Paper 2026/1749
CAKE-HI - Compact Authenticated Key Exchange Hiding Identities
Abstract
Modern public-key cryptography is threatened by advances in quantum computing. As a result, there has been a shift towards cryptographic algorithms that can resist attacks by a quantum computer. However, these algorithms use significantly longer keys, and produce larger ciphertexts and digital signatures than their classical counterparts. These bigger sizes pose problems for devices that are bandwidth- and/or power-limited, and wish to establish a secure, quantum resistant communication channel with another device. In order to reduce the overhead of using these algorithms in challenging environments while maintaining security posture, we present Compact Authenticated Key Exchange – Hiding Identities (CAKE-HI). To evaluate our protocol, we compare the key exchange handshake size and computational efficiency of mutual authenticated TLS and CAKE-HI. Measurements show that CAKE-HI significantly reduces the handshake size and the computational overhead of establishing a quantum-secure link. In addition, we formalize and prove security properties about CAKE-HI in the symbolic and computational model using the protocol analysis frameworks Verifpal and CryptoVerif.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- authenticatedcompactcryptographykey ex- changequantum-resilientbandwidth-limitedpower-limitedminimalistic
- Contact author(s)
-
uri @ ll mit edu
itkis @ ll mit edu
rkh @ ll mit edu
Brandon Luo @ ll mit edu
sean omelia @ ll mit edu
Brian Proulx @ ll mit edu
David Stott @ ll mit edu
Gabriel Torres @ ll mit edu
David Wilson @ ll mit edu - History
- 2026-08-22: approved
- 2026-08-20: received
- See all versions
- Short URL
- https://ia.cr/2026/1749
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1749,
author = {Uri Blumenthal and Gene Itkis and Roger Khazan and Brandon Luo and Sean O'Melia and Brian Proulx and David Stott and Gabriel Torres and David A. Wilson},
title = {{CAKE}-{HI} - Compact Authenticated Key Exchange Hiding Identities},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1749},
year = {2026},
url = {https://eprint.iacr.org/2026/1749}
}