Analysing the HPKE Standard
Joël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz, Benjamin Lipp, Doreen Riepel
Abstract
The Hybrid Public Key Encryption (HPKE) scheme is an emerging standard currently under consideration by the Crypto Forum Research Group (CFRG) of the IETF as a candidate for formal approval. Of the four modes of HPKE, we analyse the authenticated mode in its single-shot encryption form as it contains what is, arguably, the most novel part of HPKE. ’s intended application domain is captured by a new primitive which we call Authenticated Public Key Encryption (APKE). We provide syntax and security definitions for APKE schemes, as well as for the related Authenticated Key Encapsulation Mechanisms (AKEMs). We prove security of the AKEM scheme underlying based on the Gap Diffie-Hellman assumption and provide general AKEM/DEM composition theorems with which to argue about ’s security. To this end, we also formally analyse ’s key schedule and key derivation functions. To increase confidence in our results we use the automatic theorem proving tool CryptoVerif. All our bounds are quantitative and we discuss their practical implications for . As an independent contribution we propose the new framework of nominal groups that allows us to capture abstract syntactical and security properties of practical elliptic curves, including the Curve25519 and Curve448 based groups (which do not constitute cyclic groups).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4bdf8be7-28e8-43b3-a498-3ca820bd4a86Cited by top-tier papers10
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- Server-Aided Continuous Group Key AgreementJoël Alwen, Dominik Hartmann, Eike Kiltz, Marta MularczykCCS 2022 · 19 citations
- K-Waay: Fast and Deniable Post-Quantum X3DH without Ring SignaturesDaniel Collins, Loïs Huguenin-Dumittan, Ngoc Khanh Nguyen, Nicolas Rolin et al.USENIX Security 2024 · 12 citations
- End-to-End Encrypted Zoom Meetings: Proving Security and Strengthening LivenessYevgeniy Dodis, Daniel Jost, Balachandar Kesavan, Antonio MarcedoneEUROCRYPT 2023 · 7 citations
- Obfuscated Key ExchangeFelix Günther, Douglas Stebila, Shannon VeitchCCS 2024 · 1 citation
Builds on2
Related papers
- Identity-Concealed Authenticated Encryption and Key ExchangeYunlei ZhaoCCS 2016 · 27 citations
- CuKEM: A Concise and Unified Hybrid Key Encapsulation MechanismYiting Liu, Biming Zhou, Haodong JiangCCS 2025
- A comprehensive, formal and automated analysis of the EDHOC protocolCharlie Jacomme, Elise Klein, Steve Kremer, Maïwenn RacouchotUSENIX Security 2023
- Tightly-Secure Authenticated Key Exchange, RevisitedTibor Jager, Eike Kiltz, Doreen Riepel, Sven SchägeEUROCRYPT 2021 · 39 citations
- Post-quantum Internet Key Exchange via Authenticated Forward-Secure KEMYunlei Zhao, Biming Zhou, Zhixiang Zhao, Yifan Dong et al.CRYPTO 2026
