Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Journal articles
  4. FrodoKEM: A CCA-Secure Learning With Errors Key Encapsulation Mechanism
 
research article

FrodoKEM: A CCA-Secure Learning With Errors Key Encapsulation Mechanism

Glabush, Lewis  
•
Longa, Patrick
•
Naehrig, Michael
Show more
October 6, 2025
IACR Communications in Cryptology

Large-scale quantum computers capable of implementing Shor's algorithm pose a significant threat to the security of the most widely used public-key cryptographic schemes. This risk has motivated substantial efforts by standards bodies and government agencies to identify and standardize quantum-safe cryptographic systems. Among the proposed solutions, lattice-based cryptography has emerged as the foundation for some of the most promising protocols. This paper describes FrodoKEM, a family of conservative key-encapsulation mechanisms (KEMs) whose security is based on generic, “unstructured” lattices. FrodoKEM is proposed as an alternative to the more efficient lattice schemes that utilize algebraically structured lattices, such as the recently standardized ML-KEM scheme. By relying on generic lattices, FrodoKEM minimizes the potential for future attacks that exploit algebraic structures while enabling simple and compact implementations. Our plain C implementations demonstrate that, despite its conservative design and parameterization, FrodoKEM remains practical. For instance, the full protocol at NIST security level 1 runs in approximately 0.97 ms on a server-class processor, and 4.98 ms on a smartphone-class processor. FrodoKEM obtains (single-target) IND-CCA security using a variant of the Fujisaki-Okamoto transform, applied to an underlying public-key encryption scheme called FrodoPKE. In addition, using a new tool called the Salted Fujisaki-Okamoto (SFO) transform, FrodoKEM is also shown to tightly achieve multi-target security, without increasing the FrodoPKE message length and with a negligible performance impact, based on the multi-target IND-CPA security of FrodoPKE.

  • Details
  • Metrics
Type
research article
DOI
10.62056/ayivom2hd
Author(s)
Glabush, Lewis  

École Polytechnique Fédérale de Lausanne

Longa, Patrick
Naehrig, Michael
Peikert, Chris
Stebila, Douglas
Virdia, Fernando
Date Issued

2025-10-06

Publisher

International Association for Cryptologic Research

Published in
IACR Communications in Cryptology
Volume

2

Issue

3

Article Number

cc2-3-46

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LASEC  
FunderFunding(s)Grant NumberGrant URL

Natural Sciences and Engineering Research Council of Canada

RGPIN-2022-03187

Natural Sciences and Engineering Research Council of Canada

ALLRP 578463-22

Available on Infoscience
October 8, 2025
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/254768
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés