تحسين بروتوكولات أمان الشبكة لعصر الكم: دمج التشفير الكلاسيكي وما بعد الكم، وتوزيع المفاتيح الكمومية
Enhanced Network Security Protocols for the Quantum Era: Combining Classical and Post-Quantum Cryptography, and Quantum Key Distribution

شارك:
المجلة: IEEE Journal on Selected Areas in Communications، المجلد: 43، العدد: 8
DOI: https://doi.org/10.1109/jsac.2025.3568011
تاريخ النشر: 2025-05-13
المؤلف: Carlos Rubio García وآخرون
الموضوع الرئيسي: خوارزميات وهندسة الحوسبة الكمومية

نظرة عامة

ظهور الحوسبة الكمومية يقدم تحديات كبيرة للخوارزميات التشفير التقليدية، مما يستدعي الانتقال نحو تشفير آمن ضد الكم. يقدم هذا البحث بروتوكول أمان هجين جديد يدمج ثلاثة افتراضات تشفيرية متميزة—اثنان منها مقاوم للكم—داخل أطر أمان الشبكات الحالية مثل TLS 1.3 و IPsec. من خلال اشتراط اختراق جميع الافتراضات الثلاثة قبل اعتبار البروتوكول ضعيفاً، يعزز الحل المقترح الأمان ضد كل من التهديدات التقليدية والكمومية. يتم دمج التشفير التقليدي، والتشفير بعد الكم (PQ)، وتوزيع المفاتيح الكمومية (QKD) دون تعديلات كبيرة على البروتوكولات الحالية، مما يضمن المرونة في التشفير ومعالجة التحديات الشائعة المرتبطة بتشفير PQ و QKD.

تشير النتائج إلى أن النهج الهجين يتسبب في تدهور طفيف في الأداء، حيث يعاني مصافحة TLS من تأخير إضافي في الاتصال يبلغ حوالي 57 مللي ثانية، ويرجع ذلك أساساً إلى عمليات استرجاع المفاتيح. في المقابل، تحافظ تنفيذات IPsec على الاتصال الفعال من خلال تنفيذ مفاوضات المفاتيح في مستوى التحكم، مما يسمح بتشفير البيانات بشكل مستقل. تدعم هذه المرونة تكوينات متنوعة—أمان فردي، هجين، أو ثلاثي الهجين—مع ضمان السرية على المدى الطويل والقدرة على الصمود ضد الهجمات القائمة على الكم، مثل “الحصاد الآن، فك التشفير لاحقاً.” بشكل عام، يضع هذا العمل الأساس لأنظمة الاتصالات المستقبلية، مما يجسر الفجوة بين بروتوكولات الأمان الحالية ومشهد ما بعد الكم ويعزز توحيد أنظمة الاتصالات المقاومة للكم الثلاثية الهجينة.

مقدمة

تتناول مقدمة هذه الورقة البحثية الحاجة الملحة لأنظمة الاتصالات المقاومة للكم في ضوء التقدم في الحوسبة الكمومية، خاصة بسبب خوارزمية شور، التي تشكل تهديداً كبيراً لطرق التشفير التقليدية بالمفتاح العام (PKC) مثل RSA وتشفير المنحنيات البيانية. يؤكد المؤلفون على ضرورة الانتقال الاستباقي إلى بدائل مقاومة للكم، حيث إن طرق التشفير الحالية معرضة لهجمات “الحصاد الآن، فك التشفير لاحقاً” (HNDL)، حيث يمكن للخصوم جمع البيانات المشفرة اليوم لفك تشفيرها في المستقبل باستخدام الحواسيب الكمومية. تعمل منظمات مثل NIST و ETSI على تطوير معايير لتشفير ما بعد الكم (PQ) وتوزيع المفاتيح الكمومية (QKD)، والتي تقدم نماذج أمان مختلفة: يعتمد تشفير PQ على مشاكل رياضية مقاومة للهجمات الكمومية، بينما يوفر QKD توزيع مفاتيح آمن من الناحية المعلوماتية.

يقترح المؤلفون حلاً برمجياً جديداً مقاومًا للكم يدمج التشفير التقليدي، وتشفير PQ، و QKD لتوليد مفتاح سري مشترك للتشفير المتماثل، مما يعزز أمان بروتوكولات مثل أمان طبقة النقل (TLS) وأمان بروتوكول الإنترنت (IPsec). يهدف هذا النهج الهجين إلى معالجة الثغرات التي تطرحها الحوسبة الكمومية مع الحفاظ على التوافق مع بروتوكولات أمان الشبكات الحالية. توضح الورقة المساهمات الرئيسية، بما في ذلك أول تنفيذ لحل أمان الشبكة الذي يجمع بسلاسة بين هذه التقنيات التشفيرية، مما يوفر حلولاً جاهزة للاستخدام مقاومة للكم للشبكات الحديثة ويمهد الطريق لتوحيد بروتوكولات الأمان الهجينة في المستقبل. ستتناول الأقسام التالية من المخطوطة متطلبات الأمان للشبكات من الجيل التالي، والانتقال إلى البروتوكولات الهجينة، والتنفيذات التفصيلية للحلول المقترحة.

