P802.1AReg Support for ML-DSA

Full title: IEEE Standard for Local and metropolitan area networks–Secure Device Identity – Amendment: Support for the Module-Lattice-Based Digital Signature Algorithm

This amendment adds support for unique per-device identifiers using cryptographic binding based on the Module-Lattice-Based Digital Signature Algorithm (ML-DSA) with the ML-DSA-87, ML-DSA-65, and ML-DSA-44 parameter sets as specified in NIST FIPS 204 and the ASN.1 algorithm identifiers specified in IETF RFC 9881.

Quantum computing may provide sufficient compute power to break the current set of asymmetric keyed cryptographic algorithms used for device identification. ML-DSA is believed to be capable of supporting the unique per-device identifiers (DevIDs) specified by IEEE Std 802.1AR against attacks from both classical and quantum computers. Post Quantum Cryptography supported DevIDs are expected to become a requirement for many governments in their procurements, beginning as soon as January 2027 (as in, for example, the US Quantum Computing Cybersecurity Preparedness Act (US 117-260)).

IEEE Security Task Group projects and related standards.

Current Status

   Status
 
PAR approved 10th December, 2025
Working Group balloting in progress
Current
Draft 

P802.1AReg/D1.0 (11th December 2025)
 

Editor  Paul Bottorff

Archive

Date Document
11th December 2025 P802.1AReg/D1.0
Sidebar