Paper 2025/1861

FrodoKEM: A CCA-Secure Learning With Errors Key Encapsulation Mechanism

Lewis Glabush
Patrick Longa
Michael Naehrig
Chris Peikert
Douglas Stebila
Fernando Virdia
Abstract

Large-scale quantum computers capable of implementing Shor's algorithm pose a significant threat to the security of the most widely used public-key cryptographic schemes. This risk has motivated substantial efforts by standards bodies and government agencies to identify and standardize quantum-safe cryptographic systems. Among the proposed solutions, lattice-based cryptography has emerged as the foundation for some of the most promising protocols. This paper describes FrodoKEM, a family of conservative key-encapsulation mechanisms (KEMs) whose security is based on generic, "unstructured" lattices. FrodoKEM is proposed as an alternative to the more efficient lattice schemes that utilize algebraically structured lattices, such as the recently standardized ML-KEM scheme. By relying on generic lattices, FrodoKEM minimizes the potential for future attacks that exploit algebraic structures while enabling simple and compact implementations. Our plain C implementations demonstrate that, despite its conservative design and parameterization, FrodoKEM remains practical. For instance, the full protocol at NIST security level 1 runs in approximately 0.97 ms on a server-class processor, and 4.98 ms on a smartphone-class processor. FrodoKEM obtains (single-target) IND-CCA security using a variant of the Fujisaki-Okamoto transform, applied to an underlying public-key encryption scheme called FrodoPKE. In addition, using a new tool called the Salted Fujisaki-Okamoto (SFO) transform, FrodoKEM is also shown to tightly achieve multi-target security, without increasing the FrodoPKE message length and with a negligible performance impact, based on the multi-target IND-CPA security of FrodoPKE.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published by the IACR in CIC 2025
DOI
10.62056/ayivom2hd
Keywords
Post-Quantum CryptographyLattice CryptographyKey ExchangeMulti-target securityImplementation
Contact author(s)
lewis glabush @ epfl ch
plonga @ microsoft com
mnaehrig @ microsoft com
cpeikert @ umich edu
dstebila @ uwaterloo ca
fernando virdia @ kcl ac uk
History
2025-10-08: approved
2025-10-07: received
See all versions
Short URL
https://ia.cr/2025/1861
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1861,
      author = {Lewis Glabush and Patrick Longa and Michael Naehrig and Chris Peikert and Douglas Stebila and Fernando Virdia},
      title = {{FrodoKEM}: A {CCA}-Secure Learning With Errors Key Encapsulation Mechanism},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1861},
      year = {2025},
      doi = {10.62056/ayivom2hd},
      url = {https://eprint.iacr.org/2025/1861}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.