Realizing Flexible Broadcast Encryption: How to Broadcast to a Public-Key Directory
Rachit Garg, George Lu, Brent Waters, David J. Wu
摘要
Suppose a user wants to broadcast an encrypted message to 𝐾 recipients. With public-key encryption, the sender would construct 𝐾 different ciphertexts, one for each recipient. The size of the broadcasted message then scales linearly with 𝐾. A natural question is whether the sender can encrypt the message with a ciphertext whose size scales sublinearly with the number of recipients. Broadcast encryption offers one solution to this problem, but at the cost of introducing a central trusted party who issues keys to different users (and correspondingly, has the ability to decrypt all ciphertexts). Recently, several works have introduced notions like distributed broadcast encryption and flexible broadcast encryption, which combine the decentralized, trustless model of traditional public-key encryption with the efficiency guarantees of broadcast encryption. In the specific case of a flexible broadcast encryption scheme, users generate their own public/private keys and can then post their public key in any public-key directory. Subsequently, a user can encrypt to an arbitrary set of user public keys with a ciphertext whose size scales polylogarithmically with the number of public keys in the broadcast set. A distributed broadcast encryption scheme is a more restrictive primitive where each public key is also associated with an index, and one can only encrypt to a set of public keys corresponding to different indices. In this work, we introduce a generic compiler that takes any distributed broadcast encryption scheme and produces a flexible broadcast encryption scheme. Moreover, whereas existing concretely-efficient constructions of distributed broadcast encryption have public keys whose size scales with the maximum number of users in the system, our resulting flexible broadcast encryption scheme has the appealing property that the size of each public key scales with the size of the maximum broadcast set. We provide an implementation of the flexible broadcast encryption scheme obtained by applying our compiler to the distributed broadcast encryption scheme of Kolonelos, Malavolta, and Wee (ASIACRYPT 2023). With our scheme, a sender can encrypt a 128-bit symmetric key to a set of over 1000 recipients (from a directory with a million users) with a 2 KB ciphertext. This is 16× smaller than separately encrypting to each user using standard ElGamal encryption. The cost is that the user public keys in flexible broadcast encryption are much larger (50 KB) compared to standard ElGamal public keys (32 bytes). Compared to the similarly-instantiated distributed broadcast encryption scheme, we achieve a 32× reduction in the user's public key size (50 KB vs. 1.6 MB) without changing the ciphertext size. Thus, flexible broadcast encryption provides an efficient way to encrypt messages to large groups of users at the cost of larger individual public keys (relative to vanilla public-key encryption).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Reducing the CRS Size in Registered ABE SystemsRachit Garg, George Lu, Brent Waters, David J. WuCRYPTO 2024 · 被引用 27 次
- Multi-authority Registered Attribute-Based EncryptionGeorge Lu, Brent Waters, David J. WuEUROCRYPT 2025 · 被引用 14 次
- Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain ModelBrent Waters, David J. WuEUROCRYPT 2026 · 被引用 2 次
- BEAT-MEV: Epochless Approach to Batched Threshold Encryption for MEV PreventionJan Bormet, Sebastian Faust, Hussien Othman, Ziyan QuUSENIX Security 2025
- Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRSRoy Stracovsky, Brent Waters, David J. WuCRYPTO 2026
它引用的顶会 Paper11
- Indistinguishability obfuscation from well-founded assumptionsAayush Jain, Huijia Lin, Amit SahaiSTOC 2021 · 被引用 223 次
- Catena: Efficient Non-equivocation via BitcoinAlin Tomescu, Srinivas DevadasS&P 2017 · 被引用 144 次
- Registered Attribute-Based EncryptionSusan Hohenberger, George Lu, Brent Waters, David J. WuEUROCRYPT 2023 · 被引用 83 次
- SEEMless: Secure End-to-End Encrypted Messaging with less</> TrustMelissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen MalvaiCCS 2019 · 被引用 69 次
- Candidate Witness Encryption from Lattice TechniquesRotem TsabaryCRYPTO 2022 · 被引用 61 次
相关 Paper
- A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain ModelYao-Ching Hsieh, Brent Waters, David J. WuEUROCRYPT 2025 · 被引用 5 次
- Distributed Monotone-Policy Encryption for DNFs from LatticesJeffrey Champion, David J. WuEUROCRYPT 2026 · 被引用 2 次
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 被引用 12 次
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 被引用 49 次
- Scalable Registration-Based Encryption from LatticesMichael Klooß, Russell W. F. Lai, Jan Niklas Siemer, Monisha SwarnakarS&P 2026
