Efficient key encapsulation mechanisms with tight security reductions to standard assumptions in the two security models

Efficient key encapsulation mechanisms with tight security reductions to standard assumptions in the two security models
复制标题

DOI:
10.1002/sec.1444
复制
发表时间:
2016-08
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Yoshikazu Hanatani;Goichiro Hanaoka;Takahiro Matsuda;Takashi Yamakawa
Yoshikazu Hanatani;Goichiro Hanaoka;Takahiro Matsuda;Takashi Yamakawa
中科院分区:
其他
文献类型:
--
作者:
Yoshikazu Hanatani;Goichiro Hanaoka;Takahiro Matsuda;Takashi Yamakawa

文献摘要

相似文献

本文提出了两种新的选择密文攻击安全CCA安全密钥封装机制KEM的实用构造,KEM是混合加密中公钥加密的主要构建块,具有显著的安全特性:我们的KEM可以被证明不仅满足CCA安全性或Hofheinz和Kiltz在标准模型中引入的约束CCA安全性,而且安全性严格降低到基本的不可否认性类型的假设,但也是CCA安全的随机预言模型与一个严格的安全性减少到一个基本的计算类型的假设。我们的第一个构造是基于Diffie-Hellman型假设,与Shoup在EUROPENTPT '00上提出的在两种安全模型下都有安全约简但在随机模型下安全证明是松散约简的KEM相比,我们提出的KEM在相同的计算代价下具有更小的密文大小,更重要的是,我们的KEM在随机预言模型下也有紧密的安全约简。我们的第二个构造是基于与整数因子分解相关的假设,与Hofheinz和Kiltz在1999年发表的KEM相比,我们提出的KEM在密文大小和计算成本方面都具有相似的效率,并且安全性基于不可比拟的假设。版权所有© 2016约翰威利父子有限公司.
In this paper, we propose two new practical constructions of chosen ciphertext attack secure CCA secure key encapsulation mechanisms KEM, which is the main building block for public key encryption in hybrid encryption, with remarkable security features: Our KEMs can be proved not only to satisfy CCA security or constrained CCA security introduced by Hofheinz and Kiltz at CRYPTO'07 in the standard model with a tight security reduction to a basic indistinguishability-type assumption but also to be CCA secure in the random oracle model with a tight security reduction to a basic computational-type assumption. Our first construction is based on the Diffie-Hellman-type assumptions, and compared with the KEM by Shoup at EUROCRYPT'00 that has security reductions in two security models but its security proof in the random model is a loose reduction, our proposed KEM has a smaller ciphertext size with the same computational costs, and more importantly, ours has a tight security reduction also in the random oracle model. Our second construction is based on assumptions related to integer factoring, and compared with the KEM by Hofheinz and Kiltz at CRYPTO'99 that also has tight security reductions in two security models to factoring-related assumptions, our proposed KEM has similar efficiency both ciphertext size and computational costs and bases the security on incomparable assumptions. Copyright © 2016 John Wiley & Sons, Ltd.