{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,12]],"date-time":"2026-08-12T10:36:54Z","timestamp":1786531014347,"version":"build-2736575974"},"publisher-location":"Cham","reference-count":62,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032354273","type":"print"},{"value":"9783032354280","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-35428-0_9","type":"book-chapter","created":{"date-parts":[[2026,8,12]],"date-time":"2026-08-12T10:10:51Z","timestamp":1786529451000},"page":"267-298","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Post-quantum Internet Key Exchange via\u00a0Authenticated Forward-Secure KEM"],"prefix":"10.1007","author":[{"given":"Yunlei","family":"Zhao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Biming","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhixiang","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yifan","family":"Dong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cheng","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haodong","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,8,13]]},"reference":[{"key":"9_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"269","DOI":"10.1007\/978-3-030-26951-7_10","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"A Ambainis","year":"2019","unstructured":"Ambainis, A., Hamburg, M., Unruh, D.: Quantum security proofs using Semi-Classical Oracles. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11693, pp. 269\u2013295. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_10"},{"key":"9_CR2","doi-asserted-by":"publisher","unstructured":"Amer, S., et al.: PQ-Hammer: end-to-end key recovery attacks on post-quantum cryptography using Rowhammer. In: Blanton, M., Enck, W., Nita-Rotaru, C. (eds.) 2025 IEEE Symposium on Security and Privacy, May 2025, pp. 3567\u20133582. IEEE Computer Society Press (2025). https:\/\/doi.org\/10.1109\/SP61157.2025.00048","DOI":"10.1109\/SP61157.2025.00048"},{"key":"9_CR3","doi-asserted-by":"publisher","unstructured":"Barbosa, M., et al.: X-Wing. CiC 1(1), 21 (2024). https:\/\/doi.org\/10.62056\/a3qj89n4e","DOI":"10.62056\/a3qj89n4e"},{"key":"9_CR4","doi-asserted-by":"publisher","unstructured":"Beguinet, H., et al.: DAKE: bandwidth-efficient (u)AKE from double-KEM. In: Bai, S., Persichetti, E. (eds.) Public-Key Cryptography, PKC 2026. LNCS, vol. 16554. Springer, Cham (2026). https:\/\/doi.org\/10.1007\/978-3-032-26740-5_1","DOI":"10.1007\/978-3-032-26740-5_1"},{"key":"9_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1007\/3-540-48329-2_21","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 93","author":"M Bellare","year":"1994","unstructured":"Bellare, M., Rogaway, P.: Entity authentication and key distribution. In: Stinson, D.R. (ed.) CRYPTO 1993. LNCS, vol. 773, pp. 232\u2013249. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48329-2_21"},{"key":"9_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/978-3-030-36033-7_3","volume-title":"Theory of Cryptography","author":"N Bindel","year":"2019","unstructured":"Bindel, N., Hamburg, M., H\u00f6velmanns, K., H\u00fclsing, A., Persichetti, E.: Tighter proofs of CCA security in the Quantum Random Oracle model. In: Hofheinz, D., Rosen, A. (eds.) TCC 2019, Part II. LNCS, vol. 11892, pp. 61\u201390. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-36033-7_3"},{"key":"9_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1007\/978-3-030-44223-1_12","volume-title":"Post-Quantum Cryptography","author":"N Bindel","year":"2020","unstructured":"Bindel, N., Schanck, J.M.: Decryption failure is more likely after success. In: Ding, J., Tillich, J.-P. (eds.) PQCrypto 2020. LNCS, vol. 12100, pp. 206\u2013225. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_12"},{"key":"9_CR8","doi-asserted-by":"publisher","unstructured":"Bitansky, N., Canetti, R., Chiesa, A., Tromer, E.: From extractable collision resistance to succinct non-interactive arguments of knowledge, and back again. In: Goldwasser, S. (ed.) ITCS 2012, January 2012, pp. 326\u2013349. ACM (2012). https:\/\/doi.org\/10.1145\/2090236.2090263","DOI":"10.1145\/2090236.2090263"},{"key":"9_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1007\/3-540-36492-7_6","volume-title":"Selected Areas in Cryptography","author":"J Black","year":"2003","unstructured":"Black, J., Rogaway, P., Shrimpton, T.: Encryption-scheme security in the presence of key-dependent messages. In: Nyberg, K., Heys, H. (eds.) SAC 2002. LNCS, vol. 2595, pp. 62\u201375. