Virtual Private Networks in the Quantum Era: A Security in Depth Approach

被引:2
作者
Schatz, David [1 ]
Altheide, Friedrich [1 ]
Koerfgen, Hedwig [2 ]
Rossberg, Michael [1 ]
Schaefer, Guenter [1 ]
机构
[1] Tech Univ Ilmenau, Ilmenau, Germany
[2] Univ Bundeswehr Munchen, Munich, Germany
来源
PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, SECRYPT 2023 | 2023年
关键词
Virtual Private Networks; Internet Key Exchange; Quantum Key Distribution; Multipath Key Reinforcement;
D O I
10.5220/0012121800003555
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conventional asymmetric cryptography is threatened by the ongoing development of quantum computers. A mandatory countermeasure in the context of virtual private networks (VPNs) is to use post-quantum cryptography (PQC) as a drop-in replacement for the authenticated key exchange in the Internet Key Exchange (IKE) protocol. However, the results of the ongoing cryptanalysis of PQC cannot be predicted. Consequently, this article discusses orthogonal methods for quantum-resistant key exchanges, like quantum key distribution (QKD) and multipath key reinforcement (MKR). As each method has limitations when used on its own, we conclude that it is best to maximize security by combining all available sources of symmetric key material to protect traffic inside a VPN. As one possible realization, we propose a lightweight proxy concept that uses available symmetric keys, like QKD and MKR keys, to implement a transparent cryptographic tunnel for all IKE packets, and consequently for PQC key exchanges. In contrast to combining PQC and symmetric key material within the IKE protocol, our approach provides security in depth: If secure symmetric keys are available, attacks on IKE and hence on PQC algorithms are infeasible. But even otherwise, the security properties of IKE and thus PQC are not weakened, so the overall security of the VPN is guaranteed to increase.
引用
收藏
页码:486 / 494
页数:9
相关论文
共 46 条
  • [31] Privacy Preserving Collaborative Enforcement of Firewall Policies in Virtual Private Networks
    Liu, Alex X.
    Chen, Fei
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2011, 22 (05) : 887 - 895
  • [32] Design and reconfiguration of virtual private, networks (VPNs) over all-optical WDM networks
    Zheng, J
    Zhou, B
    Mouftah, HT
    ELEVENTH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 2002, : 599 - 602
  • [33] Configuration Faults Detection in IP Virtual Private Networks Based on Machine Learning
    Mohammedi, El-Heithem
    Lavinal, Emmanuel
    Fleury, Guillaume
    MACHINE LEARNING FOR NETWORKING, MLN 2020, 2021, 12629 : 40 - 56
  • [34] Hybrid Conventional and Quantum Security for Software Defined and Virtualized Networks
    Aguado, Alejandro
    Lopez, Victor
    Martinez-Mateo, Jesus
    Szyrkowiec, Thomas
    Autenrieth, Achim
    Peev, Momtchil
    Lopez, Diego
    Martin, Vicente
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2017, 9 (10) : 819 - 825
  • [35] Private Randomness Agreement and Its Application in Quantum Key Distribution Networks
    Christensen, Rene Bodker
    Popovski, Petar
    IEEE COMMUNICATIONS LETTERS, 2023, 27 (02) : 477 - 481
  • [36] Quantum Key Distribution Networks: Challenges and Future Research Issues in Security
    Tsai, Chia-Wei
    Yang, Chun-Wei
    Lin, Jason
    Chang, Yao-Chung
    Chang, Ruay-Shiung
    APPLIED SCIENCES-BASEL, 2021, 11 (09):
  • [37] Performance analysis of electronic code division multiple access based virtual private networks over passive optical networks
    Nadarajah, Nishaanthan
    Nirmalathas, Ampalavanapillal
    OPTICS COMMUNICATIONS, 2008, 281 (06) : 1671 - 1678
  • [38] Dynamic bandwidth allocation and buffer dimensioning for supporting video-on-demand services in virtual private networks
    Zhang, L
    Fu, H
    COMPUTER COMMUNICATIONS, 2000, 23 (14-15) : 1410 - 1424
  • [39] Monte Carlo approach to the evaluation of the security of device-independent quantum key distribution
    Su, Hong-Yi
    NEW JOURNAL OF PHYSICS, 2023, 25 (12):
  • [40] Optional dynamic bandwidth allocation based on playback tunnel to support video-on-demand service in virtual private networks
    Zhang, L
    Fu, H
    COMPUTER COMMUNICATIONS, 2001, 24 (11) : 1019 - 1030