Encryption Switching Protocols
Encryption Switching Protocols
复制标题
加密交换协议
DOI:
10.1007/978-3-662-53018-4_12
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
["Geoffroy Couteau
中科院分区:
文献类型:
--
作者:
["Geoffroy Couteau
We formally define the primitive ofencryption switching protocol(ESP), allowing to switch between two encryption schemes. Intuitively, this two-party protocol converts given ciphertexts from one scheme into ciphertexts of the same messages under the other scheme, for any polynomial number ofswitches, in any direction. AlthoughESPis a special kind of two-party computation protocol, it turns out thatESPimplies general two-party computation (2-PC) under natural conditions. In particular, our new paradigm is tailored to the evaluation of functions over rings. Indeed, assuming the compatibility of two additively and multiplicatively homomorphic encryption schemes, switching ciphertexts makes it possible to efficiently reconcile the two internal laws. Since no such pair of public-key encryption schemes appeared in the literature, except for the non-interactive case of fully homomorphic encryption which still remains prohibitive in practice, we build the first multiplicatively homomorphic ElGamal-like encryption scheme overas a complement to the Paillier encryption scheme over, wherenis a strong RSA modulus. Eventually, we also instantiate secureESPs between the two schemes, in front of malicious adversaries. This enhancement relies on a new technique calledrefreshable twin ciphertext pool, which we show being of independent interest. We additionally prove this is enough to argue the security of our general2-PCprotocol against malicious adversaries.