PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 8, 2025IACR Communications in Cryptology3 citationsOpen Access

FrodoKEM: A CCA-Secure Learning With Errors Key Encapsulation Mechanism

View Full Paper
LGLewis GlabushPLPatrick LongaMNMichael Naehrig

Key Points

  • FrodoKEM achieves IND-CCA security, enhancing public-key cryptography against quantum threats while remaining practical.
  • Using lattice-based cryptography, FrodoKEM runs at around 0.97 ms on server-class and 4.98 ms on smartphone-class processors.
  • This mechanism relies on the Fujisaki-Okamoto transform, demonstrating tight multi-target security without increased message length.
  • FrodoKEM minimizes vulnerabilities by utilizing generic lattices, diverging from algebraic structures to enhance security.

Abstract

Large-scale quantum computers capable of implementing Shor's algorithm pose a significant threat to the security of the most widely used public-key cryptographic schemes. This risk has motivated substantial efforts by standards bodies and government agencies to identify and standardize quantum-safe cryptographic systems. Among the proposed solutions, lattice-based cryptography has emerged as the foundation for some of the most promising protocols. This paper describes FrodoKEM, a family of conservative key-encapsulation mechanisms (KEMs) whose security is based on generic, “unstructured” lattices. FrodoKEM is proposed as an alternative to the more efficient lattice schemes that utilize algebraically structured lattices, such as the recently standardized ML-KEM scheme. By relying on generic lattices, FrodoKEM minimizes the potential for future attacks that exploit algebraic structures while enabling simple and compact implementations. Our plain C implementations demonstrate that, despite its conservative design and parameterization, FrodoKEM remains practical. For instance, the full protocol at NIST security level 1 runs in approximately 0.97 ms on a server-class processor, and 4.98 ms on a smartphone-class processor. FrodoKEM obtains (single-target) IND-CCA security using a variant of the Fujisaki-Okamoto transform, applied to an underlying public-key encryption scheme called FrodoPKE. In addition, using a new tool called the Salted Fujisaki-Okamoto (SFO) transform, FrodoKEM is also shown to tightly achieve multi-target security, without increasing the FrodoPKE message length and with a negligible performance impact, based on the multi-target IND-CPA security of FrodoPKE.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Glabush et al. (2025) studied this question.

synapsesocial.com/papers/68e5c1be6950a706b22b578dhttps://doi.org/10.62056/ayivom2hd
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1State preservation by repetitive error detection in a superconducting quantum circuit2015 · 945 citations
  2. 2Module-lattice-based digital signature standard2024 · 164 citations
  3. 3On the concrete hardness of Learning with Errors2015 · 837 citations
  4. 4Provable Dual Attacks on Learning with Errors2024 · 18 citations
  5. 5Post-Quantum Key Exchange for the TLS Protocol from the Ring Learning with Errors Problem2015 · 327 citations