News

Signal begins its post-quantum messaging transition with PQXDH

Signal has announced PQXDH, an upgraded key-agreement specification that adds post-quantum protection while retaining its existing cryptographic foundation.

Smartphones and radio-testing equipment on an editorial desk
Product claims are checked against official documentation and clearly attributed.

Signal announced on September 19, 2023, that it had taken the first step toward making its messaging protocol more resistant to quantum attacks. The change upgrades the X3DH specification under the name PQXDH and is designed for a future quantum computer powerful enough to break current encryption standards.

How PQXDH combines two systems

Signal selected CRYSTALS-Kyber as the post-quantum key-encapsulation mechanism for the updated specification. PQXDH calculates a shared secret with both X25519 and CRYSTALS-Kyber, then combines the two resulting secrets.

That combination defines Signal’s stated security goal: an attacker would need to break both cryptographic systems to obtain the same shared secret. The approach therefore adds a post-quantum component without removing the elliptic-curve cryptography already used by Signal.

PQXDH is an additive update rather than a wholesale replacement of the existing design. X25519 remains part of the protocol, while CRYSTALS-Kyber supplies the additional protection intended for a future quantum threat.

The rollout depends on both people updating

The latest versions of Signal’s client applications already support PQXDH when a conversation is started and both participants are using the latest software. The new protocol is therefore conditional at the beginning of a conversation: both ends need compatible, up-to-date clients for it to apply under the conditions Signal described.

Signal also said it planned to disable X3DH for new conversations in the following months, after giving users time to update, and require PQXDH for those conversations. It planned parallel updates to move existing conversations toward the new protocol as well.

The announcement did not provide a precise cutoff date. It described the change as a transition over the coming months, so the timing depended on the software update process rather than on a single date announced for every user.

A first layer in a longer migration

Signal’s protocol provides cryptographic specifications for end-to-end encryption in private communications exchanged daily by billions of people. Published in 2013, it has also been adopted beyond the Signal app. That wider use gives a change to the specification significance beyond one client, although the immediate support described in the announcement concerns Signal’s latest applications.

The protection addresses a future capability and is not presented as a complete answer to every quantum threat. Signal said additional work would still be needed against an attacker with a contemporary quantum computer. PQXDH is consequently an initial layer in a longer migration, with the near-term change focused on new conversations and the software transition required to support them.

For Signal users, the practical change is the protocol used to establish conversation secrets, not a newly announced messaging feature. Users need current software, and the other participant must also be running a compatible version when the conversation begins.

PQXDH places Signal at the start of its post-quantum transition while preserving X25519 in the combined design. Its rollout improves the protocol’s preparation for a future quantum attack, but the announcement also makes clear that the migration is ongoing and that further work remains.

Official sources

Official source: signal.org

Related reading

Guides

Reviews

Sources and evidence

Official source: signal.org (opens in a new tab)