Lune

CRYPTO2025顶会

Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWE

Jeffrey Champion, Yao-Ching Hsieh, David J. Wu

2025年份
21被引次数
5顶会引用

摘要

Registered attribute-based encryption (ABE) is a generalization of public-key encryption that enables fine-grained access control to encrypted data (like standard ABE), but without needing a central trusted authority. In a key-policy registered ABE scheme, users choose their own public and private keys and then register their public keys together with a decryption policy with an (untrusted) key curator. The key curator aggregates all of the individual public keys into a short master public key which serves as the public key for an ABE scheme.

Currently, we can build registered ABE for restricted policies (e.g., Boolean formulas) from pairing-based assumptions and for general policies using witness encryption or indistinguishability obfuscation. In this work, we construct a key-policy registered ABE for general policies (specifically, bounded-depth Boolean circuits) from the ℓ\ell-succinct learning with errors (LWE) assumption in the random oracle model. The ciphertext size in our registered ABE scheme is poly(λ,d)\mathsf{poly}(\lambda, d), where λ\lambda is a security parameter and dd is the depth of the circuit that computes the policy circuit CC. Notably, this is independent of the length of the attribute x\mathbf{x} and is optimal up to the poly(d)\mathsf{poly}(d) factor.

Previously, the only lattice-based instantiation of registered ABE uses witness encryption, which relies on private-coin evasive LWE, a stronger assumption than ℓ\ell-succinct LWE. Moreover, the ciphertext size in previous registered ABE schemes that support general policies (i.e., from obfuscation or witness encryption) scales with poly(λ,∣x∣,∣C∣)\mathsf{poly}(\lambda, |\mathbf{x}|, |C|). The ciphertext size in our scheme depends only on the depth of the circuit (and not the length of the attribute or the size of the policy). This enables new applications to identity-based distributed broadcast encryption.

Our techniques are also useful for constructing adaptively-secure (distributed) broadcast encryption, and we give the first scheme from the ℓ\ell-succinct LWE assumption in the random oracle model. Previously, the only lattice-based broadcast encryption scheme with adaptive security relied on witness encryption in the random oracle model. All other lattice-based broadcast encryption schemes only achieved selective security.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext d235fa77-bc6f-486e-a2d0-9ceb5860b801

引用它的顶会 Paper5

问问它们各自怎么用它

它引用的顶会 Paper17

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