On the Security of AMRIBE, Anonymous Multi-receiver Identity-Based Encryption
摘要
Anonymous Multi-Receiver Identity-Based Encryption (AMRIBE) is a cryptographic method that enables a sender to efficiently and securely encrypt a common message for a group of receivers while prioritizing the subscribed receivers’ outsider and insider anonymity. In 2021, Tseng and Fan [Security and Communication Network] presented an Anonymous Multi-Receiver Identity-Based Encryption (AMRIBE) scheme and asserted that their system provides security against the chosen ciphertext attacks. During our analysis, we investigated the aforementioned security of the AMRIBE scheme and found that it is susceptible to certain Probabilistic Polynomial-Time (PPT) attackers. Through our proposed two attack models, we have demonstrated that their system does not achieve the primary security requirement, which is ciphertext confidentiality in the Multi-Receiver Encryption framework. Additionally, we have shown that any PPT attacker can recover the Master Secret-Key (MSK) of the underlying system by utilizing the KeyExtract Query of some users. To further resolve this issue, in this paper we propose a generic modification technique to improve their scheme and show a pathway to construct a secure AMRIBE. Furthermore, we implemented our proposed two attack models considering a particular case, and the execution time proved that our attack technique can efficiently break their protocol in a short time.