Encryption Switching Protocols

Encryption Switching Protocols
复制标题

加密交换协议

DOI:
10.1007/978-3-662-53018-4_12
复制
发表时间:
2016
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
["Geoffroy Couteau
["Geoffroy Couteau
中科院分区:
--
文献类型:
--
作者:
["Geoffroy Couteau

文献摘要

被引文献

相似文献

我们形式化地定义了加密切换协议(ESP)的原语,允许在两种加密方案之间切换.直观地说,这个两方协议将给定的密文从一个方案转换成另一个方案下的相同消息的密文,对于任何多项式数量的开关,在任何方向上。虽然ESP是一种特殊的两方计算协议,但在自然条件下,ESP隐含着一般的两方计算(2-PC)。特别是,我们的新范式是专为环上的函数的评价。事实上,假设两个加法和乘法同态加密方案的兼容性,交换密文使得有可能有效地协调两个内部定律。由于文献中没有这样的公钥加密方案,除了全同态加密的非交互情况下,这在实践中仍然是禁止的,我们建立了第一个乘法同态ElGamal-like加密方案作为对Paillier加密方案的补充,其中是一个强RSA模。最后,我们还实例化两个方案之间的secureESP,在前面的恶意对手。这种增强依赖于一种新的技术,称为可刷新的孪生密文池,我们表明是独立的利益。我们还证明了这足以证明我们的一般2-PC协议对恶意对手的安全性。
We formally define the primitive ofencryption switching protocol(ESP), allowing to switch between two encryption schemes. Intuitively, this two-party protocol converts given ciphertexts from one scheme into ciphertexts of the same messages under the other scheme, for any polynomial number ofswitches, in any direction. AlthoughESPis a special kind of two-party computation protocol, it turns out thatESPimplies general two-party computation (2-PC) under natural conditions. In particular, our new paradigm is tailored to the evaluation of functions over rings. Indeed, assuming the compatibility of two additively and multiplicatively homomorphic encryption schemes, switching ciphertexts makes it possible to efficiently reconcile the two internal laws. Since no such pair of public-key encryption schemes appeared in the literature, except for the non-interactive case of fully homomorphic encryption which still remains prohibitive in practice, we build the first multiplicatively homomorphic ElGamal-like encryption scheme overas a complement to the Paillier encryption scheme over, wherenis a strong RSA modulus. Eventually, we also instantiate secureESPs between the two schemes, in front of malicious adversaries. This enhancement relies on a new technique calledrefreshable twin ciphertext pool, which we show being of independent interest. We additionally prove this is enough to argue the security of our general2-PCprotocol against malicious adversaries.