Beyond Object Authentication: Context-Closed Post-Quantum Authentication for the WebPKI

📅 2026-08-30
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文解决了WebPKI在后量子迁移中认证成本增加及授权上下文不一致的问题,提出了一种名为LRp的双平面后量子结构来验证可变CA上下文状态。
📝 Abstract
Post-quantum migration increases WebPKI authentication cost, but authenticating a compressed certificate object does not by itself preserve the mutable authorization context under which a relying party accepts it. We formalize \emph{context closure}: the authenticated projection accepted by a verifier must determine the selected authorization semantics it claims, relative to declared source contracts and event-coverage witnesses. We instantiate this idea with \LRp, a two-plane post-quantum construction that authenticates mutable CA-context state in an update plane while the warm path carries only state-local dependency references selected by explicit profile negotiation. In a pinned CCADB reconstruction, we obtain 44,912 path/view contexts and 16,858 physical CA lineages across Apple, Chrome, Microsoft, and Mozilla views. The core compiler yields $m_{50}=6$, $m_{95}=16$, and $m_{\max}=18$ typed dependencies. A warm LR+ selector therefore costs 296, 776, and 872 bytes at median, p95, and maximum, compared with 3,842, 5,932, and 6,350 bytes for a one-signature stateless bundle carrying the same dependency vector. The retained all-view closure state is 16.15 MB, and per-view lifecycle crossovers range from 19.60 to 50.41 median-path warm authentications/day under the stated checkpoint and update model. The implementation and evaluation artifact are available at https://github.com/nserser/LR-WebPKI
Problem

Research questions and friction points this paper is trying to address.

Post-Quantum Migration
WebPKI Authentication
Context Closure
Authorization Semantics
Certificate Object
Innovation

Methods, ideas, or system contributions that make the work stand out.

context closure
post-quantum authentication
LRp construction
mutable CA-context state
WebPKI
🔎 Similar Papers
No similar papers found.