Optimal Threshold Traitor Tracing
Sourav Das, Pratish Datta, Aditi Partap, Swagata Sasmal, Mark Zhandry
Abstract
Threshold encryption distributes decryption capability across parties such that any of them can jointly decrypt a ciphertext, while smaller coalitions learn nothing. However, once or more parties collude, traditional threshold schemes provide no accountability: a coalition of or more parties can pool its keys into a pirate decoder that enables unrestricted decryption, all without any risk of being exposed. To address this, Boneh, Partap, and Rotem [CRYPTO '24] introduced threshold traitor tracing (TTT), which equips threshold encryption with traceability. Yet, all known TTT schemes either suffer from parameter sizes growing with at least , or rely on indistinguishability obfuscation to achieve optimal parameters.
In this paper, we present the first TTT schemes with optimal parameters, where public keys, secret keys, and ciphertexts are all bounded by , built solely from standard cryptographic tools and assumptions. Our first construction relies on the decisional Bilinear Diffie–Hellman (DBDH) assumption in prime order bilinear groups. Our second scheme is a candidate construction based on the Learning with Errors (LWE) assumption, which relies on the existence of secret sharing schemes with certain properties. This construction is plausibly post-quantum secure, and supports ramp-thresholds where decryption requires a larger coalition than those tolerated by security. Both of our constructions provide traceability against coalitions of arbitrary sizes.
To achieve these results, we introduce a new primitive, Attribute-Based Threshold Encryption (ABTE), which generalizes both threshold and attribute-based encryption. We then combine ABTE with Mixed Functional Encryption through a new compiler to obtain our TTT schemes. We believe ABTE is a powerful primitive that may have independent applications beyond optimal TTT.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7b2d8bf2-a956-4f46-9c04-30f2a1d8a4d9Related papers
- Optimal Traitor Tracing from PairingsMark ZhandryEUROCRYPT 2025 · 3 citations
- CCA-Secure Traceable Threshold (ID-based) Encryption and ApplicationRishiraj Bhattacharyya, Jan Bormet, Sebastian Faust, Pratyay Mukherjee et al.CCS 2025 · 2 citations
- Traitor Tracing with N1/3-Size Ciphertexts and O(1)-Size Keys from k-LinJunqing Gong, Ji Luo, Hoeteck WeeEUROCRYPT 2023 · 12 citations
- Broadcast, Trace and Revoke with Optimal Parameters from Polynomial HardnessShweta Agrawal, Simran Kumari, Anshu Yadav, Shota YamadaEUROCRYPT 2023 · 7 citations
- Accountability for Misbehavior in Threshold Decryption via Threshold Traitor TracingDan Boneh, Aditi Partap, Lior RotemCRYPTO 2024 · 16 citations
