Obfuscation ==> (IND-CPA Security =/=> Circular Security).
Antonio Marcedone, Claudio Orlandi · 2013
Abstract Circular security is an important notion for public-key encryption schemes and is needed by several cryptographic protocols. In circular security the adversary is given an extra “hint ” consisting of a cycle of encryption of secret keys i.e., (Epk1(sk2),..., Epkn(sk1)). A natural question is whether every IND-CPA encryption scheme is also circular secure. It is trivial to see that this is not the case when n = 1. In 2010 a separation for n = 2 was shown by [ABBC10,GH10] under standard assumptions in bilinear groups. In this paper we finally settle the question showing that for every n there exist an IND-CPA secure scheme which is not n-circular secure. Our result relies on the recent progress in program obfuscation. 1