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/3-540-36492-7_6"},{"key":"9_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-25385-0_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2011","author":"D Boneh","year":"2011","unstructured":"Boneh, D., Dagdelen, \u00d6., Fischlin, M., Lehmann, A., Schaffner, C., Zhandry, M.: Random Oracles in a quantum world. In: Lee, D.H., Wang, X. (eds.) ASIACRYPT 2011. LNCS, vol. 7073, pp. 41\u201369. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25385-0_3"},{"key":"9_CR11","doi-asserted-by":"publisher","unstructured":"Bos, J.W., et al.: Frodo: take off the ring! Practical, quantum-secure key exchange from LWE. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) ACM CCS 2016, October 2016, pp. 1006\u20131018. ACM Press (2016). https:\/\/doi.org\/10.1145\/2976749.2978425","DOI":"10.1145\/2976749.2978425"},{"key":"9_CR12","doi-asserted-by":"publisher","unstructured":"Bos, J.W., et al.: CRYSTALS - Kyber: a CCA-secure module-lattice-based KEM. In: 2018 IEEE European Symposium on Security and Privacy, EuroS&P 2018, London, United Kingdom, 24\u201326 April 2018, pp. 353\u2013367. IEEE (2018). https:\/\/doi.org\/10.1109\/EUROSP.2018.00032","DOI":"10.1109\/EUROSP.2018.00032"},{"key":"9_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1007\/978-3-540-70500-0_6","volume-title":"Information Security and Privacy","author":"C Boyd","year":"2008","unstructured":"Boyd, C., Cliff, Y., Gonzalez Nieto, J., Paterson, K.G.: Efficient one-round key exchange in the standard model. In: Mu, Y., Susilo, W., Seberry, J. (eds.) ACISP 2008. LNCS, vol. 5107, pp. 69\u201383. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-70500-0_6"},{"key":"9_CR14","doi-asserted-by":"publisher","unstructured":"Boyd, C., Mathuria, A., Stebila, D.: Protocols for Authentication and Key Establishment. Information Security and Cryptography, 2nd edn. Springer, Berlin (2019). https:\/\/doi.org\/10.1007\/978-3-662-58146-9","DOI":"10.1007\/978-3-662-58146-9"},{"key":"9_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1007\/3-540-44987-6_28","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2001","author":"R Canetti","year":"2001","unstructured":"Canetti, R., Krawczyk, H.: Analysis of key-exchange protocols and their use for building secure channels. In: Pfitzmann, B. (ed.) EUROCRYPT 2001. LNCS, vol. 2045, pp. 453\u2013474. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44987-6_28"},{"key":"9_CR16","doi-asserted-by":"publisher","unstructured":"Canetti, R., Krawczyk, H.: Security analysis of IKE\u2019s signature-based key-exchange protocol. In: Yung, M. (ed.) CRYPTO\u00a02002. LNCS, August 2002, vol.\u00a02442, pp. 143\u2013161. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45708-9_10, https:\/\/eprint.iacr.org\/2002\/120\/","DOI":"10.1007\/3-540-45708-9_10"},{"key":"9_CR17","doi-asserted-by":"publisher","unstructured":"Carrel, D., Harkins, D.: The Internet Key Exchange (IKE). RFC 2409, November 1998. https:\/\/doi.org\/10.17487\/RFC2409","DOI":"10.17487\/RFC2409"},{"key":"9_CR18","doi-asserted-by":"publisher","unstructured":"Cremers, C., Dax, A., Medinger, N.: Keeping up with the KEMs: stronger security notions for KEMs and automated analysis of KEM-based protocols. In: Luo, B., Liao, X., Xu, J., Kirda, E., Lie, D. (eds.) ACM CCS 2024, October 2024, pp. 1046\u20131060. ACM Press (2024). https:\/\/doi.org\/10.1145\/3658644.3670283","DOI":"10.1145\/3658644.3670283"},{"key":"9_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"734","DOI":"10.1007\/978-3-642-33167-1_42","volume-title":"Computer Security \u2013 ESORICS 2012","author":"C Cremers","year":"2012","unstructured":"Cremers, C., Feltz, M.: Beyond eCK: perfect forward secrecy under actor compromise and ephemeral-key reveal. In: Foresti, S., Yung, M., Martinelli, F. (eds.) ESORICS 2012. LNCS, vol. 7459, pp. 734\u2013751. