Protocolo PHANTOM
Post-quantum asynchronous transport protocol specification for onion-routed networks. Formal security evaluation under a 7-phase methodology — currently in Phase 1 (Research Questions).
Especificación de protocolo de transporte asincrónico post-cuántico para redes enrutadas por onion. Evaluación formal de seguridad bajo una metodología de 7 fases — actualmente en la Fase 1 (Preguntas de Investigación).
This specification describes a cryptographic protocol in the theoretical design phase (Immutable Baseline SPEC-000). It has been modified to remedy structural deficiencies regarding post-quantum KCI, PIR index collisions, and padding side channels. It must not be deployed in production without complete formal verification in Tamarin / ProVerif and independent code audit.
Esta especificación describe un protocolo criptográfico en fase de diseño teórico (Línea Base Inmutable SPEC-000). Ha sido modificada para remediar deficiencias estructurales en KCI post-cuántico, colisiones de índices PIR y canales laterales de padding. No debe desplegarse en producción sin verificación formal completa en Tamarin / ProVerif y auditoría de código independiente.
1. Adversary Model & Security Perimeter 1. Modelo de Adversario y Perímetro de Seguridad
The protocol does not assume unconditional resistance against state-level adversaries. Instead, it is formally defined against an active and passive adversary with global network control capabilities (Extended Dolev-Yao) under four concrete parameters and a bounded security perimeter:
El protocolo no asume resistencia incondicional frente a adversarios a nivel estatal. En su lugar, se define formalmente contra un adversario activo y pasivo con capacidades de control global de red (Dolev-Yao Extendido) bajo cuatro parámetros concretos y un perímetro de seguridad delimitado:
- Infrastructure ControlControl de Infraestructura Active control of up to 30% of overlay network nodes (Tor/Mixnet). Control activo de hasta el 30% de nodos de la red overlay (Tor/Mixnet).
- Advanced Statistical AnalysisAnálisis Estadístico Avanzado IAT classifiers based on Transformer architecture for global traffic. Clasificadores IAT basados en arquitectura Transformer para tráfico global.
- Indefinite Capture (HNDL)Captura Indefinida (HNDL) Mass storage under Harvest-Now-Decrypt-Later for future decryption. Almacenamiento masivo bajo Harvest-Now-Decrypt-Later para descifrado futuro.
- Quantum Capability (CRQC)Capacidad Cuántica (CRQC) Access to a Quantum Computer in polynomial time for discrete logarithm and factorization. Acceso a Computador Cuántico en tiempo polinomial para logaritmo discreto y factorización.
- Endpoint IntegrityIntegridad de Endpoints Absolute integrity of endpoint devices is assumed, with no kernel-level malware compromise. Se asume la integridad absoluta de los dispositivos finales sin compromisos de malware a nivel de kernel.
- Out-of-Band Channel (OOB)Canal Out-of-Band (OOB) Confidentiality and authenticity of the out-of-band verification channel are assumed at pairing time. Se asume la confidencialidad y autenticidad del canal de verificación fuera de banda al momento del emparejamiento.
- Symmetric DeniabilityDeniabilidad Simétrica All protocol deniability is delegated to the construction of ephemeral symmetric secrets. Toda la deniabilidad del protocolo se delega a la construcción de secretos simétricos efímeros.
2. Cryptographic Stack & Hybrid Primitives 2. Stack Criptográfico y Primitivas Híbridas
The cryptographic layer uses a hybrid post-quantum/classical design combining lattice-based primitives (ML-KEM-768, FIPS 203; ML-DSA-87, FIPS 204) with pre-quantum elliptic-curve primitives (X25519, RFC 7748). The symmetric transport uses authenticated encryption ChaCha20-Poly1305 with domain-separated key expansion via HKDF-HMAC-SHA3-256.
