Paper 2026/125

StarFortress: Hybrid KEMs with Diffie-Hellman Inlining

Deirdre Connolly, Oracle, Selkie Cryptography
Paul Grubbs, University of Michigan–Ann Arbor
Abstract

This short paper formally specifies and analyzes the UG hybrid KEM construction from the IRTF CFRG’s recent draft on hybrid (post-quantum/traditional) KEMs. The UG construction is an optimized hybrid of a Diffie-Hellman (DH)-based KEM in a nominal group and a generic IND-CCA KEM. The main optimization is that the group elements derived in the DH-based KEM are “inlined” in the key derivation, saving unnecessary hashing. We perform two security analyses of the UG construction: one shows UG is IND-CCA even if the generic IND-CCA KEM is broken; the other complementary analysis shows UG is IND-CCA even if the DH assumptions in the nominal group are broken (by, e.g., a cryptographically-relevant quantum computer).

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Hybrid KEMPost-Quantum CryptographyPublic-Key CryptographyKEMKEM combinerIND-CCA
Contact author(s)
durumcrustulum @ gmail com
paulgrubbs12 @ gmail com
History
2026-01-30: revised
2026-01-26: received
See all versions
Short URL
https://ia.cr/2026/125
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/125,
      author = {Deirdre Connolly and Paul Grubbs},
      title = {{StarFortress}: Hybrid {KEMs} with Diffie-Hellman Inlining},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/125},
      year = {2026},
      url = {https://eprint.iacr.org/2026/125}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.