Paper 2025/1755

DAKE: Bandwidth-Efficient (U)AKE from Double-KEM

Hugo Beguinet, Thales, Gennevilliers, France
Céline Chevalier, DIENS, École normale supérieure, CNRS, PSL University, Inria, Paris, France, CRED, Paris-Panthéon-Assas University
Guirec Lebrun, DIENS, École normale supérieure, CNRS, PSL University, Inria, Paris, France, ANSSI, Paris, France
Thomas Legavre, Thales, Gennevilliers, France, Sorbonne Université, CNRS, LIP6, Paris, France, ANSSI, Paris, France
Thomas Ricosset, Thales, Gennevilliers, France
Maxime Roméas, ANSSI, Paris, France
Éric Sageloli, Thales, Gennevilliers, France, DIENS, École normale supérieure, CNRS, PSL University, Inria, Paris, France
Abstract

Bandwidth remains a major bottleneck in post-quantum cryptography, particularly for authenticated key exchange (AKE) protocols. In this work, we present DAKE, a bandwidth-efficient AKE framework built from double-KEM constructions. DAKE comes in two main versions achieving, respectively, weak and full perfect forward secrecy, as well as explicit authentication. It further admits two variants: a unilateral version, and another where a signature scheme replaces a KEM. They are proven secure in the standard model under eCKw and eCK-PFS, two strong variants of the extended Canetti–Krawczyk framework. DAKE employs a double-KEM, a primitive that encapsulates a single key under two public keys simultaneously. Such constructions can achieve smaller encapsulation sizes than two independent KEM encapsulations, offering a significant bandwidth advantage. To facilitate the design of double-KEMs compatible with DAKE, we introduce a chosen-key Fujisaki–Okamoto (CK-FO) transform proven in the QROM, which upgrades IND-CPA double-PKEs to IND-CCA double-KEMs while ensuring the one-sided chosen-key security required by DAKE. As a concrete instantiation, we propose Maul, a compact double-KEM derived from ML-KEM under the Hint-MLWE assumption. Maul reuses ciphertext components to cut encapsulation size by up to 42% compared to two parallel ML-KEMs. When instantiated with Maul, DAKE achieves overall communication reductions of about 16% (mutual authentication) and 21% (unilateral), outperforming both the double-KEM AKE of Xue et al. (ASIACRYPT 2018) and standard ML-KEM-based AKEs.

Note: A minor revision of an IACR publication in PKC 2026.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A minor revision of an IACR publication in PKC 2026
Keywords
Post-quantum (U)AKEDouble-KEMeCKML-KEM
Contact author(s)
thomas ricosset @ thalesgroup com
eric sageloli @ protonmail com
History
2026-05-22: last of 2 revisions
2025-09-25: received
See all versions
Short URL
https://ia.cr/2025/1755
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1755,
      author = {Hugo Beguinet and Céline Chevalier and Guirec Lebrun and Thomas Legavre and Thomas Ricosset and Maxime Roméas and Éric Sageloli},
      title = {{DAKE}: Bandwidth-Efficient (U){AKE} from Double-{KEM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1755},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1755}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.