Equivocal Broadcast Encryption: Adaptively-Secure Optimal Distributed Broadcast Encryption from Lattices
Rishab Goyal, Saikumar Yadugiri
Abstract
We present the first Distributed Broadcast Encryption (DBE) scheme from falsifiable lattice assumptions that achieves adaptive security with optimal parameters (short public/secret keys and ciphertexts). Our construction enjoys transparent setup and offers flexible instantiation: we achieve a succinct CRS in the Random Oracle Model, or a long CRS in the standard model. Previously, no lattice-based DBE simultaneously achieved adaptivity and optimal parameters in either setting.
To achieve this, we introduce a new methodology for proving adaptive security: . This framework operates in two indistinguishable modes: a 'real' mode utilizing standard algorithms, and a 'fake' mode where keys and ciphertexts are jointly sampled with auxiliary trapdoors, enabling the dynamic equivocation of ciphertexts to arbitrary challenge values. While our approach is technically distinct from the celebrated Dual System Encryption (Waters, CRYPTO'09), we believe it could serve as a similarly powerful paradigm for realizing adaptive security across a broad class of lattice-based encryption systems.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ba83380c-597b-470a-bcde-56b544eee657Cited by top-tier papers1
Ask how each one uses itRelated papers
- A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain ModelYao-Ching Hsieh, Brent Waters, David J. WuEUROCRYPT 2025 · 5 citations
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 12 citations
- Handling Adaptive Compromise for Practical Encryption SchemesJoseph Jaeger, Nirvan TyagiCRYPTO 2020 · 14 citations
- Adaptively Secure, Universally Composable Distributed Generation of Discrete-Logarithm Based Keys from Standard AssumptionsHanna Ek, Kelsey Melissaris, Lawrence RoyCRYPTO 2026
- Optimal Broadcast Encryption and CP-ABE from Evasive Lattice AssumptionsHoeteck WeeEUROCRYPT 2022 · 75 citations
