Advanced Cryptography 1st Semester Public Encryption

Size: px
Start display at page:

Download "Advanced Cryptography 1st Semester Public Encryption"

Transcription

1 Advanced Cryptography 1st Semester Pascal Lafourcade Université Joseph Fourrier, Verimag Master: October 1st / 64

2 Last Time (I) Indistinguishability Negligible function Probabilities Indistinguishability definition Hybrid argument Remarks, questions, comments? 2 / 64

3 Last Time (II) Exercises done 1) Negligible functions 2) Probabilities 3 5) Indistinguishability 3 / 64

4 Outline of Today: Security Notions 1 Cyclic Groups 4 / 64

5 Outline of Today: Security Notions 1 Cyclic Groups 2 Hard Problems 4 / 64

6 Outline of Today: Security Notions 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 / 64

7 Outline of Today: Security Notions 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 4 / 64

8 Outline of Today: Security Notions 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 4 / 64

9 Outline of Today: Security Notions 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 4 / 64

10 Outline of Today: Security Notions 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 4 / 64

11 Cyclic Groups Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 5 / 64

12 Cyclic Groups Definitions (I) A group (G, ) is composed of a set G and a binary operator on G which satisfy the three following axioms: a, b, c G, a (b c) = (a b) c e G, a G, e a = a e = a a G, b G, a b = b a = e Associativity Neutral Element Inverse Element b is called the inverse of a and is denoted by a 1. Example (Z, +), (Z/nZ, +), permutation group, (M (n,n), +). Counter-Example (N, +), (M (n,n), ) 6 / 64

13 Cyclic Groups Definitions (II) Cyclic Group A group G is cyclic if G is finite and there exists an element g of G such that: a G, n N, a = g n Element g is called a generator of group G. Example If p is a prime number, then Z/pZ is a cyclic group. 7 / 64

14 Hard Problems Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 8 / 64

15 Hard Problems Integer Factoring and RSA Use of algorithmically hard problems. Factorization p, q n = p.q n = p.q p, q easy (quadratic) difficult RSA function n = pq, p and q primes. e: public exponent x x e mod n easy (cubic) y = x e x mod n difficult x = y d where d = e 1 mod φ(n) 9 / 64

16 Hard Problems Complexity Estimates Estimates for integer factoring Lenstra-Verheul 2000 Modulus Operations (bits) (log 2 ) years Can be used for RSA too. 10 / 64

17 Hard Problems The Diffie-Hellman Key Exchange Protocol Let g be a generator of a cyclic group of prime order q. A B : g a B A : g b A B : {N} g ab 11 / 64

18 Hard Problems Hard Problems Most cryptographic constructions are based on hard problems. Their security is proved by reduction to these problems: Discrete Logarithm problem, DL. Given a group g and g x, compute x. Computational Diffie-Hellman, CDH Given a group g, g x and g y, compute g xy. Decisional Diffie-Hellman, DDH Given a group g, distinguish between the distributions (g x, g y, g xy ) and (g x, g y, g r ). RSA. Given N = pq and e Z ϕ(n), compute the inverse of e modulo ϕ(n) = (p 1)(q 1). Factorization 12 / 64

19 Hard Problems Relation between the problems Prop DL CDH DDH. Prop (Moaurer & Wolf) For many groups, DL CDH Prop (Joux & Wolf) There are groups for which DDH is easier than CDH. 13 / 64

20 Hard Problems Usage of DH assumption The Diffie-Hellman problems are widely used in cryptography: Public key cryptosystems [ElGamal, Cramer& Shoup] Pseudo-random functions [Noar& Reingold, Canetti] Pseudo-random generators [Blum& Micali] (Group) key exchange protocols [many] 14 / 64

21 Hard Problems Example: ElGamal Encryption Scheme Key generation: Alice chooses a prime number p and a group generator g of (Z/pZ) and a (Z/(p 1)Z). Public key: (p, g, h), where h = g a mod p. Private key: a Encryption: Bob chooses r R (Z/(p 1)Z) and computes (u, v) = (g r, Mh r ) Decryption: Given (u, v), Alice computes M p v u a Justification: v u a = Mh r g ra p M Remarque: re-usage of the same random r leads to a security flaw: M 1 h r M 2 h r p M 1 M 2 Practical Inconvenience: Cipher is twice as long as plain text. 15 / 64

22 Ideas of Security Notions Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 16 / 64

23 Ideas of Security Notions Adversary Model Qualities of the adversary: Clever: Can perform all operations he wants Limited time: Do not consider attack in Otherwise a Brute force by enumeration is always possible. Model used: Any Turing Machine. Represents all possible algorithms. Probabilistic: adversary can generates keys, random number / 64

24 Ideas of Security Notions One-Wayness (OW) Without the private key, it is computationally impossible to recover the plain-text. (Near of Perfect Security of Shannon) 18 / 64

25 Ideas of Security Notions Not enough Does not exclude to recover half of the plain-text Even worse if one has already partial information of the message: Subject: XXXX From: XXXX 19 / 64

26 Ideas of Security Notions Indistinguishability (IND) The adversary is not able to guess in polynomial-time even a bit of the plain-text knowing the cipher-text, notion introduced by S. Goldwasser and S.Micali ([GM84]). 20 / 64

27 Ideas of Security Notions Non Malleability (NM) The adversary should not be able to produce a new cipher-text such that the plain-texts are meaningfully related, notion introduced by D. Dolev, C. Dwork and M. Naor in 1991 ([DDN91,BDPR98,BS99]). 21 / 64

28 Ideas of Security Notions Relations Non Malleability Indistinguishability One-Wayness 22 / 64

29 Ideas of Security Notions Adversary Models The adversary is given access to oracles : encryption of all messages of his choice decryption of all messages of his choice Three classical security levels: Chosen-Plain-text Attacks (CPA) Non adaptive Chosen-Cipher-text Attacks (CCA1) only before the challenge Adaptive Chosen-Cipher-text Attacks (CCA2) unlimited access to the oracle (except for the challenge) 23 / 64

30 Ideas of Security Notions Chosen-Plain-text Attacks (CPA) Adversary can obtain all cipher-texts from any plain-texts. It is always the case with a scheme. 24 / 64

31 Ideas of Security Notions Non adaptive Chosen-Cipher-text Attacks (CCA1) Adversary knows the public key, has access to a decryption oracle multiple times before to get the challenge (cipher-text), also called Lunchtime Attack introduced by M. Naor and M. Yung ([NY90]). 25 / 64

32 Ideas of Security Notions Adaptive Chosen-Cipher-text Attacks (CCA2) Adversary knows the public key, has access to a decryption oracle multiple times before and AFTER to get the challenge, but of course cannot decrypt the challenge (cipher-text) introduced by C. Rackoff and D. Simon ([RS92]). 26 / 64

33 Ideas of Security Notions Parallels Attacks (PA0, PA1) Introduced by M. Bellare and A. Sahai ([BS99]) to prove the link between NM and IND. PA0 = Chosen Cipher-text Parallel Attack, after getting the challenge the adversary can ask for decrypting a finite number of cipher-text all AT THE SAME TIME which can be dependent of the challenge, but not of responses to decryption oracle. PA1 = CCA1 followed by PA0. 27 / 64

34 Definitions of Security Notions Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 28 / 64

35 Definitions of Security Notions Asymmetric Encryption An asymmetric encryption scheme S = (K, E, D) is defined by K: key generation E: encryption D: decryption K(η) = (k e, k d ) E ke (m, r) = c D(c, k d ) = m 29 / 64

36 Definitions of Security Notions One-Wayness (OW) AdversaryA: any polynomial time Turing Machine (PPTM) Basic security notion: One-Wayness (OW) Without the private key, it is computationally impossible to recover the plain text: Pr m,r [A(c) = m c = E(m, r)] is negligible. 30 / 64

