Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMs
Keitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom Wiggers
Abstract
WireGuard is a VPN based on the Noise protocol, known for its high performance, small code base, and unique security features. Recently, Hülsing et al. (IEEE S&P'21) presented post-quantum (PQ) WireGuard, replacing the Diffie-Hellman (DH) key exchange underlying the Noise protocol with key-encapsulation mechanisms (KEMs). Since WireGuard requires the handshake message to fit in one UDP packet of size roughly 1200 B, they combined Classic McEliece and a modified variant of Saber. However, as Classic McEliece public keys are notoriously large, this comes at the cost of severely increasing the server's memory requirement. This hinders deployment, especially in environments with constraints on memory (allocation), such as a kernel-level implementations.
In this work, we revisit PQ WireGuard and improve it on three fronts: design, (computational) security, and efficiency. As KEMs are semantically but not syntactically the same as DH key exchange, there are many (in hindsight) ad-hoc design choices being made, further amplified by the recent finding on the binding issues with PQ KEMs (Cremers et al., CCS'24). We redesign PQ WireGuard addressing these issues, and prove it secure in a new computational model by fixing and capturing new security features that were not modeled by Hülsing et al. We further propose reinforced KEM (RKEM) as a natural building block for key exchange protocols, enabling a PQ WireGuard construction where the server no longer needs to store Classical McEliece keys, reducing public key memory by 190 to 390×. In essence, we construct a RKEM named Rebar to compress two ML-KEM-like ciphertexts which may be of an independent interest.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f408c98-2253-4760-8ad6-82912133e157Builds on15
- WireGuard: Next Generation Kernel Network TunnelJason A. DonenfeldNDSS 2017 · 259 citations
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 162 citations
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber et al.S&P 2021 · 73 citations
- Threshold Raccoon: Practical Threshold Signatures from Standard Lattice AssumptionsRafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem et al.EUROCRYPT 2024 · 61 citations
- Toward Practical Lattice-Based Proof of Knowledge from Hint-MLWEDuhyeong Kim, Dongwon Lee, Jinyeong Seo, Yongsoo SongCRYPTO 2023 · 47 citations
Related papers
- A Tale of Two Worlds, a Formal Story of WireGuard HybridizationPascal Lafourcade, Dhekra Mahmoud, Sylvain Ruhault, Abdul Rahman TalebUSENIX Security 2025
- A Unified Symbolic Analysis of WireGuardPascal Lafourcade, Dhekra Mahmoud, Sylvain RuhaultNDSS 2024
- CuKEM: A Concise and Unified Hybrid Key Encapsulation MechanismYiting Liu, Biming Zhou, Haodong JiangCCS 2025
- ExpressPQDelivery: Toward Efficient and Immediately Deployable Post-Quantum Key Delivery for Web-of-ThingsJane Kim, Jung-Hun Kang, Hyunwoo Lee, Seung-Hyun SeoWWW 2025 · 1 citation
- Post-Quantum Private Set Intersection for Small SetsJunxin Liu, Mike Rosulek, Ni TrieuCCS 2026
