The security of PSEC-KEM versus ECIES-KEM
D. Galindo Chacon, Sebastià Martı́n, Jorge Luis Villar · 2005
The KEM-DEM methodology for designing hybrid encryption is being used in several projects aimed at evaluating or eventually standardizing cryptographic primitives. In this work we revisit one of the elliptic curve based KEMs studied to become standards, namely PSEC-KEM. Its security is based on different assumptions related to the elliptic curve discrete logarithm problem. First of all, we point out that PSEC-KEM has a non-tight security reduction to the Computational Diffie-Hellman (ECDH) problem. This obvious fact has been surprisingly ignored in the literature, or even contradicted. This remark has a direct consequence: the security of PSECKEM with the current 160 key bits length for elliptic curve cryptography is not guaranteed using only the reduction to ECDH. Fortunately, we show that previous security proofs for PSEC-KEM can be straightforward modified to obtain a tight reduction to the so-called Gap-ECDH problem. This seems to be the first time that such a reduction has been released into the public domain. Finally, we raise some doubts on the widespread opinion that ECIES-KEM offers less security guarantees than PSEC-KEM.