{
  "all_resist_teeth_verified": true,
  "family": [
    {
      "binding": "AUTH signature over the ADDKE transforms + RFC 9242 IntAuth chaining",
      "cert_valid": true,
      "deployed": "strongSwan 6.0, Palo Alto",
      "first": "first machine-checked analysis of the FINALIZED multi-KE (Gazdag et al. 2021 modeled a single KE on a superseded draft, deferred multi-KE)",
      "main": "ikev2_rfc9370_multi_ke_downgrade_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "IKEv2 (RFC 9370 multi-KE)",
      "teeth": "ikev2_no_transform_binding_teeth_hunt.pv",
      "teeth_verdict": "BREAK"
    },
    {
      "binding": "CertificateVerify signature over the ClientHello offer (RFC 8446 \u00a74.4.3)",
      "cert_valid": true,
      "deployed": "Chrome, Cloudflare, OpenSSL",
      "first": "machine-checked group-downgrade agreement for the finalized X25519MLKEM768 codepoint",
      "main": "tls13_hybrid_downgrade_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "TLS 1.3 hybrid (X25519MLKEM768)",
      "teeth": "tls13_no_transcript_binding_teeth_hunt.pv",
      "teeth_verdict": "BREAK"
    },
    {
      "binding": "host-key signature over the exchange hash H, which includes the KEXINIT I_C (RFC 4253 \u00a78)",
      "cert_valid": true,
      "deployed": "OpenSSH 9.x (default)",
      "first": "machine-checked KEX-downgrade agreement for OpenSSH's default PQ KEX",
      "main": "ssh_pq_kex_downgrade_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "SSH (mlkem768x25519)",
      "teeth": "ssh_no_kexinit_binding_teeth_hunt.pv",
      "teeth_verdict": "BREAK"
    },
    {
      "binding": "802.11 4-way-handshake MIC over the negotiated RSNE (AKM suites), keyed by the SAE-derived PMK",
      "cert_valid": true,
      "deployed": "the estate's own protocol family",
      "first": "machine-checked AKM-downgrade agreement for a PQC-augmented WPA3-SAE association \u2014 the estate's CORE domain: the same downgrade defense that protected WPA2/WPA3 extends to a PQC AKM suite",
      "main": "wifi_pqc_sae_downgrade_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "Wi-Fi PQC-SAE (WPA3, ON-DOMAIN)",
      "teeth": "wifi_pqc_no_rsne_binding_teeth_hunt.pv",
      "teeth_verdict": "BREAK"
    },
    {
      "binding": "the Welcome/GroupInfo signature over the group ciphersuite (RFC 9420 \u00a712.4.3)",
      "cert_valid": true,
      "deployed": "MLS deployments",
      "first": "machine-checked ciphersuite-downgrade agreement for a joining member of a PQ MLS group",
      "main": "mls_pq_ciphersuite_downgrade_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "MLS (RFC 9420, group messaging)",
      "teeth": "mls_no_groupinfo_binding_teeth_hunt.pv",
      "teeth_verdict": "BREAK"
    },
    {
      "binding": "the TLS 1.3 transcript binds the offered groups into CertificateVerify; the cross-layer leg binds the EAP-derived MSK/PMK to the inner TLS transcript",
      "cert_valid": true,
      "deployed": "RFC 9190 EAP-TLS 1.3 deployments (FreeRADIUS, hostapd)",
      "first": "machine-checked cross-layer downgrade agreement for a PQC EAP-TLS inner method feeding a Wi-Fi PMK",
      "main": "eap_mlkem_xlayer_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "EAP-TLS with ML-KEM (802.1X enterprise Wi-Fi)",
      "teeth": "eap_mlkem_xlayer_naive_hunt.pv",
      "teeth_verdict": "BREAK"
    },
    {
      "binding": "the initial-message MAC/AD binds the PQ prekey and its signature into the derived session key",
      "cert_valid": true,
      "deployed": "Signal (PQXDH, 2023-)",
      "first": "machine-checked prekey-binding agreement for PQXDH's PQ leg (the unbound counterfactual BREAKs)",
      "main": "pqxdh_hunt.pv",
      "main_verdict": "RESIST",
      "protocol": "Signal PQXDH",
      "teeth": "pqxdh_unbound_hunt.pv",
      "teeth_verdict": "BREAK"
    }
  ],
  "honest_scope": "Symbolic models of SIMPLIFIED protocols; classical Dolev-Yao attacker only. The active-CRQC downgrade (crypto-breaking, not a classical MITM) is OUT OF SCOPE and, for IKEv2, already public + WG-owned (draft-ietf-ipsecme-ikev2-downgrade-prevention). Symbolic checks, not computational proofs.",
  "module": "pqc_hybrid_downgrade_family",
  "n_protocols": 7,
  "n_valid_certs": 7,
  "owe_boundary": {
    "model": "wifi_pqc_owe_downgrade_teeth_hunt.pv",
    "note": "OWE derives the PMK from an UNAUTHENTICATED Diffie-Hellman, so an active on-path attacker learns the PMK, forges the 4-way MIC over a downgraded RSNE, and the STA accepts. PQC-OWE gains quantum-resistant confidentiality against PASSIVE attackers but \u2014 like classical OWE \u2014 provides NO active-MITM / downgrade resistance. Deployments needing downgrade resistance must use SAE (authenticated), for which the estate's cert RESISTs. Expected + documented, not a discovered flaw.",
    "owe_verdict": "BREAK",
    "protocol": "Wi-Fi PQC-OWE (RFC 8110, ON-DOMAIN \u2014 boundary)",
    "verdict_expected": "BREAK (by design)"
  },
  "prover": "ProVerif (real binary, via make outward-provers)",
  "result": "All 7 modeled PQC hybrid handshakes (IKEv2, TLS 1.3, SSH, Wi-Fi PQC-SAE, MLS, EAP-TLS+ML-KEM, PQXDH) RESIST classical-MITM downgrade, and each is teeth-verified (the counterfactual without the transcript binding BREAKs). The common cause: each binds the negotiated KE choice into an authenticated transcript.",
  "sprint": 140,
  "status": "machine-checked resist-certificates on THIRD-PARTY deployed protocols; not breaks, not estate IP. No legal/novelty/FTO/essentiality/price conclusion.",
  "why_stronger": "Unlike the KEM binding models (symbolic consistency checks whose verdict follows from a KDF field-list), these are genuine reachability/agreement questions with BITING teeth controls that isolate the causal property \u2014 the strongest machine-checked artifacts of the outward effort."
}
