key: 2015-ciphertext-plus-proof-of-knowledge-is-NM-CPA type: inproceedings title: NM-CPA secure encryption with proofs of plaintext knowledge authors: - Ben Smyth - Yoshikazu Hanatani - Hirofumi Muratani year: 2015 month: 6 booktitle: "IWSEC'15: 10th International Workshop on Security" series: LNCS volume: "9241" publisher: Springer doi: 10.1007/978-3-319-22425-1_8 description: >- This paper presents a construction for NM-CPA ciphertexts which prove plaintext knowledge. Applications include ballot secrecy proofs in schemes such as Helios. keywords: >- asymmetric encryption, ballot secrecy, chosen plaintext attacks, elections, election scheme, electronic voting, e-voting, Helios, homomorphic encryption, indistinguishability, non-malleability, privacy, secrecy abstract: >- NM-CPA secure asymmetric encryption schemes which prove plaintext knowledge are sufficient for secrecy and verifiability in some domains, for example, ballot secrecy and end-to-end verifiability in electronic voting. In these domains, some applications derive encryption schemes by coupling malleable IND-CPA secure ciphertexts with proofs of plaintext knowledge, without evidence that the sufficient condition is satisfied nor an independent security proof. Consequently, it is unknown whether these applications satisfy the desired secrecy and verifiability properties. In this paper, we propose a generic construction for such a coupling and prove that our construction produces NM-CPA secure encryption schemes which prove plaintext knowledge. Accordingly, we facilitate the development of applications satisfying their secrecy and verifiability objectives and, moreover, we make progress towards security proofs for existing applications. supersededby: - key: 2018-ballot-secrecy-from-NM-CPA text: extension