Public-Key Encryption Resistant to Parameter Subversion and its Realization from Efficiently-Embeddable Groups

Public-Key Encryption Resistant to Parameter Subversion and its Realization from Efficiently-Embeddable Groups
复制标题

DOI:
10.1007/978-3-319-76578-5_12
复制
发表时间:
2018-03
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Benedikt Auerbach;M. Bellare;Eike Kiltz
Benedikt Auerbach;M. Bellare;Eike Kiltz
中科院分区:
其他
文献类型:
--
作者:
Benedikt Auerbach;M. Bellare;Eike Kiltz

文献摘要

被引文献

相似文献

我们开始研究公钥加密(PKE)方案和密钥封装机制(KEM),即使他们使用的公共参数(素数,曲线)可能是不可信的和颠覆的,也能保持安全性。我们定义了一个强大的安全目标,我们称之为参数颠覆攻击下的密文伪随机性(CPR-PSA)。我们还定义了不可篡改性(PKE的密文,和封装的密钥从随机的KEM)和公钥隐藏(也称为匿名性)参数颠覆攻击下,并显示它们是隐含的CPR-PSA,PKE和KEM。我们表明,混合加密继续工作在参数颠覆设置减少CPR-PSA PKE的设计CPR-PSA KEM和对称加密的适当形式。为了获得高效的,基于椭圆曲线的KEM实现CPR-PSA,我们引入了有效嵌入群族,并给出了几个构造椭圆曲线。
We initiate the study of public-key encryption (PKE) schemes and key-encapsulation mechanisms (KEMs) that retain security even when public parameters (primes, curves) they use may be untrusted and subverted. We define a strong security goal that we call ciphertext pseudo-randomness under parameter subversion attack (CPR-PSA). We also define indistinguishability (of ciphertexts for PKE, and of encapsulated keys from random ones for KEMs) and public-key hiding (also called anonymity) under parameter subversion attack, and show they are implied by CPR-PSA, for both PKE and KEMs. We show that hybrid encryption continues to work in the parameter subversion setting to reduce the design of CPR-PSA PKE to CPR-PSA KEMs and an appropriate form of symmetric encryption. To obtain efficient, elliptic-curve-based KEMs achieving CPR-PSA, we introduce efficiently-embeddable group families and give several constructions from elliptic-curves.