International Association for Cryptologic Research

International Association
for Cryptologic Research


Paper: Gladius: LWR based efficient hybrid public key encryption with distributed decryption

Kelong Cong , imec-COSIC, KU Leuven
Daniele Cozzo , imec-COSIC, KU Leuven
Varun Maram , ETH, Zurich
Nigel Smart , imec-COSIC, KU Leuven
DOI: 10.1007/978-3-030-92068-5_5
Search ePrint
Search Google
Conference: ASIACRYPT 2021
Abstract: Standard hybrid encryption schemes based on the KEM-DEM framework are hard to implement efficiently in a distributed manner whilst maintaining the CCA security property of the scheme. This is because the DEM needs to be decrypted under the key encapsulated by the KEM, before the whole ciphertext is declared valid. In this paper we present a new variant of the KEM-DEM framework, closely related to Tag-KEMs, which sidesteps this issue. We then present a post-quantum KEM for this framework based on Learning-with-Rounding, which is designed specifically to have fast distributed decryption. Our combined construction of a hybrid encryption scheme with Learning-with-Rounding based KEM, called Gladius, is closely related to the NIST Round 3 candidate called Saber. Finally, we give a prototype distributed implementation that achieves a decapsulation time of 4.99 seconds for three parties.
Video from ASIACRYPT 2021
  title={Gladius: LWR based efficient hybrid public key encryption with distributed decryption},
  author={Kelong Cong and Daniele Cozzo and Varun Maram and Nigel Smart},