Lattice-based Revocable (Hierarchical) IBE with Decryption Key Exposure Resistance
Lattice-based Revocable (Hierarchical) IBE with Decryption Key Exposure Resistance
复制标题
DOI:
10.1016/j.tcs.2019.12.003
复制
发表时间:
2019-04
期刊:
影响因子:
--
通讯作者:
Shuichi Katsumata;Takahiro Matsuda;Atsushi Takayasu
中科院分区:
文献类型:
--
作者:
Shuichi Katsumata;Takahiro Matsuda;Atsushi Takayasu
Revocableidentity-based encryption (RIBE) is an extension of IBE that supports a key revocation mechanism, which is an indispensable feature for practical cryptographic schemes. Due to this extra feature, RIBE is often required to satisfy a strong security notion unique to the revocation setting calleddecryption key exposure resistance(DKER). Additionally,hierarchalIBE (HIBE) is another orthogonal extension of IBE that supports key delegation functionalities allowing for scalable deployments of cryptographic schemes. So far, R(H)IBE constructions with DKER are only known from bilinear maps, where all constructions rely heavily on the so-calledkey re-randomizationproperty to achieve the DKER and/or hierarchal feature. Since lattice-based schemes seem to be inherently ill-fit with the key re-randomization property, no construction of lattice-based R(H)IBE schemes with DKER are known.In this paper, we propose the first lattice-based RHIBE scheme with DKERwithoutrelying on the key re-randomization property, departing from all the previously known methods. We start our work by providing a generic construction of RIBE schemes with DKER, which uses as building blocks any two-level standard HIBE scheme and (weak) RIBE schemewithoutDKER. Based on previous lattice-based RIBE constructionswithoutDKER, our result implies the first lattice-based RIBE schemewithDKER. Then, building on top of our generic construction, we construct the first lattice-based RHIBE scheme with DKER, by further exploiting the algebraic structure of lattices. To this end, we prepare a new tool called thelevel conversion keys, which enables us to achieve the hierarchal feature without relying on the key re-randomization property. In this full version, we give the formal proofs of our proposed schemes.