Public Key Broadcast Encryption for Stateless Receivers

Public Key Broadcast Encryption for Stateless Receivers
复制标题

DOI:
10.1007/978-3-540-44993-5_5
复制
发表时间:
2002-11
期刊:
--
影响因子:
--
通讯作者:
Y. Dodis;Nelly Fazio
Y. Dodis;Nelly Fazio
中科院分区:
其他
文献类型:
--
作者:
Y. Dodis;Nelly Fazio

文献摘要

被引文献

相似文献

广播加密方案允许发送者通过不安全的通道将数据安全地分发给动态变化的用户组。此问题最具挑战性的设置之一是无状态接收器的设置,其中每个用户都获得一组固定的密钥,这些密钥在系统的生命周期内无法更新。 Naor、Naor 和 Lotspiech [17] 考虑了这种设置,他们还提出了一种非常有效的“子集差分”(SD)方法来解决这个问题。 Halevi 和 Shamir [12] 最近改进了这种方法的效率(还具有高效的叛徒追踪机制和其他一些有用的功能),他们将这种改进称为“分层 SD”(LSD)方法。上述两种方法最初都是设计用于集中式对称密钥设置,只有系统的可信设计者才能加密发送给用户的消息。另一方面,在许多应用中,不希望“在线”存储密钥,或者允许不受信任的用户广播信息。这就引出了为无状态接收者构建公钥广播加密方案的问题;特别是,将优雅的 SD/LSD 方法扩展到公钥设置。纳尔等人。 [17] 请注意,这样做的自然技术将为每个用户带来巨大的公钥和非常大的存储空间。事实上,[17]将减少公钥大小和用户存储的问题作为其论文的第一个开放问题。我们通过证明除了与对称密钥设置中相同的(小)用户存储和密文大小之外,对于两种 SD/LSD 方法都可以实现 O(1) 大小的公钥,我们以肯定的方式解决了这个问题。
Abroadcast encryptionscheme allows the sender to securely distribute data to a dynamically changing set of users over an insecure channel. One of the most challenging settings for this problem is that ofstateless receivers, where each user is given a fixed set of keys which cannot be updated through the lifetime of the system. This setting was considered by Naor, Naor and Lotspiech [17], who also present a very efficient “Subset Difference” (SD) method for solving this problem. The efficiency of this method (which also enjoys efficient traitor tracing mechanism and several other useful features) was recently improved by Halevi and Shamir [12], who called their refinement the “Layered SD” (LSD) method. Both of the above methods were originally designed to work in the centralized symmetric key setting, where only the trusted designer of the system can encrypt messages to users. On the other hand, in many applications it is desirable not to store the secret keys “on-line”, or to allow untrusted users to broadcast information. This leads to the question of building apublic keybroadcast encryption scheme for stateless receivers; in particular, of extending the elegant SD/LSD methods to the public key setting. Naor et al. [17] notice that the natural technique for doing so will result in an enormous public key and very large storage for every user. In fact, [17] pose this question of reducing the public key size and user’s storage as the first open problem of their paper. We resolve this question in the affirmative, by demonstrating that anO(1) size public key can be achieved for both of SD/LSD methods, in addition to the same (small) user’s storage and ciphertext size as in the symmetric key setting.