AI 中文总结
研究后量子迁移中X.509混合证书验证问题,通过对多种验证堆栈、模式和证书方案测量,发现经典路径验证常忽略后量子证据,存在互操作性和绑定问题,贡献了验证器模型和参考合同并分析标准未要求的原因。
AI 中文摘要
依赖方验证混合X.509证书(包含经典和后量子凭证)时,必须区分接受判断是基于后量子证据还是仅基于经典路径。为保持兼容性,可分离设计将证据置于经典路径验证可能忽略之处。验证器可能仅验证经典路径并接受,而后量子证据未影响决策。研究在八个路径验证堆栈、九种验证模式和六种证书方案下进行测量。在混合要求策略下,多数堆栈在经典路径接受而未考虑后量子证据结果;一种强制模式因签名输入编码问题破坏互操作性;验证后量子签名的堆栈默认也未强制绑定。在生命周期不同步时会出现降级情况。研究贡献了规范派生的验证器模型和可执行的策略参数化参考合同,并诊断了标准未要求此操作的原因。
英文摘要
Post-quantum migration relies on hybrid X.509 certificates, which carry post-quantum material alongside the classical so existing verifiers still work. Several designs place it where a verifier may ignore it, so the classical path decides. We tested eight open-source path-validation stacks over seven independent codebases, one in two builds: nine configurations over six certificate profiles. On their default paths, every stack that parsed a separable hybrid certificate accepted it. Invalidating the post-quantum evidence in each separable scheme, leaving the classical evidence valid, changed no verdict in any of the 27 cells: none distinguished sound post-quantum evidence from destroyed. Four stacks verify post-quantum signatures elsewhere on the same path, so immature support does not explain it. Two stacks implement the checks the schemes specify, neither on its default path, and no document defines the interface between them: one carrying a relying party's hybrid requirement, an operational policy, into path validation and reporting which kind of acceptance resulted. We contribute a specification-derived model, this test, and a policy-parametric contract pairing a policy input with a labelled result. Revoking a bound post-quantum certificate changes no verdict in any of the nine configurations, because none consults it; the labelled result makes it visible to operations.
Comments15 pages, 1 figure, 7 tables. Substantially revised manuscript with a management-focused framing, expanded lifecycle analysis, a policy-parametric validation contract, and updated reproducibility materials. Submitted to IEEE Transactions on Network and Service Management