37 Definitions of Security Notions Indistinguishability (IND) Game Adversary: A = (A 1, A 2 ) 1 The adversary A 1 is given the public key pk. 2 The adversary A 1 chooses two messages m 0, m 1. 3 b = 0, 1 is chosen at random and c = E(m b ) is given to the adversary. 4 The adversary A 2 answers b. The probability Pr[b = b ] 1 2 sould be negligible. 31 / 64

38 Definitions of Security Notions The IND-CPA Games Given an encryption scheme S = (K, E, D). An adversary is a pair A = (A 1, A 2 ) of polynomial-time probabilistic algorithms, b {0, 1}. Let Ind b CPA (A) be the following algorithm: Generate (pk, sk) R K(η). (s, m 0, m 1 ) R A 1 (η,pk) b R A2 (η,pk, s, E(pk, m b )) return b. Then, we define the advantage against the IND-CPA game by: Adv Ind CPA S,A (η) = Pr[b R Ind 1 CPA (A) : b = 1] Pr[b R Ind 0 CPA (A) : b = 1] 32 / 64

39 Definitions of Security Notions The IND-CCA1 Games Given an encryption scheme S = (K, E, D). An adversary is a pair A = (A 1, A 2 ) of polynomial-time probabilistic algorithms, b {0, 1}. Let Ind b CCA1 (A) be the following algorithm: Generate (pk, sk) R K(η). (s, m 0, m 1 ) R A O 1 1 (η,pk) where O 1 = D b R A2 (η,pk, s, E(pk, m b )) return b. Then, we define the advantage against the IND-CCA1 game by: Adv Ind CCA1 S,A (η) = Pr[b R Ind 1 CCA1 (A) : b = 1] Pr[b R Ind 0 CCA1 (A) : b = 1] 33 / 64

40 Definitions of Security Notions The IND-CCA2 Games Given an encryption scheme S = (K, E, D). An adversary is a pair A = (A 1, A 2 ) of polynomial-time probabilistic algorithms, b {0, 1}. Let Ind b CCA2 (A) be the following algorithm: Generate (pk, sk) R K(η). (s, m 0, m 1 ) R A O 1 1 (η,pk) where O 1 = D b R A O 2 2 (η,pk, s, E(pk, m b)) where O 2 = D return b. Then, we define the advantage against the IND-CCA2 game by: Adv Ind CCA2 S,A (η) = Pr[b R Ind 1 CCA2 (A) : b = 1] Pr[b R Ind 0 CCA2 (A) : b = 1] 34 / 64

41 Definitions of Security Notions IND-XXX Security Definition An encryption scheme is IND-XXX secure, if for any adversary A the function Adv IND XXX S,A is negligible. Exercice Prove that Adv Ind XXX S,A (η) = Pr[b R Ind 1 (A) : b = 1] Pr[b R Ind 0 (A) : b = 1] = 2Pr[b R Ind b (A) : b = b] 1 35 / 64

42 Definitions of Security Notions Summery of IND-XXX Games Given S = (K, E, D), A = (A 1, A 2 ) of polynomial-time probabilistic algorithms. Ind b XXX (A) follows: Generate (pk, sk) R K(η). (s, m 0, m 1 ) R A O 1 1 (η,pk) b R A O 2 2 (η,pk, s, E(pk, m b)) return b. Adv Ind XXX S,A (η) = Pr[b R Ind 1 XXX (A) : b = 1] Pr[b R Ind 0 XXX (A) : b = 1] IND-CPA, IND-CCA1, IND-CCA2 IND-CPA: O 1 = O 2 = Chosen Plain text Attack IND-CCA1: O 1 = {D}, O 2 = Non-adaptive Chosen Cipher text Attack IND-CCA2: O 1 = O 2 = {D} Adaptive Chosen Cipher text Attack. 36 / 64

43 Definitions of Security Notions Non Malleability Game Adversary: A = (A 1, A 2 ) 1 The adversary A 1 is given the public key pk. 2 The adversary A 1 chooses a message space M. 3 Two messages m and m are chosen at random in M and c = E(m; r) is given to the adversary. 4 The adversary A 2 outputs a binary relation R and a cipher-text c. Probability Pr[R(m, m )] Pr[R(m, m )] is negligible, where m = D(c ) 37 / 64

44 Definitions of Security Notions The NM-XXX Games Given S = (K, E, D). An adversary A = (A 1, A 2 ) of polynomial-time probabilistic algorithms, m,m,m M. Let NM b XXX (A): Generate (pk,sk) R K(η). (s,m) R A O1 1 (η,pk),m 0,m 1, M (R,C ) R A O2 2 (η,pk,s,m, E(pk,m b)),m D(C ) return R(m b,m ) Then, we define the advantage against the IND-CCA2 game by: Adv NM XXX S,A (η) = Pr[R(m,M ) R NMXXX 1 (A) : R(m,M ) = 1] Pr[R(m,M ) R NMXXX 0 (A) : R(m,M ) = 1] NM-CPA: O 1 = O 2 = Chosen Plain text Attack NM-CCA1: O 1 = {D}, O 2 = Non-adaptive Chosen Cipher text Attack NM-CCA2: O 1 = O 2 = {D} Adaptive Chosen Cipher text Attack. 38 / 64

45 Definitions of Security Notions Relations NM-CPA NM-CCA1 NM-CCA2 IND-CPA IND-CCA1 IND-CCA2 OW-CPA Relations Among Notions of Security for Public-Key Encryption Schemes, Crypto 98, by Mihir Bellare, Anand Desai, David Pointcheval and Phillip Rogaway [BDPR 98] 39 / 64

46 Definitions of Security Notions Relations NM-CPA NM-CCA1 NM-CCA2 IND-CPA IND-CCA1 IND-CCA2 minimal security OW-CPA weak security strong security Relations Among Notions of Security for Public-Key Encryption Schemes, Crypto 98, by Mihir Bellare, Anand Desai, David Pointcheval and Phillip Rogaway [BDPR 98] 39 / 64

47 Examples Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 40 / 64

48 Examples RSA Example: RSA public n = pq e (public key) private d = e 1 mod φ(n) (private key) RSA Encryption E(m) = m e mod n D(c) = c d mod n OW-CPA = RSA problem by definition! 41 / 64

49 Examples RSA IND-XXX and the Determinism Prop The encryption algorithm of an IND-XXX scheme must probabilistic, if it is stateless. Proof. An exercise. 42 / 64

50 Examples Diffie-Hellman The Discret Logarithm (DL) Let G = ( g, ) be any finite cyclic group of prime order. Idea: it is hard for any adversary to produce x if he only knows g x. For any adversary A, [ ] Adv DL (A) = Pr A(g x ) x x, y R [1, q] is negligible. 43 / 64

51 Examples Diffie-Hellman Computational Diffie-Hellman (CDH) Idea: it is hard for any adversary to produce g xy if he only knows g x and g y. For any adversary A, ] Adv CDH (A) = Pr [A(g x, g y ) g xy x, R y [1, q] is negligible. 44 / 64

52 Examples Diffie-Hellman Decisional Diffie-Hellman (DDH) Idea: Knowing g x and g y, it should be hard for any adversary to distinguish between g xy and g r for some random value r. For any adversary A, the advantage of A [ ] Adv DDH (A) = Pr A(g x, g y, g xy ) 1 x, y R [1, q] [ ] Pr A(g x, g y, g r ) 1 x, y, r R [1, q] is negligible. This means that an adversary cannot extract a single bit of information on g xy from g x and g y. 45 / 64

53 Examples Diffie-Hellman DDH CDH DL Exercice DDH CDH DL 46 / 64

54 Examples ElGamal Recall Elgamal G = ( g, ) finite cyclic group of prime order q. x: private key. y = g x : public key. E(m; r) = (g r, y r m) (c, d) and D(c, d) = d c x OW = CDH Assumption IND-CPA= DDH Assumption 47 / 64

