WSIS Forum 2026
Rapport généré par l'IA

Post‑Quantum: Preparing the DNS for Post-Quantum Cryptography

14 intervenants
Résumé

Résumé

Cette session s'est concentrée sur les défis liés à la préparation de l'infrastructure Internet - notamment la sécurité du DNS et du routage - à l'ère de la cryptographie post-quantique (PQC). Pierre Bonis, directeur général de l'Afnic, a expliqué que le DNS repose largement sur la cryptographie via le DNSSEC, et que les algorithmes cryptographiques actuels ne résisteront pas à l'informatique quantique . Il a averti que les algorithmes post-quantiques, bien que plus sûrs, sont plus volumineux et plus lents, ce qui pourrait engendrer des problèmes significatifs de latence et de performance pour la résolution DNS . Dans un scénario extrême, il a évoqué la possibilité controversée de supprimer le DNSSEC si aucune solution PQC viable n'est trouvée, tout en reconnaissant qu'il s'agirait d'un résultat profondément indésirable . Il a également souligné le manque de données empiriques démontrant les bénéfices concrets en matière de sécurité du déploiement du DNSSEC, appelant à de meilleures statistiques . Wout de Natris, coordinateur de l'IS3C, a présenté la question comme relevant fondamentalement d'un défi politique et économique plutôt que purement technique, insistant sur la nécessité de convaincre les décideurs d'agir avant qu'une percée quantique ne rende obsolète le chiffrement actuel . Il a mis en évidence le risque d'une « fracture en matière de sécurité numérique et quantique », avertissant que des réglementations nationales fragmentées et contradictoires - comme celles observées pour l'IoT dans 21 juridictions produisant 442 bonnes pratiques souvent contradictoires - pourraient empêcher une adoption mondiale cohérente des normes PQC . Moritz Müller, du SIDN (extension .nl), a fourni une évaluation technique, notant que le DNSSEC est plus avancé dans la planification de la transition PQC que RPKI, bien qu'aucun des deux ne soit prêt . Il a observé que les transitions d'algorithmes dans le DNSSEC ont historiquement pris une décennie ou plus, et que les algorithmes PQC adaptés au DNSSEC sont encore en cours de standardisation . Pour RPKI, il a noté un manque de dynamisme au sein de la communauté et l'absence d'expérience préalable en matière de migration d'algorithmes . Les participants ont exprimé des préoccupations quant à la fragmentation géopolitique menant à des normes nationales incompatibles , à la nécessité pour l'ICANN de s'engager plus urgemment sur la PQC , et au risque qu'une mauvaise réglementation compromette l'interopérabilité . La session s'est conclue par un appel général à la collaboration entre parties prenantes, à l'urgence d'agir et à une action mondiale coordonnée pour éviter la fragmentation des normes de sécurité internet .

Points clés
  • Points clés

  • Objectif général

  • La discussion visait à sensibiliser à la nécessité urgente de préparer l'infrastructure Internet - notamment les protocoles liés au DNS tels que le DNSSEC et RPKI - à la transition vers la cryptographie post-quantique (PQC). Organisée par l'Afnic et la Coalition dynamique IS3C, la session a réuni des experts techniques, des décideurs politiques et des parties prenantes de la gouvernance de l'Internet afin d'évaluer l'état actuel de la préparation à la PQC, d'identifier les lacunes et d'encourager une action mondiale coordonnée.
  • --
  • Principaux points de discussion

  • La menace que l'informatique quantique fait peser sur les normes cryptographiques actuelles, en particulier le DNSSEC : Les algorithmes cryptographiques actuellement utilisés dans la sécurité DNS ne résisteront pas aux attaques de l'informatique quantique. Pierre Bonis a expliqué que les algorithmes post-quantiques, bien que plus robustes, sont plus volumineux et plus lents, ce qui pourrait engendrer des problèmes significatifs de latence et de performance pour la résolution DNS. Il a évoqué de manière provocatrice l'« option nucléaire » consistant à supprimer entièrement le DNSSEC si aucune solution PQC viable n'est trouvée, tout en reconnaissant que cela serait profondément indésirable. - L'état inégal de la préparation à la PQC entre le DNSSEC et RPKI : Moritz Müller-Brus a noté que le DNSSEC est plus avancé dans sa transition PQC que RPKI, bénéficiant de migrations d'algorithmes antérieures et d'un engagement croissant de la communauté au sein de l'IETF. Cependant, RPKI présente un tableau moins clair - il s'agit d'un déploiement plus récent, qui n'a jamais subi de changement d'algorithme et ne bénéficie pas du même niveau d'urgence ou de mobilisation communautaire. Il a suggéré que l'identification des exigences spécifiques de transition de RPKI devrait constituer une prochaine étape prioritaire. - Le manque d'urgence et le risque d'une culture du « wait-and-see » : Wout de Natris a souligné que le déploiement des normes affiche un bilan médiocre à l'échelle mondiale, et que la plupart des parties prenantes attendent que d'autres agissent plutôt que de prendre l'initiative. Il a averti qu'un ordinateur quantique suffisamment puissant pourrait briser simultanément tous les chiffrements actuels, et que la fenêtre de préparation - bien qu'encore ouverte - se rétrécit rapidement. Il a également souligné que l'IS3C ne dispose pas du financement structurel nécessaire pour mener des actions de sensibilisation et de formation à l'échelle requise. - Le risque de fragmentation - tant technique que géopolitique : Jacques Beglinger a soulevé la crainte que la compétition géopolitique ne conduise à des normes PQC nationales ou régionales incompatibles. Peter Koch a renforcé ce point en avertissant qu'une réglementation mal conçue, motivée par l'urgence, pourrait entraîner l'interdiction ou la dépréciation de certains algorithmes dans certaines juridictions mais pas dans d'autres, compromettant ainsi l'interopérabilité transfrontalière du DNS. Wout de Natris a répondu que des tests et une mise en œuvre proactifs des solutions PQC, pilotés par la communauté, pourraient contribuer à prévenir une réglementation mal conçue. - La nécessité d'une justification fondée sur des données probantes pour le DNSSEC et d'une politique mondiale coordonnée : Pierre Bonis a mis en évidence un manque significatif de données empiriques démontrant les bénéfices réels du DNSSEC en matière de sécurité, notant qu'il n'avait jamais vu d'études comparatives sur les taux d'attaques dans les zones signées par rapport aux zones non signées. Jimson Olufuye a abondé dans ce sens, suggérant de demander à l'ICANN de fournir de telles statistiques. Wout de Natris a en outre soutenu que la politique PQC doit être coordonnée à l'échelle mondiale - et non cloisonnée par pays - citant en exemple la découverte antérieure de 442 bonnes pratiques contradictoires dans seulement 21 juridictions. ---
  • Tonalité générale

