Call for Papers: IAB Workshop on Accelerating the Deployment of Post-Quantum Authentication (pqws)
21 Aug 2026, 12:51 p.m.The IAB is hosting a workshop for implementers, operators and protocol designers to help facilitate the acceleration of the deployment of post-quantum signatures and authentication. The workshop will (tentatively) be held in Prague, Czechia on October 11-12 to co-locate with the 2026 OpenSSL conference. The goal of the workshop is to document deployment experience, challenges, and the open questions that remain.
The problem
Post-quantum key establishment is now widely deployed across the Internet. Post-quantum authentication is the harder half, and it lags. The signatures and public keys are large, several kilobytes for ML-DSA [FIPS204] and SLH-DSA [FIPS205] signatures larger still, whereas the elliptic-curve mechanisms in use today take a few dozen bytes. Authentication uses them in many places at once, and there is no single switch to throw, because the work is spread across certificates, the public-key infrastructure, the hardware that holds keys, identity tokens, and firmware and software signing, some of it validated offline or years later.
The first algorithms and specifications are arriving, but adoption is barely underway: a 2025 survey of more than a thousand security leaders found only 5% had deployed any quantum-safe encryption [PQREADY], and authentication lags even that. The people who will have to close the gap, certificate authorities, vendors of hardware security modules (HSMs), trusted platform modules (TPMs), secure elements and smartcards, identity providers, firmware and software signing teams, and operators of regulated, constrained, or long-lived systems, are mostly not the people who participate in standardization. Without a shared picture of what impedes deployment and where the open problems lie, post-quantum authentication will fragment. This workshop brings deployment experience together with the people working on the approaches and the relevant standards, to produce a clear, sourced snapshot of what is blocking deployment and where the open problems are.
In and out of scope
In scope is the deployment of post-quantum authentication: signatures, certificates, tokens, the hardware that holds keys, and the practice around them. The proposed approaches, including hybrid and composite signatures, Merkle Tree Certificates, and KEM-based authentication, are examined as far as their deployment implications are concerned. The workshop is not intended to compare, recommend, or converge on any particular approach, nor to select or standardize algorithms. Post-quantum key establishment is not itself in scope; it appears only as a source of lessons that carry over to authentication.
What to submit
We are looking for short position papers (1-2 pages PDF) on real experience with post-quantum authentication. The most common kind describes a specific deployment problem: what is being deployed or planned, which element is blocked, what can be worked around and at what cost, and what cannot with current specifications, tools, hardware, or practice. The paper does not need to be reporting a blocker. We also want researchers with relevant results, measurements of where deployment stands today, regulatory and policy constraints, and honest accounts of migrations that were attempted and ran into trouble. Give the figures that support your point, such as sizes, timings, throughput, memory, or validation timelines, and say where you think follow-up should occur. Lessons from post-quantum key-establishment deployment are welcome where they carry over to authentication, though key establishment is not itself a topic for this workshop.
Examples of topics we want to hear about, not an exhaustive list:
- Certificates, PKI, DNS: chain and handshake size, path validation across mixed chains, transparency, and revocation growth.
- Keys and hardware: HSM, FIPS 140-3, and PKCS#11 readiness, and the management of stateful hash-based keys, IoT/constrained devices.
- Identity and tokens: post-quantum signatures in JOSE and COSE tokens and the systems built on them, such as OAuth, verifiable credentials, and WebAuthn.
- Software and firmware signing: package, container, and firmware size limits, offline verification, and long-lived or archival validation.
- The approaches in practice: where hybrid and composite signatures [COMPOSITE], Merkle Tree Certificates [MTC], and KEM-based authentication [AUTHKEM] fit and where they break, migration strategies.
Who should participate
The people most needed are those who will deploy Post-Quantum Authentication and are not usually at the IETF: certificate authorities and trust-store operators, hardware and HSM vendors, identity providers, firmware and software signing teams, regulated-sector operators, and operators of constrained or long-lived systems.
What the workshop produces
A report published on the IAB stream summarizing the submissions and the discussion. It is intended to document deployment experience, challenges, and open questions, not to recommend or converge on any particular approach, or to direct the work of IETF working groups or the IRTF. The workshop organizers may also propose a subsequent venue for follow-ups and next steps.
The workshop will be by invitation only. This is an in-person meeting. Remote participation may be offered at the Program Committee's discretion. Those wishing to attend should submit a "position paper". One or two pages in PDF is enough, relevant submitted position papers will be published on the workshop's datatracker page, and papers from people who do not plan to attend are also welcome. Submissions are inputs to the agenda, not talks, and not every submission will be presented. The workshop itself will be focused on discussions. Anyone may submit a short statement of interest in place of a full position paper, though position papers carry more weight in shaping the agenda. The Program Committee may also invite key participants directly, without a submission.
Accepted position papers will normally be published on the Datatracker before the workshop. Authors who would prefer that their paper not be published, or that specific material be handled without attribution, should indicate this at submission and note whether it affects what they would be willing to present during the workshop. If any discussion requires the Chatham House Rule, please indicate that during the workshop or to the respective session moderator in advance. The workshop will not have public recordings or minutes, however, collabrative notes (e.g., via HedgeDoc) will be maintained to assist in preparing the report and kept as a public reference, excluding any sections subject to the Chatham House Rule.
The IETF code of conduct, and the IETF anti-harassment policy apply. Contributions are subject to the IETF intellectual property policy.
- Paper submissions due by: 2026-09-04
- Invitations to attendees sent: rolling as submissions arrive; all outcomes by 2026-09-14
- Workshop date: 2026-10-11 (Sunday) and 2026-10-12 (Monday)
- Workshop location: Prague
- Program committee:
- Nick Sullivan (Cryptography Consulting LLC/IAB)
- Yaroslav Rosomakho (Zscaler/IAB)
- Suresh Krishnan (Cisco/IAB)
- Thom Wiggers (PQShield)
- Mike Ounsworth (Cryptic Forest Software)
- Hoss Shafagh (Netflix)
- Vladimir Soukharev (Keyfactor)
- Tim Hollebeek (DigiCert)
- Murugiah Souppaya (HP)
References
* [FIPS204] NIST, "Module-Lattice-Based Digital Signature Standard," FIPS 204.
* [FIPS205] NIST, "Stateless Hash-Based Digital Signature Standard," FIPS 205.
* [COMPOSITE] "Composite ML-DSA for use in X.509 Public Key Infrastructure," draft-ietf-lamps-pq-composite-sigs.
* [MTC] "Merkle Tree Certificates," draft-ietf-plants-merkle-tree-certs.
* [AUTHKEM] "KEM-based Authentication for TLS 1.3," draft-celi-wiggers-tls-authkem.
* [PQREADY] DigiCert, "2025 Quantum Readiness Study," Propeller Insights survey of 1,042 security leaders, May 2025, https://www.digicert.com/news/quantum-readiness-gap-a-digicert-study-on-quantum-safe-encryption.