arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

在后量子认证成本下通过信任边界与委托优化凭证爆炸半径

Optimizing Credential Blast Radius Through Trust Boundaries and Delegation Under Post-Quantum Authentication Costs

Pauli Taipale, Harri Lainio

arXiv 2609.04566首次发表:更新:

AI 中文总结

该研究针对后量子认证成本下的凭证爆炸半径问题,通过联合优化信任域与凭证派生结构,在延迟预算内降低了预期影响,优于先选边界的方法。

AI 中文摘要

将交互服务划分为独立根信任域可限制签发者泄露的影响范围,但会增加跨信任边界的调用。后量子公钥认证与密钥交换机制的替换会增加受限或有损路径的跨边界延迟。我们在策略与延迟约束下,对信任域与凭证派生结构的联合选择进行建模,通过域分配将独立的服务交互图与凭证派生图关联起来。凭证爆炸半径衡量泄露后的加权服务影响,线性上界支持优化,联合事件模型给出精确的预期影响。对于共享签发者,该上界在凭证范围不重叠时是精确的,否则需要显式传播。尽管该通用问题是NP难的,但标量化双域直接签发可简化为加权最小割。在230次详尽合成比较中,联合优化比先选择边界的方法在195次中实现了更低的爆炸半径,尤其在链式委托场景下表现突出。实验使用轨迹推导的重放、实测后量子成本、合成风险输入、固定派生族及1至6个信任域。在延迟预算内,最优设计相对于单域将预期影响降低了36%。该框架将风险假设与实测跨边界成本转化为候选信任域与凭证派生设计。

英文摘要

Partitioning interacting services into independently rooted trust domains limits issuer-compromise reach while increasing calls across trust boundaries. Post-quantum replacements for public-key authentication and key-establishment mechanisms can increase crossing latency on constrained or lossy paths. We formulate the joint selection of trust domains and credential-derivation structures under policy and latency constraints, linking separate service-interaction and credential-derivation graphs through domain assignment. Credential blast radius measures weighted service impact after compromise. A linear upper bound supports optimization, while a joint event model gives exact expected impact. We identify when risk from issuers trusted across domains can be incorporated into this linear score, avoiding separate issuer-propagation calculations for each candidate. Although the general problem is NP-hard, we identify restricted cases that can be solved efficiently and exactly. Joint optimization yields lower blast radius than choosing boundaries first in 195 of 230 exhaustive synthetic comparisons, especially under chained delegation. A trace-derived replay used measured post-quantum costs, synthetic risk inputs, a fixed derivation family, and one to six trust domains. Under independent compromise events, mean expected impact was up to 36% lower than with one domain within the latency budget. The framework turns risk assumptions and measured crossing costs into candidate trust-domain and credential-derivation designs.

Comments10 pages, 4 figures, supplementary material included

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