  • La discussion s'est ouverte sur un ton informatif et mesuré, les intervenants posant le contexte technique et organisationnel des défis liés à la PQC. Elle a ensuite évolué vers un registre plus urgent et préventif, notamment lorsque Wout de Natris a utilisé une expérience de pensée sur l'ouverture simultanée de tous les verrous numériques pour illustrer les enjeux de la vulnérabilité quantique. On a noté des moments d'humour pince-sans-rire - notamment la remarque en aparté de Pierre Bonis sur le fait de garder son équipe R&D occupée et sa boutade finale sur les silos qui sont « sûrs pour le quantique, en particulier sur la lune » - qui allègent l'atmosphère sans pour autant minimiser la gravité du sujet. Dans la seconde moitié de la session, le ton est devenu nettement plus préoccupé et direct, les intervenants reconnaissant ouvertement l'inertie institutionnelle, les insuffisances de financement et le danger de la fragmentation. Dans l'ensemble, la discussion était constructive et collaborative, se terminant par un appel à l'action en faveur d'un engagement plus large des parties prenantes, plutôt que par un sentiment de désespoir.
Intervenants
PB
Pierre Bonis
111 wpm · 14 min
MM
Moritz Müller-Brus
152 wpm · 8 min
WD
Wout de Natris
143 wpm · 12 min
AM
Audience Member 1
40 wpm · 1 s
AM
Audience Member 2
122 wpm · 10 s
AM
Audience Member 3
78 wpm · 15 s
AM
Audience Member 4
90 wpm · 7 s
JO
Jimson Olufuye
123 wpm · 1 min
S1
Speaker 1
131 wpm · 1 min
PF
Philippe Foucart
121 wpm · 56 s
JB
Jacques Beglinger
86 wpm · 1 min
PK
Peter Koch
139 wpm · 1 min
M
Moderator
136 wpm · 37 s
LC
Lucien Castex
87 wpm · 3 min

Résumé étendu : Préparer l'Internet à la cryptographie post-quantique

#

Présentation générale et contexte de la session

Cette session, organisée par l'Afnic et la Coalition dynamique sur les normes, la sécurité et la sûreté de l'Internet (IS3C) du Forum sur la gouvernance de l'Internet, a réuni des experts techniques, des opérateurs de registres et des parties prenantes de la gouvernance de l'Internet afin d'évaluer les défis que représente la transition de l'infrastructure Internet - en particulier les protocoles liés au DNS - vers la cryptographie post-quantique (PQC). Présidée par Lucien Castex, la session a accueilli les contributions de Pierre Bonis (directeur général de l'Afnic), Wout de Natris (coordinateur de l'IS3C) et Moritz Müller-Brus (chercheur au SIDN, extension .nl). Un quatrième intervenant, Joao Moreno Focao, devait présenter le rapport PQC de l'IS3C, mais n'a pas pu se connecter durant la session ; Wout de Natris a proposé de résumer les conclusions en son absence. Les questions de la salle ont élargi la discussion aux dimensions géopolitiques, réglementaires et d'équité.

Pierre Bonis a ouvert la session en précisant son périmètre et l'intérêt de l'Afnic pour le sujet, notant avec une autodérision caractéristique qu'une réponse simple à la question de savoir pourquoi l'Afnic s'intéresse à la PQC est que « l'équipe R&D » doit être occupée. Plus sérieusement, il a souligné que l'intérêt de l'Afnic ne réside pas dans la construction d'ordinateurs quantiques, mais dans la compréhension de la manière dont l'informatique quantique affectera ceux qui s'appuient sur l'infrastructure cryptographique existante . Il en a également profité pour saluer la Coalition dynamique IS3C comme un exemple de ce que le FGI peut véritablement accomplir, s'inscrivant en faux contre la perception selon laquelle le FGI ne serait qu'une « vitrine symbolique » .

---

#

Pourquoi la cryptographie post-quantique est-elle importante pour le DNS ?

Pierre Bonis a expliqué que le DNS repose largement sur la cryptographie, notamment à travers le DNSSEC - un protocole développé, selon ses termes, après la découverte d'une faille majeure dans le protocole DNS, qu'il a désignée de manière hésitante comme « Lafayette Kaminsky » (reconnaissant qu'il n'avait pas tout à fait le bon nom en anglais) . Le DNSSEC utilise des signatures cryptographiques pour sécuriser les réponses DNS, et son déploiement a été fortement recommandé par l'ICANN . Cependant, les algorithmes cryptographiques qui sous-tendent actuellement le DNSSEC ne résisteront pas aux attaques d'ordinateurs quantiques suffisamment puissants .

Le défi est amplifié par la nature même des algorithmes post-quantiques. Bien que plus robustes que leurs prédécesseurs, les algorithmes PQC produisent des clés et des signatures plus volumineuses et nécessitent davantage de temps de traitement . Cela crée une tension significative avec les exigences opérationnelles du DNS, qui traite d'énormes volumes de requêtes en des délais très courts . Pierre Bonis a averti que si ces compromis en matière de performance ne peuvent être résolus, l'introduction des algorithmes PQC pourrait avoir « un impact considérable sur les performances de la résolution dans le DNS » . Il a donc appelé à des tests urgents des algorithmes et du matériel susceptible d'accélérer les opérations mathématiques nécessaires .

Dans un aparté délibérément provocateur, Pierre Bonis a soulevé ce qu'il a lui-même reconnu être « une très mauvaise chose à dire » : mais si aucune solution PQC viable ne peut être trouvée qui maintienne des performances DNS acceptables, un dernier recours théorique serait de supprimer entièrement le DNSSEC, puisque cela éliminerait le problème de cryptographie post-quantique pour le DNS . Il a soulevé ce point non pas comme une recommandation, mais pour souligner la gravité du défi de performance et la nécessité d'une prise de décision fondée sur des données probantes.

