Independent Submission H. Xie Request for Comments: XXXX getxlb.com Category: Experimental 1 April 2027 ISSN: 2070-1721 XLB-KD: Low-Cost Key Expansion over Thermally Rendered Read-Once Media Abstract This document specifies XLB-KD (eXtremely Low-Bandwidth Key Distribution), a key expansion protocol in which key material is encoded in the chemical composition of a thermally rendered read-once medium and transported in a sealed opaque carrier. Readout is performed destructively by an in vivo chemoreceptor array at the receiving endpoint. The protocol is positioned as a low-cost alternative to Quantum Key Distribution (QKD): its security rests on the destructive nature of readout, mass conservation auditing, and vacuum tamper evidence rather than on the no-cloning theorem. Subject to the stated assumptions, a session that completes verification yields information- theoretically secure key material; under the profiles defined in Section 12, sessions of fewer than four carriers are expansion-negative. A cost analysis relative to QKD is provided. Status of This Memo This document is not an Internet Standards Track specification; it is published for examination, experimental implementation, and evaluation. This document defines an Experimental Protocol for the Internet community. This is a contribution to the RFC Series, independently of any other RFC stream. The RFC Editor has chosen to publish this document at its discretion and makes no statement about its value for implementation or deployment. Documents approved for publication by the RFC Editor are not candidates for any level of Internet Standard; see Section 2 of RFC 7841. Information about the current status of this document, any errata, and how to provide feedback on it may be obtained at https://www.rfc-editor.org/info/rfcXXXX. Copyright Notice Copyright (c) 2027 the author. This document is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0): it may be copied and modified without restriction, provided that attribution to getxlb.com is preserved and that derivative works are distributed under the same license. The full license text is available at https://creativecommons.org/licenses/by-sa/4.0/. Table of Contents 1. Introduction 1.1. Motivation 1.2. Design Principle 1.3. Requirements Language 1.4. Romanization 2. Terminology and Glossary 3. Protocol Overview 4. Trust Model 5. Media Fabrication 5.1. Padding Preparation 5.2. Filling 5.3. Prohibited Payload Contents 5.4. Envelope Construction 5.5. Fold Topology 6. Symbol Encoding 6.1. Alphabet 6.2. Permutation Encoding 6.3. Grid and Frame Alignment 7. Thermal Processing and Encapsulation 8. Companion Channel 8.1. Authentication 8.2. Message Grammar 8.3. Experimental Algorithm Suite 9. Transmission 10. Verification Procedure 11. Readout and Post-Processing 11.1. Destructive Readout 11.2. Key Verification 11.3. Privacy Amplification 11.4. Key Growing 12. Session Accounting and Profiles 13. Error Handling and Abort Semantics 14. Cost Analysis 14.1. Capital and Operating Costs 14.2. Key Rate 14.3. Attack Costs 14.4. Deployment Constraints 15. Security Considerations 15.1. Assumptions 15.2. Adversary Classes and Claims 15.3. Attack/Detection Coverage Matrix 15.4. Detector Non-Idealities 15.5. Institutional Considerations 16. IANA Considerations 17. References 17.1. Normative References 17.2. Informative References Appendix A. Test Vector Acknowledgements Author's Address 1. Introduction 1.1. Motivation Quantum Key Distribution (QKD) offers key expansion whose security does not rest on computational assumptions. Its deployed cost profile is, however, unfavorable: commercial fiber-based QKD links are commonly reported in the low-to-mid six figures (USD) per link and require dedicated dark fiber, cooled single-photon detectors, trusted relay nodes at approximately 100 km intervals, and photonics personnel. National security agencies have repeatedly declined to recommend QKD deployment on cost and assurance grounds [NSA-QKD] [NCSC-QKD]. This document specifies XLB-KD (eXtremely Low-Bandwidth Key Distribution), which retains the architectural skeleton of QKD -- a physical medium that cannot be read without disturbance, an authenticated public companion channel, integrity verification, and privacy amplification -- while replacing the quantum optical substrate with a thermally rendered, destructively measured physical medium available at retail. Total capital expenditure is under 100 USD, all of which retains full residual utility outside the protocol (Section 14.1). The trade-offs, principally in key rate and in the epistemic status of the core physical assumption, are documented without concealment in Sections 14 and 15. 1.2. Design Principle The medium encapsulates a liquid payload by encoding it as a solid at the sending side; the payload undergoes a phase transition to its liquid representation during thermal processing, and the information-bearing degree of freedom is the payload's chemical composition. The central security property is that readout, performed by an in vivo chemoreceptor array at the receiving endpoint, is destructive: within the protocol's threat model (Section 15.2), an eavesdropper cannot learn a symbol without consuming the unit that carried it, and consumption is detected by audit before any key material is used. Key material is encoded not in individual units but in the permutation assigning units to positions in a sealed opaque carrier. The multiset of symbols per carrier is a public constant, so aggregate emissions from the carrier are uninformative by construction. 1.3. Requirements Language The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. 