Post-Quantum Readiness
Review status: This foundation page requires specialist review before public approval. Its claims must remain within the scope stated here.
Identity information can remain sensitive and valuable for many years. Credentials, recovery records, institutional attestations, and encrypted archives created today may still matter when cryptographic capabilities and standards have changed.
UbID therefore treats post-quantum readiness as a controlled migration program rather than a claim that every current credential or integration is already quantum-resistant.
Why identity requires long-term planning
Two time horizons matter:
- Operational lifetime — how long a key, credential, document, recovery relationship, or audit record remains in use.
- Confidentiality lifetime — how long information must remain protected even after it is no longer actively used.
An attacker may capture encrypted information today and attempt to decrypt it later. Long-lived recovery and custody data therefore require particular attention.
A progressive hybrid approach
Current identity ecosystems depend on widely supported classical cryptography. Replacing it abruptly could break interoperability with existing wallets, issuers, verifiers, browsers, and standards.
A hybrid approach allows UbID to:
- preserve current interoperable credential formats;
- add post-quantum protection to selected long-lived exchanges;
- produce separately bound post-quantum evidence where consumers can validate it;
- test new algorithms and providers before making them mandatory;
- migrate trust policy in controlled stages;
- avoid dependence on one cryptographic family.
Format-aware migration
Adding an experimental second signature directly to an established credential format can make the credential incompatible with external software. Post-quantum protection must respect the consuming format and verification ecosystem.
Depending on the use case, an implementation may use:
- hybrid key establishment for protected communication or recovery;
- a separately bound post-quantum proof;
- a multi-signature container in a controlled ecosystem;
- dual artifacts with explicit verification policy;
- future standardized formats when they are broadly supported.
The assurance label must state what is protected and what the verifier is required to validate.
No silent downgrade
A flow that claims hybrid or post-quantum assurance must not silently fall back to classical-only validation when the additional proof is missing or invalid.
Policy should distinguish:
- experimental evidence;
- optional parallel evidence;
- required hybrid verification;
- migration grace periods;
- unsupported or deprecated algorithms.
An explainable failure is safer than an invisible downgrade.
Crypto-agility foundations
Post-quantum readiness depends on broader cryptographic governance:
- a cryptographic inventory;
- named key purposes and owners;
- versioned algorithm policy;
- provider and library abstraction;
- test vectors and interoperability testing;
- rotation and re-issuance capability;
- historical verification rules;
- migration, rollback, and incident plans;
- evidence showing which protection was applied.
Without these controls, adding a new algorithm merely creates another unmanaged dependency.
Priority areas
UbID gives particular attention to information and processes with long-term value, including:
- recovery and custodian exchanges;
- holder vault protection;
- high-value institutional attestations;
- long-retained documents and evidence;
- issuer and verifier trust transitions;
- cryptographic backup and restoration.
Not every low-risk or short-lived interaction requires the same migration schedule.
Accurate status claims
Architecture target, proof of concept, tested staging control, limited production feature, and independently assured production control are different states.
Public documentation should identify the actual state and avoid using "post-quantum" as a broad marketing label for a system in which only one experimental component uses a new algorithm.
Public documentation boundary
The portal does not publish experimental key material, private test results, detailed migration schedules, provider configuration, internal compatibility gaps, or cryptographic acceptance thresholds.
See Cryptographic Protection, UbID KeyVault, and Publication Status.