Transition to RSA 3072 and Stronger Cryptographic Systems
Organizations and Companies Using Joint Certificates Must Be Ready by March Next Year

Yoonho Lee, Head of the Electronic Signature Certification Management Center at KISA

Yoonho Lee, Head of the Electronic Signature Certification Management Center at KISA

View original image

With a wide range of services—from financial transactions and e-government, to procurement, healthcare, and education—now available online, our daily lives have become even more convenient. For these conveniences to be guaranteed, a robust technological foundation that ensures digital trust must be in place. The joint authentication system is a representative digital infrastructure that has supported secure use and reliability across various sectors of our society and daily lives.


Currently, the electronic signature technology we use is based on public key cryptography such as RSA and ECC, which rely on mathematical principles. To protect cryptographic keys from rapidly evolving attack techniques, it is essential to regularly review cryptographic algorithms and key lengths and make transitions to higher security levels as needed.


The government has provided guidelines for safe cryptographic usage—such as the 'Guide for Cryptographic Algorithms and Key Lengths'—and recently announced the 'Comprehensive National Transition Plan for Post-Quantum Cryptography (PQC)', aiming to address the threats to encryption systems posed by quantum computers.


To ensure a stable electronic signature certification system, domestic and international cryptography policies are requiring a transition: starting in 2031, the use of the RSA 2048 cryptographic key, which corresponds to a security strength of 112 bits, will be restricted, and systems must migrate to cryptographic schemes of at least RSA 3072, providing 128-bit security or higher.


The joint authentication system forms an ecosystem comprising the root certification authority (Root CA), joint certification authorities (CAs), user certificates and modules, and the websites of organizations and companies. Just as the gears of a machine must fit perfectly for the wheels to turn, any single component in the joint authentication system failing to process new certificates correctly can result in failed electronic signatures or verification, causing inconvenience for users of joint certificates.


In response to these changes, the Korea Internet & Security Agency (KISA) has been progressively upgrading the cryptographic keys of the joint authentication system. This began with five joint certification authorities and the root certification authority’s cryptographic key upgrade slated for 2025, and in the first half of this year, the transition of joint certification authority certificates to RSA 3072 was completed. As a result of these efforts, the core issuance infrastructure of the joint authentication system is now equipped to support the new cryptographic environment.


It is now up to institutions and companies using joint certificates to adapt their environments in accordance with the cryptography policy, aligning them with RSA 3072. With the discontinuation of RSA 2048 set for 2031, we have just over four years remaining. While some might argue that there is still ample time, considering that the maximum validity period of subscriber certificates is three years, any subscriber certificate issued after December 31 next year must be based on RSA 3072. This is why the new cryptographic system needs to be operational in real-world service environments roughly three years before the policy goes into effect.


What matters now is ensuring momentum for the transition. Taking this into account, institutions and companies utilizing joint certificates should be prepared to correctly recognize and adopt RSA 3072-based certificates starting in March next year. To support this, KISA is providing the necessary certificate packages for testing through the Integrated Electronic Signature Support Portal.


This transition to RSA 3072 is a process of migrating a complex digital trust ecosystem to a new cryptographic environment without service disruption and serves as an important foundation for an eventual large-scale transition to post-quantum cryptography (PQC). The hourglass marking the upgrade of the joint authentication system has been flipped. The transition to a secure cryptographic system for everyone's online safety must not be delayed.



Yoonho Lee, Head of the Electronic Signature Certification Management Center at KISA


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing