Generic Trace and Revoke Schemes from Fingerprinting Codes

Murat Ak, Aggelos Kiayias, Serdar Pehlivanoğlu, Ali Aydın Selçuk · International Conference on Applied and Computational Mathematics · 2012

Broadcast encryption (BE) is a cryptographic primitive that allows a broadcaster to encrypt a content to a specific group of users called privileged users and prevent revoked users from decrypting the content even if they collude. If the privilege set is kept secret, it is called an anonymous BE scheme. In BE schemes, a group of users, called traitors may collude and form a pirate decoder. In order to trace such actions, Traitor tracing (TT) schemes are proposed so that users that contribute to such decoders can be detected and their keys get revoked. A challenging problem is to design trace and revoke (T\&R) systems which combines the functionalities of both BE and TT schemes. In this paper, we propose a generic method to obtain anonymous T\&R schemes from anonymous BE schemes. Our construction preserves the main efficiency parameters of the underlying BE schemes. More interestingly, the T\&R scheme obtained from our generic construction inherits the characteristics of the BE scheme used as a primitive. For example using an ID-based BE scheme yields the first ID-based T\&R scheme, while using an anonymous BE scheme yields an anonymous T\&R scheme.

Read the paper · More papers on PaperTik