Paper 2025/1000

mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-Optimal

Hongxiao Wang, University of Hong Kong
Ron Steinfeld, Monash University
Markku-Juhani O. Saarinen, Tampere University
Muhammed F. Esgin, Monash University
Siu-Ming Yiu, University of Hong Kong
Abstract

In applications such as secure group communication and broadcasting, it is important to efficiently deliver multiple messages to different recipients at once. To this end, multi-message multi-recipient Public Key Encryption (mmPKE) enables the batch encryption of multiple messages for multiple independent recipients in one go, significantly reducing costs–particularly bandwidth–compared to the trivial solution of encrypting each message individually. This capability is especially desirable in the post-quantum setting, where the ciphertext length is typically significantly larger than the corresponding plaintext. However, almost all prior works on mmPKE are limited to quantum-vulnerable traditional assumptions. In this work, we propose the first CPA-secure mmPKE and Multi-Key Encapsulation Mechanism (mmKEM) from the standard Module Learning with Errors (MLWE) lattice assumption, named mmCipher-PKE and mmCipher-KEM, respectively. Our design proceeds in two steps: (i) We introduce a novel generic construction of mmPKE by proposing a new PKE variant—extended reproducible PKE (XR-PKE)—that enables the reproduction of ciphertexts through additional hints; (ii) We instantiate a lattice-based XR-PKE using a new technique that can precisely estimate the impact of such hints on the ciphertext security while also establishing suitable parameters. We believe both to be of independent interest. As a bonus contribution, we explore generic constructions of adaptively secure mmPKE, resisting adaptive corruption and chosen-ciphertext attacks. We also provide an efficient implementation and thorough evaluation of the practical performance of our mmCipher. The results demonstrate substantial bandwidth and computational savings over the state-of-the-art. For example, for 1024 recipients, our mmCipher-KEM achieves a 23-45× reduction in bandwidth overhead, with ciphertexts only 4-9% larger than the plaintexts (near optimal bandwidth), while also offering a 3-5× reduction in computational cost.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Major revision. USENIX Security 2026
Keywords
Public Key EncryptionmmPKEPost-QuantumLattice
Contact author(s)
hxwang @ cs hku hk
Ron Steinfeld @ monash edu
markku-juhani saarinen @ tuni fi
Muhammed Esgin @ monash edu
smyiu @ cs hku hk
History
2026-03-06: last of 6 revisions
2025-05-30: received
See all versions
Short URL
https://ia.cr/2025/1000
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1000,
      author = {Hongxiao Wang and Ron Steinfeld and Markku-Juhani O. Saarinen and Muhammed F. Esgin and Siu-Ming Yiu},
      title = {{mmCipher}: Batching Post-Quantum Public Key Encryption Made Bandwidth-Optimal},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1000},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1000}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.