Paper 2025/1655
Lattice-based Multi-message Multi-recipient KEM/PKE with Malicious Security
Abstract
The efficiency of Public Key Encryption (PKE) and Key Encapsulation Mechanism (KEM), and in particular their large ciphertext size, is a bottleneck in real-world systems. This worsens in post-quantum secure schemes (e.g., lattice-based ones), whose ciphertexts are an order of magnitude larger than prior ones.%their non-post-quantum counterparts. The work of Kurosawa (PKC'02) introduced multi-message multi-recipient PKE (mmPKE) to reduce the amortized ciphertext size when sending messages to more than one recipient. This notion naturally extends to multi-message multi-recipient KEM (mmKEM). In this work, we first show concrete attacks on existing lattice-based mmPKE schemes: Using maliciously-crafted recipient public keys, these attacks completely break semantic security and key privacy, and are inherently undetectable. We then introduce the first lattice-based mmKEM scheme that maintains full privacy even in the presence of maliciously-generated public keys. Concretely, the ciphertext size of our mmKEM for 100 recipients is ${\sim} 8\times$ smaller than naively using Crystals-Kyber. We also show how to extend our mmKEM to mmPKE, achieving a scheme that outperforms all prior lattice-based mmPKE schemes in terms of both security and efficiency. We additionally show a similar efficiency gain when applied to batched random oblivious transfer, and to group oblivious message retrieval. Our scheme is proven secure under a new Module-LWE variant assumption, Oracle Module-LWE, which can be of its own independent interest. We reduce standard MLWE to this new assumption for some parameter regimes, which also gives intuition on why this assumption holds for the parameter we are interested in (along with additional cryptanalysis). Furthermore, we show an asymptotically efficient compiler that removes the assumption made in prior works that recipients know their position in the list of intended recipients for every ciphertext.
Note: Update on 10/19/2025: editorial fix of the evaluation section and additional notes in acknowledgments. Update on 03/05/2026: updated our concrete parameters to mitigate against the attack in 2026/177 and added discussion on 2025/1000.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A minor revision of an IACR publication in ASIACRYPT 2025
- Keywords
- Public Key EncryptionModule-LWE
- Contact author(s)
-
zeyu liu @ yale edu
katerina sotiraki @ yale edu
eprint2eran @ tromer org
yunhao wang @ yale edu - History
- 2026-03-04: last of 2 revisions
- 2025-09-12: received
- See all versions
- Short URL
- https://ia.cr/2025/1655
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1655,
author = {Zeyu Liu and Katerina Sotiraki and Eran Tromer and Yunhao Wang},
title = {Lattice-based Multi-message Multi-recipient {KEM}/{PKE} with Malicious Security},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1655},
year = {2025},
url = {https://eprint.iacr.org/2025/1655}
}