Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only Indifferentiability
Mihir Bellare, Hannah Davis, Felix Günther
Abstract
It is convenient and common for schemes in the random oracle model to assume access to multiple random oracles (ROs), leaving to implementations the task—we call it oracle cloning—of constructing them from a single RO. The first part of the paper is a case study of oracle cloning in KEM submissions to the NIST Post-Quantum Cryptography standardization process. We give key-recovery attacks on some submissions arising from mistakes in oracle cloning, and find other submissions using oracle cloning methods whose validity is unclear. Motivated by this, the second part of the paper gives a theoretical treatment of oracle cloning. We give a definition of what is an “oracle cloning method” and what it means for such a method to “work,” in a framework we call read-only indifferentiability, a simple variant of classical indifferentiability that yields security not only for usage in single-stage games but also in multi-stage ones. We formalize domain separation, and specify and study many oracle cloning methods, including common domain-separating ones, giving some general results to justify (prove read-only indifferentiability of) certain classes of methods. We are not only able to validate the oracle cloning methods used in many of the unbroken NIST PQC KEMs, but also able to specify and validate oracle cloning methods that may be useful beyond that.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d8d41bb9-c971-469d-9dbf-31e7f13520a8Cited by top-tier papers3
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 11 citations
- The OCH Authenticated Encryption SchemeSanketh Menda, Mihir Bellare, Viet Tung Hoang, Julia Len et al.CCS 2025
- OpenSSLNTRU: Faster post-quantum TLS key exchangeDaniel J. Bernstein, Billy Bob Brumley, Ming-Shing Chen, Nicola TuveriUSENIX Security 2022
Related papers
- The Impossibility of Post-quantum Public Indifferentiability for Merkle-DamgårdAkinori HosoyamadaCRYPTO 2026
- Classical vs Quantum Random OraclesTakashi Yamakawa, Mark ZhandryEUROCRYPT 2021 · 43 citations
- Indifferentiability for Public Key CryptosystemsMark Zhandry, Cong ZhangCRYPTO 2020 · 11 citations
- The Sponge Is Quantum IndifferentiableGorjan Alagic, Joseph Carolan, Christian Majenz, Saliha TokatFOCS 2025 · 6 citations
- On One-Shot Signatures, Quantum vs. Classical Binding, and Obfuscating PermutationsOmri Shmueli, Mark ZhandryCRYPTO 2025 · 6 citations
