Paper 2026/1761
Lightweight Lattice-based Single-Party Public-Key Authenticated Key Exchange
Abstract
Authenticated Key Exchange (AKE) is a cornerstone of secure communication, especially in resource-constrained IoT environments where lightweight and post-quantum security are paramount. While lattice-based cryptography offers promising solutions, existing post-quantum AKE protocols often prioritize strong security notions, such as the use of an IND-CCA encryption scheme, incurring overheads incompatible with IoT devices. This raises a critical question: Can one-way security (OW), a weaker but potentially more efficient notion, suffice for secure AKE in the post-quantum era? We address this challenge by revisiting the ALIKE framework (ISO/IEC 29192-4), which achieves OW-CCA-based AKE using deterministic RSA. However, RSA’s quantum vulnerability and the lack of lattice-based OW-CCA schemes hinder its applicability today. Our work bridges this gap through three key contributions. First, we prove that the Hash-Before-Encrypt (HBE) paradigm generically transforms deterministic OW-CPA schemes into OW-CCA-secure ones. We additionally present the Fujisaki–Okamoto transform and its security proof construction, providing a reference for understanding the efficiency advantages of the proposed HBE-based approach. Second, we modify Bai et al.’s efficient lattice-based OW-CPA scheme to a deterministic variant and rigorously prove its security. Third, we generalize the SPAKE framework to support our OW-CCA construction, enabling post-quantum AKE with minimal assumptions, implement and benchmark the resulting protocol, demonstrating state-of-the-art efficiency for lightweight, quantum-resistant AKE. By relaxing security requirements from IND-CCA to OW-CCA while preserving adaptive security we achieve a practical balance between robustness and performance, paving the way for deployable solutions in constrained environments like IoT and connected vehicles.
Note: This submission is an expanded full version of the paper published at AFRICACRYPT 2026. It includes additional security analysis and proofs, an expanded treatment of the HBE and FO transforms, detailed implementation and performance results, and extended discussions and comparisons that were not included in the original publication.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. Major revision. AFRICACRYPT 2026 — 13th International Conference on Cryptology in Africa
- DOI
- 10.1007/978-3-032-31130-6_1
- Keywords
- Post-quantum cryptographyModule-NTRUAuthenticated Key ExchangeOW-CCAHBESPAKEFujisaki-Okamoto transform
- Contact author(s)
-
alexkellyaidan @ gmail com
sebastien canard @ telecom-paris fr
emmanuelfouotsa @ yahoo fr
melchisedechmbeng7 @ gmail com - History
- 2026-08-22: approved
- 2026-08-21: received
- See all versions
- Short URL
- https://ia.cr/2026/1761
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1761,
author = {Alex Aïdan and Sébastien Canard and Emmanuel Fouotsa and Nyiang Melchisedech Mbeng},
title = {Lightweight Lattice-based Single-Party Public-Key Authenticated Key Exchange},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1761},
year = {2026},
doi = {10.1007/978-3-032-31130-6_1},
url = {https://eprint.iacr.org/2026/1761}
}