Circuit-ABE from LWE: Unbounded Attributes and Semi-adaptive Security

Circuit-ABE from LWE: Unbounded Attributes and Semi-adaptive Security
复制标题

DOI:
10.1007/978-3-662-53015-3_13
复制
发表时间:
2016-08
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Zvika Brakerski;V. Vaikuntanathan
Zvika Brakerski;V. Vaikuntanathan
中科院分区:
其他
文献类型:
--
作者:
Zvika Brakerski;V. Vaikuntanathan

文献摘要

被引文献

相似文献

构造了一个基于LWE的密钥策略属性加密方案,该方案支持多项式长度无界的属性.也就是说,公共参数的大小是安全参数和深度界限中的固定多项式,并且利用这些固定长度的参数,可以加密任意长度的属性。类似地,任何符合深度边界的多项式大小的电路都可以用作策略电路,而不管其输入长度如何(回想一下,深度电路可以有多达个输入)。这与以往的基于LWE的方案中公开参数的长度必须随最大属性长度线性增长不同,我们证明了我们的方案是半自适应安全的,即攻击者可以在看到公开参数之后(但在看到任何解密密钥之前)选择挑战属性.以前基于LWE的构造只能实现选择性安全。(We强调“复杂性杠杆”技术不适用于无限属性)。我们相信我们的技术至少和我们的最终结果一样有趣。从根本上说,选择性安全性和有界属性都是当前LWE证明技术的缺点,该技术将挑战属性编程到公共参数中。我们在这项工作中开发的LWE工具箱允许我们延迟编程。简而言之,新工具包括一种生成LWE矩阵的a优先级无界序列的方法,并对每个矩阵中嵌入的陷门进行细粒度控制,所有这些都具有简洁的表示。
We construct an LWE-based key-policy attribute-based encryption (ABE) scheme that supports attributes ofunbounded polynomial length. Namely, the size of the public parameters is a fixed polynomial in the security parameter and a depth bound, and with these fixed length parameters, one can encrypt attributes of arbitrary length. Similarly, any polynomial size circuit that adheres to the depth bound can be used as the policy circuit regardless of its input length (recall that a depthdcircuit can have as many asinputs). This is in contrast to previous LWE-based schemes where the length of the public parameters has to grow linearly with the maximal attribute length.We prove that our scheme issemi-adaptively secure, namely, the adversary can choose the challenge attribute after seeing the public parameters (but before any decryption keys). Previous LWE-based constructions were only able to achieve selective security. (We stress that the “complexity leveraging” technique is not applicable for unbounded attributes).We believe that our techniques are of interest at least as much as our end result. Fundamentally, selective security and bounded attributes are both shortcomings that arise out of the current LWE proof techniques thatprogram the challenge attributes into the public parameters. The LWE toolbox we develop in this work allows us todelay this programming. In a nutshell, the new tools include a way to generate an a-prioriunboundedsequence of LWE matrices, and have fine-grained control over which trapdoor is embedded in each and every one of them, all with succinct representation.