1.4. Romanization Several terms of art in this domain have no precise English equivalent. Such terms appear in Hanyu Pinyin romanization and are defined, together with their original Chinese forms, in Section 2. 2. Terminology and Glossary Unit One xiao long bao (Chinese: 小笼包), a soup dumpling: a wheat-flour envelope enclosing a pork payload whose soup is delivered by thermally induced phase transition. The protocol's medium. The abbreviation XLB derives from this term; the expansion given in the Abstract is equally correct, and both are normative. Envelope The wheat-flour skin enclosing the payload. Unlike conventional protocol headers, the envelope is not stripped at the destination; it is consumed together with the payload. Payload Seasoned ground pork combined with padding. Padding Gelatinized stock, diced and distributed through the payload. Known natively as "pidong" (Chinese: 皮冻, "skin jelly"). In contrast to padding in conventional protocols, the padding defined here carries the payload's liquid state and is the principal deliverable. Thirty-Seventy The REQUIRED fat-to-lean configuration of the Rule pork component: 30% fat, 70% lean by mass. Known natively as "san fen fei, qi fen shou" (Chinese: 三分肥七分瘦). Shangjin (Chinese: 上劲, "gaining strength".) The cohesive state a stirred filling MUST reach before assembly. Liyu Zui (Chinese: 鲤鱼嘴, "carp's mouth".) The twisted, sealed apex terminating the fold sequence. Kaichuang (Chinese: 开窗, "opening a window".) The receiver operation of venting the envelope sidewall to drain the rendered payload; functionally, opening a read port. Carrier An opaque metallic vessel with an airtight lid under positive mechanical retention and an asymmetric feature breaking the rotational symmetry of the grid (Section 6.3), holding one 2x4 grid of units. Serves simultaneously as steaming vessel, optical and radio-frequency shield, mass boundary, and tamper-evident enclosure. The reference implementation is a hinged aluminum meal container with a wire latch. Bu Xing (Chinese: 不行, "not permitted".) The complete and only valid response to content negotiation requests under Section 5.3, and the only abort reason defined by this protocol (Section 8.2). Rupture Event Unplanned payload egress through the envelope. Triggers session abort (Section 13). Symbol One of the eight pre-agreed flavor variants of the common payload base (Section 6.1). Manifest The authenticated announcement of session identifier, dispatch timestamp, carrier count, and the sealed gross mass of each carrier in index order. 3. Protocol Overview Participants pre-share authentication state -- a long-lived hash seed and a reserve of one-time masks (Section 11.4) -- and an ordered eight-symbol flavor alphabet. A session comprises one or more carriers (Section 12) and proceeds in six phases per carrier: 1. Fabrication: eight units are produced per Section 5, one unit of each alphabet symbol. 2. Encoding and loading: a uniformly random permutation is generated (Section 6.2) and units are loaded into the carrier grid accordingly (Section 6.3). 3. Thermal processing and encapsulation: units are steamed in the open carrier, which is then sealed at peak temperature, forming a vacuum on cooling; the sealed gross mass is recorded and the manifest announced (Sections 7 and 8). 4. Transmission: the carrier is conveyed by untrusted courier within the time-to-live (Section 9). 5. Verification: the receiver performs the ordered audit of Section 10 before readout. Any anomaly aborts the session. 6. Readout and post-processing: the receiver reads all units destructively; the participants verify agreement by universal hash over the companion channel and distill the final key by privacy amplification (Section 11). The companion channel requires authentication only, not confidentiality. It MAY be conducted aloud across the table. 4. Trust Model The following are within the trusted base of this protocol, hereafter the Trusted Culinary Base (TCB): the sender, the receiver, their kitchens, the ingredient supply, the scale, the randomness source of Section 6.2, and the endpoints of the companion channel. Compromise of any TCB element (e.g., adulteration of the white pepper supply, a scale reporting attacker-chosen masses) is out of scope. The courier is not trusted. The carrier in transit is assumed to be under adversarial custody for the full transmission interval. 5. Media Fabrication 5.1. Padding Preparation Padding is REQUIRED. A unit without padding does not render soup and is outside the scope of this document. Padding MUST be prepared by simmering pork skin (OPTIONALLY supplemented with chicken feet or a pork trotter) in water with ginger and scallion for no less than 90 minutes, straining, and chilling until fully set. The gel MUST hold a 5 mm cube at room temperature; a gel failing this test MUST be reduced further. The mass ratio of diced padding to ground pork SHOULD be between 1:2 and 1:1.5. Ratios below 1:3 yield insufficient rendered liquid and are NOT RECOMMENDED. 5.2. Filling The pork component MUST conform to the Thirty-Seventy Rule. Leaner configurations exhibit reduced payload cohesion and are NOT RECOMMENDED. The base seasoning comprises light soy sauce, Shaoxing wine, minced ginger, sugar, salt, and white pepper; sesame oil is RECOMMENDED. Symbol-differentiating adjustments are applied per Section 6.1. The mixture MUST be stirred in a single rotational direction until it reaches shangjin. Bidirectional stirring prevents this state and MUST NOT be performed. Diced padding MUST then be folded in gently, and the payload MUST be held refrigerated until assembly. 