Paper 2025/1641

Fujisaki-Okamoto Transformation under Average-Case Decryption Error: Tighter and More General Proofs with Applications to PQC

Jiangxia Ge, China Telecom Quantum Group Ltd., Hefei, China
Kang Yang, State Key Laboratory of Cryptology, Beijing, China
Yang Yu, Institute for Advanced Study, Tsinghua University, Beijing, China
Yu Yu, Shanghai Jiao Tong University, Shanghai, China
Abstract

The decryption error is an important parameter that requires estimation when applying the Fujisaki-Okamoto (FO) transformation. In general, compared with the worst-case decryption error $\delta_{wc}$, the average-case decryption error $\delta_{ac}$ is simpler to estimate, as the latter is decoupled from the malicious message selected by the adversary. In light of this, Duman et al. (PKC 2023) proposed FO variants $FOAC_0:=FO_m^\bot\circ ACWC_0$ and $FOAC:=FO_m^\bot\circ ACWC$, and subsequently proved their IND-CCA security based on $\delta_{ac}$ and $\gamma$-spread in the ROM and QROM. In this paper, we revisit the security proof of these variants and obtain the following results: 1, We present a tighter IND-CCA security proof of $FOAC_0$ in the ROM and QROM, while removing the requirement of $\gamma$-spread imposed by Duman et al. Furthermore, as a direct corollary, we fill the gap in the IND-CCA security proof of BAT (CHES 2022) and give a correct one. 2, We present a tighter IND-CCA msecurity proof of $FOAC$ in the QROM. In this proof, we also provide a tighter OW-CPA security proof of ACWC in the QROM, which reduces the loss factor of $q^2$ introduced by Duman et al. to $q$. This actually answers an open question proposed by them, where $q$ denotes the total number of random oracle queries. 3, Based on FOmnbot, we define $FOACmnbot:=FOmnbot\circ ACWC$ and provide its IND-CCA security proof in the ROM and QROM. The advantage of FOACmnbot is that it neither introduces ciphertext expansion as $FOAC_0$ does nor requires $\gamma$-spread as FOAC does. In addition, we propose a new Check Query Replacement technique to complete our QROM proofs, which may be of independent interest.

Note: Fixed some typos

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Contact author(s)
gejiangxia @ chinatelecom cn
yangk @ sklc org
yu-yang @ mail tsinghua edu cn
yuyu @ yuyu hk
History
2025-09-30: revised
2025-09-11: received
See all versions
Short URL
https://ia.cr/2025/1641
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1641,
      author = {Jiangxia Ge and Kang Yang and Yang Yu and Yu Yu},
      title = {Fujisaki-Okamoto Transformation under Average-Case Decryption Error: Tighter and More General Proofs with Applications to {PQC}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1641},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1641}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.