Non-Trivial Witness Encryption and Null-iO from Standard Assumptions
Non-Trivial Witness Encryption and Null-iO from Standard Assumptions
复制标题
标准假设的非平凡见证加密和 Null-iO
DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Daniel Wichs
中科院分区:
文献类型:
--
作者:
Zvika Brakerski;Aayush Jain;Ilan Komargodski;Alain Passelègue;Daniel Wichs
A witness encryption (WE) scheme can take any ({{ extsf {NP}}}) statement as a public-key and use it to encrypt a message. If the statement is true then it is possible to decrypt the message given a corresponding witness, but if the statement is false then the message is computationally hidden. Ideally, the encryption procedure should run in polynomial time, but it is also meaningful to define a weaker notion, which we call non-trivially exponentially efficient WE (XWE), where the encryption run-time is only required to be much smaller than the trivial (2^{m}) bound for ({{ extsf {NP}}}) relations with witness size m. We show how to construct such XWE schemes for all of ({{ extsf {NP}}}) with encryption run-time (2^{m/2}) under the sub-exponential learning with errors (LWE) assumption. For ({{ extsf {NP}}}) relations that can be verified in ({{ extsf {NC}}^1}) (e.g., SAT) we can also construct such XWE schemes under the sub-exponential Decisional Bilinear Diffie-Hellman (DBDH) assumption. Although we find the result surprising, it follows via a very simple connection to attribute-based encryption.