5.3. Prohibited Payload Contents The payload MUST NOT contain fruit. This prohibition includes, without limitation: pineapple, strawberry, durian, mango, and any ingredient marketed as "fruit-forward". Content negotiation is not supported; requests for fruit-based payloads MUST be rejected with the response "bu xing", and no further error detail is provided. Tomato is acknowledged to be botanically a fruit and is prohibited under this section regardless. Although fruit flavors would extend the symbol alphabet and thereby the channel capacity, capacity considerations do not override this section. This section is not extensible. 5.4. Envelope Construction The envelope MUST be made from a hot-water or warm-water dough of medium-gluten wheat flour, rested no less than 30 minutes. Each dough unit SHOULD weigh 8-10 g, rolled to a disc of approximately 7-8 cm diameter, center thicker than rim, target rim thickness approximately 1 mm. The envelope MUST be thin enough that the payload is faintly visible after steaming and strong enough to be lifted by the apex without a rupture event. These requirements are in tension; conformance generally requires extended operational experience. 5.5. Fold Topology Each unit SHOULD be closed with 18 folds; 14 to 22 folds are conformant. Units with fewer than 10 folds are structurally indistinguishable from jiaozi and MUST be reclassified accordingly. Folds MUST proceed in a single rotational direction and terminate in a fully sealed liyu zui. Units within a session SHOULD be fabricated to uniform external dimensions and appearance, so that symbol identity is not visually encoded. 6. Symbol Encoding 6.1. Alphabet The alphabet consists of eight flavor variants sharing an identical payload base (Section 5.2) and differing only in seasoning dimensions (e.g., salt level, ginger intensity, sugar, white pepper, sesame oil, scallion oil, wine). Variants differing in base composition (crab roe, shrimp, mushroom) MUST NOT be used: base-level differences are resolvable by density imaging (Section 15.1, Assumption 1). The alphabet is agreed out of band as an ordered list; a symbol's index is its position in that list, 0 through 7. The list order is arbitrary and carries no information; in particular, the alphabet MUST NOT be ordered by any seasoning dimension, as intensity dimensions are symbol content, not symbol identity. Adjacent symbols MUST be separated by margins exceeding the receiver's just-noticeable difference under session conditions. Narrowing symbol margins to increase capacity increases gustatory error rates and, under the abort semantics of Section 13, session failure rates. 6.2. Permutation Encoding Each carrier transports exactly one unit of each alphabet symbol. The key material contributed by a carrier is the permutation assigning symbols to the eight grid positions, yielding log2(8!) = 15.2992 raw bits per carrier. The permutation of each carrier MUST be sampled uniformly, and independently of every other carrier in the session, from the 40320 possibilities, from a randomness source providing true min-entropy (Section 8.3), via Fisher-Yates shuffling or by unranking a uniform integer in [0, 8!-1] under the factorial number system (Lehmer code; see Appendix A). Practitioners MUST NOT generate the permutation by physically shuffling units; human shuffling is measurably non-uniform. Because the multiset of flavors per carrier is a public constant, the aggregate volatile content of the carrier headspace carries zero information about the key. Chemical analysis of sampled headspace gas is thereby rendered uninformative by construction rather than by bound (Section 15.3). 6.3. Grid and Frame Alignment Carrier positions form a 2x4 grid, numbered 1 through 8 in row-major order. The grid possesses a twofold rotational symmetry; a carrier read in the wrong orientation yields the reversed permutation. The symmetry MUST be broken by an asymmetric physical feature of the carrier: the placement of its closure, or an indelible orientation marker applied before loading. Row 1 is the row nearest this feature; within a row, position numbering proceeds left to right as viewed from above with the feature toward the observer. Carriers offering no asymmetric feature MUST NOT be used. In the reference implementation, the wire latch serves this purpose. In sessions of more than one carrier, carriers are publicly indexed 0 through B-1, and the index MUST be indelibly marked on each carrier before loading: identical unmarked carriers can be reordered in transit, causing sender and receiver to reconstruct different session ranks. 7. Thermal Processing and Encapsulation Units MUST be placed on a perforated liner or napa cabbage leaves within the open carrier, no two units in contact; units in contact bond and tear on separation, producing correlated rupture events. The open carrier MUST be steamed over vigorously boiling water for 8 to 10 minutes. The steamer MUST NOT be opened mid-cycle. Immediately upon completion of steaming, the carrier lid MUST be closed and secured while contents are at peak temperature. Condensation of the enclosed steam during cooling produces a substantial partial vacuum, registered by inward deflection of the lid. The carrier MUST NOT be dispatched until inward deflection is established, and the authenticated dispatch timestamp MUST be taken after this condition is satisfied: tamper evidence is not in force while the vacuum is still forming. The carrier MUST be metallic, opaque, and airtight; assembled units MUST NOT exceed 50 mm in footprint diameter, and the carrier MUST provide internal