Generalised Key Delegation for Hierarchical Identity-Based Encryption

Abstract : This paper introduces a new primitive called identity-based encryption with wildcard key derivation (WKD-IBE or 'wicked IBE') that enhances the concept of hierarchical identity-based encryption by allowing more general key delegation patterns. A secret key is derived for a vector of identity strings, where entries can be left blank using a wildcard. This key can then be used to derive keys for any pattern that replaces wildcards with concrete identity strings. For example, one may want to allow the university's head system administrator to derive secret keys (and hence the ability to decrypt) for all departmental sysadmin email addresses sysadmin@*.univ.edu, where * is a wildcard that can be replaced with any string. The authors provide appropriate security notions and provably secure instantiations with different tradeoffs in terms of ciphertext size and efficiency. The authors also present a generic construction of identity-based broadcast encryption (IBBE) from any WKD-IBE scheme. One of their instantiations yields an IBBE scheme with constant ciphertext size.
Type de document :
Article dans une revue
IET Information Security, Institution of Engineering and Technology, 2008, 2 (3), pp.67-78. 〈10.1049/iet-ifs:20070124〉
Liste complète des métadonnées

https://hal.inria.fr/hal-00918539
Contributeur : Michel Abdalla <>
Soumis le : vendredi 13 décembre 2013 - 16:28:00
Dernière modification le : mardi 17 avril 2018 - 11:28:12

Identifiants

Collections

Citation

Michel Abdalla, Eike Kiltz, Gregory Neven. Generalised Key Delegation for Hierarchical Identity-Based Encryption. IET Information Security, Institution of Engineering and Technology, 2008, 2 (3), pp.67-78. 〈10.1049/iet-ifs:20070124〉. 〈hal-00918539〉

Partager

Métriques

Consultations de la notice

176