No fixed-construction reduction from CPA security to CCA1 security
Statement
If an IND-CPA-secure PKE scheme exists, then there is a PKE scheme that is IND-CPA-secure but not IND-CCA1-secure, so the identity map is no reduction from CPA to CCA1 security — BDPR98.
Sketch
Given an IND-CPA-secure , let and , and let return on the designated ciphertext , which never outputs. The CPA game never calls , so is IND-CPA-secure; a CCA1 adversary queries in Phase 1, receives , and decrypts — standard.
Notes
- The converse holds for every scheme: CCA1 security ⇒ CPA security — folklore.