KEMTLCP is proposed, a post-quantum secure variant of TLCP that leverages key encapsulation mechanisms (KEMs) for both key exchange and authentication while preserving TLCP’s architectural principles through a novel explicit authentication mechanism.
Abstract
Transport Layer Cryptography Protocol (TLCP) is a secure communication protocol developed in China, featuring a dual-certificate architecture and incorporating ShangMi cryptographic algorithms. It has been widely deployed in security-critical domains such as finance, government, and energy. Despite its practical significance, TLCP did not undergo comprehensive formal analysis during its standardization process, leaving potential design-level vulnerabilities insufficiently explored. Moreover, the advent of quantum computing poses fundamental challenges to the classical cryptographic primitives employed by TLCP, motivating the need for both systematic security evaluation and post-quantum enhancements. To address these gaps, we first construct the comprehensive formal model of TLCP, covering certificate-based and identity-based cipher suites as well as its distinctive dual-certificate mechanism, under a realistic threat model and security assumptions that capture both classical and quantum adversaries. Based on this model, we conduct an automated security analysis using ProVerif, identifying nine potential attack vectors and deriving five concrete mitigation recommendations. Finally, motivated by the analysis results and the limitations of incremental fixes against quantum threats, we propose KEMTLCP, a post-quantum secure variant of TLCP that leverages key encapsulation mechanisms (KEMs) for both key exchange and authentication while preserving TLCP’s architectural principles through a novel explicit authentication mechanism. We further provide a security proof for the core authentication mechanism, show that KEMTLCP effectively mitigates the majority of identified vulnerabilities through formal analysis, and evaluate its practical performance.
With the rapid advancement of quantum computing, classical cryptographic protocols face an increasing risk of being broken. The Post-Quantum OpenPGP (PQ OpenPGP) protocol is an extension of the OpenPGP standard that incorporates hybrid cryptography by combining a classical key exchange and a post-quantum key encapsulation mechanism. This design aims to provide long-term security even in the presence of adversaries equipped with quantum computational capabilities and ensures backward compatibility while transitioning safely to the quantum era. This article presents a formal specification and verification of the PQ OpenPGP protocol using the algebraic specification language CafeOBJ. Our specification captures key aspects of the protocol, including hybrid key encapsulation using post-quantum Module-Lattice Key Encapsulation Mechanism (ML-KEM) and classical Elliptic Curve Diffie–Hellman (ECDH)-KEM, dual digital signatures using post-quantum Module-Lattice Digital Signature Algorithm (ML-DSA) and classical Edwards-curve Digital Signature Algorithm (EdDSA). To model adversarial behavior, we extend the standard Dolev-Yao intruder model, widely used in the analysis of security protocols, by incorporating quantum-enabled capabilities. Under our threat model, the intruder not only has full control over the network, as in the traditional Dolev-Yao setting, but is also capable of breaking classical public-key cryptographic primitives and compromising sensitive information, reflecting the realistic power of large-scale quantum computers. We successfully verify that the PQ OpenPGP protocol satisfies three essential security properties: secrecy of the session key, forward secrecy, and authenticity. The proofs are supported by ten auxiliary lemmas. Given the formal specification, security properties, and conjecture lemmas, the Invariant Proof Score Generator (IPSG) tool automatically generates proof scores to facilitate verification. This work contributes to the growing research on formal verification in post-quantum cryptographic protocols.
Trong Binh Hoang, Duong Dinh Tran, Canh Minh Do et al.· PeerJ Computer Science· 0 citations
: The security of traditional public key cryptosystems like RSA and ECDSA is at risk due to the rapid development of quantum computing technology. Therefore, developing new cryptographic algorithms with the ability to resist quantum attacks has become a common goal for both academia and industry. This paper systematically outlines the current major Post-Quantum Cryptography (PQC) technology routes, including digital signature schemes based on lattice theory, coding theory, equations of multiple variables and hash functions, and elaborately analyzes the core principles and implementation paths of these technologies. In addition, this paper looks forward to the development trends of post-quantum cryptography from multiple dimensions, such as technological evolution, standard setting and industrial practice, and emphasizes the importance of early deployment of quantum-resistant cryptography systems. Although there are still many technical bottlenecks in the practical application of quantum computers, to ensure future network security, it is necessary to accelerate the strategic upgrade of the post-quantum cryptography system, build a multi-level security defense line through the collaborative deployment of PQC technology and existing classical cryptography systems, and provide forward-looking security guarantees for critical infrastructure in the digital age.
