Skip to content

OrbitalProof · Wi-Fi security

An automated attack search against quantum-safe Wi-Fi sign-in

Wi-Fi chip and access-point makers who test a new quantum-resistant sign-in design against a list of known attacks learn only whether it survives the attacks someone thought to write down. To test combinations the list does not spell out, the lab ran an automated search that tries combinations of the list’s moves, given no starting attack sequence, against its hardened models of ten such designs, and, within a small fixed budget, found no combination that got through.

Who did this. The lab’s AI agents did the research and engineering. Nick Harris, founder. CTO of VivaMed BioPharma; co-founder of MedSim.ai, FastRead.io and Formulai. The lab’s track record.

What we showed

The search, given no starting attack sequence, tried 11,200 combinations of moves from the lab’s own list of known attacks against ten hardened designs, and none got through. A separate run the lab reports as exhaustive, of every combination of up to three attack families on all ten designs (this site does not say how a combination of families becomes concrete moves), 53,485 in all, also found none.

Limit.
A null result within a small fixed budget, not a proof that no attack exists. It ran against the lab’s own software models, not real Wi-Fi software, and covers only combinations of the lab’s own list of moves.

The problem

A designer’s own list of attacks tests only what the designer thought of, so the lab’s claim that its repairs close combined attacks rests only on the attacks the lab thought to write down. The search is “unseeded” in one sense only: it was given no starting attack sequence and no hint of which combination works. It still builds its attempts from the lab’s own list of known attack moves, so it can find only combinations of those moves.

What it means for a buyer

If you build or certify Wi-Fi sign-in: a designer’s own attack list only tests what the designer thought of. Here an automated search, given no starting attack sequence, combined moves from the lab’s own list against ten hardened designs and found none that got through. The result covers only combinations of those moves, within a small fixed budget.

Who we expect would buy

Teams we expect would care (no customer or pilot yet): Wi-Fi chipset and access-point vendors, and Wi-Fi certification and test labs, assessing quantum-resistant sign-in designs.

Why now

NIST has published ML-KEM, its standard for quantum-resistant key exchange (the standard), so sign-in designs built on it now need testing against combined attacks, not only the ones on a known list.

Why you can trust the check

As a control, when the lab re-opened one known attack (KRACK, a key-reinstallation attack) in its models, the same search found it, so the search found the one known attack the lab put back. The attacker, its moves and the models are all the lab’s own; it is not a test of real Wi-Fi software.

No outside firm has audited it. How this result’s check works, step by step.

What this does not show yet

  • It ran against the lab’s own software models of the designs, not real Wi-Fi software, within a small fixed search budget: a null result, not a proof that no attack exists.
  • The moves the search can combine are the lab’s own list of known attacks, so the result covers only combinations of those moves. It does not reach an attack the lab did not write down as a move.
  • The search could combine up to ten steps but, within its budget, tried only a small share even of the two-step combinations (about 1,120 per design, roughly 1% of just the two-step combinations, while combinations of up to ten steps were allowed).
  • The search sorts the attacks it tries into types and keeps a “map” of which types it has reached. That the map fills up shows only that it tried varied combinations, not that it covered the space of attacks.

Prior work

Named in the lab’s prior-art search for this result, and credited here.

The exact wording, for a technical reader

The lab’s own sentences and figures for this result, word for word, its limits in plain words where the lab’s text cannot be reprinted and its formal statement: An automated attack search against quantum-safe Wi-Fi sign-in, exact wording. The formal statements of all the results are on one page.

Check it yourself

  • This result’s file: every sentence and figure on this page that is the lab’s own, copied from its current record at the commit the file names.
  • The lab’s result file, copied from its codebase at the commit it names.
  • The file this result’s statement is checked against (a proof, a certificate or a measurement record; the formal statements page says which).
  • The formal statement, set as a formula.
  • OrbitalProof, the company that carries this result.

All resultsContact / M&A

How we show numbers

Every number on this site links to the file it comes from. How each result is checked

  • We never show a number before its file has loaded.
  • A question we have not checked yet is marked as unchecked.
  • A check that found nothing says so.
  • A file with no value for a question says so.
  • A number whose file is missing or has changed is not shown.
  • Two files that disagree about what a number describes are both flagged.
  • A number from too few samples shows its sample size.
  • Two files that give different values are both shown.
  • A file we cannot publish is listed by its fingerprint only.
  • A measurement more than a week old shows its age.
  • A question that does not apply to a page is left off it.
  • A measurement whose program failed is shown as failed.