错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On the Feasibility of Identity-Based Encryption with Equality Test Against Insider Attacks

  • Keita Emura

摘要

Public key encryption with equality test, proposed by Yang et al. (CT-RSA 2010), allows anyone to check whether two ciphertexts of distinct public keys are encryptions of the same plaintext or not using trapdoors, and identity-based encryption with equality test ( \(\textsf{IBE}\textsf{ET}\) ) is its identity-based variant. As a variant of \(\textsf{IBE}\textsf{ET}\) , \(\textsf{IBE}\textsf{ET}\) against insider attacks ( \(\textsf{IBE}\textsf{ETIA}\) ) was proposed by Wu et al. (ACISP 2017), where a token is defined for each identity and is used for encryption. Lee et al. (ACISP 2018) and Duong et al. (ProvSec 2019) proposed \(\textsf{IBE}\textsf{ETIA}\) schemes constructed by identity-based encryption ( \(\textsf{IBE}\) ) related complexity assumptions. Later, Emura and Takayasu (IEICE Transactions 2023) demonstrated that symmetric key encryption and pseudo-random permutations are sufficient to construct \(\textsf{IBE}\textsf{ETIA}\) which is secure in the previous security definition. In this paper, we demonstrate a sufficient condition that \(\textsf{IBE}\textsf{ETIA}\) implies \(\textsf{IBE}\) . We define one-wayness against chosen-plaintext/ciphertext attacks for the token generator (OW-TG-CPA/CCA) and for token holders (OW-TH-CPA/CCA), which were not considered in the previous security definition. We show that OW-TG-CPA secure \(\textsf{IBE}\textsf{ETIA}\) with additional conditions implies OW-CPA secure \(\textsf{IBE}\) . On the other hand, we propose a generic construction of OW-TH-CCA secure \(\textsf{IBE}\textsf{ETIA}\) from public key encryption. Our results suggest a design principle to efficiently construct \(\textsf{IBE}\textsf{ETIA}\) without employing \(\textsf{IBE}\) -related complexity assumptions.