关于OpenSSL是否支持后量子非对称加密/签名算法及相关计划的问询
Great question! Since you’re approaching this as an enthusiast (not a cryptographer) wanting to use OpenSSL as a black box, let’s break this down straightforwardly:
当前已支持的后量子算法
Starting with OpenSSL 3.0, the project has integrated several NIST-standardized post-quantum asymmetric algorithms for both encryption/key exchange and signing:
- Key Exchange/Encapsulation (KEM): CRYSTALS-Kyber (NIST’s primary recommendation for general-purpose key exchange). You can use variants like
kyber-512,kyber-768, andkyber-1024corresponding to different security levels. - Digital Signatures: CRYSTALS-Dilithium, Falcon, and SPHINCS+. These cover different use cases—Dilithium and Falcon are efficient for most scenarios, while SPHINCS+ is a hash-based signature scheme suitable for long-term security needs.
To verify which post-quantum algorithms your OpenSSL version supports, run these commands:
# List supported KEM algorithms openssl list -kem-algorithms # List supported signature algorithms openssl list -signature-algorithms
As a quick example of using these as a black box:
- Generate a Kyber key pair:
openssl genpkey -algorithm kyber-768 -out kyber-private.pem openssl pkey -in kyber-private.pem -pubout -out kyber-public.pem - Sign data with Dilithium:
openssl pkeyutl -sign -in data.txt -inkey dilithium-private.pem -out sig.bin -pkeyopt digest:sha256
后续计划
The OpenSSL team is actively tracking NIST’s post-quantum cryptography standardization process. NIST is still evaluating additional algorithms in its third round of assessments, and OpenSSL will continue to integrate validated algorithms as they receive final approval.
Additionally, future versions will focus on optimizing the performance of existing post-quantum implementations, improving compatibility with classic algorithms (for hybrid crypto setups, which are recommended during the transition period), and expanding documentation to make black-box usage even more accessible.
A quick note for your long-term project: Stick to the latest stable OpenSSL releases (3.0 or newer) to get access to these features, and prioritize NIST-recommended parameter sets to avoid unnecessary security risks.
内容的提问来源于stack exchange,提问作者The Quantum Physicist