clearance for the 2x4 grid with no unit in contact with another unit or with a wall. The lid MUST close under positive mechanical retention sufficient to hold the seal from peak temperature through cooling. Before first use, a carrier MUST pass a leak test: sealed hot over water alone, it MUST retain visible lid deflection at room temperature for no less than twice the maximum TTL. Carriers failing this test MUST NOT be used. Insulated transit is permitted; the TTL is anchored to the authenticated timestamp, not to temperature. The carrier wall serves three functions: (a) optical opacity from the visible through the infrared, excluding spectroscopic readout (skin depth in metals is on the order of nanometers at these wavelengths); (b) a Faraday enclosure excluding radio-frequency magnetic resonance methods; (c) a closed mass boundary. With the carrier sealed, evaporation ceases to remove mass from the system, and each carrier's sealed gross mass -- carrier, liner, condensate, and units together -- becomes a conserved quantity. Each MUST be measured on a scale of 0.5 g practical resolution at sealing; deviations at the receiver are treated per Section 10. The manifest (session identifier, dispatch timestamp, carrier count, and per-carrier sealed gross masses in index order) MUST be announced on the companion channel at dispatch. 8. Companion Channel 8.1. Authentication Every companion-channel message MUST carry an authentication tag computed with a Wegman-Carter universal-hash authenticator [WC81] keyed from pre-shared key material (Section 11.4). The authenticator comprises a long-lived universal-hash seed A, part of the pre-shared authentication state and retained across sessions, and a fresh t-bit one-time mask per message: the tag is the t-bit Toeplitz hash of the canonically encoded message under A (Section 8.3), XORed with the mask. The hash seed is reusable because every tag it produces is masked; the masks are not reusable, and each transmitted tag therefore consumes exactly t bits of authentication key. Masks are indexed by transmission order: the n-th companion-channel message transmitted in a session, of any type, consumes mask B_n, so an early ABORT is unambiguous. An authentication failure MUST immediately abort the session, and the mask at the failed position is retired and MUST NOT be reused. Constructions of this form are surveyed in [RFC4418]. Tag length t is a session parameter (Section 12). The channel provides no confidentiality and requires none. 8.2. Message Grammar The protocol defines five message types, of which a successful session exchanges exactly four, CONFIRM and ABORT being mutually exclusive final messages. Messages are defined in ABNF [RFC5234]: session-id = 8HEXDIG carrier-count = %x31-39 [DIGIT] ; 1-99, no leading zero mass = 1*4DIGIT "." DIGIT %s"g" mass-list = mass *("," mass) ; carrier index order hash-seed = 1*64HEXDIG ; Toeplitz seed, verification hash-value = 1*8HEXDIG ; v bits pa-seed = 1*64HEXDIG ; Toeplitz seed, extraction tag = 1*8HEXDIG ; Wegman-Carter tag, t bits manifest = %s"MANIFEST" SP session-id SP date-time SP carrier-count SP mass-list SP tag ready = %s"READY" SP session-id SP tag verify = %s"VERIFY" SP session-id SP hash-seed SP hash-value SP pa-seed SP tag confirm = %s"CONFIRM" SP session-id SP tag abort = %s"ABORT" SP session-id SP %s"bu xing" SP tag with date-time as in [RFC3339]. Field widths are fixed by the profile: tag and hash-value MUST contain exactly t/4 and v/4 hexadecimal digits respectively; hash-seed and pa-seed widths are fixed by Section 8.3. The number of mass-list entries MUST equal carrier-count, and a session-id MUST NOT repeat under a given authentication state. MANIFEST is sent by the sender at dispatch; READY by the receiver after the audit of Section 10; VERIFY by the sender immediately upon receipt of an authenticated READY; CONFIRM or ABORT by the receiver, after readout and comparison, as the final message. "bu xing" is the only abort reason defined; implementations MUST NOT define additional reasons, as enumerated abort reasons constitute an oracle. 8.3. Experimental Algorithm Suite The following suite is mandatory to implement; additional families MAY be agreed out of band. Session rank: the per-carrier permutation ranks R_j are combined in carrier index order as R = SUM(j = 0 .. B-1) R_j * (8!)^j and encoded as a binary string x of n = ceil(B * log2(8!)) bits, most significant bit first: n = 16, 62, and 123 for B = 1, 4, and 8 respectively. Authentication: the message, taken with its trailing tag field and the preceding SP excluded, is canonically encoded as its ASCII bit string followed by a single 1 bit and zero-padding to W = 1024 bits; messages of 1024 or more bits are malformed. The tag is the t-bit Toeplitz hash (below) of this encoding under the long-lived authentication seed A, a uniform bit string of 1039 bits (W + t - 1 at the maximum mandatory t = 16); a profile with smaller t uses the first W + t - 1 bits. The hash output is XORed with B_n, the mask of the n-th transmitted message (Section 8.1). Because the family is XOR-universal and each mask is used once, forgery succeeds with probability at most 2^-t per attempt. Verification and extraction: both are Toeplitz hashes over the rank string x. A Toeplitz seed s for m output bits is a uniform bit string of length n + m - 1; output bit i, for i = 0 .. m-1, is y_i = XOR(j = 0 .. n-1) ( s_(i+j) AND x_j ) The verification hash-value uses m = v with seed hash-seed; the extractor uses m = L (Section 12) with seed pa-seed. L = 0 yields the empty key, in which case pa-seed MUST be the single digit 0. Seeds are encoded most significant bit first in exactly ceil((n + m - 1)/4) hexadecimal digits, excess leading bits zero. The sender MUST sample each seed uniformly at random, independently of R, after receipt of an authenticated READY. This family is 2-universal over the full rank string, as the leftover hash lemma requires. The initial authentication seed A and initial mask reserve, the ranks R_j, and the Toeplitz seeds MUST ultimately derive from sources providing the entropy their uses require; deterministic pseudorandom expansion alone is insufficient under the security claim of Section 15.1. After a successful session, one-time masks MAY be replenished from the privacy-amplified session output (Section 11.4). This suite is defined for B <= 8; larger sessions require an alternate companion-channel profile. Under the profiles of Section 12, no seed field exceeds 48 hexadecimal digits. 9. Transmission The carrier MAY be conveyed by any courier; the courier is not trusted. The time-to-live (TTL) from dispatch timestamp to the start of verification MUST NOT exceed 30 minutes and SHOULD be configured to the minimum the logistics permit. The TTL is a security parameter, not a freshness preference: it upper-bounds the time available for destructive measure-and-reseal pipelines (Section 15.2). Trusted relays are not supported. Any relay with readout capability necessarily consumes the medium. 10. Verification Procedure The receiver MUST perform the following checks, in order, before readout begins. Any failure aborts the session (Section 13). 1. Timestamp: elapsed time within TTL. 2. Gross mass: each carrier's sealed mass equals its manifest entry within +/- 1.0 g (two scale divisions). Any absolute deviation beyond tolerance aborts: a deficit is evidence of removal of matter, a surplus of addition or substitution. 3. Vacuum: the lid MUST exhibit inward deflection, and the report upon opening MUST be commensurate with the deep vacuum produced by hot sealing. A shallow or absent report indicates the carrier has been opened; cold re-evacuation through a needle valve does not readily reproduce condensation-depth vacuum. 4. Census and inspection: exactly eight units present, one per grid position, envelopes visually intact, no payload pooled on the liner. 5. Phase: payloads MUST be liquid. A re-gelled payload indicates elapsed time or thermal history inconsistent with the manifest and MUST trigger abort. A liquid payload provides no positive assurance (an insulated or re-steamed carrier also presents liquid payloads); this check is one-sided. Upon completion, the receiver sends READY. 11. Readout and Post-Processing 11.1. Destructive Readout The receiver reads all eight positions in grid order using the canonical procedure, transmitted between generations as "qing qing ti, man man yi, xian kai chuang, hou he tang" ("lift gently, move slowly, open the window first, drink the soup after"): lift by the apex with spoon support (the spoon is REQUIRED), perform kaichuang, drain and assess the rendered payload, then consume the unit. Ingesting an intact unit immediately after opening the carrier is a client-side error with a typical recovery time of 3-5 days and MUST NOT be performed. Ginger slivers and tea MUST be taken between units as a guard interval against inter-symbol interference (palate carryover). Zhenjiang black vinegar is RECOMMENDED and does not count against the guard interval. A dry payload, a concealed rupture discovered at kaichuang, or a symbol grossly outside the calibrated alphabet (Section 15.4) discovered during readout MUST trigger abort. Readout precedes key acceptance; abort at this stage discards the session key as usual. Reference units of known symbol MAY be consumed before the session as pilot signals for receiver calibration. 11.2. Key Verification Upon receipt of an authenticated READY, the sender samples the verification and extraction seeds as required by Section 8.3, computes the v-bit hash of the true session rank, and sends VERIFY. After readout of all carriers, the receiver computes the same hash over the rank reconstructed from readout. On match, the receiver sends CONFIRM; on mismatch, ABORT. No error correction is performed: XLB-KD is detection-only, and a single gustatory misread costs the session. An undetected disagreement survives with probability at most 2^-v. The v bits of disclosed hash value are accounted against privacy amplification. 11.3. Privacy Amplification The extractable length is bounded by the leftover hash lemma: L = max(0, floor(15.2992 * B - v - l_phys - 2 * log2(1/eps_PA))) where l_phys = 4 bits per session bounds residual aroma leakage after opening (Assumption 2, Section 15.1) and eps_PA is the secrecy distance of the final key from uniform. The extractor of Section 8.3, keyed by pa-seed, outputs L bits. Net expansion is computed in Section 12. 11.4. Key Growing A fragment of each session's output MUST be reserved to replenish the one-time masks of the next session's companion channel; the hash seed A is long-lived and is not consumed. The initial authentication state is distributed out of band, conventionally at a prior in-person meal. As with QKD, XLB-KD is therefore properly a key expansion protocol rather than a key distribution protocol; this terminology is used advisedly and in solidarity. 12. Session Accounting and Profiles A session of B carriers yields 15.2992 * B raw bits. The extractable length after privacy amplification is the floored L(B) of Section 11.3, and net expansion after authentication is: net(B) = L(B) - 4t Three profiles are defined: +-------------+----+----+--------+---+-------+-------+--------+ | Profile | t | v | eps_PA | B | raw | L | net | +-------------+----+----+--------+---+-------+-------+--------+ | CALIBRATION | 8 | 8 | 2^-8 | 1 | 15.3 | 0 | -32 | | BANQUET-4 | 8 | 8 | 2^-8 | 4 | 61.2 | 33 | +1 | | BANQUET-8 | 16 | 16 | 2^-16 | 8 | 122.4 | 70 | +6 | +-------------+----+----+--------+---+-------+-------+--------+ The single-carrier CALIBRATION profile is expansion-negative and is retained for receiver calibration and interoperability testing only; deployments operating it consume net key each session and MUST plan an in-person re-seed accordingly. The minimum key-positive deployment under these profiles is therefore BANQUET-4: four carriers, 32 units, at secrecy distance 2^-8. At secrecy distance 2^-16, eight carriers (64 units) are REQUIRED. Because authentication, verification, and leakage costs are fixed per session while raw yield is per carrier, net yield per unit increases monotonically with session size, and higher assurance parameters raise the minimum banquet accordingly. 13. Error Handling and Abort Semantics Every verification failure, rupture event, receptor anomaly, or hash mismatch resolves to the single abort procedure: the session key is discarded in its entirety and the receiver sends ABORT with the sole defined reason. The abort procedure is otherwise identical to the success procedure; in particular, consumption of the batch proceeds in either case. No retransmission mechanism is defined. A subsequent session is a new batch. 14. Cost Analysis Figures in this section are order-of-magnitude engineering estimates. 14.1. Capital and Operating Costs +---------------+---------------------------+---------------------+ | Item | QKD (commercial fiber) | XLB-KD | +---------------+---------------------------+---------------------+ | Capital, per | low-to-mid six figures | under 100 USD: | | link | (USD); dedicated dark | steamer, 0.5 g | | | fiber; cooled single- | kitchen scale, | | | photon detectors | four hinged | | | | aluminum carriers | | | | (pre-owned) | +---------------+---------------------------+---------------------+ | Marginal, per | maintenance, cooling, | approx. 25 USD | | session | fiber lease | (ingredients, | | | | 32 units) | +---------------+---------------------------+---------------------+ | Personnel | photonics engineers | one qualified | | | | practitioner | | | | (Section 5.4; | | | | non-trivial) | +---------------+---------------------------+---------------------+ | Residual | none outside QKD service | full utility as | | asset value | | cookware | +---------------+---------------------------+---------------------+ Marginal cost is additionally recoverable in substantial part as lunch. No comparable recovery is available for a single-photon detector. 14.2. Key Rate A BANQUET-4 session yields 1 net bit over roughly two hours of fabrication, transit, and readout, i.e., on the order of 10^-4 bit/s. Deployed QKD links report kilobits to megabits per second. XLB-KD therefore operates at a throughput disadvantage of approximately seven to ten orders of magnitude. Applications requiring more than a few hundred key bits per day SHOULD provision multiple practitioners. 14.3. Attack Costs +--------------------+------------------------+-------------------+ | Attack | QKD | XLB-KD | +--------------------+------------------------+-------------------+ | Passive intercept | fiber tap plus optics | excluded: opaque | | of medium | laboratory | sealed medium, | | | | constant-multiset | | | | headspace | +--------------------+------------------------+-------------------+ | Non-destructive | detector blinding | industrial CT | | readout | apparatus, order of | (six figures, | | | 10^4 USD plus | minutes per | | | expertise [MAKAROV] | scan), defeated | | | | by common-base | | | | alphabet | | | | discipline | | | | (Assumption 1) | +--------------------+------------------------+-------------------+ | Destructive | not applicable | covert reseal | | measure-and- | | pipeline: mobile | | replace | | galley, master | | | | practitioner, | | | | closed-vessel | | | | reheat, all | | | | within TTL; | | | | detection per | | | | Section 15.2 | +--------------------+------------------------+-------------------+ | Denial of service | fiber cut (trivial) | carrier drop | | | | (trivial) | +--------------------+------------------------+-------------------+ In both protocols the cheapest attack is denial of service. In both protocols the defender's response is identical: abort and retry. XLB-KD's retry has a marginal cost of 25 USD and produces a second lunch. 14.4. Deployment Constraints Link range is bounded by the courier radius achievable within the TTL, approximately 20 km in urban conditions. Range extension by trusted relay is not supported (Section 9). Multi-span topologies therefore require end-to-end re-keying, i.e., additional meals. 