NIKE ⇒ KE

Fully-black-box reduction · standard model · folklore · security loss: tight: the NIKE challenge is forwarded unchanged

Statement

If is a NIKE, the one-round protocol in which and sample , send their public keys, and output is a key exchange secure against eavesdroppers — folklore.

Sketch

The transcript is , so a distinguisher between and for is verbatim a NIKE distinguisher for one honest pair.

Notes

  • Instantiated with the Diffie–Hellman NIKE (DDH ⇒ NIKE), the protocol is the Diffie–Hellman key exchange of DH76.