【24h】

A Closer Look at Anonymity and Robustness in Encryption Schemes

机译:仔细看看加密方案中的匿名和稳健性

获取原文

摘要

In this work, we take a closer look at anonymity and robustness in encryption schemes. Roughly speaking, an anonymous encryption scheme hides the identity of the secret-key holder, while a robust encryption scheme guarantees that every ciphertext can only be decrypted to a valid plaintext under the intended recipient's secret key, In case of anonymous encryption, we show that if an anonymous PKE or IBE scheme (in presence of CCA attacks) is used in a hybrid encryption, all bets regarding the anonymity of the resulting encryption are off. We show that this is the case even if the symmetric-key component is anonymous. On the positive side, however, we prove that if the key-encapsulation method is, additionally weakly robust the resulting hybrid encryption remains anonymous. Some of the existing anonymous encryption schemes are known to be weakly robust which makes them more desirable in practice. In case of robust encryption, we design several efficient constructions for transforming any PKE/IBE scheme into weakly and strongly robust ones. Our constructions only add a minor computational overhead to the original schemes, while achieving better ciphertext sizes compared to the previous constructions. An important property of our transformations is that they are non-keyed and do not require any modifications to the public parameters of the original schemes. We also introduce a relaxation of the notion of robustness we call collision-freeness. We primarily use collision-freeness as an intermediate notion by showing a more efficient construction for transforming any collision-free encryption scheme into a strongly robust one. We believe that this simple notion can be a plausible replacement for robustness in some scenarios in practice. The advantage is that most existing schemes seem to satisfy collision-freeness without any modifications.
机译:在这项工作中,我们采取在加密方案的匿名性和稳健性一探究竟。粗略地说,一个匿名的加密方案揣秘密密钥持有者的身份,而一个强大的加密方案保证每个密文只能被解密的目标收件人的私钥下一个有效的明文,在匿名加密的情况下,我们表明,如果匿名PKE或IBE方案(在CCA攻击存在下)在一个混合加密时,关于所得到的加密的匿名所有的赌注都关闭。我们发现,这是即使对称密钥成分是匿名的情况下。从积极的一面,但是,我们证明了如果密钥封装方法是,附加弱健壮所得混合加密保持匿名。现有的一些匿名的加密方案被称为是弱强劲,这使得他们在实践中更可取。在强大的加密情况下,我们设计了几种有效的结构转化任何PKE / IBE方案到弱和较强的鲁棒性的。我们的结构只添加少量的计算开销原来的计划,而相比之前的结构实现更好的密文的大小。我们转变的一个重要特性是它们是非键,不需要到原计划的公共参数进行任何修改。我们还引入了鲁棒性的概念,我们称之为碰撞打浆度的放松。我们主要通过显示将任何无碰撞加密方案为较强的鲁棒一个更高效的建筑用碰撞游离度作为中间概念。我们认为,这一简单的概念可以在实践中的一些情景健壮性一个合理的替代品。其优点是,大多数现有的方案似乎满足了碰撞打浆度无需做任何修改。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号