| 研究生: |
呂沂瑾 Lu, Yi Jiin |
|---|---|
| 論文名稱: |
變形加密:威權政體下公鑰密碼系統中高效率之隱藏訊息通道之研究 Anamorphic Encryption: A Study on High-Bandwidth Covert Channels in Public Key Cryptosystems under Authoritarian Regimes |
| 指導教授: | 曾一凡 |
| 口試委員: |
黃政嘉
劉子源 |
| 學位類別: |
碩士
Master |
| 系所名稱: |
資訊學院 - 資訊科學系 Department of Computer Science |
| 論文出版年: | 2026 |
| 畢業學年度: | 114 |
| 語文別: | 英文 |
| 論文頁數: | 31 |
| 中文關鍵詞: | 密碼學 、公鑰加密 、變形加密 、非對稱加密 |
| 外文關鍵詞: | Cryptographic, Public Key Encryption, Anamorphic Encryption, Asymmetric Encryption |
| 相關次數: | 點閱:56 下載:4 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
變形加密(Anamorphic encryption)針對威權環境下對個人隱私的侵犯,提供了一種技術防禦手段。藉由將隱蔽通訊通道嵌入標準的公鑰密文中,即使在獨裁者能夠合法沒收私鑰或要求發送方交出加密隨機數的情況下,公民仍能維持私密通訊。然而,現有的公鑰變形加密(Public-Key Anamorphic Encryption, PKAE)構造面臨著重大的侷限性:部分方案依賴於標準方案中不常見的特殊數學性質,而其他方案則受限於狹隘的變形訊息空間。在本研究中,我們提出了 Dual Layer Anamorphic Encryption 方案,這是一種通用的 PKAE 構造,能夠在標準模型(standard model)下達成不受限的變形訊息空間。我們的構造結合了 μ-message extension 架構與隨機數可恢復加密(randomness-recoverable encryption)。變形訊息首先由內層的 PKE 方案進行加密,隨後產生的密文會透過偽隨機編碼(Pseudorandom Encoding)方案打散成 $ 個偽隨機片段;每個片段將作為對應之外層密文的加密隨機數。解密時會先還原這些隨機數片段、重新組合出內層密文,並最終解密出隱藏的訊息。我們在標準模型下,正式證明了本方案具備變形安全性(anamorphic security)、完全非對稱 IND-CPA 安全性(fully asymmetric IND-CPA security)以及強 IND-CPA 安全性(strong IND-CPA security),且發送方完全不需要預先共享任何秘密。
Anamorphic encryption provides a technical defense against the invasion of personal privacy in authoritarian environments. By embedding a covert communication channel within standard public-key ciphertexts, it enables citizens to maintain private correspondence even when a dictator can legally seize secret keys or demand the encryption randomness used by the sender. Existing Public-Key Anamorphic Encryption (PKAE) constructions, however, face significant limitations: some rely on specialized mathematical proper-
ties not widely available in standard schemes, while others suffer from restricted anamorphic message spaces.
In this work, we propose the Dual Layer Anamorphic Encryption scheme, a generic PKAE construction that achieves an unrestricted anamorphic message space under the standard model. Our construction combines a μ-message extension framework with randomness-recoverable encryption. An anamorphic message is encrypted by an inner PKE scheme, and the resulting ciphertext is shattered into n pseudorandom pieces via a Pseudorandom Encoding scheme; each piece serves as the encryption randomness for a corresponding outer ciphertext. Decryption recovers the randomness fragments, reassembles the inner ciphertext, and decrypts the hidden message. We formally prove anamorphic security, fully asymmetric IND-CPA security, and strong IND-CPA security entirely in the standard model, with no pre-shared secret required on the sender side.
