Paper 2025/1477

Adaptively Secure Threshold ElGamal Decryption from DDH

Sourav Das, University of Illinois Urbana-Champaign
Ling Ren, University of Illinois Urbana-Champaign
Ziling Yang, University of Illinois Urbana-Champaign
Abstract

Threshold decryption schemes allow a group of decryptors, each holding a private key share, to jointly decrypt ciphertexts. Over the years, numerous threshold decryption schemes have been proposed for applications such as secure data storage, internet auctions, and voting, and recently as a tool to protect against miner-extractable value attacks in blockchain. Despite the importance and popularity of threshold decryption, many natural and practical threshold decryption schemes have only been proven secure against static adversaries. In this paper, we present two threshold decryption schemes that withstand malicious adaptive corruption. Our first scheme is based on the standard ElGamal encryption scheme and is secure against chosen plaintext attack~(CPA). Our second scheme, based on the chosen ciphertext attack~(CCA) secure Shoup-Gennaro encryption scheme, is also CCA secure. Both of our schemes have non-interactive decryption protocols and comparable efficiency to their static secure counterparts. Building on the technique introduced by Das and Ren (CRYPTO 2024), our threshold ElGamal decryption scheme relies on the hardness of Decisional Diffie-Hellman and the random oracle model.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Threshold cryptographyadaptive securitychosen plaintext securitychosen ciphertext securitypublic key encryption.
Contact author(s)
souravd2 @ illinois edu
renling @ illinois edu
zilingy2 @ illinois edu
History
2025-08-20: approved
2025-08-14: received
See all versions
Short URL
https://ia.cr/2025/1477
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1477,
      author = {Sourav Das and Ling Ren and Ziling Yang},
      title = {Adaptively Secure Threshold {ElGamal} Decryption from {DDH}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1477},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1477}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.