Registration-based encryption (RBE) is a solution for the key-escrow problem in identity-based encryption. Initial RBE schemes are too theoretical and inefficient, but recent advances make RBE schemes efficient enough to be incorporated into real-world systems. On the other hand, from a security point of view, existing schemes are insufficient for such systems because they only consider CPA security. Recently, Glaeser et al. (ACM CCS’23) presented a solution to this problem. They suggested the usage of the original Fujisaki-Okamoto (FO) transformation (CRYPTO’99) to realize CCA-secure RBE. However, they did not provide its formal analysis because they considered it can be applied in a straightforward manner. In this work, we reveal that the FO transformation for RBE is non-trivial, and provide an appropriate one suitable to RBE. The essence of achieving CCA security through FO transformation is that the receiver verifies that the received ciphertext is correctly generated by re-encryption. In RBE, we find that the sender and receiver must share the public parameter used for encryption since the decryption algorithm does not take it by default. Therefore, we make the sender explicitly send the current public parameter as part of the ciphertext. Furthermore, we show that a sufficiently large min-entropy of ciphertexts (so-called well-spreadness) is necessary to apply the FO transformation to RBE, in contrast to PKE or IBE. This property guarantees that no information is leaked from the decryption oracle even if the public parameter in the ciphertext is replaced. Based on these observations, we propose a new FO transformation tailored to RBE, which allows existing CPA-secure RBE schemes to be transformed into CCA-secure ones correctly.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

How to Apply Fujisaki-Okamoto Transformation to Registration-Based Encryption

  • Sohto Chiku,
  • Keisuke Hara,
  • Keitaro Hashimoto,
  • Toi Tomita,
  • Junji Shikata

摘要

Registration-based encryption (RBE) is a solution for the key-escrow problem in identity-based encryption. Initial RBE schemes are too theoretical and inefficient, but recent advances make RBE schemes efficient enough to be incorporated into real-world systems. On the other hand, from a security point of view, existing schemes are insufficient for such systems because they only consider CPA security. Recently, Glaeser et al. (ACM CCS’23) presented a solution to this problem. They suggested the usage of the original Fujisaki-Okamoto (FO) transformation (CRYPTO’99) to realize CCA-secure RBE. However, they did not provide its formal analysis because they considered it can be applied in a straightforward manner. In this work, we reveal that the FO transformation for RBE is non-trivial, and provide an appropriate one suitable to RBE. The essence of achieving CCA security through FO transformation is that the receiver verifies that the received ciphertext is correctly generated by re-encryption. In RBE, we find that the sender and receiver must share the public parameter used for encryption since the decryption algorithm does not take it by default. Therefore, we make the sender explicitly send the current public parameter as part of the ciphertext. Furthermore, we show that a sufficiently large min-entropy of ciphertexts (so-called well-spreadness) is necessary to apply the FO transformation to RBE, in contrast to PKE or IBE. This property guarantees that no information is leaked from the decryption oracle even if the public parameter in the ciphertext is replaced. Based on these observations, we propose a new FO transformation tailored to RBE, which allows existing CPA-secure RBE schemes to be transformed into CCA-secure ones correctly.