55 Examples ElGamal OW-CPA for Elgamal Exercice Prove that under CDH assumption El-Gamal is OW-CPA. 48 / 64

56 Examples ElGamal IND-CPA for Elgamal Exercice Prove that under DDH assumption El-Gamal is IND-CPA. 49 / 64

57 Proofs Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 50 / 64

58 Proofs IND-CCA2 NM-CCA2 Intuition for IND-CCA2 NM-CCA2 Non-malleability deals with the ability to output ciphertexts. As the adversary is granted access to the decryption oracle during its whole attack, it can decrypt any ciphertext it outputs. The ability to output ciphertexts is thus not likely to increase the power of the adversary. 51 / 64

59 Proofs IND-CCA2 NM-CCA2 Main Idea We assume the scheme PE is secure in the IND-CCA2 sense. We let B = (B 1, B 2 ) be an NM-CCA2 adversary attacking PE. We must show that Adv NM CCA2 PE,B (k) is negligible. We construct an IND-CCA2 adversary A attacking the scheme, using B. Comparing these two advesaries, we show the advantages are such that : Adv NM CCA2 PE,B (k) = 2 Adv IND CCA2 PE,A (k) 52 / 64

60 Proofs IND-CCA2 NM-CCA2 Algorithm of Attack Algorithm A D sk 1 (pk) (s, M) R B D sk 1 (pk); (m 0, m 1 ) R M; s (m 0, m 1, M, s); Return (m 0, m 1, s ). Algorithm A D sk 2 (s, y) (R, C ) R B D sk 2 (M, s, y); M D sk ( C ); if R(m 0, M ) then d 0 else d R {0, 1}. Return d. 53 / 64

61 Proofs IND-CCA2 NM-CCA2 Notation Adv IND CCA2 PE,A (k) = pk(0) pk(1) p k (b) = Pr[(pk,sk) K(η);(s,m 0,m 1 ) A D sk 1 (pk) : A D sk 2 (s, E(pk,m b )) = 0] Adv NM CCA2 PE,B (k) = pk (0) pk (1) p k(b) = Pr[(pk,sk) K(η);(s,M) R B D sk 1 (pk);(m 0,m 1 ) R M; (R, C ) R B D sk 2 (M,s, E(pk,m b )) M D sk ( C ); R(m b, M )] 54 / 64

62 Proofs IND-CCA2 NM-CCA2 End of the Proof p k (0) = p k (0).Pr[d = 0 R(m 0, M)] + (1 p k (0)).Pr[d = 0 coinflip] = p k (0) p k (0) = 1 2 (1 + p k (0)) p k (1) = 1 2 (1 + p k (1)) Adv IND CCA2 PE,A (k) = pk(0) pk(1) = 1 2 (1 + p k (0)) 1 2 (1 + p k (1)) = 1 2 (p k (0) p k (1)) = 1 2 AdvNM CCA2 PE,B (k) 55 / 64

63 Proofs IND-CCA1 NM-CPA Idea:IND-CCA1 NM-CPA Assume there exists some IND-CCA1 secure encryption PE. We modifiy PE to build PE which is also IND-CCA1 secure but not NM-CPA secure. 56 / 64

64 Proofs IND-CCA1 NM-CPA Algorithm PE : Algorithm E pk (x) y 1 R Epk (x); y 2 R Epk (x); Return y 1 y 2 Where y 1 y 2 is a pair, and x us the bitwise complement of x. Algorithm D sk (y 1 y 2 ) Return D sk (y 1 ). 57 / 64

65 Proofs IND-CCA1 NM-CPA PE is not NM-CPA: Idea Given a cipher text y 1 y 2 of a messge x it is easy to create a cipher of x: just output y 2 y 1.Thus the scheme is malleable. Formally: A = (A 1, A 2 ) breaks PE in the sense of NM-CPA. (, M) R A 1 (pk), where M puts unforms distribution on {0, 1} k (R, y 2 y 1 ) R A 2 (, M, y 1 y 2 ), where R(m 1, m 2 ) = 1 if m 1 = m 2 Adv NM CPA PE,B (k) = 1 2 k 58 / 64

66 Proofs IND-CCA1 NM-CPA PE is IND-CPA: Idea Let B = (B 1, B 2 ) be some polynomial time adversary attacking PE in the IND-CCA1 sense. Show that Adv IND CCA1 PE,B (k) is negligible, using an hybrid argument. p k (i, j) = Pr[(s, m 0, m 1 ) R B D sk 1 ; y 1 R Epk (x i ); y 2 R Epk (x j ) : B 2 (s, m 0, m 1, y 1 y 2 ) = 1] Adv IND CCA1 PE,B (k) = p k (1, 1) p k (0, 0) Adv IND CCA1 PE,B (k) = p k (1, 1) p k (1, 0) + p k (1, 0) p k (0, 0) 59 / 64

67 Proofs IND-CCA1 NM-CPA Claim 1: p k (1, 1) p k (1, 0) is negligible Algorithm A D sk 1 (pk) (s,m 0,m 1 ) R B D sk 1 (pk); Return (m 0,m 1,s). Algorithm A 2 (s,m 0,m 1,y) (R, C ) R B D sk 2 (M,s,y); d R B 2 (m 0,m 1,s, E pk (m 1 ) y); Return d. Pr[(m 0,m 1,s) R A D sk 1 (pk) : A 2 (m 0,m 1,s, E pk (m 1 )] = p k (1,1) Pr[(m 0,m 1,s) R A D sk 1 (pk) : A 2 (m 0,m 1,s, E pk (m 0 )] = p k (1,0) Adv IND CCA1 PE,A (k) = p k (1,1) p k (0,0) is negligible, assumng security of PE in the IND-CCA1 sense. 60 / 64

68 Proofs IND-CCA1 NM-CPA Claim 2: p k (1, 0) p k (0, 0) is negligible Algorithm A D sk 1 (pk) (x 0,x 1,s) R B D sk 1 (pk); Return (x 0,x 1,s). Algorithm A 2 (x 0,x 1,s,y) (R, C ) R B D sk 2 (M,s,y); d R B 2 (x 0,x 1,s,y E pk (x 0 )); Return d. Pr[(x 0,x 1,s) R A D sk 1 (pk) : A 2 (x 0,x 1,s, E pk (x 1 )] = p k (1,0) Pr[(x 0,x 1,s) R A D sk 1 (pk) : A 2 (x 0,x 1,s, E pk (x 0 )] = p k (0,0) Adv IND CCA1 PE,A (k) = p k (1,0) p k (0,0) is negligible, assumng security of PE in the IND-CCA1 sense. 61 / 64

69 Conclusion Outline 1 Cyclic Groups 2 Hard Problems 3 Ideas of Security Notions 4 Definitions of Security Notions 5 Examples RSA Diffie-Hellman ElGamal 6 Proofs IND-CCA2 NM-CCA2 IND-CCA1 NM-CPA 7 Conclusion 62 / 64

70 Conclusion Summary Today Cyclic Groups Hard Problems One-way IND-CPA, IND-CCA1, IND-CCA2 NM-CPA, NM-CCA1, NM-CCA2 Examples RSA ElGamal IND-CCA2 NM-CCA2 NM-CCA1 NM-CPA 63 / 64

71 Conclusion Thank you for your attention. Questions? 64 / 64

Lecture Note 3 Date:

Lecture Note 3 Date: P.Lafourcade Lecture Note 3 Date: 28.09.2009 Security models 1st Semester 2007/2008 ROUAULT Boris GABIAM Amanda ARNEDO Pedro 1 Contents 1 Perfect Encryption 3 1.1 Notations....................................

