Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
Shuai Han, Tibor Jager, Eike Kiltz, Shengli Liu, Jiaxin Pan, Doreen Riepel, Sven Schäge
Abstract
We construct the first authenticated key exchange protocols that achieve tight security in the standard model. Previous works either relied on techniques that seem to inherently require a random oracle, or achieved only "Multi-Bit-Guess" security, which is not known to compose tightly, for instance, to build a secure channel.
Our constructions are generic, based on digital signatures and key encapsulation mechanisms (KEMs). The main technical challenges we resolve is to determine suitable KEM security notions which on the one hand are strong enough to yield tight security, but at the same time weak enough to be efficiently instantiable in the standard model, based on standard techniques such as universal hash proof systems.
Digital signature schemes with tight multi-user security in presence of adaptive corruptions are a central building block, which is used in all known constructions of tightly-secure AKE with full forward security. We identify a subtle gap in the security proof of the only previously known efficient standard model scheme by Bader et al. (TCC 2015). We develop a new variant, which yields the currently most efficient signature scheme that achieves this strong security notion without random oracles and based on standard hardness assumptions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 82bb95c4-8528-4753-8dc8-7a73737132f8Cited by top-tier papers3
- On the Tight Security of the Double RatchetDaniel Collins, Doreen Riepel, Si An Oliver TranCCS 2024 · 3 citations
- Non-Interactive Key Exchange from Lattices in the Standard ModelYing Li, Lei Zhang, Qiqi LaiUSENIX Security 2026
- Bundled Authenticated Key Exchange: A Concrete Treatment of Signal's Handshake Protocol and Post-Quantum SecurityKeitaro Hashimoto, Shuichi Katsumata, Thom WiggersUSENIX Security 2025
Builds on2
Related papers
- Almost Tight Multi-user Security Under Adaptive Corruptions & Leakages in the Standard ModelShuai Han, Shengli Liu, Dawu GuEUROCRYPT 2023 · 10 citations
- Almost Tight Multi-user Security Under Adaptive Corruptions from LWE in the Standard ModelShuai Han, Shengli Liu, Zhedong Wang, Dawu GuCRYPTO 2023 · 9 citations
- Post-quantum Internet Key Exchange via Authenticated Forward-Secure KEMYunlei Zhao, Biming Zhou, Zhixiang Zhao, Yifan Dong et al.CRYPTO 2026
- Lattice-Based Authenticated Key Exchange with Tight SecurityJiaxin Pan, Benedikt Wagner, Runzhi ZengCRYPTO 2023 · 14 citations
- Lattice-Based Updatable KEM for Group MessagingJoël Alwen, Georg Fuchsbauer, Marta Mularczyk, Doreen RiepelCRYPTO 2026
