Key encapsulation mechanism

A key encapsulation mechanism (KEM) is a public-key primitive that allows a sender to encapsulate a fresh uniformly random symmetric key into a ciphertext using a public key , such that only the holder of the secret key can recover by decapsulation. Combined with a symmetric-key data encapsulation mechanism (DEM, i.e., SKE), KEMs give the KEM-DEM paradigm for hybrid encryption — the standard approach to asymmetric encryption in practice.

Syntax

A KEM is a tuple of efficient algorithms with key space :

  • is a randomized algorithm that generates a public/secret key pair.
  • is a randomized algorithm that takes a public key and outputs a ciphertext and a symmetric key .
  • is a deterministic algorithm that recovers the symmetric key from the ciphertext.

Properties

Correctness

For all and :

IND-CCA security

\begin{algorithm}
\algname{Game}
\caption{$\Game^{\mathrm{cca}}_{\mathrm{KEM},\calA}(\secpar)$}
\begin{algorithmic}
\State $(\pk, \sk) \gets \KeyGen(1^\secpar)$
\State $(c^*, k_0) \gets \mathsf{Encap}(\pk)$
\State $k_1 \getsr \calK$
\State $b \getsr \bits$
\State $b' \gets \calA^{\mathsf{Decap}(\sk, \cdot)}(\pk, c^*, k_b)$
\Comment{$\calA$ may not query $\mathsf{Decap}$ on $c^*$}
\Return $[b' = b]$
\end{algorithmic}
\end{algorithm}

A KEM is IND-CCA secure if for all efficient ,

is negligible. The adversary cannot query the decapsulation oracle on the challenge ciphertext , since that would trivially reveal .

KEM-DEM hybrid encryption

Given an IND-CCA KEM and an IND-CPA SKE (DEM), the following construction achieves IND-CCA PKE:

  • : run ; run ; output .
  • : run ; output .

This achieves IND-CCA security as long as the KEM is IND-CCA secure and the DEM is IND-CPA secure (or even OT-secure for a one-time pad).

Variations

IND-CPA KEM

A weaker KEM where the adversary has no decapsulation oracle. Sufficient for passive adversaries.

Lattice-based KEM (Kyber / ML-KEM)

Kyber is an IND-CCA KEM based on Module LWE (rank-3 module over a polynomial ring). Standardized by NIST as ML-KEM (FIPS 203). Uses the Fujisaki-Okamoto transform to achieve IND-CCA security from an IND-CPA base scheme.

RSA-KEM / RSAES-OAEP

RSA-based KEM using OAEP padding. IND-CCA secure in the random oracle model.

Other results

Participates in

Builds on Key encapsulation mechanism

Produces Key encapsulation mechanism