@MISC{Bellare94optimalasymmetric, author = {Mihir Bellare and Phillip Rogaway}, title = {Optimal Asymmetric Encryption}, year = {1994} }
Years of Citing Articles
Bookmark
OpenURL
Abstract
Given an arbitrary k-bit to k-bit trapdoor permutation f and a hash function, we exhibit an encryption scheme for which (i) any string z of length slightly less than k bits can be encrypted as where r= is a simple probabilistic encoding of z depending on the hash function; and (ii) the scheme can be proven semantically secure assuming the hash function is "ideal." Moreover, a slightly enhanced scheme is shown to have the property that the adversary can create ciphertexts only of strings for which she "knows" the corresponding plaintexts-- such a scheme is not only semantically secure but also non-malleable and secure against chosen-ciphertext attack.