Skip to main navigation Skip to search Skip to main content

Hybrid damgård is CCA1-secure under the DDH assumption

  • University College London
  • Cybernetica AS
  • Université Paris 8

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Citations (Scopus)

Abstract

In 1991, Damgård proposed a simple public-key cryptosystem that he proved CCA1-secure under the Diffie-Hellman Knowledge assumption. Only in 2006, Gjøsteen proved its CCA1-security under a more standard but still new and strong assumption. The known CCA2-secure public-key cryptosystems are considerably more complicated. We propose a hybrid variant of Damgård's public-key cryptosystem and show that it is CCA1-secure if the used symmetric cryptosystem is CPA-secure, the used MAC is unforgeable, the used key-derivation function is secure, and the underlying group is a DDH group. The new cryptosystem is the most efficient known CCA1-secure hybrid cryptosystem based on standard assumptions.

Original languageEnglish
Title of host publicationCryptology and Network Security - 7th International Conference, CANS 2008, Proceedings
Pages18-30
Number of pages13
DOIs
Publication statusPublished - 1 Dec 2008
Externally publishedYes
Event7th International Conference on Cryptology and Network Security, CANS 2008 - Hong-Kong, China
Duration: 2 Dec 20084 Dec 2008

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5339 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference7th International Conference on Cryptology and Network Security, CANS 2008
Country/TerritoryChina
CityHong-Kong
Period2/12/084/12/08

Keywords

  • CCA1-security
  • DDH
  • Damgård's cryptosystem
  • Hybrid cryptosystems

Fingerprint

Dive into the research topics of 'Hybrid damgård is CCA1-secure under the DDH assumption'. Together they form a unique fingerprint.

Cite this