Multi-Authority ABE from Lattices without Random Oracles

Multi-Authority ABE from Lattices without Random Oracles
复制标题

DOI:
10.1007/978-3-031-22318-1_23
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Brent Waters;H. Wee;David J. Wu
Brent Waters;H. Wee;David J. Wu
中科院分区:
其他
文献类型:
--
作者:
Brent Waters;H. Wee;David J. Wu

文献摘要

相似文献

基于属性的加密(ABE)扩展了公钥加密,支持对加密数据进行细粒度控制。然而,这是以需要一个中央可信机构来发布解密密钥为代价的。多权威ABE (MA-ABE)方案将ABE分散,并允许任何人作为权威机构。现有的MA-ABE结构只能在随机oracle模型中实现安全性。在这项工作中,我们开发了为子集策略类(捕获诸如连词和DNF公式之类的策略)构建MA-ABE的新技术,这些策略的安全性可以基于没有随机oracle的普通模型。我们依靠Wee (EUROCRYPT 2022)和Tsabury (CRYPTO 2022)最近提出的带有错误的“回避”学习(LWE)假设来实现这一点。在此过程中,我们还在随机oracle模型中为Datta等人(EUROCRYPT 2021)的DNF公式提供了MA-ABE方案的模块化视图。我们通过Brakerski和Vaikuntanathan (ITCS 2022)提出的相关活板门LWE假设的一般版本将其形式化,该假设又可以简化为简单的LWE假设。作为推论,我们也得到了随机oracle模型中具有多项式模噪比的plain - lwe子集策略的MA-ABE方案。这改进了data等人的构造,该构造依赖于具有亚指数模噪声比的LWE。此外,我们乐观地认为,广义相关陷门LWE假设也将有助于分析其他基于格的结构的安全性。
Attribute-based encryption (ABE) extends public-key encryption to enable fine-grained control to encrypted data. However, this comes at the cost of needing a centraltrustedauthority to issue decryption keys. A multi-authority ABE (MA-ABE) scheme decentralizes ABE and allows anyone to serve as an authority. Existing constructions of MA-ABE only achieve security in the random oracle model.In this work, we develop new techniques for constructing MA-ABE for the class of subset policies (which captures policies such as conjunctions and DNF formulas) whose security can be based in the plain modelwithoutrandom oracles. We achieve this by relying on the recently-proposed “evasive” learning with errors (LWE) assumption by Wee (EUROCRYPT 2022) and Tsabury (CRYPTO 2022).Along the way, we also provide a modular view of the MA-ABE scheme for DNF formulas by Datta et al.  (EUROCRYPT 2021) in the random oracle model. We formalize this via a general version of a related-trapdoor LWE assumption by Brakerski and Vaikuntanathan (ITCS 2022), which can in turn be reduced to the plain LWE assumption. As a corollary, we also obtain an MA-ABE scheme for subset policies fromplainLWE with apolynomialmodulus-to-noise ratio in the random oracle model. This improves upon the Datta et al. construction which relied on LWE with asub-exponentialmodulus-to-noise ratio. Moreover, we are optimistic that the generalized related-trapdoor LWE assumption will also be useful for analyzing the security of other lattice-based constructions.