On Chosen Ciphertext Security of Multiple Encryptions

On Chosen Ciphertext Security of Multiple Encryptions
复制标题

论多重加密的选择密文安全性

DOI:
--
复制
发表时间:
2002
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
M. Naor
M. Naor
中科院分区:
--
文献类型:
--
作者:
Oded Goldreich;Yoad Lustig;M. Naor

文献摘要

被引文献

相似文献

我们考虑的安全性的多个和可能相关的明文的上下文中选择的密文攻击。也就是说,攻击者除了在同一密钥下获得多个明文的副本之外,还可以同时发出加解密查询和部分信息查询。不严格地说,如果攻击者可以从这种攻击中了解到的关于所选明文的所有信息都可以从相应的部分信息查询中获得,则加密方案在这种攻击下被认为是安全的。上述定义扩展了本文提出的在选择密文攻击下的语义安全性定义。扩展是考虑多个明文的安全性,而不是单个明文的安全性。我们证明了这两个公式是等价的CCA的标准公式,这是指不可逆的预防。好消息是,任何在标准CCA意义上安全的加密方案实际上在扩展模型中也是安全的。该处理对公钥和私钥加密方案都适用。
We consider the security of multiple and possibly related plaintexts in the context of a chosen ciphertext attack. That is the attacker in addition and concurrently to obtaining encryptions of multiple plaintexts under the same key, may issue encryption and decryption queries and partial information queries. Loosely speaking, an encryption scheme is considered secure under such attacks if all that the adversary can learn from such attacks about the selected plaintexts can be obtained from the corresponding partial information queries. The above deenition extends the deenition of semantic security under chosen ciphertext attacks (CCAs) which is also formulated in this work. The extension is in considering the security of multiple plaintexts rather than the security of a single plaintext. We prove that both these formulations are equivalent to the standard formulation of CCA, which refers to indistinguishability of encryptions. The good news is that any encryption scheme that is secure in the standard CCA sense is in fact secure in the extended model. The treatment holds both for public-key and private-key encryption schemes.