New Limits of Provable Security and Applications to ElGamal Encryption
Sven Schäge
摘要
We provide new results showing that ElGamal encryption cannot be proven CCA1-secure – a long-standing open problem in cryptography. Our result follows from a very broad, meta-reduction-based impossibility result on random self-reducible relations with efficiently re-randomizable witnesses. The techniques that we develop allow, for the first time, to provide impossibility results for very weak security notions where the challenger outputs fresh challenge statements at the end of the security game. This can be used to finally tackle encryption-type definitions that have remained elusive in the past. We show that our results have broad applicability by casting several known cryptographic setups as instances of random self-reducible and re-randomizable relations. These setups include general semi-homomorphic PKE and the large class of certified homomorphic one-way bijections. As a result, we also obtain new impossibility results for the IND-CCA1 security of the PKEs of Paillier and Damg ̊ard–Jurik, and many one-more inversion assumptions like the one-more DLOG or the one-more RSA assumption.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Leveraging Small Message Spaces for CCA1 Security in Additively Homomorphic and BGN-Type EncryptionBenoît LibertEUROCRYPT 2025 · 被引用 4 次
- Indifferentiability for Public Key CryptosystemsMark Zhandry, Cong ZhangCRYPTO 2020 · 被引用 11 次
- How to Encrypt with Random Reversible Circuits: Functional, Homomorphic and CCA-SecureRan Canetti, Ji Luo, Yiding ZhangCRYPTO 2026 · 被引用 1 次
- Lattice-Based Authenticated Key Exchange with Tight SecurityJiaxin Pan, Benedikt Wagner, Runzhi ZengCRYPTO 2023 · 被引用 14 次
- On IND-qCCA Security in the ROM and Its Applications - CPA Security Is Sufficient for TLS 1.3Loïs Huguenin-Dumittan, Serge VaudenayEUROCRYPT 2022 · 被引用 18 次
