{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T09:54:35Z","timestamp":1785405275262,"version":"3.56.0"},"reference-count":41,"publisher":"International Association for Cryptologic Research","issue":"3","license":[{"start":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T00:00:00Z","timestamp":1751846400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,9,2]]},"abstract":"<jats:p>Combiners for cryptographic schemes are a common way to increase security using redundancy. The security notions for public key encryption (PKE) combiners can be extended beyond the standard IND-CCA security to achieve even stronger security notions. In the indistinguishability under adaptive strong multiple chosen-ciphertext attack (IND-sMCCA) security notion, the adversary has additional oracle access to the underlying cipher components of the combiner. Recently, combiners have received more attention because of the possibility of combining classical and post-quantum (PQ) cryptography. This allows for the use of novel PQ algorithms while still having the security guarantees of the classical algorithms. In order to examine the security against quantum adversaries, the quantum random oracle model (QROM) has become the most relevant security model. However, there are no PKE combiners that achieve IND-sMCCA security in the QROM, even though this security notion describes much better the current state where classical, PQ, and combined schemes are deployed at the same time.<\/jats:p>\n                  <jats:p>In this paper, we close this gap by providing a new PKE combiner that is IND-sMCCA secure in the QROM. Our construction is more efficient and lean than the existing PKE combiners, considering the primitives used and the ciphertext size. We accomplish this by applying the Fujisaki-Okamoto (FO) transformation to a PKE combiner of Asmuth and Blakley. To achieve IND-sMCCA security for the combiner, the PKE components must be OW-CCA secure. However, when using weaker (OW-CPA secure) PKE components, we still achieve standard IND-CCA security for the combiner. The security reductions are given in the ROM and the QROM, achieving bounds of different tightness.<\/jats:p>","DOI":"10.62056\/ayzogyl7s","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T18:49:52Z","timestamp":1759776592000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Strong Multiple-CCA Security in the Quantum Random Oracle Model for an FO-like PKE Combiner"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8372-4503","authenticated-orcid":false,"given":"Tudor","family":"Soroceanu","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03w0bbr97","id-type":"ROR","asserted-by":"publisher"}],"name":"Fraunhofer AISEC","place":["Breite Stra\u00dfe 12, Berlin, 14199, Germany"],"department":["Secure Systems Engineering"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8388-6059","authenticated-orcid":false,"given":"Nicolas","family":"Buchmann","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03w0bbr97","id-type":"ROR","asserted-by":"publisher"}],"name":"Fraunhofer AISEC","place":["Breite Stra\u00dfe 12, Berlin, 14199, Germany"],"department":["Secure Systems Engineering"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1066-575X","authenticated-orcid":false,"given":"Theresa","family":"Graeber","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03w0bbr97","id-type":"ROR","asserted-by":"publisher"}],"name":"Fraunhofer AISEC","place":["Breite Stra\u00dfe 12, Berlin, 14199, Germany"],"department":["Secure Systems Engineering"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8577-1318","authenticated-orcid":false,"given":"Marian","family":"Margraf","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03w0bbr97","id-type":"ROR","asserted-by":"publisher"}],"name":"Fraunhofer AISEC","place":["Breite Stra\u00dfe 12, Berlin, 14199, Germany"],"department":["Secure Systems Engineering"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,10,6]]},"reference":[{"key":"ref1:shorAlgorithmsQuantumComputation1994","isbn-type":"print","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1109\/SFCS.1994.365700","article-title":"Algorithms for quantum computation: discrete logarithms and\n  factoring","author":"P.W. Shor","year":"1994","ISBN":"https:\/\/id.crossref.org\/isbn\/9780818665806"},{"key":"ref2:kimEvidenceUtilityQuantum2023","doi-asserted-by":"publisher","first-page":"500","DOI":"10.1038\/s41586-023-06096-3","article-title":"Evidence for the utility of quantum computing before fault\n  tolerance","volume":"618","author":"Youngseok Kim","year":"2023","journal-title":"Nature","ISSN":"https:\/\/id.crossref.org\/issn\/1476-4687","issn-type":"electronic"},{"key":"ref3:aghaeeInterferometricSingleshotParity2025","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1038\/s41586-024-08445-2","article-title":"Interferometric single-shot parity measurement in\n  InAs\u2013Al hybrid devices","volume":"638","author":"Morteza Aghaee","year":"2025","journal-title":"Nature","ISSN":"https:\/\/id.crossref.org\/issn\/1476-4687","issn-type":"electronic"},{"key":"ref4:acharyaQuantumErrorCorrection2025","doi-asserted-by":"publisher","first-page":"920","DOI":"10.1038\/s41586-024-08449-y","article-title":"Quantum error correction below the surface code threshold","volume":"638","author":"Rajeev Acharya","year":"2025","journal-title":"Nature","ISSN":"https:\/\/id.crossref.org\/issn\/1476-4687","issn-type":"electronic"},{"key":"ref5:merkleSecurityMultipleEncryption1981","doi-asserted-by":"publisher","first-page":"465","DOI":"10.1145\/358699.358718","article-title":"On the security of multiple encryption","volume":"24","author":"Ralph C. Merkle","year":"1981","journal-title":"Communications of the ACM","ISSN":"https:\/\/id.crossref.org\/issn\/0001-0782","issn-type":"electronic"},{"key":"ref6:menezesHandbookAppliedCryptography1997","series-title":"CRC Press series on discrete mathematics and its\n  applications","isbn-type":"print","doi-asserted-by":"publisher","DOI":"10.1201\/9780429466335","volume-title":"Handbook of applied cryptography","author":"Alfred John Menezes","year":"1997","ISBN":"https:\/\/id.crossref.org\/isbn\/9780849385230"},{"key":"ref7:TCC:FisLeh08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"375","DOI":"10.1007\/978-3-540-78524-8_21","article-title":"Multi-property Preserving Combiners for Hash Functions","volume":"4948","author":"Marc Fischlin","year":"2008"},{"key":"ref8:ICALP:FisLehPie08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"655","DOI":"10.1007\/978-3-540-70583-3_53","article-title":"Robust Multi-property Combiners for Hash Functions\n  Revisited","volume":"5126","author":"Marc Fischlin","year":"2008"},{"key":"ref9:ASMUTH1981447","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1016\/0898-1221(81)90029-8","article-title":"An efficient algorithm for constructing a cryptosystem which\n  is harder to break than two other cryptosystems","volume":"7","author":"C.A. Asmuth","year":"1981","journal-title":"Computers & Mathematics with Applications","ISSN":"https:\/\/id.crossref.org\/issn\/0898-1221","issn-type":"electronic"},{"key":"ref10:PKC:ZHSI04","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1007\/978-3-540-24632-9_26","article-title":"On the Security of Multiple Encryption or\n  CCA-security+CCA-security=CCA-security?","volume":"2947","author":"Rui Zhang","year":"2004"},{"key":"ref11:EPRINT:Herzberg02b","volume-title":"Folklore, Practice and Theory of Robust Combiners","author":"Amir Herzberg","year":"2002"},{"key":"ref12:RSA:Herzberg05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/978-3-540-30574-3_13","article-title":"On Tolerant Cryptographic Constructions","volume":"3376","author":"Amir Herzberg","year":"2005"},{"key":"ref13:PKC:GiaHeuPoe18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/978-3-319-76578-5_7","article-title":"KEM Combiners","volume":"10769","author":"Federico Giacon","year":"2018"},{"key":"ref14:PQCRYPTO:BBFGS19","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1007\/978-3-030-25510-7_12","article-title":"Hybrid Key Encapsulation Mechanisms and Authenticated Key\n  Exchange","author":"Nina Bindel","year":"2019"},{"key":"ref15:CANS:HugVau21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/978-3-030-92548-2_12","article-title":"FO-like Combiners and Hybrid Post-Quantum Cryptography","volume":"13099","author":"Lo\u00efs Huguenin-Dumittan","year":"2021"},{"key":"ref16:CiC:BCDKSV24","doi-asserted-by":"publisher","first-page":"21","DOI":"10.62056\/a3qj89n4e","article-title":"X-Wing","volume":"1","author":"Manuel Barbosa","year":"2024","journal-title":"IACR Communications in Cryptology (CiC)"},{"key":"ref17:AC:BDFLSZ11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-25385-0_3","article-title":"Random Oracles in a Quantum World","volume":"7073","author":"Dan Boneh","year":"2011"},{"key":"ref18:goncalvesTightlySecurePKE2022","doi-asserted-by":"publisher","first-page":"15","DOI":"10.3390\/cryptography6020015","article-title":"Tightly Secure PKE Combiner in the Quantum Random\n  Oracle Model","volume":"6","author":"Brian Goncalves","year":"2022","journal-title":"Cryptography","ISSN":"https:\/\/id.crossref.org\/issn\/2410-387X","issn-type":"electronic"},{"key":"ref19:TCC:DodKat05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1007\/978-3-540-30576-7_11","article-title":"Chosen-Ciphertext Security of Multiple Encryption","volume":"3378","author":"Yevgeniy Dodis","year":"2005"},{"key":"ref20:JC:FujOka13","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/s00145-011-9114-1","article-title":"Secure Integration of Asymmetric and Symmetric Encryption\n  Schemes","volume":"26","author":"Eiichiro Fujisaki","year":"2013","journal-title":"Journal of Cryptology"},{"key":"ref21:EC:HKNRR05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/11426639_6","article-title":"On Robust Combiners for Oblivious Transfer and Other\n  Primitives","volume":"3494","author":"Danny Harnik","year":"2005"},{"key":"ref22:CCS:BelRog93","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/168588.168596","article-title":"Random Oracles are Practical: A Paradigm for Designing\n  Efficient Protocols","author":"Mihir Bellare","year":"1993"},{"key":"ref23:C:BonZha13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/978-3-642-40084-1_21","article-title":"Secure Signatures and Chosen Ciphertext