Paper 2025/1228
Quantum-Safe Hybrid Key Exchanges with KEM-Based Authentication
Abstract
Authenticated Key Exchange (AKE) between any two entities is one of the most important security protocols available for securing our digital networks and infrastructures. In PQCrypto 2023, Bruckner, Ramacher and Striecks proposed a novel hybrid AKE (HAKE) protocol dubbed Muckle+ that is particularly useful in large quantum-safe networks consisting of a large number of nodes. Their protocol is hybrid in the sense that it allows key material from conventional, post-quantum, and quantum cryptography primitives to be incorporated into a single end-to-end authenticated shared key. To achieve the desired authentication properties, Muckle+ utilizes post-quantum digital signatures. However, available instantiations of such signatures schemes are not yet efficient enough compared to their post-quantum key-encapsulation mechanism (KEM) counterparts, particularly in large networks with potentially several connections in a short period of time. To mitigate this gap, we propose Muckle# that pushes the efficiency boundaries of currently known HAKE constructions. Muckle# uses post-quantum key-encapsulating mechanisms for implicit authentication inspired by recent works done in the area of Transport Layer Security (TLS) protocols, particularly, in KEMTLS (CCS'20). We port those ideas to the HAKE framework and develop novel proof techniques on the way. Due to our KEM-based approach, the resulting protocol has a slightly different message flow compared to prior work that we carefully align with the HAKE framework and which makes our changes to Muckle+ non-trivial. Lastly, we evaluate the approach by a prototypical implementation and a direct comparison with Muckle+ to highlight the efficiency gains.
Note: A version of this paper without implementation was uploaded to the arXiv on 6th November 2024.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- hybrid authenticated key exchangepost-quantum cryptographyquantum cryptography
- Contact author(s)
-
kit battarbee @ ed ac uk
christoph striecks @ ait ac at
ludovic perret @ epita fr
Sebastian Ramacher @ ait ac at
kverhaeghe @ student ethz ch - History
- 2025-07-23: revised
- 2025-07-02: received
- See all versions
- Short URL
- https://ia.cr/2025/1228
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1228,
author = {Christopher Battarbee and Christoph Striecks and Ludovic Perret and Sebastian Ramacher and Kevin Verhaeghe},
title = {Quantum-Safe Hybrid Key Exchanges with {KEM}-Based Authentication},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1228},
year = {2025},
url = {https://eprint.iacr.org/2025/1228}
}