##

L'absence de données empiriques sur les bénéfices du DNSSEC

Aggravant encore le défi, Pierre Bonis a relevé une lacune frappante dans la base de données probantes : il n'avait jamais rencontré d'étude démontrant le bénéfice réel et mesurable du déploiement du DNSSEC . La littérature existante, a-t-il observé, plaide soit en faveur du DNSSEC, soit rend compte des taux d'adoption, mais ne compare pas les taux d'attaques dans les zones signées par rapport aux zones non signées . Sans de telles données, il devient difficile de justifier les coûts et la complexité du maintien du DNSSEC - sans parler de sa migration vers des algorithmes post-quantiques. Ce point a trouvé un écho auprès de Jimson Olufuye, qui a suggéré par la suite qu'il faudrait demander formellement à l'ICANN de produire de telles statistiques, notant que les défenseurs du DNSSEC dans des régions comme le Nigeria ont besoin de données concrètes pour soutenir leurs efforts de mobilisation .

---

#

Les travaux de l'IS3C et le cadrage en termes de gouvernance

Wout de Natris, coordinateur de l'IS3C, a fourni à la fois une mise à jour organisationnelle et un recadrage conceptuel plus large du défi. Il a indiqué que l'IS3C - désormais formellement établie - a produit quatre rapports et deux boîtes à outils sur le déploiement des normes Internet et les politiques associées, le plus récent étant consacré à la PQC . Depuis la présentation de ce rapport au FGI en 2025, l'IS3C a organisé quatre ateliers et webinaires sur le sujet et créé deux groupes de travail, l'un sur le DNS et l'autre sur le RPKI, qui ont tous deux tenu leur première réunion .

Wout De Natris a également mis en lumière une évolution technique importante et préoccupante : le premier algorithme de chiffrement a déjà été cassé par un ordinateur quantique, « bien que de taille très limitée », et qu'à chaque bit quantique ajouté, la technologie gagne en puissance - soulignant que la menace n'est pas seulement théorique, mais déjà en marche.

Wout De Natris a ensuite avancé un argument central : la préparation à la cryptographie post-quantique n'est pas fondamentalement un problème technique . Il s'agit plutôt « de convaincre ceux qui détiennent le pouvoir de décision » et relève d'une « prise de décision politique et économique et de la volonté de prévenir les préjudices sociaux pour tous les citoyens, clients et utilisateurs finaux » . Il a soutenu que si les décideurs agissent positivement, les techniciens recevront la formation et les financements dont ils ont besoin pour déployer les normes pertinentes à temps . Le problème, a-t-il insisté, est que les normes Internet liées à la sécurité, telles que le DNSSEC et le RPKI, sont « au mieux modérément bien adoptées, au pire dans un état désastreux » à l'échelle mondiale , et que cela doit changer avant que la menace quantique ne devienne aiguë.

Il a également souligné l'urgence du calendrier : « quelqu'un pourrait avoir le moment eurêka demain », et si personne ne peut être prêt pour demain, la communauté devrait l'être dans deux à trois ans, « car les choses vont incroyablement vite ». Ce cadrage a donné une fenêtre concrète d'action disponible.

Pour illustrer les enjeux, Wout de Natris a eu recours à une expérience de pensée : il a demandé au public d'imaginer une invention qui ferait s'ouvrir simultanément toutes les serrures du monde, puis a établi un parallèle direct avec ce qu'un ordinateur quantique suffisamment puissant pourrait faire à l'ensemble du chiffrement numérique . Les réponses du public allaient de rentrer chez soi pour rejoindre sa famille à appeler Pierre Bonis pour trouver une solution, ce que Wout de Natris a utilisé pour renforcer son propos sur le manque généralisé d'urgence, même au sein des communautés spécialisées .

---

#

Le risque d'une fracture en matière de sécurité quantique

Wout de Natris a été explicite sur le fait que la transition vers la PQC ne doit pas reproduire les inégalités numériques existantes. Il a déclaré qu'« une fracture en matière de sécurité numérique et quantique doit être évitée » et qu'« il n'est pas acceptable que le monde occidental ne pense qu'à lui-même alors que le reste du monde est laissé pour compte. » . L'IS3C prépare des programmes de sensibilisation et de formation pour y remédier, mais manque actuellement de financements structurels pour opérer à l'échelle requise .

Il s'est également appuyé sur les recherches antérieures de l'IS3C pour illustrer les dangers d'une politique fragmentée et non coordonnée. Dans une étude des politiques IoT dans 21 juridictions, l'IS3C a recensé 442 bonnes pratiques auxquelles l'industrie était censée se conformer, dont certaines étaient « totalement contradictoires » . Il a averti que si les orientations en matière de PQC suivent la même voie - chaque pays produisant un ensemble de règles différent - l'industrie sera dans l'incapacité d'adopter des normes cohérentes . Une action coordonnée à l'échelle mondiale ou au moins régionale, impliquant l'ensemble des communautés de parties prenantes, est donc indispensable .

---

#

Évaluation technique : l'état de préparation du DNSSEC et du RPKI

Moritz Müller-Brus du SIDN a proposé une évaluation technique détaillée de l'état d'avancement du DNSSEC et du RPKI dans leur planification de la transition vers la PQC. Pour contextualiser, il a indiqué que le SIDN gère les extensions .nl, dont 60 % sont signés avec le DNSSEC - une base de déploiement significative qui confère au SIDN un intérêt direct dans la transition.

Sur le DNSSEC, il a noté que l'urgence est quelque peu moins aiguë que pour des protocoles tels que TLS, car le DNSSEC utilise la cryptographie pour la signature et la vérification plutôt que pour le chiffrement des communications - ce qui signifie qu'il n'est pas exposé à la menace du « stocker maintenant, déchiffrer plus tard » . Néanmoins, il a averti que les transitions d'algorithmes dans le DNSSEC ont historiquement pris au moins une décennie, comme en témoigne la lente migration de RSA vers la cryptographie à courbes elliptiques , et que la transition post-quantique pourrait prendre encore plus de temps, étant donné que les algorithmes PQC ne constituent pas de simples remplacements directs : ils utilisent des clés plus longues, des signatures plus volumineuses, voire les deux .