15. Security Considerations 15.1. Assumptions Assumption 1: alphabet symbols sharing a common base and differing only in gram-scale seasoning are not resolvable by transmission density imaging (X-ray/CT) at deployable resolution. This is an engineering judgment under current technology, not a theorem, and is the reason base-level symbol variants are prohibited (Section 6.1). Assumption 2 (residual aroma leakage): with E_phys the adversary's observation of volatiles released after the carrier is opened at the receiving endpoint, the conditional min-entropy of the session rank satisfies H_min(R | E_phys) >= H_min(R) - l_phys, l_phys = 4 per session. Deployments claiming conformance MUST establish this bound under their own carrier and alphabet conditions. Assumption 3 (sub-tolerance sampling): material removed within the mass tolerance of Section 10 does not suffice to recover any symbol's identity without breaching envelope or carrier in a manner detected by another verification step. As with Assumption 1, this is an engineering judgment. The corresponding property in QKD (no-cloning) is a theorem. The author notes the difference in epistemic grade between a theorem of quantum mechanics and a conjecture about dumplings, and makes no attempt to obscure it. The security claim of this document is accordingly conditional: subject to Assumptions 1 through 3 and to the TCB of Section 4, a session that completes with CONFIRM yields a key satisfying three distinct guarantees: companion-channel forgery succeeds with probability at most 2^-t per authentication attempt and at most 4 * 2^-t over a four-message session, excluding accumulated prior-session error; a disagreement between sender and receiver keys survives verification with probability at most 2^-v; and the distilled key is within secrecy distance eps_PA of uniform from the adversary's view. Statistical security errors compose across key-growing sessions: these guarantees apply per session relative to the incoming authentication state, and accumulated distinguishing advantage is additive. 15.2. Adversary Classes and Claims Class 0 (observation only): no information. Flavor is not visually encoded (Section 5.5); the headspace is sealed; positions are public by design. Class 1 (physical custody, no instruments, no kitchen): all known attacks are detected. Consumption or significant extraction of matter violates mass conservation; opening violates the vacuum evidence; replay violates timestamp, phase, and manifest; substitution requires knowledge of flavor, which requires destructive readout of the original. Class 2 (physical custody, laboratory instruments): all known non-destructive channels are excluded by physics or by construction: optical channels (including near-infrared and spatially offset Raman methods, which resolve seasoning dimensions through millimeter organic media) and RF channels by the metal wall, chemical channels by constant-multiset headspace, density imaging by Assumption 1. Class 2 adversaries are therefore forced onto destructive pathways and inherit Class 3 detection. Class 3 (destructive measure-and-replace): open, read (instrument readout is fast once the carrier is open), refabricate, reseal, deliver. The pipeline must simultaneously reproduce condensation-depth vacuum (requiring closed-vessel reheat), match the sealed gross mass, reproduce all eight flavors, suppress re-steam artifacts below gustatory threshold, and complete within the TTL. Detection of this pathway rests on the conjunction of vacuum depth, mass audit, phase evidence, and hash verification against destructively obtained flavor knowledge; it is the weakest guarantee in this document and is identified as such. 15.3. Attack/Detection Coverage Matrix +--------------------------+--------------------------------------+ | Attack | Detecting mechanism | +--------------------------+--------------------------------------+ | Unit consumption | census; gross mass | | Payload extraction | gross mass; vacuum evidence; | | | Assumption 3 below mass tolerance | | Carrier opening | vacuum deflection; acoustic report | | | commensurate with hot-seal vacuum | | Replay of prior batch | timestamp; phase; manifest mismatch | | Unit substitution | hash verification; flavor unknowable | | | without destructive read | | Slow laboratory analysis | TTL; phase | | Spectroscopic readout | excluded (metal wall) | | Magnetic resonance | excluded (Faraday enclosure) | | Headspace chemistry | uninformative (constant multiset) | | Density imaging | Assumption 1 (alphabet discipline) | | In-carrier rupture | visual census; readout; abort | | Receptor blinding | out-of-alphabet intensity; abort | | | (Section 15.4) | | Companion-channel | Wegman-Carter authentication | | forgery | | +--------------------------+--------------------------------------+ Each known attack intersects at least one detector. No single detector covers all attacks; the security argument is the coverage of the matrix, not the strength of any row. 15.4. Detector Non-Idealities The receiving detector is a human palate and inherits the failure modes of deployed detectors generally. Receptor saturation ("blinding"): a substituted unit of extreme capsaicin content saturates the receiver and suppresses discrimination for subsequent symbols. This is the gustatory analogue of detector-blinding attacks demonstrated against avalanche photodiodes in commercial QKD systems [MAKAROV]. Any symbol grossly exceeding the calibrated alphabet intensity MUST be treated as an attack indicator and trigger abort, not scored as a misread. Calibration drift: receiver discrimination varies with congestion, fatigue, and recent diet. Pilot units (Section 11.1) partially compensate. Fabrication variance: sender-side craftsmanship variance is the dominant contributor to gustatory misreads and, via rupture events, to aborts. Under detection-only verification, a single misread costs the session; field experience suggests session success rates of 40-60% [PRACTICE], dominated by envelope craftsmanship. Implementers accustomed to QKD deployment reports will find these figures familiar. 