In recent years, Post-Quantum Cryptography (PQC) has gained considerable interest. This is mainly driven by the rapid development of Quantum Computing technologies, that are continuously improving the performance. This rapid development is threatening most of the current security methodologies, because they are largely based on classical crypto systems. For this reason, the transition from classical cryptography to PQC is becoming paramount, as the threat of quantum computers is not yet present but is expected in the very near future. This is necessary for a wide range of devices, ranging from cloud to IoT scenarios. The latter has more criticalities in performing this transition, due to the resource-constrained nature of the deployed devices. Several standardisation organisations are publishing their guideline for the adoption of PQC, based on different parameters such as the scenario and the security level. A specific security aspect that is largely affected by the threat of quantumcomputers is integrity verification. This is a set of techniques that aim to verify and enforce that a specific device behaves as intended. Being largely based on cryptographic operations, especially the Remote Attestation process, the transition to PQC is crucial. In this paper, we present the integration of PQC, specifically the ML-DSA algorithm, into the Keylime framework for remote attestation. In particular, we present the integration of PQC in the Keylime Agent, which is the most crucial component, as it is deployed in untrusted environments and on various devices with differing computational resources. We also propose a deployment architecture based on the Arm TrustZone TEE technology, exploiting the OP-TEE framework as trusted operating system, integrating an ML-DSA-enabled firmware TPM implementation for PQ remote attestation

Integration of Post-Quantum Cryptography in the Keylime Agent for Quantum-Safe Remote Attestation / Vaccaro, Francesco; Bravi, Enrico; Lioy, Antonio. - 4198:(2026). ( ITASEC & SERICS 2026 Joint National Conference on Cybersecurity 2026 Cagliari (ITA) February 09-13, 2026.).

Integration of Post-Quantum Cryptography in the Keylime Agent for Quantum-Safe Remote Attestation

Vaccaro, Francesco;Bravi, Enrico;Lioy, Antonio
2026

Abstract

In recent years, Post-Quantum Cryptography (PQC) has gained considerable interest. This is mainly driven by the rapid development of Quantum Computing technologies, that are continuously improving the performance. This rapid development is threatening most of the current security methodologies, because they are largely based on classical crypto systems. For this reason, the transition from classical cryptography to PQC is becoming paramount, as the threat of quantum computers is not yet present but is expected in the very near future. This is necessary for a wide range of devices, ranging from cloud to IoT scenarios. The latter has more criticalities in performing this transition, due to the resource-constrained nature of the deployed devices. Several standardisation organisations are publishing their guideline for the adoption of PQC, based on different parameters such as the scenario and the security level. A specific security aspect that is largely affected by the threat of quantumcomputers is integrity verification. This is a set of techniques that aim to verify and enforce that a specific device behaves as intended. Being largely based on cryptographic operations, especially the Remote Attestation process, the transition to PQC is crucial. In this paper, we present the integration of PQC, specifically the ML-DSA algorithm, into the Keylime framework for remote attestation. In particular, we present the integration of PQC in the Keylime Agent, which is the most crucial component, as it is deployed in untrusted environments and on various devices with differing computational resources. We also propose a deployment architecture based on the Arm TrustZone TEE technology, exploiting the OP-TEE framework as trusted operating system, integrating an ML-DSA-enabled firmware TPM implementation for PQ remote attestation
2026
File in questo prodotto:
File Dimensione Formato  
paper56.pdf

accesso aperto

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Creative commons
Dimensione 715.01 kB
Formato Adobe PDF
715.01 kB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3006557