Multi-session security with session-state reveal

Extend the downgrade-resilience and strongest-link security model for transcript-bound hybrid key establishment to multi-session executions in which session state may be revealed.

Background

The formal analysis considers a single handshake routed through an active man-in-the-middle adversary. It does not address interactions among multiple concurrent or sequential sessions, nor does it model the consequences of revealing session state.

The authors list extending the model to multi-session settings with session-state reveal as future work, leaving the security guarantees under these stronger exposure and composition conditions unresolved.

References

Future work includes deriving a tight QROM constant for the transcript-bound combiner, extending the model to multi-session settings with session-state reveal, applying the principle to three-or-more component combiners for post-quantum agility, replacing the analytic energy model with power-instrumented single-board measurements, and integrating the combiner into a complete EDHOC extension evaluated against the existing cipher-suite negotiation.