Abstract

We propose a new efficient RKA-secure KEM scheme based on the DBDH assumption. Our scheme is secure against the function class that contains polynomial functions of (bounded) polynomial degrees and the XOR functions simultaneously.