Chosen-Ciphertext Secure Key Encapsulation Mechanism in the Standard Model

Chosen-Ciphertext Secure Key Encapsulation Mechanism in the Standard Model
复制标题

DOI:
10.1109/access.2021.3051047
复制
发表时间:
2021
期刊:
影响因子:
3.9
通讯作者:
Shengfeng Xu;Xiangxue Li
Shengfeng Xu;Xiangxue Li
中科院分区:
计算机科学3区
文献类型:
--
作者:
Shengfeng Xu;Xiangxue Li

文献摘要

相似文献

密钥封装机制(Key Encapsulation Mechanism, KEM)是一种基本的密码原语,它可以使用公钥算法为传输提供安全的对称密码密钥材料。到目前为止,许多选择密文(IND-CCA)安全KEM方案都是通过通用的Fujisaki-Okamoto (FO)转换从选择明文(IND-CPA)或单向(low - cpa)安全PKE构建的(TCC 2017)。然而,安全性依赖于随机Oracle模型(ROM)。据我们所知,目前还没有基于噪声奇偶性(LPN)假设的IND-CCA安全KEM方案可以对抗标准模型中的后量子攻击。在这项工作中,我们提出了第一个直接构建基于lpn的KEM,它在标准模型中是安全的。特别是,我们使用双陷阱门技术来正确回答对手的解密查询,并使用目标抗碰撞(TCR)哈希函数来检查密文的有效性。封装的键由一个特殊的LPN问题决定(不需要随机oracle)。在一系列博弈的低噪声LPN假设下,该方案对后量子攻击具有IND-CCA安全性,且安全性降低幅度较小。与之前128位安全级别的方案相比,我们的cca安全方案仅持有50.78MB公钥、62.50MB私钥和4.54KB密文,比Döttling等人(ASIACRYPT 2012)、Kiltz等人(PKC 2014)和Yu等人(CRYPTO 2016)的方案(分别为(7.27GB、7.24GB、7.03KB)、(80.89MB、46.23MB、6.80KB)和(70.95MB、70.65MB、86.50KB)的效率更高。
Key Encapsulation Mechanism (KEM) is a foundational cryptography primitive, which can provide secure symmetric cryptographic key material for transmission by using public key algorithms. Until now, many Chosen-Ciphertext (IND-CCA) secure KEM schemes are constructed from Chosen-Plaintext (IND-CPA) or One-Way (OW-CPA) secure PKE via the generic Fujisaki-Okamoto (FO) transformations (TCC 2017). However, the security relies on the Random Oracle Model (ROM). To the best of our knowledge, there are no IND-CCA secure KEM schemes based on Learning Parity with Noise (LPN) assumption that can against post quantum attacks in the standard model. In this work, we propose the first direct construction of LPN-based KEM, which is secure in the standard model. In particular, we use double-trapdoor technique to answer adversary’s decryption queries correctly and a Target Collision Resistant (TCR) hash function to check the validity of the ciphertext. The encapsulated key is determined by a special LPN problem (with no random oracle required). The scheme is IND-CCA secure against post-quantum attacks under the low-noise LPN assumptions by a series of games and the security reduction is tight. Compared with previous schemes on 128-bit security level, our CCA-secure scheme only holds 50.78MB public keys, 62.50MB secret keys and 4.54KB ciphertexts, which is more efficient than the schemes of Döttling et al. (ASIACRYPT 2012), Kiltz et al. (PKC 2014) and Yu et al. (CRYPTO 2016) ((7.27GB, 7.24GB, 7.03KB), (80.89MB, 46.23MB, 6.80KB) and (70.95MB, 70.65MB, 86.50KB) respectively).