Paper 2026/1732

Indifferentiability of Public-Key Encryption: Theory Meets Practice

Taiyu Wang, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Cong Zhang, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Hong-Sheng Zhou, Virginia Commonwealth University
Jiayi Ai, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Zhihong Jia, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Wenli Wang, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Jian Liu, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Xin Wang, Digital Technologies, Ant Group
Li Lin, Digital Technologies, Ant Group
Kui Ren, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Chun Chen, The State Key Laboratory of Blockchain and Data Security, Zhejiang University
Abstract

Public-key encryption (PKE) is a fundamental primitive in modern cryptography, and many PKE schemes have been standardized and widely deployed. To reason about security in complex and highly compositional environments, Zhandry and Zhang (CRYPTO 2020) initiated the study of indifferentiability for public-key cryptosystems. However, their construction for PKE departs substantially from the design paradigms used in practice, and to date no practical public-key encryption schemes are known to achieve indifferentiability. In this work, we further investigate indifferentiability for public-key encryption, asking whether it can be achieved for practical, standardized schemes. We provide evidence that the answer is yes: slightly augmented standardized group-based encryption schemes can indeed achieve provable indifferentiability. Our contributions are threefold: -- Identifying a barrier in the existing ideal PKE model: We revisit the ideal PKE definition of Zhandry and Zhang and identify an artificial requirement---namely, pseudorandom public keys and ciphertexts---that constitutes an inherent barrier to achieving indifferentiability from groups. -- Redefining the idealized model for PKE: We propose a revised ideal PKE model that removes this pseudorandomness requirement, thereby opening the possibility of achieving indifferentiable public-key encryption from practical group-based schemes. --Making standardized PKE indifferentiable: We consider two public-key encryption schemes standardized in ISO/IEC 18033-2---Elliptic Curve Integrated Encryption Scheme (ECIES) and Public-Key Secure Encryption (PSEC)---and show that, under slight augmentation, both are indifferentiable from our revised ideal PKE. In conclusion, our work advances the development of indifferentiable yet practical public-key encryption schemes, enabling future research and protocol design to build on standard PKE schemes while enjoying strong composability guarantees.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
Public-key encryptiongeneric group modelindifferentiabilityKEM/DEM paradigmECIESPSEC
Contact author(s)
taiyuwang @ zju edu cn
congresearch @ zju edu cn
hszhou @ vcu edu
jiayiai @ zju edu cn
jzh1288 @ zju edu cn
wangwenli @ zju edu cn
liujian2411 @ zju edu cn
wx352669 @ antgroup com
felix ll @ antgroup com
kuiren @ zju edu cn
chenc @ zju edu cn
History
2026-08-21: approved
2026-08-19: received
See all versions
Short URL
https://ia.cr/2026/1732
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1732,
      author = {Taiyu Wang and Cong Zhang and Hong-Sheng Zhou and Jiayi Ai and Zhihong Jia and Wenli Wang and Jian Liu and Xin Wang and Li Lin and Kui Ren and Chun Chen},
      title = {Indifferentiability of Public-Key Encryption: Theory Meets Practice},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1732},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1732}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.