arrow
Return

Nonmalleable cryptography

delete2003-01-01
delete41
PRE
AI
D
Danny Dolev
C
Cynthia Dwork
M
Moni Naor
DOI:10.1137/S0036144503429856delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The notion of nonmalleable cryptography, an extension of semantically secure cryptography, is defined. Informally, in the context of encryption the additional requirement is that given the ciphertext it is impossible to generate a different ciphertext so that the respective plaintexts are related. The same concept makes sense in the contexts of string commitment and zero-knowledge proofs of possession of knowledge. Nonmalleable schemes for each of these three problems are presented. The schemes do not assume a trusted center; a user need not know anything about the number or identity of other system users. Our cryptosystem is the first proven to be secure against a strong type of chosen ciphertext attack proposed by Rackoff and Simon, in which the attacker knows the ciphertext she wishes to break and can query the decryption oracle on any ciphertext other than the target.
Keywords:
cryptography
cryptanalysis
encryption
authentication
randomized algorithms
nonmalleability
chosen ciphertext security
auction protocols
commitment schemes
zero-knowledge
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

SIAM Review cover
SIAM Review
IF:
6.1
Papers:
888
Citations:
1.2W

Organization

No organization information available