面向多文件云存储的基于承诺的混合后量子密码模型
A Commitment-Based Hybrid Post-Quantum Cryptographic Model for Multi-File Cloud Storage
浏览论文内容
中文总结 AI 辅助
该研究针对多文件云存储的后量子认证瓶颈,提出基于承诺的混合后量子密码模型,大幅降低了多文件上传的签名阶段时间开销。
中文摘要 AI 辅助
云存储客户端日益需要能抵御未来量子能力敌手的认证机制,这推动了结合经典原语与标准化后量子替代方案的混合构造。若将此类构造直接扩展至多文件上传,会产生每个文件的格签名开销,该开销会主导认证时间,且在实际批处理规模下变得难以承受。本文提出一种基于承诺的混合后量子模型以解决此瓶颈,其包含AES-256-GCM bulk加密、混合X25519与ML-KEM-768密钥封装机制,以及基于SHA3-256批量承诺计算的混合Ed25519与ML-DSA-65双签名。该承诺将一批次中所有密文绑定为单个固定大小的摘要,仅需签名一次,使每批次的后量子签名调用次数从n降至1,与批次规模无关;剩余加密与哈希操作受限于快速对称吞吐量。在普通客户端平台上,经20次重复取平均,当批次增大时,该模型的签名阶段时间保持接近恒定,而基于每个文件的基线则呈线性扩展。当n=1000时,与共享每一个原语的每个文件双签名基线相比,该模型在100 KB、1 MB、10 MB文件的签名阶段时间分别减少629倍、606倍、725倍。
英文摘要
Cloud storage clients increasingly require authentication that remains secure against future quantum-capable adversaries, motivating hybrid constructions that combine classical primitives with standardized post-quantum alternatives. Extended naively to multi-file upload, such constructions incur a per-file lattice signing cost that dominates authentication time and becomes prohibitive at realistic batch sizes. This paper presents a commitment-based hybrid post-quantum model that addresses this bottleneck. It comprises AES-256-GCM bulk encryption, a hybrid X25519 with ML-KEM-768 key encapsulation mechanism, and a hybrid Ed25519 with ML-DSA-65 dual signature, computed over a SHA3-256 batch commitment. The commitment binds all ciphertexts in a batch to a single fixed-size digest that is signed once, reducing the number of post-quantum signature invocations per batch from n to one, independent of batch size; the remaining encryption and hashing is bounded by fast symmetric throughput. On a commodity client platform, averaged over 20 repetitions, this holds signing-phase time near-constant as the batch grows while the per-file baseline scales linearly. At n = 1000, the model reduces signing-phase time by factors of 629, 606, and 725 for 100 KB, 1 MB, and 10 MB files respectively, against a per-file dual-signing baseline sharing every other primitive.