日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
通信ミドルウェアarXiv:2609.10024

AXON: 共有メモリ/QUICトランスポートとQKD/ML-KEM鍵確立を備えたROS 2 RMW

AXON: A ROS 2 RMW with Shared-Memory/QUIC Transport and QKD/ML-KEM Key Establishment

シェア:XThreadsFacebookLINEはてブBluesky

ROS 2のミドルウェア層(RMW)をDDS以外で実装し、同一ホスト内は共有メモリ、遠隔通信はQUICで行い、耐量子暗号や量子鍵配送を用いた鍵確立方式を提案した。

詳しい要約

1. どんなもの?

- ROS 2 の RMW 実装 AXON を提案 - DDS に代わる選択肢 - 同一ホスト通信に POSIX shared-memory rings - 遠隔通信に QUIC - 発見とグラフ同期に daemon - Rust core と C++ adapter で構成 - 遠隔通信用に fail-closed TLS 1.3 鍵確立を2構成 - classic: hybrid X25519MLKEM768 のみ提供 - qkd: ETSI GS QKD 014 API で取得した256-bit鍵を external PSK として使用 - qkd の messages10 戦略: AES-256-GCM でアプリメッセージ保護、10メッセージごとに KME 素材をローテーション、envelope ごとに新 nonce - session は QUIC 保護のみに依存 - 脅威モデルを定義し、2構成の peer authentication を区別 - 実装レベルの検証を ROS 2 conformance、比較性能、物理 QKD 検証から区別

2. 先行研究と比べてどこがすごい?

- 先行研究は DDS ベースの RMW が主流 - AXON は DDS を使わず、Rust core と C++ adapter で transport policy を分離 - 同一ホストと遠隔で異なる transport を採用 - 遠隔通信で TLS 1.3 の fail-closed 鍵確立を提供 - classic 構成では hybrid X25519MLKEM768 のみを提供し、古典単独グループのネゴシエーションを防止 - qkd 構成では ETSI GS QKD 014 API から取得した鍵を external PSK として使用し、Diffie-Hellman グループを提供しない - 要旨からは、先行研究との定量的な比較や優位性の詳細は不明

3. 技術・手法の肝は?

- Rust core と C++ adapter による RMW 実装 - 同一ホスト: POSIX shared-memory rings - 遠隔: QUIC - 発見とグラフ同期: daemon - TLS 1.3 鍵確立の2構成 - classic: hybrid X25519MLKEM768 グループのみ提供 - qkd: ETSI GS QKD 014 API で256-bit鍵を取得し、pairwise external PSK としてインポート、Diffie-Hellman グループなし - qkd の messages10 戦略: AES-256-GCM で遠隔アプリメッセージを保護、10送信メッセージごとに KME 素材をローテーション、envelope ごとに新 nonce - session は QUIC 保護のみ - external-PSK パスには rustls への狭い拡張が必要で、AXON にバンドル

4. どうやって有効だと検証した?

- 要旨からは不明 - 実装レベルの検証を ROS 2 conformance、比較性能、物理 QKD 検証から区別すると述べているのみ - 具体的な検証方法や結果は記載なし

5. 議論はある?

- 脅威モデルを定義 - 2構成の peer authentication を区別 - 実装レベルの検証を ROS 2 conformance、比較性能、物理 QKD 検証から区別 - 要旨からは、議論の詳細や限界は不明

6. 次に読むべき論文は?

- 要旨で参照/比較されている研究は明示されていない - 関連手法として DDS、QUIC、TLS 1.3、X25519MLKEM768、ETSI GS QKD 014、AES-256-GCM、rustls が挙げられる - 同分野の定番として ROS 2 RMW 実装(例: Fast DDS、Cyclone DDS)や DDS セキュリティ拡張が考えられる

※ AIが要旨から生成した要約です。正確性は原文をご確認ください。

著者: Sergio Sánchez de la Fuente, Miguel Ángel González-Santamarta, Francisco Javier Rodríguez-Lera, Vicente Matellán Olivera, Ángel Manuel Guerrero-Higueras

分類: cs.RO

原文アブストラクト

Robot Operating System 2 (ROS 2) standardizes application code against a middleware interface (RMW) whose reference implementations are built on the Data Distribution Service (DDS). We present AXON, an alternative ROS 2 RMW implementation that separates transport policy by deployment scope. A Rust core and C++ adapter use POSIX shared-memory rings for same-host communication, QUIC for remote communication, and a daemon for discovery and graph synchronization. We then describe two fail-closed TLS 1.3 key-establishment configurations for remote traffic. The classic configuration offers only the hybrid X25519MLKEM768 group, preventing negotiation of a classical-only group. The qkd configuration imports a 256-bit key obtained through the ETSI GS QKD 014 API as a pairwise external PSK and offers no Diffie-Hellman group. Its default messages10 strategy additionally protects remote application messages with AES-256-GCM, rotating KME material after ten outgoing messages and using a fresh nonce per envelope; session relies on QUIC protection alone. The external-PSK path requires a narrow extension to rustls, now bundled with AXON. We define the threat model, distinguish peer authentication in the two configurations, and delimit the implementation-level validation from ROS 2 conformance, comparative performance, and physical-QKD validation.