{
 "check": "hybrid_downgrade_citation",
 "cite_as": "f4 / wifi-pqc-failure-lab, hybrid-PQC downgrade family (7 protocols)",
 "n_protocols": 7,
 "n_valid_certs": 7,
 "all_resist_teeth_verified": true,
 "n_rows_with_both_digests": 7,
 "n_model_files_missing": 0,
 "all_main_RESIST": true,
 "all_teeth_BREAK": true,
 "main_models": [
  "ikev2_rfc9370_multi_ke_downgrade_hunt.pv",
  "tls13_hybrid_downgrade_hunt.pv",
  "ssh_pq_kex_downgrade_hunt.pv",
  "wifi_pqc_sae_downgrade_hunt.pv",
  "mls_pq_ciphersuite_downgrade_hunt.pv",
  "eap_mlkem_xlayer_hunt.pv",
  "pqxdh_hunt.pv"
 ],
 "teeth_models": [
  "ikev2_no_transform_binding_teeth_hunt.pv",
  "tls13_no_transcript_binding_teeth_hunt.pv",
  "ssh_no_kexinit_binding_teeth_hunt.pv",
  "wifi_pqc_no_rsne_binding_teeth_hunt.pv",
  "mls_no_groupinfo_binding_teeth_hunt.pv",
  "eap_mlkem_xlayer_naive_hunt.pv",
  "pqxdh_unbound_hunt.pv"
 ],
 "rows": [
  {
   "protocol": "IKEv2 (RFC 9370 multi-KE)",
   "deployed_in": "strongSwan 6.0, Palo Alto",
   "binding": "AUTH signature over the ADDKE transforms + RFC 9242 IntAuth chaining",
   "main_model": "ikev2_rfc9370_multi_ke_downgrade_hunt.pv",
   "main_sha256": "dda038b72df23aa53b89fb5e194d30cdd28535ba8667efbf2645b25750285702",
   "main_verdict": "RESIST",
   "teeth_model": "ikev2_no_transform_binding_teeth_hunt.pv",
   "teeth_sha256": "ae5ad6e8e866d8194f8c1106b8bd1c2f5075b5730781112425c904dddeffa9e7",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  },
  {
   "protocol": "TLS 1.3 hybrid (X25519MLKEM768)",
   "deployed_in": "Chrome, Cloudflare, OpenSSL",
   "binding": "CertificateVerify signature over the ClientHello offer (RFC 8446 \u00a74.4.3)",
   "main_model": "tls13_hybrid_downgrade_hunt.pv",
   "main_sha256": "f16fdb04126a3557be1e4eb5df91ff3f50f5db074df7c9f83785510ba5a2564e",
   "main_verdict": "RESIST",
   "teeth_model": "tls13_no_transcript_binding_teeth_hunt.pv",
   "teeth_sha256": "a56264add099c65a1ca56b939e4e695521ff09e7005977f19fa4119e80b364f2",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  },
  {
   "protocol": "SSH (mlkem768x25519)",
   "deployed_in": "OpenSSH 9.x (default)",
   "binding": "host-key signature over the exchange hash H, which includes the KEXINIT I_C (RFC 4253 \u00a78)",
   "main_model": "ssh_pq_kex_downgrade_hunt.pv",
   "main_sha256": "94d5432c5714e29c764cd9a19da33ad22750ff452d0d7fefd1e22d606fbcd0bd",
   "main_verdict": "RESIST",
   "teeth_model": "ssh_no_kexinit_binding_teeth_hunt.pv",
   "teeth_sha256": "d90df554c171cb2769a6538dc0facdc9ba721bc6623fc0b19d6c265549131ad5",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  },
  {
   "protocol": "Wi-Fi PQC-SAE (WPA3, ON-DOMAIN)",
   "deployed_in": "the estate's own protocol family",
   "binding": "802.11 4-way-handshake MIC over the negotiated RSNE (AKM suites), keyed by the SAE-derived PMK",
   "main_model": "wifi_pqc_sae_downgrade_hunt.pv",
   "main_sha256": "442bc0044d5103004d4aee04fc3f0ad2b82d0994ccec61951af1acce60c9225c",
   "main_verdict": "RESIST",
   "teeth_model": "wifi_pqc_no_rsne_binding_teeth_hunt.pv",
   "teeth_sha256": "217b45ebb35dc5e1932f8afce9fa45f88773c2cd4ada7039d3410845b92d73e7",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  },
  {
   "protocol": "MLS (RFC 9420, group messaging)",
   "deployed_in": "MLS deployments",
   "binding": "the Welcome/GroupInfo signature over the group ciphersuite (RFC 9420 \u00a712.4.3)",
   "main_model": "mls_pq_ciphersuite_downgrade_hunt.pv",
   "main_sha256": "0271ab6f6a5eafe9db59907cc326fc56bafe8dfbea6ab1aee6aa1ce1cc0c6093",
   "main_verdict": "RESIST",
   "teeth_model": "mls_no_groupinfo_binding_teeth_hunt.pv",
   "teeth_sha256": "1b4f02b6744eafd0d9d4d93cf557ac4e2c25ed3418424a4f321f256a30b9ede7",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  },
  {
   "protocol": "EAP-TLS with ML-KEM (802.1X enterprise Wi-Fi)",
   "deployed_in": "RFC 9190 EAP-TLS 1.3 deployments (FreeRADIUS, hostapd)",
   "binding": "the TLS 1.3 transcript binds the offered groups into CertificateVerify; the cross-layer leg binds the EAP-derived MSK/PMK to the inner TLS transcript",
   "main_model": "eap_mlkem_xlayer_hunt.pv",
   "main_sha256": "007af07f7e29330105bd14e286561077c69a01e081fd537a92e2513d0e678e90",
   "main_verdict": "RESIST",
   "teeth_model": "eap_mlkem_xlayer_naive_hunt.pv",
   "teeth_sha256": "04aa59591e47ee28014caf26977f146266d11a388bae12ec80997abd806010ab",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  },
  {
   "protocol": "Signal PQXDH",
   "deployed_in": "Signal (PQXDH, 2023-)",
   "binding": "the initial-message MAC/AD binds the PQ prekey and its signature into the derived session key",
   "main_model": "pqxdh_hunt.pv",
   "main_sha256": "54d2c20844aaa877790ee791ed83b3294383f930716967d5728e8102418405aa",
   "main_verdict": "RESIST",
   "teeth_model": "pqxdh_unbound_hunt.pv",
   "teeth_sha256": "fed5a65714dd586fdbf6d5a6ae81bab99e61b01f6a2ff7fd3e356523a36f7a61",
   "teeth_verdict": "BREAK",
   "cert_valid": true
  }
 ],
 "owe_boundary_model": "wifi_pqc_owe_downgrade_teeth_hunt.pv",
 "owe_boundary_verdict": "BREAK",
 "owe_boundary_note": "BREAK BY DESIGN, not a discovered flaw: PQC-OWE derives its PMK from an unauthenticated exchange, so an active on-path attacker forges the 4-way MIC. Any lane citing this family must carry this row or it misstates the family.",
 "family_seal_name": "hybrid_family_seven",
 "family_seal_path": "conformance/predictions/hybrid_family_seven.json",
 "family_seal_blob_matches": true,
 "family_seal_anchor": {
  "tracked": true,
  "blob_ok": true,
  "head_blob": "3309c21dad7f7b3e06a30dbe93674fd08c7055ec",
  "worktree_blob": "3309c21dad7f7b3e06a30dbe93674fd08c7055ec",
  "reason": "working copy equals the committed blob"
 },
 "models_dir": "06_formal_models/proverif",
 "regenerating_command": "make outward-provers && make pqc-hybrid-downgrade-family && python3 tools/check_sealed_predictions.py --only hybrid_family_seven",
 "prover": "ProVerif (real binary, via make outward-provers)",
 "honest_scope": "Symbolic models of SIMPLIFIED protocols; classical Dolev-Yao attacker only. The active-CRQC downgrade (crypto-breaking, not a classical MITM) is OUT OF SCOPE and, for IKEv2, already public + WG-owned (draft-ietf-ipsecme-ikev2-downgrade-prevention). Symbolic checks, not computational proofs.",
 "status": "machine-checked resist-certificates on THIRD-PARTY deployed protocols; not breaks, not estate IP. No legal/novelty/FTO/essentiality/price conclusion.",
 "how_to_cite": "Cite the protocol row and its two digests, not the headline. RESIST is a statement about a symbolic model of a simplified protocol under a classical Dolev-Yao attacker, teeth-verified: the counterfactual without the transcript binding BREAKs. It is NOT a statement about deployed code, and the active-CRQC downgrade is out of scope. Verify with --verify before citing: if a digest moved, the sentence you were about to write is about a model that no longer exists."
}
