arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

转录本绑定组合器用于抗降级混合后量子密钥建立:定义、证明与嵌入式设备成本

Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment: Definition, Proof, and Embedded-Device Cost

Bhanwar Gupta, Sanjeev Rana

arXiv 2609.21273首次发表:更新:

发表机构

Maharishi Markandeshwar (Deemed to be University)(玛哈里希·马尔坎德什瓦尔(视为大学))

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文定义并证明转录本绑定组合器可使降级韧性成为局部属性,阻止主动剥离后量子选项,且嵌入式成本仅增加一次哈希(约11.8%计算、1.5%能耗)。

AI 中文摘要

混合密钥建立将后量子密钥封装机制(KEM)与经典Diffie-Hellman原语并行运行,使得当任一组件抵抗攻击时,会话密钥仍保持安全。该设计现已标准化于传输层安全协议、安全外壳和互联网密钥交换中,以后量子组件采用标准化的模块格KEM(ML-KEM)。混合KEM保护派生密钥,但不保护选择使用哪些原语的协商完整性。完整协议通过握手转录本对协商进行认证;作为独立即插即用原语部署的混合KEM,或在没有转录本认证的最小握手中部署的混合KEM,不继承此类保证,主动攻击者可剥离后量子选项。我们询问密钥调度单独必须包含什么,以使降级韧性成为组合器的局部属性。我们在组合器层给出基于博弈的定义,并证明一个双向分离:忽略转录本的组合器必然被降级,而将会话密钥和确认标签绑定到转录本哈希的组合器阻止每一次此类尝试,其概率可忽略不计(对于256位转录本哈希)。我们还给出一个显式的最强链路安全界。使用由已发布的Cortex-M4测量值组成的校准成本模型,转录本绑定为每方增加一次哈希——约占握手计算量的11.8%,但仅占包含无线电的能耗的1.5%——且不增加线上的消息或字节。报告的每个数字均由通过30次检查验证门的已发布硬件产生。

英文摘要

Hybrid key establishment runs a post-quantum key-encapsulation mechanism (KEM) alongside a classical Diffie-Hellman primitive, so that the session key stays secure while either component resists attack. This design is now standardized in the Transport Layer Security protocol, Secure Shell, and the Internet Key Exchange, with the standardized module-lattice KEM (ML-KEM) as the post-quantum component. A hybrid KEM secures the derived key, but not the integrity of the negotiation that selects which primitives are used. Full protocols authenticate that negotiation through a handshake transcript; a hybrid KEM deployed as a standalone drop-in primitive, or inside a minimal handshake without transcript authentication, inherits no such guarantee, and an active attacker can strip the post-quantum option. We ask what the key schedule alone must contain to make downgrade resilience a local property of the combiner. We give a game-based definition at the combiner layer and prove a two-sided separation: a combiner that ignores the transcript is downgraded with certainty, whereas one that binds the session key and the confirmation tag to a hash of the transcript blocks every such attempt, up to a term negligible for a 256-bit transcript hash. We also give an explicit strongest-link security bound. Using a calibrated cost model composed from published Cortex-M4 measurements, transcript binding adds one hash per party - about 11.8% of handshake computation but only 1.5% of radio-inclusive energy - and adds no messages or bytes on the wire. Every reported number is produced by a released harness that passes a 30-check validation gate.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