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-33167-1_42"},{"key":"9_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-56880-1_12","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"D Dachman-Soled","year":"2020","unstructured":"Dachman-Soled, D., Ducas, L., Gong, H., Rossi, M.: LWE with side information: attacks and concrete security estimation. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020, Part II. LNCS, vol. 12171, pp. 329\u2013358. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_12"},{"key":"9_CR21","doi-asserted-by":"publisher","unstructured":"D\u2019Anvers, J.P., Batsleer, S.: Multitarget decryption failure attacks and their application to Saber and Kyber. In: Hanaoka, G., Shikata, J., Watanabe, Y. (eds.) PKC\u00a02022, Part\u00a0I. LNCS, March 2022, vol. 13177, pp. 3\u201333. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-97121-2_1","DOI":"10.1007\/978-3-030-97121-2_1"},{"key":"9_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1007\/978-3-030-17259-6_19","volume-title":"Public-Key Cryptography \u2013 PKC 2019","author":"J-P D\u2019Anvers","year":"2019","unstructured":"D\u2019Anvers, J.-P., Guo, Q., Johansson, T., Nilsson, A., Vercauteren, F., Verbauwhede, I.: Decryption failure attacks on IND-CCA secure lattice-based schemes. In: Lin, D., Sako, K. (eds.) PKC 2019, Part II. LNCS, vol. 11443, pp. 565\u2013598. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17259-6_19"},{"key":"9_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-45727-3_1","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"J-P D\u2019Anvers","year":"2020","unstructured":"D\u2019Anvers, J.-P., Rossi, M., Virdia, F.: (One) failure is not an option: bootstrapping the search for failures in\u00a0lattice-based encryption schemes. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020, Part III. LNCS, vol. 12107, pp. 3\u201333. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45727-3_1"},{"issue":"6","key":"9_CR24","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W Diffie","year":"1976","unstructured":"Diffie, W., Hellman, M.: New directions in cryptography. IEEE Trans. Inf. Theor. 22(6), 644\u2013654 (1976). https:\/\/doi.org\/10.1109\/TIT.1976.1055638","journal-title":"IEEE Trans. Inf. Theor."},{"key":"9_CR25","doi-asserted-by":"publisher","unstructured":"Dodis, Y., Jost, D., Katsumata, S., Prest, T., Schmidt, R.: Triple ratchet: a bandwidth efficient hybrid-secure signal protocol. In: Fehr, S., Fouque, P.A. (eds.) EUROCRYPT\u00a02025, Part\u00a0VIII. LNCS, May 2025, vol. 15608, pp. 302\u2013331. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-91101-9_11","DOI":"10.1007\/978-3-031-91101-9_11"},{"key":"9_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"602","DOI":"10.1007\/978-3-030-56877-1_21","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"J Don","year":"2020","unstructured":"Don, J., Fehr, S., Majenz, C.: The measure-and-reprogram technique 2.0: multi-round Fiat-Shamir and more. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020, Part III. LNCS, vol. 12172, pp. 602\u2013631. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_21"},{"key":"9_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1007\/978-3-030-26951-7_13","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"J Don","year":"2019","unstructured":"Don, J., Fehr, S., Majenz, C., Schaffner, C.: Security of the Fiat-Shamir transformation in the Quantum Random-Oracle model. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019, Part II. LNCS, vol. 11693, pp. 356\u2013383. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_13"},{"key":"9_CR28","doi-asserted-by":"publisher","unstructured":"Duman, J., H\u00f6velmanns, K., Kiltz, E., Lyubashevsky, V., Seiler, G.: Faster lattice-based KEMs via a generic Fujisaki-Okamoto transform using prefix hashing. In: Vigna, G., Shi, E. (eds.) ACM CCS 2021, November 2021, pp. 2722\u20132737. ACM Press (2021). https:\/\/doi.org\/10.1145\/3460120.3484819","DOI":"10.1145\/3460120.3484819"},{"key":"9_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1007\/978-3-642-30057-8_28","volume-title":"Public Key Cryptography \u2013 PKC 2012","author":"A Fujioka","year":"2012","unstructured":"Fujioka, A., Suzuki, K., Xagawa, K., Yoneyama, K.: Strongly secure authenticated key exchange from factoring, codes, and lattices. In: Fischlin, M., Buchmann, J., Manulis, M. (eds.) PKC 2012. LNCS, vol. 7293, pp. 467\u2013484. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-30057-8_28"},{"key":"9_CR30","doi-asserted-by":"publisher","unstructured":"Fujioka, A., Suzuki, K., Xagawa, K., Yoneyama, K.: Practical and post-quantum authenticated key exchange from one-way secure key encapsulation mechanism. In: Chen, K., Xie, Q., Qiu, W., Li, N., Tzeng, W.G. (eds.) ASIACCS 13, May 2013, pp. 83\u201394. ACM Press (2013). https:\/\/doi.org\/10.1145\/2484313.2484323","DOI":"10.1145\/2484313.2484323"},{"key":"9_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"E Fujisaki","year":"1999","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 537\u2013554. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_34"},{"key":"9_CR32","doi-asserted-by":"publisher","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. J. Cryptol. 26(1), 80\u2013101 (2013). https:\/\/doi.org\/10.1007\/s00145-011-9114-1","DOI":"10.1007\/s00145-011-9114-1"},{"key":"9_CR33","doi-asserted-by":"publisher","unstructured":"Goldwasser, S., Micali, S., Rackoff, C.: The knowledge complexity of interactive proof systems. SIAM J. Comput. 18(1), 186\u2013208 (1989). https:\/\/doi.org\/10.1137\/0218012","DOI":"10.1137\/0218012"},{"key":"9_CR34","unstructured":"Hashimoto, K., Katsumata, S., Niot, G., Wiggers, T.: Revisiting PQ WireGuard: a comprehensive security analysis with a new design using reinforced KEMs. Cryptology ePrint Archive, Paper 2025\/1758 (2025). to appear at IEEE Symposium on Security and Privacy (S&P) 2026. https:\/\/eprint.iacr.org\/2025\/1758"},{"key":"9_CR35","unstructured":"Hashimoto, K., Katsumata, S., Niot, G., Wiggers, T.: Revisiting PQ WireGuard: a comprehensive security analysis with a new design using reinforced KEMs. Cryptology ePrint Archive, Paper 2025\/1758 (2025). https:\/\/eprint.iacr.org\/2025\/1758"},{"key":"9_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","volume-title":"Theory of Cryptography","author":"D Hofheinz","year":"2017","unstructured":"Hofheinz, D., H\u00f6velmanns, K., Kiltz, E.: A modular analysis of the Fujisaki-Okamoto transformation. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017, Part I. LNCS, vol. 10677, pp. 341\u2013371. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12"},{"key":"9_CR37","doi-asserted-by":"publisher","unstructured":"H\u00f6velmanns, K., Kiltz, E., Sch\u00e4ge, S., Unruh, D.: Generic authenticated key exchange in the Quantum Random Oracle model. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC\u00a02020, Part\u00a0II. LNCS, May 2020, vol. 12111, pp. 389\u2013422. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45388-6_14","DOI":"10.1007\/978-3-030-45388-6_14"},{"key":"9_CR38","doi-asserted-by":"publisher","unstructured":"H\u00fclsing, A., Ning, K.C., Schwabe, P., Weber, F.J., Zimmermann, P.R.: Post-quantum WireGuard. In: 2021 IEEE Symposium on Security and Privacy, May 2021, pp. 304\u2013321. IEEE Computer Society Press (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00030","DOI":"10.1109\/SP40001.2021.00030"},{"key":"9_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/978-3-319-96878-0_4","volume-title":"Advances in Cryptology \u2013 CRYPTO 2018","author":"H Jiang","year":"2018","unstructured":"Jiang, H., Zhang, Z., Chen, L., Wang, H., Ma, Z.: IND-CCA-secure key encapsulation mechanism in the Quantum Random Oracle model, revisited. In: Shacham, H., Boldyreva, A. (eds.) CRYPTO 2018, Part III. LNCS, vol. 10993, pp. 96\u2013125. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-96878-0_4"},{"key":"9_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-030-25510-7_13","volume-title":"Post-Quantum Cryptography","author":"H Jiang","year":"2019","unstructured":"Jiang, H., Zhang, Z., Ma, Z.: Tighter security proofs for generic key encapsulation mechanism in the Quantum Random Oracle model. In: Ding, J., Steinwandt, R. (eds.) PQCrypto 2019. LNCS, vol. 11505, pp. 227\u2013248. