A Zero-Knowledge Signature Framework for Efficient Post-Quantum Message Authentication in Cooperative Automated Driving
summary
The gist
The gist The proposed ZKS-PQC framework enables communication-efficient postquantum message authentication for cooperative V2X systems by replacing complete post-quantum public keys and signatures
In short
The ZKS-PQC framework replaces large post-quantum public keys and signatures with compact Zero-Knowledge Proofs (ZKP) for message authentication in V2X systems. This allows for communication efficiency while maintaining compatibility with older security systems. Experiments show acceptable processing times, enabling a smooth transition to quantum-safe cryptography without significant performance loss.
Key concepts
- PQC Migration Challenges
- Post-quantum cryptography (PQC) algorithms introduce issues for real-time systems, especially when dealing with message fragmentation. Messages exceeding frame sizes require splitting, which reduces available channel capacity and adds processing load on both sending and receiving vehicles.
- ZKS-PQC Scheme
- This proposed scheme solves the challenges by substituting traditional PQC signatures and public keys with a shorter fixed-size proof and commitment. This results in a much smaller message format, improving communication efficiency while ensuring post-quantum security.
- Zero-Knowledge Proof (ZKP)
- A ZKP is a cryptographic method that allows one party to prove they know a secret (like the private key) without revealing the secret itself. In this framework, it replaces large signatures with a compact proof, enabling authentication while keeping sensitive information private.
- Backward Compatibility
- The scheme is designed to be transparent to vehicles running legacy ECDSA-only systems. This backward compatibility ensures that vehicles supporting older standards can still operate seamlessly during the incremental migration period to post-quantum algorithms.
Terminology used across episodes
This episode discusses
- A Zero-Knowledge Signature Framework for Efficient Post-Quantum Message Authentication in Cooperative Automated Driving · Paper Radio
- Zero-Knowledge Proof Frameworks: A Systematic Survey
The paper
A Zero-Knowledge Signature Framework for Efficient Post-Quantum Message Authentication in Cooperative Automated Driving · Read on arXiv
Takahito Yoshizawa, Aysajan Abidin, Edoardo Pena-González, Bart Preneel
COSIC, KU Leuven
Connected and Automated Vehicles (CAV) rely on authenticated Vehicle-to-Everything (V2X) communications to exchange safety-critical information among vehicles and roadside infrastructure. As the automotive industry transitions toward post-quantum cryptography (PQC), the significantly larger public keys and signatures of standardized PQC digital signature algorithms introduce substantial communication overhead, which challenges the scalability of certificate-based V2X authentication, particularly for high-frequency cooperative awareness messages (CAM). This paper presents ZKS-PQC, a zero-knowledge signature framework that enables communication-efficient post-quantum message authentication for cooperative V2X systems. Instead of transmitting complete post-quantum public keys and signatures, the proposed framework replaces this authentication material with a compact Zero-Knowledge Proof (ZKP) while preserving compatibility with existing certificate-based trust architectures. This approach supports incremental migration and backward compatibility with the legacy ECDSA. The framework is implemented using the Open Quantum Safe (liboqs) and ZKP (Bulletproofs) libraries, and we evaluated the performance of standardized NIST PQC signature algorithms and additional candidate algorithms. Experimental validation on both a Linux platform and a commercial On-Board Unit (OBU) demonstrates substantial reductions in message size exceeding 95% for all algorithms, while limiting additional processing overhead by staying within the order of milliseconds at both sender and receiver in many algorithms, consistent with the latency requirements of real-time V2X operation. By decoupling communication overhead from the size characteristics of post-quantum signature algorithms, ZKS-PQC offers a practical migration strategy for scalable, quantum-resilient message authentication in future CAV systems.
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "A Zero-Knowledge Signature Framework for Efficient Post-Quantum Message Authentication in Cooperative Automated Driving".
Elias: The gist The proposed ZKS-PQC framework enables communication-efficient postquantum message authentication for cooperative V2X systems by replacing complete post-quantum public keys and signatures with a compact Zero-Knowledge Proof (ZKP) while…
Nadia: First, who's behind it and why it matters.
