{"id":"f27af388-5de5-4691-b2d0-db531732c842","arxiv_id":"2608.05087","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"Falcon-512 is the only NIST PQC signature that fits the SAE J3161 sidelink transport block, but it fails the 90% packet-delivery threshold above traffic level-of-service A under LOS, while ECDSA works through LOS C.","lead":"This paper asks whether post-quantum digital signatures can fit in the radio channel used by connected vehicles and still deliver safety messages reliably. It finds that only Falcon-512 fits the current standard, and it meets the reliability threshold only in light traffic with clear line of sight.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Falcon-512 PDR boundary rests on a non-J3161-compliant Mode 4 SPS model; missing SPS+One-Shot and SPS_004 rounding could shift the LOS A/B threshold.","rationale":"The reader's weakest assumption correctly identifies the Mode 4 SPS model. I agree because the paper's novelty claim is a standards-grounded deployment boundary, but the boundary is an output of a simulator that omits two mandatory J3161 behaviors. The concern is load-bearing because the LOS A to B transition is the empirical crux: if SPS+One-Shot were present, the mechanism is designed to break repeated half-duplex collisions that disproportionately affect wide-grant transmissions like Falcon-512; it could plausibly lift Falcon-512's LOS B PDR above 90%. Conversely, SPS_004 rounding would make Falcon-512 consume 10 subchannels on certificate transmissions, worsening PDR. Since these effects oppose each other, the current simulation cannot establish even the direction of the error, so the central threshold is unverified. I do not elevate the certificate-size undercount or the single-run issue to 'most load-bearing' because both push the result in a direction that does not threaten the qualitative conclusion (larger certificates make Falcon worse; one run is a confidence problem, not a model-fidelity problem). The paper deserves credit for explicitly listing these limitations; the issue is that a conclusion stated with this much precision about traffic LOS boundaries requires a compliant simulation.","tokens_in":21390,"tokens_out":13217,"duration_ms":151685,"concrete_test":"Modify OpenCV2X to implement (1) SPS+One-Shot as specified in SAE J3161 §7.3.3 and (2) the SPS_004 subchannel rounding rule from §8.6 (any required allocation greater than 50% and less than 100% of available subchannels is rounded up to 100%). Then rerun the LOS scenarios for traffic LOS A, B, and C for both ECDSA and Falcon-512 with at least 10 independent random seeds, and recompute mean PDR using the same 5GAA P-190033 sliding window. If Falcon-512 mean PDR at LOS B remains below 90% across all seeds, the paper's deployment boundary stands; if any seed or the mean crosses 90%, the boundary and the associated conclusion shift.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central quantitative claim—that Falcon-512 meets the 90% PDR threshold only at traffic LOS A and fails at LOS B and above—is produced by an OpenCV2X simulation whose Mode 4 SPS implementation the paper itself concedes is not SAE J3161-compliant in two named ways. The Conclusion states that SPS+One-Shot (J3161 §7.3.3) is not implemented, and that the SPS_004 subchannel constraint (J3161 §8.6) is not implemented, so the 7-subchannel allocation used for Falcon-512 certificate-bearing SPDUs is one a compliant implementation would round up to 10 subchannels. The LOS B failure is the empirical hinge of the paper's deployment boundary, and it is observed under a scheduler that both omits the standard's collision-breaking mechanism and under-allocates subchannels during certificate transmissions. The direction of the resulting bias is not determined: adding SPS+One-Shot could reduce persistent half-duplex collisions and raise Falcon-512's PDR above 90% at LOS B, while enforcing SPS_004 would consume more resources and lower it. Until the simulation is rerun with both features, the specific threshold 'LOS A only' cannot be considered a standards-grounded result.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript asks which NIST-standardized post-quantum digital signature schemes can be carried by the current SAE J3161 C-V2X PC5 Mode 4 sidelink profile and what communication-level penalty the viable scheme incurs. The authors compute IEEE 1609.2 secured-message SPDU sizes for ECDSA P-256, Falcon-512, Dilithium-2, and SPHINCS+, and show that Dilithium-2 and SPHINCS+ exceed the 2,481-byte SAE J3161 transport-block ceiling even under the most permissive MCS/subchannel configuration. Falcon-512 is carried forward and compared with ECDSA P-256 in an OpenCV2X/SUMO co-simulation across six traffic levels-of-service and LOS/NLOS propagation, using PDR and end-to-end latency at a roadside unit as KPIs. The reported results are that Falcon-512 meets the 