Reduced-size ciphertext compatible with pre-existing attribute-based encryption schemes

By employing a low-norm gadget trapdoor and LWE matrices, the ciphertext size in ABE schemes is reduced, addressing efficiency challenges and optimizing storage and computational resources while maintaining security compatibility with existing ABE systems.

WO2025212723A1PCT designated stage Publication Date: 2025-10-09NTT RESEARCH INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/022656
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-02
Filing Date
2025-04-02
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

The large ciphertext size in attribute-based encryption (ABE) schemes, particularly with complex access policies and a large number of attributes, poses challenges in terms of storage overhead, transmission bandwidth, and computational resources, necessitating more efficient methods to manage and optimize ciphertext size.

Method used

A method and system that utilize a low-norm gadget trapdoor and attribute bits to compress ciphertexts in ABE schemes, reducing their size by a factor of L while maintaining security, and expand them to be compatible with pre-existing ABE schemes, using learning with errors (LWE) matrices and lattice-based assumptions.

Benefits of technology

The proposed method achieves ciphertexts that are significantly smaller than traditional ABE schemes, optimizing storage and computational resources while maintaining security, and is compatible with existing ABE systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025022656_09102025_PF_FP_ABST
    Figure US2025022656_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a method for creating a ciphertext having a relatively smaller size that is compatible with pre-existing attribute-based encryption (ABE) schemes. The method includes receiving a plaintext message and ABE attributes, executing a set-up procedure to generate a master public-private key pair, and executing an encryption procedure. The set-up procedure involves sampling random learning with errors (LWE) matrices, establishing a gadget trapdoor, and computing matrices for the master public key. The encryption procedure generates the ciphertext from an LWE sample for a concatenation of matrices based on the ABE attributes. The method further includes storing the ciphertext and transmitting it to a recipient device over a communication network. The ciphertext has a reduced size compared to ciphertexts generated by pre-existing ABE schemes while maintaining compatibility.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]REDUCED-SIZE CIPHERTEXT COMPATIBLE WITH PRE-EXISTINGATTRIBUTE-BASED ENCRYPTION SCHEMESCROSS-REFERENCE TO RELATED APPLICATIONThis application claims the benefit of U.S. Provisional Application Ser. No. 63 / 573,234filed April 2, 2024, the content of which is incorporated by reference herein in its entirety.FIELD OF THE INVENTIONThe present invention relates to the field of cryptography and, more specifically, to attribute-based encryption (ABE) and the reduction of ciphertext size in ABE schemes.BACKGROUND OF THE INVENTIONAttribute-based encryption is a cryptographic paradigm that enables fine-grained accesscontrol over encrypted data. In ABE, the encryption and decryption processes are basedon attributes associated with the data and the users. The access policy, which specifies theconditions under which decryption is allowed, is embedded within the ciphertext itself. Thisallows for more flexible and expressive access control compared to traditional public-keyencryption schemes.In ABE, the size of the ciphertext is a critical factor that influences the efficiency andpracticality of the scheme. The ciphertext size directly impacts the storage overhead, trans-mission bandwidth, and computational resources required for encryption and decryptionoperations. Therefore, it is essential to understand how the ciphertext size is determined inABE schemes.Conventionally, the ciphertext size in ABE is influenced by several factors. One of the pri-mary factors is the complexity of the access policy. The access policy is typically representedas