Skip to Main content Skip to Navigation
Journal articles

Public-key encryption indistinguishable under plaintext-checkable attacks

Abstract : Indistinguishability under chosen-ciphertext attack (IND-CCA) is now considered the de facto security notion for public-key encryption. However, this sometimes offers a stronger security guarantee than what is needed. In this study, the authors consider a weaker security notion, termed as indistinguishability under plaintext-checking attacks (IND-PCA), in which the adversary has only access to an oracle indicating whether or not a given ciphertext encrypts a given message. After formalising this notion, the authors design a new public-key encryption scheme satisfying it. The new scheme is a variant of the Cramer–Shoup encryption scheme with shorter ciphertexts. Its security is also based on the plain decisional Diffie–Hellman (DDH) assumption. Additionally, the algebraic properties of the new scheme allow proving plaintext knowledge using Groth–Sahai non-interactive zero-knowledge proofs or smooth projective hash functions. Finally, as a concrete application, the authors show that, for many password-based authenticated key exchange (PAKE) schemes in the Bellare–Pointcheval–Rogaway security model, they can safely replace the underlying IND-CCA encryption schemes with their new IND-PCA one. By doing so, they reduce the overall communication complexity of these protocols and obtain the most efficient PAKE schemes to date based on plain DDH.
Document type :
Journal articles
Complete list of metadata
Contributor : Michel Abdalla <>
Submitted on : Thursday, October 20, 2016 - 11:02:10 PM
Last modification on : Tuesday, May 4, 2021 - 2:06:02 PM




Michel Abdalla, Fabrice Benhamouda, David Pointcheval. Public-key encryption indistinguishable under plaintext-checkable attacks. IET Information Security, Institution of Engineering and Technology, 2016, 10 (6), pp.288-303. ⟨10.1049/iet-ifs.2015.0500⟩. ⟨hal-01385178⟩



Record views