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25510-7_13"},{"key":"9_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1007\/978-3-030-64837-4_10","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"S Katsumata","year":"2020","unstructured":"Katsumata, S., Kwiatkowski, K., Pintore, F., Prest, T.: Scalable ciphertext compression techniques for post-quantum KEMs and their applications. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part I. LNCS, vol. 12491, pp. 289\u2013320. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_10"},{"key":"9_CR42","doi-asserted-by":"publisher","unstructured":"Kaufman, C., Hoffman, P.E., Nir, Y., Eronen, P., Kivinen, T.: Internet Key Exchange Protocol Version 2 (IKEv2). RFC 7296, October 2014. https:\/\/doi.org\/10.17487\/RFC7296","DOI":"10.17487\/RFC7296"},{"key":"9_CR43","doi-asserted-by":"publisher","unstructured":"Kim, D., Lee, D., Seo, J., Song, Y.: Toward practical lattice-based proof of knowledge from hint-MLWE. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0V. LNCS, August 2023, vol. 14085, pp. 549\u2013580. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38554-4_18","DOI":"10.1007\/978-3-031-38554-4_18"},{"key":"9_CR44","doi-asserted-by":"publisher","unstructured":"Krawczyk, H.: SIGMA: the \u201cSIGn-and-MAc\u201d approach to authenticated Diffie-Hellman and its use in the IKE protocols. In: Boneh, D. (ed.) CRYPTO\u00a02003. LNCS, August 2003, vol.\u00a02729, pp. 400\u2013425. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_24","DOI":"10.1007\/978-3-540-45146-4_24"},{"key":"9_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-75670-5_1","volume-title":"Provable Security","author":"B LaMacchia","year":"2007","unstructured":"LaMacchia, B., Lauter, K., Mityagin, A.: Stronger security of authenticated key exchange. In: Susilo, W., Liu, J.K., Mu, Y. (eds.) ProvSec 2007. LNCS, vol. 4784, pp. 1\u201316. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-75670-5_1"},{"key":"9_CR46","doi-asserted-by":"publisher","unstructured":"Langley, A., Hamburg, M., Turner, S.: Elliptic Curves for Security. RFC 7748, January 2016. https:\/\/doi.org\/10.17487\/RFC7748","DOI":"10.17487\/RFC7748"},{"issue":"3","key":"9_CR47","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1007\/S10623-014-9938-4","volume":"75","author":"A Langlois","year":"2015","unstructured":"Langlois, A., Stehl\u00e9, D.: Worst-case to average-case reductions for module lattices. Des. Codes Cryptogr. 75(3), 565\u2013599 (2015). https:\/\/doi.org\/10.1007\/S10623-014-9938-4","journal-title":"Des. Codes Cryptogr."},{"key":"9_CR48","unstructured":"Longa, P., Bos, J.W., Ehlen, S., Stebila, D.: FrodoKEM: key encapsulation from learning with errors. Internet-Draft draft-longa-cfrg-frodokem-01, Internet Engineering Task Force, September 2025. https:\/\/datatracker.ietf.org\/doc\/draft-longa-cfrg-frodokem\/01\/, work in Progress"},{"key":"9_CR49","doi-asserted-by":"publisher","unstructured":"Lyu, Y., Liu, S.: Two-message authenticated key exchange from public-key encryption. In: Tsudik, G., Conti, M., Liang, K., Smaragdakis, G. (eds.) ESORICS\u00a02023, Part\u00a0I. LNCS, September 2023, vol. 14344, pp. 414\u2013434. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-50594-2_21","DOI":"10.1007\/978-3-031-50594-2_21"},{"key":"9_CR50","unstructured":"Melchor, C.A., et al.: HQC: Hamming Quasi-Cyclic (2025). Selected by NIST for standardization on Mar. 11, 2025. https:\/\/pqc-hqc.org\/"},{"key":"9_CR51","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: Module-lattice-based digital signature standard (FIPS\u00a0204). Federal Information Processing Standards Publication\u00a0204, U.S. Department of Commerce, National Institute of Standards and Technology, Gaithersburg, MD, USA, August 2024. https:\/\/doi.org\/10.6028\/NIST.FIPS.204","DOI":"10.6028\/NIST.FIPS.204"},{"key":"9_CR52","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: Module-lattice-based key-encapsulation mechanism standard (FIPS\u00a0203). Federal Information Processing Standards Publication\u00a0203, U.S. Department of Commerce, National Institute of Standards and Technology, Gaithersburg, MD, USA, August 