90% PDR threshold only at LOS traffic level-of-service A, ECDSA meets it through LOS level-of-service C, neither scheme meets it under NLOS, and latency is essentially unaffected by algorithm choice.","tokens_in":21608,"tokens_out":4675,"duration_ms":59588,"significance":"If the deployment boundary is correct, the paper makes a useful and timely contribution: it gives standards bodies a concrete, checkable feasibility screen and identifies spectrum efficiency rather than cryptographic computation time as the binding constraint for PQC on LTE-V2X Mode 4. The transport-block arithmetic in Tables 1-3 is transparent, uses standard sizes, and is internally consistent. The simulation is a forward model with no fitted parameters, and the use of OpenCV2X plus liboqs is a reasonable and reproducible setup. The main quantitative claim, however, rests on a Mode 4 SPS implementation that the paper itself concedes is not SAE J3161-compliant in two named ways, so the specific 'LOS A only' threshold cannot currently be regarded as a standards-grounded result.","major_comments":[{"comment":"The central LOS-A-only deployment boundary is produced by an OpenCV2X Mode 4 SPS model that the manuscript itself concedes omits two SAE J3161 mechanisms. The Conclusion states that SPS+One-Shot (J3161 Section 7.3.3) is not implemented and that the SPS_004 subchannel constraint (J3161 Section 8.6) is not implemented, so the 7-subchannel allocation used for Falcon-512 certificate-bearing SPDUs is one that a fully compliant implementation would round up to 10 subchannels. Because the reported failure at LOS level-of-service B is the empirical hinge of the paper, this is load-bearing. Please rerun the evaluation with both mechanisms implemented, or, if that is not possible, rewrite the abstract, discussion, and conclusion so that the threshold is explicitly conditional on a non-J3161-compliant scheduler. The direction of the resulting bias is not determined a priori: SPS+One-Shot could raise Falcon-512 PDR by breaking persistent half-duplex collisions, while SPS_004 rounding would consume more resources and could lower it.","section":"Co-Simulation Platform; Conclusion (Limitations)"},{"comment":"The explanation for Falcon-512's short-range failures rests on the claim that the SPS grant settles at a steady-state 4-subchannel allocation and that certificate-bearing SPDUs are then fragmented by RLC UM across two transmission periods. This is a strong claim about Mode 4 behavior, but the paper gives no standards citation or simulator code trace showing that a packet-size change from certificate mode to digest mode does not trigger grant regeneration. If this behavior is an artifact of OpenCV2X's simplified grant management rather than a property of a compliant SPS implementation, then the '40% subchannel occupancy' mechanism used to explain the LOS B PDR drop is unsupported. Please provide the relevant OpenCV2X code path or a 3GPP/SAE reference establishing that the grant remains at the digest size when a larger certificate-bearing packet arrives.","section":"Sidelink Resource Allocation Feasibility"},{"comment":"The aggregate PDR values that support the headline threshold are reported only in prose in the Discussion (94.89%, 95.40%, 95.02% for ECDSA at LOS A-C; 92.76% and 79.86% for Falcon at LOS A-B). They do not appear in any table, and Figure 3 shows PDR versus distance curves without a corresponding aggregate-PDR table or confidence intervals. Since the central claim is a threshold comparison, the paper should provide a table of mean PDR (with standard deviation or confidence intervals) for every scenario, in addition to the distance-resolved curves.","section":"Evaluation Outcomes; Discussion"}],"minor_comments":[{"comment":"The Falcon-512 certificate-mode SPDU size is listed as 1,739 bytes in Table 3 but as 1,735 bytes in Table 2 and in the text of the Method section; these numbers should be reconciled.","section":"Table 3"},{"comment":"The acronym 'SLH-DHA' appears in the text where 'SLH-DSA' is intended; please correct the typo.","section":"Preliminaries (V2X Security and Post-Quantum Cryptography)"},{"comment":"The text and references use both 'SAE J3161' and 'SAE J3161/1' for the deployment profile; the manuscript should use one consistent designation.","section":"References and Standard Designation"},{"comment":"The fact that OpenCV2X does not implement SPS+One-Shot and SPS_004 is disclosed only in the Conclusion; it should also be stated in the Method section where the simulator is described, so that the reader knows the compliance status of the scheduler before seeing the results.","section":"Method (SAE J3161 Deployment Profile)"},{"comment":"The six subplots of Figure 3 would be easier to read if each subplot had labeled axes and the legend were placed once; as printed, the small subplot style makes it hard to compare the short-range PDR values that carry the LOS B threshold argument.","section":"Figure 3"}],"recommendation":"major_revision","confidential_remarks":"The paper is in scope for a networking/performance venue and the feasibility arithmetic is a useful contribution. My recommendation of major_revision is driven entirely by the gap between the paper's headline deployment threshold and the conceded non-compliance of the simulator's SPS model. If the authors cannot rerun with a J3161-compliant SPS implementation, they should substantially weaken the threshold claim rather than present it as standards-grounded. The citation pattern and novelty claims are otherwise reasonable."