Skip to main navigation Skip to search Skip to main content

(Hierarchical) identity-based encryption from affine message authentication

  • Ruhr-University Bochum

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

122 Citations (Scopus)

Abstract

We provide a generic transformation from any affine message authentication code (MAC) to an identity-based encryption (IBE) scheme over pairing groups of prime order. If the MAC satisfies a security notion related to unforgeability against chosen-message attacks and, for example, the k-Linear assumption holds, then the resulting IBE scheme is adaptively secure. Our security reduction is tightness preserving, i.e., if the MAC has a tight security reduction so has the IBE scheme. Furthermore, the transformation also extends to hierarchical identity-based encryption (HIBE). We also show how to construct affine MACs with a tight security reduction to standard assumptions. This, among other things, provides the first tightly secure HIBE in the standard model.

Original languageEnglish
Title of host publicationAdvances in Cryptology, CRYPTO 2014 - 34th Annual Cryptology Conference, Proceedings
PublisherSpringer Verlag
Pages408-425
Number of pages18
EditionPART 1
ISBN (Print)9783662443705
DOIs
Publication statusPublished - 1 Jan 2014
Externally publishedYes
Event34rd Annual International Cryptology Conference, CRYPTO 2014 - Santa Barbara, CA, United States
Duration: 17 Aug 201421 Aug 2014

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
NumberPART 1
Volume8616 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference34rd Annual International Cryptology Conference, CRYPTO 2014
Country/TerritoryUnited States
CitySanta Barbara, CA
Period17/08/1421/08/14

Keywords

  • HIBE
  • IBE
  • standard model
  • tight reduction

Fingerprint

Dive into the research topics of '(Hierarchical) identity-based encryption from affine message authentication'. Together they form a unique fingerprint.

Cite this