The Fujisaki-Okamoto (FO) transformation (CRYPTO 1999 and Journal of Cryptology 2013) turns any weakly secure public-key encryption scheme into a strongly (i.e., IND-CCA) secure one in the random oracle model.
O2H引理的应用之一是后量子版本的Fujisaki-Okamoto变换(FO变换)的安全性证明。FO变换最初由Fujisaki和Okamoto在1999年的论文 [3] 中提出,允许由OW-CPA安全的公钥加密算法得到IND-CCA安全的公钥加密算法。
A Modular Analysis of the Fujisaki-Okamoto Transformation
2017年11月5日 · Its security is based on the hardness of the module learning-with-errors (M-LWE) problem. The IND-CCA secure key establishment mechanism (KEM) is obtained by applying the Fujisaki-Okamoto transform...
In this paper, we reveal that rejection sampling routines that are seeded with secret-dependent information and leak timing information result in practical key recovery attacks in the code-based key encapsulation mechanisms HQC and BIKE.
The Fujisaki-Okamoto transform - Lukas Prokop
2020年6月19日 · In 1999, E. Fujisaki and T. Okamoto (FO) described a transform of a weak symmetric and asymmetric encryption scheme into a hybrid scheme secure against chosen-ciphertext attacks. After the transform, they also provided a proof of the claimed security properties and implementations for two schemes.
manns, and Kiltz (HHK) (TCC 2017) have recently shown that arianvts of the ujisaki-OkFamoto (FO) transform can work with schemes that have negligible correctness error in the (quantum) random oracle model (QROM). Many recent schemes in the NIST post-quantum competition (PQC) use arianvts of these transformations. Some of their CPA-secure
