We identify a class of encryption schemes with \emph{publicly verifiable ciphertexts} that admit generic constructions of (non-trivial) IND-CCA/CPA filters. These schemes are characterized by existence of public algorithms that can distinguish between valid and invalid ciphertexts. To this end, we formally define (non-trivial) public verifiability of ciphertexts for general encryption schemes, key encapsulation mechanisms, and hybrid encryption schemes, encompassing public-key, identity-based, and tag-based encryption flavours. We further analyze the security impact of public verifiability and discuss generic transformations and concrete constructions that enjoy this property.
Category / Keywords: public-key cryptography / public verifiability, ciphertext consistency, general encryption, key encapsulation, hybrid encryption Publication Info: This paper appears in the Proceedings of the 8th International Conference on Security and Cryptography for Networks (SCN 2012). Date: received 22 Jun 2012 Contact author: j gonzaleznieto at qut edu au, mark@manulis eu, bertram poettering@rhul ac uk, j rangasamy@qut edu au, stebila@qut edu au Available formats: PDF | BibTeX Citation Version: 20120622:200513 (All versions of this report) Discussion forum: Show discussion | Start new discussion