Anonymity of NIST PQC Round 3 KEMs
Keita Xagawa
Abstract
This paper investigates anonymity of all NIST PQC Round 3 KEMs: Classic McEliece, Kyber, NTRU, Saber, BIKE, FrodoKEM, HQC, NTRU Prime (Streamlined NTRU Prime and NTRU LPRime), and SIKE. We show the following results:
-
NTRU is anonymous in the quantum random oracle model (QROM) if the underlying deterministic PKE is strongly disjoint-simulatable. NTRU is collision-free in the QROM. A hybrid PKE scheme constructed from NTRU as KEM and appropriate DEM is anonymous and robust. (Similar results for BIKE, FrodoKEM, HQC, NTRU LPRime, and SIKE hold except for two of three parameter sets of HQC.)
-
Classic McEliece is anonymous in the QROM if the underlying PKE is strongly disjoint-simulatable and a hybrid PKE scheme constructed from it as KEM and appropriate DEM is anonymous.
-
Grubbs, Maram, and Paterson pointed out that Kyber and Saber have a gap in the current IND-CCA security proof in the QROM (EUROCRYPT 2022). We found that Streamlined NTRU Prime has another technical obstacle for the IND-CCA security proof in the QROM.
Those answer the open problem to investigate the anonymity and robustness of NIST PQC Round 3 KEMs posed by Grubbs, Maram, and Paterson (EUROCRYPT 2022).
We use strong disjoint-simulatability of the underlying PKE of KEM and strong pseudorandomness and smoothness/sparseness of KEM as the main tools, which will be of independent interest.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9d91dda1-70d3-4c7f-ab77-4b0fb3bcb89eCited by top-tier papers4
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 27 citations
- Obfuscated Key ExchangeFelix Günther, Douglas Stebila, Shannon VeitchCCS 2024 · 1 citation
- Post-Quantum Cryptographic Analysis of SSHBenjamin Bencina, Benjamin Dowling, Varun Maram, Keita XagawaS&P 2025
- Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMsKeitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom WiggersS&P 2026
Related papers
- Anonymous, Robust Post-quantum Public Key EncryptionPaul Grubbs, Varun Maram, Kenneth G. PatersonEUROCRYPT 2022 · 36 citations
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 35 citations
- Starfighters-On the General Applicability of X-WingDeirdre Connolly, Kathrin Hövelmanns, Andreas Hülsing, Stavros Kousidis et al.S&P 2026 · 4 citations
- PQ-Hammer: End-to-End Key Recovery Attacks on Post-Quantum Cryptography Using RowhammerSamy Amer, Yingchen Wang, Hunter Kippen, Thinh Dang et al.S&P 2025
- A Key-Recovery Timing Attack on Post-quantum Primitives Using the Fujisaki-Okamoto Transformation and Its Application on FrodoKEMQian Guo, Thomas Johansson, Alexander NilssonCRYPTO 2020 · 84 citations
