I am exploring how quantum-security claims can be turned into reproducible and independently verifiable evidence.
My focus is not simply on whether a system uses Post-Quantum Cryptography (PQC), Quantum Key Distribution (QKD), or other quantum-security technologies.
The question I am interested in is:
When someone claims that a system is quantum-safe, what can an independent third party actually verify from the available evidence?
QSP Public Verification Portal:
https://github.com/mokkunsuzuki-code/qsp
I am building QSP, an open verification project exploring:
- Post-Quantum Cryptography (PQC)
- Cryptographic Agility
- PQC Migration Evidence
- Cross-Implementation Verification
- Independent Re-verification
- Evidence Portability
- Cryptographic Binding
- QKD Evidence Classification
- Software Supply Chain Integrity
- External Timestamp Evidence
- Independent Assessment
Do not trust a quantum-security claim beyond what its evidence can independently demonstrate.
QSP distinguishes between:
Claimed → Evidenced → Verified → Independently Re-verified
and explicitly records states such as:
Not Verified · Pending · Unknown · Out of Scope
The project does not claim that an entire system is quantum-safe merely because PQC or another quantum-security technology has been implemented.
My current work focuses on reproducible evidence chains for post-quantum security, including cryptographic binding, deterministic verification, cross-implementation interoperability, evidence preservation, and independent third-party verification.
I welcome technical review, reproducibility testing, criticism, and independent verification.