{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T03:44:01Z","timestamp":1767930241746,"version":"3.49.0"},"reference-count":24,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T00:00:00Z","timestamp":1759881600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,12,2]]},"abstract":"<jats:p>We analyse the binding properties of explicitly-rejecting key-encapsulation mechanisms (KEMs) obtained by the Fujisaki-Okamoto (FO) transform.         The framework for binding notions, introduced by [CDM24], generalises robustness and collision-freeness, and was motivated by the discovery of new types of attacks against KEMs.                 Implicitly-rejecting FO-KEMs have already been analysed with regards to the binding notions, with [KSW25b] providing the full picture.         Binding notions for explicitly-rejecting FO-KEMs have been examined only partially, leaving several gaps.         Moreover, the analysis of the explicit-rejection setting must account for additional binding notions that implicitly-rejecting KEMs cannot satisfy.         We give mostly positive results for the explicitly-rejecting FO transform\u2014though many notions require further robustness assumptions on the underlying PKE.         We then show that the explicit FO transform with plaintext confirmation hash (HFO) achieves all notions and requires weaker robustness assumptions.         Finally, we introduce a slightly modified version of the HFO transform that achieves all binding notions without requiring any robustness of the underlying PKE.<\/jats:p>","DOI":"10.62056\/anudvurzn","type":"journal-article","created":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T23:39:47Z","timestamp":1767915587000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Binding Security of Explicitly-Rejecting KEMs  via Plaintext Confirmation and Robust PKEs"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3599-4215","authenticated-orcid":false,"given":"Juliane","family":"Kr\u00e4mer","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01eezs655","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Regensburg","place":["Bajuwarenstra\u00dfe 4, Regensburg, 93053, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yannick","family":"M\u00fcnz","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0546hnb39","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Konstanz","place":["Universit\u00e4tsstra\u00dfe 10, Konstanz, 78457, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7738-2017","authenticated-orcid":false,"given":"Patrick","family":"Struck","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0546hnb39","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Konstanz","place":["Universit\u00e4tsstra\u00dfe 10, Konstanz, 78457, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maximiliane","family":"Weish\u00e4upl","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01eezs655","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Regensburg","place":["Bajuwarenstra\u00dfe 4, Regensburg, 93053, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2026,1,8]]},"reference":[{"key":"ref1:CCS:CreDaxMed24","doi-asserted-by":"publisher","first-page":"1046","DOI":"10.1145\/3658644.3670283","article-title":"Keeping Up with the KEMs: Stronger Security Notions for\n  KEMs and Automated Analysis of KEM-based Protocols","author":"Cas Cremers","year":"2024"},{"key":"ref2:CiC:KraStrWei25","doi-asserted-by":"publisher","DOI":"10.62056\/ak2i893y6","article-title":"Binding Security of Implicitly-Rejecting KEMs and\n  Application to BIKE and HQC","volume":"2","author":"Juliane Kr\u00e4mer","year":"2025","journal-title":"IACR Communications in Cryptology","ISSN":"https:\/\/id.crossref.org\/issn\/3006-5496","issn-type":"electronic"},{"key":"ref3:C:FujOka99","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","article-title":"Secure Integration of Asymmetric and Symmetric Encryption\n  Schemes","volume":"1666","author":"Eiichiro Fujisaki","year":"1999"},{"key":"ref4:NIS17","volume-title":"Post-quantum cryptography standardization process.","author":"NIST","year":"2017"},{"key":"ref5:IMA:Dent03","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1007\/978-3-540-40974-8_12","article-title":"A Designer's Guide to KEMs","volume":"2898","author":"Alexander W. Dent","year":"2003"},{"key":"ref6:TCC:HofHovKil17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","article-title":"A