<p>This work introduces Zemlyanika, a post-quantum, IND-CCA secure key encapsulation mechanism based on the Module-LWE problem. Zemlyanika adopts a standard high-level design approach in which a passively secure public-key encryption scheme is upgraded to an actively secure key encapsulation mechanism via the Fujisaki–Okamoto transform. The scheme is characterized by three key design choices: a power-of-two modulus, explicit rejection, and revised bounds on the decapsulation failure probability. Employing a power-of-two modulus is uncommon in Module-LWE-based schemes, primarily due to the inapplicability of the Number Theoretic Transform (NTT). However, we argue that this choice offers several often underestimated advantages. We also use explicit rejection, which is more efficient than its implicit counterpart. Recent research shows that both approaches offer comparable security guarantees, and thus this choice does not compromise the scheme’s overall security. Finally, we provide a rigorous analysis showing that the conventional upper bound on the decapsulation failure probability can be safely relaxed without weakening security. Increasing this bound yields measurable gains in both performance and resistance to Module-LWE–based attacks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Zemlyanika–Module-LWE based KEM with the power-of-two modulus, explicit rejection and revisited decapsulation failures

  • Alexey Zelenetsky,
  • Petr Klyucharev

摘要

This work introduces Zemlyanika, a post-quantum, IND-CCA secure key encapsulation mechanism based on the Module-LWE problem. Zemlyanika adopts a standard high-level design approach in which a passively secure public-key encryption scheme is upgraded to an actively secure key encapsulation mechanism via the Fujisaki–Okamoto transform. The scheme is characterized by three key design choices: a power-of-two modulus, explicit rejection, and revised bounds on the decapsulation failure probability. Employing a power-of-two modulus is uncommon in Module-LWE-based schemes, primarily due to the inapplicability of the Number Theoretic Transform (NTT). However, we argue that this choice offers several often underestimated advantages. We also use explicit rejection, which is more efficient than its implicit counterpart. Recent research shows that both approaches offer comparable security guarantees, and thus this choice does not compromise the scheme’s overall security. Finally, we provide a rigorous analysis showing that the conventional upper bound on the decapsulation failure probability can be safely relaxed without weakening security. Increasing this bound yields measurable gains in both performance and resistance to Module-LWE–based attacks.