Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Presentation

A lean BIKE KEM design for ephemeral key agreement

April 12, 2024

Presenters

Shay Gueron - University of Haifa and Meta

Description

The QC-MDPC code-based KEM BIKE is an alternative candidate for standardization for the NIST Post-Quantum Cryptography Standardization Project. Per NIST’s report “The BIKE cryptosystem was initially designed for ephemeral key use but has now been claimed to also support static key use”. BIKE uses the BGF decoder of where its Decoding Failure Rate (DFR) is estimated by means of an extrapolation method. While this methodology provides a solid indication for a very small DFR, which is required for an IND-CCA claim, it may still be considered short of a proven upper bound, as stated in, “... and an upper bound on the decoding failure rate has yet to be found”. Nevertheless, the IND-CPA security of BIKE is established without a small DFR requirement on the decoder, and this property suffices for protocols that use ephemeral keys. This is the case for protocols that maintain the modern notion of forward secrecy (hence avoid static keys), where a prominent example is TLS 1.3.

This paper examines the communication bandwidth and the performance of a BIKE design that targets only the ephemeral key use cases, i.e., settles with IND-CPA security. We call this design “Lean-BIKE”. This study illustrates the incremental cost of the IND-CCA property. We argue that it would be useful to standardize two configurations of BIKE: a) “Lean-BIKE” that enjoys the reduced cost of an IND-CPA KEM, for the major class of forward secrecy supporting usages; b) BIKE whose IND-CCA security could be established by either a finer proof methodology for the BGF decoder or with another decoder that has a proven DFR upper bound.

Presented at

5th PQC Standardization Conference (2024) [in-person]

Event Details

Location

    The NIST PQC conference will be held at the:
    Hilton Washington DC/Rockville Hotel
    1750 Rockville Pike
    Rockville, MD 20852

Related Topics

Security and Privacy: post-quantum cryptography

Created April 11, 2024, Updated April 15, 2024