On the Security of Multiple Encryption or CCA-security+CCA-security=CCA-security? (2003)
| Venue: | Proc. of PKC’04, LNCS 2947 |
| Citations: | 2 - 1 self |
BibTeX
@INPROCEEDINGS{Zhang03onthe,
author = {Rui Zhang and Goichiro Hanaoka and Junji Shikata and Hideki Imai},
title = {On the Security of Multiple Encryption or CCA-security+CCA-security=CCA-security?},
booktitle = {Proc. of PKC’04, LNCS 2947},
year = {2003},
pages = {360--374},
publisher = {Springer-Verlag}
}
OpenURL
Abstract
In a practical system, a message is often encrypted more than once by different encryptions, here called multiple encryption, to enhance its security. Additionally, new features may be achieved by multiple encrypting a message for a scheme, such as the key-insulated cryptosystems [13] and anonymous channels [8]. Intuitively, a multiple encryption should remain "secure", whenever there is one component cipher unbreakable in it. In NESSIE's latest Portfolio of recommended cryptographic primitives (Feb. 2003), it is suggested to use multiple encryption with component ciphers based on different assumptions to acquire long term security. However, in this paper we show this needs careful discussion. Especially, this may not be true...