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Bottom line: the transport-block feasibility check is clean, checkable, and likely to survive independent scrutiny; the simulated deployment boundary (Falcon-512 usable only at traffic LOS A) is plausible but not yet standards-grounded, because the paper's own Limitations section concedes the simulator omits two SAE J3161 requirements. I would send this to peer review, expecting the scheduler-compliance question to drive a revision.\n\nWhat is genuinely new: a crisp arithmetic result that Dilithium-2's digest-bearing SPDU (2,495 B) exceeds the J3161 TBS ceiling (2,481 B), eliminating the two most likely PQC candidates on spectrum grounds before any simulation is needed. The full-stack Mode 4 co-simulation then produces an interesting emergent mechanism: SPS grants settle at 4 subchannels because digest-mode packets dominate, and certificate-bearing Falcon BSMs get fragmented by RLC UM across two transmission periods, with loss of either fragment killing the BSM. That mechanism, plus the NLOS result (propagation binds, algorithm choice is irrelevant), is the paper's real contribution. The thorough Limitations section is a credit.\n\nThe soft spots are real, though. The headline LOS A/B threshold is produced by a scheduler that (a) does not implement SPS+One-Shot (J3161 7.3.3) and (b) uses a 7-subchannel certificate allocation that SPS_004 (8.6) would round up to 10. The paper says in as many words that a fully compliant implementation would not use that operating point. The direction of the bias is unknown—One-Shot would reduce half-duplex collisions, the 10-subchannel rounding would make certificate transmissions far more expensive—so the specific 'LOS A only' number cannot be taken as a standards-grounded result. The qualitative picture (spectrum efficiency, not compute, is the binding constraint) is robust; the boundary could move.\n\nTwo smaller items. The simulation is a single run with no confidence intervals, and Falcon's LOS A PDR (92.76%) is close enough to the 90% line that noise matters. And the certificate size model (105 B overhead plus public key) appears to omit the CA's signature on the certificate—another ~666 B for Falcon—which would change the certificate-mode subchannel arithmetic.\n\nWho this is for: SAE/IEEE standards committees and anyone planning PQC migration for V2X. The feasibility arithmetic and the simulation design deserve a serious referee; the compliance gaps are fixable in revision. Recommend: accept for review, expect major revision.","headline":"Clean TBS arithmetic makes Falcon-512 the only viable NIST PQC scheme under SAE J3161, but the simulated LOS A-only PDR boundary rests on a scheduler the paper itself concedes is non-compliant.","tokens_in":22246,"tokens_out":9039,"would_cite":true,"duration_ms":101230,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Falcon-512 is the only NIST post-quantum signature that fits today's C-V2X sidelink profile, but even it fails the 90% packet-delivery threshold except at the lightest traffic level under line-of-sight propagation.","keywords":["post-quantum cryptography","C-V2X","Mode 4 sidelink","SAE J3161","Falcon-512","packet delivery ratio","transport block size","vehicular safety communication"],"falsifier":"Run the same 24-scenario comparison in a Mode 4 simulator that implements SPS+One-Shot and the SPS_004 subchannel constraint, or in an over-the-air field test on production-spec LTE-V2X radios, and check whether Falcon-512's line-of-sight PDR stays above 90% only at traffic level-of-service A; if a compliant allocator keeps it above 90% at level B, the paper's specific deployment boundary is wrong, and if PDR drops further, the spectrum-efficiency conclusion is strengthened.","tokens_in":21147,"feed_emoji":"🚗","tokens_out":15070,"duration_ms":140388,"temperature":0.7,"pith_summary":"The paper asks whether NIST's post-quantum digital signatures can replace ECDSA in safety-critical C-V2X sidelink messaging without breaking the current standards profile, a question that matters because vehicles fielded now may still be operating when a quantum computer arrives. It computes the full secured-message sizes for ECDSA P-256, Falcon-512, Dilithium-2, and SPHINCS+ and checks them against the SAE J3161 transport-block ceiling. Dilithium-2 and SPHINCS+ are too large for any permitted configuration, while Falcon-512 just fits. In a full-stack Mode 4 co-simulation across six traffic levels-of-service and two propagation conditions, Falcon-512 meets the 90% packet-delivery threshold only at the lightest traffic level under line-of-sight propagation, whereas ECDSA meets it through the third level. The paper concludes that spectrum efficiency, not cryptographic computation time, is the primary deployment constraint.","feed_headline":"Falcon-512 fits C-V2X, fails 90% delivery above lightest traffic","feed_subtitle":"The only NIST post-quantum signature that fits today's sidelink spec delivers 90% only at lightest traffic, LOS.","key_machinery":"The load-bearing machinery is the transport-block size (TBS) ceiling of 2,481 bytes that SAE J3161 imposes at modulation-and-coding index 11 with a full ten-subchannel allocation, combined with the IEEE 1609.2 secured protocol data unit format and the SAE J2945/1 certificate policy (one full pseudonym certificate in every five basic safety messages, a compact 8-byte HashedId8 digest in the other four). The TBS ceiling acts as the feasibility filter that eliminates Dilithium-2 and SPHINCS+; the Mode 4 semi-persistent scheduling grant fixes how many subchannels each packet occupies; and the certificate policy determines how often the expensive full-certificate packet appears. For Falcon-512 the mechanism that produces the reliability penalty is that the grant stabilizes at four subchannels, occupying 40% of the available sidelink pool per transmission, and the certificate-bearing packet is split by radio link control unacknowledged-mode fragmentation over two transmission periods, so losing either fragment discards the whole message.","core_discovery":"On the paper's own terms, the central discovery is a two-part feasibility result. The SAE J3161 transport-block size ceiling of 2,481 bytes at modulation-and-coding index 11 with all ten subchannels eliminates Dilithium-2, whose digest-only secured packet alone is 2,495 bytes, and SPHINCS+, whose signature alone is 7,856 bytes; only Falcon-512 fits, with a certificate-bearing secured packet of 1,735 bytes needing seven subchannels and a digest-mode packet of 741 bytes needing four. Fitting is not sufficient: under Mode 4 semi-persistent scheduling the grant settles at four subchannels because four of every five basic safety messages carry only a compact 8-byte digest, and certificate-bearing packets are fragmented across two transmission periods by the unacknowledged radio link control layer. In the line-of-sight case Falcon-512 sustains 92.76% mean packet delivery at traffic level-of-service A, drops to 79.86% at level B, and never meets the 90% threshold again, while ECDSA stays above 90% through level C; under non-line-of-sight neither algorithm reaches 90% at any distance. Mean latency stays near 52 ms and the 95th percentile within 96-98 ms, under the 100 ms safety budget, so the paper's stated conclusion is that spectrum efficiency, not cryptographic computation time, is the primary deployment constraint.","pith_inferences":["The paper leaves implicit that its 7-subchannel certificate operating point is not what a fully J3161-compliant allocator would use; the SPS_004 rule would round that allocation up to a full ten subchannels, so a compliant implementation would likely show worse, not better, PDR for Falcon-512.","Because ECDSA fails as badly as Falcon-512 under non-line-of-sight, the inference for deployment planners is that PQC migration should not be blocked on NLOS performance alone; the binding fix in urban canyons is coverage design, and algorithm choice only matters once coverage is adequate.","A testable extension would be to run the same comparison with SPS+One-Shot enabled; if half-duplex repetitive collisions are a major loss source at higher traffic levels, Falcon-512's penalty at level B could shrink, whereas if the dominant loss is interference from its four-subchannel occupancy, the paper's threshold would stand.","The near-constant latency across algorithms suggests that for capacity planning on Mode 4, PQC signature generation and verification can be treated as negligible; the scarce resource is subchannels, not CPU cycles, which points standards work toward payload compression, MCS extensions, or NR-V2X rather than faster hardware."],"forward_implications":["Dilithium-2 and SPHINCS+ cannot be deployed on the current SAE J3161 profile without protocol changes such as packet segmentation, hybrid schemes, or a wider permitted MCS range.","Falcon-512 is physically deployable but only at very light traffic under line-of-sight; at traffic level-of-service B and above its PDR falls below 90% even at close range, so any near-term PQC migration on LTE-V2X Mode 4 would be confined to sparse, LOS-dominated