Paper 2025/982

Simulatability versus Indistinguishability SOA: CCA Relations are Sampler-Dependent

Hans Heum, Norwegian University of Science and Technology
Abstract

Selective Opening Attack (SOA) is a set of security notions modelling the threat of encryption randomness and/or secret keys leaking after-the-fact. Contrary to expectation, we show that there is no general reduction from simulation-based selective opening security (SSO) to indistinguishability-based selective opening security (ISO) in the CCA setting. In particular, we show that when restricted to certain message distributions, SSO-CCA is incomparable with ISO-CCA. This contrasts the CPA case, where SSO-CPA is known to be strictly stronger than ISO-CPA relative to any message sampler. Any sampler with high enough min-entropy suffices for this “semi-separation” to appear. On the other hand, we show that restricting to distributions with very low min-entropy gives rise to an implication. Our main result does not rely on the presence of selective openings, but rather follow from subtleties in the game structures. At a glance, this may seem to contradict known equivalences between indistinguishability, semantic security, and selective opening security under trivial openings. We reconcile the apparent contradiction by showing that the CCA landscape splits into a “high-entropy” and a “low-entropy” world, which for notions of SOA must be treated separately.

Note: Author's version

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published by the IACR in CIC 2025
DOI
10.62056/abbngyl7s
Keywords
Public-Key EncryptionSelective Opening AttacksCCA
Contact author(s)
hans @ heum me
History
2026-01-09: revised
2025-05-28: received
See all versions
Short URL
https://ia.cr/2025/982
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2025/982,
      author = {Hans Heum},
      title = {Simulatability versus Indistinguishability {SOA}: {CCA} Relations are Sampler-Dependent},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/982},
      year = {2025},
      doi = {10.62056/abbngyl7s},
      url = {https://eprint.iacr.org/2025/982}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.