SO-CCA Secure PKE in the Quantum Random Oracle Model or the Quantum Ideal Cipher Model

SO-CCA Secure PKE in the Quantum Random Oracle Model or the Quantum Ideal Cipher Model
复制标题

DOI:
10.1007/978-3-030-35199-1_16
复制
发表时间:
2019-12
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Shingo Sato;Junji Shikata
Shingo Sato;Junji Shikata
中科院分区:
其他
文献类型:
--
作者:
Shingo Sato;Junji Shikata

文献摘要

相似文献

选择性打开安全性是多用户环境下公钥加密(PKE)最重要的安全性之一。即使在一些密文中使用的消息和随机币被泄露,SO安全性也保证了其他密文的机密性。实际上,有一些PKE方案满足标准的安全性,如针对所选密文攻击的不可区分性(IND-CCA安全性),但不满足针对所选密文攻击的SO安全性。因此,在多用户设置中考虑SO安全性非常重要。另一方面,许多研究人员已经研究了安全模型中的密码系统,其中攻击者可以向oracle提交量子叠加查询(即量子查询)。特别是量子随机预言模型中的IND-CCA安全PKE和KEM方案,目前已经得到了深入的研究。在本文中,我们证明了两种混合加密方案的结构在量子随机预言模型或量子理想密码模型中满足基于仿真的针对选择密文攻击的SO安全性(SIM-SO-CCA安全性)。第一种方案由任何IND-CCA安全KEM和任何可模拟数据封装机制(DEM)构建。第二种是基于Fujisaki-Okamoto变换的任意IND-CCA安全KEM和任意强不可遗忘消息认证码(MAC)构造的。如果底层DEM方案满足可模拟性,我们可以将任何IND-CCA安全KEM方案应用于第一个方案,而如果底层KEM基于藤崎-冈本变换,我们可以将任何满足完整性的DEM方案应用于第二个方案。
Selective opening (SO) security is one of the most important securities of public key encryption (PKE) in a multi-user setting. Even though messages and random coins used in some ciphertexts are leaked, SO security guarantees the confidentiality of the other ciphertexts. Actually, it is shown that there exist PKE schemes which meet the standard security such as indistinguishability against chosen ciphertext attacks (IND-CCA security) but do not meet SO security against chosen ciphertext attacks. Hence, it is important to consider SO security in the multi-user setting. On the other hand, many researchers have studied cryptosystems in the security model where adversaries can submit quantum superposition queries (i.e., quantum queries) to oracles. In particular, IND-CCA secure PKE and KEM schemes in the quantum random oracle model have been intensively studied so far.In this paper, we show that two kinds of constructions of hybrid encryption schemes meet simulation-based SO security against chosen ciphertext attacks (SIM-SO-CCA security) in the quantum random oracle model or the quantum ideal cipher model. The first scheme is constructed from any IND-CCA secure KEM and any simulatable data encapsulation mechanism (DEM). The second one is constructed from any IND-CCA secure KEM based on Fujisaki-Okamoto transformation and any strongly unforgetable message authentication code (MAC). We can apply any IND-CCA secure KEM scheme to the first one if the underlying DEM scheme meets simulatability, whereas we can apply any DEM scheme meeting integrity to the second one if the underlying KEM is based on Fujisaki-Okamoto transformation.