a boolean formula or a tree-like structure, where the leaf nodes represent the attributesand the internal nodes represent the logical operations (e.g., AND, OR). The number of at-tributes involved in the access policy and the depth of the policy tree directly contribute tothe size of the ciphertext. More complex access policies with a larger number of attributesand deeper policy trees result in larger ciphertexts.Another factor that impacts the ciphertext size is the way attributes are representedand encoded in the ciphertext. Attributes can be represented as binary strings, integers, ormore complex data types, depending on the specific ABE scheme. The length and encodingscheme of the attributes affect the overall ciphertext size. Larger attribute representationsor more complex encoding schemes lead to increased ciphertext size.The choice of the ABE scheme itself also influences the ciphertext size. Different ABEschemes, such as Key-Policy ABE (KP-ABE) and Ciphertext-Policy ABE (CP-ABE), may havedifferent ciphertext size characteristics due to their underlying mathematical constructionsand cryptographic primitives. The security parameters used in the ABE scheme, such as thesize of the cryptographic groups or the length of the keys, also contribute to the ciphertextsize. Higher security levels typically require larger security parameters, resulting in increasedciphertext size.Various optimization techniques have been proposed in the prior art to reduce the ci-phertext size in ABE. These techniques may involve efficient attribute encoding, policy op-timization, or the use of specialized cryptographic primitives. However, the effectiveness ofthese optimizations depends on the specific ABE scheme and the application scenario.Despite the advancements in ABE, the ciphertext size remains a challenging issue, par-ticularly when dealing with complex access policies and a large number of attributes. Theincreased ciphertext size compared to traditional public-key encryption schemes is a trade-off for the enhanced access control and fine-grained security properties provided by ABE.In light of the above, there is a need for efficient methods and systems that can effectivelymanage and optimize the ciphertext size in attribute-based encryption schemes.BRIEF SUMMARY OF THE INVENTIONThis summary is provided to introduce a selection of concepts in a simplified form thatare further described below in the detailed description. This summary is not intended toidentify key features or essential features of the claimed subject matter, nor is it intended tobe used as an aid in determining the scope of the claimed subject matter.In this work, we study attribute-based encryption and laconic function evaluation, twofundamental primitives in the study of computing on encrypted data:(a) In attribute-based encryption (ABE), ciphertexts ct are associated with an attribute x ∈{0,1}ℓ and a message µ and keys sk with a predicate f , and decryption returns µ whenx satisfies f (i.e, f (x) = 0). We require security against unbounded collusions, so thatan adversary that sees a ciphertext along with secret keys for an arbitrary number ofpredicates learns nothing about µ as long as x satisfies none of these predicates.(b) In laconic function evaluation (LFE), a server publishes a short digest dig to a functionf . Anyone can use dig to efficiently encrypt an input x ∈ {0,1}ℓ. Given f , the ciphertextct can then be decrypted to recover f (x), but hides everything else about x.In 2014, Boneh, Gentry, Gorbunov, Halevi, Nikolaenko, Segev, Vaikuntanathan, and Vinayaga-murthy, henceforth BGGHNSVV, constructed an ABE scheme for circuits with small keysfrom LWE. For depth d , size s circuits over ℓ-bit inputs where ℓ and d are fixed at set-up, thescheme achieves|mpk| = ℓ ·poly(d ,λ), |ct| = ℓ ·poly(d ,λ), |sk| = poly(d ,λ).Building on this work, Quach, Wee and Wichs, QWW for short, constructed an LFE schemefor circuits achieving digest size poly(d ,λ) and ciphertext size and encryption timeℓ·poly(d ,λ).These results remain the state of the art for ABE and LFE from LWE for shallow circuits ofdepth d = ℓo(1) (e.g. NC1 circuits), apart