Identity-Based Matchmaking Encryption with Enhanced Privacy – A Generic Construction with Practical Instantiations
摘要
Identity-based matchmaking encryption (IB-ME), proposed by Ateniese et al. (Crypto 2019), is a type of matchmaking encryption (ME). In IB-ME, the sender can specify a target identity \(\textsf{rcv}\) during encryption, and the receiver can set a target identity \(\textsf{snd}\) during decryption. The ciphertext can be decrypted if \(\textsf{snd}\) matches the sender’s identity \(\sigma \) , and \(\textsf{rcv}\) matches the receiver’s identity \(\rho \) . The basic security notion of IB-ME is privacy, whose original definition ensures that \(\sigma \) , \(\textsf{rcv}\) , and the message remain hidden as long as \(\textsf{rcv}\ne \rho \) , regardless the relation between \(\textsf{snd}\) and \(\sigma \) . Francati et al. (IndoCrypt 2021) argue that the original privacy notion is unsatisfactory as it does not match the intuitive privacy guarantee of matching encryption. They revise the original privacy notion with an enhanced privacy notion to characterise meaningful privacy under the condition \(\textsf{snd}\ne \sigma \) and construct an IB-ME system with the enhanced security in the plain model, albeit under a q-type pairing-based assumption. Chen et al. (AsiaCrypt 2022) leave how to construct IB-ME systems with enhanced privacy as an open problem. In this paper, we solve the problem by a generic construction of IB-ME with enhanced privacy. Instantiating our construction gives practical IB-ME systems with enhanced privacy from various standard assumptions.