Tight lower bounds and optimal constructions of anonymous broadcast encryption and authentication

Tight lower bounds and optimal constructions of anonymous broadcast encryption and authentication
复制标题

DOI:
10.1007/s10623-023-01211-x
复制
发表时间:
2023-04
期刊:
Designs, Codes and Cryptography
影响因子:
--
通讯作者:
Hirokazu Kobayashi;Yohei Watanabe;Kazuhiko Minematsu;Junji Shikata
Hirokazu Kobayashi;Yohei Watanabe;Kazuhiko Minematsu;Junji Shikata
中科院分区:
其他
文献类型:
--
作者:
Hirokazu Kobayashi;Yohei Watanabe;Kazuhiko Minematsu;Junji Shikata

文献摘要

相似文献

广播加密(BE)是一种公钥加密,允许发送方通过指定收件人来加密消息,并且只有指定的收件人才能解密消息。在一些BE应用中,由于允许访问消息的接收者的隐私通常与消息的机密性一样重要,因此引入匿名作为BE的附加但重要的安全要求。Kiayias和Samari(IH 2013)给出了满足匿名性的BE方案(简称ANO-BE)中密文大小的渐近下界。更准确地说,他们的下界推导下的假设,ANO-BE计划有一个特殊的属性。然而,这是不够的,以显示他们的下界是渐近紧的,因为它是不清楚现有的ANO-BE格式是否满足特殊的性质。在这项工作中,我们推导出渐近紧的下限上的密文大小在ANO-BE假设只有现有的大多数ANO-BE计划满足的属性。使用类似的技术,我们首先推导出渐进查询请提供MSC代码。欲了解更多详情,请访问http://www.ams.org/msc/。匿名广播认证(Anonymous Broadcast Authentication,阿坝)中的带宽大小的严格下限。此外,我们推广了上述结果,并提出了(非渐近)紧的上下界的查询请检查并确认运行标题。ANO-BE中的密文大小。我们证明了Li和Gong(ACNS 2018)提出的ANO-BE方案的变体是最优的。我们还提供了严格的边界上的阿坝通过相同的方法作为ANO-BE的大小,并提出了一个最佳的阿坝建设。
Broadcast Encryption (BE) is public-key encryption allowing a sender to encrypt a message by specifing recipients, and only the specified recipients can decrypt the message. In several BE applications, since the privacy of recipients allowed to access the message is often as important as the confidentiality of the message, anonymity is introduced as an additional but important security requirement for BE. Kiayias and Samari (IH 2013) presented an asymptotic lower bound on the ciphertext sizes in BE schemes satisfying anonymity (ANO-BE for short). More precisely, their lower bound is derived under the assumption that ANO-BE schemes have a special property. However, it is insufficient to show their lower bound is asymptotically tight since it is unclear whether existing ANO-BE schemes meet the special property. In this work, we derive asymptotically tight lower bounds on the ciphertext size in ANO-BE by assuming only properties that most existing ANO-BE schemes satisfy. With a similar technique, we first derive asymptoticallyqueryPlease provide MSC codes. For more details, please visit http://www.ams.org/msc/. tight lower bounds on the authenticator sizes in Anonymous Broadcast Authentication (ABA). Furthermore, we extend the above result and present (non-asymptotically) tight lower and upper bounds on thequeryPlease check and confirm the Running title. ciphertext sizes in ANO-BE. We show that a variant of ANO-BE scheme proposed by Li and Gong (ACNS 2018) is optimal. We also provide tight bounds on the authenticator sizes in ABA via the same approach as ANO-BE, and propose an optimal construction for ABA.