Il existe cependant des signes positifs. La communauté DNS est plus à même de changer d'algorithmes qu'elle ne l'était autrefois, ayant réussi la transition de RSA vers ECDSA pour .nl et de nombreux autres TLD . L'automatisation est plus développée, la racine DNS a effectué au moins un renouvellement de clés et se prépare à en effectuer un autre, et la communauté IETF est de plus en plus dans les travaux sur la PQC pour le DNSSEC . Le SIDN a également créé un laboratoire de test accessible au public - ouvert aux parties externes souhaitant tester leurs propres zones DNS - pour évaluer l'impact des algorithmes post-quantiques sur les fichiers de zone DNS, et étend désormais ses recherches au volet validation, en examinant ce qui se passe lorsque les résolveurs doivent valider de grands volumes de signatures post-quantiques .

Pour la suite, Moritz Müller-Brus a identifié plusieurs défis persistants : la communauté doit attendre que des algorithmes appropriés soient standardisés, le protocole DNS lui-même devra peut-être être modifié pour accueillir les algorithmes PQC , et des incitations - notamment la formation, un sentiment d'urgence et éventuellement une législation - seront nécessaires pour stimuler le déploiement une fois les solutions techniques disponibles .

---

#

RPKI : un tableau moins avancé

Sur le RPKI - l'infrastructure qui sécurise le routage BGP sur l'internet - Moritz Müller-Brus a dressé un tableau moins optimiste . Le RPKI est un déploiement plus récent que le DNSSEC. Il n'a jamais subi de changement d'algorithme, et la communauté développant les protocoles RPKI est encore largement concentrée sur les défis opérationnels actuels plutôt que sur les exigences futures en matière de PQC . Il n'existe pas non plus de consensus clair sur ce qui doit exactement changer dans le RPKI pour réaliser une transition post-quantique . Moritz Müller-Brus a suggéré que la priorité immédiate devrait être d'identifier les exigences techniques spécifiques de la transition du RPKI - quels composants doivent changer, lesquels peuvent rester en l'état, et quelles sont les exigences globales - en s'appuyant sur les premières recherches menées par des stagiaires au SIDN .

Wout de Natris a renforcé cette préoccupation d'un point de vue de gouvernance, notant que les membres du groupe de travail RPKI de l'IS3C « n'en discutent pas » et « ne nous demandent pas d'être actifs » . Il s'est dit surpris qu'« il ne semble pas exister à ce stade d'organisation faîtière travaillant sur ce sujet » , et a averti que le manque d'urgence au sein de la communauté RPKI est particulièrement dangereux compte tenu de la rapidité avec laquelle l'informatique quantique progresse .

---

#

L'évolution de la position de l'ICANN

La question du rôle de l'ICANN dans la préparation à la PQC a été soulevée de plusieurs côtés. Jimson Olufuye a demandé si l'ICANN travaille activement sur la préparation post-quantique, notamment en ce qui concerne les serveurs racine . Pierre Bonis a confirmé que l'engagement de l'ICANN est récent et quelque peu tardif : lors d'une discussion publique quelques mois auparavant, le Bureau du CTO de l'ICANN (OCTO) avait déclaré que la PQC « n'est pas le problème. Nous verrons cela plus tar » - selon le souvenir qu'en avait Pierre Bonis - avant de revenir sur cette position en quinze jours, la qualifiant de « problème majeur » . Pierre Bonis a suggéré que l'ICANN avait été très concentrée sur le renouvellement de la clé racine du DNS - une opération complexe et à forts enjeux - et n'avait que récemment tourné son attention vers le défi post-quantique . Il a affirmé que ce changement est bienvenu, mais a noté à quel point même les instances les plus autorisées de la gouvernance de l'Internet ont commencé à s'engager sérieusement sur ce sujet seulement récemment.

---

#

Fragmentation géopolitique et risque réglementaire

La dernière partie de la session a introduit une dimension géopolitique. Jacques Beglinger, associé au FGI suisse, a soulevé la crainte que la compétition entre grandes puissances ne produise des normes PQC nationales ou régionales incompatibles - une « norme occidentale », une « norme africaine » ou une « norme nationale » - reflétant les tendances plus larges à la fragmentation de l'Internet . Pierre Bonis a répondu en recadrant le risque de fragmentation : la préoccupation la plus pressante, a-t-il soutenu, n'est pas la concurrence entre normes, mais l'inégalité d'accès aux capacités matérielles nécessaires à la mise en œuvre de la PQC . Il a pointé les entreprises d'IA qui accaparent le matériel disponible et font monter les prix comme facteur clé d'inégalité, avertissant que cela pourrait « créer un problème entre les grands acteurs de l'Internet, les grands registres, les grands opérateurs de télécommunications, et les plus petits » .

Peter Koch du DENIC a ajouté une dimension supplémentaire, avertissant que l'urgence combinée à la compétition géopolitique « pourrait conduire à une fragmentation effective si une réglementation mal conçue venait à s'imposer » . Plus précisément, si un algorithme PQC particulier est déprécié ou interdit dans une juridiction mais utilisé dans une autre, l'interopérabilité DNS intercontinentale pourrait se rompre . Il a demandé ce que la Coalition dynamique IS3C pourrait faire pour rendre ce risque explicite et le prévenir .

Wout de Natris a répondu que des tests et une mise en œuvre proactifs de solutions PQC menés par la communauté constituent peut-être la meilleure défense contre une réglementation mal conçue, puisque « se concentrer sur l'étude, les tests et la mise en œuvre de solutions de cryptographie post-quantique peut prévenir une mauvaise réglementation » . Il a reconnu que les groupes de travail de l'IS3C devraient aborder explicitement le risque de fragmentation comme sujet à part entière, et a réitéré l'importance d'associer des parties prenantes diverses à la conversation plutôt que de laisser chaque communauté rester dans son propre cloisonnement .

