We propose a relaxed variant of CCA security, called {\sf Replayable CCA (RCCA)} security. RCCA security accepts as secure the non-CCA (yet arguably secure) schemes mentioned above; furthermore, it suffices for most existing applications of CCA security. We provide three formulations of RCCA security. The first one follows the spirit of semantic security and is formulated via an ideal functionality in the universally composable security framework. The other two are formulated following the indistinguishability and non-malleability approaches, respectively. We show that the three formulations are equivalent in most interesting cases.
Category / Keywords: public-key cryptography / Publication Info: An extended abstract of thiswork appears in the proceedings of Crypto 2003. Date: received 19 Aug 2003 Contact author: canetti at us ibm com Available format(s): Postscript (PS) | Compressed Postscript (PS.GZ) | PDF | BibTeX Citation Version: 20030819:195126 (All versions of this report) Short URL: ia.cr/2003/174 Discussion forum: Show discussion | Start new discussion