More information

Models and analysis of security protocols 1st Semester Symmetric Encryption Lecture 5

Models and analysis of security protocols 1st Semester Symmetric Encryption Lecture 5 Models and analysis of security protocols 1st Semester 2009-2010 Symmetric Encryption Lecture 5 Pascal Lafourcade Université Joseph Fourier, Verimag Master: September 29th 2009 1 / 60 Last Time (I) Security

More information

Provable Security for Public-Key Schemes. Outline. I Basics. Secrecy of Communications. Outline. David Pointcheval

Provable Security for Public-Key Schemes. Outline. I Basics. Secrecy of Communications. Outline. David Pointcheval Provable Security for Public-Key Schemes I Basics David Pointcheval Ecole normale supérieure, CNRS & INRIA IACR-SEAMS School Cryptographie: Foundations and New Directions November 2016 Hanoi Vietnam Introduction

More information

Provable security. Michel Abdalla

Provable security. Michel Abdalla Lecture 1: Provable security Michel Abdalla École normale supérieure & CNRS Cryptography Main goal: Enable secure communication in the presence of adversaries Adversary Sender 10110 10110 Receiver Only

More information

The Cramer-Shoup Cryptosystem

The Cramer-Shoup Cryptosystem The Cramer-Shoup Cryptosystem Eileen Wagner October 22, 2014 1 / 28 The Cramer-Shoup system is an asymmetric key encryption algorithm, and was the first efficient scheme proven to be secure against adaptive

More information

ASYMMETRIC ENCRYPTION

ASYMMETRIC ENCRYPTION ASYMMETRIC ENCRYPTION 1 / 1 Recommended Book Steven Levy. Crypto. Penguin books. 2001. A non-technical account of the history of public-key cryptography and the colorful characters involved. 2 / 1 Recall

More information

Models and analysis of security protocols 1st Semester Symmetric Encryption Lecture 5

Models and analysis of security protocols 1st Semester Symmetric Encryption Lecture 5 Models and analysis of security protocols 1st Semester 2010-2011 Symmetric Encryption Lecture 5 Pascal Lafourcade Université Joseph Fourier, Verimag Master: October 11th 2010 1 / 61 Last Time (I) Security

More information

Lecture 9 Julie Staub Avi Dalal Abheek Anand Gelareh Taban. 1 Introduction. 2 Background. CMSC 858K Advanced Topics in Cryptography February 24, 2004

Lecture 9 Julie Staub Avi Dalal Abheek Anand Gelareh Taban. 1 Introduction. 2 Background. CMSC 858K Advanced Topics in Cryptography February 24, 2004 CMSC 858K Advanced Topics in Cryptography February 24, 2004 Lecturer: Jonathan Katz Lecture 9 Scribe(s): Julie Staub Avi Dalal Abheek Anand Gelareh Taban 1 Introduction In previous lectures, we constructed

More information

Introduction to Cybersecurity Cryptography (Part 4)

Introduction to Cybersecurity Cryptography (Part 4) Introduction to Cybersecurity Cryptography (Part 4) Review of Last Lecture Blockciphers Review of DES Attacks on Blockciphers Advanced Encryption Standard (AES) Modes of Operation MACs and Hashes Message

More information

Public-Key Encryption: ElGamal, RSA, Rabin

Public-Key Encryption: ElGamal, RSA, Rabin Public-Key Encryption: ElGamal, RSA, Rabin Introduction to Modern Cryptography Benny Applebaum Tel-Aviv University Fall Semester, 2011 12 Public-Key Encryption Syntax Encryption algorithm: E. Decryption

More information

Introduction to Cryptography. Lecture 8

Introduction to Cryptography. Lecture 8 Introduction to Cryptography Lecture 8 Benny Pinkas page 1 1 Groups we will use Multiplication modulo a prime number p (G, ) = ({1,2,,p-1}, ) E.g., Z 7* = ( {1,2,3,4,5,6}, ) Z p * Z N * Multiplication

More information

Introduction to Cybersecurity Cryptography (Part 4)

Introduction to Cybersecurity Cryptography (Part 4) Introduction to Cybersecurity Cryptography (Part 4) Review of Last Lecture Blockciphers Review of DES Attacks on Blockciphers Advanced Encryption Standard (AES) Modes of Operation MACs and Hashes Message

More information

Public-Key Cryptography. Lecture 9 Public-Key Encryption Diffie-Hellman Key-Exchange

Public-Key Cryptography. Lecture 9 Public-Key Encryption Diffie-Hellman Key-Exchange Public-Key Cryptography Lecture 9 Public-Key Encryption Diffie-Hellman Key-Exchange Shared/Symmetric-Key Encryption (a.k.a. private-key encryption) SKE: Syntax KeyGen outputs K K E scheme E Syntax a.k.a.

More information

On The Security of The ElGamal Encryption Scheme and Damgård s Variant

On The Security of The ElGamal Encryption Scheme and Damgård s Variant On The Security of The ElGamal Encryption Scheme and Damgård s Variant J. Wu and D.R. Stinson David R. Cheriton School of Computer Science University of Waterloo Waterloo, ON, Canada {j32wu,dstinson}@uwaterloo.ca

More information

Short Exponent Diffie-Hellman Problems

Short Exponent Diffie-Hellman Problems Short Exponent Diffie-Hellman Problems Takeshi Koshiba 12 and Kaoru Kurosawa 3 1 Secure Computing Lab., Fujitsu Laboratories Ltd. 2 ERATO Quantum Computation and Information Project, Japan Science and

More information

Lecture 17 - Diffie-Hellman key exchange, pairing, Identity-Based Encryption and Forward Security

Lecture 17 - Diffie-Hellman key exchange, pairing, Identity-Based Encryption and Forward Security Lecture 17 - Diffie-Hellman key exchange, pairing, Identity-Based Encryption and Forward Security Boaz Barak November 21, 2007 Cyclic groups and discrete log A group G is cyclic if there exists a generator

More information

Lecture 17: Constructions of Public-Key Encryption

Lecture 17: Constructions of Public-Key Encryption COM S 687 Introduction to Cryptography October 24, 2006 Lecture 17: Constructions of Public-Key Encryption Instructor: Rafael Pass Scribe: Muthu 1 Secure Public-Key Encryption In the previous lecture,

More information

Outline. The Game-based Methodology for Computational Security Proofs. Public-Key Cryptography. Outline. Introduction Provable Security

Outline. The Game-based Methodology for Computational Security Proofs. Public-Key Cryptography. Outline. Introduction Provable Security The Game-based Methodology for Computational s David Pointcheval Ecole normale supérieure, CNRS & INRIA Computational and Symbolic Proofs of Security Atagawa Heights Japan April 6th, 2009 1/39 2/39 Public-Key

More information

Advanced Topics in Cryptography

Advanced Topics in Cryptography Advanced Topics in Cryptography Lecture 6: El Gamal. Chosen-ciphertext security, the Cramer-Shoup cryptosystem. Benny Pinkas based on slides of Moni Naor page 1 1 Related papers Lecture notes of Moni Naor,

More information

A Practical Elliptic Curve Public Key Encryption Scheme Provably Secure Against Adaptive Chosen-message Attack

A Practical Elliptic Curve Public Key Encryption Scheme Provably Secure Against Adaptive Chosen-message Attack A Practical Elliptic Curve Public Key Encryption Scheme Provably Secure Against Adaptive Chosen-message Attack Huafei Zhu InfoComm Security Department, Institute for InfoComm Research. 21 Heng Mui Keng

More information

ENEE 457: Computer Systems Security 10/3/16. Lecture 9 RSA Encryption and Diffie-Helmann Key Exchange

ENEE 457: Computer Systems Security 10/3/16. Lecture 9 RSA Encryption and Diffie-Helmann Key Exchange ENEE 457: Computer Systems Security 10/3/16 Lecture 9 RSA Encryption and Diffie-Helmann Key Exchange Charalampos (Babis) Papamanthou Department of Electrical and Computer Engineering University of Maryland,

