Candidate Witness Encryption from Lattice Techniques
Rotem Tsabary
Abstract
Witness encryption (WE), first introduced by Garg, Gentry, Sahai and Waters in [GGSW13], is an encryption scheme where messages are encrypted with respect to instances of an NP relation, such that in order to decrypt one needs to know a valid witness for the instance that is associated with the ciphertext.
Despite of significant efforts in the past decade to construct WE from standard assumptions, to the best of our knowledge all of the existing WE candidates either rely directly on iO or use techniques that also seem to imply iO in the same way that they seem to imply WE.
In this work we propose a new hardness assumption with regard to lattice trapdoors and show a witness encryption candidate which is secure under it. Contrary to previous WE candidates, our technique is trivially broken when one tries to convert it to iO, which suggests that the security relies on a different mechanism. We view the gap between WE and iO as an analogue to the gap between ABE and FE and thus potentially significant.
Intuitively, the assumption says that "the best an attacker can do with a trapdoor sample is to use it semi-honestly" -i.e. that LWE with respect to a public matrix A, given as auxiliary information a trapdoor sample K ← A TD (B), is as hard as LWE with respect to the public matrix [A|B] and no auxiliary information.
In order to formally utilize the assumption we define a notion of LWE oracles with generic distributions of public matrices and auxiliary information. This model allows to bound the hardness of LWE with respect to one distribution as a function of the hardness of LWE with respect to another distribution. Repeated arguments of this flavor can be used as a sequence of hybrids in order to gradually change the challenge that an adversary is facing while keeping track on the security loss in each step of the proof. Typically security proofs of LWE-based systems implicitly make arguments of this flavor for distributions that are indistinguishable, while our model allows to make relaxed arguments that in some cases suffice for the proof requirements.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d9d27e38-dc6f-4be1-b606-4761469dc95dCited by top-tier papers9
- Succinct Vector, Polynomial, and Functional Commitments from LatticesHoeteck Wee, David J. WuEUROCRYPT 2023 · 54 citations
- Attribute-Based Encryption for Circuits of Unbounded Depth from LatticesYao-Ching Hsieh, Huijia Lin, Ji LuoFOCS 2023 · 38 citations
- Fully Adaptive Decentralized Multi-Authority ABEPratish Datta, Ilan Komargodski, Brent WatersEUROCRYPT 2023 · 24 citations
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 21 citations
- Indistinguishability Obfuscation, Range Avoidance, and Bounded ArithmeticRahul Ilango, Jiatu Li, R. Ryan WilliamsSTOC 2023 · 17 citations
Builds on4
- Indistinguishability obfuscation from well-founded assumptionsAayush Jain, Huijia Lin, Amit SahaiSTOC 2021 · 223 citations
- Candidate Obfuscation via Oblivious LWE SamplingHoeteck Wee, Daniel WichsEUROCRYPT 2021 · 78 citations
- Candidate iO from Homomorphic Encryption SchemesZvika Brakerski, Nico Döttling, Sanjam Garg, Giulio MalavoltaEUROCRYPT 2020 · 60 citations
- Indistinguishability Obfuscation from Simple-to-State Hard Problems: New Assumptions, New Techniques, and SimplificationRomain Gay, Aayush Jain, Huijia Lin, Amit SahaiEUROCRYPT 2021 · 46 citations
Related papers
- On Witness Encryption and Laconic Zero-Knowledge ArgumentsYanyi Liu, Noam Mazor, Rafael PassCRYPTO 2025 · 1 citation
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 49 citations
- Statistical ZAP ArgumentsSaikrishna Badrinarayanan, Rex Fernando, Aayush Jain, Dakshita Khurana et al.EUROCRYPT 2020 · 36 citations
- Witness Semantic SecurityPaul Lou, Nathan Manohar, Amit SahaiEUROCRYPT 2024
- Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWEShweta Agrawal, Mélissa Rossi, Anshu Yadav, Shota YamadaCRYPTO 2023 · 19 citations
