CCA Updatable Encryption Against Malicious Re-encryption Attacks

CCA Updatable Encryption Against Malicious Re-encryption Attacks
复制标题

针对恶意重新加密攻击的 CCA 可更新加密

DOI:
10.1007/978-3-030-64840-4_20
复制
发表时间:
2020
期刊:
International Conference on the Theory and Application of Cryptology and Information Security
影响因子:
--
通讯作者:
Tang, Qiang
Tang, Qiang
中科院分区:
--
文献类型:
--
作者:
Chen, Long;Li, Yanan;Tang, Qiang

文献摘要

参考文献

被引文献

相似文献

可更新加密(UE)是一种有吸引力的原语,它允许外包加密数据的秘密密钥定期更新为新密钥。有几个优秀的作品研究各种安全属性。我们注意到现有的安全模型(密文相关)可更新加密,特别是完整性和CCA安全的几个主要问题。模型中的攻击者只允许请求服务器重新生成密文,而在实践中,攻击者可以根据自己的意愿尝试将任意密文注入服务器。在本文中,我们填补了差距,并在多个方面加强了安全性的定义:最重要的是,我们的完整性和CCA安全模型消除了以前的模型的限制,并实现了标准的完整性和CCA安全性的概念,在设置可更新的加密。沿着的方式,我们细化的安全模型,以捕获后妥协的安全性和增强的CCA风格的重新加密的不可否认性。在新模型的指导下,我们提供了一个新的构造ReCrypt,它满足我们加强的安全定义。来自组的同态散列的技术构建块可以具有独立的兴趣。我们还研究了安全概念之间的关系;有点令人惊讶的是,民间传说导致认证加密,IND-CPA加上密文完整性意味着IND-CCA安全不适用于密文依赖的可更新加密。
Updatable encryption (UE) is an attractive primitive, which allows the secret key of the outsourced encrypted data to be updated to a fresh one periodically. Several elegant works exist studying various security properties. We notice several major issues in existing security models of (ciphertext dependent) updatable encryption, in particular, integrity and CCA security. The adversary in the models is only allowed to request the server to re-encrypthonestlygenerated ciphertext, while in practice, an attacker could try to inject arbitrary ciphertexts into the server as she wishes. Those malformed ciphertext could be updated and leveraged by the adversary and cause serious security issues.In this paper, we fill the gap and strengthen the security definitions in multiple aspects: most importantly our integrity and CCA security models remove the restriction in previous models and achieve standard notions of integrity and CCA security in the setting of updatable encryption. Along the way, we refine the security model to capture post-compromise security and enhance the re-encryption indistinguishability to the CCA style. Guided by the new models, we provide a novel constructionReCrypt, which satisfies our strengthened security definitions. The technical building block of homomorphic hash from a group may be of independent interests. We also study the relations among security notions; and a bit surprisingly, the folklore result in authenticated encryption that IND-CPA plus ciphertext integrity imply IND-CCA security doesnothold for ciphertext dependent updatable encryption.
PCI DSS:支付卡行业数据安全标准背景
DOI: 10.1016/j.clsr.2008.07.001
发表时间: 2008
期刊: Banking & Financial Institutions
影响因子: --
作者:
E. Morse;Vasant Raval
通讯作者: Vasant Raval
(R)CCA 具有完整性保护的安全可更新加密
DOI: 10.1007/978-3-030-17653-2_3
发表时间: 2019
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
M. Klooß;A. Lehmann;A. Rupp
通讯作者: A. Rupp
具有泄露后安全性的可更新加密
DOI: --
发表时间: 2018
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Anja Lehmann;Björn Tackmann
通讯作者: Björn Tackmann