Attribute-Based Keyed Fully Homomorphic Encryption
摘要
Keyed homomorphic public key encryption ( \(\textsf{KHPKE}\) ) is a variant of homomorphic public key encryption, where only users who have a homomorphic evaluation key can perform a homomorphic evaluation. Then, \(\textsf{KHPKE}\) satisfies the \(\textsf{CCA2}\) security against users who do not have a homomorphic evaluation key, while it satisfies the \(\textsf{CCA1}\) security against users who have the key. Thus far, several \(\textsf{KHPKE}\) schemes have been proposed under the standard Diffie-Hellman-type assumptions and keyed fully homomorphic encryption ( \(\textsf{KFHE}\) ) schemes have also been proposed from lattices although there are no \(\textsf{KFHE}\) schemes secure solely under the LWE assumption in the standard model. As a natural extension, there is an identity-based variant of \(\textsf{KHPKE}\) ; however, the security is based on a q-type assumption and no attribute-based variants exist. Moreover, there are no identity-based variants of \(\textsf{KFHE}\) schemes due to the complex design of the known \(\textsf{KFHE}\) schemes. In this paper, we propose the first attribute-based \(\textsf{KFHE}\) ( \(\textsf{ABKFHE}\) ) scheme from lattices. We start by designing the first \(\textsf{KFHE}\) scheme secure solely under the LWE assumption in the standard model. Since the design is conceptually much simpler than known \(\textsf{KFHE}\) schemes, we replace their building blocks with attribute-based ones and obtain the proposed \(\textsf{ABKFHE}\) scheme.