Reductionist Security Arguments for Public-Key Cryptographic Schemes Based on Group Action
Anton Stolbunov · 2009
We provide reductionist security arguments for a key agreement protocol KA, which is the Die-Hellman key agreement protocol generalized to the context of a group action on a set, and for a publickey encryption scheme PE, which is the \hashed ElGamal scheme generalized for a group action on a set. For theKA protocol we use the notion of session key security in the authenticated links model, proposed by Canetti and Krawczyk. For thePE scheme we use a version of the semantic security notion proposed by Goldwasser and Micali. We prove that the security of the KA protocol and the PE scheme is based on the decisional Die-Hellman group action problem, dened later in this paper. ThePE scheme security also depends on the entropy smoothing property of the hash function family used in the scheme.