TY - JOUR
T1 - Contributory broadcast encryption with efficient encryption and short ciphertexts
AU - Wu, Qianhong
AU - Qin, Bo
AU - Zhang, Lei
AU - Domingo-Ferrer, Josep
AU - Farras, Oriol
AU - Manjon, Jesus A.
N1 - Publisher Copyright:
© 1968-2012 IEEE.
PY - 2016/2/1
Y1 - 2016/2/1
N2 - Broadcast encryption (BE) schemes allow a sender to securely broadcast to any subset of members but require a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the group members can decrypt the ciphertexts encrypted under the shared encryption key, but a sender cannot exclude any particular member from decrypting the ciphertexts. In this paper, we bridge these two notions with a hybrid primitive referred to as contributory broadcast encryption (ConBE). In this new primitive, a group of members negotiate a common public encryption key while each member holds a decryption key. A sender seeing the public group encryption key can limit the decryption to a subset of members of his choice. Following this model, we propose a ConBE scheme with short ciphertexts. The scheme is proven to be fully collusion-resistant under the decision n-Bilinear Diffie-Hellman Exponentiation (BDHE) assumption in the standard model. Of independent interest, we present a new BE scheme that is aggregatable. The aggregatability property is shown to be useful to construct advanced protocols.
AB - Broadcast encryption (BE) schemes allow a sender to securely broadcast to any subset of members but require a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the group members can decrypt the ciphertexts encrypted under the shared encryption key, but a sender cannot exclude any particular member from decrypting the ciphertexts. In this paper, we bridge these two notions with a hybrid primitive referred to as contributory broadcast encryption (ConBE). In this new primitive, a group of members negotiate a common public encryption key while each member holds a decryption key. A sender seeing the public group encryption key can limit the decryption to a subset of members of his choice. Following this model, we propose a ConBE scheme with short ciphertexts. The scheme is proven to be fully collusion-resistant under the decision n-Bilinear Diffie-Hellman Exponentiation (BDHE) assumption in the standard model. Of independent interest, we present a new BE scheme that is aggregatable. The aggregatability property is shown to be useful to construct advanced protocols.
KW - Broadcast encryption
KW - contributory broadcast encryption
KW - group key agreement
KW - provable security
UR - https://www.scopus.com/pages/publications/84962129560
U2 - 10.1109/TC.2015.2419662
DO - 10.1109/TC.2015.2419662
M3 - 文章
AN - SCOPUS:84962129560
SN - 0018-9340
VL - 65
SP - 466
EP - 479
JO - IEEE Transactions on Computers
JF - IEEE Transactions on Computers
IS - 2
M1 - 7079389
ER -