Efficient Public Key Cryptosystem Resilient to Key Leakage Chosen Ciphertext Attacks
Efficient Public Key Cryptosystem Resilient to Key Leakage Chosen Ciphertext Attacks
复制标题
DOI:
10.1007/978-3-642-36095-4_6
复制
发表时间:
2013-02
期刊:
影响因子:
--
通讯作者:
Shengli Liu;J. Weng;Yunlei Zhao
中科院分区:
文献类型:
--
作者:
Shengli Liu;J. Weng;Yunlei Zhao
Leakage-resilient public key encryption (PKE) schemes are designed to resist “memory attacks”, i.e., the adversary recovers the cryptographic key in the memory adaptively, but subject to constraint that the total amount of leaked information about the key is bounded by some parameterλ. Among all the IND-CCA2 leakage-resilient PKE proposals, the leakage-resilient version of the Cramer-Shoup cryptosystem (CS-PKE), referred to as the KL-CS-PKE scheme proposed by Naor and Segev in Crypto09, is the most practical one. But, the key leakage parameterλand plaintext lengthmof KL-CS-PKE are subject toλ+m≤ logq−ω(logκ), whereκis security parameter andqis the prime order of the group on which the scheme is based. Such a dependence betweenλandmis undesirable. For example, whenλ(resp.,m) approaches to logq,m(resp.,λ) approaches to 0.In this paper, we designed a new variant of CS-PKE that is resilient to key leakage chosen ciphertext attacks. Our proposal isλ≤ logq−ω(logκ) leakage-resilient, and the leakage parameterλis independent of the plaintext space that has the constant sizeq(exactly the same as that in CS-PKE). The performance of our proposal is almost as efficient as the original CS-PKE. As far as we know, this is the first leakage-resilient CS-type cryptosystem whose plaintext length is independent of the key leakage parameter, and is also the most efficient IND-CCA2 PKE scheme resilient to up to logq−ω(logκ) leakage.