Skip to main navigation Skip to search Skip to main content

Identity-Based Encryption in DDH Hard Groups

  • Royal Holloway University of London

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Citation (Scopus)

Abstract

The concept of Identity-Based Encryption was first introduced by Shamir (CRYPTO 1984) but were not realised until much later by Sakai, Ohgishi and Kasahara (SCIS 2000), Boneh and Franklin (CRYPTO 2001) and Cocks (IMACC 2001). Since then, Identity-Based Encryption has been a highly active area of research. While there have been several instantiations of Identity-Based Encryption and its variants, there is one glaring omission: there have been no instantiations in plain Decisional Diffie-Hellman groups. This seemed at odds with the fact that we can instantiate almost every single cryptographic primitive in plain Decisional Diffie-Hellman groups. An answer to this question came in a result by Papakonstantinou, Rackoff and Vahlis (EPRINT 2012), who showed that it is impossible to instantiate an Identity-Based Encryption in plain DDH groups. The impossibility result was questioned when Döttling and Garg (CRYPTO 2017) presented an Identity-Based Encryption based on the Decisional Diffie-Hellman problem. However, this result did not disprove the impossibility result, as it requires the use of garbled circuits, which are inherently interactive. This type of scheme is not covered by the impossibility result, but it does raise some questions. In this paper, we answer some of those questions by constructing an Identity-Based Encryption scheme based on the Decisional Diffie-Hellman problem. We achieve this by instantiating the generic construction based on Witness Encryption by Garg, Gentry, Sahai and Waters (STOC 2013), with some minor changes. To this end, we construct the first unique signature scheme in Decisional Diffie-Hellman groups, to the best of our knowledge. The unique signature scheme, and as a result, our Identity-Based Encryption scheme, is inefficient, but this is unavoidable. Our construction does not completely contradict the impossibility result but instead shows that the statement was too strong, and the result only rules out efficient constructions.

Original languageEnglish
Title of host publicationProgress in Cryptology - AFRICACRYPT 2022 - 13th International Conference on Cryptology in Africa, AFRICACRYPT 2022, Proceedings
EditorsLejla Batina, Joan Daemen
PublisherSpringer Science and Business Media Deutschland GmbH
Pages81-102
Number of pages22
ISBN (Print)9783031174322
DOIs
Publication statusPublished - 1 Jan 2022
Event13th International Conference on Progress in Cryptology in Africa, AFRICACRYPT 2022 - Fes, Morocco
Duration: 18 Jul 202220 Jul 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13503 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference13th International Conference on Progress in Cryptology in Africa, AFRICACRYPT 2022
Country/TerritoryMorocco
CityFes
Period18/07/2220/07/22

Keywords

  • DDH
  • Generic constructions
  • Identity-based encryption
  • Impossibility results
  • Unique signatures

Fingerprint

Dive into the research topics of 'Identity-Based Encryption in DDH Hard Groups'. Together they form a unique fingerprint.

Cite this