Skip to content

About

Post-Quantum Zero-Trust Security Mesh — ML-KEM-768 (FIPS 203), TEE enclaves, Cedar policy engine, eBPF moving-target defense

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Q-Shield — Post-Quantum Zero-Trust Security Mesh

A production-grade reference implementation of a Post-Quantum Zero-Trust Security Mesh — combining NIST FIPS 203 (ML-KEM), confidential computing enclaves, Cedar formal policy enforcement, and eBPF-driven attack-surface shrinking.

Q-Shield

Overview

The imminent arrival of cryptographically relevant quantum computers (CRQCs) threatens classical public-key cryptography (RSA, ECDH, ECDSA). Adversaries are already running Harvest-Now-Decrypt-Later campaigns — intercepting and storing encrypted traffic for future decryption.

Q-Shield answers this with a three-layer defense:

  1. Lattice-based key encapsulation (ML-KEM / FIPS 203) at network ingress gateways — replacing classical key exchange.
  2. Hardware-enforced Confidential Computing TEEs (Intel SGX, AMD SEV-SNP, Intel TDX) — protecting data in use, not just in transit and at rest.
  3. Autonomous attack-surface shrinking using eBPF, dynamic route mutation, and deterministic formal logic policy (Cedar).

This repository is a fully working implementation with a Rust/Axum backend, a React/Tailwind dashboard, and a live demo dataset — every module is functional, not a stub.

Key Features

🛡️ Post-Quantum Cryptography (PQC)

  • ML-KEM-768 (FIPS 203) — full working lattice KEM: NTT, Centered Binomial Distribution sampling, KeyGen / Encaps / Decaps. Key sizes: pk = 1184 B, sk = 2400 B, ct = 1088 B.
  • ML-DSA-65 (FIPS 204) — lattice-based digital signatures (KeyGen / Sign / Verify).
  • Hybrid Key Exchange — dual X25519 + ML-KEM-768 agreement for the 2025–2028 migration window.
  • Cryptographic Agility Protocol (CAP) — dynamic algorithm negotiation with automatic HQC fallback if lattice math is ever broken.
  • Constant-time operations — NTT and comparisons implemented to neutralize cache-timing side channels.

🔐 Confidential Computing Enclaves

  • Enclave Manager — unified abstraction over SGX, SEV-SNP, TDX, and Simulation modes.
  • Remote Attestation — quote generation & verification with MRENCLAVE-style measurement tracking.
  • Gramine LibOS interface — system-call translation, AEX (Asynchronous Enclave Exit) mitigation, thread pooling.
  • Memory isolation — simulated 128 MB isolated enclave memory.

📜 Formal Policy Enforcement (Cedar)

  • Cedar Policy Engine — full RBAC/ABAC evaluation with permit/forbid statements, when clauses, and principal/action/resource scoping. Returns ALLOW/DENY.
  • Verification Sandwich — schema grounding, policy synthesis, static contradiction analysis, unreachable-state detection.
  • Dynamic Taint Tracking — 64-bit session bitmasks with UNTRUSTED_SOURCE, ACCESS_PRIVATE, EXFILTRATION tags.
  • Lethal Trifecta Mitigation — automatically blocks sessions that combine untrusted source + private access + exfiltration capability.

🌐 eBPF & Moving Target Defense

  • XDP Fast Path — simulated in-kernel packet processing with DROP / PASS / REDIRECT verdicts and sub-microsecond decision latency.
  • Moving Target Defense (MTD) — ephemeral IPv6 overlay routing, route mutation on anomaly detection, honeypot redirection.
  • BPF-LSM — syscall monitoring, fail-closed heartbeat, enclave health checking.
  • Two-stage Anomaly Detection — Stage 1 in-kernel fast path + Stage 2 deep behavioral analysis with combined scoring.

🪪 Identity & Audit

  • SPIFFE/SPIRE — workload identity registration and trust domain management.
  • X.509 SVID — certificate generation, validation, and attestation binding.
  • UCEE Receipts — Ed25519-signed Universal Confidential Execution Evidence receipts chaining payload hash, policy bundle hash, TEE measurement hash, and prior receipt hash.
  • Hash Chain Audit Log — append-only, tamper-evident, externally verifiable.

Tech Stack

Layer Technology
Backend Rust, Axum, Tokio, SQLx (SQLite), Tower
Crypto ML-KEM-768, ML-DSA-65, X25519, AES-256-GCM, ChaCha20-Poly1305, Ed25519
Frontend React 18, TypeScript, Vite 5, Tailwind CSS, Recharts, lucide-react
Observability tracing / tracing-subscriber

