Paper 2026/1449

`ANSA-IBKEM`: Practical Quantum-Safe Identity-Based Key Encapsulation via Annular NTRU Trapdoors and Standardized PQC Arithmetic Reuse

Zhaohui Cheng, Shenzhen Olym Info. Sec. Ltd
Kaixin Xiong, Shenzhen Olym Info. Sec. Ltd
Abstract

Identity-based key encapsulation remains attractive for managed systems, but practical post-quantum instantiations must balance compact ciphertexts, low decryption-failure rate (DFR), high-throughput and protection-friendly private-key extraction, and meaningful concrete security reductions. Existing NTRU-based IBE schemes satisfy these requirements only partially: compact DLP-style constructions lack a satisfactory reduction and have high failure rates, while LATTE's higher-rank structure and correctness treatment come with larger private keys, larger ciphertexts, and additional encapsulation/decapsulation work. These lines also use moduli and transform roots distinct from those of standardized PQC schemes, complicating deployment in implementations already built around standardized arithmetic. We introduce `ANSA-IBKEM`, a practical single-level identity-based KEM that retains the compact DLP-style identity relation while redesigning the trapdoor, extraction, correctness, and implementation layers around standardized post-quantum arithmetic. The construction combines annular NTRU trapdoors, Hybrid-Sampling extraction, a BCH-based message layer, and ciphertext compression over the ML-DSA modulus $q=8380417$. At the selected compressed points $(d_u,d_v)=(21,4)$ and $(23,5)$, the resulting ciphertext sizes are $3200\,\mathrm{B}$ and $7168\,\mathrm{B}$, with BCH-tail DFR estimates below $2^{-164}$ and $2^{-248}$ after applying one-sided $95\%$ upper bounds to the measured nonzero-error rates. We present a layered random-oracle-model security reduction for `ANSA-IBKEM` with an explicit concrete advantage bound and separate accounting for birthday-style collision terms. The proof accounts for the transform layer with explicit HHK-style losses in the identity-based setting, passes from exact extraction to ideal conditional extraction using Rényi divergence, and reduces to a programmed single-user encryption experiment connected to annular-NTRU/RLWE-style assumptions. This route separates transform losses, extraction-distribution losses, correctness terms, message-space terms, collision terms, and lattice-assumption terms, and it gives a proof template for DLP-style lattice IBKEMs. We also give a method for deep arithmetic reuse, with full low-level ML-DSA arithmetic reuse on the $N=1024$ line.

Note: Better performance results and revised Appendix E.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
identity-based key encapsulationlattice cryptographyNTRU trapdoorspost-quantum cryptographyarithmetic reuse
Contact author(s)
mzhcheng @ gmail com
xiongkx @ myibc net
History
2026-08-03: revised
2026-07-16: received
See all versions
Short URL
https://ia.cr/2026/1449
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1449,
      author = {Zhaohui Cheng and Kaixin Xiong},
      title = {`{ANSA}-{IBKEM}`: Practical Quantum-Safe Identity-Based Key Encapsulation via Annular {NTRU} Trapdoors and Standardized {PQC} Arithmetic Reuse},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1449},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1449}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.