Paper 2026/1464

Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices

Jeffrey Champion, The University of Texas at Austin
David J. Wu, The University of Texas at Austin
Abstract

Distributed cryptography is a new cryptographic paradigm that enables fine-grained decryption capabilities in a trustless setting. In a distributed monotone-policy encryption scheme, users generate their own public and private keys. Thereafter, one can encrypt a message with respect to an arbitrary set of public keys together with an access policy. Any group of users that satisfies the access policy can recover the message; conversely, the message is computationally hidden from any group of users that does not satisfy the policy. The key requirement is succinctness: the size of the ciphertext should be sublinear in the size of the access policy. Distributed monotone-policy encryption generalizes related notions like distributed broadcast encryption (where the access policy is set membership) and silent threshold encryption (where the access policy is a threshold policy). In this work, we achieve the following: - First, we give the first optimal distributed monotone-policy encryption scheme for the class of DNF policies from the decomposed LWE assumption in the random oracle model. Here, optimal means that the size of the public parameters, the user public keys, and the size of the ciphertext are independent of the size of the policy. As a corollary, we also obtain a (reusable) succinct computational secret sharing scheme for DNFs from decomposed LWE in the random oracle model. - Next, we show how to adapt our techniques to obtain a distributed monotone-policy encryption scheme for $k$-DNFs in the plain model where the size of the ciphertext is $k \cdot L^{1/2}$, $k$ is the maximum size of each min-term, and $L$ is the number of min-terms in the DNF. This is the first scheme from the decomposed LWE assumption in the plain model. If we settle for a much weaker notion of selective security, then we also achieve full succinctness in the plain model (i.e., where the ciphertext size is independent of the size of the DNF). - By specializing our results to the setting of broadcast encryption, we obtain an adaptively-secure distributed broadcast encryption scheme with ciphertext size $|S|^{2/3}$, where $|S|$ is the size of the broadcast set. Security relies on decomposed LWE (with a polynomial modulus-to-noise ratio) in the plain model. This scheme is the first lattice-based scheme with adaptive security that supports an a priori unbounded number of users in the plain model. Previous lattice-based distributed broadcast encryption schemes with adaptive security in the plain model assumed an a priori bound on the number of users (but achieved optimal-size ciphertexts that are independent of the size of the broadcast set).

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
latticesdecomposed LWEsuccinct LWEsilent setupthreshold encryption
Contact author(s)
jchampion @ utexas edu
dwu4 @ cs utexas edu
History
2026-07-21: approved
2026-07-17: received
See all versions
Short URL
https://ia.cr/2026/1464
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1464,
      author = {Jeffrey Champion and David J. Wu},
      title = {Optimal Distributed Monotone-Policy Encryption for {DNFs} and More from Lattices},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1464},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1464}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.