Security in a\n  Quantum Computing World","volume":"8043","author":"Dan Boneh","year":"2013"},{"key":"ref24:unruhRevocableQuantumTimedRelease2015","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2817206","article-title":"Revocable Quantum Timed-Release Encryption","volume":"62","author":"Dominique Unruh","year":"2015","journal-title":"Journal of the ACM"},{"key":"ref25:C:AmbHamUnr19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"269","DOI":"10.1007\/978-3-030-26951-7_10","article-title":"Quantum Security Proofs Using Semi-classical Oracles","volume":"11693","author":"Andris Ambainis","year":"2019"},{"key":"ref26:C:Zhandry12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"758","DOI":"10.1007\/978-3-642-32009-5_44","article-title":"Secure Identity-Based Encryption in the Quantum Random\n  Oracle Model","volume":"7417","author":"Mark Zhandry","year":"2012"},{"key":"ref27:C:Zhandry19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-3-030-26951-7_9","article-title":"How to Record Quantum Queries, and Applications to Quantum\n  Indifferentiability","volume":"11693","author":"Mark Zhandry","year":"2019"},{"key":"ref28:LC:FujOkaSai10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/978-3-642-14712-8_2","article-title":"Security of Sequential Multiple Encryption","volume":"6212","author":"Atsushi Fujioka","year":"2010"},{"key":"ref29:soroceanuMultipleEncryptionPublicKey2023","doi-asserted-by":"publisher","first-page":"49","DOI":"10.3390\/cryptography7040049","article-title":"On Multiple Encryption for Public-Key\n  Cryptography","volume":"7","author":"Tudor Soroceanu","year":"2023","journal-title":"Cryptography","ISSN":"https:\/\/id.crossref.org\/issn\/2410-387X","issn-type":"electronic"},{"key":"ref30:TCC:HofHovKil17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","article-title":"A Modular Analysis of the Fujisaki-Okamoto\n  Transformation","volume":"10677","author":"Dennis Hofheinz","year":"2017"},{"key":"ref31:TCC:TarUnr16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/978-3-662-53644-5_8","article-title":"Post-Quantum Security of the Fujisaki-Okamoto and OAEP\n  Transforms","volume":"9986","author":"Ehsan Ebrahimi Targhi","year":"2016"},{"key":"ref32:EC:SaiXagYam18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"520","DOI":"10.1007\/978-3-319-78372-7_17","article-title":"Tightly-Secure Key-Encapsulation Mechanism in the Quantum\n  Random Oracle Model","volume":"10822","author":"Tsunekazu Saito","year":"2018"},{"key":"ref33:C:JZCWM18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/978-3-319-96878-0_4","article-title":"IND-CCA-Secure Key Encapsulation Mechanism in the\n  Quantum Random Oracle Model, Revisited","volume":"10993","author":"Haodong Jiang","year":"2018"},{"key":"ref34:PKC:ShaGeXue23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/978-3-031-31368-4_2","article-title":"QCCA-Secure Generic Transformations in the Quantum Random\n  Oracle Model","volume":"13940","author":"Tianshu Shan","year":"2023"},{"key":"ref35:C:FujOka99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","article-title":"Secure Integration of Asymmetric and Symmetric Encryption\n  Schemes","volume":"1666","author":"Eiichiro Fujisaki","year":"1999"},{"key":"ref36:nielsenQuantumComputationQuantum2010","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511976667","volume-title":"Quantum Computation and Quantum Information: 10th\n  Anniversary Edition","author":"Michael A. Nielsen","year":"2010","journal-title":"Higher Education from Cambridge University Press"},{"key":"ref37:PQCRYPTO:TarTabUnr16","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1007\/978-3-319-29360-8_6","article-title":"Quantum Collision-Resistance of Non-uniformly Distributed\n  Functions","author":"Ehsan Ebrahimi Targhi","year":"2016"},{"key":"ref38:nationalinstituteofstandardsandtechnologyusModulelatticebasedKeyencapsulationMechanism2024","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.203","volume-title":"Module-lattice-based key-encapsulation mechanism standard","author":"National Institute of Standards","year":"2024"},{"key":"ref39:nationalinstituteofstandardsandtechnologyusSHA3StandardPermutationbased2015","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.202","volume-title":"SHA-3 standard : permutation-based hash and\n  extendable-output functions","author":"National Institute of Standards","year":"2015"},{"key":"ref40:EPRINT:Shoup04","volume-title":"Sequences of games: a tool for taming complexity in security\n  proofs","author":"Victor Shoup","year":"2004"},{"key":"ref41:EPRINT:AmbHamUnr18","volume-title":"Quantum security proofs using semi-classical oracles","author":"Andris Ambainis","year":"2018"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T20:23:23Z","timestamp":1759782203000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/3\/30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,6]]},"references-count":41,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,6]]}},"URL":"https:\/\/doi.org\/10.62056\/ayzogyl7s","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,6]]},"assertion":[{"value":"2025-07-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-56"}}