Witness Encryption based on the SAT Problem*

Xingbo Wang, Yuzhu Wang, Mingwu Zhang · 2024

Witness encryption (WE) allows a ciphertext to be encrypted under an NP problem such that anyone holding a valid witness for that problem can decrypt it. However, existing WE schemes or constructions are either impractical or implement only a part of these WE features. We provide two versions of the scheme. The WE scheme that 1) is based on pairings with the property of flexible decryptors, 2) only applies to some SAT problems, and 3) does not require the decryptor’s communication with an encryptor. The SAT problem can only be partially supported as it is not fully protected against all mixed-input attacks. So We provide another version of the scheme. The Modified Witness Encryption (MWE) scheme via non-interactive Oblivious Transfer (OT) 1) is based on pairings with the property of flexible decryptors, 2) applies to all SAT problems, and 3) still requires the decryptor’s or third-party communication with an encryptor, and the communication can only perform a fixed asynchronous amount of computation at regular intervals, regardless of the number of ciphertexts. At present, there is no witness encryption scheme that can satisfy both non-interactivity and (1), (2) in MWE features and there are many interactive application cases in the application scenarios of witness encryption.

Read the paper · More papers on PaperTik