Lecture Notes in Computer Science, 2003, Volume 2595/2003, 62-75, DOI: 10.1007/3-540-36492-7_6

Encryption-Scheme Security in the Presence of Key-Dependent Messages

John Black, Phillip Rogaway and Thomas Shrimpton

View Related Documents

Abstract

Encryption that is only semantically secure should not be used on messages that depend on the underlying secret key; all bets are off when, for example, one encrypts using a shared key K the value K. Here we introduce a new notion of security, KDM security, appropriate for key-dependent messages. The notion makes sense in both the publickey and shared-key settings. For the latter we show that KDM security is easily achievable within the random-oracle model. By developing and achieving stronger notions of encryption-scheme security it is hoped that protocols which are proven secure under “formal” models of security can, in time, be safely realized by generically instantiating their primitives.

Fulltext Preview

Image of the first page of the fulltext document