AI 中文总结
本文针对在线银行加密协议安全问题及量子计算威胁,设计实现基于 DW-HKEM 和实时加密分析仪表板的集成系统,结合 RSA-256 与 ML-KEM-768,经测试总开销约 1.5ms,证明架构可行,为金融领域后量子时代加密应用提供参考。
AI 中文摘要
面向公众网络上的在线银行和金融服务数量不断增加,导致加密协议安全成为严重的系统性问题。RSA-2048 是日常互联网交易中多数使用的密钥长度。存在如“先收集、后解密”(HNDL)这样的威胁范式。量子计算对当前公钥加密基础设施构成威胁且日益临近。本文设计、实现并测试了基于双封装混合密钥封装机制(DW-HKEM)和实时加密分析仪表板的集成系统。DW-HKEM 框架内包含 RSA-256 和 ML-KEM-768,用基于 SHA-256 的密钥派生函数创建复合密钥,实现对经典和量子对手的组合安全及与现有银行系统的向后兼容。CryptoX 实时仪表板提供操作时间跟踪等功能。100 次独立迭代的实证基准测试结果显示总开销约 1.58ms,证明该架构可作为金融部门加密基础设施和应用向后量子时代迁移的实用、可扩展参考,还提供了完整源代码。
英文摘要
The increasing number of online banking and financial services on public-facing networks has caused security of cryptographic protocols to become a serious, systemic problem. RSA-2048 is the key length that is used in the majority of transactions that travel over the Internet every day. A very insidious threat vector, the Harvest Now, Decrypt Later (HNDL) paradigm, is already in existence with the adversarial nation-state actors and well-funded threat actors. The exposure window is not a time in the future it is the NOW moment! Quantum computation is a certain threat to the current public-key cryptographic infrastructure, and one that is moving ever closer. In this paper, the authors take up both of these challenges, designing, implementing and testing an integrated system based on a Dual-Wrap Hybrid Key Encapsulation Mechanism (DW-HKEM) and a live cryptographic analytics dashboard. Both the RSA-256 and ML-KEM-768 are hosted within the DW-HKEM framework and an AES-256 session key is wrapped in each of them, with a composite key created using a Key Derivation Function based on SHA-256, resulting in combinatorial security against classical and quantum adversaries and backwards compatibility with existing banking systems. The CryptoX real-time dashboard offers time tracking for each operation, session-level analytics and visualization of performance trends for immediate use in enterprise banking security operations. The results from empirical benchmarking across 100 independent iterations show a total overhead of about 1.58ms, which is well within the enterprise deployment threshold, proving the architecture viable as a practical, scalable reference for the financial-sector's cryptographic infrastructure and applications to move to a post-quantum era. We also provide complete source code of the work carried out.