Mergeable Functional Encryption.
Vincenzo Iovino, Karol Żebrowski · 2015
In recent years, there has been great interest in Functional Encryption (FE), a generaliza-tion of traditional encryption where a token enables a user to learn a specific function of the encrypted data and nothing else. In this paper we put forward a new generalization of FE that we call M ergeable FE (mFE). In a mFE system, given a ciphertext c1 encrypting m1 and a ciphertext c2 encrypting m2, it is possible to produce in an oblivious way (i.e., given only the public-key and without knowledge of the messages, master secret-key or any other aux-iliary information) a ciphertext encrypting the string m1||m2 under the security constraint that this new ciphertext does not leak more information about the original messages than what may be leaked from the new ciphertext using the tokens. For instance, suppose that the adversary is given the token for the function f(·) defined so that for strings x ∈ {0, 1}n, f(x) 4 = g(x) for some function g: {0, 1}n → {0, 1} and for strings y = (x1||x2) ∈ {0, 1}2n, f(x1||x2) 4 = g(x1) ∨ g(x2). Furthermore, suppose that the adversary gets a ciphertext c