A method of exchanging a key

WO2026202496A1PCT designated stage Publication Date: 2026-10-01PQSHIELD LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/GB2026/050464
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-07-29
Filing Date
2026-03-20
Publication Date
2026-10-01

Smart Images

  • Figure GB2026050464_01102026_PF_FP_ABST
    Figure GB2026050464_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A method of exchanging a shared secret key is described. The method comprises generating an ephemeral key pair and sending an ephemeral public key of the ephemeral key pair to a second user device. The method further comprises receiving a ciphertext with a first individual part, a second individual part and a common part. The first individual part and the common part are decrypted to obtain a first randomness. The second individual part and the common part are decrypted to obtain a second randomness. A shared secret key is generated from the first randomness and the second randomness.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A METHOD OF EXCHANGING A KEY

[0002] Technical Field

[0003] The present invention relates to a method of exchanging a key, a device, a system, and a computer program.

[0004]

[0005] Secure communication between two devices typically requires agreement on a shared secret key for encryption of communications between the two devices. Agreeing on a shared secret key may proceed via a key exchange protocol, which may use a key encapsulation mechanism (KEM).

[0006] KEMs suitable for use in key exchange protocols may use a public / secret key pair for encapsulating and decapsulating the shared key. Long-term and short-term keys may be used during key exchange protocols. Short-term ephemeral keys are regenerated for each new key exchange, and long-term keys are associated with a particular device for a longer period of time.

[0007] Current efforts in cryptography are directed to ensuring communications remain secure against quantum computers, which are developing rapidly. Encryption that is secure against quantum computers, known as post-quantum encryption, typically requires larger ciphertexts. This may further increase the upload and download size required for secure encryption. Given uploading and downloading data may be expensive and time-consuming, it is desired to reduce the total size of the ciphertexts required for a post-quantum secure key exchange protocol.

[0008] Summary

[0009] According to a first aspect of the present invention, there is provided a method of exchanging a key between a first device and a second device. The method comprises, at the first device: generating an ephemeral key pair comprising an ephemeral public key and an ephemeral secret key, and sending the ephemeral public key to the second device; and receiving a ciphertext, wherein the ciphertext comprises a first individual part that encodes a first randomness, a second individual part that encodes a second randomness and a common part that can be used to decrypt the first individual part andthe second individual part, wherein the parameters for generating the first part, the second part and the common part are generated using the ephemeral public key. The method further comprises: obtaining the first randomness using the first individual part, the common part and a long-term secret key; obtaining the second randomness using the second individual part, the common part and the ephemeral secret key; and obtaining a shared secret key using the first randomness and the second randomness.

[0010] Sending the ephemeral public key to the second device may comprise sending the ephemeral public key directly from the first device to the second device. Alternatively, sending the ephemeral public key to the second device may comprise sending the ephemeral public key from the first device to the second device via a central actor such as a server.

[0011] The method may further comprise, as part of obtaining the shared secret key using the first randomness and the second randomness: encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key; checking that the encapsulation of the first randomness and the second randomness using the long-term public key and the ephemeral public key is consistent with the received ciphertext; and, if the encapsulation of the first randomness and the second randomness using the long-term public key and the ephemeral public key is consistent with the received ciphertext, deriving the shared secret key using the first randomness and the second randomness. In some implementations, the structure of the ciphertext may reduce a download size of the ciphertext, which enables generating a shared secret key to be performed more efficiently.

[0012] The shared secret key may be derived from the first randomness and the second randomness. The shared secret key may further be derived from the long-term public key and the ephemeral public key. In more detail, deriving the shared secret from the first randomness, the second randomness, the long-term public key and the ephemeral public key may comprise hashing, using one or more key derivation functions, the concatenation of the first randomness, the second randomness, the long-term public key and the ephemeral public key.

[0013] The first randomness may be obtained based on the subtracting a product of the common part and the long-term secret key from the first individual part.The method may yet further comprise, as part of encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key: deriving a second noise, a third noise, a fourth noise and a fifth noise from the first randomness, the second randomness, the long-term public key and the ephemeral public key; generating the common part of the ciphertext, wherein the common part is formed based on ct = rT• A + zT, wherein ct is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose; generating the first individual part of the ciphertext, wherein the first individual part is formed based on ct0= rT• b + z + Encode(M), wherein ct0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode(M) is an encoding of the first randomness and T denotes a transpose; and generating the second individual part of the ciphertext, wherein the second individual part is formed based on ctx= (r + rr)T• br+ zr+ Encode(Mr), wherein ctxis the second individual part, r is the second noise, rris the first noise, bris an ephemeral public key, zris the fifth noise, Encode(Mr) is an encoding of the second randomness and T denotes a transpose. In other words: the common part of the ciphertext may be based on a sum of the third noise and a product of the second noise and the public parameter; the first individual part of the ciphertext may be based on a sum of an encoding of the first randomness, the fourth noise and a product of the second noise and the long-term public vector; and the second individual part may be a sum of: an ephemeral public key multiplied by a transpose of a sum of the second noise and the first noise; the fifth noise and an encoding of the second randomness. Deriving the second noise, the third noise, the fourth noise and the fifth noise from the first randomness, the second randomness, the long-term public key and the ephemeral public key may comprise hashing, using a key derivation function, a concatenation of the first randomness, the second randomness, the long-term public key and the ephemeral public key.

[0014] The method may comprise, as part of generating the ephemeral key pair comprising the ephemeral public key and the ephemeral secret key: sampling the ephemeral secret key and an ephemeral first mask from a random distribution; and generating the ephemeral public key, wherein the ephemeral public key is formed basedon rpk = A • sr+ xr, wherein rpk is the ephemeral public key, A is the public parameter, sris the ephemeral secret key and xris the ephemeral first mask. In other words, the ephemeral public key may be formed based on a sum of the ephemeral first mask and the public parameter multiplied by the ephemeral secret key. The public parameter may comprise a public matrix. In some implementations the public parameter may be derived from a seed.

[0015] The method may further comprise, as part of obtaining the second randomness: deriving a first noise using the first randomness, a long-term public key and the ephemeral public key; and obtaining the second randomness using the second individual part, the common part, the ephemeral secret key and the first noise. Deriving the first noise using the first randomness, the long-term public key and the ephemeral public key may comprise hashing, using a key derivation function, a concatenation of the first randomness, the long-term public key and the ephemeral public key.

[0016] In some implementations the method may comprise, as part of encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key: deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key; generating the common part of the ciphertext, wherein the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose; generating the first individual part of the ciphertext, wherein the first individual part is formed based on v0= rT• b + z + Encode z), wherein v0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; and generating the second individual part of the ciphertext, wherein the second individual part is formed based on

[0017]

[0018] = rT• (br+ 5r) + zr+ Encode(μr) + A, wherein

[0019]

[0020] is the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise, zris the fifth noise, Encode(μr) is an encoding of the second randomness, A is the first noise and T denotes a transpose. In other words: the common part of the ciphertext may be based on a sum of the third noise and a product of the second noise and the public parameter; the first individual part of the ciphertext may be based on a sum of an encoding of the firstrandomness, the fourth noise and a product of the second noise and the long-term public vector; and the second individual part may be a sum of: the fifth noise; an encoding of the second randomness; a first noise; and a product of the second noise and a sum of the ephemeral public key and the sixth noise. Deriving the second noise, the third noise, the fourth noise, the fifth noise and the sixth noise from the first randomness, the second randomness and the ephemeral public key may comprise hashing, using a key derivation function, a concatenation of the first randomness, the second randomness and the ephemeral public key.

[0021] The method may comprise, as part of encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key: deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key; generating an intermediate common part of the ciphertext, wherein the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose; generating an intermediate first individual part of the ciphertext, wherein the first individual part is formed based on v0= rT• b + z + Encode z), wherein v0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; generating an intermediate second individual part of the ciphertext, wherein the second individual part is formed based on

[0022]

[0023] = rT• (br+ 5r) + zr+ Encode(μr), wherein

[0024]

[0025] is the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise, zris the fifth noise, Encode(μr) is an encoding of the second randomness and T denotes a transpose; compressing the intermediate first individual part, the intermediate second individual part and the intermediate common part to generate a first individual part, a second individual part and a common part; and amending the second individual part with a first noise.

[0026] In some implementations, the sixth noise Srmay be zero.

[0027] The method may further comprise, as part of amending the second individual part, computing v1 / amended= v̄1⊕ Δ, wherein v1 / amendedis the amended secondindividual part,

[0028]

[0029] is the second individual part, A is the first noise and © represents a logical XOR operation.

[0030] The method may comprise, as part of generating the ephemeral key pair comprising the ephemeral public key and the ephemeral secret key: sampling the ephemeral secret key and an ephemeral first mask from a random distribution; and generating the ephemeral public key, wherein the ephemeral public key is formed at least in part based on br= A • sr+ xr, wherein bris the ephemeral public key, A is the public parameter, sris the ephemeral secret key and xris the ephemeral first mask. In other words, the ephemeral public key may be formed based on a sum of the ephemeral first mask and the public parameter multiplied by the ephemeral secret key. The public parameter may comprise a public matrix. In some implementations the public parameter may be derived from a binary seed.

[0031] The method may further comprise, as part of obtaining the second randomness: deriving a first noise using the first randomness; and obtaining the second randomness using the second individual part, the common part, the ephemeral secret key and the first noise. Deriving the first noise using the first randomness may comprise hashing, using a key derivation function, the first randomness.

[0032] The method may further comprise, as part of obtaining the second randomness: de-masking the amended individual part based on v̄1= v1 / amended⊕ Δ, wherein vj is the second individual part, v1 / amendedis the amended individual part, A is the first noise and © represents a logical XOR operation; decompressing the second individual part to obtain the intermediate second individual part; and obtaining the second randomness using the intermediate second individual part, the common part, the ephemeral secret key and the first noise.

[0033] The method may further comprise parsing a long-term secret from the long-term secret key and parsing an ephemeral secret from the ephemeral secret key.

[0034] In some implementations, the method may use a lattice-based encryption scheme. The method may take place in a polynomial ring modulo q. The method may be usable as part of Post-Quantum WireGuard (PQ WireGuard). Alternatively, the method may be usable as part of the Key Exchange Mechanism Transport Layer Security with Pre-Distributed Keys protocol (KEMTLS-PDK).According to a second aspect of the present invention, there is provided a method of exchanging a key between a first device and a second device, the method comprising, at the second device: receiving an ephemeral public key; generating a shared secret key and a ciphertext, wherein the ciphertext may comprise a first individual part that encodes a first randomness, a second individual part that encodes a second randomness, and a common part that can be used to decrypt the first individual part and the second individual part, wherein the parameters for generating the first part, the second part and the common part are generated using the ephemeral public key; and transmitting the ciphertext.

[0035] The generating, of the second aspect, of the shared secret key and the ciphertext may comprise: generating the first randomness and the second randomness; deriving a first noise from the first randomness, a long-term public key of the first device and the ephemeral public key. Deriving the first noise from the first randomness, the long-term public key and the ephemeral public key may comprise hashing, using a key derivation function, the concatenation of the first randomness, the long-term public key of the first device and the ephemeral public key. The long-term public key may be the long-term public key of the device of the first aspect.

[0036] The generating, of the second aspect, of the shared secret key and the ciphertext may further comprise deriving a second noise, a third noise, a fourth noise and a fifth noise from the first randomness, the second randomness, the long-term public key and the ephemeral public key. Deriving the second noise, the third noise, the fourth noise and the fifth noise from the first randomness, the second randomness, the long-term public key and the ephemeral public key may comprise hashing, using a key derivation function, the concatenation of the first randomness, the second randomness, the long-term public key and the ephemeral public key. The second aspect may further comprise deriving the shared secret key from the first randomness, and the second randomness. The shared secret key may further be derived from the long-term public key and the ephemeral public key. Deriving the shared secret key from the first randomness, the second randomness, the long-term public key and the ephemeral public key may comprise hashing, using one or more key derivation functions, the concatenation of the first randomness, the second randomness, the long-term public key and the ephemeral public key.The generating, of the second aspect, of the ciphertext may yet further comprise: generating the common part of the ciphertext, wherein the common part of the ciphertext is formed based on ct = rT• A + zT, wherein ct is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose; generating the first individual part of the ciphertext, wherein the first individual part of the ciphertext is formed based on ct0= rT• b + z + Encode(M), wherein ct0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode(M) is an encoding of the first randomness and T denotes a transpose; and generating the second individual part of the ciphertext, wherein the second individual part is formed based on ctx= (r + rr)T• br+ zr+ Encode(Mr), wherein ctxis the second individual part, r is the second noise, rris the first noise, bris an ephemeral public key, zris the fifth noise, Encode(Mr) is an encoding of the second randomness and T denotes a transpose. In other words: the common part of the ciphertext may be formed based on a sum of the third noise and a product of the second noise and the public parameter. The first individual part of the ciphertext may be formed based on a sum of an encoding of the first randomness, the fourth noise and a product of the second noise and the long-term public vector. The second individual part may be formed based on a sum of: an ephemeral public key multiplied by a transpose of a sum of the second noise and the first noise; the fifth noise and an encoding of the second randomness.

[0037] The generating, of the second aspect, of the shared secret key and the ciphertext may comprise: generating the first randomness and the second randomness; and deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key. Deriving the second noise, the third noise, the fourth noise, the fifth noise and the sixth noise from the first randomness, the second randomness and the ephemeral public key may comprise hashing, using a key derivation function, a concatenation of the first randomness, the second randomness and the ephemeral public key.

[0038] The generating, of the second aspect, of the shared secret key and the ciphertext may comprise deriving a first noise from the first randomness, a long-term public key of the first device and the ephemeral public key. Deriving the first noise from the firstrandomness, the long-term public key and the ephemeral public key may comprise hashing, using a key derivation function, the concatenation of the first randomness, the long-term public key of the first device and the ephemeral public key.

[0039] The generating, of the second aspect, of the ciphertext may yet further comprise: generating the common part of the ciphertext, wherein the common part of the ciphertext is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose; generating the first individual part of the ciphertext, wherein the first individual part of the ciphertext is formed based on v0= rT• b + z + Encode z), wherein v0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; and generating the second individual part of the ciphertext, wherein the second individual part is formed based on

[0040]

[0041] = rT• (br+ 5r) + zr+ Encode(μr) + A, wherein

[0042]

[0043] is the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise, zris the fifth noise, Encode(μr) is an encoding of the second randomness, A is the first noise and T denotes a transpose. In other words: the common part of the ciphertext may be formed based on a sum of the third noise and a product of the second noise and the public parameter. The first individual part of the ciphertext may be formed based on a sum of an encoding of the first randomness, the fourth noise and a product of the second noise and the long-term public vector. The second individual part may be formed based on a sum of: the fifth noise; an encoding of the second randomness; a first noise; and a product of the second noise and a sum of the ephemeral public key and the sixth noise.

[0044] The second aspect may further comprise deriving the shared secret key from the first randomness and the second randomness. The shared secret key may further be derived from the ephemeral public key. Deriving the shared secret key from the first randomness, the second randomness and the ephemeral public key may comprise hashing, using one or more key derivation functions, the concatenation of the first randomness, the second randomness and the ephemeral public key.

[0045] The long-term public key may be the long-term public key of the device of the first aspect.The method may further comprise, as part of generating the shared secret key and the ciphertext: generating the first randomness and the second randomness; deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key; deriving a first noise from the first randomness; generating an intermediate common part of the ciphertext, where the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose; generating an intermediate first individual part of the ciphertext, wherein the intermediate first individual part is formed based on v0= rT• b + z + Encode(μ), wherein v0is the first individual part, r is the second noise, b is a longterm public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; generating an intermediate second individual part of the ciphertext, wherein the intermediate second individual part is formed based

[0046]

[0047] on = rT• (br+ 5r) + zr+ Encode(μr), wherein is the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise zris the fifth noise, Encode(μr) is an encoding of the second randomness, and T denotes a transpose; compressing the intermediate first individual part, the intermediate second individual part and the intermediate common part to generate the first individual part, the second individual part and the common part; amending the second individual part with a first noise; and deriving the shared secret key from the first randomness, the second randomness and the ephemeral public key.

[0048] In some implementations, the sixth noise Srmay be zero.

[0049] Amending the second individual part with the first noise may comprise computing v1 / amended= v̄1⊕ Δ, wherein v1 / amendedis the amended second individual part, is the second individual part, A is the first noise and © represents a logical XOR operation.

[0050] The long-term public vector may be a part of the public key. The public parameter may be a public matrix, or alternatively the public parameter may be a random binary seed. The method of the second aspect may use a lattice-based encryption scheme. The method may take place in a polynomial ring modulo q. The method of the second aspect may further comprise using Post-Quantum WireGuard (PQWireGuard). Alternatively, the method may further comprise using the Key Exchange Mechanism Transport Layer Security with Pre-Distributed Keys protocol (KEMTLS-PDK).

[0051] According to a third aspect of the invention, there may be provided a method for exchanging a key, the method comprising performing the method of the first aspect at a first device, and performing the method of the second aspect at a second device.

[0052] According to a fourth aspect of the invention, there may be provided a device configured to perform a method for exchanging a key according to the first aspect of the invention.

[0053] According to a fifth aspect of the invention, there may be provided a device configured to perform a method for generating a shared secret key according to the second aspect of the invention.

[0054] According to a sixth aspect of the invention, there may be provided a system configured to perform a method for exchanging a key according to the third aspect of the invention. The system may comprise a first device and a second device.

[0055] According to a seventh aspect of the invention, there may be provided a computer program comprising instructions which, when the program is executed by an information processing apparatus, cause the information processing apparatus to perform a method for exchanging a shared secret key according to the first or the second aspect of the invention. There may further be provided a non-transitory computer-readable storage medium carrying the computer program.

[0056] Further features and advantages of the invention will become apparent from the following description of preferred embodiments of the invention, given by way of example only, which is made with reference to the accompanying drawings.

[0057]

[0058] of the

[0059] Figure 1 is a schematic diagram illustrating a key exchange protocol between devices;

[0060] Figure 2 illustrates steps of a key exchange protocol between devices;

[0061] Figure 3 shows steps of a key generation method according to a first embodiment;Figure 4 shows steps of a second key generation method according to a first embodiment;

[0062] Figure 5 shows steps of an encapsulation method according to a first embodiment;

[0063] Figure 6 shows steps of a decapsulation method according to a first embodiment;

[0064] Figure 7 shows steps of a key generation method according to a second embodiment;

[0065] Figure 8 shows steps of a second key generation method according to a second embodiment;

[0066] Figure 9 shows steps of an encapsulation method according to a second embodiment;

[0067] Figure 9a shows steps of an encapsulation method according to a third embodiment;

[0068] Figure 10 shows steps of a decapsulation method according to a second embodiment;

[0069] Figure 10a shows steps of a decapsulation method according to a third embodiment; and

[0070] Figure 11 is a schematic diagram showing components of an information processing apparatus.

[0071] Detailed Description

[0072] Preliminaries

[0073] The present embodiment relates to two-party communication protocols.

[0074] Figure 1 is a schematic diagram showing two devices 11 in a two party messaging system. The devices may be a computer, laptop, smartphone, server, cloud service, or any other type of device that is capable of transmitting and receiving data. Each of the devices may be operated by a user. In other implementations one or both devices may not be user devices. For example, the device could be a server, a cloud service, an loT device, etc. that operates autonomously or is part of an infrastructure. In some implementations, the devices may communicate directly with each other. Inother implementations, the devices may communicate with each other indirectly, such as via a server 12.

[0075] The embodiments below will be described in the context of messaging between two devices. However, this is without limitation. The methods are generally applicable to any situation where it is desirable to generate a shared key between two devices.

[0076] Referring to Figure 1, the device 11 may wish to send data to a second device 11. The communication between devices is depicted by arrows 13 between the devices 11 and the server 12. As noted, communication between the devices 11 may proceed via a server 12 or other central actor or may proceed directly between the devices without passing through a server 12 or other central actor.

[0077] The devices 11 may communicate via any communication protocol suitable for messaging between two devices. The communication protocol may be asynchronous such that the uploaded and downloaded data are stored on the server until a device retrieves them. One of the devices 11, which is arbitrarily chosen to be the device in the bottom left of Figure 1, is depicted with a pair of keys comprising a long-term public key, pki, and a long-term secret key, ski. In practice, each device may have its own long-term public / secret key pair and the long-term public keys may be centrally published. Accordingly, each device knows the public key of each other device.

[0078] The long-term public / secret key pairs may be used for a key exchange protocol so that the devices can agree on a secure key. To enable the secure key to be agreed upon, the devices may use a key exchange protocol utilising a KEM. As such, the public / secret key pairs are associated with a post-quantum KEM that is used by both devices. Here, post-quantum is used to refer to a KEM that is secure against both a quantum computer and a classical computer. A suitable post-quantum KEM is described in the section below.

[0079] The public key of each device and the secret key of each device are generated using an algorithm KeyGen. KeyGen takes place at each of the devices. KeyGen takes as input a security parameter 1K, where K is a security parameter that defines a size of the public matrix and might take a value such as 128 or 256. In other words, KeyGen is KeyGen(lK). KeyGen returns a public / secret key pair ((A,b), s). The algorithm KeyGen is described in more detail later in the specific description.Overview

[0080] This section provides a high-level overview of the key exchange protocol. In the following, Rqdenotes the polynomial ring Z[X] / Xd+ 1), where d is the power to which X is raised. All vectors are represented in the column form. Bold font may be used to denote a vector. However, not all vectors are necessarily denoted using bold font. Multiplication may be understood to mean premultiplication or postmultiplication where not otherwise specified.

[0081] The algorithms described as part of the key exchange protocol may be the algorithms of the first embodiment, or the algorithms of the second embodiment.

[0082] Figure 2 is a diagram illustrating a key exchange protocol. The key exchange protocol takes place between a first device and a second device. The device that initiates the protocol is referred to as the first device. The other device is referred to as the second device. Each of the first device and the second device holds a long-term public key and a long-term secret key. Here, long-term is used to refer to the fact that the long-term key pair is not regenerated for each key exchange and may be reused for several key exchanges. The long-term public key of the first device is known to both the first device and the second device, and the long-term public key of the second device is known to both the second device and the first device. Each of the long-term secret keys is only known to the one of the devices: the long-term secret key of the first device is known to the first device and not known to the second device, and the long-term secret key of the second device is known to the second device and not known to the first device. The long-term public key pk of the first device and the long-term secret key sk of the first device are used in the protocol, so the long-term public key of the second device and the secret key of the second device are omitted from Figure 2.

