{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T09:31:45Z","timestamp":1758274305409},"reference-count":58,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,3,9]],"date-time":"2022-03-09T00:00:00Z","timestamp":1646784000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,3,9]],"date-time":"2022-03-09T00:00:00Z","timestamp":1646784000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2022,4]]},"DOI":"10.1007\/s00145-022-09422-6","type":"journal-article","created":{"date-parts":[[2022,3,9]],"date-time":"2022-03-09T00:02:40Z","timestamp":1646784160000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Non-Malleable Functions and their Applications"],"prefix":"10.1007","volume":"35","author":[{"given":"Yu","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baodong","family":"Qin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Deng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sherman S. M.","family":"Chow","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,3,9]]},"reference":[{"key":"9422_CR1","doi-asserted-by":"crossref","unstructured":"M. Abdalla, F. Benhamouda, A. Passel\u00e8gue, K.G. Paterson, Related-key security for pseudorandom functions beyond the linear barrier, in Advances in Cryptology\u2014CRYPTO 2014. LNCS, vol. 8616 (Springer, 2014), pp. 77\u201394","DOI":"10.1007\/978-3-662-44371-2_5"},{"key":"9422_CR2","doi-asserted-by":"crossref","unstructured":"A. Akavia, S. Goldwasser, V. Vaikuntanathan, Simultaneous hardcore bits and cryptography against memory attacks, in Theory of Cryptography, 6th Theory of Cryptography Conference, TCC 2009. LNCS, vol. 5444 (Springer, 2009), pp. 474\u2013495","DOI":"10.1007\/978-3-642-00457-5_28"},{"key":"9422_CR3","unstructured":"B. Applebaum, D. Harnik, Y. Ishai, Semantic security under related-key attacks and applications, in Innovations in Computer Science\u2014ICS 2010 (2011), pp. 45\u201360"},{"key":"9422_CR4","doi-asserted-by":"crossref","unstructured":"M. Bellare, A. Boldyreva, A. O\u2019Neill, Deterministic and efficiently searchable encryption, in Advances in Cryptology\u2014CRYPTO 2007. LNCS, vol. 4622 (Springer, 2007), pp. 535\u2013552","DOI":"10.1007\/978-3-540-74143-5_30"},{"key":"9422_CR5","doi-asserted-by":"crossref","unstructured":"M. Bellare, D. Cash, Pseudorandom functions and permutations provably secure against related-key attacks, in Advances in Cryptology\u2014CRYPTO 2010 (2010), pp. 666\u2013684","DOI":"10.1007\/978-3-642-14623-7_36"},{"key":"9422_CR6","doi-asserted-by":"crossref","unstructured":"A. Boldyreva, D. Cash, M. Fischlin, B. Warinschi, Foundations of non-malleable hash and one-way functions, in Advances in Cryptology\u2014ASIACRYPT 2009 (2009), pp. 524\u2013541","DOI":"10.1007\/978-3-642-10366-7_31"},{"key":"9422_CR7","doi-asserted-by":"crossref","unstructured":"M. Bellare, D. Cash, R. Miller, Cryptography secure against related-key attacks and tampering, in Advances in Cryptology\u2014ASIACRYPT 2011. LNCS, vol. 7073 (Springer, 2011), pp. 486\u2013503","DOI":"10.1007\/978-3-642-25385-0_26"},{"key":"9422_CR8","doi-asserted-by":"crossref","unstructured":"D. Boneh, R.A. DeMillo, R.J. Lipton. On the importance of checking cryptographic protocols for faults (extended abstract), in Advances in Cryptology\u2014EUROCRYPT 1997 (1997), pp. 37\u201351","DOI":"10.1007\/3-540-69053-0_4"},{"key":"9422_CR9","doi-asserted-by":"crossref","unstructured":"M. Bellare, A. Desai, D. Pointcheval, P. Rogaway. Relations among notions of security for public-key encryption schemes, in Advances in Cryptology\u2014CRYPTO 1998.LNCS, vol. 1462 (Springer, 1998), pp. 26\u201345","DOI":"10.1007\/BFb0055718"},{"key":"9422_CR10","doi-asserted-by":"publisher","first-page":"713","DOI":"10.1090\/S0025-5718-1970-0276200-X","volume":"24","author":"ER Berlekamp","year":"1970","unstructured":"E.R. Berlekamp, Factoring polynomials over large finite fields. Math. Comput. 