TY - GEN
T1 - Threshold Batched Identity-Based Encryption from Pairings in the Plain Model
AU - Gong, Junqing
AU - Waters, Brent
AU - Wee, Hoeteck
AU - Wu, David J.
N1 - Publisher Copyright:
© International Association for Cryptologic Research 2026.
PY - 2026
Y1 - 2026
N2 - In a batched identity-based encryption (IBE) scheme, ciphertexts are associated with a batch label tg∗ and an identity id∗ while secret keys are associated with a batch label tg and a set of identities S. Decryption is possible whenever tg=tg∗ and id∗∈S. The primary efficiency property in a batched IBE scheme is that the size of the decryption key for a set S should be independent of the size of S. Batched IBE schemes provide an elegant cryptographic mechanism to support encrypted memory pools in blockchain applications. In this work, we introduce a new algebraic framework for building pairing-based batched IBE. Our framework gives the following:First, we obtain a selectively-secure batched IBE scheme under a q-type assumption in the plain model. Both the ciphertext and the secret key consist of a constant number of group elements. This is the first pairing-based batched IBE scheme in the plain model. Previous pairing-based schemes relied on the generic group model and the random oracle model.Next, we show how to extend our base scheme to a threshold batched IBE scheme with silent setup. In this setting, users independently choose their own public and private keys, and there is a non-interactive procedure to derive the master public key (for a threshold batched IBE scheme) for a group of users from their individual public keys. We obtain a statically-secure threshold batched IBE scheme with silent setup from a q-type assumption in the plain model. As before, ciphertexts and secret keys in this scheme contain a constant number of group elements. Previous pairing-based constructions of threshold batched IBE with silent setup relied on the generic group model, could only support a polynomial number of identities (where the size of the public parameters scaled linearly with this bound), and ciphertexts contained O(λ/logλ) group elements, where λ is the security parameter.Finally, we show that if we work in the generic group model, then we obtain a (threshold) batched IBE scheme with shorter ciphertexts (by 1 group element) than all previous pairing-based constructions (and without impacting the size of the secret key). First, we obtain a selectively-secure batched IBE scheme under a q-type assumption in the plain model. Both the ciphertext and the secret key consist of a constant number of group elements. This is the first pairing-based batched IBE scheme in the plain model. Previous pairing-based schemes relied on the generic group model and the random oracle model. Next, we show how to extend our base scheme to a threshold batched IBE scheme with silent setup. In this setting, users independently choose their own public and private keys, and there is a non-interactive procedure to derive the master public key (for a threshold batched IBE scheme) for a group of users from their individual public keys. We obtain a statically-secure threshold batched IBE scheme with silent setup from a q-type assumption in the plain model. As before, ciphertexts and secret keys in this scheme contain a constant number of group elements. Previous pairing-based constructions of threshold batched IBE with silent setup relied on the generic group model, could only support a polynomial number of identities (where the size of the public parameters scaled linearly with this bound), and ciphertexts contained O(λ/logλ) group elements, where λ is the security parameter. Finally, we show that if we work in the generic group model, then we obtain a (threshold) batched IBE scheme with shorter ciphertexts (by 1 group element) than all previous pairing-based constructions (and without impacting the size of the secret key). Our constructions rely on classic algebraic techniques underlying pairing-based IBE and do not rely on the signature-based witness encryption viewpoint taken in previous works.
AB - In a batched identity-based encryption (IBE) scheme, ciphertexts are associated with a batch label tg∗ and an identity id∗ while secret keys are associated with a batch label tg and a set of identities S. Decryption is possible whenever tg=tg∗ and id∗∈S. The primary efficiency property in a batched IBE scheme is that the size of the decryption key for a set S should be independent of the size of S. Batched IBE schemes provide an elegant cryptographic mechanism to support encrypted memory pools in blockchain applications. In this work, we introduce a new algebraic framework for building pairing-based batched IBE. Our framework gives the following:First, we obtain a selectively-secure batched IBE scheme under a q-type assumption in the plain model. Both the ciphertext and the secret key consist of a constant number of group elements. This is the first pairing-based batched IBE scheme in the plain model. Previous pairing-based schemes relied on the generic group model and the random oracle model.Next, we show how to extend our base scheme to a threshold batched IBE scheme with silent setup. In this setting, users independently choose their own public and private keys, and there is a non-interactive procedure to derive the master public key (for a threshold batched IBE scheme) for a group of users from their individual public keys. We obtain a statically-secure threshold batched IBE scheme with silent setup from a q-type assumption in the plain model. As before, ciphertexts and secret keys in this scheme contain a constant number of group elements. Previous pairing-based constructions of threshold batched IBE with silent setup relied on the generic group model, could only support a polynomial number of identities (where the size of the public parameters scaled linearly with this bound), and ciphertexts contained O(λ/logλ) group elements, where λ is the security parameter.Finally, we show that if we work in the generic group model, then we obtain a (threshold) batched IBE scheme with shorter ciphertexts (by 1 group element) than all previous pairing-based constructions (and without impacting the size of the secret key). First, we obtain a selectively-secure batched IBE scheme under a q-type assumption in the plain model. Both the ciphertext and the secret key consist of a constant number of group elements. This is the first pairing-based batched IBE scheme in the plain model. Previous pairing-based schemes relied on the generic group model and the random oracle model. Next, we show how to extend our base scheme to a threshold batched IBE scheme with silent setup. In this setting, users independently choose their own public and private keys, and there is a non-interactive procedure to derive the master public key (for a threshold batched IBE scheme) for a group of users from their individual public keys. We obtain a statically-secure threshold batched IBE scheme with silent setup from a q-type assumption in the plain model. As before, ciphertexts and secret keys in this scheme contain a constant number of group elements. Previous pairing-based constructions of threshold batched IBE with silent setup relied on the generic group model, could only support a polynomial number of identities (where the size of the public parameters scaled linearly with this bound), and ciphertexts contained O(λ/logλ) group elements, where λ is the security parameter. Finally, we show that if we work in the generic group model, then we obtain a (threshold) batched IBE scheme with shorter ciphertexts (by 1 group element) than all previous pairing-based constructions (and without impacting the size of the secret key). Our constructions rely on classic algebraic techniques underlying pairing-based IBE and do not rely on the signature-based witness encryption viewpoint taken in previous works.
UR - https://www.scopus.com/pages/publications/105040140849
U2 - 10.1007/978-3-032-25330-9_19
DO - 10.1007/978-3-032-25330-9_19
M3 - 会议稿件
AN - SCOPUS:105040140849
SN - 9783032253293
T3 - Lecture Notes in Computer Science
SP - 548
EP - 578
BT - Advances in Cryptology – EUROCRYPT 2026 - 45th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Proceedings
A2 - Daemen, Joan
A2 - Thomé, Emmanuel
PB - Springer Science and Business Media Deutschland GmbH
T2 - 45th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2026
Y2 - 10 May 2026 through 14 May 2026
ER -