Lune

CRYPTO2026Top-tier venue

Post-quantum Internet Key Exchange via Authenticated Forward-Secure KEM

Yunlei Zhao, Biming Zhou, Zhixiang Zhao, Yifan Dong, Cheng Huang, Haodong Jiang

2026Year

Abstract

In this work, we present a new framework for signature-free, post-quantum secure authenticated key exchange (AKE) that simultaneously satisfies: (1) exchanging at most two standard ciphertexts of a key encapsulation mechanism (KEM); (2) computational symmetry; (3) perfect forward secrecy (PFS); (4) strong resilience to secret-state exposure; (5) strong resistance to decryption-error attacks; (6) admitting instantiations based on the native structure of ML-KEM under the MLWE assumption; and (7) provable security in both the random oracle model (ROM) and the quantum-accessible random oracle model (QROM) under the post-id eCK\mbox−PFS\mathsf{eCK}\mbox{-}\mathsf{PFS} framework. This resolves several fundamental open questions in the literature. The core technical building block is a new cryptographic primitive, called an authenticated forward-secure KEM (AFS-KEM), which unifies authentication and forward secrecy within a single KEM abstraction and may be of independent interest.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 1a745e36-32af-4aae-a38d-3e45657b6776

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines