DOI: 10.3390/cryptography10050070 ISSN: 2410-387X

Backward-Compatible Hybrid Post-Quantum Qualified Electronic Signatures: Embedding ML-DSA-65 in PAdES for eIDAS

Rumen Doynov, Maria Nenova, Georgi Todovichin, Alexander Shestakov

Qualified electronic signatures (QES) under eIDAS rely almost exclusively on classical elliptic-curve or RSA algorithms, which a cryptographically relevant quantum computer (CRQC) would break, exposing signed documents to harvest-now-forge-later attacks, yet operators cannot abandon the algorithms that confer legal validity. We present an architecture and implementation for hybrid, QES-shaped PAdES that embeds a FIPS 204 ML-DSA-65 signature as an RFC 9882 CMS SignedData counter-signature in the unsignedAttrs of a classical ECDSA-P256 PAdES signature. Because RFC 5652 excludes unsignedAttrs from the classical signature, an unmodified EU DSS 6.3 validator provisioned with the issuing CA reports TOTAL-PASSED while the post-quantum layer remains independently verifiable; a three-component binding ties the two layers against mix-and-match and transplantation, and an independent validator fails closed if it cannot be reconstructed. On a running deployment we demonstrate DSS validation, tamper detection and PAdES-BASELINE-LTA support: a hundred-run SCAL2 ceremony medians ≈ 270 ms (p95 ≈ 364 ms), a size sweep resolves signing cost into a fixed ≈4.9 ms term plus ≈3.5 ms/MB, and a ten-run paired comparison isolates a ≈229 ms (≈79%) increment, with no size overhead beyond reserved capacity. We map it to eIDAS 2.0, ETSI and CEN and state its limitations, including a software module rather than a certified QSCD.