A Scalable Framework for Post-Quantum Authentication in Public Key Infrastructures

📅 2025-04-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the scalability and post-quantum (PQ) migration challenges of public key infrastructure (PKI) under quantum computing threats. Methodologically, it proposes a hierarchical certificate authentication framework compatible with both classical and NIST-standardized post-quantum cryptographic (PQC) algorithms—SPHINCS⁺, Falcon, and Dilithium—featuring a lightweight client adaptation mechanism, cross-algorithm rapid switching protocol, certificate isolation architecture resilient to cross-trust-chain attacks, and automated issuance/verification workflows. Key contributions include: (i) the first scalable, hierarchical certification authority (CA) model supporting cryptographic agility; (ii) substantial reduction in client-side cryptographic overhead; and (iii) empirical evaluation of performance–security–scalability trade-offs for all three PQC algorithms under 10,000 concurrent connections, demonstrating a viable pathway for large-scale, smooth PKI transition to quantum-resilient cryptography.

Technology Category

Machine Learning: Quantum Machine LearningData Mining & Knowledge Management: Scalability, Parallel & Distributed SystemsSearch and Optimization: Distributed Search

Application Category

Security and Privacy: Applications of cryptographySearch and Retrieval-Augmented AI: Efficiency and scalability of Web search enginesSystems and Infrastructure for Web, Mobile and WoT: Experiences and lessons learnt from Web-based algorithms and system deployments
📝 Abstract
This work explores the performance and scalability of a hierarchical certificate authority framework with automated certificate issuance employing post-quantum cryptographic (PQC) signature algorithms. The system is designed for compatibility with both classical and PQC algorithms, promoting crypto-agility while ensuring robust security against quantum-based threats. The proposed framework design expects minimal cryptographic requirements from potential clients, protects certificates of high importance against cross-dependent chains-of-trust and allows for prompt switching between classical and PQC algorithms. Finally, we evaluate SPHINCS$^+$, Falcon, and Dilithium variants in various configurations of certificate issuance and verification accommodating a large client base, underlining the trade-offs in balancing performance, scalability, and security.
Problem

Research questions and friction points this paper is trying to address.

Evaluates post-quantum authentication scalability in PKI
Ensures crypto-agility with classical and PQC algorithms
Assesses performance trade-offs in large-scale deployments
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hierarchical certificate authority with PQC
Dual compatibility for classical and PQC algorithms
Evaluates SPHINCS+, Falcon, and Dilithium variants
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
National and Kapodistrian University of Athens | Eulambia Advanced Technologies
A
Antonia Tsili
National and Kapodistrian University of Athens, Greece
K
Konstantinos Kordolaimis
Eulambia Advanced Technologies, Greece
K
Konstantinos Krilakis
Eulambia Advanced Technologies, Greece
D
Dimitris Syvridis
National and Kapodistrian University of Athens, Greece Eulambia Advanced Technologies, Greece