from trading off small secret keys for small publickeys for ABE.Some limited improvements are known if we allow non-standard lattice assumptions,most notably evasive LWE, a non-falsifiable lattice assumption which says that given a LWEchallenge (B,sB+e), getting an additional Gaussian pre-image B−1(P) is no more useful thangetting the product (sB+e) ·B−1(P) ≈ sP+e′. The state of the art for ABE and LFE from non-standard lattice assumptions is as follows:(a) For ABE, all known schemes with |sk| = poly(d ,λ) require |ct| =Ω(ℓ) and |mpk| =Ω(ℓ).Similarly for LFE with small digest, the best known ciphertext size is ℓ ·poly(λ).(b) Furthermore, if we require falsifiable and instance-independent lattice assumptions,then we do not know substantial improvements beyond what is already known fromLWE. According to an aspect of the present disclosure, a method for creating a ciphertext hav-ing a relatively smaller size that is compatible with pre-existing attribute-based encryption(ABE) schemes is provided. The method includes receiving, by a first processor, a plain-text message and ABE attributes in a computerized media. The method also includes stor-ing, by the first processor, the plaintext message and the ABE attributes in a non-transitorycomputer-readable storage medium. The method further includes executing, by a secondprocessor, a set-up procedure to generate a master public-private key pair. The set-up pro-cedure includes sampling a random learning with errors (LWE) matrix B and a correlatedgadget trapdoor for B , wherein the LWE matrix B is a matrix for security parameters n,m, and modulus q . The set-up procedure also includes sampling L random LWE matricesW1, ...,WL , sampling a random LWE matrix B1, establishing a gadget trapdoor T for a matrixrelated to B ,W1, ... ,WL , and computing L matrices A1, ... , AL by right-multiplying B1 by asubmatrix of T . The set-up procedure further includes outputting the master public key, themaster public key comprising B ,B1,T,W1, ..,WL , A1, ... , AL , wherein A1, ... , AL is a masterpublic key from the pre-existing ABE scheme, and storing the master public key in the non-transitory computer-readable storage medium, wherein the master private key is the gadgettrapdoor for B . The method also includes executing, by the first processor, an encryptionprocedure. The encryption procedure includes receiving L bits x1, ... , xL corresponding tothe ABE attributes, wherein each bit is either 0 or 1, generating the ciphertext from anLWE sample c for a concatenation of B and B1 + x1 ·W1 + ... + xL ·WL , and encrypting theplaintext message using the ciphertext and a symmetric encryption key derived from theLWE sample. The method further includes storing, by the first processor, the ciphertext inthe non-transitory computer-readable storage medium, and transmitting, by a network in-terface device communicatively coupled to the first processor, the ciphertext to a recipientdevice over a communication network.According to other aspects of the present disclosure, the method may include one ormore of the following features. The ciphertext may have a size that is reduced by a factorof L compared to a ciphertext generated according to the pre-existing scheme. The methodmay further include expanding the ciphertext into a form compatible with the pre-existingABE scheme by right-multiplying c by a low-norm matrix derived from the gadget trap-door T and the attribute bits x1, ..., xL , wherein the expanded ciphertext compatible with thepre-existing ABE scheme may comprise an LWE sample matrix obtained by concatenatingA1 − x1 ·G , ... , AL − xL ·G , wherein G is a gadget matrix, and storing the expanded cipher-text in a non-transitory computer-readable storage medium. The expanded ciphertext mayhave a size that is increased by a factor of L compared to the ABE ciphertext prior to ex-pansion. The security parameters n and m may be selected based on a desired security leveland computational efficiency, with m being at least twice the value of n log q . The modulus qmay be selected to be sufficiently large to accommodate the noise growth during encryptionand decryption operations