Cryptanalysis and improvement of a multi-receiver identity-based key encapsulation at INDOCRYPT 06
Jong Hwan Park, Ki Tak Kim, Dong Hoon Lee · 2008
Multi-receiver Identity-Based Key Encapsulation Mechanism (mIB-KEM) allows a sender to distribute messages for a set of receivers using the receiver's identity as a public key. Recently, Chatterjee and Sarkar [12] suggested a new mIB-KEM which has sublinear-size ciphertexts and private keys simultaneously. They demonstrated that their scheme is secure against chosen plaintext (or ciphertext) attacks without random oracles. In this paper, we show that their scheme is not secure in that a revoked user can easily decrypt cipher-texts. We next propose a new mIB-KEM which overcomes the security flaw identified in the construction of Chatterjee and Sarkar.