The Rosenpass VPN has been introduced, resilient against attacks using quantum computers.

A group of German researchers, developers, and cryptographers has published the first release of the Rosenpass project, which develops a VPN and key exchange mechanism resistant to hacking by quantum computers. It uses the WireGuard VPN with standard encryption algorithms and keys, and Rosenpass adds key exchange methods that are protected against quantum computer hacking (i.e., Rosenpass enhances key exchange without altering the operational algorithms and encryption methods of WireGuard). Rosenpass can also be used independently of WireGuard as a universal key exchange toolkit suitable for securing other protocols against quantum computer attacks.

The toolkit's code is written in Rust and is distributed under the MIT and Apache 2.0 licenses. Cryptographic algorithms and primitives are borrowed from the liboqs and libsodium libraries written in C. The published codebase is positioned as a reference implementation—alternative toolkit versions can be developed based on the provided specifications using other programming languages. Currently, work is underway for formal verification of the protocol, cryptographic algorithms, and implementation to provide a mathematical proof of reliability. Symbolic analysis of the protocol and its basic implementation in Rust has already been performed using ProVerif.

The Rosenpass protocol is based on the post-quantum authenticated key exchange mechanism PQWG (Post-quantum WireGuard), built using the McEliece cryptosystem, which is resistant to brute-force attacks by quantum computers. The key generated in Rosenpass is used in the form of a pre-shared symmetric key (PSK) for WireGuard, implementing an additional layer for hybrid protection VPN-of the connection.

Rosenpass provides a standalone background process used for generating pre-defined WireGuard keys and securing key exchange during the connection handshake using post-quantum cryptography methods. Like in WireGuard, symmetric keys in Rosenpass are updated every two minutes. Shared keys are used to secure the connection (a pair of public and private keys is generated on each side, after which the participants exchange public keys).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers šŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster