Paper 2026/1525

NAIBI: Binding Reconciliation KEMs and Ephemeral Key Agreement over Non-Split Commutative Algebras

Sidoine Djimnaibeye, ChadUP, N'Djamena, Chad
Djiby Sow, Université Cheikh Anta Diop
Mahamat Borgou Hassan, ENASTIC, N'Djamena, Chad
Daniel Tieudjo, University of Ngaoundéré
Ganga Tchawa, National Agency for Secure Documents (ANATS), N'Djamena, Chad
Abstract

We propose NAIBI-Full, a lattice-based key encapsulation mechanism (KEM) together with its forward-secure ephemeral key-agreement protocols, built on the regular representation $\rho$ of the non-split commutative algebra $\mathcal{A}_\alpha = R_q[y]/(y^k - \alpha)$ over $R_q = \mathbb{Z}_q[x]/(x^n + 1)$, with $k \in \{2,3\}$ and $\alpha$ a non-$k$-th power. Each party publishes the full matrix $\mathbf{t} = A\rho(\mathbf{s}) + \mathbf{e} \in R_q^{k \times k}$; because $\rho(\mathcal{A}_\alpha)$ is commutative, the cross-product collapses to small noise and a Peikert hint closes the gap to exact agreement, even though the public matrix $A$ is fully generic in $M_k(R_q)$. Hardness rests on a single, well-localised assumption: structured-secret Module-LWE $\mathrm{MLWE}_\rho$, which we identify exactly with a $\rho(y)$-linked $k$-sample MLWE problem via column decomposition, placing it inside the well-cryptanalysed MLWE landscape of ML-KEM. NAIBI-Full is the conservative member of the family: a clean account in terms of a standard lattice assumption, at the cost of $k^2$-element public keys and ciphertexts. Three primitives follow from this single core: an IND-CCA2 KEM (the $\mathrm{FO}^{\not\bot}$ transform, i.e. with implicit rejection, in the ROM and QROM) and two forward-secure ephemeral protocols, ephemeral-static and ephemeral-ephemeral. For the KEM we prove in addition a statistical, decapsulation-level binding correctness guarantee, with collision probability at most $(2/3 + 1/(3q))^{\lceil n/2 \rceil} + (8/q)^{n/2} + 2^{-256}$, below $2^{-148}$ at every parameter set. That binding survives in the malicious-key model on the public-key axis (MAL-BIND-K-PK, with a $q_H$ factor on the mechanism term), with no distributional assumption on the adversarial keys: the property ML-KEM is known to lack, and which the seed key format of FIPS 203 (which does restore the ciphertext axis) still leaves unattained. The statistical modality attaches to the accept branch; on the rejection branch, where no KEM admits a statistical guarantee, the rejection key hashes the public key, without which the notion falls to a one-line attack reusing a single $z$ across two malicious keys. We deliberately offer no static-static mode, since it would inherit the active key-mismatch attacks of the Ding/Peikert/NewHope family; NAIBI-Full is confined to its key-mismatch-resistant deployments. Parameter sets cover NIST security Categories 1, 3 and 5, all with $\delta \le 2^{-128}$.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
KEM bindingMAL-BIND-K-CTreconciliationRing-LWEnon-split algebraFujisaki--Okamotoparameter optimisation.
Contact author(s)
d sidoine @ chad-up com
dsow @ ucad edu sn
mahamatborgou @ gmail com
tieudjo @ yahoo com
tchawa8ganga @ gmail com
History
2026-08-17: last of 3 revisions
2026-07-25: received
See all versions
Short URL
https://ia.cr/2026/1525
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/1525,
      author = {Sidoine Djimnaibeye and Djiby Sow and Mahamat Borgou Hassan and Daniel Tieudjo and Ganga Tchawa},
      title = {{NAIBI}: Binding Reconciliation {KEMs} and Ephemeral Key Agreement over Non-Split Commutative Algebras},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1525},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1525}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.