Project Structure

qShield/
├── backend/                      # Rust + Axum API server
│   ├── Cargo.toml
│   └── src/
│       ├── main.rs               # Server entrypoint & routing
│       ├── config.rs             # Environment-based configuration
│       ├── api/                  # HTTP handlers
│       │   ├── gateway.rs        #   KEM encapsulate/decapsulate & key APIs
│       │   ├── policy_api.rs     #   Policy CRUD, evaluate, verify
│       │   ├── audit_api.rs      #   Audit chain & stats
│       │   └── health.rs         #   Health, metrics, mesh status, WebSocket
│       ├── crypto/               # Post-quantum crypto core
│       │   ├── ml_kem.rs         #   FIPS 203 ML-KEM-768 (NTT, CBD, KeyGen/Encaps/Decaps)
│       │   ├── ml_dsa.rs         #   FIPS 204 ML-DSA-65 signatures
│       │   ├── hybrid.rs         #   X25519 + ML-KEM hybrid key exchange
│       │   ├── cap.rs            #   Cryptographic Agility Protocol
│       │   └── constant_time.rs  #   Constant-time primitives
│       ├── enclave/              # Confidential computing
│       │   ├── tee.rs            #   Enclave manager (SGX/SEV-SNP/TDX/Simulation)
│       │   ├── attestation.rs    #   Remote attestation quotes
│       │   └── gramine.rs        #   Gramine LibOS interface
│       ├── policy/               # Formal policy engine
│       │   ├── cedar.rs          #   Cedar RBAC/ABAC evaluator
│       │   ├── verifier.rs       #   Verification Sandwich
│       │   ├── taint.rs          #   Dynamic taint tracking
│       │   └── lethal_trifecta.rs#   Lethal Trifecta blocker
│       ├── ebpf/                 # Attack-surface shrinking
│       │   ├── xdp.rs            #   XDP fast-path packet processing
│       │   ├── mtd.rs            #   Moving Target Defense
│       │   ├── lsm.rs            #   BPF-LSM kernel integrity
│       │   └── anomaly.rs        #   Two-stage anomaly detection
│       ├── identity/             # SPIFFE/SPIRE identity
│       │   ├── spiffe.rs
│       │   └── svid.rs
│       └── audit/                # Tamper-evident audit
│           ├── ucee.rs           #   Ed25519-signed UCEE receipts
│           └── chain.rs          #   Hash-chained audit log
│
└── frontend/                     # React dashboard
    ├── src/
    │   ├── App.tsx               # Routing & layout
    │   ├── api/client.ts         # REST + WebSocket client
    │   ├── components/
    │   │   ├── Dashboard/        # Stat cards, threat alerts, mesh topology
    │   │   ├── Policy/           # Policy list & interactive evaluator
    │   │   ├── Audit/            # UCEE receipt chain viewer
    │   │   └── Crypto/           # KEM key & encaps/decaps demo
    │   └── styles/globals.css    # Tailwind + custom theme
    └── ...

Getting Started

Prerequisites

  • Rust 1.70+ (edition 2021)
  • Node.js 18+ & npm
  • SQLite (bundled via SQLx, no install needed)

1. Run the Backend

cd backend
cargo run

The server starts on http://localhost:8443 with:

Q-Shield mesh listening on http://0.0.0.0:8443
API available at        http://0.0.0.0:8443/api/v1/health
WebSocket at            ws://0.0.0.0:8443/api/v1/ws

2. Run the Frontend

cd frontend
npm install
npm run dev

Open http://localhost:5173 (Vite proxies /api to the backend).

Build for Production

# Backend release build
cd backend && cargo build --release

# Frontend production build
cd frontend && npm run build && npm run preview

API Reference

Method Endpoint Description
GET /api/v1/health System health & status
GET /api/v1/metrics Security metrics
GET /api/v1/mesh/status Mesh topology status
WS /api/v1/ws Real-time event stream
POST /api/v1/keys/generate Generate ML-KEM keypair
GET /api/v1/keys/public Get public key
POST /api/v1/encapsulate ML-KEM encapsulation (shared secret + ciphertext)
POST /api/v1/decapsulate ML-KEM decapsulation
GET /api/v1/policies List policies
POST /api/v1/policies Add policy
DELETE /api/v1/policies/:id Remove policy
POST /api/v1/policies/evaluate Evaluate a request against policies
GET /api/v1/policies/verify Verify policy-set consistency
GET /api/v1/audit List audit records
GET /api/v1/audit/:id Get audit record
GET /api/v1/audit/chain/verify Verify audit chain integrity
GET /api/v1/audit/stats Audit statistics

Dashboard

The React dashboard ships with four views:

  • Dashboard — live security posture: stat cards, security health table, threat alerts, and SVG mesh topology.
  • Policies — browse/create/delete Cedar policies and interactively test evaluation with ALLOW/DENY results.
  • Audit Log — inspect the Ed25519-signed UCEE receipt hash chain and verify chain integrity.
  • Crypto — inspect ML-KEM keys, view the public key, and run encapsulate/decapsulate demos.

Security Model

  Ingress Payload (encrypted)
       │
       ▼
┌─────────────────────────┐    ┌──────────────────────────┐
│ Lattice Gateway         │    │ Confidential Enclave     │
│ FIPS 203 ML-KEM-768     │───▶│ SGX / SEV-SNP / TDX      │
│ decapsulate shared key  │    │ memory-isolated execution │
└─────────────────────────┘    └────────────┬─────────────┘
                                            ▼
                              ┌──────────────────────────┐
                              │ Zero-Trust Check (Cedar) │
                              │ schema validation        │
                              │ taint analysis           │
                              │ lethal-trifecta blocking │
                              └────────────┬─────────────┘
                                           ▼
                              ┌──────────────────────────┐
                              │ Target microservice      │
                              │   + Ed25519 UCEE receipt │
                              └──────────────────────────┘

Fail-closed by design: any parse error, schema mismatch, taint violation, or DENY decision terminates execution immediately and emits a signed audit receipt.

Roadmap

  • Real eBPF / XDP kernel module hooks (currently simulated userspace)
  • SGX/SEV-SNP/TDX hardware attestation integration
  • Envoy / sidecar mesh integration
  • ML-KEM-1024 high-security tier
  • HQC code-based KEM fallback implementation

License

MIT

About

Post-Quantum Zero-Trust Security Mesh — ML-KEM-768 (FIPS 203), TEE enclaves, Cedar policy engine, eBPF moving-target defense

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages