Lattice-based Revocable (Hierarchical) IBE with Decryption Key Exposure Resistance

Lattice-based Revocable (Hierarchical) IBE with Decryption Key Exposure Resistance
复制标题

DOI:
10.1016/j.tcs.2019.12.003
复制
发表时间:
2019-04
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Shuichi Katsumata;Takahiro Matsuda;Atsushi Takayasu
Shuichi Katsumata;Takahiro Matsuda;Atsushi Takayasu
中科院分区:
其他
文献类型:
--
作者:
Shuichi Katsumata;Takahiro Matsuda;Atsushi Takayasu

文献摘要

被引文献

相似文献

可撤销的基于身份的加密(里贝)是IBE的扩展,它支持密钥撤销机制,这是一个不可缺少的功能,为实际的密码方案。由于这个额外的功能,里贝通常需要满足一个强大的安全概念,独特的撤销设置称为解密密钥暴露阻力(DKER)。此外,hierarchalIBE(HIBE)是IBE的另一个正交扩展,其支持允许加密方案的可扩展部署的密钥委托功能。到目前为止,具有DKER的R(H)IBE构造仅从双线性映射中得知,其中所有构造都严重依赖于所谓的密钥重随机化性质来实现DKER和/或层次特征。由于基于格的方案似乎与密钥重随机化性质有着本质的不匹配,因此还没有构造出基于格的R(H)IBE方案.本文提出了第一个不依赖密钥重随机化性质的基于格的R(H)IBE方案.我们的工作首先提供了一个通用的构造里贝计划与DKER,它使用任何两个级别的标准HIBE计划和(弱)里贝计划withoutDKER的积木。在已有的不含DKER的格基里贝结构的基础上,我们的结果暗示了第一个含DKER的格基里贝结构。然后,在我们的通用构造的基础上,我们通过进一步利用格的代数结构,用DKER构造了第一个基于格的RHIBE方案。为此,我们准备了一个新的工具,称为等级转换键,它使我们能够实现层次功能,而不依赖于密钥重新随机化属性。在这个完整的版本中,我们给出了我们提出的计划的形式证明。
Revocableidentity-based encryption (RIBE) is an extension of IBE that supports a key revocation mechanism, which is an indispensable feature for practical cryptographic schemes. Due to this extra feature, RIBE is often required to satisfy a strong security notion unique to the revocation setting calleddecryption key exposure resistance(DKER). Additionally,hierarchalIBE (HIBE) is another orthogonal extension of IBE that supports key delegation functionalities allowing for scalable deployments of cryptographic schemes. So far, R(H)IBE constructions with DKER are only known from bilinear maps, where all constructions rely heavily on the so-calledkey re-randomizationproperty to achieve the DKER and/or hierarchal feature. Since lattice-based schemes seem to be inherently ill-fit with the key re-randomization property, no construction of lattice-based R(H)IBE schemes with DKER are known.In this paper, we propose the first lattice-based RHIBE scheme with DKERwithoutrelying on the key re-randomization property, departing from all the previously known methods. We start our work by providing a generic construction of RIBE schemes with DKER, which uses as building blocks any two-level standard HIBE scheme and (weak) RIBE schemewithoutDKER. Based on previous lattice-based RIBE constructionswithoutDKER, our result implies the first lattice-based RIBE schemewithDKER. Then, building on top of our generic construction, we construct the first lattice-based RHIBE scheme with DKER, by further exploiting the algebraic structure of lattices. To this end, we prepare a new tool called thelevel conversion keys, which enables us to achieve the hierarchal feature without relying on the key re-randomization property. In this full version, we give the formal proofs of our proposed schemes.