Variants of Waters’ Dual-System Primitives Using Asymmetric Pairings
نویسندگان
چکیده
Waters, in 2009, introduced an important technique, called dual-system encryption, to construct identity-based encryption (IBE) and related schemes. The resulting IBE scheme was described in the setting of symmetric pairing. A key feature of the construction is the presence of random tags in the ciphertext and decryption key. Later work by Lewko and Waters has removed the tags and proceeding through composite-order pairings has led to a more efficient dual-system IBE scheme using asymmetric pairings whose security is based on non-standard but static assumptions. In this work, we have systematically simplified Waters 2009 IBE scheme in the setting of asymmetric pairing. The simplifications retain tags used in the original description. This leads to several variants, the first one of which is based on standard assumptions and in comparison to Waters original scheme reduces ciphertexts and keys by two elements each. Going through several stages of simplifications, we finally obtain a simple scheme whose security can be based on two standard assumptions and a natural and minimal extension of the decision Diffie-Hellman problem for asymmetric pairing groups. The scheme itself is also minimal in the sense that apart from the tags, both encryption and key generation use exactly one randomiser each. This final scheme is more efficient than both the previous dual-system IBE scheme in the asymmetric setting due to Lewko and Waters and the more recent dual-system IBE scheme due to Lewko. We extend the IBE scheme to hierarchical IBE (HIBE) and broadcast encryption (BE) schemes. Both primitives are secure in their respective full models and have better efficiencies compared to previously known schemes offering the same level and type of security.
منابع مشابه
Variants of Waters' Dual System Primitives Using Asymmetric Pairings - (Extended Abstract)
Waters, in 2009, introduced an important technique, called dual system encryption, to construct identity-based encryption (IBE) and related schemes. The resulting IBE scheme was described in the setting of symmetric pairing. A key feature of the construction is the presence of random tags in the ciphertext and decryption key. Later work by Lewko and Waters removed the tags and proceeding throug...
متن کاملAnonymous Constant-Size Ciphertext HIBE from Asymmetric Pairings
We present a new hierarchical identity based encryption (HIBE) scheme with constant-size ciphertext that can be implemented using the most efficient bilinear pairings, namely, Type-3 pairings. In addition to being fully secure, our scheme is anonymous. The HIBE is obtained by extending an asymmetric pairing based IBE scheme due to Lewko and Waters. The extension uses the approach of Boneh-Boyen...
متن کاملShorter identity-based encryption via asymmetric pairings
We present efficient Identity-Based Encryption (IBE) under the Symmetric External DiffieHellman (SXDH) assumption in bilinear groups. In our IBE scheme, all parameters have constant numbers of group elements, and are shorter than those of previous constructions based on Decisional Linear (DLIN) assumption. Our construction uses both dual system encryption (Waters, Crypto ’09) and dual pairing v...
متن کاملShorter IBE and Signatures via Asymmetric Pairings
We present efficient Identity-Based Encryption (IBE) and signature schemes under the Symmetric External Diffie-Hellman (SXDH) assumption in bilinear groups; our IBE scheme also achieves anonymity. In both the IBE and the signature schemes, all parameters have constant numbers of group elements, and are shorter than those of previous constructions based on Decisional Linear (DLIN) assumption. Ou...
متن کامل(Anonymous) Fully Secure Constant-Size Ciphertext HIBE From Type-3 Pairings
This paper takes a comprehensive look at hierarchical identity-based encryption (HIBE) schemes with constant-size ciphertexts which provide desirable provable guarantees and can be implemented using the most efficient bilinear pairings, namely, Type-3 pairings. Our work results in six new HIBE schemes. The first construction, DPVS-HIBE , is obtained by extending the IBE scheme of Chen et.al. Th...
متن کامل