International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Tempo:

An ML-KEM to PAKE Compiler Resilient to Timing Attacks


Afonso Arriaga
SnT - University of Luxembourg

Manuel Barbosa
University of Porto (FCUP), INESC-TEC and Max Planck Institute for Security and Privacy

Stanislaw Jarecki
University of California at Irvine


Keywords: Password Authenticated Key Exchange (PAKE), Timing Attacks, ML-KEM, Constant-Time, Rejection Sampling, Universal Composability, Post-Quantum


Abstract

KEM-to-PAKE compilers have been recently proposed to leverage postquantum KEM standardization efforts. These typically follow the Encrypted Key Exchange (EKE) paradigm, where the KEM public key is encrypted under a password. While KEM implementations generally aim to execute all secret-dependent computations in constant time, such guarantees do not always extend to computations that depend only on the public key, as public keys are generally assumed to be public. A notable example is ML-KEM, where public keys include a short seed ρ from which a large matrix is expanded prior to algebraic computations. This expansion procedure relies on rejection sampling which is, typically, implemented as a variable-time algorithm. However, compilers that follow the EKE paradigm must treat the public key as secret, since knowledge of the public key hidden in a ciphertext enables an offline dictionary attack on the password; therefore, instantiating these compilers with off-the-shelf implementations of ML-KEM or encrypting the public key under a password using variable-time methods (e.g., cycle walking or rejection sampling, as proposed in related PAKE literature) can be problematic.In this paper we show two approaches which yield ML-KEM-based PAKEs resilient to timing attacks. First, we explore constant-time alternatives to ML-KEM rejection sampling, but as one might expect, such methods impose a performance penalty on ML-KEM. Our second approach introduces a new ML-KEM-to-PAKE compiler that mitigates this issue by design: our proposal transmits the seed ρ in the clear, decoupling password-dependent computations from the seed expansion step. This means that off-the-shelf implementations of ML-KEM can be used. Our new protocol Tempo builds on an idea from CHIC (Asiacrypt’24), which considered splitting the KEM public key, and extends the NoIC protocol and proof (ePrint:2025/231) to show protocol simulation in the UC framework, assuming ML-KEM security under adversarially chosen seeds. We justify this assumption via a new hardness assumption, which we call Oracle-MLWE, and show that it is asymptotically equivalent to the MLWE problem in the Random Oracle Model.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a48

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (476783 Bytes)  

View on Github

License
This work is licensed under the Apache License, Version 2.0.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Afonso Arriaga, Manuel Barbosa, Stanislaw Jarecki. (2026). Tempo: An ML-KEM to PAKE Compiler Resilient to Timing Attacks. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 744–768. https://doi.org/10.46586/tches.v2026.i3.744-768. Artifact at https://artifacts.iacr.org/tches/2026/a48.