2024. https:\/\/doi.org\/10.6028\/NIST.FIPS.203","DOI":"10.6028\/NIST.FIPS.203"},{"key":"9_CR53","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: Stateless hash-based digital signature standard (FIPS\u00a0205). Federal Information Processing Standards Publication\u00a0205, U.S. Department of Commerce, National Institute of Standards and Technology, Gaithersburg, MD, USA, August 2024. https:\/\/doi.org\/10.6028\/NIST.FIPS.205","DOI":"10.6028\/NIST.FIPS.205"},{"key":"9_CR54","unstructured":"National Institute of Standards and Technology (NIST): Post-quantum cryptography standardization. https:\/\/www.nist.gov\/pqcrypto (2017). Created January\u00a03,\u00a02017; last updated December\u00a011,\u00a02025"},{"key":"9_CR55","doi-asserted-by":"publisher","unstructured":"Pan, J., Wagner, B., Zeng, R.: Lattice-based authenticated key exchange with tight security. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0V. LNCS, August 2023, vol. 14085, pp. 616\u2013647. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38554-4_20","DOI":"10.1007\/978-3-031-38554-4_20"},{"key":"9_CR56","doi-asserted-by":"publisher","unstructured":"Pan, J., Zeng, R.: A generic construction of tightly secure password-based authenticated key exchange. In: Guo, J., Steinfeld, R. (eds.) ASIACRYPT\u00a02023, Part\u00a0VIII. LNCS, December 2023, vol. 14445, pp. 143\u2013175. Springer, Singapore (2023). https:\/\/doi.org\/10.1007\/978-981-99-8742-9_5","DOI":"10.1007\/978-981-99-8742-9_5"},{"key":"9_CR57","doi-asserted-by":"publisher","unstructured":"Rivest, R.L., Shamir, A., Adleman, L.: A method for obtaining digital signatures and public-key cryptosystems. Commun. ACM 21(2), 120\u2013126 (1978). https:\/\/doi.org\/10.1145\/359340.359342","DOI":"10.1145\/359340.359342"},{"key":"9_CR58","doi-asserted-by":"publisher","unstructured":"Schwabe, P., Stebila, D., Wiggers, T.: Post-quantum TLS without handshake signatures. In: Ligatti, J., Ou, X., Katz, J., Vigna, G. (eds.) ACM CCS 2020, November 2020, pp. 1461\u20131480. ACM Press (2020). https:\/\/doi.org\/10.1145\/3372297.3423350","DOI":"10.1145\/3372297.3423350"},{"key":"9_CR59","doi-asserted-by":"publisher","unstructured":"Shor, P.W.: Algorithms for quantum computation: discrete logarithms and factoring. In: 35th FOCS, November 1994, pp. 124\u2013134. IEEE Computer Society Press (1994). https:\/\/doi.org\/10.1109\/SFCS.1994.365700","DOI":"10.1109\/SFCS.1994.365700"},{"key":"9_CR60","doi-asserted-by":"crossref","unstructured":"Stebila, D., Fluhrer, S., Gueron, S.: Hybrid key exchange in TLS 1.3. Internet-Draft draft-ietf-tls-hybrid-design-16. Internet Engineering Task Force, September 2025. https:\/\/datatracker.ietf.org\/doc\/draft-ietf-tls-hybrid-design\/16\/, work in Progress","DOI":"10.17487\/RFC9954"},{"key":"9_CR61","unstructured":"Wang, G., Smyslov, V.: KEM-based authentication for IKEv2 with post-quantum security. IETF Internet-Draft, draft-wang-ipsecme-kem-auth-ikev2-02, October 2025. https:\/\/www.ietf.org\/archive\/id\/draft-wang-ipsecme-kem-auth-ikev2-02.html, work in Progress, last updated 18 Oct 2025"},{"key":"9_CR62","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/978-3-030-03329-3_6","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"H Xue","year":"2018","unstructured":"Xue, H., Lu, X., Li, B., Liang, B., He, J.: Understanding and constructing AKE via double-key key encapsulation mechanism. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018, Part II. LNCS, vol. 11273, pp. 158\u2013189. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03329-3_6"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-35428-0_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,12]],"date-time":"2026-08-12T10:10:55Z","timestamp":1786529455000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-35428-0_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032354273","9783032354280"],"references-count":62,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-35428-0_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"13 August 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 August 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"46","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}