Tight Adaptive Simulation Security for Identity-Based Inner-Product FE in the (Quantum) Random Oracle Model
摘要
Abdalla et al. (ASIACRYPT 2020) introduced a notion of identity-based inner-product functional encryption ( \(\textsf{IBIPFE}\) ) that combines identity-based encryption and inner-product functional encryption ( \(\textsf{IPFE}\) ). Thus far, several pairing-based and lattice-based \(\textsf{IBIPFE}\) schemes have been proposed. However, there are two open problems. First, there are no known \(\textsf{IBIPFE}\) schemes that satisfy the adaptive simulation-based security. Second, known \(\textsf{IBIPFE}\) schemes that satisfy the adaptive indistinguishability-based security or the selective simulation-based security do not have tight reductions. In this paper, we propose lattice-based and pairing-based \(\textsf{IBIPFE}\) schemes that satisfy the tight adaptive simulation-based security. At first, we propose a generic transformation from an indistinguishability-based secure \((L + 1)\) -dimensional \(\mathsf {(IB)IPFE}\) scheme to a simulation-based secure L-dimensional \(\mathsf {(IB)IPFE}\) scheme. The proposed transformation improves Agrawal et al.’s transformation for plain \(\textsf{IPFE}\) (PKC 2020) that requires an indistinguishability-based secure 2L-dimensional scheme. Then, we construct a lattice-based \(\textsf{IBIPFE}\) scheme that satisfies the tight adaptive indistinguishability-based security under the \(\textsf{LWE}\) assumption in the quantum random oracle model. We apply the proposed transformation and obtain the first lattice-based \(\textsf{IBIPFE}\) scheme that satisfies adaptive simulation-based security. Finally, we construct a pairing-based \(\textsf{IBIPFE}\) scheme that satisfies the tight adaptive simulation-based security under the \(\textsf{DBDH}\) assumption in the random oracle model. The pairing-based scheme does not use the proposed transformation towards the best efficiency.