Broadcast, Trace and Revoke with Optimal Parameters from Polynomial Hardness
Shweta Agrawal, Simran Kumari, Anshu Yadav, Shota Yamada
摘要
A broadcast, trace and revoke system generalizes broadcast encryption as well as traitor tracing. In such a scheme, an encryptor can specify a list of revoked users so that (i) users in can no longer decrypt ciphertexts, (ii) ciphertext size is independent of , (iii) a pirate decryption box supports tracing of compromised users. The ``holy grail'' of this line of work is a construction which resists unbounded collusions, achieves all parameters (including public and secret key) sizes independent of and , and is based on polynomial hardness assumptions. In this work we make the following contributions:
-
Public Trace Setting: We provide a construction which (i) achieves optimal parameters, (ii) supports embedding identities (from an exponential space) in user secret keys, (iii) relies on polynomial hardness assumptions, namely compact functional encryption () and a key-policy attribute based encryption () with special efficiency properties, and (iv) enjoys adaptive security with respect to the revocation list. The previous best known construction by Nishimaki, Wichs and Zhandry (Eurocrypt 2016) which achieved optimal parameters and embedded identities, relied on indistinguishability obfuscation, which is considered an inherently subexponential assumption and achieved only selective security with respect to the revocation list.
-
Secret Trace Setting: We provide the first construction with optimal ciphertext, public and secret key sizes and embedded identities from any assumption outside Obfustopia. In detail, our construction relies on Lockable Obfuscation which can be constructed using (Goyal, Koppula, Waters and Wichs, Zirdelis, Focs 2017) and two schemes: (i) the key-policy scheme with special efficiency properties by Boneh et al. (Eurocrypt 2014) and (ii) a ciphertext-policy for which was recently constructed by Wee (Eurocrypt 2022) using a new assumption called evasive and tensor . This assumption, introduced to build an , is believed to be much weaker than lattice based assumptions underlying or -- in particular it is required even for lattice based broadcast, without trace.
Moreover, by relying on subexponential security of , both our constructions can also support a super-polynomial sized revocation list, so long as it allows efficient representation and membership testing. Ours is the first work to achieve this, to the best of our knowledge.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 被引用 12 次
- Optimal Threshold Traitor TracingSourav Das, Pratish Datta, Aditi Partap, Swagata Sasmal 等EUROCRYPT 2026
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 被引用 21 次
- Optimal Traitor Tracing from PairingsMark ZhandryEUROCRYPT 2025 · 被引用 3 次
- Optimal Broadcast Encryption from Pairings and LWEShweta Agrawal, Shota YamadaEUROCRYPT 2020 · 被引用 74 次