---

#

Applications futures et dispositifs contraints

Philippe Foucart d'Orange a soulevé une question prospective sur la possibilité que des applications futures - telles que l'IA agentique fonctionnant avec le protocole UDP - introduisent de nouvelles exigences en matière de sécurité DNS, notamment en ce qui concerne l'authenticité et l'intégrité des messages . Moritz Müller-Brus a reconnu la préoccupation, mais a noté qu'elle ne constitue pas actuellement un axe de recherche prioritaire, principalement parce que l'hypothèse retenue est que la validation PQC s'effectuera au niveau des résolveurs récursifs plutôt qu'au niveau des appareils - ce qui signifie que les dispositifs contraints et les applications futures communiqueront avec ces résolveurs plutôt que d'effectuer eux-mêmes la validation .

---

#

Conclusions et appel à l'action

La session s'est conclue par un large appel à la collaboration entre parties prenantes, à l'urgence et à une action mondiale coordonnée. Wout de Natris a résumé le défi : la plupart des parties prenantes « attendent que quelqu'un d'autre prenne l'initiative », ce qui conduit historiquement à l'inaction collective et aux reproches mutuels . Il a invité toutes les parties intéressées à rejoindre les groupes de travail de l'IS3C et à contribuer à l'effort coordonné . Moritz Müller-Brus a conclu que le DNSSEC est plus avancé que le RPKI dans sa transition PQC, mais qu'aucun des deux n'est prêt, et que les défis techniques, de gouvernance et d'incitation à venir sont considérables . Pierre Bonis a conclu avec son humour pince-sans-rire caractéristique, notant que « les silos pourraient être très sûrs pour le quantique, en particulier sur la lune » - une reconnaissance ironique que l'isolement n'est pas une stratégie viable.

Le rapport de la session et les documents connexes ont été mis à disposition sur le site de l'IS3C et la page de session de l'Afnic , et les groupes de travail sur le DNS et le RPKI ont été identifiés comme les principaux vecteurs pour faire avancer les travaux. Le message général était clair : la fenêtre de préparation reste ouverte, mais elle se rétrécit, et c'est le moment d'agir de manière coordonnée - sur les plans technique, politique et institutionnel.

