Paper 2011/463

Decentralized Dynamic Broadcast Encryption

Duong Hieu Phan, David Pointcheval, and Mario Strefler


A broadcast encryption system generally involves three kinds of entities: the group manager that deals with the membership, the encryptor that encrypts the data to the registered users according to a specific policy (the target set), and the users that decrypt the data if they are authorized by the policy. Public-key broadcast encryption can be seen as removing this special role of encryptor, by allowing anybody to send encrypted data. In this paper, we go a step further in the decentralization process, by removing the group manager: the initial setup of the group, as well as the addition of further members to the system, do not require any central authority. Our construction makes black-box use of well-known primitives and can be considered as an extension to the subset-cover framework. It allows for efficient concrete instantiations, with parameter sizes that match those of the subset-cover constructions, while at the same time achieving the highest security level in the standard model under the DDH assumption.

Published elsewhere. An extended abstract appeared at SCN 2012.
Dynamic Broadcast EncryptionAdaptive SecurityCCA2Standard Model
strefler @ di ens fr
2012-09-03: revised
2011-08-29: received
Creative Commons Attribution


