Post-Quantum IPsec Gateway: Policy Enforcement Point
Leonardo Rizzo
Post-Quantum IPsec Gateway: Policy Enforcement Point.
Rel. Antonio Lioy, Flavio Ciravegna. Politecnico di Torino, Master of science program in Cybersecurity, 2025
|
Preview |
PDF (Tesi_di_laurea)
- Thesis
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (3MB) | Preview |
Abstract
The emergence of large-scale quantum computing poses a significant threat to the Public Key Infrastructure (PKI) that secures modern communications. Protocols such as Internet Protocol Security (IPsec), which rely on Internet Key Exchange version 2 (IKEv2) for key establishment, are fundamentally vulnerable to Shor’s algorithm. This vulnerability creates an immediate Har- vest Now, Decrypt Later (HNDL) attack vector, where encrypted data harvested today can be retrospectively decrypted once a sufficiently powerful quantum computer is available. While the National Institute of Standards and Technology (NIST) Post-Quantum Cryptogra- phy (PQC) standardisation process has produced new quantum-resistant algorithms, a simple “rip and replace“ migration strategy is untenable.
The volatility of new cryptographic assumptions, exemplified by the catastrophic failure of SIKE and the practical threat of implementation-specific Side-Channel Attacks (SCAs), demands a new architectural paradigm: cryptographic agility
Publication type
URI
![]() |
Modify record (reserved for operators) |
