[Wee22] Optimal Broadcast Encryption and CP-ABE from Evasive Lattice Assumptions
Authors: Hoeteck Wee | Venue: EUROCRYPT 2022 | Source
Abstract
We present new constructions of broadcast encryption and ciphertext-policy attribute-based encryption (CP-ABE) for circuits with optimal parameters — ciphertext overhead and public key size — from a new lattice assumption called evasive LWE. Evasive LWE posits that a standard LWE instance remains indistinguishable from uniform even when the adversary is given a trapdoor for a matrix derived from the LWE matrix. The assumption is motivated by the structure of the constructions and is incomparable to standard LWE; it evades known lattice attacks because the trapdoor does not directly help invert the LWE problem.