No fixed-construction reduction from CCA1 security to CCA2 security
Statement
If an IND-CCA1-secure PKE scheme exists, then there is a PKE scheme that is IND-CCA1-secure but not IND-CCA2-secure, so the identity map is no reduction from CCA1 to CCA2 security — BDPR98.
Sketch
Given an IND-CCA1-secure , let and let ignore the appended bit . A CCA1 adversary against yields one against that strips the bit from each Phase-1 query and appends to ; a CCA2 adversary flips the last bit of , queries on the result, which differs from , and receives — standard.
Notes
- The converse holds for every scheme: CCA2 security ⇒ CCA1 security — folklore.