{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T10:01:12Z","timestamp":1773223272824,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2006,10,30]],"date-time":"2006-10-30T00:00:00Z","timestamp":1162166400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2006,10,30]]},"DOI":"10.1145\/1180405.1180452","type":"proceedings-article","created":{"date-parts":[[2007,1,17]],"date-time":"2007-01-17T01:15:56Z","timestamp":1168996556000},"page":"380-389","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Stateful public-key cryptosystems"],"prefix":"10.1145","author":[{"given":"Mihir","family":"Bellare","sequence":"first","affiliation":[{"name":"University of California San Diego, La Jolla, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tadayoshi","family":"Kohno","sequence":"additional","affiliation":[{"name":"University of Washington, Seattle, WA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Victor","family":"Shoup","sequence":"additional","affiliation":[{"name":"New York University, New York, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2006,10,30]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"LNCS 3494","author":"Abe M.","unstructured":"M. Abe , R. Gennaro , K. Kurosawa and V. Shoup . Tag-KEM\/DEM: A New Framework for Hybrid Encryption and a New Analysis of Kurosawa Desmedt KEM. EUROCRYPT '05 , LNCS 3494 , Springer-Verlag .]] M. Abe, R. Gennaro, K. Kurosawa and V. Shoup. Tag-KEM\/DEM: A New Framework for Hybrid Encryption and a New Analysis of Kurosawa Desmedt KEM. EUROCRYPT '05, LNCS 3494, Springer-Verlag.]]"},{"key":"e_1_3_2_1_2_1","volume-title":"LNCS","author":"Abdalla M.","year":"2020","unstructured":"M. Abdalla , M. Bellare and P. Rogaway . The Oracle Diffie-Hellman Assumptions and an Analysis of DHIES. CT-RSA '01 , LNCS 2020 , Springer-Verlag .]] M. Abdalla, M. Bellare and P. Rogaway. The Oracle Diffie-Hellman Assumptions and an Analysis of DHIES. CT-RSA '01, LNCS 2020, Springer-Verlag.]]"},{"key":"e_1_3_2_1_4_1","volume-title":"LNCS 2332","author":"An J.","unstructured":"J. An , Y. Dodis and T. Rabin . On the Security of Joint Signature and Encryption. EUROCRYPT '02 , LNCS 2332 , Springer-Verlag .]] J. An, Y. Dodis and T. Rabin. On the Security of Joint Signature and Encryption. EUROCRYPT '02, LNCS 2332, Springer-Verlag.]]"},{"key":"e_1_3_2_1_5_1","volume-title":"LNCS 3027","author":"Bellare M.","unstructured":"M. Bellare , A. Boldyreva and A. Palacio . An Uninstantiable Random-Oracle-Model Scheme for a Hybrid-Encryption Problem. EUROCRYPT '04 , LNCS 3027 , Springer-Verlag .]] M. Bellare, A. Boldyreva and A. Palacio. An Uninstantiable Random-Oracle-Model Scheme for a Hybrid-Encryption Problem. EUROCRYPT '04, LNCS 3027, Springer-Verlag.]]"},{"key":"e_1_3_2_1_6_1","volume-title":"LNCS 2567","author":"Bellare M.","unstructured":"M. Bellare , A. Boldyreva and J. Staddon . Multi-Recipient Encryption Schemes: Security Notions and Randomness Re-Use. PKC '03 , LNCS 2567 , Springer-Verlag .]] M. Bellare, A. Boldyreva and J. Staddon. Multi-Recipient Encryption Schemes: Security Notions and Randomness Re-Use. PKC '03, LNCS 2567, Springer-Verlag.]]"},{"key":"e_1_3_2_1_7_1","volume-title":"LNCS 1109","author":"Bellare M.","unstructured":"M. Bellare , R. Canetti and H. Krawczyk . Keying hash functions for message authentication. CRYPTO '96 , LNCS 1109 , Springer-Verlag .]] M. Bellare, R. Canetti and H. Krawczyk. Keying hash functions for message authentication. CRYPTO '96, LNCS 1109, Springer-Verlag.]]"},{"key":"e_1_3_2_1_8_1","volume-title":"Proc. 38th FOCS, IEEE","author":"Bellare M.","year":"1997","unstructured":"M. Bellare , A. Desai , E. Jokipii and P. Rogaway . A Concrete Security Treatment of Symmetric Encryption: Analysis of the DES Modes of Operation . Proc. 38th FOCS, IEEE , 1997 .]] M. Bellare, A. Desai, E. Jokipii and P. Rogaway. A Concrete Security Treatment of Symmetric Encryption: Analysis of the DES Modes of Operation. Proc. 38th FOCS, IEEE, 1997.]]"},{"key":"e_1_3_2_1_9_1","volume-title":"LNCS 1462","author":"Bellare M.","unstructured":"M. Bellare , A. Desai , D. Pointcheval and P. Rogaway . Relations among notions of security for public-key encryption schemes. CRYPTO '98 , LNCS 1462 , Springer-Verlag .]] M. Bellare, A. Desai, D. Pointcheval and P. Rogaway. Relations among notions of security for public-key encryption schemes. CRYPTO '98, LNCS 1462, Springer-Verlag.]]"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44448-3_41"},{"key":"e_1_3_2_1_12_1","volume-title":"LNCS 4004","author":"Bellare M.","unstructured":"M. Bellare and P. Rogaway . Code-Based Game-Playing Proofs and the Security of Triple Encryption. EUROCRYPT '06 , LNCS 4004 , Springer-Verlag .]] M. Bellare and P. Rogaway. Code-Based Game-Playing Proofs and the Security of Triple Encryption. EUROCRYPT '06, LNCS 4004, Springer-Verlag.]]"},{"key":"e_1_3_2_1_13_1","volume-title":"LNCS 1294","author":"Bellare M.","unstructured":"M. Bellare and P. Rogaway . Collision-Resistant Hashing: Towards Making UOWHFs Practical. CRYPTO '97 , LNCS 1294 , Springer-Verlag .]] M. Bellare and P. Rogaway. Collision-Resistant Hashing: Towards Making UOWHFs Practical. CRYPTO '97, LNCS 1294, Springer-Verlag.]]"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/168588.168596"},{"key":"e_1_3_2_1_15_1","volume-title":"LNCS 3376","author":"Boneh D.","unstructured":"D. Boneh and J. Katz . Improved Efficiency for CCA-Secure Cryptosystems Built Using Identity Based Encryption. CT-RSA '05 , LNCS 3376 , Springer-Verlag .]] D. Boneh and J. Katz. Improved Efficiency for CCA-Secure Cryptosystems Built Using Identity Based Encryption. CT-RSA '05, LNCS 3376, Springer-Verlag.]]"},{"key":"e_1_3_2_1_16_1","volume-title":"LNCS 2567","author":"Boldyreva A.","unstructured":"A. Boldyreva . Threshold Signatures , Multisignatures and Blind Signatures Based on the Gap Diffie-Hellman Group Signature Scheme. PKC '03 , LNCS 2567 , Springer-Verlag .]] A. Boldyreva. Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap Diffie-Hellman Group Signature Scheme. PKC '03, LNCS 2567, Springer-Verlag.]]"},{"key":"e_1_3_2_1_17_1","volume-title":"LNCS 773","author":"Brands S.","unstructured":"S. Brands . Untraceable off-line cash in wallets with observers. CRYPTO '93 , LNCS 773 , Springer-Verlag .]] S. Brands. Untraceable off-line cash in wallets with observers. CRYPTO '93, LNCS 773, Springer-Verlag.]]"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1049\/el:19891013"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/276698.276741"},{"key":"e_1_3_2_1_20_1","volume-title":"LNCS 3027","author":"Canetti R.","unstructured":"R. Canetti , S. Halevi and J. Katz . Chosen-Ciphertext Security from Identity-Based Encryption. EUROCRYPT '04 , LNCS 3027 , Springer-Verlag .]] R. Canetti, S. Halevi and J. Katz. Chosen-Ciphertext Security from Identity-Based Encryption. EUROCRYPT '04, LNCS 3027, Springer-Verlag.]]"},{"key":"e_1_3_2_1_21_1","volume-title":"LNCS 304","author":"Chaum D.","unstructured":"D. Chaum , J. Evertse and J. van de Graaf . An improved protocol for demonstrating possession of discrete logarithms and some generalizations. EUROCRYPT '87 , LNCS 304 , Springer-Verlag .]] D. Chaum, J. Evertse and J. van de Graaf. An improved protocol for demonstrating possession of discrete logarithms and some generalizations. EUROCRYPT '87, LNCS 304, Springer-Verlag.]]"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539702403773"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539795291562"},{"key":"e_1_3_2_1_24_1","volume-title":"LNCS","author":"Desai A.","year":"1880","unstructured":"A. Desai . New Paradigms for Constructing Symmetric Encryption Schemes Secure against Chosen Ciphertext Attack. CRYPTO '00 , LNCS 1880 , Springer-Verlag .]] A. Desai. New Paradigms for Constructing Symmetric Encryption Schemes Secure against Chosen Ciphertext Attack. CRYPTO '00, LNCS 1880, Springer-Verlag.]]"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1985.1057074"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0000(84)90070-9"},{"key":"e_1_3_2_1_28_1","volume-title":"LNCS","author":"Katz J.","year":"1978","unstructured":"J. Katz and M. Yung . Unforgeable Encryption and Chosen Ciphertext Secure Modes of Operation. FSE '00 , LNCS 1978 , Springer-Verlag .]] J. Katz and M. Yung. Unforgeable Encryption and Chosen Ciphertext Secure Modes of Operation. FSE '00, LNCS 1978, Springer-Verlag.]]"