More information

5.4 ElGamal - definition

5.4 ElGamal - definition 5.4 ElGamal - definition In this section we define the ElGamal encryption scheme. Next to RSA it is the most important asymmetric encryption scheme. Recall that for a cyclic group G, an element g G is

More information

ON CIPHERTEXT UNDETECTABILITY. 1. Introduction

ON CIPHERTEXT UNDETECTABILITY. 1. Introduction Tatra Mt. Math. Publ. 41 (2008), 133 151 tm Mathematical Publications ON CIPHERTEXT UNDETECTABILITY Peter Gaži Martin Stanek ABSTRACT. We propose a novel security notion for public-key encryption schemes

More information

Equivalence between Semantic Security and Indistinguishability against Chosen Ciphertext Attacks

Equivalence between Semantic Security and Indistinguishability against Chosen Ciphertext Attacks Equivalence between Semantic Security and Indistinguishability against Chosen Ciphertext Attacks Yodai Watanabe 1, Junji Shikata 2, and Hideki Imai 3 1 RIKEN Brain Science Institute 2-1 Hirosawa, Wako-shi,

More information

Lecture 4 Chiu Yuen Koo Nikolai Yakovenko. 1 Summary. 2 Hybrid Encryption. CMSC 858K Advanced Topics in Cryptography February 5, 2004

Lecture 4 Chiu Yuen Koo Nikolai Yakovenko. 1 Summary. 2 Hybrid Encryption. CMSC 858K Advanced Topics in Cryptography February 5, 2004 CMSC 858K Advanced Topics in Cryptography February 5, 2004 Lecturer: Jonathan Katz Lecture 4 Scribe(s): Chiu Yuen Koo Nikolai Yakovenko Jeffrey Blank 1 Summary The focus of this lecture is efficient public-key

More information

Public Key Cryptography

Public Key Cryptography Public Key Cryptography Ali El Kaafarani 1 Mathematical Institute 2 PQShield Ltd. 1 of 44 Outline 1 Public Key Encryption: security notions 2 RSA Encryption Scheme 2 of 44 Course main reference 3 of 44

More information

CS 282A/MATH 209A: Foundations of Cryptography Prof. Rafail Ostrovsky. Lecture 7

CS 282A/MATH 209A: Foundations of Cryptography Prof. Rafail Ostrovsky. Lecture 7 CS 282A/MATH 209A: Foundations of Cryptography Prof. Rafail Ostrovsky Lecture 7 Lecture date: Monday, 28 February, 2005 Scribe: M.Chov, K.Leung, J.Salomone 1 Oneway Trapdoor Permutations Recall that a

More information

Public Key Cryptography

Public Key Cryptography Public Key Cryptography Ali El Kaafarani Mathematical Institute Oxford University 1 of 60 Outline 1 RSA Encryption Scheme 2 Discrete Logarithm and Diffie-Hellman Algorithm 3 ElGamal Encryption Scheme 4

More information

Chapter 11 : Private-Key Encryption

Chapter 11 : Private-Key Encryption COMP547 Claude Crépeau INTRODUCTION TO MODERN CRYPTOGRAPHY _ Second Edition _ Jonathan Katz Yehuda Lindell Chapter 11 : Private-Key Encryption 1 Chapter 11 Public-Key Encryption Apologies: all numbering

More information

RSA-OAEP and Cramer-Shoup

RSA-OAEP and Cramer-Shoup RSA-OAEP and Cramer-Shoup Olli Ahonen Laboratory of Physics, TKK 11th Dec 2007 T-79.5502 Advanced Cryptology Part I: Outline RSA, OAEP and RSA-OAEP Preliminaries for the proof Proof of IND-CCA2 security

More information

Lecture 19: Public-key Cryptography (Diffie-Hellman Key Exchange & ElGamal Encryption) Public-key Cryptography

Lecture 19: Public-key Cryptography (Diffie-Hellman Key Exchange & ElGamal Encryption) Public-key Cryptography Lecture 19: (Diffie-Hellman Key Exchange & ElGamal Encryption) Recall In private-key cryptography the secret-key sk is always established ahead of time The secrecy of the private-key cryptography relies

More information

Cryptography and Network Security Prof. D. Mukhopadhyay Department of Computer Science and Engineering Indian Institute of Technology, Kharagpur

Cryptography and Network Security Prof. D. Mukhopadhyay Department of Computer Science and Engineering Indian Institute of Technology, Kharagpur Cryptography and Network Security Prof. D. Mukhopadhyay Department of Computer Science and Engineering Indian Institute of Technology, Kharagpur Module No. # 01 Lecture No. # 33 The Diffie-Hellman Problem

More information

G Advanced Cryptography April 10th, Lecture 11

G Advanced Cryptography April 10th, Lecture 11 G.30-001 Advanced Cryptography April 10th, 007 Lecturer: Victor Shoup Lecture 11 Scribe: Kristiyan Haralambiev We continue the discussion of public key encryption. Last time, we studied Hash Proof Systems

More information

Lecture 1. 1 Introduction to These Notes. 2 Trapdoor Permutations. CMSC 858K Advanced Topics in Cryptography January 27, 2004

Lecture 1. 1 Introduction to These Notes. 2 Trapdoor Permutations. CMSC 858K Advanced Topics in Cryptography January 27, 2004 CMSC 858K Advanced Topics in Cryptography January 27, 2004 Lecturer: Jonathan Katz Lecture 1 Scribe(s): Jonathan Katz 1 Introduction to These Notes These notes are intended to supplement, not replace,

More information

Advanced Cryptography 03/06/2007. Lecture 8

Advanced Cryptography 03/06/2007. Lecture 8 Advanced Cryptography 03/06/007 Lecture 8 Lecturer: Victor Shoup Scribe: Prashant Puniya Overview In this lecture, we will introduce the notion of Public-Key Encryption. We will define the basic notion

More information

Technische Universität München (I7) Winter 2013/14 Dr. M. Luttenberger / M. Schlund SOLUTION. Cryptography Endterm

Technische Universität München (I7) Winter 2013/14 Dr. M. Luttenberger / M. Schlund SOLUTION. Cryptography Endterm Technische Universität München (I7) Winter 2013/14 Dr. M. Luttenberger / M. Schlund SOLUTION Cryptography Endterm Exercise 1 One Liners 1.5P each = 12P For each of the following statements, state if it

More information

Outline. Provable Security in the Computational Model. III Signatures. Public-Key Encryption. Outline. David Pointcheval.

Outline. Provable Security in the Computational Model. III Signatures. Public-Key Encryption. Outline. David Pointcheval. Provable Security in the Computational Model III Signatures David Pointcheval Ecole normale supérieure, CNRS & INRI Public-Key Encryption Signatures 2 dvanced Security for Signature dvanced Security Notions

More information

Cryptography IV: Asymmetric Ciphers

Cryptography IV: Asymmetric Ciphers Cryptography IV: Asymmetric Ciphers Computer Security Lecture 7 David Aspinall School of Informatics University of Edinburgh 31st January 2011 Outline Background RSA Diffie-Hellman ElGamal Summary Outline

More information

CS 4770: Cryptography. CS 6750: Cryptography and Communication Security. Alina Oprea Associate Professor, CCIS Northeastern University

CS 4770: Cryptography. CS 6750: Cryptography and Communication Security. Alina Oprea Associate Professor, CCIS Northeastern University CS 4770: Cryptography CS 6750: Cryptography and Communication Security Alina Oprea Associate Professor, CCIS Northeastern University March 26 2017 Outline RSA encryption in practice Transform RSA trapdoor

