New Approaches to Traitor Tracing with Embedded Identities

New Approaches to Traitor Tracing with Embedded Identities
复制标题

DOI:
10.1007/978-3-030-36033-7_6
复制
发表时间:
2019-12
期刊:
--
影响因子:
--
通讯作者:
Rishab Goyal;Venkata Koppula;Brent Waters
Rishab Goyal;Venkata Koppula;Brent Waters
中科院分区:
其他
文献类型:
--
作者:
Rishab Goyal;Venkata Koppula;Brent Waters

文献摘要

被引文献

相似文献

在一个多用户的叛逆者追踪系统中,每个用户都有自己的密钥。内容提供商可以使用公钥加密消息,每个用户可以使用他/她的私钥解密密文。假设其中一些用户串通起来构造一个盗版解码盒。跟踪方案有一个特殊的算法,称为,它可以识别至少一个用于构建盗版解码盒的密钥。传统上,跟踪算法只输出与叛徒相关的“索引”。因此,要使用这种系统,要么中央主权威机构必须将索引映射到实际身份,要么应该有索引到身份的公共映射。这两个选项都是有问题的,特别是如果我们需要匿名用户的公共跟踪。Nishimaki,Wichs和Zhandry(NWZ)[Eurocrypt 2016]通过构建一个叛徒追踪方案来解决这个问题,其中用户的身份嵌入在秘密密钥中,并且给定解码盒D,跟踪算法可以恢复叛徒的整个身份。我们称这种方案为“嵌入式身份叛逆者追踪”方案。NWZ基于自适应安全函数加密(FE)构造了这样的方案。目前,唯一已知的FE计划的建设是基于非标准的假设,如多线性映射和IO。在这项工作中,我们研究的问题,嵌入式身份TT基于标准的假设。我们提供了一系列的建设基于不同的假设,如公钥加密(PKE),双线性映射和错误的学习(LWE)假设。不同的结构具有不同的效率权衡。在我们基于PKE的构造中,密文大小随用户数量线性增长;基于双线性映射的构造具有次线性()大小的密文。这两个计划都有公共追踪。基于LWE的方案是具有最优密文(即,)的私有跟踪方案。最后,我们还提出了其他概念的叛徒追踪,并讨论如何建立在一个通用的方式从我们的基础嵌入式身份TT计划。
In a traitor tracing (TT) system fornusers, every user has his/her own secret key. Content providers can encrypt messages using a public key, and each user can decrypt the ciphertext using his/her secret key. Suppose some of thenusers collude to construct a pirate decoding box. Then the tracing scheme has a special algorithm, called, which can identify at least one of the secret keys used to construct the pirate decoding box.Traditionally, the trace algorithm output only the ‘index’ associated with the traitors. As a result, to use such systems, either a central master authority must map the indices to actual identities, or there should be a public mapping of indices to identities. Both these options are problematic, especially if we need public tracing with anonymity of users. Nishimaki, Wichs, and Zhandry (NWZ) [Eurocrypt 2016] addressed this problem by constructing a traitor tracing scheme where the identities of users are embedded in the secret keys, and the trace algorithm, given a decoding boxD, can recover the entire identities of the traitors. We call such schemes ‘Embedded Identity Traitor Tracing’ schemes. NWZ constructed such schemes based on adaptively secure functional encryption (FE). Currently, the only known constructions of FE schemes are based on nonstandard assumptions such as multilinear maps and iO.In this work, we study the problem of embedded identities TT based on standard assumptions. We provide a range of constructions based on different assumptions such as public key encryption (PKE), bilinear maps and the Learning with Errors (LWE) assumption. The different constructions have different efficiency trade offs. In our PKE based construction, the ciphertext size grows linearly with the number of users; the bilinear maps based construction has sub-linear () sized ciphertexts. Both these schemes have public tracing. The LWE based scheme is a private tracing scheme with optimal ciphertexts (i.e.,). Finally, we also present other notions of traitor tracing, and discuss how they can be build in a generic manner from our base embedded identity TT scheme.