We study certified everlasting secure functional encryption (FE) and many other cryptographic primitives in this work. Certified everlasting security roughly means the following. A receiver possessing a quantum cryptographic object can issue a certificate showing that the receiver has deleted the cryptographic object and information included in the object was lost. If the certificate is valid, the security is guaranteed even if the receiver becomes computationally unbounded after the deletion. Many cryptographic primitives are known to be impossible (or unlikely) to have information-theoretical security even in the quantum world. Hence, certified everlasting security is a nice compromise (intrinsic to quantum). In this work, we define certified everlasting secure versions of FE, compute-and-compare obfuscation, predicate encryption (PE), secret-key encryption (SKE), public-key encryption (PKE), receiver non-committing encryption (RNCE), and garbled circuits. We also present the following constructions: - Adaptively certified everlasting secure collusion-resistant public-key FE for all polynomial-size circuits from indistinguishability obfuscation and one-way functions. - Adaptively certified everlasting secure bounded collusion-resistant public-key FE for NC1 circuits from standard PKE. - Certified everlasting secure compute-and-compare obfuscation from standard fully homomorphic encryption and standard compute-and-compare obfuscation - Adaptively (resp., selectively) certified everlasting secure PE from standard adaptively (resp., selectively) secure attribute-based encryption and certified everlasting secure compute-and-compare obfuscation. - Certified everlasting secure SKE and PKE from standard SKE and PKE, respectively. - Certified everlasting secure RNCE from standard PKE. - Certified everlasting secure garbled circuits from standard SKE.
翻译:我们研究可认证永久安全功能加密(FE)及其他多种密码原语。可认证永久安全大致含义如下:持有量子密码对象的接收者可签发证书证明其已删除该密码对象,且对象所含信息已丢失。若证书有效,即使接收者在删除后具有无限计算能力,安全性仍能得到保障。许多密码原语在量子世界中已知不可能(或不太可能)具备信息论安全性,因此可认证永久安全是量子特有的良好折衷方案。在本工作中,我们定义了FE、计算与对比混淆、谓词加密(PE)、对称密钥加密(SKE)、公钥加密(PKE)、接收者非承诺加密(RNCE)及混淆电路的可认证永久安全版本。我们还给出以下构造:- 基于不可区分混淆和单向函数,针对所有多项式规模电路的适应性可认证永久安全抗合谋公钥FE。- 基于标准PKE,针对NC1电路的适应性可认证永久安全有界抗合谋公钥FE。- 基于标准全同态加密和标准计算与对比混淆的可认证永久安全计算与对比混淆。- 基于标准适应性(或选择性)安全属性基加密和可认证永久安全计算与对比混淆的适应性(或选择性)可认证永久安全PE。- 分别基于标准SKE和PKE的可认证永久安全SKE和PKE。- 基于标准PKE的可认证永久安全RNCE。- 基于标准SKE的可认证永久安全混淆电路。