Paper 2025/407

Adaptively Secure Hierarchical Attribute-Based Encryption from Witness Encryption

Rishab Goyal, University of Wisconsin-Madison
Saikumar Yadugiri, University of Wisconsin-Madison
Abstract

Hierarchical attribute-based encryption (HABE), also called delegatable ABE, augments ABE with a public delegation algorithm that lets any user holding a secret key for a predicate $f$ locally derive a key for a more restrictive predicate $f \land g$. Since keys are no longer produced only by the master authority, an attacker may adaptively corrupt keys generated by honest users, which makes security far more delicate than for plain ABE. For general predicates, HABE was previously known in the standard model only with selective security from lattices, where the number of delegations had to be bounded a-priori and secret key size grew quadratically with it, or from obfuscation-flavored assumptions. Beyond identity-based predicates no construction achieved adaptive security without complexity leveraging. We revisit HABE through the lens of witness encryption (WE) and achieve the following. 1. A $\textbf{selectively-secure}$ HABE scheme for all polynomial-size predicates from witness encryption, statistically-sound NIZKs, and statistically-binding commitments, supporting an $\textit{unbounded}$ number of key delegations with secret key size growing only $\textit{linearly}$ with each delegation. 2. An $\textbf{adaptively-secure}$ HABE scheme for the same class, again supporting an $\textit{unbounded}$ number of key delegations, assuming in addition equivocal commitments and a mixed hierarchical functional encryption scheme, a new primitive that we introduce. Our constructions are in the standard model, avoid random oracles, complexity leveraging, and reduce black box to the polynomial hardness of the underlying primitives. On the technical front, we extend the witness encryption based ABE template of [Garg-Gentry-Sahai-Waters; STOC'13] to support public delegation. Encoding a delegated key as a proof that verifies its parent's proof makes proof size grow exponentially with the depth of the hierarchy, capping delegations at $O(1)$. So, we instead $\textit{chain}$ proofs rather than compose them. Adaptive security then calls for a genuinely hierarchical form of the dual-systems methodology, which is what mixed hierarchical functional encryption abstracts.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Attribute-Based EncryptionWitness EncryptionKey Delegation
Contact author(s)
rishab @ cs wisc edu
saikumar @ cs wisc edu
History
2026-08-31: last of 4 revisions
2025-03-03: received
See all versions
Short URL
https://ia.cr/2025/407
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/407,
      author = {Rishab Goyal and Saikumar Yadugiri},
      title = {Adaptively Secure Hierarchical Attribute-Based Encryption from Witness Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/407},
      year = {2025},
      url = {https://eprint.iacr.org/2025/407}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.