摘要 i
Abstract ii
Contents iii
List of Notations iv
0.1 Table of Notation iv
1 Introduction 1
1.1 Anamorphic Encryption 1
1.2 Motivation of our work 8
2 Preliminaries 9
2.1 Public key Encryption 10
2.2 Public key Anamorphic Encryption 13
2.3 μ-Message Public Key Anamorphic Encryption Extension 16
3 Our Construction 17
3.1 Dual Layer Anamorphic Encryption scheme 18
3.2 Security Analysis 20
4 Comparison 25
5 Conclusion 28
Bibliography 30
[ACI+20] T. Agrikola, G. Couteau, Y. Ishai, S. Jarecki, and A. Sahai, “On pseudorandom encodings,” in Theory of Cryptography Conference, Springer, 2020, pp. 639–669 (cit. p. 12).
[BGH+23] F. Banfi, K. Gegier, M. Hirt, U. Maurer, and G. Rito, Anamorphic encryption, revisited, Cryptology ePrint Archive, Paper 2023/249, 2023 (cit. pp. 3–5, 7, 9, 12, 16, 26).
[BPR+25] S. Banerjee, T. Pal, A. Rupp, and D. Slamanig, Simple public key anamorphic encryption and signature using multi-message extensions, Cryptology ePrint Archive, Paper 2025/370, 2025 (cit. pp. 7, 8, 12–14, 16, 17, 26, 29).
[CGM24a] D. Catalano, E. Giunta, and F. Migliaro, Anamorphic encryption: New con-structions and homomorphic realizations, Cryptology ePrint Archive, Paper 2024/486, 2024 (cit. p. 9).
[CGM24b] D. Catalano, E. Giunta, and F. Migliaro, Generic anamorphic encryption, re-visited: New limitations and constructions, Cryptology ePrint Archive, Paper 2024/486, 2024 (cit. pp. 13, 25).
[CGM24c] D. Catalano, E. Giunta, and F. Migliaro, Limits of black-box anamorphic en-cryption, Cryptology ePrint Archive, Paper 2024/1098, 2024 (cit. pp. 7, 25, 27).
[CGM25] D. Catalano, E. Giunta, and F. Migliaro, “Generic anamorphic encryption, revisited: New limitations and constructions,” in Advances in Cryptology –EUROCRYPT 2025, Springer, 2025, pp. 275–303 (cit. p. 14)
[CTH10] J.-S. Chou, Y.-M. Tseng, and H.-J. Huang, “On the security of a certificate-based signature scheme,” Information Sciences, vol. 180, no. 6, pp. 1049–1056, 2010 (cit. p. 12).
[DPP+26] X. T. Do, G. Persiano, D. H. Phan, and M. Yung, Randomness-recovery trap-doors: A new methodology for enhancing anamorphic encryption, Cryptology ePrint Archive, Paper 2026/135, 2026 (cit. pp. v, 2, 5–8, 26, 29).
[KPP+23] M. Kutylowski, G. Persiano, D. H. Phan, M. Yung, and M. Zawada, The self-anti-censorship nature of encryption: On the prevalence of anamorphic cryp-tography, Cryptology ePrint Archive, Paper 2023/434, 2023 (cit. p. 27).
[PPY22] G. Persiano, D. H. Phan, and M. Yung, “Anamorphic encryption: Private com-munication against a dictator,” in Advances in Cryptology – EUROCRYPT 2022, Springer, 2022, pp. 34–63 (cit. pp. v, 1–3, 7, 13, 25, 26, 28).
[PPY23] G. Persiano, D. H. Phan, and M. Yung, The self-anti-censorship nature of en-cryption: On the prevalence of anamorphic cryptography, Cryptology ePrint Archive, Paper 2023/434, 2023 (cit. pp. 3, 7, 8).
[PPY24] G. Persiano, D. H. Phan, and M. Yung, “Public-key anamorphism in (cca-secure) public-key encryption and beyond,” in Advances in Cryptology – CRYPTO 2024, Springer, 2024, pp. 422–455 (cit. pp. v, 4, 5, 7–9, 13, 14, 26, 29).
[WCY+23] Y. Wang, R. Chen, M. Yung, and X. Huang, Sender-anamorphic encryption re-formulated: Achieving robust and generic constructions, Full version (A pre-liminary version appears in ASIACRYPT 2023), Nov. 2023 (cit. p. 27).