Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMs
Keitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom Wiggers
摘要
WireGuard is a VPN based on the Noise protocol, known for its high performance, small code base, and unique security features. Recently, Hülsing et al. (IEEE S&P'21) presented post-quantum (PQ) WireGuard, replacing the Diffie-Hellman (DH) key exchange underlying the Noise protocol with key-encapsulation mechanisms (KEMs). Since WireGuard requires the handshake message to fit in one UDP packet of size roughly 1200 B, they combined Classic McEliece and a modified variant of Saber. However, as Classic McEliece public keys are notoriously large, this comes at the cost of severely increasing the server's memory requirement. This hinders deployment, especially in environments with constraints on memory (allocation), such as a kernel-level implementations.
In this work, we revisit PQ WireGuard and improve it on three fronts: design, (computational) security, and efficiency. As KEMs are semantically but not syntactically the same as DH key exchange, there are many (in hindsight) ad-hoc design choices being made, further amplified by the recent finding on the binding issues with PQ KEMs (Cremers et al., CCS'24). We redesign PQ WireGuard addressing these issues, and prove it secure in a new computational model by fixing and capturing new security features that were not modeled by Hülsing et al. We further propose reinforced KEM (RKEM) as a natural building block for key exchange protocols, enabling a PQ WireGuard construction where the server no longer needs to store Classical McEliece keys, reducing public key memory by 190 to 390×. In essence, we construct a RKEM named Rebar to compress two ML-KEM-like ciphertexts which may be of an independent interest.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper15
- WireGuard: Next Generation Kernel Network TunnelJason A. DonenfeldNDSS 2017 · 被引用 259 次
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 被引用 162 次
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber 等S&P 2021 · 被引用 73 次
- Threshold Raccoon: Practical Threshold Signatures from Standard Lattice AssumptionsRafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem 等EUROCRYPT 2024 · 被引用 61 次
- Toward Practical Lattice-Based Proof of Knowledge from Hint-MLWEDuhyeong Kim, Dongwon Lee, Jinyeong Seo, Yongsoo SongCRYPTO 2023 · 被引用 47 次
相关 Paper
- A Tale of Two Worlds, a Formal Story of WireGuard HybridizationPascal Lafourcade, Dhekra Mahmoud, Sylvain Ruhault, Abdul Rahman TalebUSENIX Security 2025
- A Unified Symbolic Analysis of WireGuardPascal Lafourcade, Dhekra Mahmoud, Sylvain RuhaultNDSS 2024
- CuKEM: A Concise and Unified Hybrid Key Encapsulation MechanismYiting Liu, Biming Zhou, Haodong JiangCCS 2025
- ExpressPQDelivery: Toward Efficient and Immediately Deployable Post-Quantum Key Delivery for Web-of-ThingsJane Kim, Jung-Hun Kang, Hyunwoo Lee, Seung-Hyun SeoWWW 2025 · 被引用 1 次
- Post-Quantum Private Set Intersection for Small SetsJunxin Liu, Mike Rosulek, Ni TrieuCCS 2026
