Updatable Public Key Encryption from DCR: Efficient Constructions With Stronger Security
Calvin Abou Haidar, Benoît Libert, Alain Passelègue
Abstract
Forward-secure encryption (FS-PKE) is a key-evolving public-key paradigm that preserves the confidentiality of past encryptions in case of key exposure. Updatable public-key encryption (UPKE) is a natural relaxation of FS-PKE, introduced by Jost et al. (Eurocrypt'19), which is motivated by applications to secure messaging. In UPKE, key updates can be triggered by any sender -- via special update ciphertexts -- willing to enforce the forward secrecy of its encrypted messages. So far, the only truly efficient UPKE candidates (which rely on the random oracle idealization) only provide rather weak security guarantees against passive adversaries as they are malleable. Also, they offer no protection against malicious senders willing to hinder the decryption capability of honest users. A recent work of Dodis et al. (TCC'21) described UPKE systems in the standard model that also hedge against maliciously generated update messages in the chosen-ciphertext setting (where adversaries are equipped with a decryption oracle). While important feasibility results, their constructions lag behind random-oracle candidates in terms of efficiency. In this paper, we first provide a drastically more efficient UPKE realization in the standard model using Paillier's Composite Residuosity (DCR) assumption. In the random oracle model, we then extend our initial scheme so as to achieve chosen-ciphertext security, even in a model that accounts for maliciously generated update ciphertexts. Under the DCR and Strong RSA assumptions, we thus obtain the first practical UPKE systems that satisfy the strongest security notions put forth by Dodis et al.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4b1ff363-6715-4a16-bce9-1591408f1db1Related papers
- Lattice-Based Updatable KEM for Group MessagingJoël Alwen, Georg Fuchsbauer, Marta Mularczyk, Doreen RiepelCRYPTO 2026
- Updatable Public-Key Encryption, RevisitedJoël Alwen, Georg Fuchsbauer, Marta MularczykEUROCRYPT 2024 · 5 citations
- Fast and Secure Updatable EncryptionColin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao JiangCRYPTO 2020 · 52 citations
- Hollow LWE: A New Spin - Unbounded Updatable Encryption from LWE and PCEMartin R. Albrecht, Benjamin Bencina, Russell W. F. LaiEUROCRYPT 2025 · 6 citations
- Authenticated Key Exchange and Signatures with Tight Security in the Standard ModelShuai Han, Tibor Jager, Eike Kiltz, Shengli Liu et al.CRYPTO 2021 · 30 citations
