Faster Lattice-Based KEMs via a Generic Fujisaki-Okamoto Transform Using Prefix Hashing
Julien Duman, Kathrin Hövelmanns, Eike Kiltz, Vadim Lyubashevsky, Gregor Seiler
摘要
Constructing an efficient CCA-secure KEM is generally done by first constructing a passively-secure PKE scheme, and then applying the Fujisaki-Okamoto (FO) transformation. The original FO transformation was designed to offer security in a single user setting. A stronger notion, known as multi-user security, considers the attacker's advantage in breaking one of many user's ciphertexts. Bellare et al. (EUROCRYPT 2000) showed that standard single user security implies multi-user security with a multiplicative tightness gap equivalent to the number of users. To obtain even more confidence in the security of KEMs in the multi-user setting, it is a common design paradigm to also "domain separate'' the random oracles of each user by including his public key as an input to the hash function. We are not aware of any formal analysis of this technique, but it was at least informally thought to be a computationally cheap way to add security. This design principle was carried over into the FO transformations used by several schemes in the NIST post-quantum standardization effort -- notably the lattice-based schemes Kyber and Saber, which are two of the four KEM finalists. In this work, we formally analyze domain separation in the context of the FO transformation in the multi-user setting. We first show that including the public key in the hash function is indeed important for the tightness of the security reductions in the ROM and the QROM. At the same time, we show that including the entire public key into the hash function is unnecessarily wasteful -- it is enough to include just a small (e.g. byte) unpredictable part of the key to achieve the same security. Reducing the input of the hash function results in a very noticeable improvement in the running time of the lattice-based KEMs. In particular, using this generic transform results in a 2X - 3X speed-up over the current (Round 3) key generation and encapsulation procedures in Kyber, and up to a 40% improvement in the same functions in Saber.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Formally Verifying Kyber - Episode V: Machine-Checked IND-CCA Security and Correctness of ML-KEM in EasyCryptJosé Bacelar Almeida, Santiago Arranz-Olmos, Manuel Barbosa, Gilles Barthe 等CRYPTO 2024 · 被引用 16 次
- CuKEM: A Concise and Unified Hybrid Key Encapsulation MechanismYiting Liu, Biming Zhou, Haodong JiangCCS 2025
它引用的顶会 Paper3
- Practical Product Proofs for Lattice CommitmentsThomas Attema, Vadim Lyubashevsky, Gregor SeilerCRYPTO 2020 · 被引用 60 次
- Measure-Rewind-Measure: Tighter Quantum Random Oracle Model Proofs for One-Way to Hiding and CCA SecurityVeronika Kuchta, Amin Sakzad, Damien Stehlé, Ron Steinfeld 等EUROCRYPT 2020 · 被引用 60 次
- Online-Extractability in the Quantum Random-Oracle ModelJelle Don, Serge Fehr, Christian Majenz, Christian SchaffnerEUROCRYPT 2022 · 被引用 57 次
相关 Paper
- Anonymous, Robust Post-quantum Public Key EncryptionPaul Grubbs, Varun Maram, Kenneth G. PatersonEUROCRYPT 2022 · 被引用 36 次
- Compact domain-specific co-processor for accelerating module lattice-based KEMJose Maria Bermudo Mera, Furkan Turan, Angshuman Karmakar, Sujoy Sinha Roy 等DAC 2020 · 被引用 33 次
- Tighter QCCA-Secure Key Encapsulation Mechanism with Explicit Rejection in the Quantum Random Oracle ModelJiangxia Ge, Tianshu Shan, Rui XueCRYPTO 2023 · 被引用 8 次
- Proof-of-Possession for KEM Certificates using Verifiable GenerationTim Güneysu, Philip W. Hodges, Georg Land, Mike Ounsworth 等CCS 2022 · 被引用 7 次
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 被引用 35 次
