{"id":2853,"date":"2026-05-19T23:51:32","date_gmt":"2026-05-20T06:51:32","guid":{"rendered":"https:\/\/self-issued.info\/?p=2853"},"modified":"2026-05-20T00:02:39","modified_gmt":"2026-05-20T07:02:39","slug":"post-quantum-signatures-for-jose-and-cose","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2853","title":{"rendered":"Post-Quantum Signatures for JOSE and COSE"},"content":{"rendered":"<p>Congratulations to <a href=\"https:\/\/www.linkedin.com\/in\/mprorock\/\">Mike Prorock<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/or13b\/\">Orie Steele<\/a> on the publication of &#8220;<a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc9964.html\">ML-DSA for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE)<\/a>&#8221; as <a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc9964.html\">RFC 9964<\/a>! This is a major step forward towards enabling widely-available post-quantum signatures for the Internet and devices.<\/p>\n<p>The abstract from the RFC is:<\/p>\n<blockquote><p>\nThis document specifies JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE) serializations for the Module-Lattice-Based Digital Signature Standard (ML-DSA), a Post-Quantum Cryptography (PQC) digital signature scheme defined in US NIST FIPS 204.\n<\/p><\/blockquote>\n<p>As <a href=\"https:\/\/self-issued.info\/?p=2834\">I discussed<\/a> at <a href=\"https:\/\/st.fbk.eu\/events\/TDI2026\/\">TDI 2026<\/a> and will <a href=\"https:\/\/www.kuppingercole.com\/sessions\/6061\/2\">discuss tomorrow<\/a> at <a href=\"https:\/\/www.kuppingercole.com\/events\/eic2026\/\">EIC 2026<\/a>, transitioning to post-quantum algorithms is a multi-step process:<\/p>\n<ol>\n<li>Developing PQ algorithms<\/li>\n<li>Creating standards for using PQ algorithms<\/li>\n<li>Updating software to use PQ standards<\/li>\n<li>Deploying the updated software in your environment<\/li>\n<\/ol>\n<p>Mike and Orie successfully completed step 2 for JOSE and COSE signatures today!<\/p>\n<p>The JOSE and COSE algorithm identifiers for ML-DSA were actually <a href=\"https:\/\/www.iana.org\/assignments\/cose\/cose.xhtml#algorithms\">registered with IANA<\/a> in July 2025, once it was clear that the document was stable.  Some deployments already exist.  For instance, Yubico has created prototype Yubikeys (hardware passkeys) supporting ML-DSA signatures.  The <a href=\"https:\/\/self-issued.info\/?p=2829\">algorithms are now recommended<\/a> in the FIDO2 <a href=\"https:\/\/fidoalliance.org\/specs\/fidoserver\/fido-server-v2.3-rd-20260226.html\">CTAP2.3 Server Requirements<\/a>.<\/p>\n<p>I played a few supporting roles progressing this spec.  I co-chaired the <a href=\"https:\/\/datatracker.ietf.org\/wg\/cose\/about\/\">COSE Working Group<\/a> with <a href=\"https:\/\/www.linkedin.com\/in\/ivaylo-petrov-a0b17241\/\">Ivaylo Petrov<\/a> where the work occurred.  Ivo and I made a consensus call in May 2025 to standardize only one private key representation &#8211; the seed.  (As I often advocate, \u201c<a href=\"https:\/\/self-issued.info\/?p=2535\">Standards are about making choices<\/a>\u201d.)  And I requested early allocation of the algorithm identifiers with IANA in July 2025.<\/p>\n<p>Orie said to me while the spec was in AUTH48 with the RFC Editor: &#8220;This may be one of the most consequential RFCs I ever create.&#8221;  I completely agree!  And special congratulations, <a href=\"https:\/\/www.linkedin.com\/in\/mprorock\/\">Mike Prorock<\/a>, on your first RFC!<\/p>\n<hr\/>\n<p>Here&#8217;s a slide from my <a href=\"https:\/\/self-issued.info\/?p=2834\">TDI 2026<\/a> presentation on what&#8217;s hard about deploying post-quantum cryptography.  I&#8217;ll make the same case <a href=\"https:\/\/www.kuppingercole.com\/sessions\/6061\/2\">tomorrow at EIC<\/a>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/self-issued.info\/images\/Understaning_What's_Hard.jpg\" alt=\"What's Hard About Post-Quantum Cryptography\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Congratulations to Mike Prorock and Orie Steele on the publication of &#8220;ML-DSA for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE)&#8221; as RFC 9964! This is a major step forward towards enabling widely-available post-quantum signatures for the Internet and devices. The abstract from the RFC is: This document specifies JSON [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29,28,22,34,32,27,25],"tags":[],"class_list":["post-2853","post","type-post","status-publish","format-standard","hentry","category-cbor","category-cryptography","category-events","category-fido","category-ietf","category-json","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2853"}],"version-history":[{"count":5,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2853\/revisions"}],"predecessor-version":[{"id":2858,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2853\/revisions\/2858"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}