Paper 2026/1845
Lattice-based NIKE with optimal tightness
Abstract
In this work we present a new variant of the non-interactive key exchange (NIKE) scheme based on the learning with errors (LWE) assumption and prove its security with a security reduction that incurs a security loss that is only linear in the number of users. This improves upon all prior reductions for lattice-based NIKE schemes, which had a security loss that is quadratic in the number of users. Our tight reduction can handle the setting with super-polynomial modulus-to-noise ratio and negligible correctness error as well as the more challenging setting with polynomial modulus-to-noise ratio and inverse polynomial correctness error. We also give a matching lower bound on the tightness for a natural class of lattice-based NIKE schemes (that captures all existing variants of lattice-based NIKE), showing that our security loss is optimal (up to constant factors). This generalizes a lower bound by Hesse, Hofheinz and Kohl (Crypto 2018) and is the first lower bound for the tightness of lattice-based NIKE schemes. Several previous lower bounds for the tightness of NIKE exist, but none of them can be applied to lattice-based schemes.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- A major revision of an IACR publication in TCC 2026
- Keywords
- Non-interactive key exchangeLearning with errorsTightness
- Contact author(s)
-
roman langrehr @ uwaterloo ca
oliver tran @ alumni ethz ch - History
- 2026-09-01: approved
- 2026-08-31: received
- See all versions
- Short URL
- https://ia.cr/2026/1845
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1845,
author = {Roman Langrehr and Si An Oliver Tran},
title = {Lattice-based {NIKE} with optimal tightness},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1845},
year = {2026},
url = {https://eprint.iacr.org/2026/1845}
}