Revisiting BGG + 14 ABE with weakness analysis

Yupu Hu, Shanshan Zhang, Jiangshan Chen, Baocang Wang · IET Information Security · 2019

Attribute‐based encryption (ABE) supports fine‐grained sharing of encrypted data so that it can be used in a plenty of application scenarios, and many constructions of ABE scheme have been presented. The first arithmetic circuit ABE system was proposed by Boneh, Gentry, Gorbunov et al . (BGG + 14) in Eurocrypt 2014. It is one of the major candidates for ABE, whose security is based on the learning with errors assumption. In this work, the authorsanalyse three different versions of BGG + 14 ABE with weak attributes, weak variants, and weak modulus. First, they discuss weak attributes of BGG + 14 ABE. A weak attribute is generated with corresponding decryption key, such that whenever a ciphertext is labelled with this weak attribute, 1 bit of the plaintext can be revealed. Second, they discuss the security of three variants of BGG + 14 ABE with simplified pre‐sampled matrices, and show that all of them are not secure under collusion attack. Third, they consider the composite modulus rather than prime modulus in BGG + 14 ABE scheme. They show that, if a small factor of the modulus is known, the set of users able to decrypt is clearly expanded. These analyses give different perspectives on the security of BGG + 14 ABE under different conditions.

Read the paper · More papers on PaperTik