Paper 2026/1525
NAIBI: Binding Reconciliation KEMs and Ephemeral Key Agreement over Non-Split Commutative Algebras
Abstract
We propose NAIBI-Full, a lattice-based key encapsulation mechanism (KEM) together with its forward-secure ephemeral key-agreement protocols, built on the regular representation $\rho$ of the non-split commutative algebra $\mathcal{A}_\alpha = R_q[y]/(y^k - \alpha)$ over $R_q = \mathbb{Z}_q[x]/(x^n + 1)$, with $k \in \{2,3\}$ and $\alpha$ a non-$k$-th power. Each party publishes the full matrix $\mathbf{t} = A\rho(\mathbf{s}) + \mathbf{e} \in R_q^{k \times k}$; because $\rho(\mathcal{A}_\alpha)$ is commutative, the cross-product collapses to small noise and a Peikert hint closes the gap to exact agreement, even though the public matrix $A$ is fully generic in $M_k(R_q)$. Hardness rests on a single, well-localised assumption: structured-secret Module-LWE $\mathrm{MLWE}_\rho$, which we identify exactly with a $\rho(y)$-linked $k$-sample MLWE problem via column decomposition, placing it inside the well-cryptanalysed MLWE landscape of ML-KEM. NAIBI-Full is the conservative member of the family: a clean account in terms of a standard lattice assumption, at the cost of $k^2$-element public keys and ciphertexts. Three primitives follow from this single core: an IND-CCA2 KEM (the $\mathrm{FO}^{\not\bot}$ transform, i.e. with implicit rejection, in the ROM and QROM) and two forward-secure ephemeral protocols, ephemeral-static and ephemeral-ephemeral. For the KEM we prove in addition a statistical, decapsulation-level binding correctness guarantee, with collision probability at most $(2/3 + 1/(3q))^{\lceil n/2 \rceil} + (8/q)^{n/2} + 2^{-256}$, below $2^{-148}$ at every parameter set. That binding survives in the malicious-key model on the public-key axis (MAL-BIND-K-PK, with a $q_H$ factor on the mechanism term), with no distributional assumption on the adversarial keys: the property ML-KEM is known to lack, and which the seed key format of FIPS 203 (which does restore the ciphertext axis) still leaves unattained. The statistical modality attaches to the accept branch; on the rejection branch, where no KEM admits a statistical guarantee, the rejection key hashes the public key, without which the notion falls to a one-line attack reusing a single $z$ across two malicious keys. We deliberately offer no static-static mode, since it would inherit the active key-mismatch attacks of the Ding/Peikert/NewHope family; NAIBI-Full is confined to its key-mismatch-resistant deployments. Parameter sets cover NIST security Categories 1, 3 and 5, all with $\delta \le 2^{-128}$.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- KEM bindingMAL-BIND-K-CTreconciliationRing-LWEnon-split algebraFujisaki--Okamotoparameter optimisation.
- Contact author(s)
-
d sidoine @ chad-up com
dsow @ ucad edu sn
mahamatborgou @ gmail com
tieudjo @ yahoo com
tchawa8ganga @ gmail com - History
- 2026-08-17: last of 3 revisions
- 2026-07-25: received
- See all versions
- Short URL
- https://ia.cr/2026/1525
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2026/1525,
author = {Sidoine Djimnaibeye and Djiby Sow and Mahamat Borgou Hassan and Daniel Tieudjo and Ganga Tchawa},
title = {{NAIBI}: Binding Reconciliation {KEMs} and Ephemeral Key Agreement over Non-Split Commutative Algebras},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1525},
year = {2026},
url = {https://eprint.iacr.org/2026/1525}
}