while maintaining security against known lattice-based attacks.The gadget trapdoor T may be constructed using a randomized algorithm that ensures thetrapdoor has a low norm, facilitating efficient preimage sampling operations during the en-cryption and key generation procedures. The gadget trapdoor T may be a low-norm matrixthat enables efficient preimage sampling and satisfies the relation [IL ⊗B |W ] ·T = IL ⊗G ,where IL is the L ×L identity matrix, ⊗ denotes the tensor product, W is the concatenationof matrices W1, ...,WL , and G is a gadget matrix in Zn×mq with a public, fixed structure thatenables efficient decomposition operations.According to another aspect of the present disclosure, a system for creating a cipher-text having a relatively smaller size that is compatible with pre-existing attribute-based en-cryption (ABE) schemes is provided. The system includes a first processor, a non-transitorycomputer-readable storage medium, a second processor, and a network interface devicecommunicatively coupled to the first processor. The first processor is configured to receivea plaintext message and ABE attributes in a computerized media, and store the plaintextmessage and the ABE attributes in the non-transitory computer-readable storage medium.The second processor is configured to execute a set-up procedure to generate a masterpublic-private key pair. The set-up procedure includes sampling a random learning witherrors (LWE) matrix B and a correlated gadget trapdoor for B , wherein the LWE matrix Bis a matrix for security parameters n, m, and modulus q , sampling L random LWE ma-trices W1, ...,WL , sampling a random LWE matrix B1, establishing a gadget trapdoor T fora matrix related to B ,W1, ... ,WL , computing L matrices A1, ... , AL by right-multiplying B1by a submatrix of T , outputting the master public key, the master public key comprisingB ,B1,T,W1, ..,WL , A1, ... , AL , wherein A1, ... , AL is a master public key from the pre-existingABE scheme, and storing the master public key in the non-transitory computer-readablestorage medium, wherein the master private key is the gadget trapdoor for B . The first pro-cessor is further configured to execute an encryption procedure, which includes receivingL bits corresponding to the ABE attributes, wherein each bit xi is either 0 or 1,generating the ciphertext from an LWE sample c for a concatenation of B and + x1 ·W1 +... +xL ·WL , and encrypting the plaintext message using the ciphertext and a symmetric en-cryption key derived from the LWE sample. The first processor is also configured to store theciphertext in the non-transitory computer-readable storage medium. The network interfacedevice is configured to transmit the ciphertext to a recipient device over a communicationnetwork. According to other aspects of the present disclosure, the system may include one or moreof the following features. The ciphertext may have a size that is reduced by a factor of Lcompared to a ciphertext generated according to the pre-existing scheme. The first proces-sor may be further configured to expand the ciphertext into a form compatible with thepre-existing ABE scheme by right-multiplying c by a low-norm matrix derived from the gad-get trapdoor T and the attribute bits x1, ..., xL , wherein the expanded ciphertext compatiblewith the pre-existing ABE scheme may comprise an LWE sample matrix obtained by con-catenating A1 − x1 ·G , ... , AL − xL ·G , wherein G is a gadget matrix, and the non-transitorycomputer-readable storage medium may be configured to store the expanded ciphertext.The expanded ciphertext may have a size that is increased by a factor of L compared tothe ABE ciphertext prior to expansion. The security parameters n and m may be selectedbased on a desired security level and computational efficiency, with m being at least twicethe value of n log q . The modulus q may be selected to be sufficiently large to accommodatethe noise growth during encryption and decryption operations while maintaining securityagainst known lattice-based attacks. The gadget trapdoor T may be constructed using a ran-domized algorithm that ensures the trapdoor has a low