[0083] The key exchange protocol proceeds chronologically down the rows of Figure 2. The left-hand column shows stages carried out by the first device; the right-hand column shows stages carried out by the second device. The first stage is to generate an ephemeral public key rpk and an ephemeral secret key rsk using an algorithm RKeyGen. The algorithm RKeyGen takes place on the first device. The algorithm RKeyGen takes as input a public matrix that is part of the long-term public key pk of the first device. In other words, RKeyGen can be described as RKeyGen(pk). RKeyGenoutputs the ephemeral public key rpk and the ephemeral secret key rsk that is generated using sampled values and the same public matrix as the long-term public / private key pair. The algorithm RKeyGen, along with other algorithms mentioned later, are described in more detail later in the detailed description.

[0084] Here, ephemeral is used to refer to the fact that the ephemeral key is regenerated for each key exchange. The ephemeral public key may be known to both devices. The ephemeral secret key is only known to the first device, i.e., the device that initiated the key exchange protocol.

[0085] After the algorithm RKeyGen takes place on the first device, the ephemeral public key rpk is transmitted. The ephemeral public key rpk may be transmitted directly from the first device to the second device, or the ephemeral public key rpk may be sent via a central actor such as a server from the first device to the second device.

[0086] The second device receives the ephemeral public key rpk. The ephemeral public key rpk may be received directly at the second device from the first device, or the ephemeral public key rpk may be received from a central actor such as a server.

[0087] The second device, in the second stage, generates a ciphertext ct and a shared secret ss using an algorithm REnc. The algorithm REnc takes place on the second device. The algorithm REnc takes as input the long-term public key pk of the first device and the ephemeral public key rpk. In other words, REnc can be described as REnc(pk, rpk). The algorithm REnc outputs the ciphertext ct and the shared secret ss.

[0088] The third stage is to generate a shared secret key K that is to be shared between the first device and the second device. The shared secret key K is generated, at this stage, by the second device. The shared secret key K is generated as K = H(ss, aux). Here, K is the shared secret key, ss is the shared secret and aux is a piece of auxiliary information that is held by each of the devices. H is a first hash function. Hash functions, including post-quantum secure hash functions, are well known in the art and any suitable hash function can be used. In other words, the shared secret key is a hash of a concatenation of the shared secret ss and the auxiliary information aux from each of the devices. The auxiliary information aux could be any additional information about either of the devices. For example, the auxiliary information aux could be an identifierassociated with the first device or the second device. Alternatively, the auxiliary information aux could be omitted entirely from the input to the hash function.

[0089] Similarly, auxiliary information could be included or omitted in the input of any of the other hash functions mentioned later, in any of the embodiments.

[0090] Subsequently, the ciphertext ct is sent from the second device to the first device. The ciphertext ct may be sent directly from the second device to the first device, or the ciphertext ct may be sent via a central actor such as a server from the second device to the first device.

[0091] The first device then receives the ciphertext ct. In the fourth stage, the first device decapsulates the shared secret ss from the ciphertext ct using an algorithm RDec. The algorithm RDec takes place on the first device. The algorithm RDec takes as input the secret key sk of the first device, the ephemeral secret key rsk and the ciphertext ct. In other words, RDec can be described as RDec(sk, rsk, ct). The algorithm RDec outputs the shared secret ss.

[0092] The fifth stage in the key exchange protocol is to generate the shared secret key K at the first device. The shared secret key K is generated as K = H(ss, aux). Here, K is the shared secret key, ss is the shared secret and aux is a piece of auxiliary information that is held by each of the devices. H is the first hash function. In other words, the shared secret key is a hash of a concatenation of the shared secret ss and the auxiliary information aux from each of the devices. This is the same step as the key generation process that took place earlier at the second device. As such, the first device and the second device each hold an identical shared secret key K. The key exchange protocol has resulted in the exchange of the shared secret key K between the two devices, the first device and the second device.

[0093] First embodiment

[0094] The algorithms used in Figure 2 in connection with the first embodiment are now described in more detail. The algorithm KeyGen takes place as part of the setup of communication between the two devices. The setup may take place sometime before a key exchange takes place. The algorithms RKeyGen, REnc and RDec take place as part of the key exchange protocol.The algorithm KeyGen is illustrated in more detail in Figure 3. KeyGen takes the security parameter 1Kas input, where K may take a value such as 128 or 256, and returns the long-term public key pk of the first device and the long-term secret key sk of the first device. KeyGen takes place at the first device.

[0095] In step 1, a public parameter in the form of a public matrix A is sampled from a distribution Rqn×k. The distribution Rqn×kis over the polynomial ring Rqand the distribution Rqn×khas dimension n X k. Here, k is the number of entries in a long-term secret s and n is the number of entries in a long-term first mask x. In some implementations, the public matrix A may be replaced by a random binary seed that can be used to regenerate the matrix A. Such implementations may reduce the size of the public key.

[0096] In step 2, the long-term secret s is sampled from a distribution %kand the longterm first mask x is sampled from a distribution %n. The long-term secret s is a vector with a number of rows equal to k and the long-term first mask x is a vector with a number of rows equal to n. The long-term secret s may be considered to be a small noise. The term small, as used here, is in reference to the fact the noise can be removed by a decoding step later in the key exchange protocol.

[0097] Step 3 describes generating a long-term public vector b. The long-term public vector b = A • s + x, where A is the public matrix, s is the long-term secret and x is the long-term first mask. In other words, the long-term public vector b is a sum of the longterm first mask x and the public matrix A postmultiplied by the long-term secret s.

[0098] In step 4, the algorithm KeyGen returns: the long-term public key pk of the first device as the public matrix A and the long-term public vector b; and the long-term secret key sk of the first device as the long-term secret s. In other words, the long-term public key pk = (A, b) and the long-term secret key sk = s. The long-term public key pk and the long-term secret key sk may be considered to be a public / secret key pair.

[0099] After the public key of each device and secret key of each device are generated at each respective device, the public keys can be shared amongst the two devices through any standard means, such as a public key infrastructure (PKI).

[0100] Figure 4 describes the algorithm RKeyGen. The algorithm RKeyGen takes as input the long-term public key pk of the first device. RKeyGen returns the ephemeralpublic key rpk and the ephemeral secret key rsk. RKeyGen takes place at the first device.

[0101] In step 1 of RKeyGen, the public matrix A and the long-term public vector b are parsed from the long-term public key pk of the first device. In step 2, an ephemeral secret sris sampled from a distribution

[0102]

[0103] and an ephemeral first mask xris sampled from a distribution

[0104]

[0105] The ephemeral secret sris a vector with a number of rows equal to k and the ephemeral first mask xris a vector with a number of rows equal to n.

[0106] Step 3 describes generating an ephemeral public key br. The ephemeral public key br= A • sr+ xr, where A is the public matrix, sris the ephemeral secret and xris the ephemeral first mask. In other words, the ephemeral public key bris a sum of the ephemeral first mask xrand the public matrix A postmultiplied by the ephemeral secret sr. In step 4, the algorithm RKeyGen returns: the ephemeral public key rpk as the ephemeral public key br; and the ephemeral secret key rsk as the ephemeral secret sr.

[0107] In other words, the ephemeral public key rpk = brand the ephemeral secret key rsk = sr. Figure 5 describes the algorithm REnc. The algorithm REnc takes as input the long-term public key pk of the first device and the ephemeral public key rpk. REnc returns the ciphertext, ct. REnc takes place at the second device.

[0108] In step 1 of REnc, the public matrix A and the long-term public vector b are parsed from the long-term public key pk of the first device. Also in step 1, the ephemeral public key bris parsed from rpk.

[0109] In step 2, a first randomness M and a second randomness Mrare sampled from a distribution {0, l]d. The symbol d describes the dimensions of both the first randomness M and the second randomness Mr. Both the first randomness M and the second randomness Mrmay be d-dimensional binary strings.

[0110] Step 3 describes generating a first noise rr. The first noise rr= H0(M, pk, rpk). Here, H0is a second hash function. Hash functions are well known in the art and any suitable hash function can be used. M is the first randomness, pk is the long-term public key of the first device and rpk is the ephemeral public key. In other words, the first noise rris a hash of a concatenation of the first randomness M, the long-term publickey pk of the first device and the ephemeral public key rpk. The first noise rris in the polynomial ring Rqand is a vector with n rows. In other words, the first noise rr∈ Rq.

[0111] Step 4 describes generating a second noise r, a third noise z, a fourth noise z and a fifth noise zr. The second noise r, the third noise z, the fourth noise z and the fifth noise zrare generated as (r, z, z, zr) = Hi (M, Mr, pk, rpk). Here, Hi is a third hash function. Hash functions are well known in the art and any suitable hash function can be used. M is the first randomness, Mris the second randomness, pk is the long-term public key of the first device and rpk is the ephemeral public key. In other words, the second noise r, the third noise z, the fourth noise z and the fifth noise zrare a hash of a concatenation of the first randomness M, the second randomness Mr, the long-term public key pk of the first device and the ephemeral public key rpk. The second noise r is in the polynomial ring Rqand is a vector with n rows. The third noise z is in the polynomial ring Rqand is a vector with k rows. The fourth noise z and the fifth noise zrare both in the polynomial ring and each have one term. In other words, (r, z, z, zr) ∈ Rqx Rqx Rqx Rq. The second noise r, the third noise z, the fourth noise z and the fifth noise zrmay each be considered to be small noises. Note that the first randomness M, the second randomness Mr, the long-term public key pk of the first device and the ephemeral public key rpk may be combined in alternative ways to the concatenation described here. For example, they could be concatenated in a different order, or summed together. Similarly, any of the other concatenations described in the description may be replaced by alternative ways of combining the hashed terms.

[0112] In step 5, the shared secret ss is generated. The shared secret ss = G(M, Mr, pk, rpk). Here, G is a fourth hash function. Hash functions are well known in the art and any suitable hash function can be used. M is the first randomness, Mris the second randomness, pk is the long-term public key of the first device and rpk is the ephemeral public key. In other words, the shared secret ss is a hash of a concatenation of the first randomness M, the second randomness Mr, the public key pk of the first device and the ephemeral public key rpk.

[0113] In step 6, the common part ct of the ciphertext is generated. The common part ct = rT• A + zT. Here, r is the second noise, A is the public matrix and z is the third noise. The symbol T denotes “the transpose of’. For example, rTdenotes the transposeof the second noise r. In other words, the common part ct of the ciphertext is equal to a sum of the transpose of the third noise zTand the public matrix A premultiplied by the transpose of the second noise rT.

[0114] Step 7 describes generating the first individual part ct0of the ciphertext. The first individual part ct0= rT• b + z + Encode(M). Here, r is the second noise, b is the long-term public vector, z is the fourth noise and M is the first randomness. As before, the symbol T denotes “the transpose of’. The term Encode(M) denotes encoding the first randomness M. In other words, the first individual part ct0of the ciphertext is a sum of: the long-term public vector b multiplied by the transpose of the second noise rT; the fourth noise z; and an encoding of the first randomness M.

