<p>Witness encryption (WE) is a novel type of cryptographic primitive that enables a message to be encrypted via an NP instance. Anyone who possesses a solution to this instance (i.e., a witness) can then recover the message from the ciphertext. We introduce a variant of WE that allows ciphertext updates, referred to as ciphertext updateable WE (CUWE). With CUWE, a user can encrypt a message using an instance <i>x</i> and a tag <i>t</i>, and those who possess a valid witness <i>w</i> for <i>x</i> and match the access policy defined by tag <i>t</i> can decrypt the message. Furthermore, CUWE allows for the use of an update token to change the tag <i>t</i> of ciphertext to a different tag. This feature enables fine-grained access control, even after the ciphertext has been created, thereby significantly increasing the usefulness of the WE scheme. We demonstrate that such a WE framework with an updatable ciphertext scheme can be constructed using our puncturable instance-based deterministic encryption (PIDE) and indistinguishability obfuscation <InlineEquation ID="IEq1"> <EquationSource Format="TEX">\((i\cal{O})\)</EquationSource> <EquationSource Format="MATHML"><math display="block"> <mo stretchy="false">(</mo> <mi>i</mi> <mrow> <mi mathvariant="script">O</mi> </mrow> <mo stretchy="false">)</mo> </math></EquationSource> </InlineEquation>. We also propose an instantiation of PIDE utilizing puncturable pseudorandom functions (PRFs) that provide (selectively) indistinguishable security. Finally, we expand our CUWE to ciphertext-updatable functional WE (CUFWE), which offers enhanced data access control.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Witness encryption with updatable ciphertexts

  • Yuzhu Wang,
  • Mingwu Zhang

摘要

Witness encryption (WE) is a novel type of cryptographic primitive that enables a message to be encrypted via an NP instance. Anyone who possesses a solution to this instance (i.e., a witness) can then recover the message from the ciphertext. We introduce a variant of WE that allows ciphertext updates, referred to as ciphertext updateable WE (CUWE). With CUWE, a user can encrypt a message using an instance x and a tag t, and those who possess a valid witness w for x and match the access policy defined by tag t can decrypt the message. Furthermore, CUWE allows for the use of an update token to change the tag t of ciphertext to a different tag. This feature enables fine-grained access control, even after the ciphertext has been created, thereby significantly increasing the usefulness of the WE scheme. We demonstrate that such a WE framework with an updatable ciphertext scheme can be constructed using our puncturable instance-based deterministic encryption (PIDE) and indistinguishability obfuscation \((i\cal{O})\) ( i O ) . We also propose an instantiation of PIDE utilizing puncturable pseudorandom functions (PRFs) that provide (selectively) indistinguishable security. Finally, we expand our CUWE to ciphertext-updatable functional WE (CUFWE), which offers enhanced data access control.