智能暖通空调系统中后量子网络安全的非侵入式云迁移策略:架构、实现与实证评估
A Non-Invasive Cloud-Based Migration Strategy for Post-Quantum Cybersecurity in Smart HVAC Systems: Architecture, Implementation, and Empirical Evaluation
浏览论文内容
中文总结 AI 辅助
提出一种非侵入式后量子密码学代理,在不改动设备、固件或云的前提下,通过树莓派网关实现ML-KEM和ML-DSA,以应对量子威胁,并验证了其低延迟、高并发及抗侧信道攻击能力。
中文摘要 AI 辅助
传统智能暖通空调控制器依赖由ECDH和RSA保护的供应商云TLS,这两种算法均被Shor算法破解,且典型的10-15年使用寿命意味着当今设备将在量子威胁时代继续服役。直接在设备上实施后量子密码学不可行:以ESP32-S3为例,作为功能较强的暖通空调硬件代表,其仅有339 KB可用堆内存,而ML-KEM-768需要900 KB;此外,经典ECDH-P256密钥生成耗时111.93毫秒,远超硬件AES-128的0.032毫秒。我们提出一种非侵入式后量子密码学代理,无需更改设备、固件或供应商云,执行ML-KEM-768封装和ML-DSA-65认证(NIST FIPS 203/204),并通过HKDF生成AES-256-GCM会话密钥,在树莓派4B网关上使用Open Quantum Safe liboqs实现。在500次运行中,后量子握手(步骤1-6)在2.48毫秒内完成,比经典基线慢0.38毫秒,其中后量子计算约占握手时间的8%(在20毫秒模拟网络往返延迟下)。该网关可维持每秒443个会话,在32个并发连接下成功率100%,外推至32核云实例上可达每秒3546个会话。五项侧信道测试(包括验证的就地会话密钥清零和固定与随机TVLA时序分析)未发现可利用的时序泄漏或对中间人攻击的敏感性。该架构与供应商无关,一旦供应商原生采用NIST后量子标准,该架构便不再必要。
英文摘要
Legacy smart HVAC controllers rely on vendor-cloud TLS secured by ECDH and RSA, both broken by Shor's algorithm, and typical 10-15 year lifespans mean today's devices remain in service through the quantum-threat era. Direct on-device post-quantum cryptography is infeasible: an ESP32-S3, representative of capable HVAC hardware, has only 339 KB free heap against the 900 KB ML-KEM-768 requires, and even classical ECDH-P256 keygen (111.93 ms) dwarfs hardware AES-128 (0.032 ms). We propose a non-invasive PQC proxy, requiring no device, firmware, or vendor-cloud changes, performing ML-KEM-768 encapsulation and ML-DSA-65 authentication (NIST FIPS 203/204) with AES-256-GCM session keys via HKDF, implemented with Open Quantum Safe liboqs on a Raspberry Pi 4B gateway. Over 500 runs, the post-quantum handshake (Steps 1-6) completes in 2.48 ms, 0.38 ms slower than classical baseline, with PQC computation around 8% of handshake time at 20 ms simulated round-trip network latency. The gateway sustains 443 sessions/second, 100% success under 32 concurrent connections, extrapolating to 3546 sessions/second on a 32-core cloud instance. Five side-channel tests, including verified in-place session-key zeroization and a fixed-vs-random TVLA timing analysis, found no exploitable timing leakage or susceptibility to man-in-the-middle attacks. The architecture is vendor-agnostic and becomes unnecessary once vendors adopt NIST PQC natively.
发表机构
- Islamic University of Technology, Gazipur, Bangladesh(伊斯兰理工大学,加济布尔,孟加拉国)
- Laurentian University, Sudbury, ON, Canada(劳伦森大学,萨德伯里,安大略省,加拿大)
- Centennial College, Toronto, ON, Canada(百年理工学院,多伦多,安大略省,加拿大)
机构由 AI 辅助整理,请以论文原文为准。