USENIX Security2024Top-tier venue
SWOOSH: Efficient Lattice-Based Non-Interactive Key Exchange
Phillip Gajland, Bor de Kock, Miguel Quaresma, Giulio Malavolta, Peter Schwabe
Abstract
The advent of quantum computers has sparked significant interest in post-quantum cryptographic schemes, as a replacement for currently used cryptographic primitives. In this context, lattice-based cryptography has emerged as the leading paradigm to build post-quantum cryptography. However, all existing viable replacements of the classical Diffie-Hellman key exchange require additional rounds of interactions, thus failing to achieve all the benefits of this protocol. Although earlier work has shown that lattice-based Non-Interactive Key Exchange (NIKE) is theoretically possible, it has been considered too inefficient for real-life applications. In this work, we challenge this folklore belief and provide the first evidence against it. We construct an efficient lattice-based NIKE whose security is based on the standard module learning with errors (M-LWE) problem in the quantum random oracle model. Our scheme is obtained in two steps: (i) A passively-secure construction that achieves a strong notion of correctness, coupled with (ii) a generic compiler that turns any such scheme into an actively-secure one. To substantiate our efficiency claim, we provide an optimised implementation of our passively-secure construction in Rust and Jasmin. Our implementation demonstrates the scheme's applicability to real-world scenarios, yielding public keys of approximately 220 KBs. Moreover, the computation of shared keys takes fewer than 12 million cycles on an Intel Skylake CPU, offering a post-quantum security level exceeding 120 bits.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 20f33bba-6f2a-47a7-8434-5c2fb2250c4eCited by top-tier papers3
- Deterministic Algorithms for Class Group ActionsMarc HoubenCRYPTO 2025 · 1 citation
- Shadowfax: Hybrid Security and Deniability for AKEMsPhillip Gajland, Vincent Hwang, Jonas JanneckUSENIX Security 2026
- Non-Interactive Key Exchange from Lattices in the Standard ModelYing Li, Lei Zhang, Qiqi LaiUSENIX Security 2026
Builds on20
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWEJoppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov et al.CCS 2016 · 431 citations
- Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesMelissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi et al.CCS 2017 · 316 citations
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
Related papers
- SalsaPicante: A Machine Learning Attack on LWE with Binary SecretsCathy Yuanchen Li, Jana Sotáková, Emily Wenger, Mohamed Malhou et al.CCS 2023 · 11 citations
- SALSA VERDE: a machine learning attack on LWE with sparse small secretsCathy Yuanchen Li, Emily Wenger, Zeyuan Allen-Zhu, François Charton et al.NeurIPS 2023 · 13 citations
- Qelect: Lattice-based Single Secret Leader Election Made PracticalYunhao Wang, Fan ZhangUSENIX Security 2025
- Ringtail: Practical Two-Round Threshold Signatures from Learning with ErrorsCecilia Boschini, Darya Kaviani, Russell W. F. Lai, Giulio Malavolta et al.S&P 2025
- Benchmarking Attacks on Learning with ErrorsEmily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu et al.S&P 2025
