发表机构
Ho Chi Minh City Open University; Faculty of Information Technology, Ho Chi Minh City University of Industry and Trade (HUIT); Faculty of Information Technology, Ho Chi Minh City Open University; Faculty of Computer Science and Engineering, Ho Chi Minh City University of Technology (HCMUT); Vietnam National University Ho Chi Minh City(胡志明市开放大学; 胡志明市工业贸易大学信息技术学院; 胡志明市开放大学信息技术学院; 胡志明市理工大学计算机科学与工程系; 越南国家大学胡志明市分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
HPQ-AKE是面向带宽受限IoT与边缘网络的无签名混合认证密钥交换协议,结合ML-KEM-768与RSA-OAEP,可减少56.4%握手传输量,降低31.4%卫星链路延迟,性能优于混合TLS 1.3。
AI 中文摘要
在量子后迁移期间,保障带宽受限的物联网(IoT)与边缘网络安全会产生一种认证权衡:ML-KEM提供量子后密钥建立,而量子后签名则会增加证书链大小、验证成本和握手延迟。本文提出HPQ-AKE,一种面向支持RSA的IoT网关与边缘/云服务的无签名混合认证密钥交换协议,其用双密钥封装机制(KEM)替代转录签名。HPQ-AKE结合ML-KEM-768实现量子后会话保密性与前向保密性,结合RSA-OAEP实现隐式双向认证,在迁移期间保留现有支持RSA的基础设施。我们在扩展的Bellare-Rogaway模型中分析HPQ-AKE,将随机预言模型中的经典认证与量子随机预言模型中的会话密钥保密性分离。在模块学习误差(Module-LWE)和RSA假设下,该协议在仅长期密钥暴露假设下实现认证密钥交换(AKE)安全性、前向保密性和条件密钥妥协冒充(KCI)抗性。评估结合x86微基准测试、分析延迟建模和10000次迭代的蒙特卡洛模拟。HPQ-AKE将建模的握手传输量从13009字节减少至5668字节,较混合TLS 1.3完整握手减少56.4%,同时在被测x86测试平台上仅需7.11毫秒的总本地计算时间。在模拟的50kbps类卫星链路(600毫秒往返时间(RTT)和随机抖动)下,中位延迟为1914毫秒,较2791毫秒的基线降低31.4%;在20毫秒RTT下,建模的收支平衡点为:相对于预缓存基线为0.31Mbps,相对于完整基线为4.08Mbps,且两者均随RTT增加而降低。这些基于x86的结果为在网关级IoT与边缘平台上的评估提供了动力,但其在ARM网关和未加速微控制器上的性能仍未验证。
英文摘要
Securing bandwidth-constrained Internet of Things (IoT) and edge networks during post-quantum migration creates an authentication trade-off: ML-KEM provides post-quantum key establishment, whereas post-quantum signatures increase certificate-chain size, verification cost, and handshake latency. We present HPQ-AKE, a sign-less hybrid authenticated key exchange for RSA-enabled IoT gateways and edge/cloud services that replaces transcript signatures with dual KEMs. HPQ-AKE combines ML-KEM-768 for post-quantum session secrecy and forward secrecy with RSA-OAEP for implicit mutual authentication, preserving existing RSA-enabled infrastructure during migration. We analyze HPQ-AKE in an extended Bellare-Rogaway model, separating classical authentication in the Random Oracle Model from session-key secrecy in the Quantum Random Oracle Model. Under the Module-LWE and RSA assumptions, it establishes AKE security, forward secrecy, and conditional KCI resistance under the long-term-key-only exposure assumptions. Evaluation combines x86 micro-benchmarking, analytical latency modeling, and 10,000-iteration Monte Carlo simulation. HPQ-AKE reduces modeled handshake transmission from 13,009 to 5,668 Bytes, a 56.4% reduction relative to a Hybrid TLS 1.3 Full handshake, while requiring 7.11 ms of total local computation on the measured x86 testbed. Under a simulated 50 kbps satellite-like link with 600 ms RTT and stochastic jitter, median latency is 1,914 ms, 31.4% below the 2,791 ms baseline. At 20 ms RTT, modeled break-even thresholds are 0.31 Mbps against the pre-cached baseline and 4.08 Mbps against the full baseline; both decrease as RTT increases. These x86-based results motivate evaluation on gateway-class IoT and edge platforms; performance on ARM gateways and unaccelerated microcontrollers remains unvalidated.
CommentsAccepted for publication in High-Confidence Computing (Elsevier), October 2026. Author-accepted manuscript