Post-challenge leakage in public-key encryption

Post-challenge leakage in public-key encryption
复制标题

DOI:
10.1016/j.tcs.2015.01.010
复制
发表时间:
2015-03
期刊:
Theor. Comput. Sci.
影响因子:
--
通讯作者:
Zongyang Zhang;Sherman S. M. Chow;Z. Cao
Zongyang Zhang;Sherman S. M. Chow;Z. Cao
中科院分区:
其他
文献类型:
--
作者:
Zongyang Zhang;Sherman S. M. Chow;Z. Cao

文献摘要

被引文献

相似文献

当对手可以测量存储解密密钥的物理内存时,解密功能通常会派上用场。Halevi和Lin(TCC‘11)研究了公钥加密(PKE)中的事后(或挑战后)泄漏,其中敌手在看到挑战密文后可以从分裂状态进行泄漏查询,但对选择密文攻击(CCA)的安全性是未来的工作。在本文中,我们遵循他们的工作,给出了熵泄漏弹性CCA-安全PKE的定义,并证明了该定义可以由Naor-Yung“双重加密”范例(STEC‘90)实现。然后,我们利用它在存在挑战后泄漏的情况下,在相同的分裂状态的有界内存泄漏模型中获得CCA安全的密钥封装机制。最后,通过构造一种CCA安全的PKE,证明了该混合加密框架在挑战后泄漏的情况下仍然适用。作为补充,我们将这些概念扩展到基于身份的环境中,在敌手获得挑战后许多基于身份的密钥可能被泄露的情况下,给出了分裂状态模型中存在挑战后泄漏的基于身份的加密构造,该构造可以被Alwen等人的基于身份的散列证明系统实例化。(Eurocrypt‘10)和Chow等人。(CCS‘10)。
When an adversary can measure the physical memory storing the decryption key, decryption functionality often comes in handy. Halevi and Lin (TCC'11) studied after-the-fact (or post-challenge) leakage in public-key encryption (PKE), in which an adversary can make leakage queries from a split state after seeing the challenge ciphertext, but left security against chosen-ciphertext attacks (CCA) as a future work. In this paper, we follow their work and formulate the definition of entropic leakage-resilient CCA-secure PKE, which we show can be realized by the Naor–Yung “double encryption” paradigm (STOC'90). We then leverage it to get a CCA-secure key-encapsulation mechanism in the presence of post-challenge leakage, in the same model of bounded memory leakage from a split state. Finally, we prove that the hybrid encryption framework is still applicable by presenting a construction of CCA-secure PKE in the presence of post-challenge leakage. As additional results, we extend these concepts to the identity-based setting, where many identity-based secret-keys can be leaked after the adversary got the challenge, and give a construction of identity-based encryption in the presence of post-challenge leakage in the split-state model, which can be instantiated by the identity-based hash proof systems of Alwen et al. (Eurocrypt'10) and Chow et al. (CCS'10).