Leveraging Small Message Spaces for CCA1 Security in Additively Homomorphic and BGN-Type Encryption
Benoît Libert
Abstract
We show that the smallness of message spaces can be used as a checksum allowing to hedge against CCA1 attacks in additively homomorphic encryption schemes. We first show that the additively homomorphic variant of Damgård's Elgamal provides IND-CCA1 security under the standard DDH assumption. Earlier proofs either required non-standard assumptions or only applied to hybrid versions of Damgård's Elgamal, which are not additively homomorphic. Our security proof builds on hash proof systems and exploits the fact that encrypted messages must be contained in a polynomial-size interval in order to enable decryption. With group elements per ciphertext, this positions Damgård's Elgamal as the most efficient/compact DDH-based additively homomorphic CCA1 cryptosystem. Under the same assumption, the best candidate so far was the lite Cramer-Shoup cryptosystem, where ciphertexts consist of group elements. We extend this observation to build an IND-CCA1 variant of the Boneh-Goh-Nissim encryption scheme, which allows evaluating 2-DNF formulas on encrypted data. By computing tensor products of Damgård's Elgamal ciphertexts, we obtain product ciphertexts consisting of group elements (instead of elements if we were tensoring lite Cramer-Shoup ciphertexts) in the target group of a bilinear map. Using similar ideas, we also obtain a CCA1 variant of the Elgamal-Paillier cryptosystem by forcing plaintext bits to be zeroes, which yields CCA1 security almost for free. In particular, the message space remains exponentially large and ciphertexts are as short as in the IND-CPA scheme. We finally adapt the technique to the Castagnos-Laguillaumie system.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- New Limits of Provable Security and Applications to ElGamal EncryptionSven SchägeEUROCRYPT 2024 · 9 citations
- Fully Homomorphic Encryption Beyond IND-CCA1 Security: Integrity Through VerifiabilityMark Manulis, Jérôme NguyenEUROCRYPT 2024 · 27 citations
- Fully Homomorphic Encryption with Chosen-Ciphertext Security from LWERupeng Yang, Zuoxia Yu, Willy SusiloCRYPTO 2025 · 5 citations
- Somewhat Homomorphic Encryption from Linear Homomorphism and Sparse LPNHenry Corrigan-Gibbs, Alexandra Henzinger, Yael Tauman Kalai, Vinod VaikuntanathanEUROCRYPT 2025 · 5 citations
- Direct Range Proofs for Paillier Cryptosystem and Their ApplicationsZhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au et al.CCS 2024 · 7 citations
