Chosen-ciphertext secure proxy re-encryption

Chosen-ciphertext secure proxy re-encryption
复制标题

DOI:
10.1145/1315245.1315269
复制
发表时间:
2007-10
影响因子:
1.3
通讯作者:
R. Canetti;S. Hohenberger
R. Canetti;S. Hohenberger
中科院分区:
化学4区
文献类型:
--
作者:
R. Canetti;S. Hohenberger

文献摘要

被引文献

相似文献

在代理重新加密(Pre)方案中,代理被给予特殊信息,该信息允许其将一个密钥下的密文转换为不同密钥下的相同消息的密文。然而,代理不能获知任何使用这两个密钥加密的消息。Pre方案有许多实际应用,包括分布式存储、电子邮件和DRM。以前提出的重加密方案仅实现了语义安全;相比之下,应用程序通常需要针对选择的密文攻击的安全性。给出了Pre方案抗选择密文攻击的安全性定义,并给出了一个满足该定义的方案。我们的构造是有效的,并且只基于标准模型中的决策双线性Diffie-Hellman假设。我们还通过基于游戏的定义和基于模拟的定义正式地捕获了Pre方案的CCA安全性,这些定义保证了普遍可合成的安全性。我们注意到,在我们工作的同时,Green和Ateniese提出了CCA-Secure Pre,本文将对此进行讨论。
In a proxy re-encryption (PRE) scheme, a proxy is given special information that allows it to translate a ciphertext under one key into a ciphertext of the same message under a different key. The proxy cannot, however, learn anything about the messages encrypted under either key. PRE schemes have many practical applications, including distributed storage, email, and DRM. Previously proposed re-encryption schemes achieved only semantic security; in contrast, applications often require security against chosen ciphertext attacks. We propose a definition of security against chosen ciphertext attacks for PRE schemes, and present a scheme that satisfies the definition. Our construction is efficient and based only on the Decisional Bilinear Diffie-Hellman assumption in the standard model. We also formally capture CCA security for PRE schemes via both a game-based definition and simulation-based definitions that guarantee universally composable security. We note that, simultaneously with our work, Green and Ateniese proposed a CCA-secure PRE, discussed herein.