La capa criptográfica utiliza un diseño híbrido post-cuántico/clásico que combina primitivas basadas en reticulados (ML-KEM-768, FIPS 203; ML-DSA-87, FIPS 204) con primitivas pre-cuánticas de curva elíptica (X25519, RFC 7748). El transporte simétrico utiliza cifrado autenticado ChaCha20-Poly1305 con expansión de clave por separación de dominio vía HKDF-HMAC-SHA3-256.
| Function / LayerFunción / Capa | Standard PrimitivePrimitiva Estándar | Base StandardEstándar Base | Role in ProtocolRol en el Protocolo | Evidence LevelNivel de Evidencia |
|---|---|---|---|---|
| Post-Quantum KEMKEM Post-Cuántico | ML-KEM-768 | FIPS 203 | Hybrid encapsulation and session establishmentEncapsulamiento híbrido y establecimiento de sesión | Level 1 (NIST Standard)Nivel 1 (Estándar NIST) |
| Pre-Quantum KEMKEM Pre-Cuántico | X25519 | RFC 7748 | Residual classical security and elliptic bindingSeguridad remanente clásica y vinculación elíptica | Level 3 (IETF RFC)Nivel 3 (RFC IETF) |
| Post-Quantum SignatureFirma Digital PQ | ML-DSA-87 | FIPS 204 | Handshake authentication and long-term identity keyAutenticación de Handshake y clave de identidad a largo plazo | Level 1 (NIST Standard)Nivel 1 (Estándar NIST) |
| Symmetric AEAD CipherCifrado Simétrico AEAD | ChaCha20-Poly1305 | RFC 8439 | Authenticated protection of transport cellsProtección con datos asociados de las celdas de transporte | Level 3 (IETF RFC)Nivel 3 (RFC IETF) |
| Key Derivation (KDF)Derivación de Clave (KDF) | HKDF-HMAC-SHA3-256 | RFC 5869 / FIPS 202 | Extraction and expansion with strict domain separationExtracción y expansión con estricta separación de dominio | Level 3 (IETF RFC)Nivel 3 (RFC IETF) |
3. Handshake v2 & Post-Quantum Anti-KCI Authentication 3. Handshake v2 y Autenticación Anti-KCI Post-Cuántica
To mitigate the cryptographic vulnerability of version v0.1.0 (where the lack of origin authentication in the post-quantum KEM allowed KCI impersonation attacks via CRQC), Handshake v2 enforces active origin authentication using ML-DSA-87 signatures.
Para mitigar la vulnerabilidad criptográfica de la versión v0.1.0 (donde la falta de autenticación de origen en el KEM post-cuántico permitía ataques de suplantación KCI mediante CRQC), el Handshake v2 impone autenticación de origen activa mediante firmas ML-DSA-87.
PrekeyBundle_B (Bob) Total: 8,469 BytesTotal: 8.469 Bytes
- version (u16) 0x0002 (2 B)
- IK_B (X25519 Identity)(X25519 Identidad) 32 B
- PQ_IK_B (ML-DSA-87 Public)(ML-DSA-87 Pública) 2,592 B
- SPK_B (X25519 Ephemeral)(X25519 Efímera) 32 B
- SPK_B_sig (ML-DSA-87 signature over SPK_B)(Firma ML-DSA-87 sobre SPK_B) 4,627 B
- PQ_PK_B (ML-KEM-768 Public)(ML-KEM-768 Pública) 1,184 B
Initialization Operational Flow Flujo Operativo de Inicialización
- Step 1 — Generation (Alice):Paso 1 — Generación (Alice):
GeneratesGenera EK_A andy PQ_EK_A. RunsEjecuta (ct_PQ_B, ss_PQ_B) = Encaps(PQ_PK_B).
ComputesCalcula dh1, dh2, dh3 (X25519). Signs the transcript withFirma el transcrito con Sig_A = Sign(PQ_IK_A, IK_A || EK_A || ct_PQ_B || PQ_PK_A). - Step 2 — Validation & Response (Bob):Paso 2 — Validación y Respuesta (Bob):
Bob verifiesBob verifica Sig_A usingusando PQ_IK_A (if it fails, aborts immediately). Decapsulates(si falla, aborta inmediatamente). Descapsula ss_PQ_B and generates cross-encapsulationy genera encapsulamiento cruzado (ct_PQ_A, ss_PQ_A) = Encaps(PQ_PK_A).