norm, facilitating efficient preimagesampling operations during the encryption and key generation procedures. The gadget trap-door T may be a low-norm matrix that enables efficient preimage sampling and satisfies therelation [IL ⊗B |W ] ·T = IL ⊗G , where IL is the L ×L identity matrix, ⊗ denotes the tensorproduct, W is the concatenation of matrices W1, ...,WL , and G is a gadget matrix in Zn×mqwith a public, fixed structure that enables efficient decomposition operations.According to another aspect of the present disclosure, a non-transitory computer-readablestorage medium storing instructions that, when executed by one or more processors, causethe one or more processors to perform a method for creating a ciphertext having a rel-atively smaller size that is compatible with pre-existing attribute-based encryption (ABE)schemes is provided. The method includes receiving a plaintext message and ABE attributesin a computerized media, storing the plaintext message and the ABE attributes in a non-transitory computer-readable storage medium, executing a set-up procedure to generate amaster public-private key pair, executing an encryption procedure, storing the ciphertextin the non-transitory computer-readable storage medium, and transmitting the ciphertextto a recipient device over a communication network. The set-up procedure and encryptionprocedure include the same steps as described in the method aspect.According to other aspects of the present disclosure, the non-transitory computer-readablestorage medium may include one or more of the following features. The ciphertext may havea size that is reduced by a factor of L compared to a ciphertext generated according to thepre-existing scheme. The method may further include expanding the ciphertext into a formcompatible with the pre-existing ABE scheme by right-multiplying c by a low-norm matrixderived from the gadget trapdoor T and the attribute bits x1, ..., xL , wherein the expanded ci-phertext compatible with the pre-existing ABE scheme may comprise an LWE sample matrixobtained by concatenating A1−x1 ·G , ... , AL −xL ·G , wherein G is a gadget matrix, and stor-ing the expanded ciphertext in a non-transitory computer-readable storage medium. Thegadget trapdoor T may be a low-norm matrix that enables efficient preimage sampling andsatisfies the relation [IL ⊗B |W ] ·T = IL ⊗G , where IL is the L ×L identity matrix, ⊗ denotesthe tensor product, W is the concatenation of matrices , and G is a gadget matrixin Zn×mq with a public, fixed structure that enables efficient decomposition operations.The foregoing general description of the illustrative embodiments and the following de-tailed description thereof are merely exemplary aspects of the teachings of this disclosureand are not restrictive.BRIEF DESCRIPTION OF THE DRAWINGSNon-limiting and non-exhaustive examples are described with reference to the followingfigures. FIG. 1 illustrates a block diagram of a communication system, according to aspects ofthe present disclosure.FIG. 2 illustrates a block diagram of a functional encryption system, according to an em-bodiment. FIG. 3 illustrates a block diagram of a client computing architecture, in accordance withexample embodiments.FIG. 4 illustrates a server-client network architecture, according to aspects of the presentdisclosure. FIG. 5 illustrates a block diagram of an attribute-based encryption system, according toan embodiment.FIG. 6 illustrates a block diagram of a reduced-size ciphertext generation system, accord-ing to aspects of the present disclosure.DETAILED DESCRIPTION1 Introduction1.1 Our ResultsIn this work, we improve on the state of the art for ABE and LFE from non-standard latticeassumptions. For any 1 / 3 ≤α≤ 1, we construct for depth d boolean circuits over ℓ-bit inputswhere ℓ and d are fixed at set-up:an ABE with parameters: aLFE with parameters: encryption time O(ℓ)where O(·) hides poly(d ,λ) factors. Security relies on ℓ-succinct LWE, a new falsifiable andinstance-independent assumption introduced in this work. We obtain as special cases cor-responding to α= 1 and α= 1 / 3:the first ABE to simultaneously achieve poly(d ,λ)-sized