The full protocol is described, game-based security arguments under an explicit adversarial model are provided, analytic cost estimates for the friction mechanism are given, the denial-of-service surface and a two-layer mitigation strategy are analysed, and a post-quantum extension is specified using hybrid X25519/ML-KEM-768 ratcheting.
Abstract
Fingertrap is a network encryption and authentication protocol that extends the X3DH and Double Ratchet frameworks with three novel mechanisms inspired by the Chinese finger trap (zhĭ wăng): a friction ratchet that exponentially increases computational cost for each failed authentication attempt; a recursive annihilation protocol that irreversibly destroys all cryptographic state after a configurable failure threshold; and a commit-then-challenge handshake that requires a counterintuitive “inward” action for legitimate authentication. A bidirectional weave hash extends the Double Ratchet’s transcript binding to cover every message in both directions. Together, these mechanisms provide per-message forward secrecy, post-compromise security (self-healing), clock-free operation, and a self-destruct capability. The individual ingredients-client puzzles, key erasure, and ratcheting-each build on established lines of work; their combination into a single stateful protocol, in which failed authentication attempts cryptographically tighten the session state and ultimately destroy it, is not to our knowledge offered by deployed transport protocols such as TLS 1.3, Signal, or WireGuard. The design targets deployments in which interception or capture of a device implies endpoint compromise, such as Unmanned Aerial Vehicle (UAV) telemetry links and body-worn sensors, where denial of exploitation requires guaranteed loss of past and future session material. We describe the full protocol, provide game-based security arguments under an explicit adversarial model, give analytic cost estimates for the friction mechanism, analyse the denial-of-service surface and a two-layer mitigation strategy, and specify a post-quantum extension using hybrid X25519/ML-KEM-768 ratcheting.
A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.
A. K. M. Fakhrul Hossain, Article Info· 0 citations
A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.
A. K. M. Fakhrul Hossain· SUST Journal of Science and...· 0 citations
This work presents the hybrid key establishment protocol TutaCrypt in a form that enables rigorous cryptographic analysis and defines two Bellare–Rogaway-style security models that precisely characterize the provided security guarantees.
Christian Holler, Tibor Jager, Tom Neuschulten· IACR Communications in Crypt...· 0 citations
Performance evaluations demonstrate that the proposed lightweight anonymous group authentication scheme outperforms existing comparable schemes in terms of computational cost, communication overhead, and dynamic group management efficiency, demonstrating its potential for resource-constrained IoT environments, pending...
Huanjie Zhang, Yang Chen, Sheng-Hao Chen et al.· Italian National Conference...· 0 citations
The Secure Hardware Extension (SHE) provides crucial functionalities such as error-detection, authorization, and authentication of messages exchanged between Electronic Control Units (ECUs) over the Controller Area Network (CAN) bus with the help of Advanced Encryption Standard (AES) cryptographic cores. However, the s...
Soumi Chatterjee, Siddhartha Chowdhury, Urbi Chatterjee et al.· ACM Transactions on Embedded...· 0 citations
Vehicle-to-Everything (V2X) communication enables vehicles to exchange safety-critical messages, but its reliance on temporary pseudonymous identities makes it vulnerable to Sybil attacks, where a single attacker fabricates multiple identities to inject false information into the network. This paper presents a lightwei...
Maher Fayyad, Abdullah Awad, Edison Pignaton De Freitas et al.· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.