Lucien Castex
Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. so welcome everyone to this session on both quantum cryptography as we have people online and in the room we'll be using microphones also if you have questions etc you have one just behind you I can style I would say so you can you
Pierre Bonis
can take it to just use it this session is called post quantum preparing the internet for post quantum cryptography it's organized by AFNIC the French internet and the dynamic coalition on internet standard security and safety is 3c I would like first to give the floor to the CEO of AFNIC Pierre Bonis to set the stage thank you very much Lucien welcome everybody very happy to be here with you so this is I'm gonna not introduce the quantum not me but maybe there is a reason why this is a subject of interest for AFNIC as a registry and first of all thank for leading the dynamic coalition for now a few years and this is a very five years this is a very important work we we are fully dedicated to it and by the way even if it's not exactly the main point of this session I cannot stress enough the fact that dynamic coalitions in general and IS3C in particular are examples of what IGF can create. A lot of people think that IGF is not delivering. It's a token shop. I think Dynamic Coalitions shows the very opposite of it. It's a way of gathering expertise and working in an intersectional... ...very important topics in the long run. And it has worked for several years, and this is something we have to bear in mind, maybe in preparation of the next IGF in Nairobi, to remind everyone that Dynamic Coalitions are a very good tool. Now, once I've said that, why do we care about post -cum -to -cryptography? The first... The first and easy answer would be the R &D team, and I have to keep them busy. But that would be very short. And by the way, we will never be a major player of quantum, because we don't have the money to get involved in that. So this session is not about quantum. It's about post -quantum cryptography, which means that we are talking from the side of the people who are effect, not on the side of the people who are building the computers that would be the quantum computers. This is the first thing that is very important, because even my brilliant idea and R &D team is not able at all. to deliver anything that makes really sense about quantum computing, at least for us. So why does it matter? It matters because DNS is using cryptography. A lot of people know that C cryptography in other protocols are very visible, just like HTTPS or this high layer cryptography, but DNS uses it also. And I think the most well -known way of using cryptography in the DNS is DNSSEC. DNSSEC is a way of securing the DNS with cryptography, and it has been developed. So it's a way of doing it. So it's a way of doing it. after the discovering of a major flow in the DNS protocol through Kaminsky, Lafayette Kaminsky, I'm sorry, I don't have it in English. Since then, this is highly recommended, and especially by ICANN, to sign and to have DNSSEC. The third DNSSEC, as for any other cryptography or signed protocol, the crypto algorithm that we have currently will not resist quantum. So we have to deploy some other ways of security. That will be... post -quantum compliant or post -quantum ready. And it happens that for now, these but they are stronger, of course, but longer and they take more time to work. And as the DNS is a protocol with a lot of queries in a very, very short time, you know, the introduction is for people like me. I mean, it's a very basic introduction. You will have specialists who will say very, very, very precise things after me. As there are a lot of queries and this is done in a very short time, if we have to use this kind of algorithm, it may be a problem in terms of latency, in terms of and it may, in a way, if we are not prepared to that. have a huge impact on the performance of the resolution in the DNS. So we have to get prepared. We have to test this algorithm. We have to test the hardware that can help us to do the math quicker. And maybe we have to think about alternatives if we see that there are huge problems and maybe to end this introduction, why it matters to us is that one way of doing it, and I know that this is a little bit scandalous to say that, but I'm not saying that we are aiming to do that, but one way of doing it, if there are no solutions, if we see that it's going to be a problem, it's going to be very hard. to maintain a certain level of performance with the DNS would be to remove DNSSEC. Because if we remove DNSSEC, we don't have the post -cryptography problem. So that's a very bad thing to say. But I would just say that I've never seen any study on really what has been the effect of the deployment of DNSSEC. I've just seen things or papers saying you have to do it. And papers saying, oh, good, you've done it. And there are this amount of percentage of domain names or zones that are signed. And that's good. Everyone is convinced that it's a very important thing. But I've never seen it. If people in the room have this information, I'm very interested. The reason, for instance, between zones that are signed and zones that are not signed... and the number of men in the middle of attack of this kind that we had in the zone that were not signed compared to the one in the zone that were signed. So when I say that this is an option, I mean, it's a nuclear -bottom option, of course, but this is something that if we are not
Lucien Castex
Thank you very much. Strong statement. So now I understand the session is not about quantum. I'm a bit disappointed, but well. I'll give the floor to Wout. Wout, what can you say about the work and the R &D that has been done in the past few months? Well, is it working? Yes? Okay. I think Joao was going to say more about the work that's been done. I'm going to set a little bit more stage and also tell a little bit about what we've done.
Wout de Natris
So my name is Wout van Atres, from the Netherlands, a board consultant based in the Netherlands, and the coordinator of the Internet Governance Forum, Dynamic Coalition, IS3C, or Internet Standard Security and Safety. And thank you for the kind words that you shared, Pierre. I can say nowadays that we're formally running a very important and important work, and I think that's going to be a very important and important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. earlier this year. Our main goal is to get security -related internet standards and ICT best practices massively deployed, something most of these standards still are not in many parts of the world. Of course, both quantum cryptography standards. Now, we'll be brief about our work, but yes, we've been delivering reports in the past four or five years. We have produced four reports and two toolkits on internet standards deployment and policy. The latest is on PQC and it will be presented later by my colleague Joao Moreno -Focao. On this topic, since we presented the report at the IGF in 2025, we've organized four different workshops of webinars on this. We're at other events presenting on the results and we've seen we've started two working groups, one on DNS and one on RPKI. and both had had their first meeting. But let me start with doing a thought experiment with you. And I'm going to tell you, gentlemen over there, because you may be closest to the microphone, to answer my question in the microphone. I'm doing a thought experiment. Imagine a situation in which an invention would make all locks in the world open simultaneously. Because
Audience Member 1
Family.
Wout de Natris
Family. So, yeah. You'd go home, right? Thank you very much. And I'll come back to you in a moment. So, this is hypothetical, right? There's no way we can open every lock simultaneously every time. But what happens when the first powerful enough quantum computer is active? We don't know by whom. We don't know by what. But all of a sudden, everything digital, the encryption is broken and it's accessible. So where would you go first then? and what would you have to save if your car drives away by itself whatever what would you do then first
Audience Member 2
I'm not sure I'm not sure I would see this as so negative I would say I would stay home I have
Audience Member 3
ok there is a question about energy would it have an impact on energy as well what can you do
Wout de Natris
thank you I think that's the right answer what can you do where do you start do you start with your mother
Audience Member 4
if the phone works I would call Pierre for getting a solution
Wout de Natris
do you know how to get his email thank you thank you so So in other words, this is something that is not happening yet, but we know that the first encryption algorithm is already broken by a quantum computer, although it's very limited in size. That quantum bit is added, makes it more powerful. So fortunately, we still have time to do this, but also we do know that standards deployment is not something which has an extremely good reputation around the world at this moment. So that is something we need to change. And others will tell more about the technical current situation and what steps to take. However, this is not a technical issue. And everybody may think it is, but it's not a technical issue. Why? It's all about convincing those with decision power that they can do this. It is secure. It's about political, economic decision -making and the will to prevent social harm to come to all citizens, customers and end users, be they individuals or organizations. If decision -makers decide positively, the technicians will get the training and they will get the funding they need to deploy the set standards in time. But is this common practice? And was it? The new generation security -related standards like DNSSEC and RPKI and ICT best practices as for example the OWASP top 20 or 25 on websites are at best moderately well adopted to downright dismal. Now this has to change. IS3C is currently preparing for awareness raising and training programs but lacks the structural funding to make this happen at the right scale. to secure the world a digital security and quantum security divide must be prevented it cannot be that the western world is taking care of itself while the rest is not so quantum will most likely bring many positive outcomes in connections with AI and whatever because it will be power that is unleashed for the positive as well but we must first prevent mayhem financial mayhem etc. from happening so we have our work cut out for us but we can't do this in isolation and with me I mean every single stakeholder in this room and beyond this room but only across stakeholder communities and I'll give one example from our past work we've compared IOT policies in our first report we had 21 jurisdictions that we found that had an IOT policy wrote In these 21 jurisdictions, we found 442 best practices that the industry had to adhere to, 442 of which some were totally contradictory. So if you want to do the same with this post -quantum cryptography and advices around it, then industry can never adopt it if you have in every country a different set of rules. And that is what I mean we can't do this in isolation. This has to be coordinated at an ideally global level or at least regional and across stakeholder communities so everybody is clear on the steps. We see in Avnik have decided to start with the domain name and routing sectors, but many, many others will have to follow suit. Just think of IoT devices, devices in cars, whatever you have in your house working on an Internet connection, it all needs to be secured. So I would say if you're interested, join us now. We're here, so just speak to us. And from there, I hand over to Moritz,
Lucien Castex
but first to Lucien, of course. Thank you very much. Thank you, Wout. No transition. I'll give the floor to Moritz and then to our colleague Yao
Moritz Müller-Brus
online. Moritz, you have the floor. Thank you. So I work for SLM. SLM is the registry of DLNL. So we are in a quite similar situation as our colleagues from AFN. Main names, out of which 60 % signed with DNSSEC. So DNSSEC and the future of DNSSEC is close to our heart. But also the RPKI is close to our heart, and you might wonder why this is the case. But, of course, DNS relies also on the routing on the Internet, and therefore the security and reliability of routing is also at our heart, and therefore also RPKI. So we have a transition to post -content crypto at some point in time. I would like to share a bit my view or our view on the current state of protocols to post -quantum crypto where we are currently, where we are currently working on and also what still needs to be done let's start with DNSSEC so we all know that there is some sort of urgency to transition to post -quantum crypto for DNSSEC but of course it's not as urgent as with for example TLS in DNSSEC cryptography is being used for signing and verification which means we do not have the problem of store now, decrypt later so we might still have some time however we know from the experience in the past that transitioning to a new algorithm in DNSSEC does take quite some time we've seen that for classical algorithms so when we start from RSA to elliptic curve cryptography this took at least a decade or so before we got reasonable deployment of this new algorithm But in case of post -contra -crypto, urgency might of course help there. Let's start with the things that are maybe not as good in DNSSEC at the moment. As we've already heard, the post -contra -crypto algorithms are probably not dropped in replacement as they have been with transitioning from RSA to ECDSA, for example. They have larger keys, larger signatures, or maybe both, and therefore transitioning might take even more time if we do not get all behind this transition. Also, currently we're not sure yet which of these post -contra -crypto algorithms might be actually suitable for DNSSEC. Some of them are already standardized, so this might be interesting. They're still not standardized, and so we still have to kind of wait for their standardization. But I think not everything is bad when it comes to transitioning to post -contra -crypto and DNSSEC. today we are better changing algorithms so we have changed algorithms in the past for .nl we have transitioned from RSA to ECDSA and many of the other CCDLDs and TLDs have done so as well we have more automation in place so we are a bit more comfortable with doing these processes in automatic and the roots, so the top of the DNS also has rolled its keys at least once and will roll it again this year but of course it's not rolled over yet but at least we have tested the exchange of the keys so I think this is a good sign and what also makes me personally hopeful is that the community, at least the technical community from my perspective is relatively working on transitioning DNSSEC to post -contra crypto so and I think that's a good sign meetings at the ITF where we have a growing number of participants actively working and presenting and sharing their thoughts on how we can make DNSSEC quantum safe and also at SAN we're quite busy with this so in the past we've did research on the impact of signing algorithms on creating new zone files we've created a test lab for that which you can also access so if you are interested in seeing what the impact might be on a certain post quantum crypto algorithm on your DNS zone then you can test that also we're now looking into the other side so we're looking into the validation side what might be the impact when they would have suddenly have to validate a lot of post quantum crypto algorithms so also here there's already some work going on so what might be the next steps and I think there's I agree with what Wout said so we have to figure out a lot of technical details still but I think but there might not be only technical challenges afterwards. So we have to wait for an algorithm that is suitable and we might then even have to modify the DNS protocol. Also will take time. But when the technical solutions are there, we have to get incentives to deploy these new algorithms as well. Well, as I said, we used financial incentives in the past to motivate the deployment of DNSSEC, but we will also probably need education. We need a feel of urgency for the people who are in charge of this and maybe even legislation, but I'm a bit more careful with this statement. For DNSSEC, I would say I'm slightly positive where we are currently for RPKI, which is the infrastructure, infrastructure that helps us to secure the BGP on the internet. the picture is not as clear yet I would say so compared to DNSSEC RPKI or at least the deployment of RPKI is still relatively new so I have the feeling that the people developing the RPKI protocols they are still more busy with working on and not so much with problems that might appear in the future also there we have never changed an algorithm before so I think there are procedures for that but they still have to be tested at some point in time and we are still just not quite sure yet what actually needs to happen in RPKI to transition to post -contra crypto so overall there is less inertia compared to DNSSEC so I would suggest here a possible next step is to get first of all the technical and maybe similar as we did with DNSSEC to identify the problems that we actually have in RPKI when transitioning to post -contra crypto which are the parts that have to change, which are the parts that have to keep, which are the requirements actually. And we had an intern that did quite some good work on that, but I think now it's the time to take the next steps. So to summarize, I think DNSSEC is further than RPKI, but of course we're
Lucien Castex
Thank you. Moritz, I would like to give the floor online to Jao. Jao, can you hear us? Can you... I'll check with my colleague on the technical side. Is the last speaker connected to the Zoom? I'll check with the Zoom interface.
Jacques Beglinger
you might have any to ask questions if you have or if you have any remarks sure take the mic Sarah hello I'm Jacques Mecklinger I'm from Switzerland head of Swiss IGF etc and my sense is when I look at the fragmentation of the threat of fragmentation of the internet at large due to geopolitics how how close are we to a fragmentation also of these technical standards or in other terms will we end up in the end with a nation standard, with a western standard, with an African standard, things like that, that some kind of competition of standards as we may come closer to even acerbated competition of systems
Lucien Castex
Do we take several questions and then after?
Jimson Olufuye
Okay. Thank you very much. My name is Jim Sinalufuye, a contemporary consultant in Africa, Africa Alliance based in Abuja, Nigeria. This doggo, Pierre, talked about the gap in statistics. Okay, DNSSEC, we have it, but we don't know the effect if we don't have it. don't think it's an important statistics we need to get and shouldn't we ask ICANN to give us that statistics because it's good to know what is going on so that we can really fully justify because we did some roadshow in Lagos some time back I made a lot of mobilization so we should have something to show that yes it's actually quite positive secondly I don't know ICANN should be concerned about this post -quantum too because of the routes and what have you so any idea ICANN is working in that regard thank
Speaker 1
