Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency

Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency
复制标题

DOI:
10.1016/j.tcs.2016.04.003
复制
发表时间:
2016-05
期刊:
Theor. Comput. Sci.
影响因子:
--
通讯作者:
Yusuke Sakai;K. Emura;Jacob C. N. Schuldt;Goichiro Hanaoka;K. Ohta
Yusuke Sakai;K. Emura;Jacob C. N. Schuldt;Goichiro Hanaoka;K. Ohta
中科院分区:
其他
文献类型:
--
作者:
Yusuke Sakai;K. Emura;Jacob C. N. Schuldt;Goichiro Hanaoka;K. Ohta

文献摘要

相似文献

动态阈值公钥加密由 Delerablée 和 Pointcheval (CRYPTO 2008) 提出,是普通阈值加密的扩展,它使得解密服务器即使在设置阶段后也能加入系统,并动态选择授权集和解密阈值。 Delerablée 和 Pointcheval 提出了第一个动态阈值公钥加密方案,并在非标准 q 型假设下证明了该方案的安全性。然而,解密一致性是保证解密唯一性的重要安全属性,即使发送者和解密服务器行为恶意,也仅在随机预言模型中表现出来。在本文中,我们提出了三种阈值公钥加密方案。第一种方案和第二种方案都是动态方案。前者实现了解密一致性相对较弱的变体,而后者实现了解密一致性的强变体。前者是非交互式开放公钥加密(PKENO)的通用构造,而后者是标准数论假设的特定构造。这是动态公钥加密的第一个构造,无需依赖随机预言模型即可实现解密一致性。此外,这两种方案都可以基于标准假设来实现。第三种结构是 PKENO 的通用结构,实现了解密一致性的强变体。这种结构肯定地回答了 Galindo 等人间接提出的问题。 (AFRICRYPT 2010)是否有可能实现强解密一致性的通用结构。
Dynamic threshold public-key encryption, proposed by Delerablée and Pointcheval (CRYPTO 2008), is an extension of ordinary threshold encryption which enables decryption servers to join the system even after the setup phase, and to choose the authorized set and the threshold of decryption dynamically. Delerablée and Pointcheval proposed the first dynamic threshold public-key encryption scheme, which they proved secure under a non-standardq-type assumption. However, decryption consistency, which is an important security property that guarantees uniqueness of decryption, even when a sender and decryption servers behave maliciously, is only shown to hold in the random oracle model. In this paper, we propose three threshold public-key encryption schemes. The first and second schemes are both dynamic schemes. The former achieves a relatively weaker variant of decryption consistency, while the latter achieves a strong variant thereof. The former is a generic construction from public-key encryption with non-interactive opening (PKENO), while the latter is a specific construction from a standard number-theoretic assumption. These are the first constructions of dynamic public-key encryption, which achieve decryption consistency without relying on the random oracle model. Furthermore, both schemes can be realized based on standard assumptions. The third construction is a generic construction from PKENO achieving the strong variant of decryption consistency. This construction affirmatively answers the question indirectly posed by Galindo et al. (AFRICACRYPT 2010) of whether a generic construction achieving strong decryption consistency is possible.