Google Aggressively Targets 2029 to Migrate Fully to PQC
嗯,用户让我帮忙总结一篇文章的内容,控制在100个字以内,而且不需要特定的开头。我得先仔细看看这篇文章讲的是什么。 文章主要讲的是Google计划在2029年之前完成向抗量子密码学(PQC)的迁移,比NSA和一些政府机构提前。这看起来是一个重要的安全举措,因为量子计算机可能会在2030年代威胁到现有的加密技术。 然后,文章还提到了Sectigo的研究,指出大多数组织已经意识到准备短期证书和PQC之间的重叠,并且很多组织已经在预算中分配了资金来应对PQC。同时,Sectigo也提醒人们不要低估短期证书带来的紧迫性,因为这可能导致立即的问题。 我需要把这些关键点浓缩到100字以内。首先提到Google的目标年份和时间表,然后提到NSA和其他机构的时间表。接着提到量子计算机对加密的威胁,以及Google采取的措施。最后可以简要提到Sectigo的研究结果和建议。 确保语言简洁明了,不使用复杂的术语,同时涵盖主要信息:Google的计划、时间对比、威胁、应对措施以及研究结果。 </think> Google计划于2029年前完成向抗量子密码学(PQC)的迁移,领先于NSA(2031年)及其他政府机构(2035年)。其强调量子计算机对现有加密标准的威胁,并调整时间表优先迁移认证服务。Android 17已集成PQC技术。研究显示90%组织正准备应对短期证书与PQC挑战。 2026-3-31 06:0:59 Author: securityboulevard.com(查看原文) 阅读量:2 收藏

Security soothsayers predict we’ll reach Q-day, when quantum computers can break current encryption, sometime in the 2030s. But Google plans to be ready before that—aggressively targeting 2029 as the deadline to migrate completely to post-quantum cryptography. 

That puts Google well ahead of the NSA, which plans to move to PQC by 2031—other government agencies are aiming for 2035. 

Noting that “quantum computers will pose a significant threat to current cryptographic standards, and specifically to encryption and digital signatures,” Google wrote in a blog that “the threat to encryption is relevant today with store-now-decrypt-later attacks, while digital signatures are a future threat that require the transition to PQC before a Cryptographically Relevant Quantum Computer (CRQC).” It adjusted its timeline accordingly to “prioritize PQC migration for authentication services,” which it points out is “an important component of online security and digital signature migrations.” 

The company said it is its “responsibility to lead by example and share an ambitious timeline. By doing this, we hope to provide the clarity and urgency needed to accelerate digital transitions not only for Google, but also across the industry.” 

And Google is offering a sign of good faith, underscoring its migration plans. “As an example of our ongoing PQC commitments, Android 17 is integrating PQC digital signature protection using ML-DSA in alignment with the National Institute of Standards and Technology (NIST),” according to the blog post. “This continues to put advanced PQC technology directly into the hands of our customers, building on our Google Chrome support for PQC, providing PQC solutions in the cloud and insights and guidance for leaders on their PQC journey.” 

“Google’s announcement of a 2029 timeline for postquantum cryptography migration reinforces how quickly the cryptographic landscape is evolving,” says Jason Soroko, senior fellow at Sectigo.  

That same year, Soroko says, “the CA/Browser Forum will reduce the maximum SSL/TLS certificate lifespan to just 47 days, a 12× increase in renewal frequency that fundamentally changes how organizations must operate.” 

Currently, Sectigo’s research shows that “90% of organizations see a direct overlap between preparing for short-lived certificates and preparing for PQC adoption.” 

And, he says, the “parallel 2029 deadlines are not coincidental; they represent two sides of the same challenge: preparing for a world where cryptography must be updated far more frequently and with far greater agility.” 

Indeed, the “convergence of these deadlines is in some way harmonious: As Google advances the PQC timeline, and as certificate validity shrinks to 47 days, the ecosystem must move together,” Soroko says. 

“Continued collaboration through the IETF and the CA/Browser Forum will be essential to ensuring that organizations can rotate keys, algorithms, and certificates quickly and safely, building the agility needed to secure the quantum era,” he explains. 

Sectigo’s research indicates that organizations “appear to be taking PQC preparation more seriously than the upcoming shift to 47-day certificate lifespans, even though the deadlines attached to certificate lifespans occur sooner,” suggesting that  “PQC is viewed as a strategic, long-term imperative tied to existential threats, whereas the 47-day change is seen as a more tactical, operational hurdle.” The research found that 14% of organizations “have done a full assessment of quantum-vulnerable systems, while 90% have budgets allocated to PQC preparedness initiatives in the next 12 months and a few more than that (92 percent) plan to increase their investments in PQC over the next 2-3 years”. 

Sectigo says that taking PQC more seriously than shortened certificated lifespans “may underestimate the urgency of near-term risks: Failure to prepare for shortened certificate lifespans is far more likely to result in immediate outage, application failure, and trust disruption.” 

The shorter certificate lifespan is solvable and can be automated, the research contends, “While PQC represents a future-breaking threat, the 47-day challenge poses a present-breaking one, and both require equal prioritization in any robust crypto agile strategy.” 

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/03/google-aggressively-targets-2029-to-migrate-fully-to-pqc/
如有侵权请联系:admin#unsafe.sh