Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWE
Jeffrey Champion, Yao-Ching Hsieh, David J. Wu
摘要
Registered attribute-based encryption (ABE) is a generalization of public-key encryption that enables fine-grained access control to encrypted data (like standard ABE), but without needing a central trusted authority. In a key-policy registered ABE scheme, users choose their own public and private keys and then register their public keys together with a decryption policy with an (untrusted) key curator. The key curator aggregates all of the individual public keys into a short master public key which serves as the public key for an ABE scheme.
Currently, we can build registered ABE for restricted policies (e.g., Boolean formulas) from pairing-based assumptions and for general policies using witness encryption or indistinguishability obfuscation. In this work, we construct a key-policy registered ABE for general policies (specifically, bounded-depth Boolean circuits) from the -succinct learning with errors (LWE) assumption in the random oracle model. The ciphertext size in our registered ABE scheme is , where is a security parameter and is the depth of the circuit that computes the policy circuit . Notably, this is independent of the length of the attribute and is optimal up to the factor.
Previously, the only lattice-based instantiation of registered ABE uses witness encryption, which relies on private-coin evasive LWE, a stronger assumption than -succinct LWE. Moreover, the ciphertext size in previous registered ABE schemes that support general policies (i.e., from obfuscation or witness encryption) scales with . The ciphertext size in our scheme depends only on the depth of the circuit (and not the length of the attribute or the size of the policy). This enables new applications to identity-based distributed broadcast encryption.
Our techniques are also useful for constructing adaptively-secure (distributed) broadcast encryption, and we give the first scheme from the -succinct LWE assumption in the random oracle model. Previously, the only lattice-based broadcast encryption scheme with adaptive security relied on witness encryption in the random oracle model. All other lattice-based broadcast encryption schemes only achieved selective security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Multi-authority Registered Attribute-Based EncryptionGeorge Lu, Brent Waters, David J. WuEUROCRYPT 2025 · 被引用 14 次
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 被引用 12 次
- Threshold Batched Identity-Based Encryption from Pairings in the Plain ModelJunqing Gong, Brent Waters, Hoeteck Wee, David J. WuEUROCRYPT 2026 · 被引用 9 次
- Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain ModelBrent Waters, David J. WuEUROCRYPT 2026 · 被引用 2 次
- Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRSRoy Stracovsky, Brent Waters, David J. WuCRYPTO 2026
它引用的顶会 Paper17
- Registered Attribute-Based EncryptionSusan Hohenberger, George Lu, Brent Waters, David J. WuEUROCRYPT 2023 · 被引用 83 次
- Indistinguishability obfuscation from circular securityRomain Gay, Rafael PassSTOC 2021 · 被引用 78 次
- Optimal Broadcast Encryption and CP-ABE from Evasive Lattice AssumptionsHoeteck WeeEUROCRYPT 2022 · 被引用 75 次
- Optimal Broadcast Encryption from Pairings and LWEShweta Agrawal, Shota YamadaEUROCRYPT 2020 · 被引用 74 次
- Decentralized Multi-authority ABE for DNFs from LWEPratish Datta, Ilan Komargodski, Brent WatersEUROCRYPT 2021 · 被引用 62 次
相关 Paper
- ABE for Circuits with poly (λ) -sized Keys from LWEValerio Cini, Hoeteck WeeFOCS 2023 · 被引用 7 次
- Reducing the CRS Size in Registered ABE SystemsRachit Garg, George Lu, Brent Waters, David J. WuCRYPTO 2024 · 被引用 27 次
- Large-Universe (Multi-Authority) ABE from LWEPratish Datta, Yannis Rouselakis, Junichi Tomida, Nikhil VanjaniCCS 2026
- Almost Optimal KP and CP-ABE for Circuits from Succinct LWEHoeteck WeeEUROCRYPT 2025 · 被引用 16 次
- Unbounded Broadcast and KP-ABE with Sublinear Ciphertext from PairingsJunichi Tomida, Hoeteck WeeCRYPTO 2026
