How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and More
Cody Freitag, Brent Waters, David J. Wu
摘要
Witness encryption is a generalization of public-key encryption where the public key can be any NP statement x and the associated decryption key is any witness w for x. While early constructions of witness encryption relied on multilinear maps and indistinguishability obfuscation (iO), recent works have provided direct constructions of witness encryption that are more efficient than iO (and also seem unlikely to yield iO). Motivated by this progress, we revisit the possibility of using witness encryption to realize advanced cryptographic primitives previously known only in "obfustopia."
In this work, we give new constructions of trustless encryption systems from plain witness encryption (in conjunction with the learning-with-errors assumption): (1) flexible broadcast encryption (a broadcast encryption scheme where users choose their own secret keys and users can encrypt to an arbitrary set of public keys); and (2) registered attribute-based encryption (a system where users choose their own keys and then register their public key together with a set of attributes with a deterministic and transparent key curator). Both primitives were previously only known from iO. We also show how to use our techniques to obtain an optimal broadcast encryption scheme in the random oracle model.
Underlying our constructions is a novel technique for using witness encryption based on a new primitive which we call function-binding hash functions. Whereas a somewhere statistically binding hash function statistically binds a digest to a few bits of the input, a function-binding hash function statistically binds a digest to the output of a function of the inputs. As we demonstrate in this work, function-binding hash functions provide us new ways to leverage the power of plain witness encryption and use it as the foundation of advanced cryptographic primitives. Finally, we show how to build function-binding hash functions for the class of disjunctions of block functions from leveled homomorphic encryption; this in combination with witness encryption yields our main results.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper8
- Reducing the CRS Size in Registered ABE SystemsRachit Garg, George Lu, Brent Waters, David J. WuCRYPTO 2024 · 被引用 27 次
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 被引用 21 次
- Adaptively-Sound Succinct Arguments for NP from Indistinguishability ObfuscationBrent Waters, David J. WuSTOC 2024 · 被引用 18 次
- Multi-authority Registered Attribute-Based EncryptionGeorge Lu, Brent Waters, David J. WuEUROCRYPT 2025 · 被引用 14 次
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 被引用 12 次
相关 Paper
- On Witness Encryption and Laconic Zero-Knowledge ArgumentsYanyi Liu, Noam Mazor, Rafael PassCRYPTO 2025 · 被引用 1 次
- A Framework for Witness Encryption from Linearly Verifiable SNARKs and ApplicationsSanjam Garg, Mohammad Hajiabadi, Dimitris Kolonelos, Abhiram Kothapalli 等CRYPTO 2025 · 被引用 3 次
- Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWEShweta Agrawal, Mélissa Rossi, Anshu Yadav, Shota YamadaCRYPTO 2023 · 被引用 19 次
- Registered Attribute-Based EncryptionSusan Hohenberger, George Lu, Brent Waters, David J. WuEUROCRYPT 2023 · 被引用 83 次
- Candidate Witness Encryption from Lattice TechniquesRotem TsabaryCRYPTO 2022 · 被引用 61 次
