Receiver Selective Opening CCA Secure Public Key Encryption from Various Assumptions

Receiver Selective Opening CCA Secure Public Key Encryption from Various Assumptions
复制标题

DOI:
10.1007/978-3-030-62576-4_11
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Yi Lu;Keisuke Hara;Keisuke Tanaka
Yi Lu;Keisuke Hara;Keisuke Tanaka
中科院分区:
其他
文献类型:
--
作者:
Yi Lu;Keisuke Hara;Keisuke Tanaka

文献摘要

相似文献

用于公钥加密 (PKE) 的接收者选择性开放 (RSO) 攻击捕获这样一种情况:一个发送者向多个接收者发送消息,对手可以破坏一组接收者并获取他们的消息和密钥。 PKE 方案针对 RSO 攻击的安全性确保了其他未损坏接收者密文的机密性。在所有 RSO 安全概念中,针对选定密文攻击的基于模拟的 RSO 安全性(SIM-RSO-CCA 安全性)是最强的概念。在本文中,我们从各种计算假设中探索了 SIM-RSO-CCA 安全 PKE 的构造。为了实现这一目标,我们证明可以基于 IND-CPA 安全 PKE 方案和满足一次性模拟健全性的指定验证者非交互式零知识(DV-NIZK)参数构建 SIM-RSO-CCA 安全 PKE 方案。此外,我们还给出了满足一次性模拟可靠性的DV-NIZK论证的第一个构造。因此,通过我们的通用构造,我们在计算 Diffie-Hellman (CDH) 或学习噪声奇偶校验 (LPN) 假设下获得了第一个 SIM-RSO-CCA 安全 PKE 方案。
Receiver selective opening (RSO) attack for public key encryption (PKE) captures a situation where one sender sends messages to multiple receivers, an adversary can corrupt a set of receivers and get their messages and secret keys. Security against RSO attack for a PKE scheme ensures confidentiality of other uncorrupted receivers' ciphertexts. Among all of the RSO security notions, simulation-based RSO security against chosen ciphertext attack (SIM-RSO-CCA security) is the strongest notion. In this paper, we explore constructions of SIM-RSO-CCA secure PKE from various computational assumptions. Toward this goal, we show that a SIM-RSO-CCA secure PKE scheme can be constructed based on an IND-CPA secure PKE scheme and a designated-verifier non-interactive zero-knowledge (DV-NIZK) argument satisfying one-time simulation soundness. Moreover, we give the first construction of DV-NIZK argument satisfying one-time simulation soundness. Consequently, through our generic construction, we obtain the first SIM-RSO-CCA secure PKE scheme under the computational Diffie-Hellman (CDH) or learning parity with noise (LPN) assumption.