An Improved Certificateless Public Key Encryption
Routo Terada, Denise Goya · 2006
The concept of Identity Based Encryption — IBE — system was proposed by [Sh4] for which the public key can be the identity itself. [BoFr1] presented an IBE system based on bilinear pairing functions, that requires a Public Key Generator — PKG. The PKG needs to be trusted in the sense that it can generate any of the private keys, i.e., it can exercise the so-called key escrow, which is undesirable in many applications. On the other hand this system does not require the so-called Public Key Infrastructure — PKI — with its complex and costly management of Digital Certificates. [AlPa3] proposed a Certificateless Public Key Encryption — CL-PKE — scheme, i.e., a cryptographic scheme which does not require either a Digital Certificate to certify the public key or a PKI. It is also based on bilinear pairing functions. In CL-PKE an adversary A may replace the victm’s public key with another one, say X, so thatA knows the private key corresponding toX; but still A is not able to decrypt the message encrypted with the original published public key. This important property is accomplished by the fact that only the PKG can bind the key pair for any other entity with that entity. For a secure CL-PKE scheme the public key of an entity can be bound to an identity of the entity without any security measure. Furthermore, it is key escrow free, which is not achieved in the framework proposed in [Sh4]. In this paper we construct a CL-PKE scheme based on bilinear pairing functions which: (1) does not allow key escrow by the PKG; (2) does not require Digital Certificates; (3) is more efficient on computation than previously published IBE or CL-PKE schemes ([BoFr1], [Ge3], [AlPa3], [AlPa5], [ChCo5], [Ga5]); (4) and is secure in the sense that it is strong against IND-CCA2 attack 1 [Be8a], based on the Random Oracle Model [Be8a] and the difficulty of the BDH Problem [ChLe2]. For the security proof we reduce (in polynomial time) the problem of solving the BDH Problem to the IND-CCA2 attack against our CL-PKE. The BDH Problem is as follows: (1) Let G1 and G2 be two groups of prime order q and let e : G1 ×G1 → G2 be a bilinear pairing function; (2) Given P ∈ G1, a, b, c ∈ Z∗ q