Paper 2026/2207
Two Laws of Public-Key Cryptography
Abstract
We discover two laws governing public-key key exchange and public-key encryption. The first states that a non-interactive key-exchange scheme is secure only if it is kleptographically insecure. The second states that a public-key encryption scheme is secure only if it is kleptographically insecure. They give two impossibility results: no kleptographically secure non-interactive key exchange with pseudorandom shared keys exists, and no kleptographically secure public-key encryption with pseudorandom ciphertexts exists. More precisely, no non-interactive key-exchange scheme can simultaneously establish pseudorandom shared keys and support black-box execution in which the user observes only the public keys and the final shared keys output by the black box, and no public-key encryption scheme can simultaneously have pseudorandom ciphertexts and support black-box execution in which the user observes only the public keys and plaintexts input to the black box and the ciphertexts output by it. Our argument turns the very shield of a primitive into a spear against itself, showing that the security guarantee of the primitive is precisely what enables a kleptographic attack. We instantiate the laws with two post-quantum schemes: CSIDH and Regev encryption.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- Preprint.
- Keywords
- LawsPublic-Key CryptographyKleptographyNon-Interactive Key ExchangePublic-Key EncryptionCSIDHLWE
- Contact author(s)
- trey li @ manchester ac uk
- History
- 2026-09-27: approved
- 2026-09-24: received
- See all versions
- Short URL
- https://ia.cr/2026/2207
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2207,
author = {Trey Li},
title = {Two Laws of Public-Key Cryptography},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2207},
year = {2026},
url = {https://eprint.iacr.org/2026/2207}
}