Stickybit.← Post-quantumPortuguêsService · device identity · 2026
Post-quantum PKI · the identity of each device

Device identity still has no new lock.

NIST standardized quantum-resistant signatures in 2024. In 2026, half the web already exchanges keys with the new protection, yet no identity certificate uses the new signature. On the public web that depends on a whole ecosystem. On your satellite, substation or car, which uses its own certificates and stays 15 to 20 years in the field, it can be solved now.

Specimen · a certificate chain, link by link
↓ stamps
↓ stamps
↓ stamps

—chain size (keys + signatures)
—radio packets of ~200 B
—resists a quantum computer?
—old verifier accepts?

Public-key and signature sizes are those of the standards (FIPS 204 and FIPS 205); a real certificate has more fields and is larger. The ~200 B packet is the UHF radio link from our satellite study. The rest is illustrative.

In everyday life

An ID card with a notary’s stamp.

A digital certificate is the ID card of a server or a device. What guarantees it is genuine is an authority that stamps it with its own signature, like a notary. And the notary’s stamp is, in turn, recognized by an authority above it: that is the chain of trust.

Today’s signatures (RSA, ECDSA) are stamps a quantum computer could forge. Whoever forges the notary’s stamp makes fake IDs that pass any check. That is why, during migration, the chain is only as strong as its weakest link.

Rootstamps the next Intermediatestamps the device Deviceshows its ID stamp = digital signature
Each link stamps the next. If one stamp can be forged, everything below it stops proving identity.
The 2026 picture

Key exchange is moving. Signatures are at zero.

A 2026 study measured 32,011 web domains. 49.3% already do the key exchange with the new protection (ML-KEM together with X25519). The share of certificates with the new signature: 0%. Certificates remain 54% RSA and 42% ECDSA, two years after the standard.

In practice: what is being protected today is the secrecy of the conversation, not proof of who is on the other end. And the reason isn’t lack of interest. There are no authorities yet issuing new certificates recognized by browsers, expected for late 2026 or 2027.

Two caveats on the number: the 49% is inflated by sites behind delivery networks that turn the new mode on by default; and the study measures the public web, not the devices this page is about.

New key exchange
49.3%
Certificate with new signature
0.0%
Adoption on the public web in 2026 (arXiv 2606.16473, 32,011 domains). Sites behind CDNs inflate the first bar.
Why devices are different

The device outlives the deadline.

A web server renews its certificate every few months. A substation remote unit stays 15 to 20 years in the field; a car’s control unit, more than 15; a satellite, years in orbit with nobody to swap parts. The cryptography must last the device’s whole life, and whoever records the traffic today may try to decrypt it tomorrow.

The deadlines already have dates: in the US, national security systems require resistant algorithms in new purchases from 2027 (CNSA 2.0); the US federal government targets 2030 for key exchange and 2031 for authentication; the European Union, critical infrastructure by 2030. A device installed in 2026 will still be running through all of them.

The good news: devices use their own certificates (private PKI), under your control. They don’t need to wait for browsers. New identity can be issued now.

20272027 CNSA 2.0 (US): new purchases20302030 US: key exchange · EU: critical infrastructure20312031 US: authentication20352035 EU: full transitionSubstation remote unitCar control unitSatellite (illustrative)20262031203620412046
Typical life of a device installed today against the deadlines already published. The satellite bar is illustrative.
How we do it

Issue, verify, update.

Issue. Your own authority, under your control, issues identity with the new signature (ML-DSA, SLH-DSA or XMSS) for each device. That part is off-the-shelf software (EJBCA, step-ca); we deliver the integration, we don’t reinvent cryptography.

Verify. Issuing is useless if the device doesn’t check properly. The differentiator is the root of trust on the device: secure boot and identity checking done in a hardware component. It builds on our post-quantum coprocessor design for satellites (documented, not yet a flight product).

Update. A fixed lock becomes a liability at the first new standard. The device in the field must be able to switch algorithms by remote update, without replacing hardware: that is crypto-agility. During the transition, hybrid mode runs the old and new locks at the same time.

Issue your authority new signature Verify on the device root of trust Update remote switches algorithmwhen the standard changes, start over
The authority issues; the device checks with its own root of trust; the remote update switches the algorithm when the standard changes.
Size matters

New signatures are big.

Today’s ECDSA signature is 64 bytes. ML-DSA-65 is 3,309; the most compact SLH-DSA, 7,856. On a server it doesn’t matter. On a satellite radio link with packets of about 200 bytes, one new signature takes 13 to 40 packets.

In practice: on a satellite you don’t sign every message. The new lock sits at the edge of the session (one key exchange per pass, signatures only for rare commands) and telemetry runs on symmetric encryption, which already resists. It is the same design as TUBESEC.

SignaturePublic keySignatureQuantum-resistant
ECDSA P-25664 B64 Bno
Ed2551932 B64 Bno
ML-DSA-441,312 B2,420 Byes
ML-DSA-651,952 B3,309 Byes
SLH-DSA-SHA2-128s32 B7,856 Byes
Where to use it

Long-lived device, own PKI.

Makes sense

  • Satellite and satellite IoT: command and telemetry of devices nobody can reach physically.
  • Energy and industrial automation: meters, remote units and controllers with 15 to 20 years of life (NERC CIP, IEC 62443).
  • Automotive: control units and vehicle-to-vehicle communication (UNECE R155/R156).

Not yet

  • Public website: depends on browser-recognized authorities, expected for late 2026 or 2027.
  • Short-lived device: if it will be replaced before the deadline, urgency is lower.
  • No control of the root: if the manufacturer won’t let you issue or update, the first step is contractual.
Three words from this page
Certificate

The digital ID card of a server or device, stamped by an authority.

Chain of trust

The sequence of stamps, from the root down to the device. It is worth what its weakest link is worth.

Crypto-agility

Changing the lock without changing the door: switching the algorithm by update, without replacing hardware.

Limits

Where this could be wrong.

The study measures the web, not your device

The 0% is for the public web. We don’t know adoption in private device PKIs, which is this page’s market.

Sizes are the standard’s

A real certificate carries names, dates and extensions, and is larger. The specimen’s packet count is a floor.

Deadlines are third parties’ and they move

The US and EU dates are those published through mid-2026 and have been revised, usually earlier.

The root of trust is still a design

Hardware verification builds on a satellite coprocessor design, not a certified product. Issuing and updating are off-the-shelf software.

How do your devices prove who they are, and how will they in 2035?

An assessment maps how your fleet issues and checks identity today, where "record now, decrypt later" exposes it, and what migration looks like: your own authority with the new signature, on-device checking and crypto-agility.

See also

← Post-quantum · stickybit.com.br

Sources