Paper 2026/452

On the CCA security properties (and more) of a new variant of Paillier-ElGamal

Duong Hieu Phan, Télécom Paris, Institut Polytechnique de Paris, Palaiseau, France
Renaud Sirdey, Université Paris-Saclay, CEA, List, Palaiseau, France
Jean Vacher, Université Paris-Saclay, CEA, List, Palaiseau, France
Abstract

We solve the long-standing open question of designing a "truly" linearly homomorphic scheme -- meaning it supports homomorphic additions on arbitrary plaintexts, with no restriction, in contrast to "somewhat" ones -- that achieves CCA1 security under a standard assumption. We do so by introducing a new variant of Paillier-ElGamal, which we call Damgard-Paillier-ElGamal (DPEG) as its design follows a Knowledge-of-Exponent pattern. On top of being linearly homomorphic without any restriction, our scheme enjoys the following properties: - It achieves CCA1 security solely under the DCR assumption. To the best of our knowledge, it is the first "truly" linearly homomorphic proven CCA1 secure solely under this assumption (or any other standard one). - It can be extended to support one level of multiplication while still preserving its CCA1 security under the same assumption. This extension is then the first concrete scheme supporting both homomorphic additions and multiplications (even limited to one-level) that is proven CCA1 secure under DCR. - It also achieves Manulis&Nguyen's stronger notion of vCCA security under an additional non-falsifiable linear-only homomorphism assumption that is commonly used in proof-of-knowledge constructs. DPEG is then the first scheme that is proven vCCA secure while being CCA1 secure under a standard assumption. This also carries over to the multiplicative extension. Interestingly, DPEG achieves the above at only 1.5 times the cost of the baseline CPA-secure Paillier-ElGamal scheme. To establish the CCA1 security of DPEG, we introduce a new abstract framework that allows to prove CCA1 security of a large class of of group-based PKE that also covers other somewhat linearly homomorphic schemes previously known to achieve CCA1 security under falsifiable assumptions such as Damgard-ElGamal, Cramer-Shoup-Lite and the recent variant of Paillier-ElGamal with plaintext zero padding of Libert. This framework may be of independent interest to more easily prove the CCA1 security of other schemes. Lastly, on the negative side, we take a first step in connecting vCCA security to an impossibility result of Gentry&Wichs and show that, under mild assumptions, the vCCA security of DPEG cannot be established from any falsifiable assumption.

Note: Previous title of this report was "On the CCA security properties of a class of group-based linearly homomorphic encryption schemes"

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
Homomorphic EncryptionCCA Security
Contact author(s)
hieu phan @ telecom-paris fr
renaud sirdey @ cea fr
jean vacher @ cea fr
History
2026-08-27: last of 3 revisions
2026-03-04: received
See all versions
Short URL
https://ia.cr/2026/452
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/452,
      author = {Duong Hieu Phan and Renaud Sirdey and Jean Vacher},
      title = {On the {CCA} security properties (and more) of a new variant of Paillier-{ElGamal}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/452},
      year = {2026},
      url = {https://eprint.iacr.org/2026/452}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.