Paper 2025/1655

Lattice-based Multi-message Multi-recipient KEM/PKE with Malicious Security

Zeyu Liu, Yale University
Katerina Sotiraki, Yale University
Eran Tromer, Boston University
Yunhao Wang, Yale University
Abstract

The efficiency of Public Key Encryption (PKE) and Key Encapsulation Mechanism (KEM), and in particular their large ciphertext size, is a bottleneck in real-world systems. This worsens in post-quantum secure schemes (e.g., lattice-based ones), whose ciphertexts are an order of magnitude larger than prior ones.%their non-post-quantum counterparts. The work of Kurosawa (PKC'02) introduced multi-message multi-recipient PKE (mmPKE) to reduce the amortized ciphertext size when sending messages to more than one recipient. This notion naturally extends to multi-message multi-recipient KEM (mmKEM). In this work, we first show concrete attacks on existing lattice-based mmPKE schemes: Using maliciously-crafted recipient public keys, these attacks completely break semantic security and key privacy, and are inherently undetectable. We then introduce the first lattice-based mmKEM scheme that maintains full privacy even in the presence of maliciously-generated public keys. Concretely, the ciphertext size of our mmKEM for 100 recipients is ${\sim} 8\times$ smaller than naively using Crystals-Kyber. We also show how to extend our mmKEM to mmPKE, achieving a scheme that outperforms all prior lattice-based mmPKE schemes in terms of both security and efficiency. We additionally show a similar efficiency gain when applied to batched random oblivious transfer, and to group oblivious message retrieval. Our scheme is proven secure under a new Module-LWE variant assumption, Oracle Module-LWE, which can be of its own independent interest. We reduce standard MLWE to this new assumption for some parameter regimes, which also gives intuition on why this assumption holds for the parameter we are interested in (along with additional cryptanalysis). Furthermore, we show an asymptotically efficient compiler that removes the assumption made in prior works that recipients know their position in the list of intended recipients for every ciphertext.

Note: Update on 10/19/2025: editorial fix of the evaluation section and additional notes in acknowledgments. Update on 03/05/2026: updated our concrete parameters to mitigate against the attack in 2026/177 and added discussion on 2025/1000.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A minor revision of an IACR publication in ASIACRYPT 2025
Keywords
Public Key EncryptionModule-LWE
Contact author(s)
zeyu liu @ yale edu
katerina sotiraki @ yale edu
eprint2eran @ tromer org
yunhao wang @ yale edu
History
2026-03-04: last of 2 revisions
2025-09-12: received
See all versions
Short URL
https://ia.cr/2025/1655
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1655,
      author = {Zeyu Liu and Katerina Sotiraki and Eran Tromer and Yunhao Wang},
      title = {Lattice-based Multi-message Multi-recipient {KEM}/{PKE} with Malicious Security},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1655},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1655}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.