conditions.","Under non-line-of-sight propagation neither ECDSA nor Falcon-512 meets the 90% threshold, so improving PDR in urban canyons requires infrastructure changes such as RSU placement, antenna orientation, or relay integration rather than a different signature algorithm.","The latency results show that PQC signing and verification time is not a bottleneck for Mode 4; delivered packets meet the 100 ms safety budget with mean latency near 52 ms, so standards work should focus on payload size and resource allocation.","If the standard were extended to higher MCS indices or if NR-V2X's higher data rates were available, Falcon-512's subchannel requirement could shrink and its viable traffic range could widen."],"supporting_citations":[{"why":"It defines the J3161 deployment profile whose permitted MCS set and 2,481-byte TBS ceiling form the feasibility filter.","marker":"SAE International 2024"},{"why":"It sets the 90% PDR reliability threshold, the 100 ms latency budget, and the every-fifth-BSM full-certificate policy used in the scenarios.","marker":"SAE International 2020"},{"why":"It defines the IEEE 1609.2 signed SPDU structure, certificate and digest fields, and the ECDSA baseline that PQC must replace.","marker":"IEEE 2022"},{"why":"It supplies the MCS-to-TBS mapping and resource-block calculations used to compute subchannel requirements.","marker":"3GPP 2018b"},{"why":"It provides Falcon-512's signature and public-key sizes, 666 and 897 bytes, used in the SPDU-size computation.","marker":"Fouque et al. 2017"},{"why":"It provides Dilithium-2 (ML-DSA-44) signature and public-key sizes, making it the scheme whose digest-mode SPDU exceeds the TBS ceiling.","marker":"NIST 2024"},{"why":"It provides the SPHINCS+ parameter sizes that place its 7,856-byte signature far beyond the transport-block ceiling.","marker":"National Institute of Standards and Technology 2024b"},{"why":"It defines the M.2135 LOS and urban-microcell NLOS path-loss models used in the two propagation configurations.","marker":"ITU-R 2009"},{"why":"It supplies the Mode 4 C-V2X network simulator used for the full-stack co-simulation.","marker":"McCarthy and O'Driscoll 2019"}],"fun_headline_variants":["Falcon-512 only PQC that fits C-V2X, but fails 90% above lightest traffic","Falcon-512 fits C-V2X but only meets 90% PDR at lightest traffic","C-V2X PQC: Falcon-512 barely fits, fails 90% above lightest traffic","Only Falcon-512 fits C-V2X sidelink; fails 90% beyond lightest traffic","Falcon-512 fits C-V2X but misses 90% PDR except at lightest traffic"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the simulator's Mode 4 resource-selection behavior represents real compliant operation, yet the paper concedes it omits SPS+One-Shot and the J3161 SPS_004 subchannel rule, so the 7-subchannel allocation used for Falcon certificate transmissions is one a fully compliant implementation would not use.","fun_headline_variants_meta":{"raw":{"variants":["Falcon-512 only PQC that fits C-V2X, but fails 90% above lightest traffic","Falcon-512 fits C-V2X but only meets 90% PDR at lightest traffic","C-V2X PQC: Falcon-512 barely fits, fails 90% above lightest traffic","Only Falcon-512 fits C-V2X sidelink; fails 90% beyond lightest traffic","Falcon-512 fits C-V2X but misses 90% PDR except at lightest traffic"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000623,"raw_usage":{"total_tokens":3026,"prompt_tokens":1229,"completion_tokens":1797,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":845,"completion_tokens_details":{"reasoning_tokens":1662}},"tokens_in":845,"tokens_out":1797,"duration_ms":15065,"temperature":1.0,"reasoning_tokens":1662,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T05:33:56.460843+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the same 24-scenario comparison in a Mode 4 simulator that implements SPS+One-Shot and the SPS_004 subchannel constraint, or in an over-the-air field test on production-spec LTE-V2X radios, and check whether Falcon-512's line-of-sight PDR stays above 90% only at traffic level-of-service A; if a compliant allocator keeps it above 90% at level B, the paper's specific deployment boundary is wrong, and if PDR drops further, the spectrum-efficiency conclusion is strengthened.","supporting_citations":[{"cited_title":"IEEE Standard for Wireless Access in Vehicular Environments (WAVE) - Certificate Management Interfaces for End Entities","cited_arxiv_id":null,"evidence_quote":"It defines the IEEE 1609.2 signed SPDU structure, certificate and digest fields, and the ECDSA baseline that PQC must replace."},{"cited_title":"2024.Module-Lattice-Based Digital Signature Standard.Federal Information Processing Standard FIPS","cited_arxiv_id":null,"evidence_quote":"It provides Dilithium-2 (ML-DSA-44) signature and public-key sizes, making it the scheme whose digest-mode SPDU exceeds the TBS ceiling."}],"review_version":1}