ciphertexts and secret keys, an-swering a natural question left open in BGGHNSVV (BGGHNSVV actually constructed asecond ABE for circuits with |ct| = poly(d ,λ) and |sk| = s ·poly(d ,λ), assuming multi-linearmaps. Security relies on (d+1,ℓ)-Multilinear Diffie-Hellman Exponent Assumption, a q-type assumption.);an LFE for circuits with |ct| = ℓ+O(1), |dig| =O(1) and encryption running time O(ℓ);an ABE for circuits with |mpk| = |ct| = O(ℓ2 / 3), |sk| = O(1), simultaneously breaking boththe |ct| =Ω(ℓ) and |mpk| =Ω(ℓ) barriers.The first two results achieve essentially optimal ciphertext and secret key / digest sizes forthe important subclass of NC1 circuits where we can bound d = O(logℓ) by λ. We reiteratethat none of these results was known even from the stronger and non-falsifiable evasive LWEassumption. The ℓ-succinct LWE assumption is a parameterized assumption (with parameter ℓ), sim-ilar to q-type assumptions in pairing-based cryptography: it becomes stronger asℓ increases,and is both falsifiable and instance-independent. When ℓ= 1, it follows from standard LWE,and for general ℓ, it is implied by evasive LWE. The gap between ℓ-succinct LWE and eva-sive LWE is analogous to that q-type assumptions and the generic group model (GGM) inpairing-based cryptography; in both cases, the former is more desirable from both a the-oretical and cryptanalytic stand-point. The study of parameterized lattice assumptions goback to two recent works where they used parameterized SIS assumptions to construct suc-cinct arguments and functional commitments. Our work builds on these techniques andassumptions. We regard the introduction and use of parameterized LWE assumptions foradvanced encryption primitives, where the assumption can in turn be justified using eva-sive LWE, as an additional conceptual contribution of this work.1.2 High-level OverviewWe begin our overview with the results in the two works mentioned in the preceding para-graph, using the notion of homomorphic instead of functional commitments. We continueto use O(·) to hide poly(d ,λ) factors.Homomomorphic commitments.Homomorphic commitments (HC) enable computing on a commitment com to x ∈ {0,1}ℓ toderive a commitment com f to f (x); moreover, given the opening to x, we can also derive anopening to f (x). In 2015, Gorbunov, Vaikuntanathan and Wichs (GVW) constructed homo-morphic commitments for circuits with |com| =O(ℓ), |com f | =O(1), whose security relies onSIS. The GVW construction builds on the first BGGHNSVV ABE, where com,com f are derivedfrom the ABE ciphertexts and keys respectively.A recent work of Wee and Wu (WW) improves on the GVW construction to achieve |com| =|com f | = O(1). The key innovation in WW to compress the GVW commitment down to O(1)bits using a trapdoor basis; homomorphic computation first decompresses –or, expands–the compressed commitment to recover a GVW commitment, and then proceeds as beforein GVW. Security relies on BASISstruct, a non-standard and falsifiable variant of SIS intro-duced in WW, which asserts that SIS is hard even given the trapdoor basis.Our approach.Our high-level approach is to “lift” the WW homomorphic commitment into an ABE withO(1)-sized ciphertexts and keys à la GVW; in particular, we show how to compress BG-GHNSVV ABE ciphertexts à la WW. Our key technical contribution is an error-friendly vari-ant of WW compression dualWW where decompression entails multiplication by low-normmatrices. In a nutshell,The WW compressed commitment is derived from a linear combination of sub-matricesof the trapdoor basis, and decompression entails left-multiplication by random matricesV1, ... ,Vℓ←Zn×nq in the public parameters(The matrix Vi corresponds to W−1i .); the latteris incompatible with ABE ciphertexts due to the blow-up in the error term.Our compressed ciphertext in dualWW is derived from a linear combination of V1, ... ,Vℓ,multiplied by an LWE secret on the left. Decompression entails right-multiplication bylow-norm sub-matrices of the trapdoor basis. In fact, our compressed ciphertext for at-tribute (x1, ... , xℓ) ∈ {0,1}ℓ is quite simply: where B,B1 ←Zn×mq ,Vi ←Zn×nq are specified in the public key and G ∈Zn×mq is the gadgetmatrix.Applying dualWW compression to the BGGHNSVV ABE, we obtain an ABE for circuits withpoly(λ,d)-sized ciphertexts and keys. Security relies on the LWE analogue of BASISstruct,which we refer to as BALWEstruct. We can also apply dualWW compression to the QWW LFEfor circuits to reduce the ciphertext size from to ℓ+O(1), while preserving digest sizeO(1) and encryption time O(ℓ). Security of the ensuing LFE also relies on BALWEstruct.Additional improvements.At this point, we inherit two limitations of the WW scheme. The first is a large public key ofsize O(ℓ2). To mitigate this issue, we show how to reduce the public key size to O(ℓ2α+ℓ1−α),at the cost of increasing the ciphertext size to O(ℓ1−α), for any 0 ≤ α ≤ 1. The first idea isto break up x ∈ {0,1}ℓ into ℓ1−α blocks of size ℓα, with several additional ideas to achievesublinear dependency on ℓ. The second limitation is that BALWEstruct assumption does notfollow from evasive LWE. To this end, we simply replace Vi ← Zn×nq (more precisely, Vi G)with Wi ← Zn×mq in both BALWEstruct and our scheme. We refer to the ensuing assumptionas ℓ-succinct LWE assumption to emphasize that the assumption is parameterized by ℓ,and we show that ℓ-succinct LWE is implied by evasive LWE (up to a small polynomial lossin parameters).1.3 Technical OverviewFix LWE parameters n, q,m = O(n log q). For notational simplicity, we often omit LWE errorterms, or replace them with curly underlines.The WW commitment scheme.We begin with an overview of the core WW commitment scheme, adapted to the notationand setting in this work. The scheme achieves succinct commitments of size independentof the input length ℓ; this succinct commitment can in turn be expanded to a GVW commit-ment of the same input.The public parameters compriseB ←Zn×m ℓn×nq ,V ∈Zqalong with a random Gaussian that That is, T is a random gadget trapdoor for [Iℓ⊗B | VG]. Given x ∈ {0,1}ℓ, we multiply bothsides of (1) on the right by x⊤⊗ Im to obtain︷ ope︸n︸ing︷ ︷ comm︸i︸tmentI ⊗B) · ⊤ ⊤ ︷( ⊤ℓ T(x ⊗ Im)+V · GT(x ⊗ Im) = x ⊗G (2)The commitment C to x ∈ {0,1}ℓ is given by G · T(x⊤ ⊗ Im) ∈ Zn×mq and the opening byT(x⊤⊗ Im) ∈Zℓm×m .Verification checks that the opening has low norm and satisfies the above relation in (2).Binding follows from the BASISstruct assumption, which states that SIS is hard with respectto B, given V,T. Moreover, we can expand C into V ·C ∈Zℓn×mq , which is a GVW commitmentto x with opening T(x⊤⊗ Im).Compressing s(A−x⊗G).In the BGGHNSVV ABE, the public key specifies a uniformly random A ← andciphertext for an attribute x ∈ {0,1}ℓ contains Our goal is to compress the above quantity into a vector in ZO(m)q using B,V,T.First idea. A natural strategy following GVW would be to use s:C:as the compressed cipher-text, where C is a homomorphic commitment to x (looking ahead, we will rely on homorphicopening in the security proof). Instantiating this idea with the WW commitment is problem-atic because multiplying C on the left by V as in (2) interacts poorly with both the error term eand the secret s. Instead, we will modify the commitment scheme and (2) as follows. We startby multiplying both sides of (1) on the left by x⊗ In and use the fact that x⊗ In “commutes”with Iℓ⊗B —i.e., (x⊗ In)(Iℓ⊗B) = B(x⊗ Im)— to obtain:︷ ope︸n︸ing︷ ︷ comm︸i︸tmen︷tB · (x⊗ Im)T+ (x⊗ In)VG ·T = x⊗G (3)Now, consider a commitment C to x is given by (x⊗ In)VG ∈ Zn×mq . This fixes both of theissues above: multiplying C on the right by the low-norm matrix T is compatible with bothe and s, but introduces a security issue – given sC+ e = s(x⊗ In)VG+ e, we can efficientlyrecover s due to the gadget matrix G in C.Our construction. To solve the latter issue, we append to the public key a matrix B1 ←and our compressed ciphertext is now given by:s:[:B::|:B:1:+::(:x::⊗:I:n:):V::G:]∈Z2qm(4)Towards decompression, add BT to both sides of (3) and flip the signs to obtain: We can now define A := Multiplying both sides of (5) by s on theleft yields the desired decompression: Next, we show that replacing a uniformly random A ← Zn×ℓmq in the BGGHNSVV ABE withA :=−B1T does not affect security. Looking ahead to the setting