Multi-authority Registered Attribute-Based Encryption
George Lu, Brent Waters, David J. Wu
Abstract
Registered attribute-based encryption (ABE) enables fine-grained access control to encrypted data without a trusted authority. In this model, users generate their own public keys and register their public key along with a set of attributes with a key curator. The key curator aggregates the public keys into a short master public key that functions as the public key for an ABE scheme.
A limitation of ABE (registered or centralized) is the assumption that a single entity manages all of the attributes in a system. In many settings, the attributes belong to different organizations, making it unrealistic to expect that a single entity manage all of them. In the centralized setting, this motivated the notion of multi-authority ABE, where multiple independent authorities control their individual set of attributes. Access policies are then defined over attributes across multiple authorities.
In this work, we introduce multi-authority registered ABE, where multiple (independent) key curators each manage their individual sets of attributes. Users can register their public keys with any key curator, and access policies can be defined over attributes from multiple key curators. Multi-authority registered ABE combines the trustless nature of registered ABE with the decentralized nature of multi-authority ABE.
We start by constructing a multi-authority registered ABE scheme from composite-order pairing groups. This scheme supports an a priori bounded number of users and access policies that can be represented by a linear secret sharing scheme (which includes monotone Boolean formulas). Our construction relies on a careful integration of ideas from pairing-based registered ABE and multi-authority ABE schemes. We also construct a multi-authority registered ABE scheme that supports an unbounded number of users and arbitrary monotone policies using indistinguishability obfuscation (and function-binding hash functions).
• KeyGen(gpp, gid) → (pk gid , sk gid ): The key-generation algorithm uses the global public parameters gpp and the user identifier gid to generate a public/secret key-pair.
• RegPK(gpp, aux, gid, pk gid ) → (mpk ′ , aux ′ ): The registration algorithm uses the global public parameters gpp, the current state of the key curator aux, the user identifier gid, and the associated public key pk gid , and outputs a new master public key mpk ′ and curator state aux ′ . We require this algorithm to be deterministic (so that it is possible to audit the key curator).
• UpdateKey(gpp, aux, gid) → hsk gid : The update algorithm takes the global public parameters gpp, the curator state aux, and the identifier gid for the user requesting an update, and outputs a helper decryption key hsk gid .
• Encrypt(gep, (𝑆 enc , 𝜑), (aid, mpk aid ) aid∈𝑆 enc , 𝑚) → ct: The encryption algorithm take the global encryption parameters gep, a set of authority identifiers 𝑆 enc , a policy function 𝜑 defined over those authorities, the master public keys mpk aid associated with the authorities aid ∈ 𝑆 enc , and a message 𝑚, and outputs a ciphertext ct.
• Decrypt(gpp, 𝑆, (aid, sk aid,gid , hsk aid,gid ) aid∈𝑆 , ct) → 𝑚: The decryption algorithm takes in the global public parameters gpp, a set of authority identifiers 𝑆, and the secret keys sk aid,gid and helper decryption keys hsk aid,gid , and a ciphertext ct, and outputs the message 𝑚.
The correctness requirement is that any user registered with a set of authorities that satisfy the access policy associated with a ciphertext can successfully recover the message. Security says that any set of users who individually do not satisfy the access policy cannot learn anything about the encrypted message.
Slotted multi-authority registered ABE. Much like in [HLWW23], our constructions of multi-authority registered ABE will proceed in two steps: (1) we first construct a "slotted" version of the primitive; and (2) we show how to generically upgrade the slotted primitive to the full primitive. The slotted multi-authority registered ABE scheme makes the following simplifying assumptions:
• The slotted scheme supports a fixed number of users 𝐿 (which is provided as an explicit parameter to the setup algorithm GlobalSetup).
• The scheme supports one-shot aggregation rather than incremental updates to the public key. Instead of the RegPK, UpdateKey algorithms, the slotted scheme has a single Aggregate algorithm that takes as input the global parameters gpp, and a set of 𝐿 public keys pk 1 , . . . , pk 𝐿 for user identifiers gid 1 , . . . , gid 𝐿 . The aggregate algorithm outputs a succinct master public key mpk and helper decryption keys hsk 𝑖 for each of the users. 𝑡 𝑗 𝑖,0 , 𝑈 𝑡 𝑗 𝑖,1 ) and compute the cross terms as Ŵ𝑖 = 𝑗≠𝑖 𝐻 ( ì 𝐾 𝑗,𝑖 , gid 𝑖 ) = 𝑗≠𝑖 𝐻 ( ì 𝑈 𝑗 , gid 𝑖 ) 𝑡 𝑖 .
More generally, for policies involving 𝑃 attributes, we would use a 𝑃-universal hash function. Putting everything together, our slotted multi-authority registered ABE scheme (for policies involving up to 2 attributes
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b508fe1c-0530-424e-b56e-0a2df26f89ceCited by top-tier papers4
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 12 citations
- Threshold Batched Identity-Based Encryption from Pairings in the Plain ModelJunqing Gong, Brent Waters, Hoeteck Wee, David J. WuEUROCRYPT 2026 · 9 citations
- Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain ModelBrent Waters, David J. WuEUROCRYPT 2026 · 2 citations
- Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRSRoy Stracovsky, Brent Waters, David J. WuCRYPTO 2026
Builds on14
- Registered Attribute-Based EncryptionSusan Hohenberger, George Lu, Brent Waters, David J. WuEUROCRYPT 2023 · 83 citations
- Decentralized Multi-authority ABE for DNFs from LWEPratish Datta, Ilan Komargodski, Brent WatersEUROCRYPT 2021 · 62 citations
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 49 citations
- Efficient Laconic Cryptography from Learning with ErrorsNico Döttling, Dimitris Kolonelos, Russell W. F. Lai, Chuanwei Lin et al.EUROCRYPT 2023 · 46 citations
- Verifiable Registration-Based EncryptionRishab Goyal, Satyanarayana VusirikalaCRYPTO 2020 · 45 citations
Related papers
- Reducing the CRS Size in Registered ABE SystemsRachit Garg, George Lu, Brent Waters, David J. WuCRYPTO 2024 · 27 citations
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 21 citations
- A Modular Approach to Registered ABE for Unbounded PredicatesNuttapong Attrapadung, Junichi TomidaCRYPTO 2024 · 19 citations
- ISABELLA: Improving Structures of Attribute-Based Encryption Leveraging Linear AlgebraDoreen Riepel, Marloes Venema, Tanya VermaCCS 2024 · 1 citation
- Large-Universe (Multi-Authority) ABE from LWEPratish Datta, Yannis Rouselakis, Junichi Tomida, Nikhil VanjaniCCS 2026
