发表机构
IRT SystemX(系统X研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对WebPKI后量子认证的上下文问题,提出LR+双平面构造,通过实验验证其在依赖项大小和状态存储上的优势,为WebPKI后量子迁移提供更优方案。
AI 中文摘要
后量子迁移增加了WebPKI认证的成本,但仅对压缩证书对象进行认证本身并不能保留依赖方接受该证书的可变授权上下文。我们将「上下文封闭」形式化:验证方接受的认证投影必须确定其声称的选定授权语义,该语义相对于声明的源契约和事件覆盖见证。我们用LR+(一种双平面后量子构造)实例化这一思路,该构造在更新平面中认证可变的CA上下文状态,而热路径仅携带通过显式配置文件协商选定的状态局部依赖引用。在固定的CCADB重建中,我们获得了Apple、Chrome、Microsoft和Mozilla视图下的44912条路径/视图上下文和16858个物理CA谱系。核心编译器产生m₅₀=6、m₉₅=16和mₘₐₓ=18个类型化依赖。因此,热LR+选择器在中位数、p95和最大值时的成本分别为296、776和872字节,而携带相同依赖向量的单签名无状态束的成本分别为3842、5932和6350字节。保留的全视图封闭状态为16.15 MB,在所述检查点和更新模型下,每视图生命周期交叉的中位数路径热认证/天范围为19.60至50.41。实现和评估工件可在该https URL获取。
英文摘要
Post-quantum migration increases WebPKI authentication cost, but authenticating a compressed certificate object does not by itself preserve the mutable authorization context under which a relying party accepts it. We formalize \emph{context closure}: the authenticated projection accepted by a verifier must determine the selected authorization semantics it claims, relative to declared source contracts and event-coverage witnesses. We instantiate this idea with \LRp, a two-plane post-quantum construction that authenticates mutable CA-context state in an update plane while the warm path carries only state-local dependency references selected by explicit profile negotiation. In a pinned CCADB reconstruction, we obtain 44,912 path/view contexts and 16,858 physical CA lineages across Apple, Chrome, Microsoft, and Mozilla views. The core compiler yields $m_{50}=6$, $m_{95}=16$, and $m_{\max}=18$ typed dependencies. A warm LR+ selector therefore costs 296, 776, and 872 bytes at median, p95, and maximum, compared with 3,842, 5,932, and 6,350 bytes for a one-signature stateless bundle carrying the same dependency vector. The retained all-view closure state is 16.15 MB, and per-view lifecycle crossovers range from 19.60 to 50.41 median-path warm authentications/day under the stated checkpoint and update model. The implementation and evaluation artifact are available at https://github.com/nserser/LR-WebPKI