Securing named data networking (NDN) content: a quantum homomorphic encryption protocol
Abstract Named data networking (NDN) supports receiver-driven content retrieval with stateful forwarding (pending interest table (PIT)/forwarding information base) and in-network caching, yet many deployments still rely on classical cryptography that may be undermined by quantum-capable adversaries. Despite NDN’s built-in data authenticity via producer signatures, quantum-enabled attacks become plausible once RSA/ECC-based trust anchors are weakened by Shor-type attacks. Existing quantum-security efforts for NDN largely focus on post-quantum replacements of signatures or key exchange, but do not address the tension between confidentiality-preserving payload protection and NDN’s in-network processing (forwarding/caching decisions) in a quantum setting. This paper presents a quantum-enhanced NDN architecture that preserves NDN’s content-centric semantics—naming, PIT-driven forwarding, and cache-assisted dissemination of verifiable control objects—while delivering privacy-sensitive payloads as quantum homomorphic encryption (QHE)-encrypted quantum states over an underlying quantum network. QHE provides end-to-end confidentiality and enables authorized operations on encrypted quantum payloads without exposing plaintext. To make the design compatible with NDN forwarding, the proposed protocol encrypts the payload while keeping name-based forwarding semantics intact, and supports ciphertext-domain processing for selected policy functions. To protect provenance and integrity of NDN metadata, routing instructions, and session state, we incorporate quantum digital signatures (QDS) bound to NDN names and session identifiers. The main contributions are: (i) a QHE+QDS layered protection model tailored to NDN’s Interest and Data exchange; (ii) a session workflow that couples proactive entanglement distribution with NDN-style stateful signaling for efficient establishment and recovery; and (iii) a security analysis clarifying the achieved guarantees and the remaining trust assumptions. Security analysis indicates robustness against quantum man-in-the-middle and tampering attacks, with modest overhead on NDN control traffic.
Read more