More information

Lecture 28: Public-key Cryptography. Public-key Cryptography

Lecture 28: Public-key Cryptography. Public-key Cryptography Lecture 28: Recall In private-key cryptography the secret-key sk is always established ahead of time The secrecy of the private-key cryptography relies on the fact that the adversary does not have access

More information

1 Number Theory Basics

1 Number Theory Basics ECS 289M (Franklin), Winter 2010, Crypto Review 1 Number Theory Basics This section has some basic facts about number theory, mostly taken (or adapted) from Dan Boneh s number theory fact sheets for his

More information

Public Key Cryptography

Public Key Cryptography Public Key Cryptography Ali El Kaafarani Mathematical Institute Oxford University 1 of 74 Outline 1 Complexity measures 2 Algebra and Number Theory Background 3 Public Key Encryption: security notions

More information

Security Issues in Cloud Computing Modern Cryptography II Asymmetric Cryptography

Security Issues in Cloud Computing Modern Cryptography II Asymmetric Cryptography Security Issues in Cloud Computing Modern Cryptography II Asymmetric Cryptography Peter Schwabe October 21 and 28, 2011 So far we assumed that Alice and Bob both have some key, which nobody else has. How

More information

Key-Privacy in Public-Key Encryption

Key-Privacy in Public-Key Encryption The extended abstract of this paper appeared in Advances in Cryptology Proceedings of Asiacrypt 2001 (9 13 december 2001, Gold Coast, Australia) C. Boyd Ed. Springer-Verlag, LNCS 2248, pages 566 582. Key-Privacy

More information

Introduction to Elliptic Curve Cryptography

Introduction to Elliptic Curve Cryptography Indian Statistical Institute Kolkata May 19, 2017 ElGamal Public Key Cryptosystem, 1984 Key Generation: 1 Choose a suitable large prime p 2 Choose a generator g of the cyclic group IZ p 3 Choose a cyclic

More information

How to Enhance the Security of Public-Key. Encryption at Minimum Cost 3. NTT Laboratories, 1-1 Hikarinooka Yokosuka-shi Kanagawa Japan

How to Enhance the Security of Public-Key. Encryption at Minimum Cost 3. NTT Laboratories, 1-1 Hikarinooka Yokosuka-shi Kanagawa Japan How to Enhance the Security of Public-Key Encryption at Minimum Cost 3 Eiichiro Fujisaki Tatsuaki Okamoto NTT Laboratories, 1-1 Hikarinooka Yokosuka-shi Kanagawa 239-0847 Japan ffujisaki,okamotog@isl.ntt.co.jp

More information

On the CCA1-Security of Elgamal and Damgård s Elgamal

On the CCA1-Security of Elgamal and Damgård s Elgamal On the CCA1-Security of Elgamal and Damgård s Elgamal Cybernetica AS, Estonia Tallinn University, Estonia October 21, 2010 Outline I Motivation 1 Motivation 2 3 Motivation Three well-known security requirements

More information

El Gamal A DDH based encryption scheme. Table of contents

El Gamal A DDH based encryption scheme. Table of contents El Gamal A DDH based encryption scheme Foundations of Cryptography Computer Science Department Wellesley College Fall 2016 Table of contents Introduction El Gamal Practical Issues The El Gamal encryption

More information

Chosen-Ciphertext Security without Redundancy

Chosen-Ciphertext Security without Redundancy This is the full version of the extended abstract which appears in Advances in Cryptology Proceedings of Asiacrypt 03 (30 november 4 december 2003, Taiwan) C. S. Laih Ed. Springer-Verlag, LNCS 2894, pages

More information

Probabilistic Polynomial-Time Process Calculus for Security Protocol Analysis. Standard analysis methods. Compositionality

Probabilistic Polynomial-Time Process Calculus for Security Protocol Analysis. Standard analysis methods. Compositionality Probabilistic Polynomial-Time Process Calculus for Security Protocol Analysis J. Mitchell, A. Ramanathan, A. Scedrov, V. Teague P. Lincoln, P. Mateus, M. Mitchell Standard analysis methods Finite-state

More information

f (x) f (x) easy easy

f (x) f (x) easy easy A General Construction of IND-CCA2 Secure Public Key Encryption? Eike Kiltz 1 and John Malone-Lee 2 1 Lehrstuhl Mathematik & Informatik, Fakultat fur Mathematik, Ruhr-Universitat Bochum, Germany. URL:

More information

ECS 189A Final Cryptography Spring 2011

ECS 189A Final Cryptography Spring 2011 ECS 127: Cryptography Handout F UC Davis Phillip Rogaway June 9, 2011 ECS 189A Final Cryptography Spring 2011 Hints for success: Good luck on the exam. I don t think it s all that hard (I do believe I

More information

Public-Key Cryptography. Lecture 10 DDH Assumption El Gamal Encryption Public-Key Encryption from Trapdoor OWP

Public-Key Cryptography. Lecture 10 DDH Assumption El Gamal Encryption Public-Key Encryption from Trapdoor OWP Public-Key Cryptography Lecture 10 DDH Assumption El Gamal Encryption Public-Key Encryption from Trapdoor OWP Diffie-Hellman Key-exchange Secure under DDH: (g x,g x,g xy ) (g x,g x,g r ) Random x {0,..,

More information

CS 282A/MATH 209A: Foundations of Cryptography Prof. Rafail Ostrosky. Lecture 4

CS 282A/MATH 209A: Foundations of Cryptography Prof. Rafail Ostrosky. Lecture 4 CS 282A/MATH 209A: Foundations of Cryptography Prof. Rafail Ostrosky Lecture 4 Lecture date: January 26, 2005 Scribe: Paul Ray, Mike Welch, Fernando Pereira 1 Private Key Encryption Consider a game between

More information

Simple SK-ID-KEM 1. 1 Introduction

Simple SK-ID-KEM 1. 1 Introduction 1 Simple SK-ID-KEM 1 Zhaohui Cheng School of Computing Science, Middlesex University The Burroughs, Hendon, London, NW4 4BT, United Kingdom. m.z.cheng@mdx.ac.uk Abstract. In 2001, Boneh and Franklin presented

More information

Definition: For a positive integer n, if 0<a<n and gcd(a,n)=1, a is relatively prime to n. Ahmet Burak Can Hacettepe University

Definition: For a positive integer n, if 0<a<n and gcd(a,n)=1, a is relatively prime to n. Ahmet Burak Can Hacettepe University Number Theory, Public Key Cryptography, RSA Ahmet Burak Can Hacettepe University abc@hacettepe.edu.tr The Euler Phi Function For a positive integer n, if 0

More information

Notes for Lecture 17

Notes for Lecture 17 U.C. Berkeley CS276: Cryptography Handout N17 Luca Trevisan March 17, 2009 Notes for Lecture 17 Scribed by Matt Finifter, posted April 8, 2009 Summary Today we begin to talk about public-key cryptography,

More information

Universal Hash Proofs and a Paradigm for Adaptive Chosen Ciphertext Secure Public-Key Encryption

Universal Hash Proofs and a Paradigm for Adaptive Chosen Ciphertext Secure Public-Key Encryption Universal Hash Proofs and a Paradigm for Adaptive Chosen Ciphertext Secure Public-Key Encryption Ronald Cramer Victor Shoup October 12, 2001 Abstract We present several new and fairly practical public-key

More information

Adaptive Security of Compositions

Adaptive Security of Compositions emester Thesis in Cryptography Adaptive ecurity of Compositions Patrick Pletscher ETH Zurich June 30, 2005 upervised by: Krzysztof Pietrzak, Prof. Ueli Maurer Email: pat@student.ethz.ch In a recent paper

More information

14 Diffie-Hellman Key Agreement

14 Diffie-Hellman Key Agreement 14 Diffie-Hellman Key Agreement 14.1 Cyclic Groups Definition 14.1 Example Let д Z n. Define д n = {д i % n i Z}, the set of all powers of д reduced mod n. Then д is called a generator of д n, and д n

