Identity-Based Encryption with Security Against the KGC: A Formal Model and Its Instantiation from Lattices

Identity-Based Encryption with Security Against the KGC: A Formal Model and Its Instantiation from Lattices
复制标题

DOI:
10.1007/978-3-030-29962-0_6
复制
发表时间:
2019-09
期刊:
--
影响因子:
--
通讯作者:
K. Emura;Shuichi Katsumata;Yohei Watanabe
K. Emura;Shuichi Katsumata;Yohei Watanabe
中科院分区:
其他
文献类型:
--
作者:
K. Emura;Shuichi Katsumata;Yohei Watanabe

文献摘要

相似文献

密钥托管问题是在现实世界中广泛使用基于身份的加密(IBE)的主要障碍之一。具体来说,为给定身份生成密钥的密钥生成中心(KGC)具有解密所有密文的能力。在PKC 2009上,Chow定义了一个针对KGC的安全概念,该概念依赖于假设它无法发现密文背后的底层身份。然而,这不是一个现实的假设,因为在实践中,KGC管理一个身份列表,因此它可以很容易地猜测与给定密文对应的身份。周后来通过引入一个名为身份认证机构(ICA)的新实体,并提出了匿名密钥颁发协议,缩小了理论与实践之间的差距。从本质上讲,这允许用户、KGC和ICA交互地生成密钥,而无需用户向KGC透露他们的身份。不幸的是,提议的协议没有包括具体的安全定义,这意味着Chow之后的所有后续工作都缺乏确定它是否为密钥托管问题提供安全解决方案所需的正式证明。在本文中,基于Chow的工作,我们正式定义了一个解决密钥托管问题的IBE方案,并提供了针对腐败用户、KGC和ICA的安全的正式定义。在此过程中,我们观察到,如果我们被允许假设一个完全可信的ICA,就像在Chow的工作中一样,那么我们可以构建一个微不足道的(而且毫无意义的)IBE方案,它可以对抗KGC。最后,我们在Gentry-Peikert-Vaikuntanathan (GPV) IBE方案(STOC 2008)和r<s:1> ckert的基于格子的盲签名方案(ASIACRYPT 2010)的基础上提出了基于格子的新安全模型构建。
Thekey escrow problemis one of the main barriers to the widespread real-world use of identity-based encryption (IBE). Specifically, a key generation center (KGC), which generates secret keys for a given identity, has the power to decrypt all ciphertexts. At PKC 2009, Chow defined a notion of security against the KGC, that relies on assuming that it cannot discover the underlying identities behind ciphertexts. However, this is not a realistic assumption since, in practice, the KGC manages an identity list and hence it can easily guess the identities corresponding to given ciphertexts. Chow later closed the gap between theory and practice by introducing a new entity called an identity-certifying authority (ICA) and proposed ananonymous key-issuing protocol. Essentially, this allows the users, KGC, and ICA to interactively generate secret keys without users ever having to reveal their identities to the KGC. Unfortunately, the proposed protocol did not include a concrete security definition, meaning that all of the subsequent works following Chow lack the formal proofs needed to determine whether or not it delivers a secure solution to the key escrow problem.In this paper, based on Chow’s work, we formally define an IBE scheme that resolves the key escrow problem and provide formal definitions of security against corrupted users, KGC, and ICA. Along the way, we observe that if we are allowed to assume a fully trusted ICA, as in Chow’s work, then we can construct a trivial (and meaningless) IBE scheme that is secure against the KGC. Finally, we present a lattice-based construction in our new security model based on the Gentry–Peikert–Vaikuntanathan (GPV) IBE scheme (STOC 2008) and Rückert’s lattice-based blind signature scheme (ASIACRYPT 2010).