On the Equivalence of Several Security Notions of Key Encapsulation Mechanism

On the Equivalence of Several Security Notions of Key Encapsulation Mechanism
复制标题

密钥封装机制的几种安全概念的等价性

DOI:
--
复制
发表时间:
2006
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
T. Okamoto
T. Okamoto
中科院分区:
--
文献类型:
--
作者:
Waka Nagao;Yoshifumi Manabe;T. Okamoto

文献摘要

被引文献

相似文献

KEM(密钥封装机制)是Shoup引入的,用于形式化ISO公钥加密标准中为密钥分发指定的非对称加密。Shoup将“针对自适应选择密文攻击(CCA2)的语义安全(IND)”定义为KEM的理想安全概念。本文引入了KEM的“非延展性(NM)”,这是一个比IND更强的安全概念,给出了三个NM的定义,并证明了这三个定义是等价的。然后,我们证明了NM-CCA2 KEM与IND-CCA2 KEM等效。也就是说,我们证明了在CCA2攻击下NM相当于IND,尽管在定义中NM比IND强(或者在CCA1等一些攻击下)。此外,本文还定义了KEM的普遍可组合(UC)安全性,并证明了NM-CCA2 KEM等价于UC KEM。
KEM (Key Encapsulation Mechanism) was introduced by Shoup to formalize the asymmetric encryption specified for key distribution in ISO standards on public-key encryption. Shoup defined the “semantic security (IND) against adaptively chosen ciphertext attacks (CCA2)” as a desirable security notion of KEM. This paper introduces ”nonmalleability (NM)” of KEM, a stronger security notion than IND. We provide three definitions of NM, and show that these three definitions are equivalent. We then show that NM-CCA2 KEM is equivalent to IND-CCA2 KEM. That is, we show that NM is equivalent to IND under CCA2 attacks, although NM is stronger than IND in the definition (or under some attacks like CCA1). In addition, this paper defines the universally composable (UC) security of KEM and shows that NM-CCA2 KEM is equivalent to UC KEM.