{
 "_doc": "One result as verifycorelabs.com prints it: the headline, the problem and the buyer cut (never reworded) from the lab's plain-English account of the result, the one figure a buyer is shown and its limit, and the lab's current claim and limits verbatim, copied at the commit named in source. A field is left out, never reworded, when it uses a word this site keeps for its own process or names a file this site does not serve (not_reprinted).",
 "slug": "ap-memory-bound",
 "company": "OrbitalProof",
 "order": null,
 "rank": 17,
 "served_receipt": "wireless-pqc/results/ap-wide-memory-bound.json",
 "lab_file_older": false,
 "headline": [
  "A computer-checked proof of a simple reservation rule — each half-finished sign-in reserves a full 16-kilobyte slot up front and a fifth is refused — showing that a Wi-Fi access point running the lab's admission-control module never holds more than 64 kilobytes of half-received sign-in messages from devices it has not yet verified, no matter how many devices an attacker makes connect at once"
 ],
 "qualification": [
  "though as built an attacker who starts four sign-ins and never finishes them locks every other device out"
 ],
 "why": [
  "The sign-in messages of the new quantum-resistant Wi-Fi handshakes are large enough to arrive in pieces, and capping memory per connection alone does not stop an attacker who opens many connections at once from exhausting the access point's memory"
 ],
 "buyer": [
  "enterprise Wi-Fi access-point and controller vendors, and Wi-Fi chipset firmware teams, preparing for quantum-resistant sign-in."
 ],
 "figure": "never exceeds 64 KiB, with at most 4 live contexts",
 "figure_from": "claim",
 "limit": "Measured on the Python reference path; no 802.11 frame crosses a radio.",
 "limit_from": "lab scope",
 "quotes": {},
 "claim": "Under an adversary-chosen schedule over an unbounded number of concurrent sessions, the AP's total pre-authentication reassembly residency never exceeds 64 KiB, with at most 4 live contexts.",
 "not_reprinted": [
  "limits"
 ],
 "prior_work": [
  {
   "title": "IP Sysctl",
   "by": "The Linux Kernel documentation (v5.8)",
   "url": "https://www.kernel.org/doc/html/v5.8/networking/ip-sysctl.html"
  },
  {
   "title": "SYN flood",
   "by": "Wikipedia, 2026",
   "url": "https://en.wikipedia.org/wiki/SYN_flood"
  },
  {
   "title": "WPA3 Denial of Service: SAE Resource Exhaustion",
   "by": "Óscar Alfonso Díaz, NCC Group research blog, 2026",
   "url": "https://www.nccgroup.com/research/wpa3-denial-of-service-sae-resource-exhaustion/"
  },
  {
   "title": "Revisiting Client Puzzles for State Exhaustion Attacks Resilience",
   "by": "Mohammad A. Noureddine, Ahmed Fawaz, Tamer Basar, William H. Sanders, arXiv 1807.11892, 2018",
   "url": "https://arxiv.org/abs/1807.11892"
  }
 ],
 "source": {
  "claims_file": "registry/CLAIMS_CURRENT.jsonl",
  "claims_sha256": "81776df15a1498abec7228ea179c952d01c54e031ffd4144498a30660963074b",
  "ranking_file": "views/VALUE_RANKING.md",
  "ranking_sha256": "2e980e26178b34dc49ec1d365f966be292f57d7c636143fc62c12feab72ae470",
  "dossier_sha256": "a1b8472d0b333ee86b37ea67704fb04f3df30feb7d5b463e49fc297c29f540cc",
  "commit": "25d755d2f06518b632c3658ae83f20312daac53e"
 }
}
