Deterministic Public-Key Encryption for Adaptively Chosen Plaintext Distributions
- Ananth RaghunathanAffiliated withLancaster UniversityComputer Science Department, Stanford University
- , Gil SegevAffiliated withLancaster UniversityComputer Science Department, Stanford University
- , Salil VadhanAffiliated withLancaster UniversitySchool of Engineering and Applied Sciences & Center for Research on Computation and Society, Harvard University
Bellare, Boldyreva, and O’Neill (CRYPTO ’07) initiated the study of deterministic public-key encryption as an alternative in scenarios where randomized encryption has inherent drawbacks. The resulting line of research has so far guaranteed security only for adversarially-chosen plaintext distributions that are independent of the public key used by the scheme. In most scenarios, however, it is typically not realistic to assume that adversaries do not take the public key into account when attacking a scheme.
We show that it is possible to guarantee meaningful security even for plaintext distributions that depend on the public key. We extend the previously proposed notions of security, allowing adversaries to adaptively choose plaintext distributions after seeing the public key, in an interactive manner. The only restrictions we make are that: (1) plaintext distributions are unpredictable (as is essential in deterministic public-key encryption), and (2) the number of plaintext distributions from which each adversary is allowed to adaptively choose is upper bounded by 2 p , where p can be any predetermined polynomial in the security parameter. For example, with p = 0 we capture plaintext distributions that are independent of the public key, and with p = O(s logs) we capture, in particular, all plaintext distributions that are samplable by circuits of size s.
Within our framework we present both constructions in the random-oracle model based on any public-key encryption scheme, and constructions in the standard model based on lossy trapdoor functions (thus, based on a variety of number-theoretic assumptions). Previously known constructions heavily relied on the independence between the plaintext distributions and the public key for the purposes of randomness extraction. In our setting, however, randomness extraction becomes significantly more challenging once the plaintext distributions and the public key are no longer independent. Our approach is inspired by research on randomness extraction from seed-dependent distributions. Underlying our approach is a new generalization of a method for such randomness extraction, originally introduced by Trevisan and Vadhan (FOCS ’00) and Dodis (PhD Thesis, MIT, ’00).
- Deterministic Public-Key Encryption for Adaptively Chosen Plaintext Distributions
- Book Title
- Advances in Cryptology – EUROCRYPT 2013
- Book Subtitle
- 32nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Athens, Greece, May 26-30, 2013. Proceedings
- pp 93-110
- Print ISBN
- Online ISBN
- Series Title
- Lecture Notes in Computer Science
- Series Volume
- Series ISSN
- Springer Berlin Heidelberg
- Copyright Holder
- International Association for Cryptologic Research
- Additional Links
- Industry Sectors
- eBook Packages
- Editor Affiliations
- 16. Dept. of Electrical and Information Technology, Lund University
- 17. Départment d’informatique, Ecole normale supérieure
- Author Affiliations
- 18. Computer Science Department, Stanford University, Stanford, CA, 94305, USA
- 19. School of Engineering and Applied Sciences & Center for Research on Computation and Society, Harvard University, Cambridge, MA, 02138, USA
To view the rest of this content please follow the download PDF link above.