Lune

CRYPTO2024顶会

Attribute Based Encryption for Turing Machines from Lattices

Shweta Agrawal, Simran Kumari, Shota Yamada

2024年份
15被引次数

摘要

We provide the first attribute based encryption (ABE) scheme for Turing machines supporting unbounded collusions from lattice assumptions. In more detail, the encryptor encodes an attribute x\mathbf{x} together with a bound tt on the machine running time and a message mm into the ciphertext, the key generator embeds a Turing machine MM into the secret key and decryption returns mm if and only if M(x)=1M(\mathbf{x})=1. Crucially, the input x\mathbf{x} and machine MM can be of unbounded size, the time bound tt can be chosen dynamically for each input and decryption runs in input specific time.

Previously the best known ABE for uniform computation supported only non-deterministic log space Turing machines (NL){\sf NL}) from pairings (Lin and Luo, Eurocrypt 2020). In the post-quantum regime, the state of the art supports non-deterministic finite automata from LWE in the  symmetric\textit{ symmetric} key setting (Agrawal, Maitra and Yamada, Crypto 2019).

In more detail, our results are:

  1. We construct the first ABE for NL{\sf NL} from the LWE, evasive LWE (Wee, Eurocrypt 2022 and Tsabary, Crypto 2022) and Tensor LWE (Wee, Eurocrypt 2022) assumptions. This yields the first (conjectured) post-quantum ABE for NL{\sf NL}.
  2. Relying on LWE, evasive LWE and a new assumption called circular tensor\textit{circular tensor} LWE, we construct ABE for all Turing machines. At a high level, the circular tensor LWE assumption incorporates circularity into the tensor LWE (Wee, Eurocrypt 2022) assumption.

Towards our ABE for Turing machines, we obtain the first CP-ABE for circuits of unbounded depth and size from the same assumptions -- this may be of independent interest.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