Unidirectional Chosen-Ciphertext Secure Proxy Re-Encryption

Unidirectional Chosen-Ciphertext Secure Proxy Re-Encryption
复制标题

DOI:
10.1007/978-3-540-78440-1_21
复制
发表时间:
2008-03
影响因子:
2.5
通讯作者:
Benoît Libert;Damien Vergnaud
Benoît Libert;Damien Vergnaud
中科院分区:
计算机科学2区
文献类型:
--
作者:
Benoît Libert;Damien Vergnaud

文献摘要

被引文献

相似文献

在1998年,Blaze、Bleumer和Strauss提出了一种称为代理重新加密的密码学原语,其中代理将根据Alice的公钥计算的密文转换为可以使用Bob的密钥打开的密文,而不需要看到相应的明文。最近,Canetti和Hohenberger提出了选择密文安全性的一个合适的定义和一个适合该模型的构造。他们的系统是双向的:为了将密文从Alice转移到Bob而释放的信息也可以用于在相反方向上翻译密文。本文在标准模型下(即不依赖于随机预言机理想化)首次构造了具有选择密文安全性的单向代理重加密方案,解决了CCS'07中的一个问题.我们的建设是有效的,需要一个合理的复杂性假设双线性映射组。像Canetti-Hohenberger方案一样,它根据Canetti,Krawczyk和Nielsen引入的选择密文的宽松定义来确保安全性。
In 1998, Blaze, Bleumer, and Strauss proposed a cryptographic primitive calledproxy re-encryption, in which a proxy transforms – without seeing the corresponding plaintext – a ciphertext computed under Alice’s public key into one that can be opened using Bob’s secret key. Recently, an appropriate definition of chosen-ciphertext security and a construction fitting this model were put forth by Canetti and Hohenberger. Their system isbidirectional: the information released to divert ciphertexts from Alice to Bob can also be used to translate ciphertexts in the opposite direction. In this paper, we present the first construction ofunidirectionalproxy re-encryption scheme with chosen-ciphertext security in the standard model (i.e. without relying on the random oracle idealization), which solves a problem left open at CCS’07. Our construction is efficient and requires a reasonable complexity assumption in bilinear map groups. Like the Canetti-Hohenberger scheme, it ensures security according to a relaxed definition of chosen-ciphertext introduced by Canetti, Krawczyk and Nielsen.