arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于后量子ACVP测试向量跨实现评估的可复现性协议

A Reproducibility Protocol for Cross-Implementation Evaluation of Post-Quantum ACVP Test Vectors

Christopher M. Frost

arXiv 2608.13784首次发表:更新:

AI 中文总结

本研究提出了一种后量子ACVP测试向量跨实现评估的可复现性协议,通过实验验证了三个ML-KEM实现的一致性,揭示了公共ML-KEM包的测试表面差异,未观察到独立外部复现。

AI 中文摘要

密码学标准的独立实现应能复现相同的已知答案结果,但只有当语料库、修订版本、公共接口、排除项和证据都被精确说明时,这种一致性才有意义。本研究针对NIST ML-KEM的三个公共实现,定义了一种与产品无关的可复现性协议,用于针对固定的公共自动密码验证协议(Automated Cryptographic Validation Protocol,ACVP)语料库进行评估。协议v2冻结了特定于提供者的能力,对称应用了一种验证错误分类法,保留了所有选定的案例,并区分了字节、验证结果、不支持的操作和适配器错误。基于源代码构建的实验评估了@noble/post-quantum 0.7.0、liboqs 0.16.0和Go 1.26.4。在三次重复实验中,所需的笛卡尔积包含2160个基础记录:所有1650个已声明的可执行评估都与NIST预言机匹配,所有510个不支持的记录都与Go预先声明的能力边界匹配。在每个可执行重叠上的成对一致性是完全的:720个noble-liboqs记录中的720个,以及每个Go配对的210个记录中的210个。一个单独的keyGen-ek投影诊断匹配了所有150个Go封装密钥投影,且未将它们计为完整的密钥生成。三个冻结的控制分别测试了字节比较、结果比较和畸形响应错误分离;每个都产生了其确切的预先声明结果。没有出现基础失败、适配器错误或状态不稳定的情况。这些证据确立了有限的作者运行可复现性,并揭示了一个实际的标准缺口:公共ML-KEM包提供了实质上不同的确定性和验证测试表面。独立的外部复现仍未被观察到。这些结果并未确立认证、详尽的正确性、侧信道抗性、安全集成或生产保证。

英文摘要

Independent implementations of a cryptographic standard should reproduce the same known-answer results, yet agreement is meaningful only when the corpus, revisions, public interfaces, exclusions, and evidence are precisely stated. This study defines a product-neutral reproducibility protocol for three public implementations of NIST ML-KEM against a pinned public Automated Cryptographic Validation Protocol corpus. Protocol v2 freezes provider-specific capabilities, applies one validation-error taxonomy symmetrically, preserves every selected case, and separates bytes, validation verdicts, unsupported operations, and adapter errors. The source-built experiment evaluated @noble/post-quantum 0.7.0, liboqs 0.16.0, and Go 1.26.4. Across three repetitions, the required Cartesian product comprised 2,160 base records: all 1,650 declared executable evaluations matched the NIST oracle, and all 510 unsupported records matched Go's predeclared capability boundary. Pairwise agreement was complete on every executable overlap: 720 of 720 noble-liboqs records and 210 of 210 records for each Go pairing. A separate keyGen-ek-projection diagnostic matched all 150 Go encapsulation-key projections without counting them as full key generation. Three frozen controls independently exercised byte comparison, verdict comparison, and malformed-response error separation; each produced its exact predeclared outcome. No base failure, adapter error, or status instability occurred. The evidence establishes bounded author-run repeatability and exposes a practical standards gap: public ML-KEM packages provide materially different deterministic and validation-test surfaces. Independent external reproduction remains unobserved. The results do not establish certification, exhaustive correctness, side-channel resistance, secure integration, or production assurance.

Comments16 pages, 4 figures, 9 tables, 28 references. Research artifact: https://doi.org/10.5281/zenodo.21910571

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