Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRS
Roy Stracovsky, Brent Waters, David J. Wu
Abstract
Registered attribute-based encryption (ABE) is a generalization of ABE that replaces the central trusted key-issuer with an untrusted key curator. In registered (ciphertext-policy) ABE, users generate their own public keys and there is a transparent aggregation process that takes the public keys of the users together with their attributes and aggregates them into a short master public key that functions as the public key for a standard ABE scheme.
A sequence of works has focused on improving the efficiency and expressivity of pairing-based registered ABE. Today, all constructions of pairing-based registered ABE rely on a structured common reference string (CRS) whose size scales with the total number of users in the system . While the first pairing-based constructions needed a CRS of size , a recent line of work has shown how to reduce it to in the case of general policies (albeit with extremely large constant factors), and to if we restrict the policy family to conjunctions and DNFs (earlier schemes could support general monotone Boolean formulas) and if we analyze security in the generic group model (earlier schemes could be proven secure in the plain model).
In this work, we give the first pairing-based registered ABE scheme with a linear-size CRS that supports general policies (i.e., monotone span programs which include monotone Boolean formulas as well as threshold policies). We can show static security based on a -type assumption in the plain model and adaptive security if we instead work in the random oracle model. Our scheme is also the first pairing-based construction where users can be identified by arbitrary strings (e.g., identities) rather than by integers from a polynomial-size range. This directly enables registered ABE with stateless key-generation. Namely, users in our system can sample their key independently of the current state of the system. Previous approaches require users either to first retrieve the current state of the system before they could generate their key or to generate multiple public keys to avoid collisions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e4da423a-e9ff-4571-8e88-aa50eddc0537Builds on18
- FAME: Fast Attribute-based Message EncryptionShashank Agrawal, Melissa ChaseCCS 2017 · 243 citations
- Registered Attribute-Based EncryptionSusan Hohenberger, George Lu, Brent Waters, David J. WuEUROCRYPT 2023 · 83 citations
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 49 citations
- Verifiable Registration-Based EncryptionRishab Goyal, Satyanarayana VusirikalaCRYPTO 2020 · 45 citations
- FABEO: Fast Attribute-Based Encryption with Optimal SecurityDoreen Riepel, Hoeteck WeeCCS 2022 · 42 citations
Related papers
- Reducing the CRS Size in Registered ABE SystemsRachit Garg, George Lu, Brent Waters, David J. WuCRYPTO 2024 · 27 citations
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 21 citations
- Multi-authority Registered Attribute-Based EncryptionGeorge Lu, Brent Waters, David J. WuEUROCRYPT 2025 · 14 citations
- Unbounded Broadcast and KP-ABE with Sublinear Ciphertext from PairingsJunichi Tomida, Hoeteck WeeCRYPTO 2026
- A Modular Approach to Registered ABE for Unbounded PredicatesNuttapong Attrapadung, Junichi TomidaCRYPTO 2024 · 19 citations
