Efficient public key encryption with smallest ciphertext expansion from factoring

Research output: Contribution to journalArticlepeer-review

2 Scopus citations

Abstract

For public key encryption schemes, adaptive chosen ciphertext security is a widely accepted security notion since it captures a wide range of attacks. SAEP and SAEP+ are asymmetric encryption schemes which were proven to achieve semantic security against adaptive chosen ciphertext attacks. However, the bandwidth for message is essentially worse, that is the ciphertext expansion (the length difference between the ciphertext and the plaintext) is too large. In most of the mobile networks and bandwidth constrained communication systems, it is necessary to securely send as many messages as possible. In this article, we propose two chosen-ciphertext secure asymmetric encryption schemes. The first scheme is a generic asymmetric encryption padding scheme based on trapdoor permutations. The second one is its application to the Rabin-Williams function which has a very fast encryption algorithm. These asymmetric encryption schemes both achieve the optimal bandwidth w.r.t. the ciphertext expansion, namely with the smallest ciphertext expansion. Further, tight security reductions are shown to prove the security of these encryption schemes.

Original languageEnglish
Pages (from-to)233-249
Number of pages17
JournalDesigns, Codes, and Cryptography
Volume49
Issue number1-3
DOIs
StatePublished - Dec 2008

Keywords

  • Encryption scheme
  • Factoring
  • Random oracle model
  • Random permutation model
  • SAEP
  • Tight security

Fingerprint

Dive into the research topics of 'Efficient public key encryption with smallest ciphertext expansion from factoring'. Together they form a unique fingerprint.

Cite this