Analysis of Network-level Key Exchange Protocols in the Post-Quantum Era
Andrea Pazienza, Eufemia Lella, Pietro Noviello, Felice Vitulano · 2022
A Virtual Private Network (VPN) ensures the confidentiality and integrity of data transferred between two endpoints, even if the means of transport are insecure. One popular protocol is Internet Protocol Security (IPSec) which operates at OSI layer 3 and protects all protocols at higher layers. Cryptographic keys in IPSec are negotiated using the Internet Key Exchange (IKE) protocol. IKE negotiates security parameters for IPSec sessions. In particular, the IKEv2 protocol uses the Elliptic Curve Diffie-Hellman (ECDH) algorithm to establish a secret key shared between two nodes on a network. Although solving such a problem remains difficult with current computing power, it is believed that generic quantum computers will be able to solve this problem, which implies that the security of IKEv2 is compromised. There are, however, several cryptographic systems that are trusted to be resistant to attacks by quantum computers. This family of cryptosystems is known as quantum-resistant cryptography (QRC). In this paper, after highlighting the requirements for a secure key exchange protocol, we briefly review the QRC solutions that have been proposed in the recent literature.