OpenSSL Communities

OpenSSL at Waseda University: Seminar on Post-Quantum Cryptography

Nikolas GauderNikolas Gauder Sat 18 Jul 2026 3:56PMPublicSeen by 26

Hi everyone,

As part of OpenSSL's ongoing effort to strengthen engagement with the broader academic community and showcase the work being done within the project, we recently hosted an online seminar for students and researchers at Waseda University. We hope initiatives like this will encourage greater collaboration between academia and the OpenSSL community, creating more opportunities for knowledge exchange and joint research in the future.

On 11 July, Aditya Koranga, Paul Yang and I gave an online seminar for students and researchers from Professor Kazue Sako's and Professor Tatsuya Mori's labs at Waseda University.

We gave three talks:

  • Aditya — Why Post-Quantum Cryptography Is Critical for Digital Security Today

    An introduction to the quantum threat, "harvest now, decrypt later," migration timelines, PQC support in OpenSSL and the importance of crypto-agility.

  • Paul — Quantum-Resilient Confidential Computing

    An overview of confidential computing and trusted execution environments, followed by a discussion of quantum-safe remote attestation, key provisioning and the role OpenSSL can play in the transition.

  • Nikolas — Measuring Post-Quantum Cryptography in QUIC on the Internet

    Results from Internet-scale QUIC measurements. Around 41% supported post-quantum key exchange, while none of the over 14 000 certificate chains examined used post-quantum signatures, showing that there is still plenty of work ahead.

The seminar was a good opportunity to connect current standards and OpenSSL development with academic research and real-world deployment data. We hope it can be the start of further exchanges with Waseda University and other academic institutions.

A recording will be made publicly available. I'll share the link here once it is ready!

Many thanks to Professor Sako, Professor Mori and their students for joining us, and to Leonid Posadskov for initiating and coordinating the collaboration. We look forward to many more opportunities to engage with the academic community and to bring more people to OpenSSL's academic community!

— Nikolas

Anton Arapov

Anton ArapovWed 29 Jul 2026 3:44PM

Great initiative, the kind of academic exchange we'd like more of.

Two things: please drop the recording (and slides, if you can) here once ready. And a standing offer — for events like this, OpenSSL can usually field a representative from the Foundation or the Corporation, whether a talk, a Q&A, or just someone in the room. Anyone organising something similar, at any institution: don't be shy to ask.

Gadepalli R G

Gadepalli R GThu 30 Jul 2026 10:44PM

@Anton Arapov Folks , please note , Your focus is on Academic community and hope my question falls within the scope and I posted it here because this recording pertained to Waseeda university in. Japan,🎈

Nikolas Gauder

Nikolas GauderFri 31 Jul 2026 5:52PM

@anton Slides are uploaded. Recording will follow

Gadepalli R G

Gadepalli R GWed 29 Jul 2026 5:45PM

Hello , Great and look forward to be able to review the slides to better understand how PQC works actually protecting digital identity, since you mention “ crypto agility “ , Do you have an approximate time frame between harvest of sensitive data and decryption. Is there any way to classify this concept based on industry verticals like say Healthcare or Finance for example, Risk and cost analysis will be different in each scenario, FYI ?Please share your suggestions , Thank you

Nikolas Gauder

Nikolas GauderThu 30 Jul 2026 9:50AM

@ravgade PQC protects/is about the cryptographic mechanisms supporting a digital identity. This includes quantum-resistant key exchange, digital certificates, authentication signatures, software or firmware signing etc. Crypto agility is the ability to replace these algorithms and keys without redesigning or disrupting the entire identity platform/system. NIST describes it as the capability to adapt cryptography across applications, hardware, protocols, and infrastructure while maintaining operational continuity.

Regarding the interval between harvesting sensitive encrypted data and decrypting it, there is no reliable fixed time frame. Data can be collected today and retained until a cryptographically relevant quantum computer becomes available. No one currently knows when this will happen, although some forecasts suggest it could be within ~ten years. Therefore, information that must remain confidential into the 2030s or longer should already be considered potentially exposed to a "harvest now, decrypt later" scenario.

So a practical assessment would compare:
* How long the information must remain confidential
* How long the PQC migration will take
* The expected lifetime of the affected systems
* The consequences if the information is eventually decrypted
* Regulatory, operational, and reputational exposure...

For healthcare, I can think of long-lived patient records, genomic information, digital prescriptions, clinical research data etc. that may remain sensitive for decades. Migration costs may also be higher here because of many legacy systems, connected medical devices, interoperability requirements, and long equipment-replacement cycles.

For financial services, priorities may include customer identity and KYC records, payment infrastructure, interbank communications, and long-term financial agreements. Challenges I can think of are transaction latency, large-scale PKI and HSM replacement, regulatory things.

So my recommendation - although I am not an expert in this regard - would be to begin with a cryptographic inventory and then ranking each use case according to data sensitivity, required protection time, migration complexity, and business impact. Internet-facing communications, identity and certificate infrastructure, code-signing systems, and long-term archives would normally receive early attention. CISA, NIST, and NSA similarly recommend creating a quantum-readiness roadmap and prioritizing systems that currently depend on vulnerable public-key cryptography.

Hope this helps!

Gadepalli R G

Gadepalli R GThu 30 Jul 2026 10:50PM

@Nikolas Gauder Hello , Is there a way for me to message you directly as all my questions may not be relevant to the whole group, Could you please clarify as there are many important questions you have raised , Thank you

Nikolas Gauder

Nikolas GauderFri 31 Jul 2026 11:44AM

@ravgade I've sent you a DM. For any questions that are related to what we're covering though, feel free to ask them here in the group thread as well so everyone can benefit from the answers. Maybe it will help others who have the same questions too 🙂

Gadepalli R G

Gadepalli R GSat 1 Aug 2026 12:23AM

@Nikolas Gauder Of course that’s quite a Valid point , I will post my questions here as long it’s fine with the general guidelines of the community and feel free to respond and I will learn along the way also Have a good evening , thank you

Gadepalli R G

Gadepalli R GThu 30 Jul 2026 8:27PM

👋,! Great answer with an in-depth analysis and explanation of the topic in question, I have read your response and it helped me understand my question from your perspective or point of view 🙂, Thank you to start with,

Gadepalli R G

Gadepalli R GThu 30 Jul 2026 11:03PM

Thank you folks ,pausing to reorganize my thoughts 💭