<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blog on CE Labs</title><link>https://celabs.eu/blog/</link><description>Recent content in Blog on CE Labs</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 31 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://celabs.eu/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Post-Quantum HPKE</title><link>https://celabs.eu/blog/pq-hpke/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://celabs.eu/blog/pq-hpke/</guid><description>&lt;p&gt;The IETF is working on &lt;a href="https://datatracker.ietf.org/doc/html/draft-ietf-hpke-pq-05" target="_blank" rel="noopener noreferrer"&gt;post-quantum security for HPKE&lt;/a&gt;
,
the scheme used in protocols like TLS ECH, MLS, and Oblivious HTTP.
We&amp;rsquo;ve implemented the draft: it runs today in hpke-rs, part of &lt;a href="https://github.com/celabshq/libcrux" target="_blank" rel="noopener noreferrer"&gt;libcrux&lt;/a&gt;
, and
you can try it live in the demo further down this post.
This post covers what changes on the way to post-quantum HPKE, and why the
transition may not be a drop-in.&lt;/p&gt;</description></item><item><title>Check Your Post-Quantum Readiness</title><link>https://celabs.eu/blog/pq-readiness-check/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>https://celabs.eu/blog/pq-readiness-check/</guid><description>&lt;p&gt;The post-quantum transition is no longer a future concern.
Browsers and cloud providers are negotiating post-quantum key exchange by default
for a while now, using the NIST standardized algorithms.
The &lt;em&gt;harvest-now, decrypt-later&lt;/em&gt; threat means data captured today can be broken
once a cryptographically relevant quantum computer exists.
None of this is new, but the timelines keep moving closer:
&lt;a href="https://arxiv.org/html/2505.15917v1" target="_blank" rel="noopener noreferrer"&gt;Google&amp;rsquo;s estimates&lt;/a&gt;

for the resources needed to break classical cryptography have dropped sharply, and the
&lt;a href="https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Quantentechnologien-und-Post-Quanten-Kryptografie/quantentechnologien-und-post-quanten-kryptografie_node.html" target="_blank" rel="noopener noreferrer"&gt;BSI&lt;/a&gt;

continues to urge organizations to start migrating now.
The practical question for most teams is simple: &lt;strong&gt;where do we actually stand right now?&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Announcing CE Labs</title><link>https://celabs.eu/blog/ce-labs-announcement/</link><pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate><guid>https://celabs.eu/blog/ce-labs-announcement/</guid><description>&lt;p&gt;Today we&amp;rsquo;re launching CE Labs, focused on high-assurance security engineering, spun off from &lt;a href="https://cryspen.com" target="_blank" rel="noopener noreferrer"&gt;Cryspen&lt;/a&gt;
. The new independence lets both teams pursue their missions with greater agility: Cryspen continues its work on verification products and the &lt;a href="https://cryspen.com/spectrum" target="_blank" rel="noopener noreferrer"&gt;Spectrum EIC Grant initiative&lt;/a&gt;
, while we concentrate on designing and building systems that are secure from the cryptography up. This is just the start — we&amp;rsquo;ve got exciting projects underway and plenty to share, so expect more from us here soon.&lt;/p&gt;</description></item><item><title>Pushing the Boundaries of PQC for IoT</title><link>https://celabs.eu/blog/iot-pqc-06-2025/</link><pubDate>Wed, 02 Jul 2025 00:00:00 +0000</pubDate><guid>https://celabs.eu/blog/iot-pqc-06-2025/</guid><description>&lt;p&gt;We&amp;rsquo;re dedicated to bringing robust, next-generation cryptography to even the most resource-constrained devices. One direction of ongoing work has focused heavily on implementing and optimizing the NIST-standardized post-quantum cryptographic algorithms, ML-KEM (formerly Kyber) and ML-DSA (formerly Dilithium), along with the SHA-3 hash function, specifically for the Internet of Things (IoT) ecosystem. All of our technical work and results are open source and available on our &lt;a href="https://github.com/cryspen/libcrux-iot/" target="_blank" rel="noopener noreferrer"&gt;Github repository&lt;/a&gt;
.&lt;/p&gt;</description></item><item><title>High Assurance Post-Quantum Cryptography for IoT</title><link>https://celabs.eu/blog/iot-pqc-announce/</link><pubDate>Mon, 05 Aug 2024 00:00:00 +0000</pubDate><guid>https://celabs.eu/blog/iot-pqc-announce/</guid><description>&lt;p&gt;We extend the &lt;a href="https://github.com/cryspen/libcrux" target="_blank" rel="noopener noreferrer"&gt;libcrux&lt;/a&gt;
 cryptographic library with support for resource constrained IoT devices.
The libcrux-iot library contains high performance, high assurance implementations of post-quantum, as well as classical, cryptographic primitives.&lt;/p&gt;</description></item></channel></rss>