SoK: Post-Quantum Key Encapsulation Mechanisms—Security Definitions, Constructions, and Applications
摘要
The Key Encapsulation Mechanism (KEM) is one of the most important foundational cryptographic primitives. It can be used to construct Public Key Encryption (PKE), Key Exchange, and Authenticated Key Exchange. With the continuing advances in quantum computing (e.g., Shor’s algorithm), traditional KEMs based on RSA and ECC will eventually become insecure. As the NIST Post-Quantum Cryptography (PQC) Standardization progresses, exploring the construction of post-quantum secure KEMs has become a highly relevant topic. This paper presents a comprehensive survey of general constructions of post-quantum secure KEMs in both the random oracle model (ROM) and quantum random oracle model (QROM), focusing on their security definitions, general constructions, and practical applications. We examine key security notions for KEMs, such as OW-CPA, IND-CPA, IND-1CCA, and IND-CCA, as well as their general construction from CPA-secure PKE schemes alongside applications in real-world protocols, including TLS 1.3, KEMTLS, Signal, and Noise. Specifically, we examine the FO and modular variants for IND-CCA KEMs, three distinct T-transforms for IND-1CCA KEMs, and the CPA transform for CPA-secure KEMs derived from CPA-secure PKEs. We further discuss the security requirements of KEMs within various protocols and highlight that IND-1CCA KEMs can be used to construct practical protocols such as KEMTLS, Signal, and Noise. In particular, CPA-secure KEMs can be employed in constructing post-quantum TLS 1.3.