Quantum computers could break currently used asymmetric cryptographic schemes in a few years using Shor's algorithm. They are used in numerous protocols and applications to secure authenticity as well as key agreement, and quantum-safe alternatives are urgently needed. NIST therefore initiated a standardization process. This requires intensive evaluation, also with regard to performance and integrability. Here, the integration into TLS 1.3 plays an important role, since it is used for 90% of all Internet connections. In the present work, algorithms for quantum-safe key exchange during TLS 1.3 handshake were reviewed. The focus is on the influence of dedicated network parameters such as transmission rate or packet loss in order to gain insights regarding the suitability of the algorithms under corresponding network conditions. For the implementation, a framework by Paquin et al. was extended to emulate network scenarios and capture the handshake duration for selected algorithms. It is shown that the evaluated candidates Kyber, Saber and NTRU as well as the alternative NTRU Prime have a very good overall performance and partly undercut the handshake duration of the classical ECDH. The choice of a higher security level or hybrid variants does not make a significant difference here. This is not the case with alternatives such as FrodoKEM, SIKE, HQC or BIKE, which have individual disadvantages and whose respective performance varies greatly depending on the security level and hybrid implementation. This is especially true for the data-intensive algorithm FrodoKEM. In general, the prevailing network characteristics should be taken into account when choosing scheme and variant. Further it becomes clear that the performance of the handshake is influenced by external factors such as TCP mechanisms or MTU, which could compensate for possible disadvantages due to PQC if configured appropriately.
翻译:量子计算机可能在数年内利用Shor算法破解当前使用的非对称密码体制。这些密码体制被广泛应用于众多协议和应用中以保障认证和密钥协商的安全性,因此迫切需要量子安全替代方案。美国国家标准与技术研究院(NIST)为此启动了标准化流程。这需要开展深入评估,特别是针对性能与可集成性方面。其中,与TLS 1.3的集成尤为重要,因为该协议用于支持90%的互联网连接。本研究综述了TLS 1.3握手过程中用于量子安全密钥协商的算法,重点考察传输速率、丢包率等特定网络参数的影响,以期获得算法在相应网络条件下的适用性见解。实现层面,我们扩展了Paquin等人的框架,通过模拟网络场景来测量选定算法的握手持续时间。结果表明,候选算法Kyber、Saber、NTRU以及替代方案NTRU Prime均展现出优异的整体性能,其握手时长甚至部分低于经典ECDH。选择更高安全等级或混合变体并未带来显著差异。但FrodoKEM、SIKE、HQC和BIKE等替代方案则存在各自缺陷,其性能随安全等级和混合实现方式的差异而大幅波动,尤其以数据密集型的FrodoKEM最为显著。总体而言,选择方案与变体时应考虑当前网络特征。进一步研究发现,握手性能受TCP机制或MTU等外部因素影响,若配置得当,这些因素可弥补PQC可能带来的性能劣势。