Attribute-Based Encryption for Circuits
Name
Vaikuntanathan_Attribute-based.pdf
Size
429 KB
Format
Adobe PDF
Checksum (MD5)
544fceb4fc6be9dcaeca0a5a0614504e
Author(s) • •
Gorbunov, Sergey
Vaikuntanathan, Vinod
Wee, Hoeteck
Date Issued
December 2015
Journal
Journal of the ACM
Publisher
Association for Computing Machinery (ACM)
Citation
Gorbunov, Sergey et al. “Attribute-Based Encryption for Circuits.” Journal of the ACM 62, 6 (December 2015): 1–33 © 2015 Association for Computing Machinery (ACM)
Version
Original manuscript
Abstract
In an attribute-based encryption (ABE) scheme, a ciphertext is associated with an ℓ-bit public index ind and a message m, and a secret key is associated with a Boolean predicate P. The secret key allows decrypting the ciphertext and learning m if and only if P(ind) = 1. Moreover, the scheme should be secure against collusions of users, namely, given secret keys for polynomially many predicates, an adversary learns nothing about the message if none of the secret keys can individually decrypt the ciphertext.
We present attribute-based encryption schemes for circuits of any arbitrary polynomial size, where the public parameters and the ciphertext grow linearly with the depth of the circuit. Our construction is secure under the standard learning with errors (LWE) assumption. Previous constructions of attribute-based encryption were for Boolean formulas, captured by the complexity class NC1.
In the course of our construction, we present a new framework for constructing ABE schemes. As a by-product of our framework, we obtain ABE schemes for polynomial-size branching programs, corresponding to the complexity class LOGSPACE, under quantitatively better assumptions.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/2824233