In this paper, we present a SmartNIC/DPU-accelerated secure multicast framework that integrates Ciphertext Policy Attribute Based Encryption (CP-ABE), post quantum key encapsulation (ML-KEM / ML-KEM-768), and AES-256-GCM data-plane encryption into a unified architecture. The design decouples control-plane security operations from the data plane, enabling efficient session key distribution via CP-ABE and ML-KEM, while offloading per-packet encryption and decryption to hardware using DPUs and the DOCA framework. We implement a fully functional both unicast and multicast transmission modes, where a single encrypted stream is securely distributed to multiple receivers. Each receiver independently reconstructs the session key using attribute-based policies and post-quantum decapsulation, ensuring fine-grained access control and quantum-resilient security for key exchange. The data plane leverages hardware-accelerated AES-GCM-256 with asynchronous task execution, zero-copy memory, and batched packet processing to achieve high throughput.
PQKE–hCPABE: A Hybrid CP-ABE Scheme with Post-Quantum Key Exchange for Secure Multicast
Sandrucci M.;Paolucci F.;Castoldi P.;Cugini F.
2026-01-01
Abstract
In this paper, we present a SmartNIC/DPU-accelerated secure multicast framework that integrates Ciphertext Policy Attribute Based Encryption (CP-ABE), post quantum key encapsulation (ML-KEM / ML-KEM-768), and AES-256-GCM data-plane encryption into a unified architecture. The design decouples control-plane security operations from the data plane, enabling efficient session key distribution via CP-ABE and ML-KEM, while offloading per-packet encryption and decryption to hardware using DPUs and the DOCA framework. We implement a fully functional both unicast and multicast transmission modes, where a single encrypted stream is securely distributed to multiple receivers. Each receiver independently reconstructs the session key using attribute-based policies and post-quantum decapsulation, ensuring fine-grained access control and quantum-resilient security for key exchange. The data plane leverages hardware-accelerated AES-GCM-256 with asynchronous task execution, zero-copy memory, and batched packet processing to achieve high throughput.| File | Dimensione | Formato | |
|---|---|---|---|
|
150835.pdf
solo utenti autorizzati
Tipologia:
PDF Editoriale
Licenza:
Copyright dell'editore
Dimensione
1.42 MB
Formato
Adobe PDF
|
1.42 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

