Lune

CRYPTO2023Top-tier venue

Attribute-Based Multi-input FE (and More) for Attribute-Weighted Sums

Shweta Agrawal, Junichi Tomida, Anshu Yadav

2023Year
16Citations
1Top-tier citations

Abstract

Recently, Abdalla, Gong and Wee (Crypto 2020) provided the first functional encryption scheme for attribute-weighted sums (AWS), where encryption takes as input NN (unbounded) attribute-value pairs {x⃗i,z⃗i}I∈[N]\{\vec{x}_i, \vec{z}_i\}_{I \in [N]} where x⃗i\vec{x}_i is public and z⃗i\vec{z}_i is private, the secret key is associated with an arithmetic branching programs ff, and decryption returns the weighted sum ∑i∈[N]f(x⃗i)⊤z⃗i{\sum}_{{i \in [N]}} f(\vec{x}_i)^\top \vec{z}_i, leaking no additional information about the z⃗i\vec{z}_i's. We extend FE for AWS to the significantly more challenging multi-party setting and provide the first construction for attribute-based multi-input FE (MIFE) supporting AWS. For i∈[n]i \in [n], encryptor ii can choose an attribute y⃗i\vec{y}_i together with AWS input {x⃗i,j,z⃗i,j}\{\vec{x}_{i,j}, \vec{z}_{i,j}\} where j∈[Ni]j \in [N_i] and NiN_i is unbounded, the key generator can choose an access control policy gig_i along with its AWS function hih_i for each i∈[n]i \in [n], and the decryptor can compute

∑i∈[n]∑j∈[Ni]hi(x⃗i,j)⊤z⃗i,j iff gi(y⃗i)=0 for all i∈[n]\sum_{i \in [n]}\sum_{j \in [N_{i}]}h_{i}(\vec{x}_{i,j})^{\top}\vec{z}_{i,j} \text{ iff } g_{i}(\vec{y}_{i}) =0 \text{ for all } i \in [n]

Previously, the only known attribute based MIFE was for the inner product functionality (Abdalla et al. Asiacrypt 2020), where additionally, y⃗i\vec{y}_i had to be fixed during setup and must remain the same for all ciphertexts in a given slot. Our attribute based MIFE implies the notion of multi-input attribute based encryption () recently studied by Agrawal, Yadav and Yamada (Crypto 2022) and Francati, Friolo, Malavolta and Venturi (Eurocrypt 2023), for a conjunction of predicates represented as arithmetic branching programs (ABP). Along the way, we also provide the first constructions of multi-client FE (MCFE) and dynamic decentralized FE (DDFE) for the AWS functionality. Previously, the best known MCFE and DDFE schemes were for inner products (Chotard et al. ePrint 2018, Abdalla, Benhamouda and Gay, Asiacrypt 2019, and Chotard et al. Crypto 2020). Our constructions are based on pairings and proven selectively secure under the matrix DDH assumption.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 781803a4-2a64-4e1f-ae98-8c010084394e

Cited by top-tier papers1

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines