Paper 2023/898

Spilling-Cascade: an Optimal PKE Combiner for KEM Hybridization

Céline Chevalier, École Normale Supérieure - PSL, Université Paris-Panthéon-Assas
Guirec Lebrun, École Normale Supérieure - PSL, ANSSI
Ange Martinelli, ANSSI
Abstract

Hybrid Post-Quantum cryptography is a cautious approach that aims to guard against the threat posed by the quantum computer, through the simultaneous use of Post-Quantum (PQ) and classical (i.e. pre-quantum) cryptosystems, should the post-quantum schemes used prove insecure. Regarding the hybridization of Key Encapsulation Mechanisms (KEMs), most recent studies focus on safely combining the symmetric keys output by a parallel execution of classical and Post-Quantum KEMs. While this architecture is straightforward, it appears to lack bandwidth optimization. Hence, we propose a novel method for hybridizing several KEMs more effectively, by combining the underlying Public-Key Encryption schemes (PKEs) in an innovative variant of the cascade composition that we call “spilling-cascade”, before turning the hybrid PKE into a KEM with a FO transformation. We prove that this architecture constitutes a robust combiner for encryption schemes up to IND-CPA security, which permits to eventually generate an IND-CCA-secure KEM. In terms of performance, our spilling-cascade scheme has a better communication cost than the commonly used parallel combination, with a bandwidth gain of its ciphertext that ranges from 2.8% to 13 % com- pared to the latter, depending on the number and the characteristics of the PKEs that are combined. Moreover, we prove that for given PKEs to hybridize, the ciphertext communication cost of the spilling-cascade is optimal.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. ACNS 2025
Keywords
PKE combinerKEM hybridizationCascadePost-Quantum CryptographyHybrid Key Exchange
Contact author(s)
celine chevalier @ ens fr
guirec lebrun @ ens fr
ange martinelli @ ssi gouv fr
History
2025-04-12: last of 2 revisions
2023-06-09: received
See all versions
Short URL
https://ia.cr/2023/898
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/898,
      author = {Céline Chevalier and Guirec Lebrun and Ange Martinelli},
      title = {Spilling-Cascade: an Optimal {PKE} Combiner for {KEM} Hybridization},
      howpublished = {Cryptology {ePrint} Archive, Paper 2023/898},
      year = {2023},
      url = {https://eprint.iacr.org/2023/898}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.