[0115] Step 8 describes generating the second individual part ctxof the ciphertext. The second individual part ctx= (r + rr)T• br+ zr+ Encode(Mr). Here, r is the second noise, rris the first noise, bris the ephemeral public key, zris the fifth noise and Mris the second randomness. As before, the symbol T denotes “the transpose of’. The term Encode(Mr) denotes encoding the second randomness Mr. In other words, the second individual part is a sum of: the ephemeral public key brpremultiplied by the transpose of a sum of the second noise r and the first noise rr; the fifth noise zr; and an encoding of the second randomness Mr.

[0116] In step 9, the ciphertext is returned. The ciphertext comprises the common part ct, the first individual part ct0and the second individual part ctx.

[0117] Figure 6 describes the algorithm RDec. The algorithm RDec takes as input the long-term secret key of the first device, the ephemeral secret key and the ciphertext. RDec takes place at the first device.

[0118] In step 1 of RDec, the long-term secret s is parsed from the long-term secret key sk of the first device. Also in step 1, the ephemeral secret sris parsed from the ephemeral secret key rsk. Step 2 describes parsing the common part ct of the ciphertext, the first individual part ct0of the ciphertext and the second individual part ctxof the ciphertext from the ciphertext ct.

[0119] Step 3 describes decoding the common part ct of the ciphertext and the first individual part ct0of the ciphertext to obtain the first randomness M. A difference of the first individual part ct0of the ciphertext and a product of the common part ct of theciphertext and the long-term secret s is inputted into an error-correcting code, Decode. The error-correcting code Decode outputs the first randomness M. In other words, M = Decode(ct0— ct • s). Error-correcting codes are well known in the art and as such are not described further here.

[0120] In step 4, the first randomness M that was obtained in step 3 is used to obtain the first noise rr. The first noise rr= H0(M, pk, rpk). Here, Hois the second hash function, M is the first randomness, pk is the long-term public key of the first device and rpk is the ephemeral public key. In other words, the first noise rris a hash of a concatenation of the first randomness M, the long-term public key pk of the first device and the ephemeral public key rpk. Recall that this is the same definition of the first noise rras the definition of the first noise rrin the algorithm REnc. The obtained value of the first noise rrmay therefore equal the value of the first noise rrobtained in the algorithm REnc.

[0121] Step 5 of RDec describes decoding the common part ct of the ciphertext and the second individual part ctxof the ciphertext to obtain the second randomness Mr. The second randomness Mris obtained by decoding ctx— (ct + rrT- A) • sr. Here, ctxis the second individual part of the ciphertext, ct is the common part of the ciphertext, rris the first noise, A is the public matrix and sris the ephemeral secret. The term Decode in step 5 refers to an error-correcting code. Error-correcting codes are well known in the art and as such are not described further here. In other words, the second randomness Mris a decoding of a difference of the second individual part ctxof the ciphertext and the product of the ephemeral secret srand the sum of the common part ct of the ciphertext and the public matrix A premultiplied by the first noise rr.

[0122] Step 6 describes generating the second noise r, the third noise z, the fourth noise z and the fifth noise zr. The second noise r, the third noise z, the fourth noise z and the fifth noise zrare generated as (r, z, z,zr) = H1(M, Mr, pk, rpk). Here, Hi is the third hash function, M is the first randomness, Mris the second randomness, pk is the long-term public key of the first device and rpk is the ephemeral public key. In other words, the second noise r, the third noise z, the fourth noise z and the fifth noise zrare a hash of a concatenation of the first randomness M, the second randomness Mr, the long-term public key pk of the first device and the ephemeral public key rpk. Recall that step 6of RDec is the same as step 4 of REnc. The obtained values of the second noise r, the third noise z, the fourth noise z and the fifth noise zrin RDec may therefore equal the respective obtained values of REnc.

[0123] In steps 7 to 10, it is checked whether decryption of the ciphertext has proceeded correctly. In step 7, the components of the ciphertext ct are reconstructed using the parameters obtained earlier. The common part ct of the ciphertext is calculated as ct = rT• A + zT. Here, r is the second noise, A is the public matrix and z is the third noise. The symbol T denotes “the transpose of’. For example, rTdenotes the transpose of the second noise r. In other words, the common part ct of the ciphertext is equal to a sum of the transpose of the third noise zTand the public matrix A premultiplied by the transpose of the second noise rT.

[0124] The first individual part ct0of the ciphertext is calculated as ct0= rT• b + z + Encode(M). Here, r is the second noise, b is the long-term public vector, z is the fourth noise and M is the first randomness. As before, the symbol T denotes “the transpose of’. The term Encode(M) denotes encoding the first randomness M. In other words, the first individual part ct0of the ciphertext is a sum of: the long-term public vector b multiplied by the transpose of the second noise rT; the fourth noise z; and an encoding of the first randomness M.

[0125] The second individual part ctxis calculated as ctx= (r + rr)T• br+ zr+ Encode(Mr). Here, r is the second noise, rris the first noise, bris the ephemeral public key, zris the fifth noise and Mris the second randomness. As before, the symbol T denotes “the transpose of’. The term Encode(Mr) denotes encoding the second randomness Mr. In other words, the second individual part is a sum of: the ephemeral public key brpremultiplied by the transpose of a sum of the second noise r and the first noise rr; the fifth noise zr; and an encoding of the second randomness Mr.

[0126] As before, the ciphertext comprises the common part ct, the first individual part ct0and the second individual part ctx. Note that reconstructing the ciphertext in step 7 of RDec corresponds to steps 6 to 8 of REnc.

[0127] The reconstructed ciphertext is then compared with the ciphertext obtained earlier. It is checked whether the output of REnc equals the ciphertext ct that was received as input into RDec. If the output of REnc in step 7 of RDec does not equal theciphertext ct that was received as input into RDec, the algorithm RDec aborts in step 8. Otherwise, the algorithm returns the shared secret ss in steps 9 and 10. The shared secret ss is a hash of a concatenation of the first randomness M, the second randomness Mr, the long-term public key pk of the first device and the ephemeral public key rpk. In other words, the shared secret ss = G(M, Mr, pk, rpk). Here, G is a fourth hash function. Hash functions are well known in the art and any suitable hash function can be used. M is the first randomness, Mris the second randomness, pk is the public key of the first device and rpk is the ephemeral public key.

[0128] Throughout the first embodiment, standard techniques such as bit dropping may be used to reduce the size of the common part of the ciphertext. Standard techniques such as bit dropping may be used to reduce the size of the first individual part of the ciphertext. Standard techniques such as bit dropping may be used to reduce the size of the second individual part of the ciphertext.

[0129] Second embodiment

[0130] The second embodiment also uses the algorithms described earlier in connection with Figure 2. The algorithm KeyGen takes place as part of the setup of communication between the two devices. The setup may take place sometime before a key exchange takes place. The algorithms RKeyGen, REnc and RDec take place as part of the key exchange protocol.

[0131] The algorithm KeyGen is illustrated in more detail in Figure 7. KeyGen takes the security parameter 1λas input, where A may take a value such as 128 or 256, and returns the long-term public key pk of the first device and the long-term secret key sk of the first device. KeyGen takes place at the first device.

[0132] In step 1, a seed, referred to as seedA, is sampled from a random distribution. In this illustrated example, the security parameter (length of the seed) is 256, but this may be different in other embodiments. In step 2, a public parameter in the form of a public matrix A is generated from seedAusing the KeyGen hash function G. In other words, A = G(seedA). Hash functions are well known in the art and any suitable hash function can be used. The public matrix A is over the distribution Rqn×k. The distribution Rqn×kis over the polynomial ring Rqand the distribution Rqn×khas dimension n × k.Here, k is the number of entries in a long-term secret s and n is the number of entries in a long-term first mask x. In some implementations, as explained above, the public matrix A may be replaced by a random binary seed, seedA, that can be used to regenerate the matrix A. Such implementations may reduce the size of the public key.

[0133] In step 3, the long-term first secret s is sampled from a distribution χkand the long-term first mask x is sampled from a distribution χn. The long-term first secret s is a vector with a number of rows equal to k and the long-term first mask x is a vector with a number of rows equal to n. The long-term secret s may be considered to be a small noise. The term small, as used here, is in reference to the fact the noise can be removed by a decoding step later in the key exchange protocol.

[0134] Step 4 describes generating a long-term public vector b. The long-term public vector b = A • s + x, where A is the public matrix, s is the long-term first secret and x is the long-term first mask. In other words, the long-term public vector b is a sum of the long-term first mask x and the public matrix A postmultiplied by the long-term first secret s.

[0135] In step 5, the long-term public key pk of the first device is generated as the seed seedAand the long-term public vector b. In other words, the long-term public key pk = (seedA,b). In step 6, a long-term second secret s̃ is sampled from a binary string of length l. The length l may be, for example, 128 or 256. In step 7, the long-term secret key sk is defined as the seed, seedA, the long-term first secret s and the long-term second secret s̃. In other words, the long-term secret key sk = (seedA, s, s̃).

[0136] In step 8, the algorithm KeyGen returns the long-term public key pk of the first device and the long-term secret key sk of the first device. The long-term public key pk and the long-term secret key sk may be considered to be a public / secret key pair.

[0137] After the public key of each device and secret key of each device are generated at each respective device, the public keys can be shared amongst the two devices through any standard means, such as a public key infrastructure (PKI).

[0138] Figure 8 describes the algorithm RKeyGen. The algorithm RKeyGen takes as input the long-term public key pk of the first device. RKeyGen returns the ephemeral public key rpk and the ephemeral secret key rsk. RKeyGen takes place at the first device.In step 1 of RKeyGen, the seed, seedA, and the long-term public vector b are parsed from the long-term public key pk of the first device. In step 2, the public matrix A is generated from seedAusing the KeyGen hash function G. In other words, A = G(seedA). In step 3, an ephemeral first secret sris sampled from a distribution / and an ephemeral first maskxris sampled from a distribution / ”. The ephemeral first secret sris a vector with a number of rows equal to k and the ephemeral first mask xris a vector with a number of rows equal to n.

[0139] Step 4 describes generating an ephemeral public key br. The ephemeral public key br= A • sr+ xr, where A is the public matrix, sris the ephemeral first secret and xris the ephemeral first mask. In other words, the ephemeral public key bris a sum of the ephemeral first mask xrand the public matrix A postmultiplied by the ephemeral first secret sr.

[0140] In step 5, bit dropping is performed on the ephemeral public key brto generate the compressed ephemeral public key br. In other words, br= Compressq(br, dbr). Here, the subscript q denotes that the bit dropping takes place over the polynomial ring modulo q. The term dbrdescribes the degree of bit dropping that is performed on the ephemeral public key br. Bit dropping is well known in the art. In the second embodiment and other embodiments, compressed objects such as the compressed ephemeral public key may alternatively still be referred to without reference to the compression, i.e. they may still be referred to as the ephemeral public key or similar. In some descriptions of the second and other embodiments, objects before compression, such as the common part, may be referred to as the intermediate common part. Objects after compression, such as the compressed common part, may be referred to as the common part.

[0141] In step 6, the ephemeral second secret sris sampled from a binary string of length I. The length I may be, for example, 128 or 256.

[0142] In step 7, the algorithm RKeyGen returns: the ephemeral public key rpk as the compressed ephemeral public key br; and the ephemeral secret key rsk as the ephemeral first secret srand the ephemeral second secret sr. In other words, the ephemeral public key rpk = brand the ephemeral secret key rsk = (sr,s̃r).Figure 9 describes the algorithm REnc. The algorithm REnc takes as input the long-term public key pk of the first device and the ephemeral public key rpk. REnc returns the ciphertext ct and the shared secret ss. REnc takes place at the second device.

