On the Key Dependent Message Security of the Fujisaki-Okamoto Constructions

On the Key Dependent Message Security of the Fujisaki-Okamoto Constructions
复制标题

DOI:
10.1007/978-3-662-49384-7_5
复制
发表时间:
2016-03
影响因子:
2.1
通讯作者:
Fuyuki Kitagawa;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka
Fuyuki Kitagawa;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka
中科院分区:
农林科学3区
文献类型:
--
作者:
Fuyuki Kitagawa;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka

文献摘要

被引文献

相似文献

在 PKC 1999 中,Fujisaki 和 Okamoto 展示了如何将任何能够抵御选择明文攻击 (CPA) 的公钥加密 (PKE) 方案转换为能够在随机预言机模型中抵御选择密文攻击 (CCA) 的 PKE 方案。令人惊讶的是,最终的 CCA 安全方案与底层 CPA 安全方案具有几乎相同的效率。此外,在 J. Cryptology 2013 中,他们提出了通过使用混合加密框架进行更有效的转换。在这项工作中,我们阐明了在与 Fujisaki 和 Okamoto 使用的构建块完全相同的假设下,这两种结构在针对选定密文攻击的密钥相关消息安全性(KDM-CCA 安全性)方面是否也是安全的。具体来说,我们展示了两个结果:首先,我们展示了 PKC 1999 中提出的构造总体上不满足安全性。其次,另一方面,我们证明J. Cryptology 2013中提出的构造满足安全性。
In PKC 1999, Fujisaki and Okamoto showed how to convert any public key encryption (PKE) scheme secure against chosen plaintext attacks (CPA) to a PKE scheme which is secure against chosen ciphertext attacks (CCA) in the random oracle model. Surprisingly, the resulting CCA secure scheme has almost the same efficiency as the underlying CPA secure scheme. Moreover, in J. Cryptology 2013, they proposed more efficient conversion by using the hybrid encryption framework.In this work, we clarify whether these two constructions are also secure in the sense ofkey dependent message securityagainst chosen ciphertext attacks (KDM-CCA security), under exactly the same assumptions on the building blocks as those used by Fujisaki and Okamoto. Specifically, we show two results: Firstly, we show that the construction proposed in PKC 1999 does not satisfysecurity generally. Secondly, on the other hand, we show that the construction proposed in J. Cryptology 2013 satisfiessecurity.