Paper 2026/2207

Two Laws of Public-Key Cryptography

Trey Li, The University of Manchester
Abstract

We discover two laws governing public-key key exchange and public-key encryption. The first states that a non-interactive key-exchange scheme is secure only if it is kleptographically insecure. The second states that a public-key encryption scheme is secure only if it is kleptographically insecure. They give two impossibility results: no kleptographically secure non-interactive key exchange with pseudorandom shared keys exists, and no kleptographically secure public-key encryption with pseudorandom ciphertexts exists. More precisely, no non-interactive key-exchange scheme can simultaneously establish pseudorandom shared keys and support black-box execution in which the user observes only the public keys and the final shared keys output by the black box, and no public-key encryption scheme can simultaneously have pseudorandom ciphertexts and support black-box execution in which the user observes only the public keys and plaintexts input to the black box and the ciphertexts output by it. Our argument turns the very shield of a primitive into a spear against itself, showing that the security guarantee of the primitive is precisely what enables a kleptographic attack. We instantiate the laws with two post-quantum schemes: CSIDH and Regev encryption.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
LawsPublic-Key CryptographyKleptographyNon-Interactive Key ExchangePublic-Key EncryptionCSIDHLWE
Contact author(s)
trey li @ manchester ac uk
History
2026-09-27: approved
2026-09-24: received
See all versions
Short URL
https://ia.cr/2026/2207
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2207,
      author = {Trey Li},
      title = {Two Laws of Public-Key Cryptography},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2207},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2207}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.