Candidate Witness Encryption from Lattice Techniques
Rotem Tsabary
摘要
Witness encryption (WE), first introduced by Garg, Gentry, Sahai and Waters in [GGSW13], is an encryption scheme where messages are encrypted with respect to instances of an NP relation, such that in order to decrypt one needs to know a valid witness for the instance that is associated with the ciphertext.
Despite of significant efforts in the past decade to construct WE from standard assumptions, to the best of our knowledge all of the existing WE candidates either rely directly on iO or use techniques that also seem to imply iO in the same way that they seem to imply WE.
In this work we propose a new hardness assumption with regard to lattice trapdoors and show a witness encryption candidate which is secure under it. Contrary to previous WE candidates, our technique is trivially broken when one tries to convert it to iO, which suggests that the security relies on a different mechanism. We view the gap between WE and iO as an analogue to the gap between ABE and FE and thus potentially significant.
Intuitively, the assumption says that "the best an attacker can do with a trapdoor sample is to use it semi-honestly" -i.e. that LWE with respect to a public matrix A, given as auxiliary information a trapdoor sample K ← A TD (B), is as hard as LWE with respect to the public matrix [A|B] and no auxiliary information.
In order to formally utilize the assumption we define a notion of LWE oracles with generic distributions of public matrices and auxiliary information. This model allows to bound the hardness of LWE with respect to one distribution as a function of the hardness of LWE with respect to another distribution. Repeated arguments of this flavor can be used as a sequence of hybrids in order to gradually change the challenge that an adversary is facing while keeping track on the security loss in each step of the proof. Typically security proofs of LWE-based systems implicitly make arguments of this flavor for distributions that are indistinguishable, while our model allows to make relaxed arguments that in some cases suffice for the proof requirements.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Succinct Vector, Polynomial, and Functional Commitments from LatticesHoeteck Wee, David J. WuEUROCRYPT 2023 · 被引用 54 次
- Attribute-Based Encryption for Circuits of Unbounded Depth from LatticesYao-Ching Hsieh, Huijia Lin, Ji LuoFOCS 2023 · 被引用 38 次
- Fully Adaptive Decentralized Multi-Authority ABEPratish Datta, Ilan Komargodski, Brent WatersEUROCRYPT 2023 · 被引用 24 次
- Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWEJeffrey Champion, Yao-Ching Hsieh, David J. WuCRYPTO 2025 · 被引用 21 次
- Indistinguishability Obfuscation, Range Avoidance, and Bounded ArithmeticRahul Ilango, Jiatu Li, R. Ryan WilliamsSTOC 2023 · 被引用 17 次
它引用的顶会 Paper4
- Indistinguishability obfuscation from well-founded assumptionsAayush Jain, Huijia Lin, Amit SahaiSTOC 2021 · 被引用 223 次
- Candidate Obfuscation via Oblivious LWE SamplingHoeteck Wee, Daniel WichsEUROCRYPT 2021 · 被引用 78 次
- Candidate iO from Homomorphic Encryption SchemesZvika Brakerski, Nico Döttling, Sanjam Garg, Giulio MalavoltaEUROCRYPT 2020 · 被引用 60 次
- Indistinguishability Obfuscation from Simple-to-State Hard Problems: New Assumptions, New Techniques, and SimplificationRomain Gay, Aayush Jain, Huijia Lin, Amit SahaiEUROCRYPT 2021 · 被引用 46 次
相关 Paper
- On Witness Encryption and Laconic Zero-Knowledge ArgumentsYanyi Liu, Noam Mazor, Rafael PassCRYPTO 2025 · 被引用 1 次
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 被引用 49 次
- Statistical ZAP ArgumentsSaikrishna Badrinarayanan, Rex Fernando, Aayush Jain, Dakshita Khurana 等EUROCRYPT 2020 · 被引用 36 次
- Witness Semantic SecurityPaul Lou, Nathan Manohar, Amit SahaiEUROCRYPT 2024
- Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWEShweta Agrawal, Mélissa Rossi, Anshu Yadav, Shota YamadaCRYPTO 2023 · 被引用 19 次
