Public-Key Anamorphism in (CCA-Secure) Public-Key Encryption and Beyond

被引:0
作者
Persiano, Giuseppe [1 ,2 ]
Phan, Duong Hieu [3 ]
Yung, Moti [2 ,4 ]
机构
[1] Univ Salerno, Fisciano, Italy
[2] Google LLC, New York, NY 10011 USA
[3] Inst Polytech Paris, Telecom Paris, Paris, France
[4] Columbia Univ, New York, NY 10027 USA
来源
ADVANCES IN CRYPTOLOGY - CRYPTO 2024, PT II | 2024年 / 14921卷
关键词
CHOSEN-CIPHERTEXT SECURITY;
D O I
10.1007/978-3-031-68379-4_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The notion of (Receiver-) Anamorphic Encryption was put forth recently to show that a dictator (i.e., an overreaching government), which demands to get the receiver's private key and even dictates messages to the sender, cannot prevent the receiver from getting an additional covert anamorphic message from a sender. The model required an initial private collaboration to share some secret. There may be settings though where an initial collaboration may be impossible or performance-wise prohibitive, or cases when we need an immediate message to be sent without private key generation (e.g., by any casual sender in need). This situation, to date, somewhat limits the applicability of anamorphic encryption. To overcome this, in this work, we put forth the new notion of "public-key anamorphic encryption," where, without any initialization, any sender that has not coordinated in any shape or form with the receiver, can nevertheless, under the dictator control of the receiver's private key, send the receiver an additional anamorphic secret message hidden from the dictator. We define the new notion with its unique new properties, and then prove that, quite interestingly, the known CCA-secure Koppula-Waters (KW) system is, in fact, public-key anamorphic. We then describe how a public-key anamorphic scheme can support a new hybrid anamorphic encapsulation mode (KDEM) where the public-key anamorphic part serves a bootstrapping mechanism to activate regular anamorphic messages in the same ciphertext, thus together increasing the anamorphic channel capacity. Looking at the state of research thus far, we observe that the initial system (Eurocrypt'22) that was shown to have regular anamorphic properties is the CCA-secure Naor-Yung (and other related schemes). Here we identify that the KW CCA-secure scheme also provides a new type of anamorphism. Thus, this situation is hinting that there may be a connection between some types of CCA-secure schemes and some type of anamorphic schemes (in spite of the fact that the goals of the two primitives are fundamentally different); this question is foundational in nature. Given this, we identify a sufficient condition for a "CCA-secure scheme which is black-box reduced from a CPA secure scheme" to directly give rise to an "anamorphic encryption scheme!" Furthermore, we identify one extra property of the reduction, that yields a public-key anamorphic scheme as defined here.
引用
收藏
页码:422 / 455
页数:34
相关论文
共 21 条
  • [1] Anamorphic Encryption, Revisited
    Banfi, Fabio
    Gegier, Konstantin
    Hirt, Martin
    Maurer, Ueli
    Rito, Guilherme
    [J]. ADVANCES IN CRYPTOLOGY, PT II, EUROCRYPT 2024, 2024, 14652 : 3 - 32
  • [2] Bellare M., 1993, LECT NOTES COMPUTER, V773, P232, DOI [DOI 10.1007/3-540-48329-2_21, DOI 10.1007/3-540-48329-221]
  • [3] Chosen-ciphertext security from identity-based encryption
    Canetti, R
    Halevi, S
    Katz, J
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2004, PROCEEDINGS, 2004, 3027 : 207 - 222
  • [4] Anamorphic Encryption: New Constructions and Homomorphic Realizations
    Catalano, Dario
    Giunta, Emanuele
    Migliaro, Francesco
    [J]. ADVANCES IN CRYPTOLOGY, PT II, EUROCRYPT 2024, 2024, 14652 : 33 - 62
  • [5] De Santis A., 2001, Advances in Cryptology - CRTPTO 2001. 21st Annual International Cryptology Conference, Proceedings (Lecture Notes in Computer Science Vol.2139), P566
  • [6] FEIGE U, 1990, ANN IEEE SYMP FOUND, P308
  • [7] Stealth Key Exchange and Confined Access to the Record Protocol Data in TLS 1.3
    Fischlin, Marc
    [J]. PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 2901 - 2914
  • [8] Fujisaki E., 2001, Advances in Cryptology - CRTPTO 2001. 21st Annual International Cryptology Conference, Proceedings (Lecture Notes in Computer Science Vol.2139), P260
  • [9] Fujisaki E, 1999, LECT NOTES COMPUT SC, V1560, P53
  • [10] HPRV19 Horel T., 2019, ITCS 2019, V124