This paper presents a dual-layer pre-authentication framework tailored for regulated cybersecurity environments where identity assurance, post-quantum resilience, and auditability are essential. The proposed architecture combines a hardwarebound root of trust, derived from static SRAM PUF responses, with a dynamic authentication token encapsulated in a blockchainnative, tradable NFT-termed RedToken.The solution integrates elliptic curve cryptography (ECC) for key derivation with NIST-endorsed post-quantum cryptographic (PQC) schemes (Kyber and Dilithium) for secure certificate generation and identity validation. Although the components are individually established in the literature, their orchestration in a unified, compliance-driven architecture-mapped explicitly to the NIST Cybersecurity Framework (CSF) 2.0, the Digital Operational Resilience Act (DORA), and the EU Cyber Resilience Act (CRA)-constitutes the core innovation of this work.The architecture supports implementation across highperformance and resource-constrained environments and is designed to be blockchain-agnostic, with current instantiations leveraging Solana and Hedera for RedToken issuance and verification. While experimental performance evaluation is left for future work, the proposed model is theoretically efficient and scalable, offering a promising foundation for secure identity provisioning in critical infrastructures and regulated digital ecosystems.
Exploiting RedToken for Hardware-Assisted Pre-Authentication for NIST CSF 2.0 Compliance
Felicetti, Carmelo
Conceptualization
;Sacca', DomenicoSupervision
2025-01-01
Abstract
This paper presents a dual-layer pre-authentication framework tailored for regulated cybersecurity environments where identity assurance, post-quantum resilience, and auditability are essential. The proposed architecture combines a hardwarebound root of trust, derived from static SRAM PUF responses, with a dynamic authentication token encapsulated in a blockchainnative, tradable NFT-termed RedToken.The solution integrates elliptic curve cryptography (ECC) for key derivation with NIST-endorsed post-quantum cryptographic (PQC) schemes (Kyber and Dilithium) for secure certificate generation and identity validation. Although the components are individually established in the literature, their orchestration in a unified, compliance-driven architecture-mapped explicitly to the NIST Cybersecurity Framework (CSF) 2.0, the Digital Operational Resilience Act (DORA), and the EU Cyber Resilience Act (CRA)-constitutes the core innovation of this work.The architecture supports implementation across highperformance and resource-constrained environments and is designed to be blockchain-agnostic, with current instantiations leveraging Solana and Hedera for RedToken issuance and verification. While experimental performance evaluation is left for future work, the proposed model is theoretically efficient and scalable, offering a promising foundation for secure identity provisioning in critical infrastructures and regulated digital ecosystems.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


