Paper 2025/1641
Fujisaki-Okamoto Transformation under Average-Case Decryption Error: Tighter and More General Proofs with Applications to PQC
Abstract
The decryption error is an important parameter that requires estimation when applying the Fujisaki-Okamoto (FO) transformation. In general, compared with the worst-case decryption error $\delta_{wc}$, the average-case decryption error $\delta_{ac}$ is simpler to estimate, as the latter is decoupled from the malicious message selected by the adversary. In light of this, Duman et al. (PKC 2023) proposed FO variants $FOAC_0:=FO_m^\bot\circ ACWC_0$ and $FOAC:=FO_m^\bot\circ ACWC$, and subsequently proved their IND-CCA security based on $\delta_{ac}$ and $\gamma$-spread in the ROM and QROM. In this paper, we revisit the security proof of these variants and obtain the following results: 1, We present a tighter IND-CCA security proof of $FOAC_0$ in the ROM and QROM, while removing the requirement of $\gamma$-spread imposed by Duman et al. Furthermore, as a direct corollary, we fill the gap in the IND-CCA security proof of BAT (CHES 2022) and give a correct one. 2, We present a tighter IND-CCA msecurity proof of $FOAC$ in the QROM. In this proof, we also provide a tighter OW-CPA security proof of ACWC in the QROM, which reduces the loss factor of $q^2$ introduced by Duman et al. to $q$. This actually answers an open question proposed by them, where $q$ denotes the total number of random oracle queries. 3, Based on FOmnbot, we define $FOACmnbot:=FOmnbot\circ ACWC$ and provide its IND-CCA security proof in the ROM and QROM. The advantage of FOACmnbot is that it neither introduces ciphertext expansion as $FOAC_0$ does nor requires $\gamma$-spread as FOAC does. In addition, we propose a new Check Query Replacement technique to complete our QROM proofs, which may be of independent interest.
Note: Fixed some typos
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Contact author(s)
-
gejiangxia @ chinatelecom cn
yangk @ sklc org
yu-yang @ mail tsinghua edu cn
yuyu @ yuyu hk - History
- 2025-09-30: revised
- 2025-09-11: received
- See all versions
- Short URL
- https://ia.cr/2025/1641
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1641,
author = {Jiangxia Ge and Kang Yang and Yang Yu and Yu Yu},
title = {Fujisaki-Okamoto Transformation under Average-Case Decryption Error: Tighter and More General Proofs with Applications to {PQC}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1641},
year = {2025},
url = {https://eprint.iacr.org/2025/1641}
}