arrow
Return

Updatable Encryption Secure against Randomness Compromise

delete2026-03-01
delete0
PRE
AI
Y
Yuichi Tanishita *
R
Ryuya Hayashi
R
Ryu Ishii
M
Matsuda, Takahiro
M
Matsuura, Kanta
DOI:10.1587/transfun.2025CIP0020delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Updatable encryption (UE) allows a third-party server to update outsourced encrypted data without exposing keys and plaintexts. The server can update ciphertexts to ones under a new key using an update token provided by the client. UE can realize efficient key rotation and is effective against key compromise. The standard security notions of UE capture the property that even if keys or update tokens are compromised, the confidentiality of messages is maintained by the key update and ciphertext update. In general, the randomnesses used in the encryption and ciphertext update algorithms must be kept secret in the same way as the keys. On the other hand, while key compromise is considered in existing security notions, randomness compromise is not. In this paper, we define a new security notion for UE, IND-UE-R security, that is resilient to the compromise of randomnesses used to generate or update ciphertexts. Furthermore, we prove that the UE construction RISE (EUROCRYPT'18) satisfies our proposed security notion.
Keywords:
updatable encryption
public-key encryption
ElGamal encryp-tion
DDH assumption
randomness compromise

Journal

IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences cover
IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences
IF:
0.4
Papers:
210
Citations:
1.3K

Organization

D
deloitte touche tohmatsu limited
Scholars:
405
Papers: 270
Citations: 0
U
university of tokyo
Scholars:
6.3K
Papers: 2.5K
Citations: 1
researcher View more organizations