Whether CPA-plus security implies identical-challenge CPA security

Determine whether CPA-plus anti-piracy security implies identical-challenge CPA security for single-decryptor encryption.

Background

Identical-challenge CPA security requires two freeloaders to distinguish the same ciphertext using their respective portions of a quantum decryption key. The paper establishes that IDEN-CPA security does not imply CPA-plus security through a two-key construction.

The converse implication remains unresolved and is identified as the N=1 instance of the broader question concerning whether CPA-plus security implies full SDE-CORR security.

References

In particular, it is not known whether CPA${+}$ implies IDEN-CPA security.

Copy-Protection with Correlated Challenges: Point Functions and More via Decisional Coset Monogamy  (2608.18841 - Behera et al., 19 Aug 2026) in Section “Hierarchy of Definitions,” immediately after the statement that full SDE-CORR may differ from CPA+

Thus, separating CPA${+}$ from IDEN-CPA would require an entangled attack that specifically exploits the fact that both parties receive the same ciphertext. Constructing such an attack remains open.

Copy-Protection with Correlated Challenges: Point Functions and More via Decisional Coset Monogamy  (2608.18841 - Behera et al., 19 Aug 2026) in Section “Hierarchy of Definitions,” immediately after Lemma “Separable IDEN-CPA attacks violate strong CPA”