A Modular Analysis of the Fujisaki-Okamoto Transformation

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

Abstract

The Fujisaki-Okamoto (FO) transformation (CRYPTO 1999 and Journal of Cryptology 2013) turns any weakly secure public-key encryption scheme into a strongly (i.e., IND-CCA) secure one in the random oracle model. Unfortunately, the FO analysis suffers from several drawbacks, such as a non-tight security reduction, and the need for a perfectly correct scheme. While several alternatives to the FO transformation have been proposed, they have stronger requirements, or do not obtain all desired properties. In this work, we provide a fine-grained and modular toolkit of transformations for turning weakly secure into strongly secure public-key encryption schemes. All of our transformations are robust against schemes with correctness errors, and their combination leads to several tradeoffs among tightness of the reduction, efficiency, and the required security level of the used encryption scheme. For instance, one variant of the FO transformation constructs an IND-CCA secure scheme from an IND-CPA secure one with a tight reduction and very small efficiency overhead. Another variant assumes only an OW-CPA secure scheme, but leads to an IND-CCA secure scheme with larger ciphertexts. We note that we also analyze our transformations in the quantum random oracle model, which yields security guarantees in a post-quantum setting.
Original languageEnglish
Title of host publicationTheory of Cryptography
Subtitle of host publication5th International Conference, TCC 2017, Baltimore, MD, USA, November 12-15, 2017, Proceedings
EditorsYael Kalai, Leonid Reyzin
PublisherSpringer
Pages341-371
Number of pages31
ISBN (Electronic)978-3-319-70500-2
ISBN (Print)978-3-319-70499-9
DOIs
Publication statusPublished - 2017
Externally publishedYes

Publication series

NameLecture Notes in Computer Science
Volume10677

Fingerprint

Dive into the research topics of 'A Modular Analysis of the Fujisaki-Okamoto Transformation'. Together they form a unique fingerprint.

Cite this