طرق

في هذه الدراسة، يتضمن الإعداد التجريبي لاختبار تنفيذات TLS 1.3 و IPsec عقدتين لتوزيع المفاتيح الكمومية (QKD) متصلتين عبر الألياف الضوئية في تكوين نقطة إلى نقطة. تتكون كل عقدة QKD من وحدة QKD، ونظام إدارة المفاتيح (KMS)، وتطبيق مقاوم للكم (إما TLS أو IPsec). يتم استضافة هذه التطبيقات في حاويات Docker المعتمدة على Ubuntu (Ubuntu 22.04 LTS) على خوادم منفصلة تتوافق مع كل عقدة QKD. تستخدم وحدات QKD معدات Clavis3 من IDQuantique، التي تعمل باستخدام بروتوكول Coherent One-Way (COW)، وهو طريقة ضمن إطار QKD المتغير المنفصل (DV-QKD) التي تشفر المعلومات في نبضات ضوئية متماسكة تُنقل عبر الألياف الضوئية. يتيح هذا الإعداد تبادل المفاتيح بمعدل مفتاح سري متوسط (SKR) يبلغ 2.5 كيلوبت/ثانية.

لضمان الأمان، يستخدم نظام Clavis3 مبادئ ميكانيكا الكم لضمان توزيع المفاتيح بشكل آمن. يتم تسهيل الاتصال التقليدي بين العقد من خلال مفتاح شبكة، مما يسمح باسترجاع المفاتيح المرسلة عبر القناة الكمومية. تستفيد تطبيقات TLS و IPsec من هذه الأسرار المشتركة الكمومية لتنفيذ تشفير متماثل مقاوم للكم باستخدام AES-256-GCM. تعتمد المكونات البرمجية للنظام على أحدث إصدارات OpenSSL (3.4.0)، و strongSwan (6.0.6)، و Liboqs (0.10.0)، مما يضمن أداءً قويًا وأمانًا في التطبيقات المقاومة للكم.

نتائج

في هذا القسم، يقدم المؤلفون نتائج تحليلهم التجريبي لبروتوكولات TLS 1.3 و IKEv2 المقاومة للكم، مع التركيز على دمج مخططات التشفير الثلاثية الهجينة. يظهر تنفيذ TLS 1.3 تعزيزًا في مقاومة الكم من خلال تفعيل جميع تقنيات مفاوضة المفاتيح—التقليدية، بعد الكم (PQ)، وتوزيع المفاتيح الكمومية (QKD)—على جانب العميل قبل تبادل رسالة عميل مرحب. يقلل هذا النهج من خطر هجمات استنفاد المفاتيح على الخادم ويظهر تأثيرًا ضئيلاً على وقت المصافحة مقارنةً بالتنفيذات السابقة. تشير معايير الأداء إلى أن التركيبات الهجينة من X25519 و ML-KEM-1024 تظهر كفاءة قابلة للمقارنة، مع إدخال QKD لزيادة قدرها حوالي 48 مللي ثانية بسبب تأخيرات استرجاع المفاتيح.

بالنسبة لبروتوكول IKEv2، يحلل المؤلفون مجموعات مختلفة من تبادل المفاتيح، بما في ذلك الطرق التقليدية والهجينة والثلاثية الهجينة. تكشف النتائج أنه بينما تعتبر تكلفة الاتصال عاملاً حاسمًا، فإن دمج التشفير الثلاثي الهجين يعزز الأمان بشكل كبير ضد كل من التهديدات التقليدية والكمومية. يتسبب بروتوكول IKEv2 الثلاثي الهجين المقترح في زيادة إضافية تبلغ حوالي 30 مللي ثانية بسبب استرجاع مفاتيح QKD، ولكن يتم تعويض ذلك من خلال متطلبات النطاق الترددي المنخفض لـ QKD، مما يسمح بالتكامل الفعال مع تبادلات المفاتيح التقليدية. يستنتج المؤلفون أنه بينما يتم الشعور بتأثير الأداء بشكل أساسي في مستوى التحكم، فإن مستوى البيانات يبقى غير متأثر، مما يضمن تجربة مستخدم سلسة. يُقترح العمل المستقبلي لمزيد من تحسين خوارزميات PQ ودمجها في بروتوكولات الاتصالات الآمنة.

نقاش

يسلط النقاش الضوء على الحاجة الملحة للانتقال من أنظمة الاتصالات التقليدية إلى أنظمة مقاومة للكم بسبب الثغرات التي تطرحها الحوسبة الكمومية، خاصة من خلال خوارزميات مثل شور وغروفر. تعتبر طرق التشفير التقليدية، التي تعتمد على التشفير بالمفتاح العام غير المتماثل (PKC) والتشفير المتماثل، معرضة للخطر حيث يمكن للخوارزميات الكمومية حل مشاكل معقدة مثل تحليل الأعداد الصحيحة واللوغاريتمات المنفصلة في وقت متعدد الحدود، مما يقوض أمانها. تؤكد الورقة على ضرورة اعتماد بروتوكولات مقاومة للكم، وخاصة تشفير ما بعد الكم (PQ) وتوزيع المفاتيح الكمومية (QKD)، لحماية البيانات أثناء النقل. ومع ذلك، لا تزال التحديات قائمة، بما في ذلك نضج خوارزميات PQ وقيود QKD، مثل التوازن بين معدل توليد المفاتيح السرية والمسافة المرسلة.

لمعالجة هذه التحديات، يقترح المؤلفون إطار أمان ثلاثي الهجين يدمج التشفير التقليدي، وتشفير PQ، و QKD. يهدف هذا النهج إلى تعزيز قدرة أنظمة الاتصالات على الصمود ضد التهديدات الكمومية مع ضمان المرونة في التشفير، مما يسمح بالاستبدال السريع للمكونات التشفيرية استجابةً للثغرات الناشئة. توضح الورقة متطلبات البنية التحتية لنشر مثل هذه الحلول الهجينة، موضحةً المكونات المادية والبرمجية اللازمة لمفاوضة المفاتيح الفعالة والاتصال الآمن. من خلال الاستفادة من نقاط القوة في كل طريقة تشفير، يهدف الإطار المقترح إلى توفير أمان قوي ضد التهديدات الحالية والمستقبلية من الحوسبة الكمومية، مما يضمن سلامة وسرية الاتصالات الرقمية.

Journal: IEEE Journal on Selected Areas in Communications, Volume: 43, Issue: 8
DOI: https://doi.org/10.1109/jsac.2025.3568011
Publication Date: 2025-05-13
Author(s): Carlos Rubio García et al.
Primary Topic: Quantum Computing Algorithms and Architecture

Overview

The emergence of quantum computing presents significant challenges to classical cryptographic algorithms, prompting a transition towards quantum secure cryptography. This research introduces a novel hybrid security protocol that integrates three distinct cryptographic assumptions—two of which are quantum-resistant—into existing network security frameworks such as TLS 1.3 and IPsec. By requiring the compromise of all three assumptions before the protocol is deemed vulnerable, the proposed solution enhances security against both classical and quantum threats. The integration of classical cryptography, post-quantum (PQ) cryptography, and quantum key distribution (QKD) is achieved without major modifications to existing protocols, thereby ensuring crypto-agility and addressing common challenges associated with PQ cryptography and QKD.

The findings indicate that the hybrid approach incurs minimal performance degradation, with the TLS handshake experiencing an additional communication delay of approximately 57 ms, primarily due to key retrieval processes. In contrast, the IPsec implementation maintains efficient communication by executing key negotiations at the control plane, allowing data encryption to proceed independently. This flexibility supports various configurations—single, hybrid, or triple-hybrid security—while ensuring long-term confidentiality and resilience against quantum-based attacks, such as “harvest now, decrypt later.” Overall, this work lays the groundwork for future-proof communication systems, bridging current security protocols with the post-quantum landscape and promoting the standardization of triple-hybrid quantum-resistant communication systems.

Introduction

The introduction of this research paper addresses the urgent need for quantum-resistant communication systems in light of advancements in quantum computing, particularly due to Shor’s algorithm, which poses a significant threat to traditional public key cryptography (PKC) methods such as RSA and elliptic curve cryptography. The authors emphasize the necessity for a proactive transition to quantum-resistant alternatives, as current encryption methods are vulnerable to “harvest now, decrypt later” (HNDL) attacks, where adversaries can collect encrypted data today for future decryption using quantum computers. Organizations like NIST and ETSI are actively developing standards for post-quantum (PQ) cryptography and quantum key distribution (QKD), which offer different security paradigms: PQ cryptography relies on mathematical problems resistant to quantum attacks, while QKD provides information-theoretically secure key distribution.

