Paper 2024/1360
CPA-secure KEMs are also sufficient for Post-Quantum TLS 1.3
Abstract
In the post-quantum migration of TLS 1.3, an ephemeral Diffie-Hellman must be replaced with a post-quantum key encapsulation mechanism (KEM). At EUROCRYPT 2022, Huguenin-Dumittan and Vaudenay [EC:HugVau22] demonstrated that KEMs with standard CPA security are sufficient for the security of the TLS1.3 handshake. However, their result is only proven in the random oracle model (ROM), and as the authors comment, their reduction is very much non-tight and not sufficient to guarantee security in practice due to the
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A minor revision of an IACR publication in ASIACRYPT 2024
- Keywords
- TLS1.3tightnessQROMKEM-TLS
- Contact author(s)
-
bmzhou22 @ m fudan edu cn
hdjiang13 @ 163 com - History
- 2024-09-25: last of 4 revisions
- 2024-08-29: received
- See all versions
- Short URL
- https://ia.cr/2024/1360
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1360, author = {Biming Zhou and Haodong Jiang and Yunlei Zhao}, title = {{CPA}-secure {KEMs} are also sufficient for Post-Quantum {TLS} 1.3}, howpublished = {Cryptology {ePrint} Archive, Paper 2024/1360}, year = {2024}, url = {https://eprint.iacr.org/2024/1360} }