PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 11, 2026Journal of Mathematical Cryptology0 citationsOpen Access

On the security of the CLSV PAEKS scheme

View Full Paper
KEKeita EmuraTOToshihiro OhigashiNSNobuyuki Sugio

Key Points

  • The aim is to evaluate the security of the CLSV public key encryption with keyword search scheme against potential attacks.
  • Demonstrated a concrete attack on the CLSV scheme
  • Analyzed ciphertext structure as ElGamal ciphertext
  • Proposed a ciphertext-trapdoor conversion algorithm
  • Evaluated attack complexity in context of design objectives
  • Successfully retrieves keyword information from ciphertexts
  • Identified the impact of malleability in ElGamal ciphertexts
  • Attack completes in approximately 100 ms
  • Outlined the need for stronger security measures beyond what CLSV provides

Abstract

Abstract Calderini, Longo, Sala and Villa (Journal of Mathematical Cryptology 2024) proposed a public key encryption with keyword search (PKES) scheme which we call the CLSV scheme. They claim that the scheme provides Ciphertext-Indistinguishability (CI) security where no keyword information is leaked from ciphertexts. In this paper, we demonstrate a concrete attack that obtains keyword information from ciphertexts. We point out that a ciphertext of the CLSV scheme is an ElGamal ciphertext, which is malleable. By employing the malleability, we propose a ciphertext-trapdoor conversion algorithm that allows an CI adversary to generate a trapdoor for the challenge keyword without using the receiver’s secret key. We note that our attack follows a security model called full CI security, i.e., the attack needs an active adversary, and lies outside CI security considered in the CLSV paper. Thus, we do not claim to break the CLSV scheme. Due to this situation, we evaluate the validity of our attack model in light of the design objectives of the CLSV scheme. We also analyze the attack complexity, and show that our attack completes about 100 ms.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Emura et al. (2026) studied this question.

synapsesocial.com/papers/69d9e4d578050d08c1b75366https://doi.org/10.1515/jmc-2025-0028
Ask AI
Helpful
Bookmark
Share
View Full Paper