[0143] In step 1 of REnc, the seed, seedA, and the long-term public vector b are parsed from the long-term public key pk of the first device. Also in step 1, the compressed ephemeral public key bris parsed from rpk. In step 2, the public matrix A is generated from seedAusing the KeyGen hash function G. In other words, A = G(seedA).

[0144] In step 3, the decompressed ephemeral public key bris obtained by decompressing the compressed ephemeral public key br. In other words, br= Decompress(br, dbr). The term dbrdescribes the degree of bit dropping that was performed on the ephemeral public key brin the algorithm RKeyGen.

[0145] In step 4, a first randomness μ and a second randomness μrare sampled from a distribution {0,1}l. The symbol l describes the dimensions of both the first randomness μ and the second randomness μr. Both the first randomness μ and the second randomness μrmay be binary strings.

[0146] Step 5 describes generating a second noise r, a third noise z, a fourth noise z, a fifth noise zrand a sixth noise Sr. The second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise δrare generated as (r, z, z, zr, δr) = F(rpk, μ, μr). Here, F is a third hash function. Hash functions are well known in the art and any suitable hash function can be used, rpk is the ephemeral public key, μ is the first randomness, and μris the second randomness. In other words, the second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise δrare a hash of a concatenation of the ephemeral public key rpk, the first randomness μ, and the second randomness μr. The second noise r is in the polynomial ring Rqand is a vector with n rows. The third noise z is in the polynomial ring Rqand is a vector with k rows. The fourth noise z and the fifth noise zrare both in the polynomial ring and each have one term. The sixth noise Sris in the polynomial ring Rqand is a vector with n rows. In other words, (r, z, z, zr, δr) ∈ Rqn× Rqk× Rq× Rq× Rqn. The second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise Srmay each be considered to be small noises. Note that the ephemeral public key rpk, the firstrandomness, and the second randomnessrmay be combined in alternative ways to the concatenation described here. For example, they could be concatenated in a different order or summed together. Similarly, any of the other concatenations described in the description may be replaced by alternative ways of combining the hashed terms. Note that generating the sixth noise Sris optional and may be made redundant by altering parameters such as the degree of bit dropping used later step 12 of REnc.

[0147] Step 6 describes generating a first noise Δ. The first noise Δ = Gr(μ). Here, Gris a second hash function. Hash functions are well known in the art and any suitable hash function can be used. μ is the first randomness. In other words, the first noise Δ is a hash of the first randomness μ. The first noise Δ is in the polynomial ring Rqand is a single term. In other words, the first noise Δ ∈ Rq.

[0148] In step 7, the common part u of the ciphertext is generated. The common part u = rT· A + zT. Here, r is the second noise, A is the public matrix and z is the third noise. The symbol T denotes “the transpose of’. For example, rTdenotes the transpose of the second noise r. In other words, the common part u of the ciphertext is equal to a sum of the transpose of the third noise zTand the public matrix A premultiplied by the transpose of the second noise rT.

[0149] Step 8 describes generating the first individual part v0of the ciphertext. The first individual part is v0= rT· b + z + μ · ⌊q / 2⌋. Here, r is the second noise, b is the

[0150]

[0151] long-term public vector, z is the fourth noise and μ is the first randomness. The term q refers to the modulo of the ring over which the method takes place. The term q may take a value in the range 7,000 to 10,000, or any other value. The brackets [... J denotes rounding the term inside the brackets to the nearest integer. The term μ · ⌊q / 2⌋ may be used to denote an encoding of the first randomness μ. Accordingly, the term μ · ⌊q / 2⌋ could alternatively be denoted Encode(μ). Alternatively, any suitable encoding function could be used. As before, the symbol T denotes “the transpose of’. In other words, the first individual part v0of the ciphertext is a sum of: the long-term public vector b multiplied by the transpose of the second noise rT; the fourth noise z; and an encoding of the first randomness μ.Step 9 describes generating the second individual part v of the ciphertext. The second individual part is v1= rT· (br+ δr) + zr+ μr· ⌊q / 2⌋ + Δ. Here, r is the

[0152]

[0153] second noise, bris the decompressed ephemeral public vector, δris the sixth noise, zris the fifth noise, μris the second randomness, q is the modulo of the ring over which the method takes place, and Δ is the first noise. The term q may take a value in the range 7,000 to 10,000, or any other value. The brackets [... J denotes rounding the term inside the brackets to the nearest integer. The term μr· ⌊q / 2⌋ may be used to denote an encoding of the second randomness μr. Accordingly, the term μr· ⌊q / 2⌋ could alternatively be denoted Encode(μr). Alternatively, any suitable encoding function could be used. As before, the symbol T denotes “the transpose of’. In other words, the second individual part is a sum of: a product of the transpose of the second noise r and a sum of the decompressed ephemeral public vector brand the sixth noise δr; the fifth noise zr; an encoding of the second randomness μr; and the first noise Δ.

[0154] In step 10, bit dropping is performed on the common part u of the ciphertext to generate the compressed common part u of the ciphertext. In other words, u = Compressq(u, du). The term dudescribes the degree of bit dropping that is performed on the common part u of the ciphertext. In step 11, bit dropping is performed on the first individual part v0of the ciphertext to generate the compressed first individual part of the ciphertext. In other words,

[0155]

[0156] = Compressq(v0, dv). The term dVodescribes the degree of bit dropping that is performed on the first individual part v0of the ciphertext. In step 12, bit dropping is performed on the second individual part

[0157]

[0158] of the ciphertext to generate the compressed second individual part 14 of the ciphertext. In other words, v̄1= Compressq(v1, dv) The term dVidescribes the degree of bit dropping that is performed on the second individual part

[0159]

[0160] of the ciphertext. In steps 10, 11 and 12, the subscript q denotes that the bit dropping takes place over the polynomial ring modulo q. Bit dropping is well known in the art.

[0161] Step 13 describes generating the ciphertext ct. The ciphertext comprises the compressed common part u, the compressed first individual part

[0162]

[0163] and the compressed second individual part vj. In other words, ct =

[0164]

[0165] (u,In step 14, the shared secret ss is generated. The shared secret ss = H(rpk, μ, μr). Here, H is the first hash function. Hash functions are well known in the art and any suitable hash function can be used, rpk is the ephemeral public key, μ is the first randomness, and μris the second randomness. In other words, the shared secret ss is a hash of a concatenation of the ephemeral public key rpk, the first randomness μ, and the second randomness μr.

[0166] In step 15, the ciphertext ct and the shared secret ss are returned.

[0167] Figure 10 describes the algorithm RDec. The algorithm RDec takes as input the long-term secret key of the first device sk, the ephemeral secret key rsk and the ciphertext ct. RDec takes place at the first device.

[0168] In step 1 of RDec, the seed, seedA, the long-term first secret s and the long-term second secret s are parsed from the long-term secret key sk of the first device. In step 2, the ephemeral first secret srand the ephemeral second secret srare parsed from the ephemeral secret key rsk. In step 3, the compressed common part u of the ciphertext, the compressed first individual part

[0169]

[0170] of the ciphertext and the compressed second individual part vj of the ciphertext are parsed from the ciphertext ct.

[0171] Step 4 describes obtaining the decompressed common part u of the ciphertext by decompressing the compressed common part u of the ciphertext. In other words, u = Decompress(u, du). The term dudescribes the degree of bit dropping that was performed on the common part u of the ciphertext in the algorithm REnc. Step 5 describes obtaining the decompressed first individual part

[0172]

[0173] of the ciphertext by decompressing the compressed first individual part

[0174]

[0175] of the ciphertext. In other words, v̄0= Decompressq(v̄0, dv). The term dVgdescribes the degree of bit dropping that was performed on the first individual part v0of the ciphertext in the algorithm REnc. Step 6 describes obtaining the decompressed second individual part

[0176]

[0177] of the ciphertext by decompressing the compressed second individual part vf of the ciphertext. In other words,

[0178]

[0179] = Decompressq(v̄1, dv) The term dVidescribes the degree of bit dropping that was performed on the second individual part

[0180]

[0181] of the ciphertext in the algorithm REnc.

[0182] In step 7, the decrypted first randomness

[0183]

[0184] is obtained by rounding the difference of the decompressed first individual part v0~ and a product of thedecompressed common part u and the long-term first secret s. In other words,

[0185]

[0186] = Roundq(v̄0− u · s). The subscript q denotes that the rounding takes place over the polynomial ring modulo q. The rounded term can be interpreted, with knowledge of the publicly available parameter, modulo q, to obtain the decrypted first randomness / / '. The decrypted first randomness μ' can be found, despite the presence of noise, because the modulo value is far larger than the noise and so the zero or one coefficients that comprise the decrypted first randomness

[0187]

[0188] can still be determined. For example, each coefficient of the resulting term may be rounded to zero if the respective each of the coefficients is closer to zero than ||j, and rounding each coefficient of the resulting

[0189]

[0190] term to one if the respective each of the coefficients is closer to |^j than zero. If the

[0191]

[0192] more general method Encode z) is used instead of • |^j, the encoding of the

[0193]

[0194] decrypted first randomness

[0195]

[0196] can be decoded by any suitable decoding method.

[0197] Step 8 describes obtaining the first noise Δ using the first randomness μ'. The first noise Δ = Gr(μ'). Here, Gris the second hash function and

[0198]

[0199] μ' is the decrypted first randomness. In other words, the first noise Δ is a hash of the first decrypted randomness μ'. Recall that this is the same definition of the first noise Δ as the definition of the first noise Δ in the algorithm REnc. The obtained value of the first noise Δ may therefore equal the value of the first noise Δ obtained in the algorithm REnc.

[0200] Step 9 describes obtaining the decrypted second randomness μr' using the decompressed second individual part

[0201]

[0202] and the decompressed common part u. The decrypted second randomness is found by rounding the decompressed second individual part

[0203]

[0204] minus a sum of the first noise Δ and a product of a transpose of the decompressed common part uTand the ephemeral first secret sr. In other words, μr' = Roundq(v̄1− uT· sr− Δ). The subscript q denotes that the rounding takes place over the polynomial ring modulo q. The rounded term can be interpreted, with knowledge of the publicly available parameter, modulo q, to obtain the decrypted second randomness μr'. The decrypted second randomness μr' can be found, despite the presence of noise, because the modulo value is far larger than the noise and so the zero or one coefficients that comprise the decrypted second randomness μr' can still be determined. For example, each coefficient of the resulting term may be rounded to zeroif the respective each of the coefficients is closer to zero than ||j, and rounding each

[0205]

[0206] coefficient of the resulting term to one if the respective each of the coefficients is closer to ||j than zero. If the more general method Encode(μr) is used instead ofr• | j, the encoding of the decrypted second randomness [ir' can be decoded by any suitable decoding method.

[0207] Step 10 describes obtaining the decrypted ciphertext ct' and the decrypted shared secret ss'. The decrypted ciphertext ct' is constructed from the public key pk of the first device, the ephemeral public key rpk, the decrypted first randomness ' and the decrypted second randomness,'..

