Encry ryption for Quadratic Functions wit ith Applications to - - PowerPoint PPT Presentation

encry ryption for quadratic
SMART_READER_LITE
LIVE PREVIEW

Encry ryption for Quadratic Functions wit ith Applications to - - PowerPoint PPT Presentation

Practical Functional Encry ryption for Quadratic Functions wit ith Applications to Predicate Encry ryption Carmen Elisabetta Zaira Baltico Universit di Catania Dario Catalano Universit di Catania Dario Fiore IMDEA Romain Gay


slide-1
SLIDE 1

Practical Functional Encry ryption for Quadratic Functions wit ith Applications to Predicate Encry ryption

Carmen Elisabetta Zaira Baltico Università di Catania Dario Catalano Università di Catania Dario Fiore IMDEA Romain Gay (speaker) ENS

slide-2
SLIDE 2

FE [Boneh, , Sahai, Waters 11]

Alice

m

Bob f(m)

slide-3
SLIDE 3

FE [Boneh, , Sahai, Waters 11]

Setup Alice

m

pk skf msk KeyGen Bob skf → f(m)

slide-4
SLIDE 4

FE [Boneh, , Sahai, Waters 11]

Setup Alice

m

Carl pk skf, skg msk KeyGen skg → g(m) Bob skf → f(m)

slide-5
SLIDE 5

FE [Boneh, , Sahai, Waters 11]

Setup Alice

m

pk skf, skg msk KeyGen

Adv

Only learns f m , g(m) Carl skg → g(m) Bob skf → f(m) Collusion

slide-6
SLIDE 6

FE [Boneh, , Sahai, Waters 11]

Setup Alice

m0

pk skf, skg msk KeyGen

Adv

f m0 = f m1 g m0 = g m1 Carl skg → g(m) Bob skf → f(m)

m1 ≈𝑑

Collusion

slide-7
SLIDE 7

Pri rior works on FE

𝑛 = Ԧ 𝑦 ∈ ℤ𝑞

𝑜

𝑔 = Ԧ 𝑧 ∈ ℤ𝑞

𝑜

𝑔 𝑛 = Ԧ 𝑦𝑈 Ԧ 𝑧 ∈ ℤ𝑞 ct size = 𝑃(𝑜) Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH

slide-8
SLIDE 8

Our work on FE

Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings 𝑛 = Ԧ 𝑦, Ԧ 𝑧 ∈ ℤ𝑞

𝑜 × ℤ𝑞 𝑛

𝑔 = 𝑔

𝑗,𝑘 𝑗∈ 𝑜 ,𝑘∈[𝑛] ∈ ℤ𝑞 𝑜×𝑛

𝑔 𝑛 = Ԧ 𝑦𝑈𝑔 Ԧ 𝑧 = ෍

𝑗∈ 𝑜 ,𝑘∈[𝑛]

𝑦𝑗 𝑔

𝑗,𝑘𝑧𝑘 ∈ ℤ𝑞

ct size = 𝑃(𝑜 + 𝑛)

slide-9
SLIDE 9

Our work on FE

Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings 𝑛 = Ԧ 𝑦, Ԧ 𝑧 ∈ ℤ𝑞

𝑜 × ℤ𝑞 𝑛

𝑔 = 𝑔

𝑗,𝑘 𝑗∈ 𝑜 ,𝑘∈[𝑛] ∈ ℤ𝑞 𝑜×𝑛

𝑔 𝑛 = Ԧ 𝑦𝑈𝑔 Ԧ 𝑧 = ෍

𝑗∈ 𝑜 ,𝑘∈[𝑛]

𝑦𝑗 𝑔

𝑗,𝑘𝑧𝑘 ∈ ℤ𝑞

ct size = 𝑃(𝑜 + 𝑛) ct size = 𝑃(𝑜 ⋅ 𝑛) vs with [ABDP 15]

slide-10
SLIDE 10

In Independent works on FE

Quadratic: Private/public key: [AS 17] private [Lin 17] private Our work public Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings

slide-11
SLIDE 11

In Independent works on FE

Quadratic: Private/public key: [AS 17] private [Lin 17] private Our work public Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings Function- hiding:

slide-12
SLIDE 12

In Independent works on FE

Quadratic: Private/public key: [AS 17] private [Lin 17] private Our work public Our work public Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings Function- hiding: Assumption: GGM SXDH