More information

Lecture 8 Alvaro A. Cardenas Nicholas Sze Yinian Mao Kavitha Swaminathan. 1 Introduction. 2 The Dolev-Dwork-Naor (DDN) Scheme [1]

Lecture 8 Alvaro A. Cardenas Nicholas Sze Yinian Mao Kavitha Swaminathan. 1 Introduction. 2 The Dolev-Dwork-Naor (DDN) Scheme [1] CMSC 858K Advanced Topics in Cryptography February 19, 2004 Lecturer: Jonathan Katz Lecture 8 Scribe(s): Alvaro A. Cardenas Nicholas Sze Yinian Mao Kavitha Swaminathan 1 Introduction Last time we introduced

More information

Introduction to Modern Cryptography Recitation 3. Orit Moskovich Tel Aviv University November 16, 2016

Introduction to Modern Cryptography Recitation 3. Orit Moskovich Tel Aviv University November 16, 2016 Introduction to Modern Cryptography Recitation 3 Orit Moskovich Tel Aviv University November 16, 2016 The group: Z N Let N 2 be an integer The set Z N = a 1,, N 1 gcd a, N = 1 with respect to multiplication

More information

Notes for Lecture Decision Diffie Hellman and Quadratic Residues

Notes for Lecture Decision Diffie Hellman and Quadratic Residues U.C. Berkeley CS276: Cryptography Handout N19 Luca Trevisan March 31, 2009 Notes for Lecture 19 Scribed by Cynthia Sturton, posted May 1, 2009 Summary Today we continue to discuss number-theoretic constructions

More information

Computer Science A Cryptography and Data Security. Claude Crépeau

Computer Science A Cryptography and Data Security. Claude Crépeau Computer Science 308-547A Cryptography and Data Security Claude Crépeau These notes are, largely, transcriptions by Anton Stiglic of class notes from the former course Cryptography and Data Security (308-647A)

More information

Lemma 1.2. (1) If p is prime, then ϕ(p) = p 1. (2) If p q are two primes, then ϕ(pq) = (p 1)(q 1).

Lemma 1.2. (1) If p is prime, then ϕ(p) = p 1. (2) If p q are two primes, then ϕ(pq) = (p 1)(q 1). 1 Background 1.1 The group of units MAT 3343, APPLIED ALGEBRA, FALL 2003 Handout 3: The RSA Cryptosystem Peter Selinger Let (R, +, ) be a ring. Then R forms an abelian group under addition. R does not

More information

CS 395T. Probabilistic Polynomial-Time Calculus

CS 395T. Probabilistic Polynomial-Time Calculus CS 395T Probabilistic Polynomial-Time Calculus Security as Equivalence Intuition: encryption scheme is secure if ciphertext is indistinguishable from random noise Intuition: protocol is secure if it is

More information

ID-based Encryption Scheme Secure against Chosen Ciphertext Attacks

ID-based Encryption Scheme Secure against Chosen Ciphertext Attacks ID-based Encryption Scheme Secure against Chosen Ciphertext Attacks ongxing Lu and Zhenfu Cao Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai 200030, P.. China {cao-zf,

More information

14 Years of Chosen Ciphertext Security: A Survey of Public Key Encryption. Victor Shoup New York University

14 Years of Chosen Ciphertext Security: A Survey of Public Key Encryption. Victor Shoup New York University 14 Years of Chosen Ciphertext Security: A Survey of Public Key Encryption Victor Shoup New York University A Historical Perspective The wild years (mid 70 s-mid 80 s): Diffie-Hellman, RSA, ElGamal The

More information

Public-Key Cryptosystems CHAPTER 4

Public-Key Cryptosystems CHAPTER 4 Public-Key Cryptosystems CHAPTER 4 Introduction How to distribute the cryptographic keys? Naïve Solution Naïve Solution Give every user P i a separate random key K ij to communicate with every P j. Disadvantage:

More information

Lecture 11: Key Agreement

Lecture 11: Key Agreement Introduction to Cryptography 02/22/2018 Lecture 11: Key Agreement Instructor: Vipul Goyal Scribe: Francisco Maturana 1 Hardness Assumptions In order to prove the security of cryptographic primitives, we

More information

Chosen-Ciphertext Secure RSA-type Cryptosystems

Chosen-Ciphertext Secure RSA-type Cryptosystems Published in J. Pieprzyk and F. Zhang, Eds, Provable Security (ProvSec 2009), vol 5848 of Lecture Notes in Computer Science, pp. 32 46, Springer, 2009. Chosen-Ciphertext Secure RSA-type Cryptosystems Benoît

More information

Lossy Trapdoor Functions from Smooth Homomorphic Hash Proof Systems

Lossy Trapdoor Functions from Smooth Homomorphic Hash Proof Systems Lossy Trapdoor Functions from Smooth Homomorphic Hash Proof Systems Brett Hemenway UCLA bretth@mathuclaedu Rafail Ostrovsky UCLA rafail@csuclaedu January 9, 2010 Abstract In STOC 08, Peikert and Waters

More information

Permutation Generators Based on Unbalanced Feistel Network: Analysis of the Conditions of Pseudorandomness 1

Permutation Generators Based on Unbalanced Feistel Network: Analysis of the Conditions of Pseudorandomness 1 Permutation Generators Based on Unbalanced Feistel Network: Analysis of the Conditions of Pseudorandomness 1 Kwangsu Lee A Thesis for the Degree of Master of Science Division of Computer Science, Department

More information

RSA OAEP is Secure under the RSA Assumption

RSA OAEP is Secure under the RSA Assumption RSA OAEP is Secure under the RSA Assumption Eiichiro Fujisaki 1, Tatsuaki Okamoto 1, David Pointcheval 2, and Jacques Stern 2 1 NTT Labs, 1-1 Hikarino-oka, Yokosuka-shi, 239-0847 Japan. E-mail: {fujisaki,okamoto}@isl.ntt.co.jp.

More information

Introduction to Cybersecurity Cryptography (Part 5)

Introduction to Cybersecurity Cryptography (Part 5) Introduction to Cybersecurity Cryptography (Part 5) Prof. Dr. Michael Backes 13.01.2017 February 17 th Special Lecture! 45 Minutes Your Choice 1. Automotive Security 2. Smartphone Security 3. Side Channel

More information

Strongly Unforgeable Signatures Based on Computational Diffie-Hellman

Strongly Unforgeable Signatures Based on Computational Diffie-Hellman Strongly Unforgeable Signatures Based on Computational Diffie-Hellman Dan Boneh 1, Emily Shen 1, and Brent Waters 2 1 Computer Science Department, Stanford University, Stanford, CA {dabo,emily}@cs.stanford.edu

More information

2. Cryptography 2.5. ElGamal cryptosystems and Discrete logarithms

2. Cryptography 2.5. ElGamal cryptosystems and Discrete logarithms CRYPTOGRAPHY 19 Cryptography 5 ElGamal cryptosystems and Discrete logarithms Definition Let G be a cyclic group of order n and let α be a generator of G For each A G there exists an uniue 0 a n 1 such

More information

Type-based Proxy Re-encryption and its Construction

Type-based Proxy Re-encryption and its Construction Type-based Proxy Re-encryption and its Construction Qiang Tang Faculty of EWI, University of Twente, the Netherlands q.tang@utwente.nl Abstract. Recently, the concept of proxy re-encryption has been shown

More information

Encoding-Free ElGamal Encryption Without Random Oracles

Encoding-Free ElGamal Encryption Without Random Oracles Encoding-Free ElGamal Encryption Without Random Oracles Benoît Chevallier-Mames 1,2, Pascal Paillier 3, and David Pointcheval 2 1 Gemplus, Security Technology Department, La Vigie, Avenue du Jujubier,

