< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Microsoft prioritizes threat modeling for post-quantum migration

Microsoft is prioritizing threat modeling as a core component of its migration to post-quantum cryptography. The company aims to migrate its critical products and services by 2029 to defend against potential quantum-era attacks.

To achieve this, Microsoft recommends transitioning RSA, ECDH, and Diffie-Hellman key establishment to ML-KEM, while utilizing ML-DSA, SLH-DSA, or composite signatures to replace RSA and elliptic-curve-based signing. AES-256 remains the recommended standard for bulk encryption. While TLS 1.3 provides a foundation for network security, it requires the negotiation of supported post-quantum or hybrid key-establishment groups to be quantum-resistant.

Effective migration requires maintaining a detailed cryptographic inventory that includes algorithms, protocol versions, cipher suites, and key sizes. This inventory must account for dependencies within operating systems, cloud platforms, hardware, and third-party frameworks to ensure comprehensive protection.

Entities

Microsoft