Abstract:
We analyze whether the security of encryption and signature mechanisms in RuCMS is weakened when they are used with the same key. In the case of KEM/DEM encryption (Key/Data Encapsulation Mechanism), to analyze the joint security of encryption and signature, it is sufficient to analyze the joint security of KEM and signature. We obtained the proof of security for RuCMS KEM in the gIND-CCA model, as well as proofs of the joint security for RuCMS KEM and generalized ElGamal signature in the following models: gIND-CCA in the presence of a signing oracle and UF-CMA in the presence of a decapsulation oracle. The results obtained indicate that there are no fundamentally new classes of attacks arising from the use of a single key instead of two separate keys.