Inhaltsverzeichnis

5.1 PQ Security for Developers

Post-Quantum Cryptography in the Data Gateway.

Architecture

[Client + PQ Certificate]
        | TLS 1.3 (ML-KEM)
[Proxy :443]
        | Named Pipe
[Data Gateway API]
        |
[Database]

Zero Trust Model

Certificate Hierarchy

Type Purpose Validity
Root CA Trust anchor 10+ years
Intermediate CA Signing 2-5 years
Client Certificate Authentication 1 year
Ephemeral Certificate Session key Minutes

Further Reading