Paper 2004/258

Escrow-Free Encryption Supporting Cryptographic Workflow

S. S. Al-Riyami, J. Malone-Lee, and N. P. Smart


Since Boneh and Franklin published their seminal paper on identity based encryption (IBE) using the Weil pairing , there has been a great deal of interest in cryptographic primitives based on elliptic-curve pairings. One particularly interesting application has been to control access to data, via possibly complex policies. In this paper we continue the research in this vein. We present an encryption scheme such that the receiver of an encrypted message can only decrypt if it satisfies a particular policy chosen by the sender at the time of encryption. Unlike standard IBE, our encryption scheme is escrow free in that no key-issuing authority (or colluding set of key-issuing authorities) is able to decrypt ciphertexts itself. In addition we describe a security model for the scenario in question and provide proofs of security for our scheme (in the random oracle model).

Available format(s)
Cryptographic protocols
Publication info
Published elsewhere. Unknown where it was published
Contact author(s)
nigel @ cs bris ac uk
2005-05-05: last of 2 revisions
2004-10-08: received
See all versions
Short URL
Creative Commons Attribution


      author = {S. S.  Al-Riyami and J.  Malone-Lee and N. P.  Smart},
      title = {Escrow-Free Encryption Supporting Cryptographic Workflow},
      howpublished = {Cryptology ePrint Archive, Paper 2004/258},
      year = {2004},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.