Whether CPA-plus security implies full correlated-challenge SDE security

Determine whether CPA-plus anti-piracy security implies full SDE-CORR security for single-decryptor encryption, including the identical-challenge mode.

Background

The paper introduces SDE-CORR as a security notion allowing correlated challenge bits and both separate- and identical-challenge modes. It proves that the restriction of SDE-CORR to separate mode is equivalent to CPA-plus security, and that SDE-CORR implies strong CPA security.

The unresolved issue is whether CPA-plus security also suffices for the full correlated-challenge notion. Any possible separation must therefore exploit the identical-challenge mode, where both parties receive the same ciphertext.

References

It is not known whether CPA${+}$ security implies full SDE-CORR security.

Copy-Protection with Correlated Challenges: Point Functions and More via Decisional Coset Monogamy  (2608.18841 - Behera et al., 19 Aug 2026) in Section “Hierarchy of Definitions,” immediately after Theorem “Separate mode is exactly CPA+”