International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 25 May 2023

Manuel Barbosa, Andreas Hülsing
ePrint Report ePrint Report
In this short note we give another direct proof for the variant of the FO transform used by Kyber in the QROM. At PKC'23 Maram & Xagawa gave the first direct proof which does not require the indirection via FO with explicit rejection, thereby avoiding either a non-tight bound, or the necessity to analyze the failure probability in a new setting. However, on the downside their proof produces a bound that incurs an additive collision bound term. We explore a different approach for a direct proof, which results in a simpler argument closer to prior proofs, but a slightly worse bound.
Expand

Additional news items may be found on the IACR news page.