Forward-Secure Tag-Inverse Puncturable Identity-Based Encryption
摘要
Identity-based encryption eliminates the complex certificate management overhead inherent in traditional public-key infrastructures, leading to its widespread adoption across various domains. However, this popularity also increases exposure to critical security threats, most notably private key leakage, which allows unauthorized parties to decrypt sensitive data. While existing forward-secure IBE schemes mitigate the impact of leakage through periodic key updates, they typically lack the granularity to revoke the decryption capability of individual ciphertexts instantaneously. To bridge this gap, we propose a novel cryptographic primitive, Forward-Secure Tag-Inverse Puncturable Identity-Based Encryption (FS-TIPIBE), that provides fine-grained forward security. Specifically, FS-TIPIBE incorporates two synergistic algorithms: private key puncturing and exclude-from-puncturing. The former updates private keys for specific tags to maintain forward security and generates corresponding tokens; the latter leverages these tokens to precisely control which ciphertexts are excluded from the puncturing process. This ensures that only non-expired and specifically excluded ciphertexts remain decryptable post-update. Furthermore, we propose a concrete FS-TIPIBE construction and provide formal security proofs under a standard bilinear group assumption. Both theoretical analysis and experimental validation attest to the efficiency and practical merits of the proposed scheme, making it a robust solution for systems requiring stringent forward security guarantees.