[0208] To begin construction of the decrypted ciphertext ct', the second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise Srare generated as (r, z, z, zr, 5r) = F(rpk, / / ', / ). Here, F is the third hash function. Hash functions are well known in the art and any suitable hash function can be used, rpk is the ephemeral public key, / / ' is the decrypted first randomness, and [ir' is the decrypted second randomness. In other words, the second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise Srare a hash of a concatenation of the ephemeral public key rpk, the decrypted first randomness / / ', and the decrypted second randomness,'..

[0209] Next, the common part u of the ciphertext is reconstructed as u = rT• A + zT.

[0210] Here, r is the second noise, A is the public matrix and z is the third noise. The symbol T denotes “the transpose of’. For example, rTdenotes the transpose of the second noise r. In other words, the common part u of the ciphertext is equal to a sum of the transpose of the third noise zTand the public matrix A premultiplied by the transpose of the second noise rT.

[0211] Then, the first individual part v0of the ciphertext is reconstructed as v0= rT- b + z + ' • | j. Here, r is the second noise, b is the long-term public vector, z is the fourth noise and / / ' is the decrypted first randomness. As before, the symbol T denotes “the transpose of’. In other words, the first individual part v0of the ciphertext is a sum of: the long-term public vector b multiplied by the transpose of the second noise rT; the fourth noise z; and an encoding of the decrypted first randomness / / '. The long-termpublic vector b is already known to the first device because it was generated as part of the algorithm KeyGen and is a part of the public key of the first device.

[0212] Next, the second individual part

[0213]

[0214] of the ciphertext is reconstructed as

[0215]

[0216] = rT• ( br+ 5r) + zr+ / ir' • + A. Here, r is the second noise, bris the ephemeral

[0217]

[0218] public vector, Sris the sixth noise, zris the fifth noise, [ir' is the decrypted second randomness, q is the modulo of the ring over which the method takes place, and A is the first noise. The term q may take a value in the range 7,000 to 10,000, or any other value. The brackets [... J denotes rounding the term inside the brackets to the nearest integer. The term [ir' • \q / 2 J may be used to denote an encoding of the decrypted second randomness q'r. Accordingly, the term fir' • [q / 2] could alternatively be denoted Encode( / ). Alternatively, any suitable encoding function could be used. As before, the symbol T denotes “the transpose of’. In other words, the second individual part is a sum of a product of the transpose of the second noise r and a sum of the ephemeral public vector brand the sixth noise Sr, the fifth noise zr; an encoding of the decrypted second randomness [ir' and the first noise A. The ephemeral public vector bris known to the first device because it was generated as part of the algorithm RKeyGen.

[0219] The next steps are to perform bit dropping on each part of the ciphertext. Bit dropping is performed on the common part u of the ciphertext to generate the compressed common part u of the ciphertext. In other words, u = Compressq(u, du). The term dudescribes the degree of bit dropping that is performed on the common part u of the ciphertext. Bit dropping is performed on the first individual part v0of the ciphertext to generate the compressed first individual part

[0220]

[0221] of the ciphertext. In other words,

[0222]

[0223] = Compressq(v0, dVo). The term dVodescribes the degree of bit dropping that is performed on the first individual part v0of the ciphertext. Bit dropping is performed on the second individual part

[0224]

[0225] of the ciphertext to generate the compressed second individual part vf of the ciphertext. In other words, v̄1= Compressq(v1, dv) The term dVidescribes the degree of bit dropping that is performed on the second individual part

[0226]

[0227] of the ciphertext.

[0228] The decrypted ciphertext ct' is then obtained using the compressed common part u, the compressed first individual part and the compressed second individualpart that were obtained as part of step 10 of RDec. The decrypted ciphertext ct' comprises the compressed common part u, the compressed first individual part

[0229]

[0230] and the compressed second individual part vj. In other words, ct = (u,t^,v ).

[0231] The decrypted shared secret is obtained as ss' = H(rpk, / / ',,.). Here, H is the first hash function. Hash functions are well known in the art and any suitable hash function can be used, rpk is the ephemeral public key, ' is the decrypted first randomness, and [ir' is the decrypted second randomness. In other words, the decrypted shared secret ss' is a hash of a concatenation of the ephemeral public key rpk, the decrypted first randomness / / ', and the decrypted second randomness,'.. Note that step 10 of RDec corresponds to step 5 of REnc and steps 7 to 14 of REnc.

[0232] In steps 11 to 13, it then is checked whether the decryption of the ciphertext has proceeded correctly. In step 11, it is checked whether the decrypted ciphertext ct' equals the ciphertext ct that was received as input into RDec. Alternatively, each of the common part, the first individual part and the second individual part of the decrypted ciphertext could be compared to the respective each of the common part, the first individual part and the second individual part of the received ciphertext. The common part, the first individual part and the second individual part of the decrypted ciphertext may be compared to the respective each of the common part, the first individual part and the second individual part after bit dropping takes place. In another alternative, the common part, the first individual part and the second individual part of the decrypted ciphertext may be compared to the respective each of the common part, the first individual part and the second individual part of the received ciphertext without bit dropping.

[0233] If the decrypted ciphertext ct' does not equal the ciphertext ct that was received as input into RDec, the algorithm RDec aborts in step 12 by returning Hprf(s,sr, rpk, ct). Here, Hprfis a pseudo-random function, s is the long-term second secret, sris the ephemeral second secret, rpk is the ephemeral public key and ct is the ciphertext that was received by the first device at the beginning of RDec. The returned value is an implicit rejection. Alternatively, an explicit symbol indicating that the decrypted ciphertext ct' does not equal the ciphertext ct that was received as input into RDec could be returned, such as the symbol 1.If the decrypted ciphertext ct' does equal the ciphertext ct that was received as input into RDec, the algorithm returns the shared secret ss in step 13. In step 13, decryption has proceeded correctly, so the shared secret ss is equal to the decrypted shared secret ss'. This means that the first device and the second device each hold a copy of the shared secret ss.

[0234] Third embodiment

[0235] As with the first and second embodiments, the third embodiment uses the algorithms described earlier in connection with Figure 2. The algorithm KeyGen takes place as part of the setup of communication between the two devices. The setup may take place sometime before a key exchange takes place. The algorithms RKeyGen, REnc and RDec take place as part of the key exchange protocol.

[0236] The algorithm KeyGen is the same as the algorithm KeyGen of the second embodiment, which is shown in Figure 7, and a description of the algorithm KeyGen is not repeated here.

[0237] The algorithm RKeyGen is the same as the algorithm RKeyGen of the second embodiment, which is shown in Figure 8, and a description of the algorithm RKeyGen is not repeated here.

[0238] The algorithm REnc of the third embodiment is different to the algorithm REnc of the second embodiment. The algorithm REnc of the third embodiment is described here with reference to Figure 9a. The algorithm REnc takes as input the long-term public key pk of the first device and the ephemeral public key rpk. REnc returns the ciphertext ct and the shared secret ss. REnc takes place at the second device.

[0239] Steps 1 to 5 of REnc of the third embodiment are the same as steps 1 to 5 of REnc of the second embodiment and a description of the steps is not repeated here. Step 6 of REnc of the third embodiment describes generating a first noise A. The first noise A = Gr( / z). Here, Gris a second hash function. Hash functions are well known in the art and any suitable hash function can be used. is the first randomness. In other words, the first noise A is a hash of the first randomness. The first noise A, in contrast to the first noise A of the second embodiment, is a vector of dimension d. Each entry in the vector is a bit string of length dVi. Because each entry is a bit string of length dVi, eachentry may take one of 2dpi possible values. The bit strings may be sampled uniformly from a set of integers to produce random bit strings. This saves computational resources compared to sampling from the polynomial ring.

[0240] Steps 7 and 8 of REnc of the third embodiment are the same as steps 7 and 8 of REnc of the second embodiment and a description of the steps is not repeated here. Step 9 of REnc of the third embodiment describes generating the second individual part of the ciphertext. The second individual part is = rT• ( br+ 5r) + zr+ gr• [|]. r

[0241]

[0242] is the second noise, bris the decompressed ephemeral public vector, Sris the sixth noise, zris the fifth noise,ris the second randomness, and q is the modulo of the ring over which the method takes place. The term q may take a value in the range 7,000 to 10,000, or any other value. The brackets [... J denotes rounding the term inside the brackets to the nearest integer. The termr• [q / 2] may be used to denote an encoding of the second randomnessr. Accordingly, the termr• [q / 2] could alternatively be denoted Encode(μr). Alternatively, any suitable encoding function could be used. As before, the symbol T denotes “the transpose of’. In other words, the second individual part is a sum of: a product of the transpose of the second noise r and a sum of the decompressed ephemeral public vector brand the sixth noise Sr, the fifth noise zr; and an encoding of the second randomnessr. Note that, in contrast to the second embodiment, the first noise A is not added when generating the second individual part in the third embodiment.

[0243] Steps 10 and 11 of REnc of the third embodiment are the same as steps 10 and 11 of REnc of the second embodiment and a description of the steps is not repeated here. In step 12, bit dropping is performed on the second individual part v15and then a logical XOR operation is performed with the second individual part and the first noise A. This generates the compressed second individual part 14 of the ciphertext. In other words,

[0244]

[0245] = Compressors dv) © A. The term Compressq(v1, dv) describes the bit dropping performed on the second individual part v±. The term dVidescribes the degree of bit dropping that is performed on the second individual part

[0246]

[0247] of the ciphertext. The subscript q denotes that the bit dropping takes place over the polynomial ring modulo q. The symbol © denotes the logical XOR operation with the first noiseA. The logical XOR operation compares its two input values, in this case Compressor?!, dV1) and A, in a bitwise fashion, and returns a value of 1 if the two values are the same and a value of 0 if the two values are different. In this case, because the values over the polynomial ring comprised multiple elements, and bit dropping has been performed on each of the elements, the term Compressq(v1, dv) is a vector of dimension d with each entry of the vector comprising a bit string of length dVi. As described above, the term A is a vector of dimension d with each entry of the vector comprising a bit string of length dVi. Accordingly, each of the entries in Compressors, d

[0248]

[0249] Vi) are compared bit-by-bit with the entries in A when performing the logical XOR operation. The first noise A therefore acts to mask the second individual part t?i. The compressed second individual part after the logical XOR operation has been performed may be referred to as the amended compressed second individual part to distinguish it from the compressed second individual part before the logical XOR operation has been performed.

[0250] Steps 13 to 15 of REnc of the third embodiment are the same as steps 13 to 15 of REnc of the second embodiment and a description of the steps is not repeated here.

[0251] Figure 10a describes the algorithm RDec. The algorithm RDec takes as input the long-term secret key of the first device sk, the ephemeral secret key rsk and the ciphertext ct. RDec takes place at the first device.

[0252] Steps 1 to 5 of RDec of the third embodiment are the same as steps 1 to 5 of RDec of the second embodiment and a description of the steps is not repeated here. Step 6 of RDec of the third embodiment is the same as step 7 of RDec of the second embodiment. Step 7 of RDec of the third embodiment describes obtaining the first noise A using the first randomness / / '. The first noise A = Gr( / / '). Here Gris the second hash function

[0253]

[0254] and is the decrypted first randomness. In other words, the first noise A is a hash of the first decrypted randomness / / '. Recall that this is the same definition of the first noise A as the definition of the first noise A in the algorithm REnc of the third embodiment. The obtained value of the first noise A may therefore equal the value of the first noise A obtained in the algorithm REnc. Note that, as described in connection with REnc, the first noise A is a vector of dimension d and each entry in the vector is a bit string of length dVi.Step 8 of RDec involves obtaining the decompressed second individual part v^. Because the second individual part was masked with the first noise A during REnc, the second individual part is de-masked with the first noise A before decompression. The second individual part is de-masked by performing an XOR operation with the compressed second individual part and the first noise A. In other words, the second individual part is de-masked by calculating vj © A, where vj is the compressed second individual part, A is the first noise and © represents an XOR operation. The calculation of step 8 is therefore performed as

[0255]

[0256] = Decompressq(v © A, dVi~). The term dVidescribes the degree of bit dropping that was performed on the second individual part of the ciphertext in the algorithm REnc. The subscript q, along with the subscript qs used elsewhere in reference to compression and decompression, denotes that the compression was of a term in the polynomial ring Rq.

