The major
contributions of this work are summarized as follows:
• A downgrade (rollback) attack is identified and demon-
strated against naive context-adaptive Kyber key encap-
sulation, in which an active on-path adversary forces
negotiation to a weaker security level without detection
by either endpoint.
• A rollback-resistant negotiation protocol is proposed that
binds the negotiated security level into a transcript hash
and verifies it via a shared-secret-derived MAC, causing
any tampering to result in handshake rejection.
• A comprehensive experimental evaluation is conducted,
implementing both the vulnerable baseline and the pro-
tected protocol across all three Kyber security levels, to
demonstrate the attack and its mitigation and to quan-
tify the overhead introduced by the proposed protection
mechanism.
