Efficient chosen ciphertext secure PKE scheme with short ciphertext

Kurosawa and Matsuo[1] showed that MAC can be removed from DHIES while the underlying symmetric-key encryption(SKE) scheme is secure against adaptive chosen ciphertext attacks(INDCCA). We construct a variant of DHIES which eliminate the MAC while the SKE scheme is secure against passive attacks(IND-PA). Since IND-PA is the basic requirement of SKE schemes, the new scheme is more flexible than [1]. Our new scheme can be seen as a combination of a tag-KEM [12] and a DEM. Our construction offers the first tag-KEM with single element. When the hash function H in the ODH assumption is a non-malleable hash function we can prove that the new scheme is IND-CCA secure under the ODH assumption.