arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

适用于带宽受限或非地面网络以及功率受限设备的实用后量子密码学

Practical Post-Quantum Cryptography for Bandwidth Constrained or Non-Terrestrial Networks, and Power Constrained Devices

Elliot Eichen, Sylvia Llosa, Yueqi Chen, Sangtae Ha

arXiv 2607.23007首次发表:更新:

AI 中文总结

研究针对带宽或功率受限网络中后量子加密认证成本高的问题,提出用共享密钥取代数字证书的加密框架,结合密钥分发中心等技术,相比传统方法减少了相关资源消耗,保留安全特性,适用于多种应用场景。

AI 中文摘要

后量子(PQ)加密算法,尤其是用于认证时,比经典算法更复杂,需要更大的证书、签名和密钥。建立PQ安全网络连接会增加带宽、内存、计算时间和能耗。在非地面网络(NTN)中这些成本尤为严重,类似限制也影响低功耗物联网设备和带宽或能量受限的地面网络。本文研究了一种替代加密框架,用共享密钥(SSK)取代PQ数字证书。该框架利用不依赖非对称密钥分发的共享秘密生态系统,如5G/6G,并将密钥分发中心(KDC)与预共享密钥PQ握手和临时PQ密钥建立相结合。与基于证书的PQ认证相比,该方法减少了握手带宽、端点RAM、计算时间和能源使用,同时保留了PQ安全的AEAD,包括前向保密和抗重放。应用包括基于NTN的密钥轮换和管理、无人机指挥控制系统、嵌入式医疗传感器以及供应链监测和资产跟踪平台。

英文摘要

Post-quantum (PQ) cryptographic algorithms, particularly for authentication, are more complex than classical algorithms and require larger certificates, signatures, and keys. Establishing a PQ-secure network connection increases bandwidth, memory, computation time, and energy consumption. These costs are especially severe in Non-Terrestrial Networks (NTNs), where long propagation delays, intermittent connectivity, constrained link budgets, satellite handovers, limited terminal resources, and bandwidth-constrained satellite-to-ground links amplify the overhead of certificate-based PQ authentication. Consequently, applications such as key rotation and key management may be unable to achieve acceptable handshake reliability or support NIST PQ Security Categories above Category 1. Similar limitations affect low-power IoT devices and bandwidth- or energy-constrained terrestrial networks, where PQ authentication may restrict devices to Category 1 security or prevent ambient-powered endpoints from supporting PQ authentication altogether. This paper investigates an alternative cryptographic framework that replaces PQ digital certificates with shared secret keys (SSKs). The framework leverages shared-secret ecosystems that do not rely on asymmetric key distribution, such as 5G/6G, and combines a Key Distribution Center (KDC) (e.g., Kerberos) with a preshared-key PQ handshake (e.g., DTLS-PSK) and ephemeral PQ key establishment (e.g., ML-KEM). Compared with certificate-based PQ authentication (e.g., ML-DSA), the proposed approach reduces handshake bandwidth, endpoint RAM, computation time, and energy use while preserving PQ-secure AEAD, including forward secrecy and replay resistance. Applications include NTN-based key rotation and management, uncrewed aerial vehicle (UAV) command-and-control systems, embedded medical sensors, and supply-chain monitoring and asset-tracking platforms.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