Post-quantum TLS 1.3 Handshake from CPA-Secure KEMs with Tighter Reductions
Jinrong Chen, Biming Zhou, Rongmao Chen, Haodong Jiang, Yi Wang, Xinyi Huang, Yunlei Zhao, Moti Yung
Abstract
TLS 1.3 is at the heart of secure modern internet communications. With the rise of quantum attacks, post-quantum TLS 1.3, built on post-quantum key encapsulation mechanisms (KEMs), has naturally become a major research focus. At Eurocrypt 2022, Huguenin-Dumittan and Vaudenay demonstrated that KEMs secure against chosen-plaintext attacks (CPA) are sufficient to construct a secure TLS 1.3 handshake in the random oracle model (ROM), but their security reduction incurs an loss, where is the number of random oracle queries. Improving their security bounds was left as an open problem. To address this problem, Zhou et al. took the first step at Asiacrypt 2024, improving the loss factor to in the ROM and in the quantum ROM (QROM) for OW-CPA secure KEMs, and to (ROM) and (QROM) for IND-CPA secure KEMs.
In this work, we advance the state-of-the-art by providing tighter security reductions for TLS 1.3 handshake based on CPA-secure KEMs. We introduce a new security notion, IND-1CCA-1MAC, and show that with a slight ciphertext expansion, the reduction losses can be significantly improved to (ROM) and (QROM) for OW-CPA secure KEMs, and to only in both models for IND-CPA secure KEMs. Moreover, we prove that without additional modifications such as ciphertext expansion, the loss of (ROM) and (QROM) is unavoidable. Finally, we analyze the security of TLS 1.3 from CPA-secure KEMs in the hybrid key exchange setting, and provide experimental evidence that ciphertext expansion is a practical trade-off for mitigating reduction losses.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a5f7f43c-8ac4-4c6d-99b9-ddafba6c3bb1Related papers
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 162 citations
- On IND-qCCA Security in the ROM and Its Applications - CPA Security Is Sufficient for TLS 1.3Loïs Huguenin-Dumittan, Serge VaudenayEUROCRYPT 2022 · 18 citations
- Tighter QCCA-Secure Key Encapsulation Mechanism with Explicit Rejection in the Quantum Random Oracle ModelJiangxia Ge, Tianshu Shan, Rui XueCRYPTO 2023 · 8 citations
- Looma: A Low-Latency PQTLS Authentication Architecture for Cloud ApplicationsXinshu Ma, Michio HondaNDSS 2026
- Post-Quantum Authentication in TLS 1.3: A Performance StudyDimitrios Sikeridis, Panos Kampanakis, Michael DevetsikiotisNDSS 2020
