Paper 2025/1504

On the $\gamma$-Spreadness of Average-Case to Worst-Case Transformations

Hyun Ji Kwag, Korea University
Jonghyun Kim, Korea University
Changmin Lee, Korea University
Jong Hwan Park, Sangmyung University
Abstract

Achieving (at least) a worst-case correctness error is essential for an underlying public-key encryption (PKE) scheme to which the Fujisaki-Okamoto (FO) transformation is applied. There are three average-case to worst-case (ACWC) transformations—denoted as $\mathsf{ACWC}_{0}$, $\mathsf{ACWC}_{1}$ (PKC 2023), and $\mathsf{ACWC}_{2}$ (TIFS 2023)-which generically convert a PKE scheme with an average-case correctness error into one with a worst-case correctness error. However, in these ACWC transformations the $\gamma$-spreadness, a critical factor in determining explicit rejection ($\mathsf{FO}^{\perp}$) or implicit rejection ($\mathsf{FO}^{\not\perp}$), has not been established with rigorous proofs. Existing analyses of $\gamma$-spreadness lack rigorous proofs, include analytical flaws, or fail to achieve the tightest possible bounds. In this work, we reprove the $\gamma$-spreadness of ACWC-transformed PKE schemes by leveraging two key facts: the random oracle is chosen at random and the encoding mechanism used in the ACWC framework is message-hiding. Our new proofs are applied to the previous NTRU-based PKE schemes, called $\mathsf{NTRU}\mbox{-}\mathsf{C}$, $\mathsf{NTRU}\mbox{-}\mathsf{B}$, and $\mathsf{NTRU+}$, giving the corrected $\gamma$-spreadness for those PKE schemes with concrete parameters.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Designs, Codes and Cryptography
DOI
10.1007/s10623-026-01862-6
Keywords
γ-spreadnessACWC transformationFujisaki-Okamoto transformationNTRU
Contact author(s)
ijnuyh01 @ korea ac kr
yoswuk @ korea ac kr
changminlee @ korea ac kr
jhpark @ smu ac kr
History
2026-06-10: last of 2 revisions
2025-08-21: received
See all versions
Short URL
https://ia.cr/2025/1504
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1504,
      author = {Hyun Ji Kwag and Jonghyun Kim and Changmin Lee and Jong Hwan Park},
      title = {On the $\gamma$-Spreadness of Average-Case to Worst-Case Transformations},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1504},
      year = {2025},
      doi = {10.1007/s10623-026-01862-6},
      url = {https://eprint.iacr.org/2025/1504}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.