Overview
Syllabus
Detecting Dangerous Queries
Public Key Encryption DH76,RSA78,GM84
IND-CPA (GM84) Indistinguishability under Chosen Plaintext Attack
IND-CCA (NY90, DDN91,RS91) Indistinguishability under Chosen Ciphertext Attack
The Grand Goal: CCA from CPA
Some Prior Methods (Standard Model)
1-bit CCA to n-bit CCA MS09
Our Result
DCCA Security: Intuition
Detectable Encryption System
Property 1: Hard to Predict (Strong)
Property 2: Indistinguishability
Examples
The Ingredients
Setup
A Few Comments
What is the trouble?
Nested Indist. Game
Proof Overview
Summary
Our Picture (not necessarily to scale)
Thank you
Taught by
TheIACR