15.5. Institutional Considerations Availability is not provided: a dropped carrier, a late courier, or a single rupture aborts the session. As in QKD, the cheapest adversary action is denial of service, and the defender's remedy is retry. Because every companion-channel message consumes a fresh authentication mask, repeated adversarial aborts drain the authentication reserve while producing no key; this key-exhaustion denial of service is inherent to one-time authentication and is cleared only by the in-person re-seed. The initial authentication state is distributed out of band (Section 11.4). XLB-KD therefore does not solve the key bootstrap problem; neither does QKD. Assessments of QKD by national security agencies -- citing hardware trust, denial of service, relay exposure, and residual reliance on classical authentication -- apply to this protocol without modification, and are hereby incorporated by reference. 16. IANA Considerations This document establishes no registry. The symbol alphabet is session-local and agreed out of band. A registry of approved seasoning symbols was considered; all fruit-derived entries would be permanently marked "Reserved (MUST NOT be assigned)" per Section 5.3, and the remaining registration policy reduces to local kitchen practice, for which IANA is not the appropriate authority. 17. References 17.1. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997. [RFC3339] Klyne, G. and C. Newman, "Date and Time on the Internet: Timestamps", RFC 3339, DOI 10.17487/RFC3339, July 2002. [RFC5234] Crocker, D., Ed., and P. Overell, "Augmented BNF for Syntax Specifications: ABNF", STD 68, RFC 5234, DOI 10.17487/RFC5234, January 2008. [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017. [WC81] Wegman, M. and J. Carter, "New hash functions and their use in authentication and set equality", J. Computer and System Sciences 22(3), 1981. 17.2. Informative References [BB84] Bennett, C. and G. Brassard, "Quantum cryptography: Public key distribution and coin tossing", Proc. IEEE Int. Conf. on Computers, Systems and Signal Processing, Bangalore, 1984. [NSA-QKD] National Security Agency, "Quantum Key Distribution (QKD) and Quantum Cryptography (QC)", cybersecurity guidance, 2020. [NCSC-QKD] UK National Cyber Security Centre, "Quantum security technologies", whitepaper, 2020. [MAKAROV] Lydersen, L., et al., "Hacking commercial quantum cryptography systems by tailored bright illumination", Nature Photonics 4, 2010. [RFC1149] Waitzman, D., "A Standard for the Transmission of IP Datagrams on Avian Carriers", RFC 1149, DOI 10.17487/RFC1149, 1 April 1990. [RFC4418] Krovetz, T., Ed., "UMAC: Message Authentication Code using Universal Hashing", RFC 4418, DOI 10.17487/RFC4418, March 2006. [PRACTICE] Practitioners of the Jiangnan region, "Standard Practice for Xiao Long Bao", oral tradition, continuously revised. Appendix A. Test Vector This appendix exercises the CALIBRATION profile (one carrier) under the mandatory suite of Section 8.3; every value below is reproducible by implementations. The resulting session is expansion-negative, as expected. Alphabet (example; agreed out of band, ordered): 0 base seasoning (Section 5.2) 1 base + salt increment 2 base + sugar increment 3 base + white pepper increment 4 base + ginger increment 5 base + sesame oil increment 6 base + scallion oil increment 7 base + Shaoxing wine increment Session keys (example): masks B1..B4: 3C 91 5A E4 (t = 8) authentication seed A (1039 bits: W + t - 1 at the maximum mandatory t = 16; one excess leading zero bit, 260 hexadecimal digits). The CALIBRATION profile (t = 8) uses the first 1031 bits: 027B4A79EF7BADFAA58B84EA795440A98C0CD8C9DFBBB02D052B 0A18C4C10538D12BD928187C965FC72A5740E1616452D6AAFC0A E322339228BB9FC51AF9AA28D6B9CE521674423DE5BF14E89310 7B65B9CB641737D240F016598E65FBC01AB273EC14FE8C53BC9B 4B1597FB3F290DA9FF1C19D0B21278997DC7E72FA941B4E41DD2 Permutation rank (uniform in [0, 40319], from a physical randomness source): R = 31337 Lehmer decomposition of R under factorial base (5040, 720, 120, 24, 6, 2, 1): 31337 = 6*5040 + 1*720 + 3*120 + 0*24 + 2*6 + 2*2 + 1*1 digits: (6, 1, 3, 0, 2, 2, 1, 0) Unranking against the ordered symbol list yields the position-to-symbol assignment: position: 1 2 3 4 5 6 7 8 symbol: 6 1 4 0 5 7 3 2 i.e., position 1 (latch row, leftmost) carries the scallion oil variant, and position 8 carries the sugar variant. Manifest values: session-id: 1F2E3D4C timestamp: 2027-04-01T11:30:00+08:00 gross mass: 583.5g (8 units, liner, condensate, carrier) Rank encoding (n = 16): x = 0x7A69 = 0111101001101001 Verification Toeplitz seed (23 bits in 6 hex digits, excess leading bit zero) and resulting hash: hash-seed = 5AC3F1 hash-value = B7 With L = 0 (see accounting below), pa-seed is the single digit 0. Message trace, tags computed per Section 8.3 over each message with its trailing tag field and preceding SP excluded: A->B MANIFEST 1F2E3D4C 2027-04-01T11:30:00+08:00 1 583.5g E4 B->A READY 1F2E3D4C E2 A->B VERIFY 1F2E3D4C 5AC3F1 B7 0 00 B->A CONFIRM 1F2E3D4C DE The receiver's readout of positions 1 through 8, with guard intervals observed, reproduces (6, 1, 4, 0, 5, 7, 3, 2); the v = 8 bit verification hash matches (B7). Accounting: raw: 15.30 bits verification hash: -8 aroma bound l_phys: -4 (Assumption 2) privacy amplification: -16 (eps_PA = 2^-8) extractable L: 0 (floored) authentication: -32 (4 messages, t = 8) net: -32 bits The extractor with pa-seed 0 outputs the empty key (L = 0), which implementations MUST reproduce exactly. The deployment draws the authentication deficit from reserve and schedules an in-person meal. Acknowledgements The author thanks several generations of implementers whose uncompensated conformance testing informed Sections 5, 10, and 11, and whose interpretations of the requirements in this document are consistently stricter than BCP 14 provides for. Author's Address Huang Xie getxlb.com