2

Recently, I studied about Cramer-Shoup encryption scheme. Then, I read a book which mentioned a simpler version of this scheme, the Cramer-Shoup Lite encryption scheme. I was wondering if there is somewhere a formal proof of IND-CCA security of Cramer-Shoup Lite encryption scheme. Any help would be appreciated.

user178592
  • 41
  • 4

1 Answers1

1

It's far from a full proof, but if you use the sketch from Boaz Barak's lecture notes, together with the full proof of the full scheme from the Cramer-Shoup paper, you should be able to work it out.

Yehuda Lindell
  • 28,270
  • 1
  • 69
  • 86