Efficient Public Key Cryptosystem Resilient to Key Leakage Chosen Ciphertext Attacks

Efficient Public Key Cryptosystem Resilient to Key Leakage Chosen Ciphertext Attacks
复制标题

DOI:
10.1007/978-3-642-36095-4_6
复制
发表时间:
2013-02
期刊:
--
影响因子:
--
通讯作者:
Shengli Liu;J. Weng;Yunlei Zhao
Shengli Liu;J. Weng;Yunlei Zhao
中科院分区:
其他
文献类型:
--
作者:
Shengli Liu;J. Weng;Yunlei Zhao

文献摘要

被引文献

相似文献

泄漏弹性公钥加密(PKE)方案被设计为抵抗“存储器攻击”,即,攻击者自适应地恢复存储器中的密码密钥,但是受到关于密钥的泄露信息的总量受某个参数λ限制的约束。在所有IND-CCA 2泄漏弹性PKE提案中,Cramer-Shoup密码系统(CS-PKE)的泄漏弹性版本,被称为由Naor和Segev在Crypto 09中提出的KL-CS-PKE方案,是最实用的一个。但是,KL-CS-PKE的密钥泄漏参数λ和明文长度m满足λ+m≤ logq−ω(logκ),其中κ为安全参数,q为方案所基于群的素数阶。λ和之间的这种依赖性是不可取的。例如,当λ(resp.,m)接近logq,m(分别,本文设计了一种新的CS-PKE算法,该算法能够抵抗密钥泄漏选择密文攻击。我们的建议是λ≤ logq−ω(logκ)泄漏弹性,并且泄漏参数λ与具有常数大小q的明文空间无关(与CS-PKE中的完全相同)。我们的建议的性能几乎是一样有效的原始CS-PKE。据我们所知,这是第一个明文长度与密钥泄漏参数无关的泄漏弹性CS-型密码系统,也是最有效的IND-CCA 2 PKE方案,可以承受高达logq−ω(logκ)的泄漏。
Leakage-resilient public key encryption (PKE) schemes are designed to resist “memory attacks”, i.e., the adversary recovers the cryptographic key in the memory adaptively, but subject to constraint that the total amount of leaked information about the key is bounded by some parameterλ. Among all the IND-CCA2 leakage-resilient PKE proposals, the leakage-resilient version of the Cramer-Shoup cryptosystem (CS-PKE), referred to as the KL-CS-PKE scheme proposed by Naor and Segev in Crypto09, is the most practical one. But, the key leakage parameterλand plaintext lengthmof KL-CS-PKE are subject toλ+m≤ logq−ω(logκ), whereκis security parameter andqis the prime order of the group on which the scheme is based. Such a dependence betweenλandmis undesirable. For example, whenλ(resp.,m) approaches to logq,m(resp.,λ) approaches to 0.In this paper, we designed a new variant of CS-PKE that is resilient to key leakage chosen ciphertext attacks. Our proposal isλ≤ logq−ω(logκ) leakage-resilient, and the leakage parameterλis independent of the plaintext space that has the constant sizeq(exactly the same as that in CS-PKE). The performance of our proposal is almost as efficient as the original CS-PKE. As far as we know, this is the first leakage-resilient CS-type cryptosystem whose plaintext length is independent of the key leakage parameter, and is also the most efficient IND-CCA2 PKE scheme resilient to up to logq−ω(logκ) leakage.