  • SXDH & 3-PDDH
  • GGM
slide-13
SLIDE 13

In Independent works on FE

Quadratic: Private/public key: [AS 17] private [Lin 17] private Our work public Our work public Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings Function- hiding: Assumption: Security: GGM SEL-IND SXDH SEL-IND

  • SXDH & 3-PDDH

SEL-IND

  • GGM

AD-IND

slide-14
SLIDE 14

Application to Predicate Encry ryption

ct size = 𝑃(𝑜 + 𝑛) ct size = 𝑃(𝑜 ⋅ 𝑛) vs Our work: [KSW 08]: 𝑛 = plaintext, Ԧ 𝑦, Ԧ 𝑧 ∈ ℤ𝑞

𝑜 × ℤ𝑞 𝑛

𝑔 𝑛 = plaintext iff Ԧ 𝑦𝑈𝑔 Ԧ 𝑧 = 0

slide-15
SLIDE 15

FE for quadratic fu functions

Enc 𝑞𝑙, ( Ԧ 𝑦, Ԧ 𝑧) Enc(𝑞𝑙, Ԧ 𝑦) Enc(𝑞𝑙, Ԧ 𝑧) = , 𝑔 Enc(𝑞𝑙𝑔, 𝑔( Ԧ 𝑦, Ԧ 𝑧)) size 𝑃(𝑜) size 𝑃(𝑛) FE 𝑔: Ԧ 𝑦, Ԧ 𝑧 ∈ ℤ𝑞

𝑜 × ℤ𝑞 𝑛 → Ԧ

𝑦𝑈𝑔 Ԧ 𝑧 ∈ ℤ𝑞 in 𝔿𝑈 in 𝔿 𝑓: 𝔿 × 𝔿 → 𝔿𝑈 𝑓 𝑕𝑏, 𝑕𝑐 = 𝑓 𝑕, 𝑕 𝑏𝑐 in 𝔿

slide-16
SLIDE 16

Outline

Private-key FE, GGM

1

Public-key FE, GGM

2

Public-key FE, from standard assumptions

3

slide-17
SLIDE 17

Pri rivate-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑛𝑡𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑛𝑡𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2

slide-18
SLIDE 18

Pri rivate-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑛𝑡𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑛𝑡𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2 𝑦𝑗𝑧𝑘 + 𝑠

𝑗𝑡 𝑘 T

slide-19
SLIDE 19

Pri rivate-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑛𝑡𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑛𝑡𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2 𝑔( Ԧ 𝑦, Ԧ 𝑧) + 𝑔(Ԧ 𝑠, Ԧ 𝑡) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

= 𝑡𝑙𝑔

slide-20
SLIDE 20

Pri rivate-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑛𝑡𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑛𝑡𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2 𝑔( Ԧ 𝑦, Ԧ 𝑧) + 𝑔(Ԧ 𝑠, Ԧ 𝑡) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

= 𝑡𝑙𝑔 𝑡𝑙𝑔 = 𝑔 Ԧ 𝑠, Ԧ 𝑡

𝑈

slide-21
SLIDE 21

Pri rivate-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑛𝑡𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑛𝑡𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2 𝑔( Ԧ 𝑦, Ԧ 𝑧) + 𝑔(Ԧ 𝑠, Ԧ 𝑡) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

= 𝑡𝑙𝑔 𝑡𝑙𝑔 = 𝑔 Ԧ 𝑠, Ԧ 𝑡

𝑈

∀𝑔 ∈ Collusion

slide-22
SLIDE 22

Public-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑞𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2 𝑡𝑙𝑔 = 𝑔 Ԧ 𝑠, Ԧ 𝑡