[0257] Step 9 of RDec describes obtaining the decrypted second randomness [ir' using the decompressed second individual partly and the decompressed common part u. The decrypted second randomness [ir' is found by rounding the decompressed second individual part minus a product of a transpose of the decompressed common part uTand the ephemeral first secret sr. In other words, [ir' = Roundq( — uT• sr). The subscript q denotes that the rounding takes place over the polynomial ring modulo q. The rounded term can be interpreted, with knowledge of the publicly available parameter, modulo q, to obtain the decrypted second randomness

[0258]

[0259] For a description of how the coefficients are determined, see the method of the second embodiment. As with the second embodiment, if the more general method Encode(μr) is used instead of gr• the encoding of the decrypted second randomness / ir' can be decoded by any suitable decoding method.

[0260] Step 10 describes obtaining the decrypted ciphertext ct' and the decrypted shared secret ss'. The decrypted ciphertext ct' is constructed from the public key pk of the first device, the ephemeral public key rpk, the decrypted first randomness g' and the decrypted second randomness g,'.. Step 10 of RDec of the third embodiment has similarities with step 10 of RDec of the second embodiment.

[0261] To begin construction of the decrypted ciphertext ct', the second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise Srare generatedas (r, z, z, zr, 5r) = F(rpk, f ', Here, F is the third hash function. Hash functions are well known in the art and any suitable hash function can be used, rpk is the ephemeral public key,

[0262]

[0263] is the decrypted first randomness, and [ir' is the decrypted second randomness. In other words, the second noise r, the third noise z, the fourth noise z, the fifth noise zrand the sixth noise Srare a hash of a concatenation of the ephemeral public key rpk, the decrypted first randomness / / ', and the decrypted second randomness q'r.

[0264] Next, the common part u of the ciphertext is reconstructed as u = rT• A + zT.

[0265] Here, r is the second noise, A is the public matrix and z is the third noise. The symbol T denotes “the transpose of’. For example, rTdenotes the transpose of the second noise r. In other words, the common part u of the ciphertext is equal to a sum of the transpose of the third noise zTand the public matrix A premultiplied by the transpose of the second noise rT.

[0266] Then, the first individual part v0of the ciphertext is reconstructed as v0= rT- b + z + / / ' • |^j. Here, r is the second noise, b is the long-term public vector, z is the

[0267]

[0268] fourth noise and

[0269] is the decrypted first randomness. As before, the symbol T denotes “the transpose of’. In other words, the first individual part v0of the ciphertext is a sum of: the long-term public vector b multiplied by the transpose of the second noise rT; the fourth noise z; and an encoding of the decrypted first randomness / / '. The long-term public vector b is already known to the first device because it was generated as part of the algorithm KeyGen and is a part of the public key of the first device.

[0270] Next, the second individual part

[0271]

[0272] of the ciphertext is reconstructed as V-L = rT• ( br+ 5r) + zr+ / ir' • ||j. Here, r is the second noise, bris the ephemeral

[0273]

[0274] public vector, Sris the sixth noise, zris the fifth noise, [ir' is the decrypted second randomness, and q is the modulo of the ring over which the method takes place. The term q may take a value in the range 7,000 to 10,000, or any other value. The brackets [... J denotes rounding the term inside the brackets to the nearest integer. The term [ir' • [q / 2] may be used to denote an encoding of the decrypted second randomness

[0275]

[0276] Accordingly, the term [ir' • [q / 2] could alternatively be denoted Encode( / ). Alternatively, any suitable encoding function could be used. As before,the symbol T denotes “the transpose of’. In other words, the second individual part is a sum of: a product of the transpose of the second noise r and a sum of the ephemeral public vector brand the sixth noise Sr, the fifth noise zr; and an encoding of the decrypted second randomness

[0277]

[0278] The ephemeral public vector bris known to the first device because it was generated as part of the algorithm RKeyGen.

[0279] The next steps are to perform bit dropping on each part of the ciphertext. Bit dropping is performed on the common part u of the ciphertext to generate the compressed common part u of the ciphertext. In other words, u = Compressq(u, du). The term dudescribes the degree of bit dropping that is performed on the common part u of the ciphertext. Bit dropping is performed on the first individual part v0of the ciphertext to generate the compressed first individual part

[0280]

[0281] of the ciphertext. In other words,

[0282]

[0283] = Compressq(v0, dVo). The term dVodescribes the degree of bit dropping that is performed on the first individual part v0of the ciphertext. As discussed in connection with the second embodiment, in some descriptions objects before compressed may be referred to as ‘intermediate’ objects, e.g. intermediate first individual part, and objects after compression may be referred to without the prefix ‘compressed’, e.g. first individual part.

[0284] Bit dropping is performed on the second individual part v15and then a logical XOR operation is performed with the second individual part and the first noise A. This generates the compressed second individual part 14 of the ciphertext. In other words,

[0285]

[0286] = Compressors, dv) © A. The term Compressq(v1, dv) describes the bit dropping performed on the second individual part v±. The term dVidescribes the degree of bit dropping that is performed on the second individual part

[0287]

[0288] of the ciphertext. The subscript q denotes that the bit dropping takes place over the polynomial ring modulo q. The symbol © denotes the logical XOR operation with the first noise A. The logical XOR operation functions in the manner described above. Also as above, the compressed second individual part after the logical XOR operation has been performed may be referred to as the amended compressed second individual part to distinguish it from the compressed second individual part before the logical XOR operation has been performed.The decrypted ciphertext ct' is then obtained using the compressed common part u, the compressed first individual part

[0289]

[0290] and the compressed second individual part that were obtained as part of step 10 of RDec. The decrypted ciphertext ct' comprises the compressed common part u, the compressed first individual part

[0291]

[0292] and the compressed second individual part vj. In other words, ct =

[0293]

[0294] (u, vf).

[0295] The decrypted shared secret is obtained as ss' = H(rpk, / / ', / ). Here, H is the first hash function. Hash functions are well known in the art and any suitable hash function can be used, rpk is the ephemeral public key, ' is the decrypted first randomness, and [ir' is the decrypted second randomness. In other words, the decrypted shared secret ss' is a hash of a concatenation of the ephemeral public key rpk, the decrypted first randomness / / ', and the decrypted second randomness,'.. Note that step 10 of RDec corresponds to step 5 of REnc and steps 7 to 14 of REnc.

[0296] Steps 11 to 13 of RDec of the third embodiment are the same as steps 11 to 13 of RDec of the second embodiment and a description of the steps is not repeated here.

[0297] Differences

[0298] The first embodiment and the second embodiment have several differences. One difference is that the first embodiment, in the second individual part ctxof the ciphertext, contains a noise term that is a product of a transpose of the first noise rrand the ephemeral public key br. By contrast, the second embodiment contains a noise term, in the second individual part of the ciphertext, that is the first noise A. In general the second individual part may be expressed as 14 = rT■ br+ zr+ Encode(μr) + G( / / r, aux) for some suitable function G. The noise term of the second embodiment provides greater flexibility to the structure of the second individual part whilst maintaining the same security as the first embodiment.

[0299] A difference between the third embodiment and the second embodiment is that the first noise A is a random bit string sampled from a uniform distribution rather than a member of the polynomial ring. As a consequence, the first noise is used to mask the second individual part after compression of the first individual part. The first noise A is therefore less computationally intensive to generate in the third embodiment.Security

[0300] The embodiment described can be described in terms of two security effects. The embodiment has IND-CCA security with respect to the long-term public key pk. CCA security is a known term in the art. A system is said to be CCA-secure when it is secure against an attack where an adversary can decrypt ciphertexts of the adversary’s choosing to obtain the associated plaintext. The highest level of CCA security, IND-CCA security, is when the adversary can attempt some number of decryptions with its chosen ciphertexts, then change its choice of ciphertexts based on the obtained plaintexts to attempt to get closer to the “true” ciphertext. In the context of the embodiment, this means the embodiment is secure against an attack where an adversary obtains a challenge ciphertext on the long-term public key pk and a possibly incorrectly-generated ephemeral public key rpk, whilst having access to a decryption oracle. In other words, this means that even if an incorrectly-generated ephemeral public key rpk is used, the security of the long-term public key pk is not compromised.

[0301] The embodiment has half-IND-CCA security with respect to the ephemeral public key rpk. This level of security means that even if the long-term secret key sk leaks, there is still IND-CCA security as long as the ephemeral public key rpk and the ephemeral secret key rsk are secure. The level of security is referred to as “half’ in reference to the challenge ciphertext being generated with respect to the correctly-generated long-term public key pk and ephemeral public key rpk, instead of the incorrectly-generated long-term public key pk. Building the system with half-IND-CCA security with respect to the ephemeral public key rpk instead of full IND-CCA security with respect to the ephemeral public key rpk enables construction of a more efficient KEM.

[0302] The steps of the embodiment performed in RDec could be described as a “cascaded” Fujisaki-Okamoto (FO) transform. The FO transform is well-known in the art and further details are not described here. The transform is described as “cascaded” since the long-term secret key sk allows the first device to first decrypt the first randomness M. The first randomness M is then used to decrypt the second randomness Mrusing the ephemeral secret key. Once both the first randomness M and the second randomness Mrare generated, a re-encapsulation check is performed to verify that there-encapsulated ciphertext ct matches the ciphertext ct obtained from the second device. Decrypting the first randomness M and the second randomness Mrin stages provides IND-CCA security while reducing the size of the ciphertext ct that is used in exchanging the shared secret key.

[0303] Implementation

[0304] Figure 11 is a schematic diagram of components of an example information processing apparatus suitable for use in the methods described above. For example, the devices / user devices described above may be implemented as information processing apparatus. The diagram is illustrative and different hardware configurations for information processing apparatus are possible as is well known in the art. The information processing apparatus includes an VO interface 111, such a USB port, Thunderbolt port, etc. to which an additional device, such as a storage device, could be connected. The information processing apparatus comprises a processor 112 such as a CPU, NPU, GPU or other hardware accelerator, a storage in the form of memory 113 such as a solid-state drive, a network module 114, a display 115, and a user interface 116. The network module may allow the information processing apparatus to communicate over a network such as a Wi-Fi network, a mobile telecommunications network, a local area network etc. The user interface may include components such as a keyboard, mouse, camera, etc. The components of the information processing apparatus may communicate with each other over a bus 117. Further components may be provided but are not shown or described. Any of the steps of the methods described above may be performed by computer-readable instructions of one or more programs stored in a storage and executed by a processor on one or more information processing apparatuses. The computer-readable instructions may be stored on a non-transitory computer-readable storage medium.

