IPK-pq: Identity-Based Post-Quantum RPKI

Arxiv pdf 2026-03-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

With the rapid evolution of the Industrial Internet of Things (IIoT), the boundaries and scale of the Internet are continuously expanding. Consequently, the limitations of traditional certificate-based Public Key Infrastructure (PKI) have become increasingly evident, particularly in scenarios requiring large-scale certificate storage, verification, and frequent transmission. These challenges are expected to be further amplified by the widespread adoption of post-quantum cryptography. In this paper, we propose a novel identity-based public key management framework for PKI based on post-quantum cryptography, termed IPK-pq. This approach implements an identity key generation protocol leveraging NIST ML-DSA and random matrix theory. Building on the concept of the Composite Public Key (CPK), IPK-pq addresses the linear collusion problem inherent in CPK through an enhanced identity mapping mechanism. Furthermore, it simplifies the verification of the declared public keys authenticity, effectively reducing the complexity associated with certificate-based key management. We also provide a formal security proof for IPKpq, covering both individual private key components and the composite private key. To validate our approach, formally, we directly implement and evaluate IPK-pq within a typical PKI application scenario: Resource PKI (RPKI). Comparative experimental results demonstrate that an RPKI system based on IPK-pq yields significant improvements in efficiency and scalability. These results validate the feasibility and rationality of IPK-pq, positioning it as a strong candidate for nextgeneration RPKI systems capable of securely managing largescale routing information.

Loading executive summary...

LINK COPIED TO CLIPBOARD