24:713\u2013735 (1970)","journal-title":"Math. Comput."},{"key":"9422_CR11","doi-asserted-by":"crossref","unstructured":"P. Baecher, M. Fischlin, D. Schr\u00f6der, Expedient non-malleability notions for hash functions, in CT-RSA 2011 (2011), pp. 268\u2013283","DOI":"10.1007\/978-3-642-19074-2_18"},{"key":"9422_CR12","doi-asserted-by":"crossref","unstructured":"M. Bellare, S. Halevi, A. Sahai, S.P. Vadhan, Many-to-one trapdoor functions and their ralation to public-key cryptosystems, in CRYPTO 1998. LNCS, vol. 1462 (Springer, 1998), pp. 283\u2013298","DOI":"10.1007\/BFb0055735"},{"key":"9422_CR13","doi-asserted-by":"crossref","unstructured":"M. Bellare, T. Kohno, A theoretical treatment of related-key attacks: RKA-PRPS, RKA-PRFS, and applications, in Advances in Cryptology\u2014EUROCRYPT 2003. LNCS, vol. 2656 (Springer, 2003), pp. 491\u2013506","DOI":"10.1007\/3-540-39200-9_31"},{"key":"9422_CR14","doi-asserted-by":"crossref","unstructured":"M. Bellare, K.G. Paterson, S. Thomson, RKA security beyond the linear barrier: Ibe, encryption and signatures, in ASIACRYPT 2012 (2012), pp. 331\u2013348","DOI":"10.1007\/978-3-642-34961-4_21"},{"key":"9422_CR15","doi-asserted-by":"crossref","unstructured":"M. Bellare, P. Rogaway. Random oracles are practical: A paradigm for designing efficient protocols, in 1st ACM Conference on Computer and Communications Security (1993), pp. 62\u201373","DOI":"10.1145\/168588.168596"},{"key":"9422_CR16","doi-asserted-by":"crossref","unstructured":"E. Biham, A. Shamir. Differential fault analysis of secret key cryptosystems, in Advances in Cryptology\u2014CRYPTO 1997 (1997), pp. 513\u2013525","DOI":"10.1007\/BFb0052259"},{"key":"9422_CR17","doi-asserted-by":"crossref","unstructured":"M. Bellare, A. Sahai, Non-malleable encryption: Equivalence between two notions, and an indistinguishability-based characterization, in Advances in Cryptology\u2014CRYPTO 1999. LNCS, vol. 1666 (Springer, 1999), pp. 519\u2013536","DOI":"10.1007\/3-540-48405-1_33"},{"key":"9422_CR18","doi-asserted-by":"crossref","unstructured":"M. Bellare, I. Stepanovs, S. Tessaro, Poly-many hardcore bits for any one-way function and a framework for differing-inputs obfuscation, in Advances in Cryptology\u2014ASIACRYPT 2014. LNCS, vol. 8874 (Springer, 2014), pp. 102\u2013121","DOI":"10.1007\/978-3-662-45608-8_6"},{"key":"9422_CR19","doi-asserted-by":"crossref","unstructured":"R. Canetti, R.R. Dakdouk, Extractable perfectly one-way functions, in Automata, Languages and Programming, 35th International Colloquium, ICALP 2008. LNCS, vol. 5126 (Springer, 2008), pp. 449\u2013460","DOI":"10.1007\/978-3-540-70583-3_37"},{"key":"9422_CR20","doi-asserted-by":"crossref","unstructured":"D. Catalano, R. Gennaro, N. Howgrave-Graham, The bit security of Paillier\u2019s encryption scheme and its applications, in Advances in Cryptology\u2014EUROCRYPT 2001. Lecture Notes in Computer Science, vol. 2045 (Springer, 2001), pp. 229\u2013243","DOI":"10.1007\/3-540-44987-6_15"},{"key":"9422_CR21","doi-asserted-by":"crossref","unstructured":"G.D. Crescenzo, Y. Ishai, R. Ostrovsky, Non-interactive and non-malleable commitment, in Proceedings of the Thirtieth Annual ACM Symposium on the Theory of Computing, STOC 1998 (ACM, 1998), pp. 141\u2013150","DOI":"10.1145\/276698.276722"},{"key":"9422_CR22","doi-asserted-by":"crossref","unstructured":"G.D. Crescenzo, J. Katz, R. Ostrovsky, A. Smith, Efficient and non-interactive non-malleable commitment, in Advances in Cryptology\u2014EUROCRYPT 2001. LNCS, vol. 2045 (Springer, 2001), pp. 