USENIX Security2026Top-tier venue
Non-Interactive Key Exchange from Lattices in the Standard Model
Ying Li, Lei Zhang, Qiqi Lai
Abstract
Existing non-interactive key exchange (NIKE) constructions in the CKS-heavy security model either incur loose security reductions or lack lattice instantiations due to the absence of suitable hash proof systems (HPS). To overcome this limitation, we introduce a new cryptographic primitive, named as decoupled key encapsulation mechanisms (decoupled KEMs), which separates recipient-independent ciphertext generation from recipient-specific key derivation. Moreover, we formalize the security of our decoupled KEM as MU-IND-wCCA^Corr+, which is a multi-user security notion. Based on this, we give a new framework that any decoupled KEM with MU-IND-wCCA^Corr+ implies a NIKE protocol with much tighter security in the CKS-heavy security model. For concrete instantiation, we first construct a specific HPS based on Modulus-LWE in the standard model, and then obtain a decoupled KEM with the desired security notion. Applying our framework, we obtain a lattice-based NIKE secure in the standard model, denoted NIKE HPS . NIKE HPS . achieves a linear security reduction loss in the number of users and close to the known optimum, improving upon the quadratic loss of SWOOSH (USENIX Security' 24) under CKS-heavy security. Experiments show that our protocol achieves significant speedups in key generation and shared-key derivation over SWOOSH.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e00e5617-ba31-4a72-aaf9-78d1f3ac146eBuilds on13
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 162 citations
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican et al.CCS 2018 · 140 citations
- Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More GeneralVadim Lyubashevsky, Ngoc Khanh Nguyen, Maxime PlançonCRYPTO 2022 · 125 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
Related papers
- SWOOSH: Efficient Lattice-Based Non-Interactive Key ExchangePhillip Gajland, Bor de Kock, Miguel Quaresma, Giulio Malavolta et al.USENIX Security 2024 · 12 citations
- Authenticated Key Exchange and Signatures with Tight Security in the Standard ModelShuai Han, Tibor Jager, Eike Kiltz, Shengli Liu et al.CRYPTO 2021 · 30 citations
- CuKEM: A Concise and Unified Hybrid Key Encapsulation MechanismYiting Liu, Biming Zhou, Haodong JiangCCS 2025
- Lattice-Based Authenticated Key Exchange with Tight SecurityJiaxin Pan, Benedikt Wagner, Runzhi ZengCRYPTO 2023 · 14 citations
- Almost Tight Multi-user Security Under Adaptive Corruptions from LWE in the Standard ModelShuai Han, Shengli Liu, Zhedong Wang, Dawu GuCRYPTO 2023 · 9 citations
