Skip to main content
QUICK REVIEW

[Paper Review] Hierarchical Identity-Based Lossy Trapdoor Functions

Alex Escala, Javier Herranz|arXiv (Cornell University)|Feb 27, 2012
Cryptography and Data Security37 references3 citations
TL;DR

This paper introduces hierarchical identity-based (lossy) trapdoor functions (HIB-TDFs), proposing a new security definition that enables constructions of secure cryptographic primitives in the adaptive identity-based setting. It presents the first pairing-based HIB-TDF under traditional number-theoretic assumptions, leveraging hierarchical predicate encryption, and proves security against selective or constant-depth adaptive adversaries with only selective security required from the underlying system.

ABSTRACT

Lossy trapdoor functions, introduced by Peikert and Waters (STOC'08), have received a lot of attention in the last years, because of their wide range of applications in theoretical cryptography. The notion has been recently extended to the identity-based setting by Bellare et al. (Eurocrypt'12). We provide one more step in this direction, by considering the notion of hierarchical identity-based (lossy) trapdoor functions (HIB-TDFs). Hierarchical identity-based cryptography has proved very useful both for practical applications and to establish theoretical relations with other cryptographic primitives. The notion of security for IB-TDFs put forward by Bellare et al. easily extends to the hierarchical scenario, but an (H)IB-TDF secure in this sense is not known to generically imply other related primitives with security against adaptive-id adversaries, not even IND-ID-CPA secure encryption. Our first contribution is to define a new security property for (H)IB-TDFs. We show that functions satisfying this property imply secure cryptographic primitives in the adaptive identity-based setting: these include encryption schemes with semantic security under chosen-plaintext attacks, deterministic encryption schemes, and (non-adaptive) hedged encryption schemes that maintain some security when messages are encrypted using randomness of poor quality. Then, we describe the first pairing-based HIB-TDF realization. Our HIB-TDF construction is based on techniques that differ from those of Bellare et al. in that it uses a hierarchical predicate encryption scheme as a key ingredient. The resulting HIB-TDF is proved to satisfy the new security definition, against either selective or, for hierarchies of constant depth, adaptive adversaries.

Motivation & Objective

  • To extend lossy trapdoor functions to the hierarchical identity-based setting, addressing limitations in prior work regarding adaptive security.
  • To define a new security property for HIB-TDFs that generically implies IND-ID-CPA, deterministic, and hedged encryption schemes.
  • To construct the first HIB-TDF based on traditional number-theoretic assumptions (not lattices), using hierarchical predicate encryption as a core component.
  • To achieve security against adaptive adversaries in constant-depth hierarchies, requiring only selectively secure underlying predicate encryption.
  • To resolve the open problem of whether IB-TDFs can imply secure primitives under adaptive-ID adversaries, which was unresolved in prior work.

Proposed method

  • Propose a new security notion called 'partial lossiness' for HIB-TDFs, ensuring indistinguishability between injective and lossy modes even under adaptive identity choice.
  • Construct the HIB-TDF using a hierarchical predicate encryption (HPE) scheme as a building block, mapping identities to access policies.
  • Use the HPE system’s lossiness to instantiate the lossy mode of the HIB-TDF, while maintaining trapdoor functionality via secret keys.
  • Prove that the resulting HIB-TDF satisfies the new security definition under the assumption that the underlying HPE is selectively secure.
  • Demonstrate that the HIB-TDF construction supports the derivation of secure identity-based encryption, deterministic encryption, and hedged encryption schemes.
  • Employ a simulation-based proof strategy to show that the HIB-TDF construction is secure against adaptive adversaries in constant-depth hierarchies.

Experimental results

Research questions

  • RQ1Can a hierarchical identity-based trapdoor function be constructed under traditional number-theoretic assumptions, rather than relying on lattice-based constructions?
  • RQ2Does a new security definition for HIB-TDFs imply secure identity-based encryption under adaptive-ID attacks?
  • RQ3Can the new HIB-TDF notion support not only IND-ID-CPA encryption but also deterministic and hedged encryption schemes?
  • RQ4Is it possible to achieve security against adaptive adversaries in constant-depth hierarchies using only selectively secure underlying primitives?
  • RQ5Can the partial lossiness property of HIB-TDFs be used to construct non-adaptive hedged identity-based encryption schemes?

Key findings

  • The paper presents the first HIB-TDF construction based on traditional number-theoretic assumptions, specifically using pairing-based cryptography.
  • The proposed HIB-TDF satisfies a new security definition that implies IND-ID-CPA secure identity-based encryption, deterministic encryption, and non-adaptive hedged encryption.
  • The construction is secure against adaptive adversaries when the hierarchy depth is constant, relying only on selectively secure hierarchical predicate encryption.
  • The security of the HIB-TDF is proven via a simulation-based argument, showing indistinguishability between injective and lossy modes under adaptive identity queries.
  • The work resolves an open problem left by Bellare et al. by showing that partial lossiness in the HIB setting can yield secure primitives even under adaptive-ID adversaries.
  • The results demonstrate that HIB-TDFs with the new security definition can be used to build a wide range of cryptographic primitives in the identity-based setting.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.