To capture all reasonable security properties of public key encryption (PKE), the notion of ideal public key encryption is proposed by Zhandry and Zhang (CRYPTO 20). Informally, an ideal primitive is a minimal structured random function constrained by its definite functionality, that is, it has nothing more than its indispensable functionality. In Zhandry and Zhang’s definition, the decryption algorithm returns a rejection symbol for an invalid ciphertext which seems additional to decryption correctness, the indispensable functionality of ideal PKE. So, we propose to replace the property of explicit rejection of invalid ciphertexts with implicit rejection of invalid ciphertexts which seems more compact and suitable to the definition of ideal PKE. We aim to explore the relationship between them by investigating the existence of an efficient transformation between them. As a first step, we explore the implication from the situation of implicit rejection to that of explicit rejection by providing a transformation from the former to the latter. For the other direction, we provide only an intuitive separation conjecture at this point. Additionally, we discuss the construction of ideal PKE with implicit rejection to demonstrate its feasibility.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ideal Public Key Encryption, Revisited

  • Yao Cheng,
  • Xianhui Lu,
  • Ziyi Li

摘要

To capture all reasonable security properties of public key encryption (PKE), the notion of ideal public key encryption is proposed by Zhandry and Zhang (CRYPTO 20). Informally, an ideal primitive is a minimal structured random function constrained by its definite functionality, that is, it has nothing more than its indispensable functionality. In Zhandry and Zhang’s definition, the decryption algorithm returns a rejection symbol for an invalid ciphertext which seems additional to decryption correctness, the indispensable functionality of ideal PKE. So, we propose to replace the property of explicit rejection of invalid ciphertexts with implicit rejection of invalid ciphertexts which seems more compact and suitable to the definition of ideal PKE. We aim to explore the relationship between them by investigating the existence of an efficient transformation between them. As a first step, we explore the implication from the situation of implicit rejection to that of explicit rejection by providing a transformation from the former to the latter. For the other direction, we provide only an intuitive separation conjecture at this point. Additionally, we discuss the construction of ideal PKE with implicit rejection to demonstrate its feasibility.