Semantic Definition of Anonymity in Identity-Based Encryption and Its Relation to Indistinguishability-Based Definition

Semantic Definition of Anonymity in Identity-Based Encryption and Its Relation to Indistinguishability-Based Definition
复制标题

DOI:
10.1007/978-3-030-59013-0_4
复制
发表时间:
2020-09
期刊:
--
影响因子:
--
通讯作者:
Goichiro Hanaoka;Misaki Komatsu;Kazuma Ohara;Yusuke Sakai;Shota Yamada
Goichiro Hanaoka;Misaki Komatsu;Kazuma Ohara;Yusuke Sakai;Shota Yamada
中科院分区:
其他
文献类型:
--
作者:
Goichiro Hanaoka;Misaki Komatsu;Kazuma Ohara;Yusuke Sakai;Shota Yamada

文献摘要

相似文献

在本文中,我们指出了在给基于身份的匿名加密(匿名IBE)及其应用(如可搜索加密)提供适当的安全定义方面被忽视的微妙之处。也就是说,我们发现,到目前为止,还没有讨论过广泛使用的基于不可区分的国际教育局匿名性概念是否意味着基于模拟的匿名性定义,这直接捕获了接收者的ID不会从密文中泄露的直觉。我们通过提供一种基于模拟的概念来补偿这种不期望的情况,该概念要求在不知道相关ID的情况下可以模拟密文,方法是将先前工作中为更一般的基于属性的加密概念定义的匿名性概念专门用于IBE的设置,然后证明该定义等价于传统的基于不可区分的定义。我们注意到,虽然最终结果是意料之中的,但我们的证明并不完全是微不足道的。特别是,由于身份和消息的语义与密钥提取预言的存在之间的差异,以前的证明在有效负载的安全性是主要关注的设置下,显示了语义安全和基于不可区分的证明之间的等价性,但在我们的设置中并不立即有效。
In this paper we point out an overlooked subtlety in providing proper security definitions of anonymous identity-based encryption (anonymous IBE) and its applications such as searchable encryption. Namely, we find that until now there is no discussion whether the widely used indistinguishability-based notion of anonymity for IBE implies simulation-based definition of anonymity, which directly captures the intuition that recipients’ IDs are not leaked from ciphertexts. We compensate this undesirable situation by providing a simulation-based notion, which requires that a ciphertext can be simulated without knowing the associated ID, by specializing the anonymity notion defined for more generalized notion of attribute-based encryption in previous work to the setting of IBE and then proving that this definition is equivalent to the conventional indistinguishability-based definition. We note that while the final result is something one would expect, our proof is not completely trivial. In particular, previous proofs that show the equivalence between semantic security and indistinguishability-based one in the setting where the security of payload is the main concern do not work immediately in our setting due to the difference between the semantics of identities and messages and the existence of the key extraction oracles.