652.
|
| 66 |
Hohm J, Heinemann A, Wiesmaier A. Towards a maturity model for crypto-agility assessment[C]//Foundations and Practice of Security. Cham: Springer, 2023: 104-119.
|
| 67 |
Marchesi L, Marchesi M, Tonelli R. Reviewing crypto-agility and quantum resistance in the light of agile practices[M]//Agile Processes in Software Engineering and Extreme Programming – Workshops. ChamSpringer Nature Switzerland, 2023: 213-221.
|
/
| 〈 |
|
〉 |