To deal with the potential threat of quantum computers, both industry and academia have started to deploy schemes that are composition of classically secure and quantum-secure constructions. In particular, the IETF has proposed three composite encryption modes that establish a shared key using a combination of public key encryption, key encapsulation, and key exchange primitives. However, no security proofs are provided. As a complement to their proposals, this work first defines various quantum CPA-security that capture the capability of adversary during the transition to the fully quantum world. Towards this goal, we follow the footprint by Bindel et al. (PQCrypto 2017, PQCrypto 2019) to categorize the adversaries according to whether the adversaries have a quantum computer and whether they have quantum access to the challenge queries. We then observe that our security definitions coincide with those defined by Gagliardoni (Thesis 2017), which could be of independent interest. Finally, we prove the quantum CPA-security of the first two composite encryption modes in the IETF draft. The results show that the composite schemes are secure as long as at least one of its components is secure.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Transitioning to Quantum-Secure Encryption Schemes

  • Shao Huang,
  • Songsong Li,
  • Ying Ouyang,
  • Yanhong Xu

摘要

To deal with the potential threat of quantum computers, both industry and academia have started to deploy schemes that are composition of classically secure and quantum-secure constructions. In particular, the IETF has proposed three composite encryption modes that establish a shared key using a combination of public key encryption, key encapsulation, and key exchange primitives. However, no security proofs are provided. As a complement to their proposals, this work first defines various quantum CPA-security that capture the capability of adversary during the transition to the fully quantum world. Towards this goal, we follow the footprint by Bindel et al. (PQCrypto 2017, PQCrypto 2019) to categorize the adversaries according to whether the adversaries have a quantum computer and whether they have quantum access to the challenge queries. We then observe that our security definitions coincide with those defined by Gagliardoni (Thesis 2017), which could be of independent interest. Finally, we prove the quantum CPA-security of the first two composite encryption modes in the IETF draft. The results show that the composite schemes are secure as long as at least one of its components is secure.