Session Master Key Derivation (SPEC-000 §3.2) Derivación de Clave Maestra de Sesión (SPEC-000 §3.2)
4. The Split Ratchet Mechanism 4. El Mecanismo del Split Ratchet
To avoid performance degradation and artificial payload size inflation per packet, the Split Ratchet separates symmetric-chain operations from post-quantum asymmetric steps. Post-quantum asymmetric key exchange runs exclusively on communication direction changes (Turn-based Ratchet).
Para evitar la degradación de rendimiento y la inflación artificial del tamaño de payload por paquete, el Split Ratchet separa las operaciones de cadena simétrica de los pasos asimétricos post-cuánticos. El intercambio de claves asimétrico post-cuántico se ejecuta exclusivamente en cambios de dirección del flujo de comunicación (Turn-based Ratchet).
State Structure (RatchetState §4.1)Estructura de Estado (RatchetState §4.1)
Unidirectional Symmetric Transition (§4.2)Transición Simétrica Unidireccional (§4.2)
In consecutive sends without a response, only the symmetric HKDF chain advances, reducing asymmetric overhead per packet to zero:
En envíos consecutivos sin respuesta, solo avanza la cadena simétrica HKDF, reduciendo a cero el overhead asimétrico por paquete:
5. Private Storage Network & SimplePIR Epochs 5. Red de Almacenamiento Privado y SimplePIR Epochs
To resolve the desynchronization and index-collision problems of version v0.1.0, the storage network abandons real-time indexing over dynamic matrices and adopts a Time-Structured Frozen Epochs architecture.
Para resolver los problemas de desincronización y colisiones de índices de la versión v0.1.0, la red de almacenamiento abandona los índices en tiempo real sobre matrices dinámicas y adopta una arquitectura de Epochs Congelados Estructurados en el Tiempo.
Frozen Epochs Mechanism (§5.1)Mecanismo de Epochs Congelados (§5.1)
The relay database is frozen at discrete intervals of Δt = 300 seconds. During an active epoch, write requests (StoreRequest) are stored in a temporary buffer indexed by:
La base de datos del relay se congela a intervalos discretos de Δt = 300 segundos. Durante un epoch activo, las solicitudes de escritura (StoreRequest) se almacenan en un búfer temporal indexado por:
At epoch close, the server compiles a static matrix sorted lexicographically by message_id and publishes its root hash.
Al cierre del epoch, el servidor compila una matriz estática ordenada lexicográficamente por message_id y publica su root hash.
Private Retrieval with SimplePIR (§5.2)Recuperación Privada con SimplePIR (§5.2)
Estimating that its message belongs to Epoch E_n, the receiver downloads the binary metadata map and identifies the exact row.
Al estimar que su mensaje pertenece al Epoch E_n, el receptor descarga el mapa binario de metadatos e identifica la fila exacta.
The SimplePIR query runs over an immutable, static matrix, guaranteeing that the query vector computation matches the server structure bit by bit without failures from concurrent insertions.
La consulta SimplePIR se ejecuta sobre una matriz inmutable y estática, garantizando que el cálculo del vector de consulta coincida bit a bit con la estructura del servidor sin sufrir fallos por inserciones concurrentes.
6. Advanced Transport Layer & DP-Adaptive Padding 6. Capa de Transporte Avanzado y Padding DP-Adaptativo
To prevent pattern detection caused by large-payload fragmentation, the specification radically alters cell parameters in the overlay network:
Para prevenir la detección de patrones provocada por la fragmentación de payloads grandes, la especificación altera radicalmente los parámetros de celda en la red overlay:
Maximum Transmission Unit (MTU §6.1)Unidad Máxima de Transmisión (MTU §6.1)
The fixed cell size is set immutably to S_cell = 2048 bytes. Every control packet, handshake, or short message is padded with pseudo-random bytes (sequential encryption of 0x00) to reach exactly 2048 bytes before being injected into the Loopix Sphinx circuit.
El tamaño fijo de celda se establece inalterablemente en S_cell = 2048 bytes. Todo paquete de control, handshake o mensaje corto se rellena con bytes pseudo-aleatorios (cifrado secuencial de 0x00) hasta alcanzar exactamente 2048 bytes antes de inyectarse en el circuito Loopix Sphinx.
