Trading Plaintext-Awareness for Simulatability to Achieve Chosen Ciphertext Security

Trading Plaintext-Awareness for Simulatability to Achieve Chosen Ciphertext Security
复制标题

用明文感知换取可模拟性,以实现选定的密文安全性

DOI:
10.1007/978-3-662-49384-7_1
复制
发表时间:
2016
期刊:
Public-Key Cryptography - PKC 2016, Lecture Notes in Computer Science
影响因子:
--
通讯作者:
Goichiro Hanaoka
Goichiro Hanaoka
中科院分区:
--
文献类型:
--
作者:
Takahiro Matsuda;Goichiro Hanaoka

文献摘要

相似文献

在PKC 2014中,Dachman-Soled展示了一个基于选择密文(CCA)安全公钥加密(PKE)方案的构造,该方案在存在多个公钥的情况下同时满足称为弱可模拟性和(标准模型)明文感知(SPA1)的安全性质。对于多密钥设置的明文感知是否等同于在单密钥设置中的更熟悉的概念并不是众所周知的,并且通常认为明文感知是一种强安全假设(因为为了实现它,我们必须依赖于“知识”类型的假设)。在Dachman-soled的构造中,潜在的PKE方案需要在公钥存在的情况下是明文感知的,这项工作的主要结果是证明了Dachman-soled构造所需的明文感知的强度可以通过某种方式与其他构建块的“可模拟性”性质的强度“交换”。此外,我们还证明了我们可以“分离”假设,即单个PKE方案需要在她的构造中既是弱模拟的,又是明文感知的。具体地说,本文给出了两个新的CCA安全密钥封装机制(KEM)的构造:第一个方案基于仅在两个密钥设置下被选择为明文(CPA)安全且明文可感知的KEM和一个满足比弱可模拟性“稍强”的可模拟性的PKE方案,称为“陷门可模拟性”(由Choi等人提出)。ASIACRYPT 2009)。我们的第二个方案是基于KEM的,它是1-有界CCA安全的(Cramer等人)。ASIACRYPT 2007)和仅在相同密钥设置中的明文感知,以及陷门模拟PKE方案。我们的结果增加了从一般假设(无法与Dachman-Soled使用的假设相比)构建CCA安全PKE/KEM的新配方,特别是显示了构建块与Dachman-Soled构建中使用的构建块之间有趣的权衡。
In PKC 2014, Dachman-Soled showed a construction of a chosen ciphertext (CCA) secure public key encryption (PKE) scheme based on a PKE scheme which simultaneously satisfies a security property called weak simulatability and (standard model) plaintext awareness (sPA1) in the presence of multiple public keys. It is not well-known if plaintext awareness for the multiple keys setting is equivalent to the more familiar notion of that in the single key setting, and it is typically considered that plaintext awareness is a strong security assumption (because to achieve it we have to rely on a “knowledge”-type assumption). In Dachman-Soled’s construction, the underlying PKE scheme needs to be plaintext aware in the presence ofpublic keys.The main result in this work is to show that the strength of plaintext awareness required in the Dachman-Soled construction can be somehow “traded” with the strength of a “simulatability” property of other building blocks. Furthermore, we also show that we can “separate” the assumption that a single PKE scheme needs to be both weakly simulatable and plaintext aware in her construction. Specifically, in this paper we show two new constructions of CCA secure key encapsulation mechanisms (KEMs): Our first scheme is based on a KEM which is chosen plaintext (CPA) secure and plaintext aware only under the 2 keys setting, and a PKE scheme satisfying a “slightly stronger” simulatability than weak simulatability, called “trapdoor simulatability” (introduced by Choi et al. ASIACRYPT 2009). Our second scheme is based on a KEM which is 1-bounded CCA secure (Cramer et al. ASIACRYPT 2007) and plaintext aware only in thesinglekey setting, and a trapdoor simulatable PKE scheme. Our results add new recipes for constructing CCA secure PKE/KEM from general assumptions (that are incomparable to those used by Dachman-Soled), and in particular show interesting trade-offs among building blocks with those used in Dachman-Soled’s construction.