Paper 2025/407
Adaptively Secure Hierarchical Attribute-Based Encryption from Witness Encryption
Abstract
Hierarchical attribute-based encryption (HABE), also called delegatable ABE, augments ABE with a public delegation algorithm that lets any user holding a secret key for a predicate $f$ locally derive a key for a more restrictive predicate $f \land g$. Since keys are no longer produced only by the master authority, an attacker may adaptively corrupt keys generated by honest users, which makes security far more delicate than for plain ABE. For general predicates, HABE was previously known in the standard model only with selective security from lattices, where the number of delegations had to be bounded a-priori and secret key size grew quadratically with it, or from obfuscation-flavored assumptions. Beyond identity-based predicates no construction achieved adaptive security without complexity leveraging. We revisit HABE through the lens of witness encryption (WE) and achieve the following. 1. A $\textbf{selectively-secure}$ HABE scheme for all polynomial-size predicates from witness encryption, statistically-sound NIZKs, and statistically-binding commitments, supporting an $\textit{unbounded}$ number of key delegations with secret key size growing only $\textit{linearly}$ with each delegation. 2. An $\textbf{adaptively-secure}$ HABE scheme for the same class, again supporting an $\textit{unbounded}$ number of key delegations, assuming in addition equivocal commitments and a mixed hierarchical functional encryption scheme, a new primitive that we introduce. Our constructions are in the standard model, avoid random oracles, complexity leveraging, and reduce black box to the polynomial hardness of the underlying primitives. On the technical front, we extend the witness encryption based ABE template of [Garg-Gentry-Sahai-Waters; STOC'13] to support public delegation. Encoding a delegated key as a proof that verifies its parent's proof makes proof size grow exponentially with the depth of the hierarchy, capping delegations at $O(1)$. So, we instead $\textit{chain}$ proofs rather than compose them. Adaptive security then calls for a genuinely hierarchical form of the dual-systems methodology, which is what mixed hierarchical functional encryption abstracts.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Attribute-Based EncryptionWitness EncryptionKey Delegation
- Contact author(s)
-
rishab @ cs wisc edu
saikumar @ cs wisc edu - History
- 2026-08-31: last of 4 revisions
- 2025-03-03: received
- See all versions
- Short URL
- https://ia.cr/2025/407
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/407,
author = {Rishab Goyal and Saikumar Yadugiri},
title = {Adaptively Secure Hierarchical Attribute-Based Encryption from Witness Encryption},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/407},
year = {2025},
url = {https://eprint.iacr.org/2025/407}
}