40\u201359","DOI":"10.1007\/3-540-44987-6_4"},{"key":"9422_CR23","doi-asserted-by":"crossref","unstructured":"Y. Chen, B. Qin, J. Zhang, Y. Deng, S.S.M. Chow, Non-malleable functions and their applications, in Public-Key Cryptography\u2014PKC 2016 (2016). Full version to appear at JoC (2022), pp. 386\u2013416","DOI":"10.1007\/978-3-662-49387-8_15"},{"key":"9422_CR24","unstructured":"R. Cramer. Modular design of secure yet practical cryptographic protocols. Ph.D. Thesis (CWI and University of Amsterdam, 1996)"},{"key":"9422_CR25","doi-asserted-by":"crossref","unstructured":"R. Canetti, M. Varia, Non-malleable obfuscation, in Theory of Cryptography, 6th Theory of Cryptography Conference, TCC 2009. LNCS, vol. 5444 (Springer, 2009), pp. 73\u201390","DOI":"10.1007\/978-3-642-00457-5_6"},{"key":"9422_CR26","doi-asserted-by":"crossref","unstructured":"D. Dolev, C. Dwork, M. Naor, Non-malleable cryptography (extended abstract), in STOC (ACM, 1991), pp. 542\u2013552","DOI":"10.1145\/103418.103474"},{"key":"9422_CR27","doi-asserted-by":"crossref","unstructured":"D. Dolev, C. Dwork, M. Naor. Nonmalleable cryptography. SIAM J. Comput. 30(2):391\u2013437 (2000)","DOI":"10.1137\/S0097539795291562"},{"key":"9422_CR28","doi-asserted-by":"crossref","unstructured":"W. Diffie, M.E. Hellman, New directions in cryptograpgy. IEEE Trans. Inf. Theory 22(6):644\u2013654 (1976)","DOI":"10.1109\/TIT.1976.1055638"},{"issue":"1","key":"9422_CR29","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1137\/060651380","volume":"38","author":"Y Dodis","year":"2008","unstructured":"Y. Dodis, R. Ostrovsky, L. Reyzin, A. Smith, Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. SIAM J. Comput. 38(1):97\u2013139 (2008)","journal-title":"SIAM J. Comput."},{"key":"9422_CR30","unstructured":"S. Dziembowski, K. Pietrzak, D. Wichs, Non-malleable codes, in Innovations in Computer Science\u2014ICS 2010 (Tsinghua University Press, 2010), pp. 434\u2013452"},{"key":"9422_CR31","doi-asserted-by":"crossref","unstructured":"Y. Dodis, Y. Yu, Overcoming weak expectations, in Theory of Cryptography\u201410th Theory of Cryptography Conference, TCC 2013. LNCS, vol. 7785 (Springer, 2013), pp. 1\u201322","DOI":"10.1007\/978-3-642-36594-2_1"},{"key":"9422_CR32","doi-asserted-by":"crossref","unstructured":"M. Fischlin, R. Fischlin, Efficient non-malleable commitment schemes, in Advances in Cryptology\u2014CRYPTO 2000. LNCS, vol. 1880 (Springer, 2000), pp. 413\u2013431","DOI":"10.1007\/3-540-44598-6_26"},{"key":"9422_CR33","doi-asserted-by":"crossref","unstructured":"S. Faust, P. Mukherjee, J.B. Nielsen, D. Venturi. Continuous non-malleable codes, in Theory of Cryptography\u201411th Theory of Cryptography Conference, TCC 2014. LNCS, vol. 8349 (Springer, 2014), pp. 465\u2013488","DOI":"10.1007\/978-3-642-54242-8_20"},{"key":"9422_CR34","doi-asserted-by":"crossref","unstructured":"S. Faust, P.Mukherjee, D.Venturi, D. Wichs, Efficient non-malleable codes and key-derivation for poly-size tampering circuits, in Advances in Cryptology\u2014EUROCRYPT 2014. LNCS, vol. 8441 (Springer, 2014), pp. 111\u2013128","DOI":"10.1007\/978-3-642-55220-5_7"},{"key":"9422_CR35","doi-asserted-by":"crossref","unstructured":"O. Goldreich, L.A. Levin, A hard-core predicate for all one-way functions, in Proceedings of the 21st Annual ACM Symposium on Theory of Computing, STOC 1989 (ACM, 1989), pp. 25\u201332","DOI":"10.1145\/73007.73010"},{"key":"9422_CR36","doi-asserted-by":"crossref","unstructured":"D. Goldenberg, M. Liskov, On related-secret pseudorandomness, in Theory of Cryptography, 7th Theory of Cryptography Conference, TCC 2010 (2010), pp. 255\u2013272","DOI":"10.1007\/978-3-642-11799-2_16"},{"key":"9422_CR37","doi-asserted-by":"crossref","unstructured":"V. Goyal, A. O\u2019Neill, V. Rao, Correlated-input