Paper 2026/1076

Decentralizing Traitor Tracing: A Multi-Authority Approach

Rishab Goyal, University of Wisconsin-Madison
Alex Snyder, University of Wisconsin-Madison
Saikumar Yadugiri, University of Wisconsin-Madison
Abstract

Traitor tracing [Chor-Fiat-Naor; CRYPTO'94] has historically been formalized through the lens of a $\textit{single}$ trusted authority that samples the master keys and that, therefore, can read every ciphertext on its own. This $\textit{key escrow}$ problem makes traditional traitor tracing fundamentally incompatible with end-to-end encrypted broadcast networks. In this work, we study introduce $\textit{multi-authority traitor tracing}$ (MA-TT) [Goyal-Yadugiri; ePrint] a new decentralized model for traitor tracing in which the setup is split across $K$ asynchronous and non-interacting authorities, and a user can decrypt only by combining partial keys from $\textit{every}$ authority. We require that semantic security holds even when an arbitrary set of authorities is corrupted (as long as some honest partial key remains hidden for every user), and that traceability never accuses a user for whom an honest partial key remains hidden. We design MA-TT by combining any multi-authority attribute-based encryption (MA-ABE) scheme with a new primitive that we introduce, distributed mixed functional encryption (DMFE), a careful decentralization of the mixed functional encryption notion [Goyal-Koppula-Waters; STOC'18]. We construct DMFE from LWE via single-key key-homomorphic private constrained PRFs. Plugging in known MA-ABE schemes, we obtain MA-TT from LWE plus pairings with ciphertext size $K \cdot \mathsf{poly}(\lambda, \log N)$. As feasibility, we also give MA-TT from any PKE (with ciphertexts of size $K \cdot N \cdot \mathsf{poly}(\lambda)$) and from any multi-authority functional encryption (with fully succinct parameters).

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Traitor TracingMulti-Autority
Contact author(s)
rishab @ cs wisc edu
ajsnyder7 @ wisc edu
saikumar @ cs wisc edu
History
2026-05-31: approved
2026-05-28: received
See all versions
Short URL
https://ia.cr/2026/1076
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1076,
      author = {Rishab Goyal and Alex Snyder and Saikumar Yadugiri},
      title = {Decentralizing Traitor Tracing: A Multi-Authority Approach},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1076},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1076}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.