Paper 2026/2201

Dance with Noise: Safely Trade Minor Decryption Failures for More Compact KEMs with Applications to IKEv2

Zidi Zhuang, Institute of Software, Chinese Academy of Sciences, University of Chinese Academy of Sciences
Yuyang Xiao, Institute of Software, Chinese Academy of Sciences, University of Chinese Academy of Sciences
Long Chen, Institute of Software, Chinese Academy of Sciences
Qiang Tang, The University of Sydney
Zhenfeng Zhang, Institute of Software, Chinese Academy of Sciences
Abstract

The standardization of post-quantum cryptography, notably ML-KEM, introduces a severe network bottleneck: large public keys and ciphertexts often exceed the Maximum Transmission Unit (MTU) limits of UDP-based protocols. This size explosion inevitably leads to unreliable IP-layer fragmentation or forces complex protocol workarounds. To overcome this, we propose a novel design philosophy for post-quantum Authenticated Key Exchange (AKE). We challenge the rigid cryptographic paradigm that mandates negligible decryption failure rates (DFR). By safely trading minor, manageable decryption failures for aggressive size compression, we drastically reduce the bandwidth footprint of lattice KEMs in ephemeral exchanges. We demonstrate this approach via a compact AKE for the Internet Key Exchange protocol (IKEv2). Integrating standard ML-KEM into IKEv2 currently necessitates the high-latency IKE_INTERMEDIATE exchange (RFC 9242) to distribute large payloads. By employing our compressed KEM design (800-byte public key, 928-byte ciphertext), the entire key exchange fits within the initial IKE_SA_INIT packet, completely eliminating the need for RFC 9242. To ensure that protocol aborts caused by decryption failures do not introduce security vulnerabilities, we formalize IND-CPAF (Indistinguishability under Chosen Plaintext Attack with Failures) to rigorously bound failure-dependent leakage. More importantly, we prove our IKEv2 instantiation still secure in the classical Canetti-Krawczyk model. Finally, our implementation in the strongSwan IPsec library confirms a fragmentation-free handshake: over 10,000 real-world connections, it achieves a 48.8 ms average setup time---matching classical ECDH---and keeps initial packets strictly under the 1280-byte IPv6 MTU, with merely a 0.002% retry rate.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. ACM CCS 2026
DOI
10.1145/3830454.3846669
Keywords
Post-quantum MigrationIKEv2IP FragmentationKEM
Contact author(s)
zidi2021 @ iscas ac cn
xiaoyuyang2023 @ iscas ac cn
chenlong @ iscas ac cn
qiang tang @ sydney edu au
zhenfeng @ iscas ac cn
History
2026-09-27: approved
2026-09-24: received
See all versions
Short URL
https://ia.cr/2026/2201
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/2201,
      author = {Zidi Zhuang and Yuyang Xiao and Long Chen and Qiang Tang and Zhenfeng Zhang},
      title = {Dance with Noise: Safely Trade Minor Decryption Failures for More Compact {KEMs} with Applications to {IKEv2}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2201},
      year = {2026},
      doi = {10.1145/3830454.3846669},
      url = {https://eprint.iacr.org/2026/2201}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.