Paper 2026/1585
Proving Threshold Regev PKE from Adaptive Hint-MLWE: Efficient, Non-interactive, and CCA Secure
Abstract
Threshold public-key encryption (tPKE) has recently attracted renewed interest, largely due to NIST's call for Multi-Party Threshold Cryptography. While classical tPKE has approached a high state of maturity, its post-quantum counterpart has not. Indeed, thresholdizing the celebrated lattice-based Regev PKE, which forms the basis of ML-KEM, remains unsatisfactory. Interestingly, how to thresholdize Regev PKE has not fundamentally changed in over a decade --- the only thing that has gradually progressed is its security analysis. To this day, it remains open whether threshold Regev can be proven secure while simultaneously satisfying a polynomial modulus, non-interactive decryption, and CCA-compatibility, each of which is essential for practical deployment. We answer this affirmatively, providing the first proof that threshold Regev is secure under the MLWE assumption while satisfying all three requirements. In fact, we prove that it satisfies a very strong form of simulation-based security --- even stronger than what was known under a super-polynomial modulus --- allowing the adversary to obtain partial decryptions even of the challenge ciphertext. At the technical heart of our result is the adaptive hint-MLWE (AHMLWE) problem, an adaptive variant of hint-MLWE where the adversary obtains hints on the MLWE secret with adaptively chosen coefficients. We show that AHMLWE reduces tightly to standard MLWE, which may be of independent interest.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- threshold PKECCAHint-MLWE
- Contact author(s)
-
yisol hwang @ snu ac kr
shuichi katsumata @ pqshield com
minsh @ snu ac kr
guilhem niot @ pqshield com
y song @ snu ac kr - History
- 2026-08-05: revised
- 2026-08-03: received
- See all versions
- Short URL
- https://ia.cr/2026/1585
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1585,
author = {Yisol Hwang and Shuichi Katsumata and Seonhong Min and Guilhem Niot and Yongsoo Song},
title = {Proving Threshold Regev {PKE} from Adaptive Hint-{MLWE}: Efficient, Non-interactive, and {CCA} Secure},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1585},
year = {2026},
url = {https://eprint.iacr.org/2026/1585}
}