Paper 2026/2268

Kopis: A KEM for Obfuscation

Andrea Basso, IBM Research Europe – Zurich
Michael Rosenberg
Abstract

Password-authenticated key exchange (PAKE) and obfuscated key exchange (OKEX) are widely used protocols, appearing in passport access control, Tor's censorship evasion, and more. As quantum threats grow nearer, there have been an increasing number of proposals for post-quantum PAKE and OKEX. All such protocols are similar in that they build on a KEM, obfuscating public keys and/or ciphertexts sent over the wire, e.g., by adding a random mask or applying an ideal cipher. Many propose instantiation with ML-KEM, a NIST-standardized lattice-based KEM. Unfortunately, ML-KEM is a poor fit for these obfuscating protocols. The algebraic structure of ML-KEM public keys and ciphertexts means that obfuscating these values requires custom procedures for hash-to-vector, matrix expansion, serialization/deserialization, and randomized ciphertext decompression. In order to be broadly useful, these procedures also must be constant-time to prevent side channels and must be standardized to permit interoperability. No such set of procedures exists today. We observe that the barriers to instantiating PAKE and OKEX disappear if some of the KEM's algebraic structure is removed, i.e., if ML-KEM is replaced with a KEM whose public keys and ciphertexts appear to be uniform as bytestrings. In this work, we specify Kopis, a Module Learning-with-Rounding (MLWR) KEM with public keys and ciphertexts that are uniform as bytestrings. Kopis is intended to be a drop-in replacement for ML-KEM, in size, speed, and security. Kopis is nearly identical to Saber, a NIST PQC finalist, and thus inherits its years of cryptanalysis. We demonstrate that Kopis bears the security properties needed for use in various PAKE and OKEX schemes and provide a formally verified Rust implementation complete with portable, AVX2, and NEON backends, and a non-formally-verified C implementation for Cortex-M4. We perform benchmarks and find that Kopis is comparable to and often outperforms the fastest known ML-KEM implementations.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
post-quantum cryptographykey encapsulation mechanismSaberhigh-assurance cryptographyformal verification
Contact author(s)
Andrea Basso @ ibm com
research @ mrosenberg pub
History
2026-09-30: approved
2026-09-29: received
See all versions
Short URL
https://ia.cr/2026/2268
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/2268,
      author = {Andrea Basso and Michael Rosenberg},
      title = {Kopis: A {KEM} for Obfuscation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2268},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2268}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.