Given its integral role in modern encryption systems such as CRYSTALS-Kyber, the Fujisaki-Okamoto (FO) transform will soon be at the center of our secure communications infrastructure. An enduring debate surrounding the FO transform is whether to use explicit or implicit rejection when decapsulation fails. Presently, implicit rejection, as implemented in CRYSTALS-Kyber, is supported by a strong set of arguments. Therefore, understanding its security implications in different attacker models is essential.
In this work, we study implicit rejection through a novel lens, namely, from the perspective of kleptography. Concretely, we consider an attacker model in which the attacker can subvert the user’s code to compromise security while remaining undetectable. In this scenario, we present three attacks that significantly reduce the security level of the FO transform with implicit rejection. Notably, our attacks apply to CRYSTALS-Kyber.
History
Primary Research Area
Algorithmic Foundations and Cryptography
CISPA Affiliation
Yes
Volume
15677
Book Title
Public-Key Cryptography – PKC 2025
Page Range
214-245
Series
Lecture Notes in Computer Science
Publisher
Springer Nature
Open Access Type
Not Open Access
BibTeX
@inbook{Joux:Loss:Wagner:2025,
title = "Kleptographic Attacks Against Implicit Rejection",
author = "Joux, Antoine" AND "Loss, Julian" AND "Wagner, Benedikt",
year = 2025,
month = 1,
booktitle = "Public-Key Cryptography – PKC 2025",
series = "Lecture Notes in Computer Science",
pages = "214--245",
publisher = "Springer Nature",
doi = "10.1007/978-3-031-91829-2_7"
}