Attribute-Based Encryption Schemes with Constant-Size Ciphertexts
Nuttapong Attrapadung, Javier Herranz, Fabien Laguillaume, Benoît Libert, Élie de Panafieu, Carla Ràfols · HAL (Le Centre pour la Communication Scientifique Directe) · 2012
Abstract. Attribute-based encryption (ABE), as introduced by Sahai and Waters, allows for finegrained access control on encrypted data. In its key-policy flavor (the dual ciphertext-policy scenario proceeds the other way around), the primitive enables senders to encrypt messages under a set of attributes and private keys are associated with access structures that specify which ciphertexts the key holder will be allowed to decrypt. In most ABE systems, the ciphertext size grows linearly with the number of ciphertext attributes and the only known exception only supports restricted forms of access policies. This paper proposes the first attribute-based encryption (ABE) schemes allowing for truly expressive access structures and with constant ciphertext size. Our first result is a ciphertext-policy attribute-based encryption (CP-ABE) scheme with O(1)-size ciphertexts for threshold access policies andwhereprivatekeysremainasshortasinprevioussystems.Asasecondresult,weshowthatacertain class of identity-based broadcast encryption schemes generically yields monotonic key-policy attributebased encryption (KP-ABE) systems in the selective set model. Our final contribution is a KP-ABE realization supporting non-monotonic access structures (i.e., that may contain negated attributes) with short ciphertexts. As an intermediate step towards this result, we describe a new efficient identity-based revocation mechanism that, when combined with a particular instantiation of our general monotonic