Hedged Public-Key Encryption: How to Protect against Bad Randomness

  • Mihir Bellare
  • Zvika Brakerski
  • Moni Naor
  • Thomas Ristenpart
  • Gil Segev
  • Hovav Shacham
  • Scott Yilek
Conference paper

DOI: 10.1007/978-3-642-10366-7_14

Part of the Lecture Notes in Computer Science book series (LNCS, volume 5912)
Cite this paper as:
Bellare M. et al. (2009) Hedged Public-Key Encryption: How to Protect against Bad Randomness. In: Matsui M. (eds) Advances in Cryptology – ASIACRYPT 2009. ASIACRYPT 2009. Lecture Notes in Computer Science, vol 5912. Springer, Berlin, Heidelberg

Abstract

Public-key encryption schemes rely for their IND-CPA security on per-message fresh randomness. In practice, randomness may be of poor quality for a variety of reasons, leading to failure of the schemes. Expecting the systems to improve is unrealistic. What we show in this paper is that we can, instead, improve the cryptography to offset the lack of possible randomness. We provide public-key encryption schemes that achieve IND-CPA security when the randomness they use is of high quality, but, when the latter is not the case, rather than breaking completely, they achieve a weaker but still useful notion of security that we call IND-CDA. This hedged public-key encryption provides the best possible security guarantees in the face of bad randomness. We provide simple RO-based ways to make in-practice IND-CPA schemes hedge secure with minimal software changes. We also provide non-RO model schemes relying on lossy trapdoor functions (LTDFs) and techniques from deterministic encryption. They achieve adaptive security by establishing and exploiting the anonymity of LTDFs which we believe is of independent interest.

Download to read the full conference paper text

Copyright information

© Springer-Verlag Berlin Heidelberg 2009

Authors and Affiliations

  • Mihir Bellare
    • 1
  • Zvika Brakerski
    • 2
  • Moni Naor
    • 2
  • Thomas Ristenpart
    • 1
  • Gil Segev
    • 2
  • Hovav Shacham
    • 1
  • Scott Yilek
    • 1
  1. 1.Dept. of Computer Science & EngineeringUniversity of California at San DiegoLa JollaUSA
  2. 2.Dept. of Computer Science and Applied MathematicsWeizmann Institute of ScienceRehovotIsrael

Personalised recommendations