This paper presents a dual-layer pre-authentication framework tailored for regulated cybersecurity environments where identity assurance, post-quantum resilience, and auditability are essential. The proposed architecture combines a hardwarebound root of trust, derived from static SRAM PUF responses, with a dynamic authentication token encapsulated in a blockchainnative, tradable NFT-termed RedToken.The solution integrates elliptic curve cryptography (ECC) for key derivation with NIST-endorsed post-quantum cryptographic (PQC) schemes (Kyber and Dilithium) for secure certificate generation and identity validation. Although the components are individually established in the literature, their orchestration in a unified, compliance-driven architecture-mapped explicitly to the NIST Cybersecurity Framework (CSF) 2.0, the Digital Operational Resilience Act (DORA), and the EU Cyber Resilience Act (CRA)-constitutes the core innovation of this work.The architecture supports implementation across highperformance and resource-constrained environments and is designed to be blockchain-agnostic, with current instantiations leveraging Solana and Hedera for RedToken issuance and verification. While experimental performance evaluation is left for future work, the proposed model is theoretically efficient and scalable, offering a promising foundation for secure identity provisioning in critical infrastructures and regulated digital ecosystems.

Exploiting RedToken for Hardware-Assisted Pre-Authentication for NIST CSF 2.0 Compliance

Felicetti, Carmelo
Conceptualization
;
Sacca', Domenico
Supervision
2025-01-01

Abstract

This paper presents a dual-layer pre-authentication framework tailored for regulated cybersecurity environments where identity assurance, post-quantum resilience, and auditability are essential. The proposed architecture combines a hardwarebound root of trust, derived from static SRAM PUF responses, with a dynamic authentication token encapsulated in a blockchainnative, tradable NFT-termed RedToken.The solution integrates elliptic curve cryptography (ECC) for key derivation with NIST-endorsed post-quantum cryptographic (PQC) schemes (Kyber and Dilithium) for secure certificate generation and identity validation. Although the components are individually established in the literature, their orchestration in a unified, compliance-driven architecture-mapped explicitly to the NIST Cybersecurity Framework (CSF) 2.0, the Digital Operational Resilience Act (DORA), and the EU Cyber Resilience Act (CRA)-constitutes the core innovation of this work.The architecture supports implementation across highperformance and resource-constrained environments and is designed to be blockchain-agnostic, with current instantiations leveraging Solana and Hedera for RedToken issuance and verification. While experimental performance evaluation is left for future work, the proposed model is theoretically efficient and scalable, offering a promising foundation for secure identity provisioning in critical infrastructures and regulated digital ecosystems.
2025
Authentication
Blockchain
Cybersecurity
ECC
Hardware Identity
NIST CSF 2.0
PQC
RedToken
SRAM-PUF
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.11770/414742
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? 0
social impact