The authors propose a novel quantum-resistant software solution that integrates classical cryptography, PQ cryptography, and QKD to generate a shared secret key for symmetric encryption, enhancing the security of protocols like Transport Layer Security (TLS) and Internet Protocol Security (IPsec). This hybrid approach aims to address the vulnerabilities posed by quantum computing while maintaining compatibility with existing network security protocols. The paper outlines the main contributions, including the first implementation of a network security solution that seamlessly combines these cryptographic techniques, providing ready-to-use quantum-resistant solutions for modern networks and paving the way for future standardization of hybrid security protocols. The subsequent sections of the manuscript will elaborate on the security requirements for next-generation networks, the transition to hybrid protocols, and detailed implementations of the proposed solutions.

Methods

In this study, the experimental setup for testing TLS 1.3 and IPsec implementations involves two Quantum Key Distribution (QKD) nodes connected via optical fibers in a point-to-point configuration. Each QKD node comprises a QKD module, a Key Management System (KMS), and a quantum-resistant application (either TLS or IPsec). These applications are hosted in Ubuntu-based Docker containers (Ubuntu 22.04 LTS) on separate servers corresponding to each QKD node. The QKD modules utilize Clavis3 equipment from IDQuantique, which operates using the Coherent One-Way (COW) protocol, a method within the discrete-variable QKD (DV-QKD) framework that encodes information in coherent light pulses transmitted through optical fibers. This setup enables key exchange at an average secret key rate (SKR) of 2.5 kbit/s.

For security, the Clavis3 system employs quantum mechanics principles to ensure secure key distribution. The classical communication between the nodes is facilitated through a network switch, allowing the retrieval of keys transmitted over the quantum channel. The TLS and IPsec applications leverage these quantum-shared secrets to implement quantum-resistant symmetric encryption using AES-256-GCM. The software components of the system are based on the latest versions of OpenSSL (3.4.0), strongSwan (6.0.6), and Liboqs (0.10.0), ensuring robust performance and security in the quantum-resistant applications.

Results

In this section, the authors present the results of their experimental analysis of quantum-resistant TLS 1.3 and IKEv2 protocols, emphasizing the integration of triple-hybrid cryptographic schemes. The TLS 1.3 implementation demonstrates enhanced quantum-resiliency by triggering all key negotiation techniques—classical, post-quantum (PQ), and quantum key distribution (QKD)—at the client’s side before the client hello message is exchanged. This approach mitigates the risk of key exhaustion attacks on the server and shows minimal impact on handshake time compared to previous implementations. Performance benchmarks indicate that the hybrid combinations of X25519 and ML-KEM-1024 exhibit comparable efficiency, with QKD introducing an overhead of approximately 48 ms due to key retrieval delays.

For the IKEv2 protocol, the authors analyze various key exchange combinations, including classical, hybrid, and triple-hybrid methods. The results reveal that while the communication cost is a critical factor, the integration of triple-hybrid encryption significantly enhances security against both classical and quantum threats. The proposed triple-hybrid IKEv2 protocol incurs an additional overhead of about 30 ms due to QKD key retrieval, but this is offset by the low bandwidth requirements of QKD, which allows for efficient integration with classical key exchanges. The authors conclude that while the performance impact is primarily felt in the control plane, the data plane remains unaffected, ensuring seamless user experience. Future work is suggested to further optimize PQ algorithms and their integration into secure communication protocols.

Discussion

The discussion highlights the urgent need for transitioning from classical to quantum-resistant communication systems due to the vulnerabilities posed by quantum computing, particularly through algorithms like Shor’s and Grover’s. Classical cryptographic methods, which rely on asymmetric public key cryptography (PKC) and symmetric encryption, are at risk as quantum algorithms can solve complex problems such as integer factorization and discrete logarithms in polynomial time, undermining their security. The paper emphasizes the necessity of adopting quantum-resistant protocols, particularly Post-Quantum (PQ) cryptography and Quantum Key Distribution (QKD), to safeguard data in transit. However, challenges remain, including the maturity of PQ algorithms and the limitations of QKD, such as the trade-off between secret key generation rate and transmission distance.

To address these challenges, the authors propose a triple-hybrid security framework that integrates classical cryptography, PQ cryptography, and QKD. This approach aims to enhance the resilience of communication systems against quantum threats while ensuring crypto-agility, allowing for the swift replacement of cryptographic components in response to emerging vulnerabilities. The paper outlines the infrastructure requirements for deploying such hybrid solutions, detailing the necessary hardware and software components for effective key negotiation and secure communication. By leveraging the strengths of each cryptographic method, the proposed framework aims to provide robust security against both current and future quantum computing threats, ensuring the integrity and confidentiality of digital communications.

شارك: