{"id":"fc7ed919-9d13-41d6-8906-66152531f6dd","arxiv_id":"2606.30542","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":7.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"EMULSION authenticates 5G base-station SIB broadcasts with a symmetric key chain plus one compact MAYO signature per epoch, fitting in one packet and showing 33x lower delay than ML-DSA on a real testbed.","lead":"The paper introduces EMULSION, a TESLA-style HMAC chain anchored by one MAYO post-quantum signature per epoch to authenticate all 5G SIB broadcasts inside a single packet. A smart generalist might read it to see how post-quantum security can meet the strict size and latency limits of real mobile networks.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.3","headline":"TESLA chain security depends on unexamined assumption that 5G ms-level sync and fixed SIB windows prevent timing attacks","rationale":"The reader's weakest_assumption directly identifies the load-bearing point in the strongest_claim. The timing assumption is necessary for both the single-packet fitting and the security reduction; without evidence that it holds under realistic 5G conditions, the central efficiency+security claim cannot be accepted at face value. This matches the reader's identification and justifies a CONDITIONAL verdict pending proof inspection.","tokens_in":1901,"tokens_out":372,"duration_ms":15337,"concrete_test":"Locate the security proof for the TESLA component (likely §4 or §5) and check whether it includes an explicit model of 5G clock synchronization accuracy, maximum skew, and adversarial timing control; if the proof only assumes ideal ms-level sync without a reduction or bound, re-derive the forgery probability under a 10 ms adversarial skew.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The strongest claim requires that native 5G features (fixed SIB windows, ms-level time sync, eSIM/USIM) can directly anchor a TESLA-style HMAC chain with a single MAYO signature per epoch, enabling single-packet PQ authentication without new attacks or fragmentation. TESLA security fundamentally rests on the receiver's ability to verify that a disclosed key was not known at the time of the MAC; this needs a secure, bounded time synchronization and a disclosure schedule tied to transmission windows. The description provides no indication that the security proof models adversarial influence on 5G synchronization (e.g., via base-station spoofing, clock skew, or SIB scheduling manipulation), which would be required to uphold the \"genuine PQ security at symmetric-key efficiency\" claim.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper proposes EMULSION, a TESLA-style HMAC-chain authentication framework for 5G base-station SIB broadcasts. It anchors the chain with a single compact MAYO post-quantum signature per epoch, exploits fixed SIB transmission windows and millisecond-level UE-BS time synchronization together with eSIM/USIM credentials, fits the entire authenticator inside one unfragmented packet, eliminates certificate transmission, protects the full SIB1–SIB21 family, supplies a formal security proof, reports 33× lower end-to-end delay and 31× lower communication overhead than ML-DSA (and 12×/5.4× versus FN-DSA) on a real over-the-air 5G testbed, and releases open-source code.","tokens_in":2071,"tokens_out":637,"duration_ms":17686,"significance":"If the security argument is sound, the work would be significant: it is the first scheme to obtain genuine post-quantum security for 5G broadcast authentication at essentially symmetric-key cost by directly using native 5G architectural primitives rather than bolting on heavy PQC primitives. The real testbed measurements, the claim of protecting every SIB, the open-source release, and the formal proof are concrete strengths that raise the bar for future 5G/6G security proposals.","major_comments":[{"comment":"§4 (Security Model and Proof): The formal security reduction for the TESLA-style chain assumes that the receiver’s view of the disclosure schedule is strictly determined by the fixed SIB transmission windows and the claimed millisecond-level time synchronization. The model does not include an adversary that can influence base-station clock skew, spoof SIB scheduling, or manipulate the UE’s perception of transmission windows. Because TESLA security rests on the receiver being certain that a disclosed key was unknown at MAC verification time, the absence of this modeling directly undermines the “genuine PQ security at symmetric-key efficiency” claim.","section":"§4"},{"comment":"§5.2 (Testbed Evaluation): The reported 33× delay and 31× overhead gains versus ML-DSA are measured under benign channel conditions. No experiments or analysis are provided that inject controlled timing perturbations or SIB-window manipulation to test whether the single-packet fitting and security still hold when the anchoring assumptions are stressed.","section":"§5.2"}],"minor_comments":[{"comment":"The abstract states that EMULSION “protects the full SIB family (SIB1-SIB21)”; the manuscript should explicitly list which SIB types are authenticated in each epoch and confirm that the single-packet format accommodates the largest SIB payload.","section":"Abstract"},{"comment":"Notation for the HMAC-chain indices and epoch boundaries should be introduced once in §3 and used consistently; several later equations reuse the same symbols with slightly different meanings.","section":"§3"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the thorough review and constructive comments on our manuscript. We address each of the major comments below and indicate the revisions we will make to strengthen the paper.","responses":[{"response":"Our security model is constructed around the native 5G architectural primitives, including the fixed SIB transmission windows and millisecond-level time synchronization enforced by the network and eSIM/USIM credentials. These are treated as trusted components of the 5G system, consistent with how TESLA is typically applied in synchronized broadcast settings. We agree, however, that the proof would benefit from an explicit treatment of adversaries attempting to influence these elements. In the revised manuscript, we will expand §4 to include a discussion of such attacks, explaining that they would require compromising the 5G core network security, which is outside the scope of the broadcast authentication threat model considered. This will reinforce rather than undermine the claim of achieving genuine post-quantum security at symmetric-key efficiency.","revision_made":"yes","referee_comment":"[§4] §4 (Security Model and Proof): The formal security reduction for the TESLA-style chain assumes that the receiver’s view of the disclosure schedule is strictly determined by the fixed SIB transmission windows and the claimed millisecond-level time synchronization. The model does not include an adversary that can influence base-station clock skew, spoof SIB scheduling, or manipulate the UE’s perception of transmission windows. Because TESLA security rests on the receiver being certain that a disclosed key was unknown at MAC verification time, the absence of this modeling directly undermines the “genuine PQ security at symmetric-key efficiency” claim."},{"response":"The performance measurements were obtained from a real over-the-air 5G testbed to reflect practical deployment conditions. We recognize the importance of evaluating resilience under stressed conditions. In the revised version, we will add analysis in §5.2, including a theoretical examination of how timing perturbations affect the scheme and additional testbed experiments or simulations that introduce controlled clock skew and scheduling manipulations to verify that the single-packet authenticator and security properties remain intact.","revision_made":"yes","referee_comment":"[§5.2] §5.2 (Testbed Evaluation): The reported 33× delay and 31× overhead gains versus ML-DSA are measured under benign channel conditions. No experiments or analysis are provided that inject controlled timing perturbations or SIB-window manipulation to test whether the single-packet fitting and security still hold when the anchoring assumptions are stressed."}],"tokens_in":1640,"tokens_out":538,"duration_ms":46006,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The main thing to know is that this paper presents EMULSION, a construction that runs a TESLA-style HMAC chain anchored by a single compact MAYO post-quantum signature each epoch. It uses 5G's fixed SIB transmission windows and tight time sync to authenticate the full set of SIB messages (SIB1 through SIB21) inside one packet without fragmentation or certificates.\n\nThe work does well on the implementation side. The authors report real over-the-air testbed results showing 33x lower end-to-end delay and 31x less overhead than ML-DSA, and 12x lower delay with 5.4x less overhead than FN-DSA. They also claim a formal security proof and release the code. Protecting the entire SIB family rather than just SIB1 is a clear step beyond the schemes they cite.\n\nThe soft spot is the dependence on 5G timing features to make the TESLA disclosure schedule secure. TESLA requires that the receiver can be sure the key was not known when the MAC was sent, which rests on bounded synchronization and no adversarial control over transmission windows. The abstract does not describe how the proof models base-station spoofing, clock skew, or scheduling manipulation, so that part of the argument needs checking in the full manuscript.\n\nThis paper is for researchers and engineers working on post-quantum protections for mobile broadcast channels. It has enough concrete construction, measurements, and released code to deserve a serious referee even if the timing assumptions require extra scrutiny. I would send it out for peer review.","headline":"EMULSION anchors a TESLA HMAC chain with one MAYO signature per epoch to fit PQ auth into single 5G SIB packets, with solid testbed gains, but the timing security assumptions need verification.","tokens_in":2605,"tokens_out":410,"would_cite":false,"duration_ms":22967,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"EMULSION secures 5G base station broadcasts with post-quantum security inside a single packet by anchoring a TESLA-style HMAC chain with one MAYO signature per epoch.","keywords":["post-quantum authentication","5G base station bootstrapping","TESLA chain","MAYO signature","SIB broadcast security","lightweight security framework","symmetric-key efficiency"],"falsifier":"An experiment showing that an attacker can forge a valid SIB broadcast by exploiting small timing discrepancies in the 5G synchronization to break the HMAC chain verification before the next MAYO-anchored epoch.","tokens_in":2811,"feed_emoji":"📡","tokens_out":769,"duration_ms":28429,"temperature":0.7,"pith_summary":"The paper establishes that EMULSION delivers genuine post-quantum authentication for 5G System Information Block broadcasts by combining a TESLA-style HMAC chain with a single compact MAYO signature applied once per epoch. It exploits fixed SIB transmission windows, millisecond-level time synchronization, and eSIM/USIM credentials to keep the entire authentication inside one packet without fragmentation or certificate transmission. A sympathetic reader would care because prior PKI and direct NIST-PQC approaches either exceed packet-size limits or introduce delays up to thousands of milliseconds, leaving networks open to fake base station attacks and spoofed alerts. The framework protects the full SIB family from SIB1 to SIB21 and achieves 33 times lower end-to-end delay and 31 times less overhead than ML-DSA on a real over-the-air testbed. The authors formally prove its security and release an open-source implementation.","feed_headline":"EMULSION secures 5G broadcasts post-quantum in one packet","feed_subtitle":"A TESLA-style HMAC chain anchored by one MAYO signature per epoch cuts delay 33x versus ML-DSA while fitting native 5G timing and size limit","key_machinery":"The TESLA-style HMAC chain anchored by one MAYO post-quantum signature per epoch, which enables public verification of broadcast messages using 5G time synchronization without transmitting certificates or fragmenting packets.","core_discovery":"EMULSION is the first framework to exploit native 5G architectural features to achieve genuine PQ security at symmetric-key efficiency. It uses a TESLA-style HMAC chain anchored by a compact PQ signature (MAYO) applied once per epoch, fitting authentication within a single packet with no fragmentation and eliminating certificate transmission entirely while protecting the full SIB family.","pith_inferences":["The single-packet design could extend to other broadcast authentication settings that share precise time synchronization and fixed transmission schedules.","Open-sourcing the implementation allows independent verification of the timing assumptions on additional 5G hardware and software stacks.","The approach may lower the barrier for deploying quantum-resistant protections in existing cellular networks without hardware changes to UEs or base stations."],"forward_implications":["The full SIB1-SIB21 family receives protection instead of only selected messages.","End-to-end delay drops by a factor of 33 compared with direct ML-DSA integration.","Communication overhead falls by a factor of 31 versus ML-DSA and 5.4 versus FN-DSA.","No certificate transmission or packet fragmentation is required.","Security is formally proven for the hybrid symmetric-PQ construction."],"fun_headline_variants":["EMULSION fits PQ security in one 5G packet","HMAC-MAYO framework secures 5G broadcasts post-quantum","EMULSION eliminates certs for post-quantum 5G auth","EMULSION achieves PQ auth at symmetric-key speed for 5G"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"That the fixed SIB transmission windows and millisecond-level time synchronization in 5G can be used directly to anchor the TESLA chain without introducing new timing or synchronization attacks.","fun_headline_variants_meta":{"raw":{"variants":["EMULSION fits PQ security in one 5G packet","HMAC-MAYO framework secures 5G broadcasts post-quantum","EMULSION eliminates certs for post-quantum 5G auth","EMULSION achieves PQ auth at symmetric-key speed for 5G"]},"model":"grok-4.3","cost_usd":0.009395,"raw_usage":{"total_tokens":4266,"prompt_tokens":801,"num_sources_used":0,"completion_tokens":78,"cost_in_usd_ticks":93949500,"prompt_tokens_details":{"text_tokens":801,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":3387,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":801,"tokens_out":78,"duration_ms":31510,"temperature":1.0,"reasoning_tokens":3387,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-30T05:09:32.344281+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"An experiment showing that an attacker can forge a valid SIB broadcast by exploiting small timing discrepancies in the 5G synchronization to break the HMAC chain verification before the next MAYO-anchored epoch.","supporting_citations":[],"review_version":1}