Comments on an Efficient ID-Based Broadcast Encryption Scheme
Hung‐Yu Chien · IEEE Transactions on Broadcasting · 2007
Based on bilinear pairing, Du et al. recently proposed an efficient ID-based broadcast encryption scheme. This correspondence shows that the scheme is not secure in the sense that an adversary can easily derive the secret when there are only two designated receivers. By the way, we comment that the scheme gains the efficiency of the sender at the price of sacrificing the efficiency of the receivers.