Author
Kwiatkowski, K
Katsumata, S
Pintore, F
Prest, T
Journal title
Proceedings of the 2020 IACR Conference
DOI
10.1007/978-3-030-64837-4_10
Volume
12491
Last updated
2021-01-04T15:25:52.67+00:00
Page
289-320
Abstract
A multi-recipient key encapsulation mechanism, or mKEM, provides a scalable solution to securely communicating to a large group, and offers savings in both bandwidth and computational cost compared to the trivial solution of communicating with each member individually. All prior works on mKEM are only limited to classical assumptions and, although some generic constructions are known, they all require specific properties that are not shared by most post-quantum schemes.

In this work, we first provide a simple and efficient generic construction of mKEM that can be instantiated from versatile assumptions, including post-quantum ones. We then study these mKEM instantiations at a practical level using 8 post-quantum KEMs (which are lattice and isogeny-based NIST candidates), and CSIDH, and show that compared to the trivial solution, our
mKEM offers savings of at least one order of magnitude in the bandwidth, and make encryption time shorter by a factor ranging from 1.92 to 35.
Additionally, we show that by combining mKEM with the TreeKEM protocol used by MLS – an IETF draft for secure group messaging – we obtain significant bandwidth savings.
Symplectic ID
1131682
Publication type
Conference Paper
ISBN-13
978-3-030-64836-7
Publication date
6 December 2020
Please contact us with feedback and comments about this page. Created on 11 Sep 2020 - 17:30.