Lune

CRYPTO2023顶会

Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWE

Shweta Agrawal, Mélissa Rossi, Anshu Yadav, Shota Yamada

2023年份
19被引次数
1顶会引用

摘要

Constructing advanced cryptographic primitives such as obfuscation or broadcast encryption from standard hardness assumptions in the post quantum regime is an important area of research, which has met with limited success despite significant effort. It is therefore extremely important to find new, simple to state assumptions in this regime which can be used to fill this gap. An important step was taken recently by Wee (Eurocrypt '22) who identified two new assumptions from lattices, namely evasive LWE{\sf LWE} and tensor LWE{\sf LWE}, and used these to construct broadcast encryption and ciphertext policy attribute based encryption for P{\sf P} with optimal parameters. Independently, Tsabary formulated a similar assumption and used it to construct witness encryption (Crypto '22). Following Wee's work, Vaikuntanathan, Wee and Wichs independently provided a construction of witness encryption (Asiacrypt '22).

In this work, we advance this line of research by providing the first construction of multi-input attribute based encryption (MIABE{\sf MIABE}) for the function class NC1{\sf NC_1} for any constant arity from evasive LWE{\sf LWE}. Our construction can be extended to support the function class P{\sf P} by using evasive and a suitable strengthening of tensor LWE{\sf LWE}. In more detail, our construction supports kk encryptors, for any constant kk, where each encryptor uses the master secret key msk{\sf msk} to encode its input (xi,mi)(\mathbf{x}_i, m_i), the key generator computes a key skf{\sf sk}_f for a function f∈NC1f \in {\sf NC}_1 and the decryptor can recover (m1,…,mk)(m_1,\ldots,m_k) if and only if f(x1,…,xk)=1f(\mathbf{x}_1,\ldots,\mathbf{x}_k)=1. The only known construction for MIABE{\sf MIABE} for NC1{\sf NC}_1 by Agrawal, Yadav and Yamada (Crypto '22) supports arity 22 and relies on pairings in the generic group model (or with a non-standard knowledge assumption) in addition to LWE{\sf LWE}. Furthermore, it is completely unclear how to go beyond arity 22 using this approach due to the reliance on pairings.

Using a compiler from Agrawal, Yadav and Yamada (Crypto '22), our MIABE{\sf MIABE} can be upgraded to multi-input predicate encryption for the same arity and function class. Thus, we obtain the first constructions for constant-arity predicate and attribute based encryption for a generalized class such as NC1{\sf NC}_1 or P{\sf P} from simple assumptions that may be conjectured post-quantum secure. Along the way, we show that the tensor LWE{\sf LWE} assumption can be reduced to standard LWE{\sf LWE} in an important special case which was not known before. This adds confidence to the plausibility of the assumption and may be of wider interest.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