[0305] The embodiments described above improve bandwidth for initiator-authenticated key exchange. As described in the second embodiment, standard techniques such as bit dropping can be used for further efficiency improvements. The above embodiments may be suitable for use with communication protocols such as Post-Quantum WireGuard (PQ WireGuard), which is a post-quantum variant of the WireGuard VPN protocol.Messages used in the PQ-WireGuard communication protocol may fit in a 1200 byte UDP packet. By implementing a key exchange as described above, the ciphertext sizes may be reduced. The embodiments described above may allow PQ WireGuard to use a lattice-based key exchange within the packet size constraints, and thus enable lattice-based post-quantum encryption.

[0306] While the key exchange described above is of general application, further embodiments may implement the Key Encapsulation Mechanism Transport Layer Security with Pre-Distributed Keys protocol (KEMTLS-PDK).

[0307] The above embodiments are to be understood as illustrative examples of the invention. Further embodiments of the invention are envisaged. It is to be understood that any feature described in relation to any one embodiment may be used alone, or in combination with other features described, and may also be used in combination with one or more features of any other of the embodiments, or any combination of any other of the embodiments. Furthermore, equivalents and modifications not described above may also be employed without departing from the scope of the invention, which is defined in the accompanying claims.

Claims

CLAIMS1. A method of exchanging a key between a first device and a second device, the method comprising, at the first device:a) generating an ephemeral key pair comprising an ephemeral public key and an ephemeral secret key, and sending the ephemeral public key to the second device;b) receiving a ciphertext, wherein the ciphertext comprises a first individual part that encodes a first randomness, a second individual part that encodes a second randomness, and a common part that can be used to decrypt the first individual part and the second individual part, wherein the parameters for generating the first part, the second part, and common part are generated using the ephemeral public key; c) obtaining the first randomness using the first individual part, the common part and a long-term secret key;d) obtaining the second randomness using the second individual part, the common part and the ephemeral secret key; and e) obtaining a shared secret key using the first randomness and the second randomness.

2. The method of claim 1, wherein obtaining the shared secret key using the first randomness and the second randomness comprises:i) encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key; ii) checking that the encapsulation of step i) is consistent with the received ciphertext; andiii) if the check of step ii) passes, deriving the shared secret key using the first randomness and the second randomness.

3. The method of claim 2, wherein the shared secret key is derived from the first randomness, the second randomness, the long-term public key and the ephemeral public key.

4. The method of either claim 2 or claim 3, wherein encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key comprises:deriving a second noise, a third noise, a fourth noise and a fifth noise from the first randomness, the second randomness, the long-term public key and the ephemeral public key;generating the common part of the ciphertext, wherein the common part is formed based on ct = rT• A + zT, wherein ct is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose;generating the first individual part of the ciphertext, wherein the first individual part is formed based on ct0= rT• b + z + Encode(M), wherein ct0is the first individual part, r is the second noise, b is a longterm public vector, z is the fourth noise, Encode(M) is an encoding of the first randomness and T denotes a transpose; andgenerating the second individual part of the ciphertext, wherein the second individual part is formed based on ctx= (r + rr)T• br+ zr+ Encode(Mr), wherein ctxis the second individual part, r is the second noise, rris the first noise, bris an ephemeral public key, zris the fifth noise, Encode(Mr) is an encoding of the second randomness and T denotes a transpose.

5. The method of any preceding claim, wherein generating an ephemeral key pair comprises:sampling the ephemeral secret key and an ephemeral first mask from a random distribution; andgenerating the ephemeral public key, wherein the ephemeral public key is formed based on rpk = A • sr+ xr, wherein rpk is the ephemeral public key, A is the public parameter, sris the ephemeral secret key and xris the ephemeral first mask.

6. The method of any preceding claim, wherein obtaining the second randomness comprises:deriving a first noise using the first randomness, a long-term public key and the ephemeral public key; andobtaining the second randomness using the second individual part, the common part, the ephemeral secret key and the first noise.

7. The method of either claim 2 or claim 3, wherein encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key comprises:deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key;generating the common part of the ciphertext, wherein the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose;generating the first individual part of the ciphertext, wherein the first individual part is formed based on v0= rT• b + z + Encode z), wherein v0is the first individual part, r is the second noise, b is a longterm public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; andgenerating the second individual part of the ciphertext, wherein the second individual part is formed based on= rT• (br+ 5r) + zr+ Encode(μr) + A, whereinis the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise, zris the fifth noise, Encode(μr) is an encoding of the second randomness, A is a first noise and T denotes a transpose.

8. The method of claim 7, wherein the sixth noise is zero.

9. The method of either claim 2 or claim 3, wherein encapsulating the first randomness and the second randomness using the long-term public key and the ephemeral public key comprises:deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key;generating an intermediate common part of the ciphertext, wherein the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose;generating an intermediate first individual part of the ciphertext, wherein the first individual part is formed based on v0= rT• b + z + Encode(μ), wherein v0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; generating an intermediate second individual part of the ciphertext, wherein the second individual part is formed based on= rT• (br+ 5r) + zr+ Encode(μr), whereinis the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise, zris the fifth noise, Encode(μr) is an encoding of the second randomness and T denotes a transpose;compressing the intermediate first individual part, the intermediate second individual part and the intermediate common part to generate a first individual part, a second individual part and a common part; and amending the second individual part with a first noise.

10. The method of claim 9, wherein amending the second individual part comprises computing v1 / amended= v̄1⊕ Δ, wherein v1 / amendedis the amended second individual part, vj is the second individual part, A is the first noise and © represents a logical XOR operation.

11. The method of any of claims 7 to 10, wherein generating an ephemeral key pair comprises:sampling the ephemeral secret key and an ephemeral first mask from a random distribution; andgenerating the ephemeral public key, wherein the ephemeral public key is formed at least in part based on br= A • sr+ xr, wherein bris the ephemeral public key, A is the public parameter, sris an ephemeral secret and xris an ephemeral first mask.

12. The method of any of claims 7 to 11, wherein obtaining the second randomness comprises:deriving a first noise using the first randomness; andobtaining the second randomness using the second individual part, the common part, the ephemeral secret key and the first noise.

13. The method of claim 12 when dependent on claim 10, wherein obtaining the second randomness comprises:de-masking the amended individual part based on v̄1= v1 / amended⊕ Δ, wherein vj is the second individual part, v1 / amendedis the amended individual part, A is the first noise and © represents a logical XOR operation;decompressing the second individual part to obtain the intermediate second individual part; andobtaining the second randomness using the intermediate second individual part, the common part, the ephemeral secret key and the first noise.

14. A method of exchanging a key between a first device and a second device, the method comprising, at the second device:receiving an ephemeral public key;generating a shared secret key and a ciphertext, wherein the ciphertext comprises a first individual part that encodes a first randomness, a second individual part that encodes a second randomness, and a common part that can be used to decrypt the first individual part and the second individual part, wherein the parameters for generating the first part, the second part and the common part are generated using the ephemeral public key; andtransmitting the ciphertext.

15. The method of claim 14, wherein generating the shared secret key and the ciphertext comprises:generating the first randomness and the second randomness; deriving a first noise from the first randomness, a long-term public key of the first device and the ephemeral public key;deriving a second noise, a third noise, a fourth noise and a fifth noise from the first randomness, the second randomness, the long-term public key and the ephemeral public key;deriving the shared secret key from the first randomness, the second randomness, the long-term public key of the first device and the ephemeral public key;generating the common part of the ciphertext, wherein the common part is formed based on ct = rT• A + zT, wherein ct is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose;generating the first individual part of the ciphertext, wherein the first individual part is formed based on ct0= rT• b + z + Encode(M), wherein ct0is the first individual part, r is the second noise, b is a longterm public vector, z is the fourth noise, Encode(M) is an encoding of the first randomness and T denotes a transpose; andgenerating the second individual part of the ciphertext, wherein the second individual part is formed based on ctx= (r + rr)T• br+ zr+Encode(Mr), wherein ctxis the second individual part, r is the second noise, rris the first noise, bris an ephemeral public key, zris the fifth noise, Encode(Mr) is an encoding of the second randomness and T denotes a transpose.

16. The method of claim 14, wherein generating the shared secret key and the ciphertext comprises:generating the first randomness and the second randomness; deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key;deriving a first noise from the first randomness;generating the common part of the ciphertext, wherein the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose;generating the first individual part of the ciphertext, wherein the first individual part is formed based on v0= rT• b + z + Encode z), wherein v0is the first individual part, r is the second noise, b is a longterm public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose;generating the second individual part of the ciphertext, wherein the second individual part is formed based on= rT• (br+ 5r) + zr+ Encode(μr) + A, whereinis the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise zris the fifth noise, Encode(μr) is an encoding of the second randomness, A is the first noise and T denotes a transpose; andderiving the shared secret key from the first randomness, the second randomness and the ephemeral public key.

17. The method of claim 16, wherein the sixth noise is zero.

18. The method of claim 14, wherein generating the shared secret key and the ciphertext comprises:generating the first randomness and the second randomness; deriving a second noise, a third noise, a fourth noise, a fifth noise and a sixth noise from the first randomness, the second randomness and the ephemeral public key;deriving a first noise from the first randomness;generating an intermediate common part of the ciphertext, where the common part is formed based on u = rT• A + zT, wherein u is the common part, r is the second noise, A is a public parameter, z is the third noise and T denotes a transpose;generating an intermediate first individual part of the ciphertext, wherein the intermediate first individual part is formed based on v0= rT• b + z + Encode(μ), wherein v0is the first individual part, r is the second noise, b is a long-term public vector, z is the fourth noise, Encode z) is an encoding of the first randomness and T denotes a transpose; generating an intermediate second individual part of the ciphertext, wherein the intermediate second individual part is formed based on= rT• (br+ 5r) + zr+ Encode(μr), whereinis the second individual part, r is the second noise, bris an ephemeral public key, Sris the sixth noise zris the fifth noise, Encode(μr) is an encoding of the second randomness, and T denotes a transpose;compressing the intermediate first individual part, the intermediate second individual part and the intermediate common part to generate the first individual part, the second individual part and the common part; amending the second individual part with a first noise; and deriving the shared secret key from the first randomness, the second randomness and the ephemeral public key.

19. A method for exchanging a key, the method comprising:performing the method of any of claims 1 to 6 at a first device; andperforming the method of either of claim 14 or claim 15 at a second device.

20. A method for exchanging a key between a first device and a second device, the method comprising:performing, at the first device, the method of any of claims 1, 2, 3, 7 or 8, or claim 11 when dependent on either of claims 7 or 8, or claim 12 when dependent on either of claims 7 or 8; andperforming, at the second device, the method of any of claims 14, 16 or 17.

21. A method for exchanging a key between a first device and a second device, the method comprising:performing, at the first device, the method of any of claims 1, 2, 3, 9, 10 or 13, or claim 11 when dependent on any of claims 7, 9 or 10, or claim 12 when dependent on any of claims 7, 9 or 10; andperforming, at the second device, the method of either claim 14 or claim 18.

22. A device configured to perform the method of any of claims 1 to 18.

23. A system for exchanging a key, the system comprising a first device and a second device, wherein the system is configured to perform the method of any of claims 19 to 21.

24. A computer program comprising instructions which, when the program is executed by an information processing apparatus, cause the information processing apparatus to perform the method of any of claims 1 to 18.

25. A non-transitory computer-readable storage medium carrying the computer program of claim 24.