[Wee25] Almost Optimal KP and CP-ABE for Circuits from Succinct LWE

Authors: Hoeteck Wee | Venue: EUROCRYPT 2025 | Source

Abstract

We construct key-policy (KP) and ciphertext-policy (CP) attribute-based encryption (ABE) for circuits with almost-optimal parameters — ciphertext size, secret key size, and public key size — from a new assumption called succinct LWE (introduced in the author’s prior CRYPTO 2024 work on CP-ABE for ). The -succinct LWE assumption states that an LWE instance is indistinguishable from uniform even given a trapdoor for , where . This is a strengthening of evasive LWE that enables encoding circuit depth information succinctly. We also construct laconic function evaluation (LFE) with -size CRS and digest. The constructions use a circular small-secret variant of succinct LWE.