Přístupnostní navigace
E-application
Search Search Close
Master's Thesis
Author of thesis: Ing. Jiří Hrachovina
Acad. year: 2025/2026
Supervisor: M.Sc. Sara Ricci, Ph.D.
Reviewer: Ing. Petr Dzurenda, Ph.D.
The potential emergence of large-scale quantum computers poses a fundamental threat to public-key mechanisms used in certificate enrollment protocols such as SCEP and EST. This thesis analyzes where these protocols rely on quantum-vulnerable algorithms, particularly RSA, ECDSA, and ECDH, and proposes migration strategies based on hybrid and post-quantum cryptography. Composite ML-DSA signatures are considered for authentication, proof-of-possession, certificates, CSRs, and CMS structures, while ML-KEM-based mechanisms are considered for quantum-resistant key establishment. The thesis compares SCEP and EST and concludes that EST provides a more suitable basis for post-quantum migration due to its mandatory TLS-based security model. Selected classical and post-quantum algorithms are evaluated on the STM32WB55RG microcontroller platform in terms of performance, memory usage, and communication overhead. An experimental post-quantum EST prototype is also implemented. The results show that ML-KEM-512 and ML-DSA-44 are suitable for constrained EST clients and that post-quantum EST enrollment is feasible on Cortex-M4-based STM32WB55RG device.
Post-quantum cryptography, Digital signatures, Public key infrastructure (PKI), Certificate enrollment protocols, Enrollment over secure transport (EST), Simple certificate enrollment protocol (SCEP)
Date of defence
09.06.2026
Result of the defence
Defended (thesis was successfully defended)
Grading
A
Process of defence
Student prezentoval výsledky své práce a komise byla seznámena s posudky. Otázky: Vysvětlete, do jaké míry byla v práci integrována a vyhodnocována komunikace TLS s podporou postkvantových kryptografických algoritmů. V rámci experimentální implementace bylo zjištěno, že protokol EST navazuje více samostatných TLS spojení prostřednictvím UART proxy, v důsledku čehož opakované TLS handshaky dominují celkové době zpracování. Dále bylo zjištěno, že podepisování pomocí algoritmu ML-DSA představuje významnou výpočetní zátěž. Jaká řešení navrhujete pro zmírnění těchto úzkých míst a jaký dopad by měla na celkovou výkonnost navrženého systému? Student obhájil diplomovou práci a odpověděl na otázky členů komise a oponenta.
Language of thesis
English
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Information Security (MPC-IBE)
Composition of Committee
Ing. Ondřej Krajsa, Ph.D. (člen) Ing. Jan Skapa, Ph.D. (člen) Ing. Róberta Hlavatá, Ph.D. (člen) JUDr. Mgr. Jakub Harašta, Ph.D. (člen) doc. Ing. Rastislav Róka, PhD. (předseda) doc. Ing. Jan Jeřábek, Ph.D. (místopředseda) Ing. Ondřej Klíčník (člen) Ing. Vojtěch Kovanda (člen)
Supervisor’s reportM.Sc. Sara Ricci, Ph.D.
Grade proposed by supervisor: A
Reviewer’s reportIng. Petr Dzurenda, Ph.D.
Grade proposed by reviewer: A
Responsibility: Mgr. et Mgr. Hana Odstrčilová