Universal Amplification of KDM Security: From 1-Key Circular to Multi-Key KDM
Brent Waters, Daniel Wichs
Abstract
An encryption scheme is Key Dependent Message (KDM) secure if it is safe to encrypt messages that can arbitrarily depend on the secret keys themselves. In this work, we show how to upgrade essentially the weakest form of KDM security into the strongest one. In particular, we assume the existence of a symmetric-key bit-encryption that is circular-secure in the -key setting, meaning that it maintains security even if one can encrypt individual bits of a single secret key under itself. We also rely on a standard CPA-secure public-key encryption. We construct a public-key encryption scheme that is KDM secure for general functions (of a-priori bounded circuit size) in the multi-key setting, meaning that it maintains security even if one can encrypt arbitrary functions of arbitrarily many secret keys under each of the public keys. As a special case, the latter guarantees security in the presence of arbitrary length key cycles. Prior work already showed how to amplify -key circular to -key KDM security for general functions. Therefore, the main novelty of our work is to upgrade from -key to -key security for arbitrary .
As an independently interesting feature of our result, our construction does not need to know the actual specification of the underlying 1-key circular secure scheme, and we only rely on the existence of some such scheme in the proof of security. In particular, we present a universal construction of a multi-key KDM-secure encryption that is secure as long as some 1-key circular-secure scheme exists. While this feature is similar in spirit to Levin's universal construction of one-way functions, the way we achieve it is quite different technically, and does not come with the same ``galactic inefficiency''.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4bcc5c56-bf2c-48c1-b557-b45623bf5174Related papers
- A Unifying Umbrella for Circular-Secure Cryptographic PrimitivesFuyuki Kitagawa, Takahiro MatsudaCRYPTO 2026
- Multi-copy Security in Quantum Cryptography and MoreAlper Çakan, Vipul Goyal, Fuyuki Kitagawa, Ryo Nishimaki et al.CRYPTO 2026
- Quantum Public-Key Encryption with Tamper-Resilient Public Keys from One-Way FunctionsFuyuki Kitagawa, Tomoyuki Morimae, Ryo Nishimaki, Takashi YamakawaCRYPTO 2024 · 13 citations
- Functional Encryption for Turing Machines with Dynamic Bounded Collusion from LWEShweta Agrawal, Monosij Maitra, Narasimha Sai Vempati, Shota YamadaCRYPTO 2021 · 25 citations
- Multi-key and Multi-input Predicate Encryption from Learning with ErrorsDanilo Francati, Daniele Friolo, Giulio Malavolta, Daniele VenturiEUROCRYPT 2023 · 22 citations
