Paper 2026/1926
Symmetric and Asymmetric Anonymous Authenticated KEM
Abstract
The terms Signcryption, Split KEM, and Authenticated Key-Encapsulation Mechanism (AKEM) are often used synonymously to capture the amalgamation of a KEM and a Digital Signature Scheme in a single primitive. This means that a sender Alice can encapsulate a symmetric secret to the public key of receiver Bob, and Bob can use Alice's public key to verify that Alice was indeed the sender. Some constructions of AKEM additionally use symmetric pre-shared key material between Alice and Bob to redundantly protect the confidentiality and authenticity of the encapsulated symmetric secret. So far, only special variants of such redundancy have been studied in the literature. Furthermore, beyond confidentiality and authenticity, anonymity of senders and receivers is a desirable property of AKEM that has received little attention yet. In this work, we begin with formally defining strong compatible notions of confidentiality, authenticity, and anonymity for AKEM. In these notions, Alice and Bob can redundantly protect the encapsulated secret using all possible combinations of asymmetric sender key, asymmetric receiver key, and symmetric pre-shared key material. For every such combination, we develop an efficient construction from standard primitives. Our consideration of anonymity and the use of symmetric pre-shared key material provokes the study of a tagging and detection mechanism: When Bob receives a ciphertext that is anonymously protected with a pre-shared key, he needs to detect which out of multiple candidate pre-shared keys to use for decryption. We prove that this detection cannot be substantially more efficient than preforming trial decryptions, even when permitting pre-computation. This result is of independent interest and may have broader applications as we prove its equivalence to 1-out-of-n multi-key decryption, resp. verification, in Symmetric Encryption and Message Authentication Codes.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Authenticated KEMSigncryptionAnonymityRedundant SecurityKey TaggingLower Bound
- Contact author(s)
-
benedikt auerbach @ pqshield com
riepel @ cispa de
paul roesler @ fau de
lea thiemt @ fau de
julian thomas @ fau de - History
- 2026-09-12: approved
- 2026-09-08: received
- See all versions
- Short URL
- https://ia.cr/2026/1926
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1926,
author = {Benedikt Auerbach and Doreen Riepel and Paul Rösler and Lea Thiemt and Julian Thomas},
title = {Symmetric and Asymmetric Anonymous Authenticated {KEM}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1926},
year = {2026},
url = {https://eprint.iacr.org/2026/1926}
}