Paper 2026/1398
How to Encrypt with Random Reversible Circuits
Abstract
This work revisits a natural paradigm for constructing public-key encryption, whereby the public key is an obfuscated block cipher in encryption mode. We show that if the block cipher is a permutable pseudorandom permutation [Shmueli–Zhandry, Crypto ’25] and the obfuscator is indistinguishability-secure, then the following holds. 1. Applying the obfuscated cipher directly to the message and a short random nonce, without any additional structure or consistency checks, suffices for CCA2 security. 2. Augmenting the scheme with the capability to generate obfuscated decrypt-then-apply-$f$ circuits (for any given function $f$), yields a *functional encryption* scheme that is *simulation-secure against adaptive chosen-ciphertext attacks*. 3. For any length-preserving function $g$, augmenting the public key with an obfuscated decrypt-apply-$g$-reencrypt circuit allows anyone to homomorphically apply $g$ to encrypted data, for an unbounded number of times, while preserving semantic security. (This relies on subexponential security.) We also show that, under the split-circuit pseudorandomness (SCP) assumption of [Canetti–Chamon–Mucciolo–Ruckenstein, TCC ’24], random reversible circuits form a permutable pseudorandom permutation family. This points to obfuscated random reversible circuits as a potential alternative avenue to public-key encryption with strong security and rich functionality.
Note: 1st part of the Crypto paper.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A major revision of an IACR publication in CRYPTO 2026
- Keywords
- functional encryptionhomomorphic encryptionreversible circuitsobfuscationCCA security
- Contact author(s)
-
canetti @ bu edu
luoji @ cs washington edu
zyding @ bu edu - History
- 2026-07-12: approved
- 2026-07-08: received
- See all versions
- Short URL
- https://ia.cr/2026/1398
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1398,
author = {Ran Canetti and Ji Luo and Yiding Zhang},
title = {How to Encrypt with Random Reversible Circuits},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1398},
year = {2026},
url = {https://eprint.iacr.org/2026/1398}
}