Paper 2026/019

Subversion-resilient Key-exchange in the Post-quantum World

Kévin Duverger, Université de Limoges, XLIM, CNRS 7252
Pierre-Alain Fouque, University of Rennes 1
Charlie Jacomme, Université de Lorraine, CNRS, Inria, LORIA
Guilhem Niot, PQShield, Université de Rennes, CNRS, IRISA
Cristina Onete, Université de Limoges, XLIM, CNRS 7252
Abstract

Subversion-resilient Authenticated key-exchange (AKE) aims to achieve the guarantees of secure AKE even in the presence of an adversary that has tampered with parts of the protocol's implementation. One way to achieve subversion-resilient AKE is the use of Reverse Firewalls (RFs), an untrusted third-party that can restore security. Recent work [18] highlights the challenges of designing RFs for practical secure channel-establishment. This paper extends existing RF-based subversion-resilient AKE at three levels: security definitions, constructions, and the use of formal verification. First, we introduce a useful relaxation of the notion of security in subversion-resilient AKE with RFs: the goal is no longer to prevent all exfiltration, but rather to restore to the AKE protocol a property lost upon subversion. We focus specifically on authenticating and (key-)securing RFs. We also discuss subversion-resilience against a spectrum of compromises, designing a flexible framework in which protocols are proved secure with respect to adversaries that can tamper with some components of the implementation, but perhaps not others. Our ultimate goal is to achieve post-quantum secure subversion-resilient key-exchange. Far from being trivial, this requires the introduction of a malleable-yet-secure notion of key encapsulation, which we dub re-randomizable Key Encapsulation Mechanism. We carefully formalize this new primitive and instantiate it first based on a classical Diffie-Hellman KEM and one based on Kyber. Finally, we lay the foundations for the formal verification of RF based protocols, by formally proving our protocol with the CryptoVerif prover, in addition to computational-security proofs in usual Bellare-Rogaway methodology.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. ACM CCS 2025
DOI
10.1145/3719027.3765165
Keywords
key-exchangesubversion-resiliencereverse firewalllattices
Contact author(s)
kevin duverger @ etu unilim fr
pierre-alain fouque @ irisa fr
charlie jacomme @ inria fr
guilhem @ gniot fr
cristina onete @ gmail com
History
2026-01-09: approved
2026-01-06: received
See all versions
Short URL
https://ia.cr/2026/019
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/019,
      author = {Kévin Duverger and Pierre-Alain Fouque and Charlie Jacomme and Guilhem Niot and Cristina Onete},
      title = {Subversion-resilient Key-exchange in the Post-quantum World},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/019},
      year = {2026},
      doi = {10.1145/3719027.3765165},
      url = {https://eprint.iacr.org/2026/019}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.