based in Abuja, Nigeria. This dog will appear. Talk about the gap in statistics. That, okay, DNA -seq, we have it, but we don't know the effect if we don't have it. Don't think it's an important statistic we need to get, and shouldn't we ask ICANN to give us that statistic? Because it's good to know what is going on so that we can really fully justify because we did some roadshow in Lagos some time back. I made also a lot of mobilization. So we should have something to show that, yes, it's actually quite positive. Then secondly, I don't know whether ICANN. ICANN should be concerned about this post -quantum too because of the roots servers and what have you. So any idea, ICANN is working? That we got?
Moderator
Thank you. Anybody have questions before? Sure. Since we have time.
Philippe Foucart
I'm with Orange. On a different topic, I was wondering, because Pierre mentioned the fact that, moving forward, DNSSEC may be somewhat redundant with other mechanisms and higher levels. We're hearing that there are also other applications which may not provide that level of security, possibly running on UDP, et cetera, whereby maybe authenticity and integrity of the messages would be required for those applications. I'm thinking about genetic AI, for example. It's still a pie in the sky at the moment. But I'm just wondering whether you also gave some thought about how those future, applications may... and be robust towards change in the security of the DNS, if I'm making sense. Thank you.
Moderator
So, Pierre, do you want to jump in?
Pierre Bonis
Yeah, thank you. Maybe I will leave shortly the question of Philippe to my colleagues because I'm not very sure that I want to answer. And anyway, the answer is going to be partial to each and every question that was asked. As for the fragmentation, thank you very much for the question. I think more it stays that. This is, I mean, this post -quantum cryptography is not only about DNSSEC. It's about other core functions or core. Cryptography challenges that we have. Talking only about the Internet layer, not the other layers. So that might be a question of hardware capacity. So it's not one standard for some country, one other standard for another one. It's how are we able to equip ourselves. And to me, this is a very important question that you raise. It's much bigger than the question of different standards. It may be the question of access to the hardware capacity. And by the way, it's not only about HSM. For instance. Or this kind of hardware. It's about the scarcity, the price rising up, the fact that some AI giants are buying everything, may, at the end of the day, create a problem between, let's say, big Internet players, big registries, big telcos, and smaller ones. And so this is something that we have in mind. And I think that would be useful to have it, because I fear that at one point... people decide to unsign. That's why I said that patient. So I think every statistic that can show the actual utility, the actual pertinence of DNSSEC is worth doing now. And not having said that, if IETF said it, if ICANN said it, it's in the Bible. No. You have to show that we have decided to do something a year ago and we are not able to say to the world we were right to do that. It was useful and we can give evidence. And I think this is a huge problem. And as a on the question of is ICANN preparing itself for this post -consumption cryptography challenge? Yes. But that's very recent. And I remember that with Regis Massé, our CTO, we had a discussion with Octo. It was not a bilateral discussion by the way. It was a public discussion in ICANN. And a few months ago, Octo said, oh, this is not the problem. We will see that later. And 15 days after, they said, oh, this is a huge problem. We are going to... So, I mean, there was a shift. I think on the ICANN and maybe on the IANA function, they are very much concerned, I mean, focused on the rollover and, as I said, on the huge that they have to do this year because there's a lot of And even if people sometimes laugh about it and they say, okay, it takes a lot of time for Yana to do that, but if they fail, it's a huge problem for everyone. So maybe they were very focused on it, but now they realize and they recognize that they have to work on the post -quantum too. So this is good
Wout de Natris
Thank you. University is willing to work, but they all say there's nothing we can do at this point because the message was there is no algorithm in theory about deploying. it. And then I think you got the message wrong because the algorithm will be there and at least you can identify the challenges you're going to run into and have them ready in a roadmap or something. On the RPKI side, the only thing I heard, our members are not discussing it. They're not asking for us to be active. So in other words, there doesn't seem to be an overarching organization at this point in time working on it. This is something which surprises me, but that's just me. But there is a lack of urgency that is missing. There's a lack of urgency because let's face it, somebody could have the eureka moment tomorrow. And of course, nobody can be prepared for tomorrow, whatever we do. But we should be prepared for two years or three years from now because things are going incredibly fast. and I'm not seeing that urgency in most people that I'm talking to, most are looking at somebody else to start the action and that is usually where everybody blames somebody else in the end so I can say that we see the urgency so don't get me wrong but there is a lack of urgency I'll ask again if Joao is there now I can say something about the conclusion in the report but I can't explain what exactly they've done give the floor to Moritz maybe to bump in that and we'll link the report to the session so that everyone can actually access it if needed and the further work that we want to do Moritz
Moritz Müller-Brus
I can answer a bit Philippe's question I guess it's about the size of packets that we might get and that constrained devices might have problems But from my perspective as a researcher, people think about it, but it's definitely not the main concern. So I think there's something that we keep in our minds, but the assumption probably is also that validation is taking place at recursive resolvers, and these recursive resolvers will take care of it, and these constrained devices will then talk to these recursion themselves at all. So I think this is why this topic doesn't have such a high priority, unfortunately.
Peter Koch
Hi there. My name is Peter Koch. I work for DNIC, which is another DNS top -level domain name registry, and I wanted to advertise DNS -ORG as the DNS operator community, where lots of people look into this. When this is about how to do the transport and stuff, there are a lot of incentives to change that anyway for a couple of other very technical reasons that I'm not going into here. But the reason to get to the microphone was inspiring a bit the urgency that Wout mentioned together with geopolitics and competition in algorithms might lead to fragmentation actually when unwise regulation kicks in. And this is because you hadn't mentioned that explicitly, but I think it's very important to understand that this is to be sure. Make sure that the DNS can talk from continent to continent and across all those. So if we have a particular algorithm arising in one place, which is deprecated, say, or banned or something in another place, then obviously. that interoperability will not be there and maybe you can reflect on what your dynamic coalition might have done to make that clear. Thank you.
Wout de Natris
Thank you very much Peter. When you say DINIC is another registry you should say DINIC is the registry. It's not just another one. But short answer. We all know that regulation comes when regulators or legislators first of all discover a problem and but luckily because sometimes there is regulation without a problem and this is a problem discover a problem secondly think that no one cares or no one has taken the good steps to resolve this problem so I would say that focusing on studying testing and implementing post -quantum cryptography solution may prevent bad regulation and if as a community I will see that later then we are in grave danger of having regulation that cannot be a good one because this is still a work in progress so that was my answer thank you we have not looked into that yet because we looked at the policies of 2025 but yes if we have this working group then this should be one of the topics we are discussing quite obviously and I may 442 best practices in 21 different jurisdictions and about the necessity to not isolate ourselves in silos but to talk in a broader sense and that can only happen when you bring in other people and I think from the answers that we have been getting so far people have the tendency to go into their silo and wait for others to act so I think that is what needs to be broken there needs to be a door there needs to be a bridge to the other silo and I think that is something that the Internet Governance Forum could provide and whether this dynamic coalition is able to do that that is going to be an experiment but we doubt in favor of inviting other people to these discussions to prevent exactly what you've been mentioning, Peter. So that's the best answer I can give you at this
Moderator
Thank you, everyone. I think we are at the end of the session.
Pierre Bonis
I was thinking the silos might be very safe for both quantum, you know, in particular on the moon.
Moderator
Thank you, Pierre. Thank you, Moritz. Thank you, Wout. And thank you, everyone, for the questions and the thoughts. We will post on the session page the report that Wout mentioned, as well as obviously on the I3C website and AFNIC as well. Thank you, everyone, and see you around in the WSS.

Avertissement : Il ne s'agit pas d'un compte rendu officiel de la session. DiploAI génère ces ressources à partir d'enregistrements audiovisuels ; elles sont présentées telles quelles, y compris d'éventuelles erreurs. En raison de contraintes logistiques (audio/vidéo ou transcriptions), les noms peuvent être mal orthographiés. Nous nous efforçons d'être aussi précis que possible.