如何设计在标准模型下满足适应性选择密文安全(IND-CCA2)的高效公钥加密方案,是公钥密码学领域中的一个重要研究课题.康立等人提出了一个高效的公钥加密方案,并认为他们的方案在标准模型下满足IND-CCA2安全.文中首先对该方案进行分析,通过给出具体的攻击方法表明该方案并不满足IND-CCA2安全.然后对该方案进行改进得到一个新的公钥加密方案,并在标准模型下证明了新方案的IND-CCA2安全性.
It is an important research topic in public key cryptography to design public key encryption schemes secure against adaptive chosen-ciphertext attacks in the standard model. Kang et al. proposed an efficient public key eneryption scheme, and claimed that their scheme satisfies the security of indistinguishability against adaptive chosen-ciphertext attacks (IND-CCA2). However, by giving an adaptive chosen-ciphertext attack, we indicate that their scheme is not IND-CCA2 secure. We further improved Kang et al.'s scheme to obtain a new public key encryp- tion scheme, and prove its IND-CCA2 security in the standard model.