Lune

CRYPTO2023Top-tier venue

Tighter QCCA-Secure Key Encapsulation Mechanism with Explicit Rejection in the Quantum Random Oracle Model

Jiangxia Ge, Tianshu Shan, Rui Xue

2023Year
8Citations

Abstract

Hofheinz et al. (TCC 2017) proposed several key encapsulation mechanism (KEM) variants of Fujisaki-Okamoto (FO) transformation, including FO\slashed⊥\textsf{FO}^{\slashed{\bot}}, FOm\slashed⊥\textsf{FO}_m^{\slashed{\bot}}, QFOm\slashed⊥\textsf{QFO}_m^{\slashed{\bot}}, FO⊥\textsf{FO}^{\bot}, FOm⊥\textsf{FO}_m^\bot and QFOm⊥\textsf{QFO}_m^\bot, and they are widely used in the post-quantum cryptography standardization launched by NIST. These transformations are divided into two types, the implicit and explicit rejection type, including {FO\slashed⊥,FOm\slashed⊥,QFOm\slashed⊥}\{\textsf{FO}^{\slashed{\bot}}, \textsf{FO}_m^{\slashed{\bot}}, \textsf{QFO}_m^{\slashed{\bot}}\} and FO⊥,FOm⊥,QFOm⊥\textsf{FO}^{\bot}, \textsf{FO}_m^\bot, \textsf{QFO}_m^\bot, respectively. The decapsulation algorithm of the implicit (resp. explicit) rejection type returns a pseudorandom value (resp. an abort symbol ⊥\bot) for an invalid ciphertext.

For the implicit rejection type, the IND-CCA security reduction of FO\slashed⊥\textsf{FO}^{\slashed{\bot}} in the quantum random oracle model (QROM) can avoid the quadratic security loss, as shown by Kuchta et al. (EUROCRYPT 2020). However, for the explicit rejection type, the best known IND-CCA security reduction in the QROM presented by Hövelmanns et al. (ASIACRYPT 2022) for FOm⊥\textsf{FO}_m^\bot still suffers from a quadratic security loss. Moreover, it is not clear until now whether the implicit rejection type is more secure than the explicit rejection type.

In this paper, a QROM security reduction of FOm⊥\textsf{FO}_m^\bot without incurring a quadratic security loss is provided. Furthermore, our reduction achieves IND-qCCA security, which is stronger than the IND-CCA security. To achieve our result, two steps are taken: The first step is to prove that the IND-qCCA security of FOm⊥\textsf{FO}_m^\bot can be tightly reduced to the IND-CPA security of FOm⊥\textsf{FO}_m^\bot by using the online extraction technique proposed by Don et al. (EUROCRYPT 2022). The second step is to prove that the IND-CPA security of FOm⊥\textsf{FO}_m^\bot can be reduced to the IND-CPA security of the underlying public key encryption (PKE) scheme without incurring quadratic security loss by using the Measure-Rewind-Measure One-Way to Hiding Lemma (EUROCRYPT 2020).

In addition, we prove that (at least from a theoretic point of view), security is independent of whether the rejection type is explicit (FOm⊥\textsf{FO}_m^\bot) or implicit (FOm\slashed⊥\textsf{FO}_m^{\slashed{\bot}}) if the underlying PKE scheme is weakly γ\gamma-spread.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 98045bee-dd24-4bc4-89e0-45f6d2a5150e

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines