- adaptive chosen ciphertext attack
- in which an attacker can arbitrarily use a decryption oracle except for the challenge ciphertext
- decryption oracle
- A service that will decrypt cipher text, yet not reveal the key. Some oracles refuse some particular ciphertext.
- Claw-Free
- See Self-Definable Claw Free Functions
- Non-Malleable
- from ciphertext, can't produce different plaintext "related" to original plaintext.