Modular Analysis of the Fujisaki-Okamoto\n  Transformation","volume":"10677","author":"Dennis Hofheinz","year":"2017"},{"key":"ref7:PKC:JiaZhaMa19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"618","DOI":"10.1007\/978-3-030-17259-6_21","article-title":"Key Encapsulation Mechanism with Explicit Rejection in the\n  Quantum Random Oracle Model","volume":"11443","author":"Haodong Jiang","year":"2019"},{"key":"ref8:EC:BelHoa22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"845","DOI":"10.1007\/978-3-031-07085-3_29","article-title":"Efficient Schemes for Committing Authenticated Encryption","volume":"13276","author":"Mihir Bellare","year":"2022"},{"key":"ref9:SP:CDFFJ21","doi-asserted-by":"publisher","first-page":"1696","DOI":"10.1109\/SP40001.2021.00093","article-title":"BUFFing signature schemes beyond unforgeability and the\n  case of post-quantum signatures","author":"Cas Cremers","year":"2021"},{"key":"ref10:EUROSP:BDKLLSSSS18","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1109\/EuroSP.2018.00032","article-title":"CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based\n  KEM","author":"Joppe W. Bos","year":"2018"},{"key":"ref11:AC:Mohassel10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"501","DOI":"10.1007\/978-3-642-17373-8_29","article-title":"A Closer Look at Anonymity and Robustness in Encryption\n  Schemes","volume":"6477","author":"Payman Mohassel","year":"2010"},{"key":"ref12:PKC:FLPQ13","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"352","DOI":"10.1007\/978-3-642-36362-7_22","article-title":"Robust Encryption, Revisited","volume":"7778","author":"Pooya Farshim","year":"2013"},{"key":"ref13:TCC:AbdBelNev10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"480","DOI":"10.1007\/978-3-642-11799-2_28","article-title":"Robust Encryption","volume":"5978","author":"Michel Abdalla","year":"2010"},{"key":"ref14:AC:BBDP01","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"566","DOI":"10.1007\/3-540-45682-1_33","article-title":"Key-Privacy in Public-Key Encryption","volume":"2248","author":"Mihir Bellare","year":"2001"},{"key":"ref15:EC:GruMarPat22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1007\/978-3-031-07082-2_15","article-title":"Anonymous, Robust Post-quantum Public Key Encryption","volume":"13277","author":"Paul Grubbs","year":"2022"},{"key":"ref16:PKC:FieGun25","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-031-91823-0_5","article-title":"Security Analysis of Signal's PQXDH Handshake","volume":"15675","author":"Rune Fiedler","year":"2025"},{"key":"ref17:EPRINT:KraStrWei25","volume-title":"Binding Security of Combined KEMs: An Analysis of\n  Real-World KEM Combiners","author":"Juliane Kr\u00e4mer","year":"2025"},{"key":"ref18:EPRINT:CHHKM25","volume-title":"Starfighters\u2014On the General Applicability of X-Wing","author":"Deirdre Connolly","year":"2025"},{"key":"ref19:EPRINT:BerPer18","volume-title":"Towards KEM Unification","author":"Daniel J. Bernstein","year":"2018"},{"key":"ref20:EPRINT:Schmieg24","volume-title":"Unbindable Kemmy Schmidt: ML-KEM is neither\n  MAL-BIND-K-CT nor MAL-BIND-K-PK","author":"Sophie Schmieg","year":"2024"},{"key":"ref21:AC:BDFLSZ11","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-25385-0_3","article-title":"Random Oracles in a Quantum World","volume":"7073","author":"Dan Boneh","year":"2011"},{"key":"ref22:EPRINT:StrWei25","volume-title":"A Framework for Advanced Signature Notions","author":"Patrick Struck","year":"2025"},{"key":"ref23:SPIQE:KKKLTW25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-032-01806-9_18","article-title":"Public Key Linting for ML-KEM and ML-DSA","author":"Evangelos Karatsiolis","year":"2025"},{"key":"ref24:USENIX:BJKS24","article-title":"Formal verification of the PQXDH Post-Quantum key\n  agreement protocol for end-to-end secure messaging","author":"Karthikeyan Bhargavan","year":"2024"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T23:40:29Z","timestamp":1767915629000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/4\/34"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,8]]},"references-count":24,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,1,8]]}},"URL":"https:\/\/doi.org\/10.62056\/anudvurzn","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,8]]},"assertion":[{"value":"2025-10-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-4-71"}}