USENIX Security2026Top-tier venue
mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-Optimal
Hongxiao Wang, Ron Steinfeld, Markku-Juhani O. Saarinen, Muhammed F. Esgin, Siu-Ming Yiu
Abstract
In applications such as secure group communication and broadcasting, it is important to efficiently deliver multiple messages to different recipients at once. To this end, multi-message multi-recipient Public Key Encryption (mmPKE) enables the batch encryption of multiple messages for multiple independent recipients in one go, significantly reducing costs–particularly bandwidth–compared to the trivial solution of encrypting each message individually. This capability is especially desirable in the post-quantum setting, where the ciphertext length is typically significantly larger than the corresponding plaintext. However, almost all prior works on mmPKE are limited to quantum-vulnerable traditional assumptions. In this work, we propose the first CPA-secure mmPKE and Multi-Key Encapsulation Mechanism (mmKEM) from the standard Module Learning with Errors (MLWE) lattice assumption, named mmCipher-PKE and mmCipher-KEM, respectively. Our design proceeds in two steps: (i) We introduce a novel generic construction of mmPKE by proposing a new PKE variant—extended reproducible PKE (XR-PKE)—that enables the reproduction of ciphertexts through additional hints; (ii) We instantiate a lattice-based XR-PKE using a new technique that can precisely estimate the impact of such hints on the ciphertext security while also establishing suitable parameters. We believe both to be of independent interest. As a bonus contribution, we explore generic constructions of adaptively secure mmPKE, resisting adaptive corruption and chosen-ciphertext attacks. We also provide an efficient implementation and thorough evaluation of the practical performance of our mmCipher. The results demonstrate substantial bandwidth and computational savings over the state-of-the-art. For example, for 1024 recipients, our mmCipher-KEM achieves a 23–45× reduction in bandwidth overhead, with ciphertexts only 4–9% larger than the plaintexts (near optimal bandwidth), while also offering a 3–5× reduction in computational cost.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- InstantOMR: Oblivious Message Retrieval with Low Latency and Optimal ParallelizabilityHaofei Liang, Zeyu Liu, Eran Tromer, Xiang Xie et al.USENIX Security 2026
- LUNA+: More Succinct Post-Quantum ZK-SNARKs from Computational PrivacyYuki Kume, Ron Steinfeld, Amin Sakzad, Mert YassiCCS 2026
- Lether: Practical Post-Quantum Account-Based Private Blockchain PaymentsHongxiao Wang, Muhammed F. Esgin, Ron Steinfeld, Siu-Ming YiuCCS 2026
Builds on17
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWEJoppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov et al.CCS 2016 · 431 citations
- Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More GeneralVadim Lyubashevsky, Ngoc Khanh Nguyen, Maxime PlançonCRYPTO 2022 · 125 citations
- MatRiCT+: More Efficient Post-Quantum Private Blockchain PaymentsMuhammed F. Esgin, Ron Steinfeld, Raymond K. ZhaoS&P 2022 · 59 citations
- A New Framework for More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor SamplingRafaël del Pino, Shuichi KatsumataCRYPTO 2022 · 50 citations
Related papers
- Post-Quantum Multi-Recipient Public Key EncryptionJoël Alwen, Dominik Hartmann, Eike Kiltz, Marta Mularczyk et al.CCS 2023 · 6 citations
- Lattice-Based Updatable KEM for Group MessagingJoël Alwen, Georg Fuchsbauer, Marta Mularczyk, Doreen RiepelCRYPTO 2026
- Universal Composable Password Authenticated Key Exchange for the Post-Quantum WorldYou Lyu, Shengli Liu, Shuai HanEUROCRYPT 2024 · 11 citations
- Almost Tight Multi-user Security Under Adaptive Corruptions from LWE in the Standard ModelShuai Han, Shengli Liu, Zhedong Wang, Dawu GuCRYPTO 2023 · 9 citations
- Updatable Public-Key Encryption, RevisitedJoël Alwen, Georg Fuchsbauer, Marta MularczykEUROCRYPT 2024 · 5 citations
