量子就绪的安全广域网:风险评估与迁移框架
Quantum-Ready Secure WAN: A Risk Assessment and Migration Framework
- The university of Southern Mississippi(南密西西比大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对企业广域网量子安全迁移,提出供应商中立框架,分离暴露优先级、迁移就绪性与证据置信度,并设计TLS 1.3和IKEv2/IPsec混合密钥评估,实测p95延迟差异最高达5%。
AI中文摘要:
企业广域网(WAN)使用易受量子攻击的公钥密码学来认证对等体,并为互联网协议安全(IPsec)、传输层安全(TLS)和软件定义广域网服务建立密钥。“先收集,后解密”的攻击方式已经威胁到那些保护寿命可能超过迁移所需时间的数据,而未来一台具备密码学相关能力的量子计算机还将危及证书和其他认证依赖。后量子标准与政府指令现已定义了算法和过渡里程碑,但它们并未告知企业应优先迁移哪些广域网服务,或哪些证据足以支持部署。本文提出一个供应商中立的框架,该框架将暴露优先级、迁移就绪性和证据置信度分离,并将这些输出映射到分阶段的安全、运营和治理门禁。它还定义了在TLS 1.3和IKEv2/IPsec中经典与ML-KEM混合密钥建立的完整评估设计。保留的工件范围较窄:它包含作者报告的聚合TLS p50、p95和p99延迟,在配置的丢包率0%、1%、3%和5%下,一个算术检查器,以及有限的环境和MTU/MSS说明。在这些设置下,TLS-H减去TLS-C的p95差异分别为0.00、0.16、0.38和0.63毫秒,相对于TLS-C对应为0.00%、1.32%、3.07%和5.00%。这些值是描述性的聚合观测结果,而非推断性结果,因为每次试验的数据、样本数量、原始捕获和时间戳日志未被保留。协议大小和MTU/MSS计算与测量行为分开报告,且不支持的IKE、资源、吞吐量、重传和降级结果被排除在外。
英文摘要:
Enterprise wide-area networks (WANs) use quantum-vulnerable public-key cryptography to authenticate peers and establish keys for Internet Protocol Security (IPsec), Transport Layer Security (TLS), and software-defined WAN services. Harvest-now, decrypt-later collection already threatens data whose protection lifetime may exceed the time needed to migrate, while a future cryptographically relevant quantum computer would also endanger certificates and other authentication dependencies. Post-quantum standards and government directives now define algorithms and transition milestones, but they do not tell an enterprise which WAN services to migrate first or what evidence is sufficient for deployment. This paper proposes a vendor-neutral framework that separates exposure priority, migration readiness, and evidence confidence, and maps those outputs to staged security, operational, and governance gates. It also defines a complete evaluation design for classical and ML-KEM hybrid key establishment in TLS 1.3 and IKEv2/IPsec. The retained artifact is narrower: it contains author-reported aggregate TLS p50, p95, and p99 latencies at configured loss settings of 0%, 1%, 3%, and 5%, an arithmetic checker, and limited environment and MTU/MSS notes. At those settings, the TLS-H minus TLS-C p95 differences are 0.00, 0.16, 0.38, and 0.63 ms, corresponding to 0.00%, 1.32%, 3.07%, and 5.00% relative to TLS-C. These values are descriptive aggregate observations, not inferential results, because per-trial data, sample counts, original captures, and timestamped logs were not retained. Protocol-size and MTU/MSS calculations are reported separately from measured behavior, and unsupported IKE, resource, throughput, retransmission, and downgrade outcomes are excluded.