Large-Universe (Multi-Authority) ABE from LWE
Pratish Datta, Yannis Rouselakis, Junichi Tomida, Nikhil Vanjani
Abstract
An attribute-based encryption (ABE) scheme is "large-universe" if its attribute universe is superpolynomial and is not enumerated during setup. In the multi-authority setting, we further require that each authority can independently manage a superpolynomial set of attributes and dynamically issue an arbitrary polynomial number of secret keys per user. Although large-universe (multi-authority) ABE from pairings is well studied, explicit lattice-based constructions have remained elusive. In the centralized setting, a standard workaround is to instantiate lattice-based ABE for general circuits and encode each attribute as a bit string; however, unless one adopts non-standard lattice assumptions, this approach typically yields prohibitively large ciphertexts. In the multi-authority setting, even though lattice-based ABE for general circuits is known, this bit-encoding approach applied to those schemes does not yield a genuine large-universe construction. We close this gap by presenting the first lattice-based large-universe (multi-authority) ABE schemes under the Learning With Errors (LWE) assumption, achieving ciphertext and key sizes that are comparable to those in the pairing-based setting. Concretely, we construct: • a large-universe key-policy ABE scheme with ciphertext size ; • a large-universe ciphertext-policy ABE scheme with ciphertext size ; and • a large-universe multi-authority ABE scheme, where is the number of attributes, is the policy size, and the notation suppresses factors. All schemes support policies in disjunctive normal form (DNF) and are proved secure in the random oracle model. We further develop more efficient variants of our key-policy and ciphertext-policy ABE schemes over ideal lattices under the Ring-LWE assumption, aiming for practical performance on the order of seconds to minutes. Experimental results from our implementations confirm practical runtimes and memory consumption, providing concrete evidence that large-universe lattice-based ABE is feasible for efficient real-world deployment.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Decentralized Multi-authority ABE for DNFs from LWEPratish Datta, Ilan Komargodski, Brent WatersEUROCRYPT 2021 · 62 citations
- ABE for Circuits with poly (λ) -sized Keys from LWEValerio Cini, Hoeteck WeeFOCS 2023 · 7 citations
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 21 citations
- Almost Optimal KP and CP-ABE for Circuits from Succinct LWEHoeteck WeeEUROCRYPT 2025 · 16 citations
- A General Framework for Lattice-Based ABE Using Evasive Inner-Product Functional EncryptionYao-Ching Hsieh, Huijia Lin, Ji LuoEUROCRYPT 2024 · 12 citations
