[论文解读] Hierarchical Identity-Based Lossy Trapdoor Functions
本文引入了分层身份基(损失性)陷门函数(HIB-TDFs),提出了一种新的安全定义,使得在自适应身份基设置下可构造出安全的密码原语。该文在传统数论假设下,首次基于配对构造了HIB-TDF,利用分层谓词加密作为核心组件,并证明了其在仅需选择性安全的底层系统下,对选择性或常数深度自适应敌手具备安全性。
Lossy trapdoor functions, introduced by Peikert and Waters (STOC'08), have received a lot of attention in the last years, because of their wide range of applications in theoretical cryptography. The notion has been recently extended to the identity-based setting by Bellare et al. (Eurocrypt'12). We provide one more step in this direction, by considering the notion of hierarchical identity-based (lossy) trapdoor functions (HIB-TDFs). Hierarchical identity-based cryptography has proved very useful both for practical applications and to establish theoretical relations with other cryptographic primitives. The notion of security for IB-TDFs put forward by Bellare et al. easily extends to the hierarchical scenario, but an (H)IB-TDF secure in this sense is not known to generically imply other related primitives with security against adaptive-id adversaries, not even IND-ID-CPA secure encryption. Our first contribution is to define a new security property for (H)IB-TDFs. We show that functions satisfying this property imply secure cryptographic primitives in the adaptive identity-based setting: these include encryption schemes with semantic security under chosen-plaintext attacks, deterministic encryption schemes, and (non-adaptive) hedged encryption schemes that maintain some security when messages are encrypted using randomness of poor quality. Then, we describe the first pairing-based HIB-TDF realization. Our HIB-TDF construction is based on techniques that differ from those of Bellare et al. in that it uses a hierarchical predicate encryption scheme as a key ingredient. The resulting HIB-TDF is proved to satisfy the new security definition, against either selective or, for hierarchies of constant depth, adaptive adversaries.
研究动机与目标
- 将损失性陷门函数扩展至分层身份基设置,解决先前工作中在自适应安全性方面的局限性。
- 为HIB-TDFs定义一种新安全属性,该属性通用地蕴含IND-ID-CPA、确定性及抗碰撞性加密方案。
- 基于传统数论假设(非格基)构造首个HIB-TDF,以分层谓词加密作为核心组件。
- 在常数深度分层结构中实现对自适应敌手的安全性,且仅需底层谓词加密系统具备选择性安全。
- 解决先前工作中未解决的开放问题:IB-TDFs是否能在自适应-ID敌手下隐含安全原语。
提出的方法
- 提出一种名为“部分损失性”的HIB-TDF新安全概念,确保即使在自适应身份选择下,注入模式与损失模式之间仍不可区分。
- 使用分层谓词加密(HPE)方案作为构建模块来构造HIB-TDF,将身份映射至访问策略。
- 利用HPE系统的损失性来实现HIB-TDF的损失模式,同时通过密钥保持陷门功能。
- 证明在底层HPE系统具备选择性安全的假设下,所构造的HIB-TDF满足新的安全定义。
- 展示HIB-TDF构造可支持安全的身份基加密、确定性加密及抗碰撞性加密方案的生成。
- 采用基于模拟的证明策略,表明HIB-TDF构造在常数深度分层结构中对自适应敌手具备安全性。
实验结果
研究问题
- RQ1能否在传统数论假设下构造分层身份基陷门函数,而非依赖于格基构造?
- RQ2HIB-TDFs的新安全定义是否蕴含在自适应-ID攻击下安全的身份基加密?
- RQ3新HIB-TDF概念是否不仅能支持IND-ID-CPA加密,还能支持确定性及抗碰撞性加密方案?
- RQ4是否仅使用选择性安全的底层原原子,即可在常数深度分层结构中实现对自适应敌手的安全性?
- RQ5HIB-TDFs的“部分损失性”特性是否可用于构造非自适应抗碰撞性身份基加密方案?
主要发现
- 本文首次基于传统数论假设(具体为基于配对的密码学)构造了HIB-TDF。
- 所提出的HIB-TDF满足一种新安全定义,该定义蕴含IND-ID-CPA安全的身份基加密、确定性加密及非自适应抗碰撞性加密。
- 当分层深度为常数时,该构造对自适应敌手具备安全性,且仅依赖于选择性安全的分层谓词加密系统。
- HIB-TDF的安全性通过基于模拟的论证方法证明,表明在自适应身份查询下,注入模式与损失模式之间不可区分。
- 本工作解决了Bellare等人遗留的开放问题,表明在HIB设置下,部分损失性可产生即使在自适应-ID敌手下也安全的密码原语。
- 结果表明,具备新安全定义的HIB-TDF可被用于构建身份基设置下的多种密码原语。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。