Paper 2026/2220
Threshold Key Encapsulation Mechanisms via MPC: ML-KEM Compatibility and Optimization
Abstract
There is currently a strong interest in designing standard-compatible threshold cryptographic primitives, a trend bolstered by NIST's Call for Multi-Party Threshold Schemes (NIST IR 8214C). While Multi-Party Computation (MPC) can be applied to the construction of threshold Key Encapsulation Mechanism (KEM) from NIST standard ML-KEM scheme to preserve the compatibility with ML-KEM, such a direct construction yields a high number of threshold decapsulation rounds as many as 384 for MK-KEM-512. In this paper, we optimise the round complexity of MPC-based threshold ML-KEM decapsulation. Our first construction (Scheme A) uses masked predicates, parallel coin expansion and global scheduling methods to improve the round complexity of MPC-based ML-KEM decapsulation, while maintaining ML-KEM encapsulation, public key and ciphertext formats. For ML-KEM-512, 768 and 1024, our construction improves the round complexity to 145, 218, and 290, respectively. We also introduce a variant (Scheme B) that uses an MPC-friendly variant of Kyber KEM and KangarooTwelve hash to further improve the round complexity to $35$ at the security level of ML-KEM-512, without full ML-KEM compatibility. In the semi-honest MPC model, we prove Scheme A security by exact composition with ML-KEM, and Scheme B IND-CCA security in the QROM from Module-LWE and negligible decryption failure.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- threshold cryptographykey encapsulation mechanismsML-KEMpost-quantum cryptographymulti-party computation
- Contact author(s)
-
tatheanhdtvt @ gmail com
dongxi liu @ csiro au
sid chau @ acm org
jiafan wang @ csiro au - History
- 2026-09-27: approved
- 2026-09-25: received
- See all versions
- Short URL
- https://ia.cr/2026/2220
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2026/2220,
author = {The-Anh Ta and Dongxi Liu and Sid Chau and Jiafan Wang},
title = {Threshold Key Encapsulation Mechanisms via {MPC}: {ML}-{KEM} Compatibility and Optimization},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2220},
year = {2026},
url = {https://eprint.iacr.org/2026/2220}
}