Paper summary: Nadia: So, to recap what we just covered, this paper introduces ZKS-PQC, which is a zero-knowledge signature framework aiming to make post-quantum message authentication efficient for connected and automated vehicles.
Elias: Essentially, the authors are tackling the problem where the larger public keys and signatures of standard PQC digital signature algorithms create too much communication overhead in V2X communications.
Priya: They claim their contribution is a new approach that neutralizes those stated impacts by replacing the PQC signature and public key with a compact zero-knowledge proof and commitment.
Nadia: The paper argues that conventional messages, which include both a certificate containing the public key and a signature, become excessively long when you apply these larger PQC Digital Signature Algorithms to them.
Elias: This excessive length stresses the communication channel because longer messages take up more time on the line and if they exceed a frame size, fragmentation happens which slows down both sending and receiving.
Priya: It’s important to remember that this is specifically aimed at high-rate communication contexts, like vehicle ITS stations where CAM generation intervals are specified from one hundred to one thousand milliseconds <ref:2610.11490#pg2>.
Nadia: And the paper's main contribution is demonstrating that their scheme reduces message size by more than ninety-five percent compared to the conventional approach in most of the PQC signature algorithms they tested <ref:2610.11490#pg2>.
Elias: This dramatic size reduction is what allows them to remove the obstacles that were previously limiting which PQC DSAs you could even use, meaning you aren't restricted to only the smallest or least secure ones.
Priya: So, for those of us interested in the data, this means we can potentially use a much stronger post-quantum algorithm without immediately knowing it will cripple our real-time system's ability to handle safety-relevant information.
Nadia: It shifts the focus away from just picking the smallest signature and public key and lets you choose based on how secure you actually need to be while keeping performance in mind.
Elias: They are showing that this framework provides a way to make the PQC DSAs compatible with existing certificate-based trust architectures in a communication-efficient manner.
Priya: It’s about making the migration path from current standards to post-quantum cryptography much smoother and less disruptive for connected vehicle infrastructure.
Nadia: The abstract sets up the scenario: CAVs need authenticated V2X communications, but PQC migration introduces problems with message size and processing time in real-time systems.
Elias: The paper lays out the need to address these constraints, showing how conventional methods lead to excessive message length stressing channels and causing delays.
Conclusion: Nadia: So wrapping up this discussion on "A Zero-Knowledge Signature Framework for Efficient Post-Quantum Message Authentication in Cooperative Automated Driving," the authors have essentially presented ZKS-PQC as a solution to the size and latency issues inherent in using large post-quantum signatures.
Elias: The paper’s main implication is that they provide a method to enable communication-efficient post-quantum message authentication for cooperative V2X systems by replacing those large components with a compact zero-knowledge proof structure.
Priya: For someone listening just about driving, the big picture is that this means vehicles can use much more robust security against future quantum threats without sacrificing the speed and reliability needed for real-time safety messages.
Nadia: It allows for an incremental migration where you can support legacy ECDSA systems while gradually integrating PQC DSAs using this framework transparently to those older vehicles.
Elias: The authors are showing that their scheme brings all the different PQC Digital Signature Algorithms onto the same playing field, allowing users to select algorithms based on security requirements without being overly concerned about the resulting message size increase.
Priya: It’s a practical step toward making post-quantum cryptography viable for high-speed, safety-critical communications in connected vehicle environments.
More episodes
- 2610.10644-SoK: Failure Modes in Common Criteria Product Evaluation - A Taxonomy and Design-for-Evaluability Guidance
- 2610.10617-MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking
- 2610.10620-When AI Finds Hidden Messages, Does It Report?
- 2610.10625-Safe at One Loop, Risky at Another: Aligning Safety Across Recurrent Depths in Looped Language Models
- 2610.10992-The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical Study across the Three FIPS 204 Parameter Sets
- 2610.10659-Applying Security by Design at the Point of Execution: How Governed Security Requirements Affect the Security of AI-Generated Code
- 2610.10735-DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits
- 2610.10742-BRANCH: Bypassing Multi-Scanner AI Guardrails
- 2610.10752-Detection-Guided Adaptive Purification with Diffusion Models for Robust Audio Deepfake Detection
- 2610.10766-CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel