{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T14:51:08Z","timestamp":1779202268448,"version":"3.51.4"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2009,4,11]],"date-time":"2009-04-11T00:00:00Z","timestamp":1239408000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2009,10]]},"DOI":"10.1007\/s00145-009-9041-6","type":"journal-article","created":{"date-parts":[[2009,4,10]],"date-time":"2009-04-10T14:10:55Z","timestamp":1239372655000},"page":"470-504","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":59,"title":["The Twin Diffie\u2013Hellman Problem and Applications"],"prefix":"10.1007","volume":"22","author":[{"given":"David","family":"Cash","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eike","family":"Kiltz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Victor","family":"Shoup","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,4,11]]},"reference":[{"key":"9041_CR1","series-title":"LNCS","first-page":"191","volume-title":"CT-RSA 2005","author":"M. Abdalla","year":"2005","unstructured":"M. Abdalla, D. Pointcheval, Simple password-based encrypted key exchange protocols, in CT-RSA 2005, ed. by A. Menezes. LNCS, vol. 3376 (Springer, Berlin, 2005), pp. 191\u2013208"},{"key":"9041_CR2","series-title":"LNCS","first-page":"143","volume-title":"CT-RSA 2001","author":"M. Abdalla","year":"2001","unstructured":"M. Abdalla, M. Bellare, P. Rogaway, The oracle Diffie\u2013Hellman assumptions and an analysis of DHIES, in CT-RSA 2001, ed. by D. Naccache. LNCS, vol. 2020 (Springer, Berlin, 2001), pp. 143\u2013158"},{"key":"9041_CR3","unstructured":"J. Baek, B. Lee, K. Kim, Secure length-saving ElGamal encryption under the computational Diffie\u2013Hellman assumption, in ACISP 2000 (2000), pp. 49\u201358"},{"key":"9041_CR4","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1007\/978-3-540-24676-3_14","volume-title":"EUROCRYPT 2004","author":"D. Boneh","year":"2004","unstructured":"D. Boneh, X. Boyen, Efficient selective-ID secure identity based encryption without random oracles, in EUROCRYPT 2004, ed. by C. Cachin, J. Camenisch. LNCS, vol. 3027 (Springer, Berlin, 2004), pp. 223\u2013238"},{"key":"9041_CR5","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1007\/978-3-540-24676-3_4","volume-title":"EUROCRYPT 2004","author":"D. Boneh","year":"2004","unstructured":"D. Boneh, X. Boyen, Short signatures without random oracles, in EUROCRYPT 2004, ed. by C. Cachin, J. Camenisch. LNCS, vol. 3027 (Springer, Berlin, 2004), pp. 56\u201373"},{"key":"9041_CR6","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/3-540-44647-8_13","volume-title":"CRYPTO 2001","author":"D. Boneh","year":"2001","unstructured":"D. Boneh, M.K. Franklin, Identity-based encryption from the Weil pairing, in CRYPTO 2001, ed. by J.\u00a0Kilian. LNCS, vol. 2139 (Springer, Berlin, 2001), pp. 213\u2013229"},{"key":"9041_CR7","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"485","DOI":"10.1007\/978-3-540-76900-2_30","volume-title":"Advances in Cryptology\u2014ASIACRYPT 2007","author":"X. Boyen","year":"2007","unstructured":"X. Boyen, Miniature CCA2 PK encryption: Tight security without redundancy, in Advances in Cryptology\u2014ASIACRYPT 2007. LNCS, vol. 4833 (Springer, Berlin, 2007), pp. 485\u2013501"},{"key":"9041_CR8","doi-asserted-by":"publisher","first-page":"320","DOI":"10.1145\/1102120.1102162","volume-title":"ACM CCS 05","author":"X. Boyen","year":"2005","unstructured":"X. Boyen, Q. Mei, B. Waters, Direct chosen ciphertext security from identity-based techniques, in ACM CCS 05 (ACM Press, New York, 2005), pp. 320\u2013329"},{"key":"9041_CR9","series-title":"LNCS","first-page":"263","volume-title":"CT-RSA 2002","author":"J.-S. Coron","year":"2002","unstructured":"J.-S. Coron, H. Handschuh, M. Joye, P. Paillier, D. Pointcheval, C. Tymen, GEM: A generic chosen-ciphertext secure encryption method, in CT-RSA 2002, ed. by B. Preneel. LNCS, vol. 2271 (Springer, Berlin, 2002), pp. 263\u2013276"},{"key":"9041_CR10","series-title":"LNCS","first-page":"13","volume-title":"CRYPTO\u201998","author":"R. Cramer","year":"1998","unstructured":"R. Cramer, V. Shoup, A practical public key cryptosystem provably secure against adaptive chosen ciphertext attack, in CRYPTO\u201998, ed. by H. Krawczyk. LNCS, vol. 1462 (Springer, Berlin, 1998), pp. 13\u201325"},{"issue":"1","key":"9041_CR11","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1137\/S0097539702403773","volume":"33","author":"R. Cramer","year":"2003","unstructured":"R. Cramer, V. Shoup, Design and analysis of practical public-key encryption schemes secure against adaptive chosen ciphertext attack. SIAM J. Comput.\n                           33(1), 167\u2013226 (2003)","journal-title":"SIAM J. Comput."},{"issue":"6","key":"9041_CR12","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W. Diffie","year":"1976","unstructured":"W. Diffie, M.E. Hellman, New directions in cryptography. IEEE Trans. Inf. Theory\n                           22(6), 644\u2013654 (1976)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"9041_CR13","series-title":"LNCS","first-page":"537","volume-title":"CRYPTO\u201999","author":"E. Fujisaki","year":"1999","unstructured":"E. Fujisaki, T. Okamoto, Secure integration of asymmetric and symmetric encryption schemes, in CRYPTO\u201999, ed. by M.J. Wiener. LNCS, vol. 1666 (Springer, Berlin, 1999), pp. 537\u2013554"},{"key":"9041_CR14","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1007\/978-3-540-24676-3_22","volume-title":"EUROCRYPT 2004","author":"R. Gennaro","year":"2004","unstructured":"R. Gennaro, H. Krawczyk, T. Rabin, Secure hashed Diffie\u2013Hellman over non-DDH groups, in EUROCRYPT 2004, ed. by C. Cachin, J. Camenisch. LNCS, vol. 3027 (Springer, Berlin, 2004), pp. 361\u2013381"},{"key":"9041_CR15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/11818175_9","volume-title":"CRYPTO 2006","author":"C. Gentry","year":"2006","unstructured":"C. Gentry, P. MacKenzie, Z. Ramzan, A method for making password-based key exchange resilient to server compromise, in CRYPTO 2006, ed. by C. Dwork. LNCS (Springer, Berlin, 2006), pp. 142\u2013159"},{"key":"9041_CR16","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9780511546891","volume-title":"Foundations of Cryptography: Basic Tools","author":"O. Goldreich","year":"2001","unstructured":"O. Goldreich, Foundations of Cryptography: Basic Tools, vol. 1 (Cambridge University Press, Cambridge, 2001)"},{"key":"9041_CR17","first-page":"25","volume-title":"21st ACM STOC","author":"O. Goldreich","year":"1989","unstructured":"O. Goldreich, L.A. Levin, A hard-core predicate for all one-way functions, in 21st ACM STOC (ACM Press, New York, 1989), pp. 25\u201332"},{"key":"9041_CR18","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"315","DOI":"10.1007\/978-3-540-30556-9_25","volume-title":"INDOCRYPT 2004","author":"S. Halevi","year":"2004","unstructured":"S. Halevi, EME*: Extending EME to handle arbitrary-length messages with associated data, in INDOCRYPT 2004, ed. by A. Canteaut, K. Viswanathan. LNCS, vol. 3348 (Springer, Berlin, 2004), pp. 315\u2013327"},{"key":"9041_CR19","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"482","DOI":"10.1007\/978-3-540-45146-4_28","volume-title":"CRYPTO 2003","author":"S. Halevi","year":"2003","unstructured":"S. Halevi, P. Rogaway, A tweakable enciphering mode, in CRYPTO 2003, ed. by D. Boneh. LNCS, vol. 2729 (Springer, Berlin, 2003), pp. 482\u2013499"},{"key":"9041_CR20","series-title":"LNCS","first-page":"292","volume-title":"CT-RSA 2004","author":"S. Halevi","year":"2004","unstructured":"S. Halevi, P. Rogaway, A parallelizable enciphering mode, in CT-RSA 2004, ed. by T. Okamoto. LNCS, vol. 2964 (Springer, Berlin, 2004), pp. 292\u2013304"},{"key":"9041_CR21","doi-asserted-by":"crossref","unstructured":"G. Hanaoka, K. Kurosawa, Efficient chosen ciphertext secure public key encryption under the computational Diffie\u2013Hellman assumption, in ASIACRYPT, 2008, pp. 308\u2013325","DOI":"10.1007\/978-3-540-89255-7_19"},{"key":"9041_CR22","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"553","DOI":"10.1007\/978-3-540-74143-5_31","volume-title":"Advances in Cryptology, Proceedings of CRYPTO 2007","author":"D. Hofheinz","year":"2007","unstructured":"D. Hofheinz, E. Kiltz, Secure hybrid encryption from weakened key encapsulation, in Advances in Cryptology, Proceedings of CRYPTO 2007, ed. by A. Menezes. LNCS (Springer, Berlin, 2007), pp. 553\u2013571. Full version available from \n                    http:\/\/eprint.iacr.org\/2007\/288"},{"key":"9041_CR23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/11593447_30","volume-title":"ASIACRYPT 2005","author":"C. Kudla","year":"2005","unstructured":"C. Kudla, K.G. Paterson, Modular security proofs for key agreement protocols, in ASIACRYPT 2005, ed. by B.K. Roy. LNCS, vol. 3788 (Springer, Berlin, 2005), pp. 549\u2013565"},{"key":"9041_CR24","unstructured":"K. Kurosawa, T. Matsuo, How to remove MAC from DHIES, in ACISP 2004 (2004), pp. 236\u2013247"},{"key":"9041_CR25","series-title":"LNCS","first-page":"285","volume-title":"ACNS 05","author":"B. Libert","year":"2005","unstructured":"B. Libert, J.-J. Quisquater, Identity based encryption without redundancy, in ACNS 05, ed. by J. Ioannidis, A. Keromytis, M. Yung. LNCS, vol. 3531 (Springer, Berlin, 2005), pp. 285\u2013300"},{"key":"9041_CR26","series-title":"LNCS","first-page":"268","volume-title":"CRYPTO\u201996","author":"U.M. Maurer","year":"1996","unstructured":"U.M. Maurer, S. Wolf, Diffie\u2013Hellman oracles, in CRYPTO\u201996, ed. by N. Koblitz. LNCS, vol. 1109 (Springer, Berlin, 1996), pp. 268\u2013282"},{"key":"9041_CR27","series-title":"The CRC Press Series on Discrete Mathematics and Its Applications","volume-title":"Handbook of Applied Cryptography","author":"A.J. Menezes","year":"1997","unstructured":"A.J. Menezes, P.C. van Oorschot, S.A. Vanstone, Handbook of Applied Cryptography, The CRC Press Series on Discrete Mathematics and Its Applications (CRC Press, Boca Raton, 1997)"},{"key":"9041_CR28","series-title":"LNCS","first-page":"104","volume-title":"PKC 2001","author":"T. Okamoto","year":"2001","unstructured":"T. Okamoto, D. Pointcheval, The gap-problems: A new class of problems for the security of cryptographic schemes, in PKC 2001, ed. by K. Kim. LNCS, vol. 1992 (Springer, Berlin, 2001), pp. 104\u2013118"},{"key":"9041_CR29","series-title":"LNCS","first-page":"159","volume-title":"CT-RSA 2001","author":"T. Okamoto","year":"2001","unstructured":"T. Okamoto, D. Pointcheval, REACT: Rapid enhanced-security asymmetric cryptosystem transform, in CT-RSA 2001, ed. by D. Naccache. LNCS, vol. 2020 (Springer, Berlin, 2001), pp. 159\u2013175"},{"key":"9041_CR30","series-title":"LNCS","first-page":"182","volume-title":"SAC 2004","author":"D.H. Phan","year":"2004","unstructured":"D.H. Phan, D. Pointcheval, About the security of ciphers (semantic security and pseudo-random permutations), in SAC 2004, ed. by H. Handschuh, A. Hasan. LNCS, vol. 3357 (Springer, Berlin, 2004), pp. 182\u2013197"},{"key":"9041_CR31","unstructured":"R. Sakai, M. Kasahara, ID based cryptosystems with pairing on elliptic curve. Cryptology ePrint Archive, Report 2003\/054, 2003. \n                    http:\/\/eprint.iacr.org\/"},{"key":"9041_CR32","series-title":"LNCS","first-page":"256","volume-title":"EUROCRYPT\u201997","author":"V. Shoup","year":"1997","unstructured":"V. Shoup, Lower bounds for discrete logarithms and related problems, in EUROCRYPT\u201997, ed. by W.\u00a0Fumy. LNCS, vol. 1233 (Springer, Berlin, 1997), pp. 256\u2013266"},{"key":"9041_CR33","series-title":"LNCS","first-page":"241","volume-title":"ACISP 2002","author":"R. Steinfeld","year":"2002","unstructured":"R. Steinfeld, J. Baek, Y. Zheng, On the necessity of strong assumptions for the security of a class of asymmetric encryption schemes, in ACISP 2002. LNCS, vol. 2384 (Springer, Berlin, 2002), pp. 241\u2013256"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-009-9041-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-009-9041-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-009-9041-6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-009-9041-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:42:15Z","timestamp":1586335335000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-009-9041-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,4,11]]},"references-count":33,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2009,10]]}},"alternative-id":["9041"],"URL":"https:\/\/doi.org\/10.1007\/s00145-009-9041-6","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,4,11]]},"assertion":[{"value":"11 June 2008","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2009","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 April 2009","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}