Skip to content
Open access

FINGERTRAP: A Self-Defending Cryptographic Protocol for Network Communications

Aug 2026 · Electronics · Vol 15, pp. 3690 · 0 citations · 12 references

TL;DR

The full protocol is described, game-based security arguments under an explicit adversarial model are provided, analytic cost estimates for the friction mechanism are given, the denial-of-service surface and a two-layer mitigation strategy are analysed, and a post-quantum extension is specified using hybrid X25519/ML-KEM-768 ratcheting.

Abstract

Fingertrap is a network encryption and authentication protocol that extends the X3DH and Double Ratchet frameworks with three novel mechanisms inspired by the Chinese finger trap (zhĭ wăng): a friction ratchet that exponentially increases computational cost for each failed authentication attempt; a recursive annihilation protocol that irreversibly destroys all cryptographic state after a configurable failure threshold; and a commit-then-challenge handshake that requires a counterintuitive “inward” action for legitimate authentication. A bidirectional weave hash extends the Double Ratchet’s transcript binding to cover every message in both directions. Together, these mechanisms provide per-message forward secrecy, post-compromise security (self-healing), clock-free operation, and a self-destruct capability. The individual ingredients-client puzzles, key erasure, and ratcheting-each build on established lines of work; their combination into a single stateful protocol, in which failed authentication attempts cryptographically tighten the session state and ultimately destroy it, is not to our knowledge offered by deployed transport protocols such as TLS 1.3, Signal, or WireGuard. The design targets deployments in which interception or capture of a device implies endpoint compromise, such as Unmanned Aerial Vehicle (UAV) telemetry links and body-worn sensors, where denial of exploitation requires guaranteed loss of past and future session material. We describe the full protocol, provide game-based security arguments under an explicit adversarial model, give analytic cost estimates for the friction mechanism, analyse the denial-of-service surface and a two-layer mitigation strategy, and specify a post-quantum extension using hybrid X25519/ML-KEM-768 ratcheting.

Read PDF

Similar papers

SUST Journal of Science and Technology

A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.

A. K. M. Fakhrul Hossain, Article Info · 0 citations
Open access Aug 2026

Quantum-Resistant Diffie-Hellman Key Exchange Protocol

The necessity of a secure key exchange protocol arises from the critical need to establish encrypted communication over an untrusted network. Over time, a multitude of key exchange mechanisms have been developed to counteract adversarial threats. The Diffie-Hellman key exchange protocol (DHKE) is one of the most widely used protocols for symmetric key sharing. However, this protocol exhibits certain inherent limitations that attackers may exploit. It lacks authentication mechanism and is susceptible to Man-in-the-Middle (MITM) attacks and quantum attacks. To mitigate these vulnerabilities, we have designed a hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive. This proposed protocol provides authentication via a Public Key Infrastructure (PKI) together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats. We have done a security analysis using the Dolev-Yao threat model, extended to quantum-equipped attackers, and showed that the protocol achieves mutual authentication, session key secrecy, and forward secrecy under the hardness of LWE and DHKE. Lastly, we provided detailed parameter recommendations based on NIST standards and shed light on side-channel attacks.

A. K. M. Fakhrul Hossain · 0 citations
Open access Aug 2026

Migrating to Hybrid Cryptography in Practice: The TutaCrypt Protocol and Its Security

This work presents the hybrid key establishment protocol TutaCrypt in a form that enables rigorous cryptographic analysis and defines two Bellare–Rogaway-style security models that precisely characterize the provided security guarantees.

Christian Holler, Tibor Jager, Tom Neuschulten · 0 citations
Open access Jul 2026

Lightweight Anonymous Group Authentication and Quantum-Cloud Key Distribution Based on PUF for Classical Network Environments

Performance evaluations demonstrate that the proposed lightweight anonymous group authentication scheme outperforms existing comparable schemes in terms of computational cost, communication overhead, and dynamic group management efficiency, demonstrating its potential for resource-constrained IoT environments, pending further validation on real hardware platforms.

Huanjie Zhang, Yang Chen, Shenghao Chen et al. · 0 citations
Open access Jul 2026

LISHARK: Lightweight Side Channel Protected Secure Hardware Extension with Re-keying

The Secure Hardware Extension (SHE) provides crucial functionalities such as error-detection, authorization, and authentication of messages exchanged between Electronic Control Units (ECUs) over the Controller Area Network (CAN) bus with the help of Advanced Encryption Standard (AES) cryptographic cores. However, the security guarantees of SHE can be entirely compromised if an adversary with physical access to the vehicle extracts the secret key using power or electromagnetic side-channel measurements. While countermeasures like Threshold Implementation (TI) and Domain-Oriented Masking (DOM) offer robust protection, they are impractical for SHE due to the stringent resource constraints and real-time safety requirements of automotive systems. To address this critical vulnerability, this article explores the concept of re-keying, utilizing two rounds of AES hardware as a lightweight key derivation function. This approach eliminates the need for additional key exchanges between the sender and receiver. Our experimental results, supported by theoretical analysis, indicate that re-keying every 10 encryptions provides a practical and secure solution that limits the effectiveness of side-channel attacks; leakage analysis performed on over 1,000,000 electromagnetic (EM) traces for this configuration revealed no detectable leakage. These findings are supported by real-world side-channel attack experiments conducted on a prototype implemented on the Cora-Z7 platform, built on Xilinx’s Zynq-7000 system featuring a single or dual-core 667 MHz ARM Cortex-A9 processor and Artix-7 FPGA. The proposed lightweight architecture, named LISHARK, maintains the same area footprint as a standalone AES core, making it significantly more efficient compared to TI and DOM. Measurements show that when integrated with the Secure Onboard Communication (SecOC) protocol, the design achieves end-to-end message authentication in approximately 90 microseconds, well within the industry-standard threshold of 10 milliseconds.

Soumi Chatterjee, Siddhartha Chowdhury, Urbi Chatterjee et al. · 0 citations
Conference Jul 2026

Mitigating Sybil Attacks in V2X Communication Through Cryptographic Trust Anchors

Vehicle-to-Everything (V2X) communication enables vehicles to exchange safety-critical messages, but its reliance on temporary pseudonymous identities makes it vulnerable to Sybil attacks, where a single attacker fabricates multiple identities to inject false information into the network. This paper presents a lightweight cryptographic mechanism that combines SHA-256 Proof-of-Work token mining with a time-windowed ratecontrol layer to limit the number of new identities a vehicle can activate within a given interval. The mechanism was implemented in Java and evaluated through a parametric simulation across three independent variables: PoW difficulty, rate limit, and attack intensity. Results show that a difficulty of 4 and a rate limit of 5 tokens per 10-second window provide an effective balance between Sybil resistance and legitimate vehicle access in an 8-vehicle scenario, with an average mining time of 0.227 seconds. The evaluation identifies the rate-control layer as the primary security mechanism, while PoW difficulty increases the computational cost per identity without independently capping accepted tokens. The proposed approach is infrastructure-free and suitable for regulated V2X deployments where attackers represent a minority of the network.

Maher Fayyad, Abdullah Awad, Edison Pignaton De Freitas et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.