Paper 2026/020

HIC Is All You Need: Practical Post-Quantum Password-Authenticated Public-Key Encryption

Afonso Arriaga, University of Luxembourg
David Mestel, Maastricht University
Jan Oupický, University of Luxembourg
Peter Browne Rønne, University of Luxembourg
Marjan Škrobot, University of Luxembourg
Abstract

Password-Authenticated Public Key Encryption (PAPKE) enables secure encryption using only a shared, human-memorable password—eliminating the need for trusted intermediaries or pre-established infrastructure. It allows a sender to encrypt a message for a recipient, using the recipient's password-authenticated public key and a shared password, while provably resisting man-in-the-middle and offline dictionary attacks. PAPKE's support for reusable password-authenticated public keys makes it especially suitable for asynchronous, PKI-free communication scenarios. An important open problem is to construct PAPKE schemes that are secure against quantum adversaries, as existing instantiations rely on Diffie-Hellman assumptions. The PAPKE-IC construction (ACNS 2019) is generic and admits integration with post-quantum PKE schemes. However, the scheme assumes an Ideal Cipher (IC) over the public key domain, which is large for most post-quantum PKE schemes. While an IC is typically instantiated using a block cipher, standard block ciphers operate over much smaller domains (e.g., 128 or 256 bits). Alternatively, one can use an 8-round Feistel network, which achieves indifferentiability from an ideal cipher, or domain extenders. The latter are inefficient at the domain sizes required, making the efficient and secure instantiation of the IC in PAPKE-IC, in combination with post-quantum PKE, particularly challenging. In this paper, we propose PAPKE-HIC, a UC-secure PAPKE scheme built from a PKE scheme and a Half-Ideal Cipher (HIC, introduced at EUROCRYPT 2023), which circumvents the challenges of instantiating ideal ciphers over large domains. We provide a detailed security proof of PAPKE-HIC and establish precise requirements for the underlying PKE: strong robustness, one-wayness, ciphertext anonymity, and pseudo-uniformity of public keys. Our analysis identifies a gap in the original PAPKE-IC security proof, motivating the introduction of a novel property, which we denote Decryption Robustness (DROB-CCA). Although DROB-CCA is implied by strong robustness (SROB-CCA), the reduction is not tight and incurs a quadratic security loss. We analyze which PKE schemes directly satisfy DROB-CCA, and conclude by presenting concrete instantiations of PAPKE-HIC. To our knowledge, this is the first practical, post-quantum instantiation of the PAPKE primitive.

Note: Grammar and stylistic fixes; corrected definition of the AI-CCA decryption oracle; clarified Theorem 1 proof step.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Major revision. CT-RSAC 2026
DOI
10.1007/978-3-032-22931-1_5
Keywords
password authenticated key exchangepublic key encryptionuniversal composabilitypost-quantumauthentication
Contact author(s)
afonso delerue @ uni lu
david mestel @ maastrichtuniversity nl
jan oupicky @ uni lu
peter roenne @ uni lu
marjanskrobot @ gmail com
History
2026-06-20: revised
2026-01-06: received
See all versions
Short URL
https://ia.cr/2026/020
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/020,
      author = {Afonso Arriaga and David Mestel and Jan Oupický and Peter Browne Rønne and Marjan Škrobot},
      title = {{HIC} Is All You Need: Practical Post-Quantum Password-Authenticated Public-Key Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/020},
      year = {2026},
      doi = {10.1007/978-3-032-22931-1_5},
      url = {https://eprint.iacr.org/2026/020}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.