𝑈

slide-23
SLIDE 23

Public-key FE, , GGM GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑞𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] for 𝑋 ←𝑆 𝐻𝑀2 𝑡𝑙𝑔 = 𝑔 Ԧ 𝑠, Ԧ 𝑡

slide-24
SLIDE 24

Public-key FE, , GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑞𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝜏𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛 , for 𝑋 ←𝑆 𝐻𝑀2, 𝜏 ←𝑆 ℤ𝑞 𝑡𝑙𝑔 = 𝑔 Ԧ 𝑠, Ԧ 𝑡 𝑔( Ԧ 𝑦, Ԧ 𝑧) + 𝜏𝑔(Ԧ 𝑠, Ԧ 𝑡) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

= 𝑓( 𝜏 , 𝑡𝑙𝑔) [𝜏]

slide-25
SLIDE 25

Public-key FE, , GGM

𝑓: 𝔿 × 𝔿 → 𝔿𝑈 of order 𝑞. 𝑏 = 𝑕𝑏 𝑞𝑙 = 𝑠

𝑗 , 𝑡 𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ [𝑛] 𝐹𝑜𝑑(𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 ) = 𝑦𝑗, 𝜏𝑠

𝑗 𝑋 , 𝑋−1 𝑧𝑘

𝑡

𝑘

for 𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛 , for 𝑋 ←𝑆 𝐻𝑀2, 𝜏 ←𝑆 ℤ𝑞 𝑡𝑙𝑔 = 𝑔 Ԧ 𝑠, Ԧ 𝑡 𝑔( Ԧ 𝑦, Ԧ 𝑧) + 𝜏𝑔(Ԧ 𝑠, Ԧ 𝑡) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

= 𝑓( 𝜏 , 𝑡𝑙𝑔) [𝜏] ∀𝑔 ∈ Collusion

slide-26
SLIDE 26

Public-key FE, , standard

𝑠

𝑗 , 𝑡 𝑘 ⇒ (Ԧ

𝑠

𝑗 𝑈, 0 𝑊], 𝑊−1

Ԧ 𝑡

𝑘

𝑡𝑙𝑔 = ෍

𝑗,𝑘

𝑔

𝑗,𝑘𝑠 𝑗𝑡 𝑘 ⇒ ෍ 𝑗,𝑘

𝑔

𝑗,𝑘 Ԧ

𝑠

𝑗 𝑈 Ԧ

𝑡

𝑘

DPVS [OT 08]

slide-27
SLIDE 27

Public-key FE, , standard

𝑠

𝑗 , 𝑡 𝑘 ⇒ (Ԧ

𝑠

𝑗 𝑈, 𝑦𝑗 𝑊], 𝑊−1

Ԧ 𝑡𝑘 𝑧𝑘 𝑡𝑙𝑔 = ෍

𝑗,𝑘

𝑔

𝑗,𝑘𝑠 𝑗𝑡 𝑘 ⇒ ෍ 𝑗,𝑘

𝑔

𝑗,𝑘 Ԧ

𝑠

𝑗 𝑈 Ԧ

𝑡

𝑘 + 𝑔( Ԧ

𝑦, Ԧ 𝑧) DPVS [OT 08] DLIN assumption

slide-28
SLIDE 28

Public-key FE, , standard

𝑞𝑙 = (Ԧ 𝑠

𝑗 𝑈, 0 𝑊], 𝑊−1

Ԧ 𝑡

𝑘

𝐹𝑜𝑑 𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 = 𝑦𝑗, 𝜏(Ԧ 𝑠

𝑗 𝑈, 0) 𝑋 , 𝑋−1

𝑧𝑘 Ԧ 𝑡𝑘 , for 𝑋 ←𝑆 𝐻𝑀4, 𝜏 ←𝑆 ℤ𝑞

∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛 ∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛

𝑡𝑙𝑔 = ෍

𝑗,𝑘

𝑔

𝑗,𝑘 Ԧ

𝑠

𝑗 𝑈 Ԧ

𝑡

𝑘

[𝜏]

slide-29
SLIDE 29

Public-key FE, , standard

𝑞𝑙 = (Ԧ 𝑠

𝑗 𝑈, 0 𝑊], 𝑊−1

Ԧ 𝑡

𝑘

𝐹𝑜𝑑 𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 = 𝑦𝑗, 𝜏(Ԧ 𝑠

𝑗 𝑈, 0) 𝑋 , 𝑋−1

𝑧𝑘 Ԧ 𝑡𝑘 , for 𝑋 ←𝑆 𝐻𝑀4, 𝜏 ←𝑆 ℤ𝑞 𝑔 Ԧ 𝑦, Ԧ 𝑧 + 𝜏𝑡𝑙𝑔) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛 ∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛

𝑡𝑙𝑔 = ෍

𝑗,𝑘

𝑔

𝑗,𝑘 Ԧ

𝑠

𝑗 𝑈 Ԧ

𝑡

𝑘

[𝜏]

slide-30
SLIDE 30

Public-key FE, , standard

𝑞𝑙 = (Ԧ 𝑠

𝑗 𝑈, 0 𝑊], 𝑊−1

Ԧ 𝑡

𝑘

𝐹𝑜𝑑 𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 = 𝑦𝑗, 𝜏(Ԧ 𝑠

𝑗 𝑈, 0) 𝑋 , 𝑋−1

𝑧𝑘 Ԧ 𝑡𝑘 , for 𝑋 ←𝑆 𝐻𝑀4, 𝜏 ←𝑆 ℤ𝑞

∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛 ∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛

𝑔 Ԧ 𝑦, Ԧ 𝑧 + 𝜏𝑡𝑙𝑔) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

𝑡𝑙𝑔 = ෍

𝑗,𝑘

𝑔

𝑗,𝑘 Ԧ

𝑠

𝑗 𝑈 Ԧ

𝑡

𝑘

[𝜏] ∀𝑔 ∈ Collusion

slide-31
SLIDE 31

Public-key FE, , standard

𝑞𝑙 = (Ԧ 𝑠

𝑗 𝑈, 0 𝑊], 𝑊−1

Ԧ 𝑡

𝑘

𝐹𝑜𝑑 𝑞𝑙, Ԧ 𝑦, Ԧ 𝑧 = 𝑦𝑗, 𝜏(Ԧ 𝑠

𝑗 𝑈, 0) 𝑋 , 𝑋−1

𝑧𝑘 Ԧ 𝑡𝑘 , for 𝑋 ←𝑆 𝐻𝑀4, 𝜏 ←𝑆 ℤ𝑞

∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛 ∀𝑗 ∈ 𝑜 , 𝑘 ∈ 𝑛

𝑔 Ԧ 𝑦, Ԧ 𝑧 + 𝜏𝑡𝑙𝑔) T ∀𝑔 ∈ ℤ𝑞

𝑜×𝑛

𝑡𝑙𝑔 = ෍

𝑗,𝑘

𝑔

𝑗,𝑘 Ԧ

𝑠

𝑗 𝑈 Ԧ

𝑡

𝑘

[𝜏] ∀𝑔 ∈ Collusion DLIN assumption

slide-32
SLIDE 32

Conclusion

Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings 𝑛 = Ԧ 𝑦, Ԧ 𝑧 ∈ ℤ𝑞

𝑜 × ℤ𝑞 𝑛

𝑔 = 𝑔

𝑗,𝑘 𝑗∈ 𝑜 ,𝑘∈[𝑛] ∈ ℤ𝑞 𝑜×𝑛

𝑔 𝑛 = Ԧ 𝑦𝑈𝑔 Ԧ 𝑧 ct size = 𝑃(𝑜 + 𝑛)

slide-33
SLIDE 33

Conclusion

Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings Quadratic: Assumption: Security: ct size: Our work SXDH & 3-PDDH SEL-IND 6 𝑜 + 𝑛 + 2 Our work GGM AD-IND 2 𝑜 + 𝑛 + 2

slide-34
SLIDE 34

Conclusion

Construction: Functions: Assumption: [GGHRSW 13,…] any circuit iO [ABDP 15] inner product DDH Our work quadratic pairings Open More expressive? standard