Several breakthrough results have already been achieved in the context of very efficient protocol with provable security.
For isogeny-based cryptography, we revisited the security of two previously proposed important protocols based on
isogenies: the Group Action Hashed ElGamal key encapsulation mechanism and the Group Action Hashed Diffie-Hellman non-interactive key-exchange protocol.
We prove that, suprisingly, active security of the two protocols in the Quantum Random Oracle Model inherently relies on very
strong variants of the Group Action Strong CDH problem, where the adversary is given arbitrary
quantum access to a DDH oracle. That is, quantum accessible Strong CDH assumptions are not
only sufficient but also necessary to prove active security of the GA-HEG KEM and the GA-HDH
NIKE protocols.
For lattice-based cryptography, we proposed new NTRU-based encryption schemes whose efficiency is equal (even slightly better,
actually) then their Ring/Module-LWE counterparts.
We also revisited the provable security of traditional signatures schemes. One of the most widely used digital signature schemes is ECDSA due to its use in TLS, various
Blockchains such as Bitcoin and Ethereum, and many other applications.
Are strong idealized models are necessary for proving the security of ECDSA?
In order to answer this question, we focused on the programmability of ECDSA’s “conversion function” which
maps an elliptic curve point into its x-coordinate modulo the group order. Unfortunately, our main
results are negative. We prove that an algebraic security reduction for can only exist if the security
reduction is allowed to program the conversion function. Consequently, a meaningful security
proof for is unlikely to exist for ECDSA without strong idealizations.