Multi-Authority Functional Encryption ( \(\textsf{MA}\text {-}\textsf{FE}\) ) [Chase, TCC’07; Lewko-Waters, Eurocrypt’11; Brakerski et al., ITCS’17] is a popular generalization of functional encryption ( \(\textsf{FE}\) ) with the central goal of decentralizing the trust assumption from a single central trusted key authority to a group of multiple, independent and non-interacting, key authorities. Over the last several decades, we have seen tremendous advances in new designs and constructions for \(\textsf{FE}\) supporting different function classes, from a variety of assumptions and with varying levels of security. Unfortunately, the same has not been replicated in the multi-authority setting. The current scope of \(\textsf{MA}\text {-}\textsf{FE}\) designs is rather limited, with positive results only known for certain attribute-based functionalities or from general-purpose code obfuscation. This state-of-the-art in \(\textsf{MA}\text {-}\textsf{FE}\) could be explained in part by the implication provided by Brakerski et al. (ITCS’17). It was shown that a general-purpose obfuscation scheme can be designed from any \(\textsf{MA}\text {-}\textsf{FE}\) scheme for circuits, even if the \(\textsf{MA}\text {-}\textsf{FE}\) scheme is secure only in a bounded-collusion model, where at most two keys per authority get corrupted. In this work, we revisit the problem of \(\textsf{MA}\text {-}\textsf{FE}\) , and show that existing implication from \(\textsf{MA}\text {-}\textsf{FE}\) to obfuscation is not tight. We provide new methods to design \(\textsf{MA}\text {-}\textsf{FE}\) for circuits from simple and minimal cryptographic assumptions. Our main contributions are summarized below–

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Multi-authority Functional Encryption with Bounded Collusions from Standard Assumptions

  • Rishab Goyal,
  • Saikumar Yadugiri

摘要

Multi-Authority Functional Encryption ( \(\textsf{MA}\text {-}\textsf{FE}\) ) [Chase, TCC’07; Lewko-Waters, Eurocrypt’11; Brakerski et al., ITCS’17] is a popular generalization of functional encryption ( \(\textsf{FE}\) ) with the central goal of decentralizing the trust assumption from a single central trusted key authority to a group of multiple, independent and non-interacting, key authorities. Over the last several decades, we have seen tremendous advances in new designs and constructions for \(\textsf{FE}\) supporting different function classes, from a variety of assumptions and with varying levels of security. Unfortunately, the same has not been replicated in the multi-authority setting. The current scope of \(\textsf{MA}\text {-}\textsf{FE}\) designs is rather limited, with positive results only known for certain attribute-based functionalities or from general-purpose code obfuscation. This state-of-the-art in \(\textsf{MA}\text {-}\textsf{FE}\) could be explained in part by the implication provided by Brakerski et al. (ITCS’17). It was shown that a general-purpose obfuscation scheme can be designed from any \(\textsf{MA}\text {-}\textsf{FE}\) scheme for circuits, even if the \(\textsf{MA}\text {-}\textsf{FE}\) scheme is secure only in a bounded-collusion model, where at most two keys per authority get corrupted. In this work, we revisit the problem of \(\textsf{MA}\text {-}\textsf{FE}\) , and show that existing implication from \(\textsf{MA}\text {-}\textsf{FE}\) to obfuscation is not tight. We provide new methods to design \(\textsf{MA}\text {-}\textsf{FE}\) for circuits from simple and minimal cryptographic assumptions. Our main contributions are summarized below–