Time-Based State-Management of Hash-Based Signature CAs for VPN-Authentication

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Herzinger, Daniel, Heise, Linus, Loebenberger, Daniel, Söllner, Matthias
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912587540594688
author Herzinger, Daniel
Heise, Linus
Loebenberger, Daniel
Söllner, Matthias
author_facet Herzinger, Daniel
Heise, Linus
Loebenberger, Daniel
Söllner, Matthias
contents Advances in quantum computing necessitate migrating the entire technology stack to post-quantum cryptography. This includes IPsec-based VPN connection authentication. Although there is an RFC draft for post-quantum authentication in this setting, the draft does not consider (stateful) hash-based signatures despite their small signature size and trusted long-term security. We propose a design with time-based state-management that assigns VPN devices a certificate authority (CA) based on the hash-based signature scheme XMSS. The CA then issues leaf certificates which are based on classical cryptography but have a short validity time, e. g., four hours. It is to be expected that even large quantum computers will take significantly longer to break the cryptography, making the design quantum-secure. We propose strategies to make the timekeeping more resilient to faults and tampering, as well as strategies to recognize a wrong system time, minimize its potential damage, and quickly recover. The result is an OpenBSD implementation of a quantum-safe and, regarding the leaf certificates, highly flexible VPN authentication design that requires significantly less bandwidth and computational resources compared to existing alternatives.
format Preprint
id arxiv_https___arxiv_org_abs_2509_11695
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Time-Based State-Management of Hash-Based Signature CAs for VPN-Authentication
Herzinger, Daniel
Heise, Linus
Loebenberger, Daniel
Söllner, Matthias
Cryptography and Security
Advances in quantum computing necessitate migrating the entire technology stack to post-quantum cryptography. This includes IPsec-based VPN connection authentication. Although there is an RFC draft for post-quantum authentication in this setting, the draft does not consider (stateful) hash-based signatures despite their small signature size and trusted long-term security. We propose a design with time-based state-management that assigns VPN devices a certificate authority (CA) based on the hash-based signature scheme XMSS. The CA then issues leaf certificates which are based on classical cryptography but have a short validity time, e. g., four hours. It is to be expected that even large quantum computers will take significantly longer to break the cryptography, making the design quantum-secure. We propose strategies to make the timekeeping more resilient to faults and tampering, as well as strategies to recognize a wrong system time, minimize its potential damage, and quickly recover. The result is an OpenBSD implementation of a quantum-safe and, regarding the leaf certificates, highly flexible VPN authentication design that requires significantly less bandwidth and computational resources compared to existing alternatives.
title Time-Based State-Management of Hash-Based Signature CAs for VPN-Authentication
topic Cryptography and Security
url https://arxiv.org/abs/2509.11695