DDH ⇒ Multiplicatively homomorphic encryption

Fully-black-box reduction · standard model · ElGamal85, TY98 · security loss: tight: one oracle call, advantage-preserving

Statement

The ElGamal scheme of ElGamal85 over , with and for , is multiplicatively homomorphic: the componentwise product of encryptions of and is distributed exactly as a fresh encryption of — standard. It is semantically secure iff DDH is hard for — TY98.

Sketch

, and is uniform in when is. CPA security is the reduction on DDH ⇒ PKE: on DDH challenge set and answer the challenge query with .

Notes

  • ElGamal85 predates the DDH assumption; the DDH-based CPA proof is later — TY98.