Securing threshold cryptosystems against chosen ciphertext attack
In a threshold cryptosystem the secret key of a public key cryptosystem is shared among a set of decryption servers, so that a quorum of these servers can be used to decrypt a given ciphertext. The article focuses on two important aspects of threshold cryptosystems, namely practicality and security. Particularly, two practical threshold cryptosystems are presented, and their security against a chosen ciphertext attack in the random oracle model is proved. First, after a brief introduction, threshold cryptosystems and their applications are discussed, followed by a survey of constructions of (non-threshold) chosen ciphertext secure cryptosystems. Then difficulties in securing threshold cryptosystems against chosen ciphertext attacks are considered, followed by a brief survey of the random oracle model. This introductory part ends with a description of a simple threshold cryptosystem that has been claimed in several papers to be secure against a chosen ciphertext attack, however the authors argue that these claims are not justified. The authors then present a formal model for a \(k\) out of \(n\) threshold cryptosystem and make precise what is meant by security against chosen ciphertext attack and consistency of decryptions. In the next section basic tools, namely threshold secret sharing and zero-knowledge proof of discrete logarithm identities are reviewed. Then two practical threshold cryptosystems are proposed and their security in the random oracle model is proved. The first scheme is secure assuming the hardness of the computational Diffie-Hellman problem, while the second, more efficient scheme is secure assuming the hardness of the decisional Diffie-Hellman problem. Finally, some implementation issues are briefly discussed and some open problems outlined.
- Securing threshold cryptosystems against chosen ciphertext attack
- An Efficient threshold Public Key Cryptosystem Secure Against Adaptive Chosen Ciphertext Attack (Extended Abstract)
- scientific article; zbMATH DE number 1023994
- scientific article; zbMATH DE number 2081075
- Topics in Cryptology – CT-RSA 2006
- Efficient identity-based threshold decryption scheme from bilinear pairings
- Zero-knowledge argument for simultaneous discrete logarithms
- Fully secure ABE with outsourced decryption against chosen ciphertext attack
- Non-interactive CCA2-secure threshold cryptosystems: achieving adaptive security in the standard model without pairings
- Coin-based multi-party fair exchange
- Blind Schnorr signatures and signed ElGamal encryption in the algebraic group model
- Adaptively secure threshold symmetric-key encryption
- New technique for chosen-ciphertext security based on non-interactive zero-knowledge
- Efficient chosen-ciphertext secure certificateless threshold key encapsulation mechanism
- Signcryption schemes with threshold unsigncryption, and applications
- Certificateless threshold cryptosystem secure against chosen-ciphertext attack
- Tag-KEM/DEM: A new framework for hybrid encryption
- Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency
- Ad-hoc threshold broadcast encryption with shorter ciphertexts
- Dynamic threshold public-key encryption with decryption consistency from static assumptions
- Adaptive chosen ciphertext secure threshold key escrow scheme from pairing
- CCA2-Secure Threshold Broadcast Encryption with Shorter Ciphertexts
- Practical Threshold Signatures Without Random Oracles
- Privacy Preserving Data Mining within Anonymous Credential Systems
- New results and applications for multi-secret sharing schemes
- Securing threshold cryptosystems against chosen ciphertext attack
- An Efficient threshold Public Key Cryptosystem Secure Against Adaptive Chosen Ciphertext Attack (Extended Abstract)
- An Efficient Two-Party Public Key Cryptosystem Secure against Adaptive Chosen Ciphertext Attack
- scientific article; zbMATH DE number 2081075 (Why is no real title available?)
- The Security of Ciphertext Stealing
- Fully secure threshold unsigncryption
- Gladius: LWR Based Efficient Hybrid Public Key Encryption with Distributed Decryption
- Improved straight-line extraction in the random oracle model with applications to signature aggregation
- Efficient selective identity-based encryption without random oracles
- Detecting causality in the presence of Byzantine processes: the case of synchronous systems
- Threshold encryption with silent setup
- Practical traceable receipt-free encryption
- A verifiable multi-secret sharing scheme based on -intersection pair of cyclic codes
- Threshold Niederreiter: chosen-ciphertext security and improved distributed decoding
- Straight-line knowledge extraction for multi-round protocols
- Instance compression, revisited
- Quantum (t, n) threshold signature based on shift-code operation and Lagrange unitary operation
- Context-dependent threshold decryption and its applications
- Simple three-round multiparty Schnorr signing with full simulatability
This page was built for publication: Securing threshold cryptosystems against chosen ciphertext attack
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q1601827)