2025-himmelberger-drivel

Drivel: A Quantum-Safe Fully Encrypted Protocol Proxy

Abstract

MSc thesis from ETH Zurich on implementing and evaluating quantum-safe fully encrypted protocols. Designs Drivel — an obfs4-style fully encrypted protocol with post-quantum cryptographic primitives — and evaluates it against the GFW's fully-encrypted-traffic detector and the post-quantum threat model. Forwarded to the tor-dev mailing list in late 2025.

Team notes

Forward-looking work — most circumvention protocols still rely on pre-quantum primitives (X25519, AES-GCM). Drivel is one of the first serious treatments of how fully-encrypted protocols evolve once post-quantum becomes a deployment requirement. Lantern relevance: any new protocol Lantern designs (Reflex, Unbounded, etc.) should factor in PQ migration; this thesis is the closest reference for doing it in a circumvention context.

Tags

censors
cngeneric
techniques
fully-encrypted-detectrandom-payload-detect
defenses
obfs4scramblesuitrandomization

findings extracted from this paper