In this paper, we present a SmartNIC/DPU-accelerated secure multicast framework that integrates Ciphertext Policy Attribute Based Encryption (CP-ABE), post quantum key encapsulation (ML-KEM / ML-KEM-768), and AES-256-GCM data-plane encryption into a unified architecture. The design decouples control-plane security operations from the data plane, enabling efficient session key distribution via CP-ABE and ML-KEM, while offloading per-packet encryption and decryption to hardware using DPUs and the DOCA framework. We implement a fully functional both unicast and multicast transmission modes, where a single encrypted stream is securely distributed to multiple receivers. Each receiver independently reconstructs the session key using attribute-based policies and post-quantum decapsulation, ensuring fine-grained access control and quantum-resilient security for key exchange. The data plane leverages hardware-accelerated AES-GCM-256 with asynchronous task execution, zero-copy memory, and batched packet processing to achieve high throughput.

PQKE–hCPABE: A Hybrid CP-ABE Scheme with Post-Quantum Key Exchange for Secure Multicast

Sandrucci M.;Paolucci F.;Castoldi P.;Cugini F.
2026-01-01

Abstract

In this paper, we present a SmartNIC/DPU-accelerated secure multicast framework that integrates Ciphertext Policy Attribute Based Encryption (CP-ABE), post quantum key encapsulation (ML-KEM / ML-KEM-768), and AES-256-GCM data-plane encryption into a unified architecture. The design decouples control-plane security operations from the data plane, enabling efficient session key distribution via CP-ABE and ML-KEM, while offloading per-packet encryption and decryption to hardware using DPUs and the DOCA framework. We implement a fully functional both unicast and multicast transmission modes, where a single encrypted stream is securely distributed to multiple receivers. Each receiver independently reconstructs the session key using attribute-based policies and post-quantum decapsulation, ensuring fine-grained access control and quantum-resilient security for key exchange. The data plane leverages hardware-accelerated AES-GCM-256 with asynchronous task execution, zero-copy memory, and batched packet processing to achieve high throughput.
File in questo prodotto:
File Dimensione Formato  
150835.pdf

solo utenti autorizzati

Tipologia: PDF Editoriale
Licenza: Copyright dell'editore
Dimensione 1.42 MB
Formato Adobe PDF
1.42 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11382/591345
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
social impact