Sub-exponentially selective HIBE ⇒ adaptive HIBE
Statement
Every sub-exponentially IND-sHIBE-CPA-secure HIBE scheme, with constant , is IND-HIBE-CPA-secure whenever is negligible: an adaptive adversary with advantage yields a selective adversary of similar size with advantage (complexity leveraging) — folklore.
Sketch
The reduction samples , commits to it as its selective challenge and runs the adaptive adversary, forwarding extraction queries and aborting with a random bit if the adversary queries a prefix of or challenges on another vector. The guess is independent of the adversary’s view, so it equals the adversary’s challenge with probability , and then the admissible adversary never triggers an abort; the reduction’s advantage is the adversary’s divided by .
Notes
- Polynomial selective security does not suffice: when is superpolynomial, IND-sHIBE-CPA security of a scheme does not imply its IND-HIBE-CPA security (No fixed-construction reduction from IND-sHIBE-CPA to IND-HIBE-CPA security) — folklore.
- The IBE analogue loses the size of the identity space (Sub-exponential IND-sID-CPA ⇒ IND-ID-CPA security) — BB04.