},{"key":"e_1_3_2_1_29_1","volume-title":"LNCS 3876","author":"Kiltz E.","unstructured":"E. Kiltz . Chosen-Ciphertext Security from Tag-Based Encryption. Theory of Cryptography -- TCC '06 , LNCS 3876 , Springer-Verlag .]] E. Kiltz. Chosen-Ciphertext Security from Tag-Based Encryption. Theory of Cryptography -- TCC '06, LNCS 3876, Springer-Verlag.]]"},{"key":"e_1_3_2_1_30_1","volume-title":"LNCS 2274","author":"Kurosawa K.","unstructured":"K. Kurosawa . Multi-Recipient Public-Key Encryption with Shortened Ciphertext. PKC '02 , LNCS 2274 , Springer-Verlag .]] K. Kurosawa. Multi-Recipient Public-Key Encryption with Shortened Ciphertext. PKC '02, LNCS 2274, Springer-Verlag.]]"},{"key":"e_1_3_2_1_31_1","volume-title":"LNCS 3152","author":"Kurosawa K.","unstructured":"K. Kurosawa and Y. Desmedt . A New Paradigm of Hybrid Encryption Scheme. CRYPTO '04 , LNCS 3152 , Springer-Verlag .]] K. Kurosawa and Y. Desmedt. A New Paradigm of Hybrid Encryption Scheme. CRYPTO '04, LNCS 3152, Springer-Verlag.]]"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/73007.73011"},{"key":"e_1_3_2_1_33_1","volume-title":"May","author":"Block Cipher ST.","year":"2005","unstructured":"NI ST. Recommendation for Block Cipher Modes of Operation : The CMAC Mode for Authentication. Document SP 800-38B , May 2005 .]] NIST. Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication. Document SP 800-38B, May 2005.]]"},{"key":"e_1_3_2_1_34_1","volume-title":"LNCS","author":"Okamoto T.","year":"1992","unstructured":"T. Okamoto and D. Pointcheval . The Gap Problems: A New Class of Problems for the Security of Cryptographic Schemes. PKC '01 , LNCS 1992 , Springer-Verlag .]] T. Okamoto and D. Pointcheval. The Gap Problems: A New Class of Problems for the Security of Cryptographic Schemes. PKC '01, LNCS 1992, Springer-Verlag.]]"},{"key":"e_1_3_2_1_35_1","volume-title":"LNCS 576","author":"Rackoff C.","unstructured":"C. Rackoff and D. Simon . Non-interactive zero knowledge proof of knowledge and chosen ciphertext attack. CRYPTO '91 , LNCS 576 , Springer-Verlag .]] C. Rackoff and D. Simon. Non-interactive zero knowledge proof of knowledge and chosen ciphertext attack. CRYPTO '91, LNCS 576, Springer-Verlag.]]"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/937527.937529"},{"key":"e_1_3_2_1_38_1","volume-title":"Why chosen ciphertext security matters. IBM Research Report RZ","author":"Shoup V.","year":"1998","unstructured":"V. Shoup . Why chosen ciphertext security matters. IBM Research Report RZ 3076, November 1998 .]] V. Shoup. Why chosen ciphertext security matters. IBM Research Report RZ 3076, November 1998.]]"},{"key":"e_1_3_2_1_39_1","volume-title":"Digital Signcryption or How to Achieve Cost(Signature & Encryption) &lt;&lt;&lt","author":"Zheng Y.","unstructured":"Y. Zheng . Digital Signcryption or How to Achieve Cost(Signature & Encryption) &lt;&lt;&lt ; Cost(Signature) + Cost(Encryption). CRYPTO '97, LNCS 1294, Springer-Verlag .]] Y. Zheng. Digital Signcryption or How to Achieve Cost(Signature & Encryption) &lt;&lt;&lt; Cost(Signature) + Cost(Encryption). CRYPTO '97, LNCS 1294, Springer-Verlag.]]"}],"event":{"name":"CCS06: 13th ACM Conference on Computer and Communications Security 2006","location":"Alexandria Virginia USA","acronym":"CCS06","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the 13th ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1180405.1180452","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,7]],"date-time":"2023-01-07T09:14:28Z","timestamp":1673082868000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1180405.1180452"}},"subtitle":["how to encrypt with one 160-bit exponentiation"],"short-title":[],"issued":{"date-parts":[[2006,10,30]]},"references-count":35,"alternative-id":["10.1145\/1180405.1180452","10.1145\/1180405"],"URL":"https:\/\/doi.org\/10.1145\/1180405.1180452","relation":{},"subject":[],"published":{"date-parts":[[2006,10,30]]},"assertion":[{"value":"2006-10-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}