IND$-CPA Security ⇒ CPA Security

Fully-black-box reduction · standard model · folklore · security loss: factor 2

Statement

Every IND$-CPA-secure SKE scheme is CPA-secure — folklore. For every CPA adversary there are IND$-CPA adversaries , each running once, with

Sketch

answers each query of with its own oracle on and outputs ‘s guess: with the real oracle it simulates , with the uniform oracle an oracle independent of . The triangle inequality over the hybrids , uniform, gives the bound.

Notes

  • The converse fails for the identity construction: appending a constant bit to every ciphertext preserves CPA security and breaks IND$-CPA security (CPA ⇏ IND$-CPA) — folklore.