On Tight Multi-Challenge-Multi-User CCA2 Security in the QROM

Pouria Fallahpour;Benoît Libert;Peters, Thomas;et.al.
(2022) , 41 pages

Files

No attached file found for this publication.

Details

Authors
  • Pouria FallahpourENS de Lyon, France
    Author
  • Benoît LibertZama, France
    Author
  • Author
  • et. al.
Abstract
In the quantum random oracle model, despite intensive recent research efforts, we are still lacking a public-key encryption scheme that can be proven tightly secure in the IND-CCA sense in a multi-user environment when the adversary obtains multiple challenge ciphertexts. To fill this gap, we put forth lattice-based schemes whose chosen-ciphertext security in the multi-user-multi-challenge setting tightly relates to the RLWE and NTRUE assumptions with a security loss O(log(lambda)), where lambda is the security parameter. The security reductions are thus unaffected by the number of users or the number of challenge ciphertexts. Previously, even a linear security loss O(lambda) was not known to be achievable. Our main construction is a simple hybrid encryption scheme, based on the structure of the LPR cryptosystem (Eurocrypt 2010) in the ring setting, which is made randomness-recoverable in order to bypass the Fujisaki-Okamoto transform in the multi-challenge setting. Using a suitable lossiness argument and reprogrammability techniques, our proof thus preserves tightness as the number of challenge ciphertexts increases.
Affiliations

Citations

Pouria Fallahpour, Benoît Libert, Peters, T., & et al. (2022). On Tight Multi-Challenge-Multi-User CCA2 Security in the QROM. https://hdl.handle.net/2078.5/101529