secure hash functions, in Theory of Cryptography\u20148th Theory of Cryptography Conference, TCC 2011. LNCS, vol. 6597 (Springer, 2011), pp. 182\u2013200","DOI":"10.1007\/978-3-642-19571-6_12"},{"issue":"3","key":"9422_CR38","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1016\/0022-0000(93)90038-X","volume":"47","author":"J H\u00e5stad","year":"1993","unstructured":"J. H\u00e5stad, A.W. Schrift, A. Shamir, The discrete logarithm modulo a composite hides o(n) bits. J. Comput. Syst. Sci. 47(3):376\u2013404 (1993)","journal-title":"J. Comput. Syst. Sci."},{"key":"9422_CR39","unstructured":"A. Juels, J.G. Brainard, Client puzzles: A cryptographic countermeasure against connection depletion attacks, in Proceedings of the Network and Distributed System Security Symposium, NDSS 1999 (The Internet Society, 1999)"},{"key":"9422_CR40","doi-asserted-by":"crossref","unstructured":"D. Jia, X. Lu, B. Li, Q. Mei, RKA secure PKE based on the DDH and HR assumptions, in Provable Security\u20147th International Conference, ProvSec 2013. LNCS, vol. 8209. (Springer, 2013), pp. 271\u2013287","DOI":"10.1007\/978-3-642-41227-1_16"},{"key":"9422_CR41","doi-asserted-by":"crossref","unstructured":"Z. Jafargholi, D. Wichs, Tamper detection and continuous non-malleable codes, in Theory of Cryptography\u201412th Theory of Cryptography Conference, TCC 2015. LNCS, vol. 9014 (Springer, 2015), pp. 451\u2013480","DOI":"10.1007\/978-3-662-46494-6_19"},{"key":"9422_CR42","doi-asserted-by":"crossref","unstructured":"E. Kiltz, P. Mohassel, A. O\u2019Neill, Adaptive trapdoor functions and chosen-ciphertext security, in Advances in Cryptology\u2014EUROCRYPT 2010 (2010), pp. 673\u2013692","DOI":"10.1007\/978-3-642-13190-5_34"},{"key":"9422_CR43","doi-asserted-by":"crossref","unstructured":"X. Lu, B. Li, D. Jia, Related-key security for hybrid encryption, in Information Security\u201417th International Conference, ISC 2014. LNCS, vol. 8783 (Springer, 2014), pp. 19\u201332","DOI":"10.1007\/978-3-319-13257-0_2"},{"key":"9422_CR44","doi-asserted-by":"crossref","unstructured":"H. Lin, R. Pass, W.-L.D. Tseng, M. Venkitasubramaniam, Concurrent non-malleable zero knowledge proofs, in Advances in Cryptology\u2014CRYPTO 2010. LNCS, vol. 6223 (Springer, 2010), pp. 429\u2013446","DOI":"10.1007\/978-3-642-14623-7_23"},{"key":"9422_CR45","doi-asserted-by":"crossref","unstructured":"S. Lucks, Ciphers secure against related-key attacks, in Fast Software Encryption, 11th International Workshop, FSE 2004 (2004), pp. 359\u2013370","DOI":"10.1007\/978-3-540-25937-4_23"},{"key":"9422_CR46","doi-asserted-by":"crossref","unstructured":"R. Ostrovsky, G. Persiano, I. Visconti, Constant-round concurrent non-malleable zero knowledge in the bare public-key model, in Automata, Languages and Programming, 35th International Colloquium, ICALP 2008. LNCS, vol. 5126 (Springer, 2008), pp. 548\u2013559","DOI":"10.1007\/978-3-540-70583-3_45"},{"key":"9422_CR47","doi-asserted-by":"crossref","unstructured":"O. Pandey, R. Pass, V. Vaikuntanathan, Adaptive one-way functions and applications, in Advances in Cryptology\u2014CRYPTO 2008. LNCS, vol. 5157 (Springer, 2008), pp. 57\u201374","DOI":"10.1007\/978-3-540-85174-5_4"},{"key":"9422_CR48","doi-asserted-by":"crossref","unstructured":"R. Pass, A. Rosen, Concurrent non-malleable commitments, in 46th Annual IEEE Symposium on Foundations of Computer Science, FOCS 2005 (IEEE Computer Society, 2005), pp. 563\u2013572","DOI":"10.1109\/SFCS.2005.27"},{"key":"9422_CR49","doi-asserted-by":"crossref","unstructured":"S. Patel, G.S. Sundaram, An efficient discrete log pseudo random generator, in Advances in Cryptology\u2014CRYPTO 1998.Lecture Notes in Computer Science, vol. 1462. (Springer, 1998), pp. 304\u2013317","DOI":"10.1007\/BFb0055737"},{"key":"9422_CR50","doi-asserted-by":"crossref","unstructured":"C. Peikert, B. Waters, Lossy trapdoor functions and their applications, in Proceedings of the 40th Annual ACM Symposium on Theory of Computing, STOC 2008 (2008), pp. 187\u2013196","DOI":"10.1145\/1374376.1374406"},{"key":"9422_CR51","doi-asserted-by":"crossref","unstructured":"B. Qin, S. Liu, Leakage-resilient chosen-ciphertext secure public-key encryption from hash proof system and one-time lossy filter, in Advances in Cryptology\u2014ASIACRYPT 2013.LNCS, vol. 8270 (Springer, 2013), pp. 381\u2013400","DOI":"10.1007\/978-3-642-42045-0_20"},{"key":"9422_CR52","doi-asserted-by":"crossref","unstructured":"B. Qin, S. Liu, Leakage-flexible CCA-secure public-key encryption: Simple construction and free of pairing, in Public-Key Cryptography - PKC 2014\u201417th International Conference on Practice and Theory in Public-Key Cryptography. LNCS, vol. 8383 (Springer, 2014), pp. 19\u201336","DOI":"10.1007\/978-3-642-54631-0_2"},{"key":"9422_CR53","doi-asserted-by":"crossref","unstructured":"B. Qin, S. Liu, T.H. Yuen, R.H. Deng, K. Chen. Continuous non-malleable key derivation and its application to related-key security, in Public-Key Cryptography\u2014PKC 2015. LNCS, vol. 9020 (Springer, 2015), pp. 557\u2013578","DOI":"10.1007\/978-3-662-46447-2_25"},{"key":"9422_CR54","doi-asserted-by":"crossref","unstructured":"A. Rosen, G. Segev, Chosen-ciphertext security via correlated products, in Theory of Cryptography, 6th Theory of Cryptography Conference, TCC 2009. LNCS, vol. 5444 (Springer, 2009), pp. 419\u2013436","DOI":"10.1007\/978-3-642-00457-5_25"},{"key":"9422_CR55","unstructured":"A. Sahai, Non-malleable non-interactive zero knowledge and adaptive chosen-ciphertext security, in FOCS 1999 (ACM, 1999), pp. 543\u2013553"},{"key":"9422_CR56","doi-asserted-by":"crossref","unstructured":"J. von\u00a0zur Gathen, V. Shoup, Computing frobenius maps and factoring polynomials (extended abstract), in Proceedings of the 24th Annual ACM Symposium on Theory of Computing, STOC 1992 (ACM, 1992), pp. 97\u2013105","DOI":"10.1145\/129712.129722"},{"key":"9422_CR57","doi-asserted-by":"crossref","unstructured":"H. Wee, Efficient chosen-ciphertext security via extractable hash proofs, in Advances in Cryptology\u2014CRYPTO 2010, vol. 6223 (2010), pp. 314\u2013332","DOI":"10.1007\/978-3-642-14623-7_17"},{"key":"9422_CR58","doi-asserted-by":"crossref","unstructured":"H. Wee, Public key encryption against related key attacks, in Public Key Cryptography\u2014PKC 2012 (2012), pp. 262\u2013279","DOI":"10.1007\/978-3-642-30057-8_16"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-022-09422-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00145-022-09422-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-022-09422-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,19]],"date-time":"2024-09-19T23:18:12Z","timestamp":1726787892000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00145-022-09422-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,9]]},"references-count":58,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,4]]}},"alternative-id":["9422"],"URL":"https:\/\/doi.org\/10.1007\/s00145-022-09422-6","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"type":"print","value":"0933-2790"},{"type":"electronic","value":"1432-1378"}],"subject":[],"published":{"date-parts":[[2022,3,9]]},"assertion":[{"value":"23 December 2017","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 January 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 January 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 March 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"11"}}