






















Céline Chevalier, DIENS, École normale supérieure, CNRS, PSL University, Inria, Paris, France, CRED, Paris-Panthéon-Assas University
Guirec Lebrun, DIENS, École normale supérieure, CNRS, PSL University, Inria, Paris, France, ANSSI, Paris, France
Thomas Legavre, Thales, Gennevilliers, France, Sorbonne Université, CNRS, LIP6, Paris, France, ANSSI, Paris, France
Thomas Ricosset, Thales, Gennevilliers, France
Maxime Roméas, ANSSI, Paris, France
Éric Sageloli, Thales, Gennevilliers, France, DIENS, École normale supérieure, CNRS, PSL University, Inria, Paris, France
Bandwidth remains a major bottleneck in post-quantum cryptography, particularly for authenticated key exchange (AKE) protocols. In this work, we present DAKE, a bandwidth-efficient AKE framework built from double-KEM constructions. DAKE comes in two main versions achieving, respectively, weak and full perfect forward secrecy, as well as explicit authentication. It further admits two variants: a unilateral version, and another where a signature scheme replaces a KEM. They are proven secure in the standard model under eCKw and eCK-PFS, two strong variants of the extended Canetti–Krawczyk framework. DAKE employs a double-KEM, a primitive that encapsulates a single key under two public keys simultaneously. Such constructions can achieve smaller encapsulation sizes than two independent KEM encapsulations, offering a significant bandwidth advantage. To facilitate the design of double-KEMs compatible with DAKE, we introduce a chosen-key Fujisaki–Okamoto (CK-FO) transform proven in the QROM, which upgrades IND-CPA double-PKEs to IND-CCA double-KEMs while ensuring the one-sided chosen-key security required by DAKE. As a concrete instantiation, we propose Maul, a compact double-KEM derived from ML-KEM under the Hint-MLWE assumption. Maul reuses ciphertext components to cut encapsulation size by up to 42% compared to two parallel ML-KEMs. When instantiated with Maul, DAKE achieves overall communication reductions of about 16% (mutual authentication) and 21% (unilateral), outperforming both the double-KEM AKE of Xue et al. (ASIACRYPT 2018) and standard ML-KEM-based AKEs.
Note: A minor revision of an IACR publication in PKC 2026.
BibTeX
@misc{cryptoeprint:2025/1755,
author = {Hugo Beguinet and Céline Chevalier and Guirec Lebrun and Thomas Legavre and Thomas Ricosset and Maxime Roméas and Éric Sageloli},
title = {{DAKE}: Bandwidth-Efficient (U){AKE} from Double-{KEM}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1755},
year = {2025},
url = {https://eprint.iacr.org/2025/1755}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。