Emmanuel Konan

EAP-PSK-256: quantum-resistant authentication draft

Public contribution · Cryptography

I coauthored the EAP-PSK-256 individual Internet-Draft with Bruno Rohee, Michael Le Clerc and Clément Devun. It proposes changes to EAP-PSK, an authentication method based on pre-shared secrets.

The aim is quantum-resistant authentication with limited memory and code size. The approach uses symmetric cryptography based on AES-256. Alongside this protocol work, I work on integrating post-quantum algorithms into environments with limited compute and storage resources.

The draft is a work in progress, not an RFC or an adopted IETF standard.

Proposed changes

  • AES-256-based mechanisms in place of the original AES-128 construction.
  • Key derivation based on NIST SP 800-108.
  • Randomness from both the peer and the server in session-key derivation.
  • Descriptions of message flows, the key hierarchy and security assumptions.

Limitations

The proposal does not provide perfect forward secrecy. Quantum resistance is an objective of the proposal, not a certification. Key provisioning, random-number generation and implementation behavior remain questions for a deployment review.

The IETF Datatracker record lists the authors, revisions and document status.

Read the Internet-Draft