Differential Privacy Injection (Laplace Engine §6.2)Inyección con Privacidad Diferencial (Laplace Engine §6.2)
The engine evaluates the queue at strict intervals of T_slot = 50 ms. The global adversary's advantage in determining whether a slot contains real or cover traffic is bounded by:
El motor evalúa la cola a intervalos estrictos de T_slot = 50 ms. La ventaja del adversario global para determinar si un slot contiene tráfico real o de cobertura está acotada por:
If the queue is empty, an indistinguishable synthetic cell generated via local CSPRNG is injected.
Si la cola está vacía, se inyecta una celda sintética indistinguible generada vía CSPRNG local.
7. OOB Verification & Anti-Sybil PoW Rate Limiting 7. Verificación OOB y Limitación Anti-Sybil PoW
Out-of-Band Verification (OOB SAS §7)Verificación Fuera de Banda (OOB SAS §7)
The session state remains locked in STATUS_AWAITING_VERIFICATION after the handshake concludes. Transitioning to STATUS_ACTIVE requires:
El estado de la sesión permanece bloqueado en STATUS_AWAITING_VERIFICATION tras concluir el handshake. Transicionar a STATUS_ACTIVE requiere:
Comparison of an 8-digit SAS code and mutual QR scanning with interleaved signature of the full transcript and PQ identities.
Comparación de código SAS de 8 dígitos y escaneo mutuo de QR con firma entrelazada del transcrito completo e identidades PQ.
Anti-Sybil Rate Limiting with Argon2id (§8)Limitación Anti-Sybil con Argon2id (§8)
Due to the impossibility of identifying IPs or circuits on Tor hidden services, each StoreRequest requires a memory-hard proof of work:
Debido a la imposibilidad de identificar IP o circuitos en servicios ocultos de Tor, cada StoreRequest exige una prueba de trabajo de memoria dura:
Protects the SimplePIR matrix buffer against distributed denial-of-service attacks.
Protege el búfer de la matriz SimplePIR previniendo ataques de denegación de servicio distribuido.
1. Deterministic 7-Phase Research Lifecycle 1. Ciclo de Vida de Investigación Determinista de 7 Fases
Every architectural evolution in PHANTOM follows a strict 7-phase methodology. Advancing between phases requires meeting explicit exit criteria. Qualitative assessments are not accepted; validation requires mathematical proofs, formal models (Tamarin / ProVerif), or reproducible empirical simulations.
Toda evolución arquitectónica en PHANTOM sigue una metodología estricta de 7 fases. El avance entre fases requiere cumplir criterios de salida explícitos. No se aceptan evaluaciones cualitativas; la validación exige pruebas matemáticas, modelos formales (Tamarin / ProVerif) o simulaciones empíricas reproducibles.
| PhaseFase | Phase ObjectiveObjetivo de Fase | Artifact PatternPatrón de Artefacto | Exit CriterionCriterio de Salida |
|---|---|---|---|
| Phase 1Fase 1 | Research QuestionsPreguntas de Investigación | RQ-XXX | Formulation of verifiable security hypothesesFormulación de hipótesis de seguridad verificables |
| Phase 2Fase 2 | Literature & Notes ReviewRevisión de Literatura y Notas | LR-XXX / LN-XXX | Cataloging against the Evidence Hierarchy (Levels 1–7)Catalogación contra Jerarquía de Evidencia (Niveles 1–7) |
| Phase 3Fase 3 | Architectural DecisionsDecisiones Arquitectónicas | ADR-XXX | Mandatory analysis of counter-evidence and trade-offsAnálisis obligatorio de evidencia en contra y compensaciones |
| Phase 4Fase 4 | Threat ModelsModelos de Amenazas | TM-XXX | Formal delimitation of boundaries and attacker scopeDelimitación formal de fronteras y alcance del atacante |
| Phase 5Fase 5 | Technical SpecificationsEspecificaciones Técnicas | SPEC-000 (v0.2.0) | Immutable Evaluation BaselineLínea Base Inmutable de Evaluación |
| Phase 6Fase 6 | Formal Proofs & ExperimentsPruebas Formales y Experimentos | VER-XXX / EXP-XXX | Tamarin / ProVerif models and simulation metricsModelos en Tamarin / ProVerif y métricas de simulación |
