Paper 2025/343

On The Multi-target Security of Post-Quantum Key Encapsulation Mechanisms

Lewis Glabush, École Polytechnique Fédérale de Lausanne
Kathrin Hövelmanns, Eindhoven University of Technology
Douglas Stebila, University of Waterloo
Abstract

Practical deployments of key encapsulation mechanisms (KEMs) may entail large servers each using their public keys to communicate with potentially millions of clients simultaneously. While the standard IND-CCA security definition for KEMs considers only a single challenge public key and single challenge ciphertext, it can be relevant to consider \emph{multi-target} scenarios where the adversary aims to break one of many challenge ciphertexts, for one of many challenge public keys. Many post-quantum KEMs have been built by applying the Fujisaki-Okamoto (FO) transform to a public key encryption (PKE) scheme. Although the FO transform incurs only a few bits of security loss for the standard, single-challenge IND-CCA property, this does not hold in the multi-target setting. Attacks have been identified against standards-track FO-based KEMs with 128-bit message spaces (FrodoKEM-640 and HQC-128) which become feasible if the adversary is given many challenge ciphertexts. These attacks exploit the deterministic encryption induced by the FO transform which allows the IND-CCA experiment to be reduced to a search problem on the message space, which in some cases may not be large enough to avoid collisions between pre-computation and challenge values. A cost effective way to amplify the hardness of this search problem is to add a random but public salt during encapsulation. While revised versions of FrodoKEM and HQC have used salts, there has been no proof showing that salting provides multi-ciphertext security. In this work, we formally analyze a salted variant of the Fujisaki-Okamoto transform, in the classical and quantum random oracle model (ROM); for the classical ROM, we show that multi-target IND-CCA security of the resulting KEM tightly reduces to the multi-target IND-CPA security of the underlying PKE. Our results imply that, for FrodoKEM and HQC at the 128-bit security level, replacing the FO transform with the salted variant can recover 62 bits of multi-target security, at the cost of a very small overhead increase.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published by the IACR in CIC 2026
DOI
10.62056/a63zl83y6
Keywords
Fujisaki–Okamoto transformkey exchangequantum random oracle modelmulti-challenge securityFrodoKEMHQCML-KEM
Contact author(s)
lewis glabush @ epfl ch
kathrin @ hoevelmanns net
dstebila @ uwaterloo ca
History
2026-05-05: last of 2 revisions
2025-02-24: received
See all versions
Short URL
https://ia.cr/2025/343
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2025/343,
      author = {Lewis Glabush and Kathrin Hövelmanns and Douglas Stebila},
      title = {On The Multi-target Security of Post-Quantum Key Encapsulation Mechanisms},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/343},
      year = {2025},
      doi = {10.62056/a63zl83y6},
      url = {https://eprint.iacr.org/2025/343}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.