Lune

USENIX Security2026顶会

Non-Interactive Key Exchange from Lattices in the Standard Model

Ying Li, Lei Zhang, Qiqi Lai

2026年份

摘要

Existing non-interactive key exchange (NIKE) constructions in the CKS-heavy security model either incur loose security reductions or lack lattice instantiations due to the absence of suitable hash proof systems (HPS). To overcome this limitation, we introduce a new cryptographic primitive, named as decoupled key encapsulation mechanisms (decoupled KEMs), which separates recipient-independent ciphertext generation from recipient-specific key derivation. Moreover, we formalize the security of our decoupled KEM as MU-IND-wCCA^Corr+, which is a multi-user security notion. Based on this, we give a new framework that any decoupled KEM with MU-IND-wCCA^Corr+ implies a NIKE protocol with much tighter security in the CKS-heavy security model. For concrete instantiation, we first construct a specific HPS based on Modulus-LWE in the standard model, and then obtain a decoupled KEM with the desired security notion. Applying our framework, we obtain a lattice-based NIKE secure in the standard model, denoted NIKE HPS . NIKE HPS . achieves a linear security reduction loss in the number of users and close to the known optimum, improving upon the quadratic loss of SWOOSH (USENIX Security' 24) under CKS-heavy security. Experiments show that our protocol achieves significant speedups in key generation and shared-key derivation over SWOOSH.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper13

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