This paper introduces the concept of “ideal transformations”, which refers to transformations between two ideal primitives that capture the security boundaries of cryptographic schemes. Specifically, if the starting point is an ideal scheme, then the ending point of an ideal transformation should also be an ideal scheme. In other words, an ideal transformation will never weaken the security properties of the scheme. Building on the security enhancements provided by existing transformations, we propose a new perspective on public key encryption (PKE) design, viewing it from the ideal transformation point. Our goal is to lift existing transformations to their ideal forms. We explore the most popular transformations in PKE design, including Fujisaki-Okamoto (FO) and Optimal Asymmetric Encryption Padding (OAEP). We show that they bring weaknesses during transformation, and demonstrate how to lift them to ideal forms. Specifically, FO and OAEP are designed to defend the chosen ciphertext attacks by introducing the power of ciphertext validity checking based on randomness recovery. However, the ability of randomness recovery conflicts with the ideal PKE. We address this issue by adding just one additional random oracle hash, which prevents randomness recovery and allows us to achieve the idealized versions of FO and OAEP.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ideal Transformations for Public Key Encryption

  • Yao Cheng,
  • Xianhui Lu,
  • Ziyi Li

摘要

This paper introduces the concept of “ideal transformations”, which refers to transformations between two ideal primitives that capture the security boundaries of cryptographic schemes. Specifically, if the starting point is an ideal scheme, then the ending point of an ideal transformation should also be an ideal scheme. In other words, an ideal transformation will never weaken the security properties of the scheme. Building on the security enhancements provided by existing transformations, we propose a new perspective on public key encryption (PKE) design, viewing it from the ideal transformation point. Our goal is to lift existing transformations to their ideal forms. We explore the most popular transformations in PKE design, including Fujisaki-Okamoto (FO) and Optimal Asymmetric Encryption Padding (OAEP). We show that they bring weaknesses during transformation, and demonstrate how to lift them to ideal forms. Specifically, FO and OAEP are designed to defend the chosen ciphertext attacks by introducing the power of ciphertext validity checking based on randomness recovery. However, the ability of randomness recovery conflicts with the ideal PKE. We address this issue by adding just one additional random oracle hash, which prevents randomness recovery and allows us to achieve the idealized versions of FO and OAEP.