Qirui Luo· Proceedings of the 3rd Inter...· 0 citations
Quantum computing offers major computational advances but threatens modern public-key cryptography. Classical algorithms such as RSA, Diffie–Hellman (DH), and Elliptic Curve Cryptography (ECC) are vulnerable to quantum attacks, particularly Shor’s algorithm. As large-scale quantum capabilities emerge, post-quantum cryptography (PQC) has become essential to ensure future data confidentiality, integrity, and authentication. This paper discusses the need to replace classical cryptography, explores quantum-safe solutions, and examines challenges in large-scale migration. PQC is critical across government, critical infrastructure, finance, healthcare, telecommunications, IoT, autonomous vehicles, and 6G networks. A key concern is “harvest-now, decrypt-later” attacks, where encrypted data is stored today for future quantum decryption. The study analyzes classical cryptographic vulnerabilities and reviews major PQC families: lattice-based, hash-based, code-based, multivariate-based, and isogeny-based schemes, highlighting the ongoing NIST standardization efforts. It proposes a migration framework including quantum-readiness assessment, algorithm selection, hybrid implementation, and performance evaluation. Results show that although PQC introduces higher computational complexity, optimized implementations can support real-time applications with reasonable overhead. Among PQC approaches, lattice-based schemes appear most mature and balanced in terms of security and key size. The paper concludes that quantum-safe cryptography is a necessary evolution requiring continuous monitoring, adaptable systems, and alignment with emerging standards.
Noah Wright, Isabella Moore· International Journal of Mod...· 0 citations
The introduction of quantum computers is moving fast and one issue that should nt be overlooked is that they would be capable of breaking modern cryptographic systems easily. This scenario is likely to become real because with the help of Shor's algorithm they could break the only widely used public-key systems (e.g. RSA and ECC) which would mean that the security of internet communications,digital signaturesand sensitive stored data could be compromised. Even if post-quantum cryptography (PQC) is the right direction of development, there are many problems with it like low performance, complex implementation plans, complicated migration approaches and uncertain security eventually. This paper highlights the risk that quantum computers pose to current encryptions and gives an overview of the top PQC solutions that have been standardized by NIST. It also pinpoints the main problems that are still unsolved and offers practical strategies for mitigating the risk in this area. Based on an extensive review of literature and a computational experiment on hybrid key exchange, the article points out that hybrid approaches are the most efficient ones, cryptographic agility is necessary, and migration should be phased, these measures are aimed at making the transition to the post-quantum era safe and smooth.
Bhanu Pratap Singh· International Journal of Adv...· 0 citations
In the rapidly evolving landscape of cybersecurity, traditional cryptographic systems are increasingly vulnerable to attacks, including brute-force, side-channel, man-in-the-middle, replay, and ransomware attacks, highlight the limitations of classical encryption techniques. Quantum cryptography leverages the no-cloning theorem and the properties of quantum states to establish fundamentally secure communication protocols with intrinsic eavesdropping detection capabilities. This security framework provides information-theoretic protection beyond the mathematical assumptions underlying conventional cryptographic systems. Quantum image security has evolved into two major paradigms: Quantum Key Distribution (QKD) and Quantum Secure Direct Communication (QSDC). Although recent surveys have reviewed both approaches chronologically, they have not systematically analysed their security thresholds The objective of this paper proposes a three-axis taxonomy of QSDC protocols, classifying them by quantum resource type, physical transmission channel, and device trust model. Furthermore, it presents a comparative performance analysis of QKD employing a hyperchaotic cipher over QSDC channels across seven quantum image representations, including FRQI, NEQR, GQIR, and MCQI. The analysis shows that QKD-seeded schemes achieve efficient key distribution, whereas pixel-level security remains dependent on cipher complexity. In contrast, QSDC provides end-to-end security governed by quantum mechanical principles; hyperentangled carriers achieve an eavesdropping detection probability of 0.875 compared with 0.5 for conventional two-step protocols, although communication throughput remains a limiting factor. Based on these findings, this review outlines future research directions, including QSDC-specific quantum repeaters for continental-scale deployment, hyperentangled carriers supporting up to 12 bits per photon pair compatible with NEQR’s 8-bit encoding, and machine-learning-assisted management of hybrid fiber–free-space quantum communication networks.
S. Deepika, N. Jeyanthi· Frontiers of Physics· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.