On the Equivalence of Several Security Notions of Key Encapsulation Mechanism
On the Equivalence of Several Security Notions of Key Encapsulation Mechanism
复制标题
密钥封装机制的几种安全概念的等价性
DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
T. Okamoto
中科院分区:
文献类型:
--
作者:
Waka Nagao;Yoshifumi Manabe;T. Okamoto
KEM (Key Encapsulation Mechanism) was introduced by Shoup to formalize the asymmetric encryption specified for key distribution in ISO standards on public-key encryption. Shoup defined the “semantic security (IND) against adaptively chosen ciphertext attacks (CCA2)” as a desirable security notion of KEM. This paper introduces ”nonmalleability (NM)” of KEM, a stronger security notion than IND. We provide three definitions of NM, and show that these three definitions are equivalent. We then show that NM-CCA2 KEM is equivalent to IND-CCA2 KEM. That is, we show that NM is equivalent to IND under CCA2 attacks, although NM is stronger than IND in the definition (or under some attacks like CCA1). In addition, this paper defines the universally composable (UC) security of KEM and shows that NM-CCA2 KEM is equivalent to UC KEM.