More information

Practice Final Exam Winter 2017, CS 485/585 Crypto March 14, 2017

Practice Final Exam Winter 2017, CS 485/585 Crypto March 14, 2017 Practice Final Exam Name: Winter 2017, CS 485/585 Crypto March 14, 2017 Portland State University Prof. Fang Song Instructions This exam contains 7 pages (including this cover page) and 5 questions. Total

More information

Computational security & Private key encryption

Computational security & Private key encryption Computational security & Private key encryption Emma Arfelt Stud. BSc. Software Development Frederik Madsen Stud. MSc. Software Development March 2017 Recap Perfect Secrecy Perfect indistinguishability

More information

Non-malleability under Selective Opening Attacks: Implication and Separation

Non-malleability under Selective Opening Attacks: Implication and Separation Non-malleability under Selective Opening Attacks: Implication and Separation Zhengan Huang 1, Shengli Liu 1, Xianping Mao 1, and Kefei Chen 2,3 1. Department of Computer Science and Engineering, Shanghai

More information

Lecture 14 - CCA Security

Lecture 14 - CCA Security Lecture 14 - CCA Security Boaz Barak November 7, 2007 Key exchange Suppose we have following situation: Alice wants to buy something from the well known website Bob.com Since they will exchange private

More information

Network Security Technology Spring, 2018 Tutorial 3, Week 4 (March 23) Due Date: March 30

Network Security Technology Spring, 2018 Tutorial 3, Week 4 (March 23) Due Date: March 30 Network Security Technology Spring, 2018 Tutorial 3, Week 4 (March 23) LIU Zhen Due Date: March 30 Questions: 1. RSA (20 Points) Assume that we use RSA with the prime numbers p = 17 and q = 23. (a) Calculate

More information

A New Paradigm of Hybrid Encryption Scheme

A New Paradigm of Hybrid Encryption Scheme A New Paradigm of Hybrid Encryption Scheme Kaoru Kurosawa 1 and Yvo Desmedt 2 1 Ibaraki University, Japan kurosawa@cis.ibaraki.ac.jp 2 Dept. of Computer Science, University College London, UK, and Florida

More information

Relations Among Notions of Security for Public-Key Encryption Schemes. Debdeep Mukhopadhyay IIT Kharagpur. Notions

Relations Among Notions of Security for Public-Key Encryption Schemes. Debdeep Mukhopadhyay IIT Kharagpur. Notions Relations Among Notions of Security for Public-Key Encryption Schemes Debdeep Muhopadhyay IIT Kharagpur Notions To organize the definitions of secure encryptions Classified depending on: security goals:

More information

Extractable Perfectly One-way Functions

Extractable Perfectly One-way Functions Extractable Perfectly One-way Functions Ran Canetti 1 and Ronny Ramzi Dakdouk 2 1 IBM T. J. Watson Research Center, Hawthorne, NY. canetti@watson.ibm.com 2 Yale University, New Haven, CT. dakdouk@cs.yale.edu

More information

Lecture 6. 2 Adaptively-Secure Non-Interactive Zero-Knowledge

Lecture 6. 2 Adaptively-Secure Non-Interactive Zero-Knowledge CMSC 858K Advanced Topics in Cryptography February 12, 2004 Lecturer: Jonathan Katz Lecture 6 Scribe(s): Omer Horvitz John Trafton Zhongchao Yu Akhil Gupta 1 Introduction In this lecture, we show how to

More information

An Introduction to Probabilistic Encryption

An Introduction to Probabilistic Encryption Osječki matematički list 6(2006), 37 44 37 An Introduction to Probabilistic Encryption Georg J. Fuchsbauer Abstract. An introduction to probabilistic encryption is given, presenting the first probabilistic

More information

Parallel Decryption Queries in Bounded Chosen Ciphertext Attacks

Parallel Decryption Queries in Bounded Chosen Ciphertext Attacks Parallel Decryption Queries in Bounded Chosen Ciphertext Attacks Takahiro Matsuda and Kanta Matsuura The University of Tokyo, Japan {tmatsuda,kanta}@iis.u-tokyo.ac.jp Abstract. Whether it is possible to

More information

Non-Malleable Encryption: Equivalence between Two Notions, and an Indistinguishability-Based Characterization

Non-Malleable Encryption: Equivalence between Two Notions, and an Indistinguishability-Based Characterization A preliminary version of this paper appears in Advances in Cryptology CRYPTO 99, Lecture Notes in Computer Science Vol. 1666, M. Wiener ed., Springer-Verlag, 1999. This revised version corrects some mistakes

More information

TECHNISCHE UNIVERSITEIT EINDHOVEN Faculty of Mathematics and Computer Science Exam Cryptology, Friday 25 January 2019

TECHNISCHE UNIVERSITEIT EINDHOVEN Faculty of Mathematics and Computer Science Exam Cryptology, Friday 25 January 2019 Faculty of Mathematics and Computer Science Exam Cryptology, Friday 25 January 2019 Name : TU/e student number : Exercise 1 2 3 4 5 total points Notes: Please hand in all sheets at the end of the exam.

More information

1 What are Physical Attacks. 2 Physical Attacks on RSA. Today:

1 What are Physical Attacks. 2 Physical Attacks on RSA. Today: Today: Introduction to the class. Examples of concrete physical attacks on RSA A computational approach to cryptography Pseudorandomness 1 What are Physical Attacks Tampering/Leakage attacks Issue of how

More information

Lecture 1: Introduction to Public key cryptography

Lecture 1: Introduction to Public key cryptography Lecture 1: Introduction to Public key cryptography Thomas Johansson T. Johansson (Lund University) 1 / 44 Key distribution Symmetric key cryptography: Alice and Bob share a common secret key. Some means

More information

Non-malleable Encryption: Equivalence between Two Notions, and an Indistinguishability-Based Characterization

Non-malleable Encryption: Equivalence between Two Notions, and an Indistinguishability-Based Characterization Non-malleable Encryption: Equivalence between Two Notions, and an Indistinguishability-Based Characterization Mihir Bellare 1 and Amit Sahai 2 1 Dept. of Computer Science & Engineering, University of California

More information

Lecture 7: ElGamal and Discrete Logarithms

Lecture 7: ElGamal and Discrete Logarithms Lecture 7: ElGamal and Discrete Logarithms Johan Håstad, transcribed by Johan Linde 2006-02-07 1 The discrete logarithm problem Recall that a generator g of a group G is an element of order n such that

More information

Public Key Cryptography

Public Key Cryptography Public Key Cryptography Introduction Public Key Cryptography Unlike symmetric key, there is no need for Alice and Bob to share a common secret Alice can convey her public key to Bob in a public communication:

More information

Lecture Notes, Week 6

Lecture Notes, Week 6 YALE UNIVERSITY DEPARTMENT OF COMPUTER SCIENCE CPSC 467b: Cryptography and Computer Security Week 6 (rev. 3) Professor M. J. Fischer February 15 & 17, 2005 1 RSA Security Lecture Notes, Week 6 Several

More information

Efficient Identity-based Encryption Without Random Oracles

Efficient Identity-based Encryption Without Random Oracles Efficient Identity-based Encryption Without Random Oracles Brent Waters Weiwei Liu School of Computer Science and Software Engineering 1/32 Weiwei Liu Efficient Identity-based Encryption Without Random

More information

CSA E0 235: Cryptography March 16, (Extra) Lecture 3

CSA E0 235: Cryptography March 16, (Extra) Lecture 3 CSA E0 235: Cryptography March 16, 2015 Instructor: Arpita Patra (Extra) Lecture 3 Submitted by: Ajith S 1 Chosen Plaintext Attack A chosen-plaintext attack (CPA) is an attack model for cryptanalysis which

More information