Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. On IND-qCCA security in the ROM and its applications CPA security is sufficient for TLS 1.3
 
conference paper

On IND-qCCA security in the ROM and its applications CPA security is sufficient for TLS 1.3

Huguenin-Dumittan, Loïs Evan  
•
Vaudenay, Serge  
2022
Advances in Cryptology – EUROCRYPT 2022
Eurocrypt 2022

Bounded IND-CCA security (IND-qCCA) is a notion similar to the traditional IND-CCA security, except the adversary is restricted to a constant number q of decryption/decapsulation queries. We show in this work that IND-qCCA is easily obtained from any passively secure PKE in the (Q)ROM. That is, simply adding a confirmation hash or computing the key as the hash of the plaintext and ciphertext holds an IND-qCCA KEM. In particular, there is no need for derandomization or re-encryption as in the Fujisaki-Okamoto (FO) transform. This makes the decapsulation process of such IND-qCCA KEM much more efficient than its FO-derived counterpart. In addition, IND-qCCA KEMs could be used in the recently proposed KEMTLS protocol [ACM CCS 2020] that requires IND-1CCA ephemeral key-exchange mechanisms or in TLS 1.3. Then, using similar proof techniques, we show that CPA-secure KEMs are sufficient for the TLS 1.3 handshake to be secure, solving an open problem in the ROM. In turn, this implies that the PRF-ODH assumption used to prove the security of TLS 1.3 is not necessary and can be replaced by the CDH assumption in the ROM. We also highlight and briefly discuss several use cases of IND-1CCA KEMs in protocols and ratcheting primitives.

  • Files
  • Details
  • Metrics
Type
conference paper
DOI
10.1007/978-3-031-07082-2_22
Author(s)
Huguenin-Dumittan, Loïs Evan  
Vaudenay, Serge  
Date Issued

2022

Published in
Advances in Cryptology – EUROCRYPT 2022
Start page

613

End page

642

URL

preprint

https://eprint.iacr.org/2021/844.pdfhttps://eprint.iacr.org/2021/844.pdf
Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LASEC  
Event nameEvent placeEvent date
Eurocrypt 2022

Trondheim, Norway

May 30 to June 3, 2022

Available on Infoscience
August 5, 2022
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/189777
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés