Amendment to Trace and Revoke Systems with Short Ciphertexts.

Xingwen Zhao · International journal of network security · 2012

Traitor tracing is needed because some users in broadcast encryption system may give out their decryption keys to construct pirate decoders. Recently, Liu and Yuan described a trace and revoke systems with short ciphertexts. In this paper, we show that their scheme cannot achieve traitor tracing, since any receiver can decide whether the given ciphertext is well-formed or not so as to decide whether the system is now in normal broadcasting mode or in tracing mode. Thus, any user can construct decoders that will decrypt well-formed ciphertexts (ciphertexts for normal broadcasting) and refuse the badly-formed ciphertexts (ciphertexts for traitor tracing), so that traitors cannot be identified. In such case, innocent users will be framed. We provide an amendment to their scheme and render it useful in traitor tracing against both perfect and imperfect decoders.

Read the paper · More papers on PaperTik