Security Analysis of a Privacy-Preserving Identity-Based Encryption Architecture
- 1 School of Electrical Engineering and Computer Science, University of Ottawa, Ottawa, Canada
Abstract
Identity-Based Encryption (IBE) has seen limited adoption, largely due to the absolute trust that must be placed in the private key generator (PKG) — an authority that computes the private keys for all the users in the environment. Several constructions have been proposed to reduce the trust required in the PKG (and thus preserve the privacy of users), but these have generally relied on unrealistic assumptions regarding non-collusion between various entities in the system. Unfortunately, these constructions have not significantly improved IBE adoption rates in real-world environments. In this paper, we present a con struction that reduces trust in the PKG without unrealistic non-collusion as sumptions. We achieve this by incorporating a novel combination of digital credential technology and bilinear maps, and making use of multiple ran dom ly-chosen entities to complete certain tasks. The main result and primary contribution of this paper are a thorough security analysis of this proposed construction, examining the various entity types, attacker models, and collusion opportunities in this environment. We show that this construction can prevent, or at least mitigate, all considered attacks. We conclude that our construction appears to be effective in preserving user privacy and we hope that this construction and its security analysis will encourage greater use of IBE in real-world environments.
- Shamir, A. (1985) Identity-Based Cryptosystems and Signature Schemes. Advances in Cryptology—Proceedings of CRYPTO ’84, Vol. 196, Santa Barbara, 19-22 August 1984, 47-53.
- Boneh, D. and Franklin, M. (2001) Identity-Based Encryption from the Weil Pairing (Extended Abstract). Advances in Cryptology—Proceedings of Crypto ’2001, Vol. 2139, Santa Barbara, 19-23 August 2001, 231-229. http://eprint.iacr.org/2001/090/ https://doi.org/10.1007/3-540-44647-8_13
- Boneh, D. and Franklin, M. (2003) Identity-Based Encryption from the Weil Pairing. SIAM Journal on Computing, 32, 586-615. https://doi.org/10.1137/S0097539701398521
- Chow, S.S.M. (2009) Removing Escrow from Identity-Based Encryption. Public Key Cryptography—PKC 2009, Vol. 5443, Irvine, 18-20 March 2009, 256-276. https://doi.org/10.1007/978-3-642-00468-1_15
- Bendlin, R., Krehbiel, S. and Peikert, C. (2013) How to Share a Lattice Trapdoor: Threshold Protocols for Signatures and (H)IBE. ACNS 2013: Applied Cryptography and Network Security, Vol. 7954, Banff, 25-28 June 2013, 218-236. https://doi.org/10.1007/978-3-642-38980-1_14
- Emura, K., Katsumata, S. and Watanabe, Y. (2022) Identity-Based Encryption with Security against the KGC: A Formal Model and its Instantiations. Theoretical Computer Science, 900, 97-119. https://doi.org/10.1016/j.tcs.2021.11.021 https://www.sciencedirect.com/science/article/pii/S030439752100699X
- Brands, S. (2000) Rethinking Public Key Infrastructure and Digital Certificates: Building in Privacy. The MIT Press, Cambridge, MA. https://doi.org/10.7551/mitpress/5931.001.0001
- Brands, S. (2002) A Technical Overview of Digital Credentials. Credentica. Credentica Technical Paper. http://www.credentica.com/overview.pdf
- Koblitz, N. (1987) Elliptic Curve Cryptosystems. Mathematics of Computation, 48, 203-209. https://doi.org/10.1090/S0025-5718-1987-0866109-5
- Miller, V. (1986) Use of Elliptic Curves in Cryptography. Advances in Cryptology—Proceedings of CRYPTO ‘85, Vol. 218, Santa Barbara, 18-22 August 1985, 417-426. https://doi.org/10.1007/3-540-39799-X_31
- Galbraith, S., Harrison, K. and Soldera, D. (2002) Implementing the Tate Pairing. Algorithmic Number Theory Symposium: 5th International Symposium (ANTS-V), Vol. 2369, Sydney, 7-12 July 2002, 324-337. https://doi.org/10.1007/3-540-45455-1_26
- Miller, V. (2004) The Weil Pairing, and its Efficient Calculation. Journal of Cryptology, 17, 235-261. https://doi.org/10.1007/s00145-004-0315-8