Paper 2026/1398

How to Encrypt with Random Reversible Circuits

Ran Canetti, Boston University
Ji Luo, Boston University
Yiding Zhang, Boston University
Abstract

This work revisits a natural paradigm for constructing public-key encryption, whereby the public key is an obfuscated block cipher in encryption mode. We show that if the block cipher is a permutable pseudorandom permutation [Shmueli–Zhandry, Crypto ’25] and the obfuscator is indistinguishability-secure, then the following holds. 1. Applying the obfuscated cipher directly to the message and a short random nonce, without any additional structure or consistency checks, suffices for CCA2 security. 2. Augmenting the scheme with the capability to generate obfuscated decrypt-then-apply-$f$ circuits (for any given function $f$), yields a *functional encryption* scheme that is *simulation-secure against adaptive chosen-ciphertext attacks*. 3. For any length-preserving function $g$, augmenting the public key with an obfuscated decrypt-apply-$g$-reencrypt circuit allows anyone to homomorphically apply $g$ to encrypted data, for an unbounded number of times, while preserving semantic security. (This relies on subexponential security.) We also show that, under the split-circuit pseudorandomness (SCP) assumption of [Canetti–Chamon–Mucciolo–Ruckenstein, TCC ’24], random reversible circuits form a permutable pseudorandom permutation family. This points to obfuscated random reversible circuits as a potential alternative avenue to public-key encryption with strong security and rich functionality.

Note: 1st part of the Crypto paper.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
functional encryptionhomomorphic encryptionreversible circuitsobfuscationCCA security
Contact author(s)
canetti @ bu edu
luoji @ cs washington edu
zyding @ bu edu
History
2026-07-12: approved
2026-07-08: received
See all versions
Short URL
https://ia.cr/2026/1398
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1398,
      author = {Ran Canetti and Ji Luo and Yiding Zhang},
      title = {How to Encrypt with Random Reversible Circuits},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1398},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1398}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.