| Phase 7Fase 7 | Publications & MonographPublicaciones y Monografía | PUB-XXX | Peer-reviewed research articlesArtículos de investigación revisados por pares |
2. Cryptographic Evidence Hierarchy (Levels 1–7) 2. Jerarquía de Evidencia Criptográfica (Niveles 1–7)
Each primitive, parameter, and theoretical claim must be explicitly linked to a source cataloged according to the project's governance standards:
Cada primitiva, parámetro y afirmación teórica debe estar vinculada explícitamente a una fuente catalogada según los estándares de gobernanza del proyecto:
| LevelNivel | Source CategoryCategoría de Fuente | Examples & Standards IncludedEjemplos y Estándares Incluidos |
|---|---|---|
| Level 1Nivel 1 | International / Government StandardsEstándares Internacionales / Estatales | ISO, IEC, IEEE, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) |
| Level 2Nivel 2 | Reference Special PublicationsPublicaciones Especiales de Referencia | NIST SP 800 Series, IETF Standards Track RFCs |
| Level 3Nivel 3 | Consolidated Internet StandardsEstándares Consolidados de Internet | Active RFCsRFCs Activos (RFC 7748, RFC 8439, RFC 5869) |
| Level 4Nivel 4 | Active Technical DraftsBorradores Técnicos Activos | IETF Internet-Drafts |
| Level 5Nivel 5 | Peer-Reviewed Scientific LiteratureLiteratura Científica Revisada por Pares | IACR ePrint, IEEE Xplore, ACM DL, USENIX, NDSS |
| Level 6Nivel 6 | Official Code & DocumentationCódigo y Documentación Oficial | Project documentation, repositories and verified executablesDocumentación de proyecto, repositorios y ejecutables verificados |
| Level 7Nivel 7 | Verifiable Grey LiteratureLiteratura Gris Verificable | Independent audit reports, industry white papersInformes de auditorías independientes, whitepapers industriales |
3. Human Operator Primacy & Audit Rules 3. Primacía del Operador Humano y Reglas de Auditoría
Human Authorship & Manual Verification Rule (GOVERNANCE §3)Autoría Humana y Regla de Verificación Manual (GOVERNANCE §3)
Critical research tasks—including primary literature reading, RQ formulation, cryptographic flaw identification, and specification drafting—are directed and executed directly by the human operator (Eduardo Camarillo [Noir0x63]).
Las tareas críticas de investigación—incluyendo lectura de literatura primaria, formulación de RQs, identificación de fallas criptográficas y redacción de especificaciones—son dirigidas y ejecutadas directamente por el operador humano (Eduardo Camarillo [Noir0x63]).
Manual Verification Rule:Regla de Verificación Manual: No claim, formula, or architectural decision suggested or assisted by AI tools is accepted into the baseline without direct manual verification against primary sources (Levels 1–7).Ninguna afirmación, fórmula o decisión arquitectónica sugerida o asistida por herramientas de IA se acepta en la línea base sin verificación manual directa contra fuentes primarias (Niveles 1–7).
Counter-Evidence Analysis & Retrospective Audit (§4–§5)Análisis de Evidencia en Contra y Auditoría Retrospectiva (§4–§5)
Counter-Evidence Analysis:Análisis de Evidencia en Contra: Each Architectural Decision Record (ADR) requires actively investigating published theoretical attacks, latency/CPU/RAM/bandwidth penalties, and edge-case failure points.Cada Registro de Decisión Arquitectónica (ADR) exige investigar activamente ataques teóricos publicados, penalizaciones de latencia/CPU/RAM/ancho de banda y puntos de falla en casos límite.
Retrospective Audit:Auditoría Retrospectiva: If an audit detects a break in the traceability chainSi una auditoría detecta una ruptura en la cadena trazable PUB → SPEC → TM → ADR → LR → LN → Primary SourceFuente Primaria, the affected component isel componente afectado es invalidated immediatelyinvalidado de inmediato and reverted.y revertido.