Simple and Generic Constructions of Succinct Functional Encryption

Simple and Generic Constructions of Succinct Functional Encryption
复制标题

DOI:
10.1007/s00145-021-09396-x
复制
发表时间:
2018-03
影响因子:
3
通讯作者:
Fuyuki Kitagawa;R. Nishimaki;Keisuke Tanaka
Fuyuki Kitagawa;R. Nishimaki;Keisuke Tanaka
中科院分区:
计算机科学4区
文献类型:
--
作者:
Fuyuki Kitagawa;R. Nishimaki;Keisuke Tanaka

文献摘要

相似文献

我们提出了简洁的函数加密简单的通用结构。我们的关键工具是强指数效率的不可混淆混淆器(SXIO),它与不可混淆混淆器(IO)相同,只是混淆电路的大小和混淆器的运行时间略小于输出待混淆电路的整个真值表的暴力规范化器。SXIO的“压缩因子”指示SXIO压缩蛮力规范化器的程度。在这项研究中,我们提出了一个非常简单的框架,通过SXIO构建简洁的功能加密,并表明SXIO是强大到足以实现尖端的密码学。特别地,我们提出了以下构造:单密钥弱简洁秘密密钥函数加密(SKFE)是由SXIO(即使有一个坏的压缩因子)和单向函数构造的;单密钥弱简洁公钥函数加密(PKFE)是由SXIO(即使有一个坏的压缩因子)和公钥加密构造的;单密钥弱简洁PKFE是由SXIO(即使有一个坏的压缩因子)和基于身份的加密构造的。我们的构造不依赖于任何数论或格的假设,如决策Diffie-Hellman和错误学习假设。此外,所有的安全性降低只会导致多项式安全性损失。已知的结构弱简洁SKFE或PKFE从SXIO多项式安全损失依赖于数论或格假设。作为推论,我们的结果,SXIO,SKFE的几个变种,和随机编码的一个变种之间的关系被发现。
We propose simple generic constructions of succinct functional encryption. Our key tool is strong exponentially efficient indistinguishability obfuscator (SXIO), which is the same as indistinguishability obfuscator (IO) except that the size of an obfuscated circuit and the running time of an obfuscator areslightlysmaller than that of a brute-force canonicalizer that outputs the entire truth table of a circuit to be obfuscated. A “compression factor” of SXIO indicates how much SXIO compresses the brute-force canonicalizer. In this study, we propose a significantly simple framework to construct succinct functional encryption via SXIO and show that SXIO is powerful enough to achieve cutting-edge cryptography. In particular, we propose the following constructions:Single-key weakly succinct secret-key functional encryption (SKFE) is constructed from SXIO (even with a bad compression factor) and one-way functions.Single-key weakly succinct public-key functional encryption (PKFE) is constructed from SXIO with a good compression factor and public-key encryption.Single-key weakly succinct PKFE is constructed from SXIO (even with a bad compression factor) and identity-based encryption.Our new framework has side benefits. Our constructions do not rely on any number theoretic or lattice assumptions such as decisional Diffie–Hellman and learning with errors assumptions. Moreover, all security reductions incur only polynomial security loss. Known constructions of weakly succinct SKFE or PKFE from SXIO with polynomial security loss rely on number theoretic or lattice assumptions. As corollaries of our results, relationships among SXIO, a few variants of SKFE, and a variant of randomized encoding are discovered.