Public‐Key Encryption and Security Notions
Nuttapong Attrapadung, Takahiro Matsuda · 2022
Public-key encryption (PKE) allows a sender to use a receiver's public key to encrypt a message under it and send it to the receiver, who possesses the corresponding secret key. This chapter provides some basic knowledge on PKE and its security notions and survey important results in this field. It talks about the security notion called indistinguishability against chosen-ciphertext attacks (IND-CCA), which is widely accepted as the de facto standard notion for PKE. The chapter details the Cramer-Shoup PKE, which is the first practical IND-CCA secure PKE under a reasonable assumption. It also serves as introductory material for a popular method to prove security, namely, using the game-based approach. The chapter provides a survey on specific and generic constructions for IND-CCA secure PKE. It also covers some advanced recent research topics for PKE, such as tight security, key-dependent-message security, and so on.