|
SATP: Symmetric Authenticated Tunneling Protocol 1.0.0.0a (A1)
A quantum secure symmetric pre-shared key tunneling protocol
|
The Symmetric Authenticated Tunneling Protocol (SATP) is a next-generation secure communications framework designed to establish cryptographically authenticated and confidential tunnels using only symmetric primitives. SATP eliminates the reliance on online public-key infrastructures (PKI) and ephemeral asymmetric exchanges, achieving equivalent levels of confidentiality, integrity, and forward secrecy through pre-provisioned hierarchical symmetric keys and authenticated encryption.
SATP is optimized for environments where centralized trust authorities exist, such as industrial control, secure embedded systems, field communications, and closed network infrastructures. Its lightweight design enables high-speed, low-latency encryption without the computational cost of traditional hybrid or asymmetric protocols.
Traditional secure tunneling protocols such as TLS, SSH, and IKE rely on asymmetric key exchange mechanisms and certificate-based authentication. These systems present challenges in environments where:
In such cases, asymmetric operations increase computational cost and complexity, while their key lifecycles remain vulnerable to compromise or certificate mismanagement. SATP was designed to provide a provably secure alternative in these constrained or regulated environments.
SATP uses a hierarchical symmetric key structure combined with ephemeral per-session derivations to establish a tunnel with full AEAD protection. The protocol consists of two phases:
The server then performs optional client authentication using a hardened SCB (SHAKE Cost-Based) passphrase verification. This process occurs after the encrypted channel is active, ensuring that credentials are never exposed in plaintext.
SATP employs a secure hierarchical key derivation system:
Session keys (Kt and Kr) are further derived from Kc,i and a mixed nonce (Nh = SHAKE256(Nh_c â Nh_s)), ensuring bidirectional key independence. This structure isolates compromise to a single device and session, maintaining network-wide containment.
SATP is applicable to:
SATP provides a fully symmetric, authenticated encryption framework with forward secrecy and high operational efficiency. Its reliance on hierarchical symmetric derivations instead of online public-key exchanges allows deployment in closed or offline systems while preserving the cryptographic strength and integrity of traditional secure tunnels. By integrating SCB-based authentication, timestamp-bound replay protection, and deterministic AEAD operations, SATP achieves strong, scalable, and verifiable tunnel security within a lightweight implementation footprint.
QRCS-PL private license. See license file for details. All rights reserved by QRCS Corporation, copyrighted and patents pending.