Paper 2026/1581

Post-Quantum Internet Key Exchange via Authenticated Forward-Secure KEM

Yunlei Zhao, Fudan University
Biming Zhou, Fudan University
Zhixiang Zhao, Fudan University
Yifan Dong, Fudan University
Cheng Huang, Fudan University
Haodong Jiang, Henan Key Laboratory of Network Cryptography Technology
Abstract

In this work, we present a new framework for signature-free, post-quantum secure authenticated key exchange (AKE) that simultaneously satisfies: (1) exchanging at most two standard ciphertexts of a key encapsulation mechanism (KEM); (2) computational symmetry; (3) perfect forward secrecy (PFS); (4) strong resilience to secret-state exposure; (5) strong resistance to decryption-error attacks; (6) admitting instantiations based on the native structure of \textsf{ML-KEM} under the \textsf{MLWE} assumption; and (7) provable security in both the random oracle model (ROM) and the quantum-accessible random oracle model (QROM) under the post-id $\mathsf{eCK}\mbox{-}\mathsf{PFS}$ framework. This resolves several fundamental open questions in the literature. The core technical building block is a new cryptographic primitive, called an \emph{authenticated forward-secure} KEM (AFS-KEM), which unifies authentication and forward secrecy within a single KEM abstraction and may be of independent interest.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
Post-quantumInternet key exchangeAFS-KEMQROMML-KEM
Contact author(s)
ylzhao @ fudan edu cn
bmzhou22 @ m fudan edu cn
hdjiang13 @ 163 com
History
2026-08-14: revised
2026-08-03: received
See all versions
Short URL
https://ia.cr/2026/1581
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2026/1581,
      author = {Yunlei Zhao and Biming Zhou and Zhixiang Zhao and Yifan Dong and Cheng Huang and Haodong Jiang},
      title = {Post-Quantum Internet Key Exchange via Authenticated Forward-Secure {KEM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1581},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1581}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.