with general α, the fact thatA is deterministically derived from B1,T is crucial for obtaining o(ℓ) total parameter size.Security analysis. Recall that in the proof of selective security for the BGGHNSVV ABE, thereduction receives an LWE challenge (B,s:B:) and an attribute x, samples a low-norm R ← and programs A := BR+x⊗G. This allows the reduction to simulate s:(:A::−::x:⊗::G::)in the ciphertext given s:B:, and answer key queries using a trapdoor derived from R. In ourcase, we sample U ← {0,1}m×m , and programs B1 := BU− (x⊗ In)VG.In our setting, security will instead rely onBALWEstruct (the LWE analogue ofBASISstruct),namely (B,sB+e) is pseudorandom, given V,T. The reduction receives a BALWEstruct chal-lenge (B,sB,V,T) and an att m×m::ribute x, samples a low-norm U ← {0,1} and programs B1 :=BU− (x⊗ In)VG. This allows the reduction to simulate s:[:B::|:B:1:+::(:x::⊗:I:n:):V::G:] in the ciphertextgiven s:B:. Next, observe that the matrix A in our scheme satisfies: This follows from replacing B1 + (x⊗ In)VG in (5) with BU. We can then answer key queriesas in the BGGHNSVV ABE security with [I | U] ·Tx in place of R.From compression to ABE and LFE. Our ABE and LFE schemes with poly(λ,d)-sized ci-phertexts follow from applying our compression mechanism to the prior BGGHNSVV ABEand QWW LFE in a straight-forward manner:We append (B,V,T) to the public key / CRS of prior schemes, and replace A ← with A :=−B1T;Key generation and digest computation are exactly as before, except with the new A;We replace s:(:A::−::x:⊗::G::) in the ciphertexts with s:[:B::|:B:1:+::(:x::⊗:I:n:):V::G:]; Decryption runs decompression as in (6) and proceeds as before;In the security proofs, we replace programming A = B ·R+x⊗G with programming B1 asdecsribed above, and proceed as before.Parameter trade-offs.In the rest of this section, we use O(·) to supress poly(n, log q) factors. So far, we have |mpk| =O(ℓ2), dominated by the matrix T. Fix ℓ0,ℓ1 such that ℓ0 ·ℓ1 = ℓ. We show how to reduce thesize of the public parameter mpk from O(ℓ2) to at the cost of increasing the sizeof the compressed LWE sample ct from O(1) to O(ℓ1). The results in Section 1.1 correspondto setting ℓ0 = ℓα,ℓ1 = ℓ1−α.The basic idea is to divide x ∈ {0,1}ℓ as well as s(A−x⊗G) into blocks of size and run ℓ1 copies of our base scheme with input length ℓ0. Naively implementing this ideayields To get to |mpk| =O(ℓ20+ℓ1), we reuse (V,T) for all blocks (contributing O ), while sam-pling a fresh B1 ← Zn×mq for each block (contributing O(ℓ1)). It is straight-forward to verifythat this does not affect functionality. To see why reusing V,T is fine for security, observe thatthe reduction from BALWEstruct programs B1 but not V; the latter also means that we need afresh B1 for each block for security. As mentioned earlier, we exploit the fact that A ∈Zn×ℓmqis derived from T and the B1 matrices to avoid an additive blow-up.Weakening the assumption.BALWEstruct is implied by evasive LWE plus the following non-standard variant of LWE (re-lated to building simpler PRFs from lattices, namely:(B,V , ′1 ... ,Vℓ,R,sB+e,sVi R+ei ) (7)is pseudorandom, In this work, we introduce ℓ-succinct LWE, where we replace VG in BALWEstruct withW ← . That is, ℓ-succinct LWE states that (B,sB + e) is pseudorandom, given W,T,where [Iℓ⊗B | W] ·T = Iℓ⊗G. We would then also replace VG in our compressed LWE samplein (4) with W to obtain: It is easy to see that LWE implies 1-succinct LWE (by sampling W with a trapdoor)and the assumption becomes stronger as ℓ increases (i.e., ℓ-succinct LWE implies (ℓ− 1)-succinct LWE). We have that ℓ-succinct LWE is implied by evasive LWE, plus pseudoran-domness of the following distribution: where Wi ← Zn×mq ,R ← Dm×2mZ,χ ,e ← The key distinctions from (7) are thatWi are wider than Vi , and that R has low-norm, which allow us to base pseudorandomnessof the latter on LWE.Putting everything together.We sketch the compression scheme for general ℓ0,ℓ1 based on ℓ-succinct LWE. We sample and output as the compressed LWE sample We can then adapt (5) to obtainT 2 PreliminariesNotations.We use boldface lower case for row vectors (e.g. v) and boldface upper case for matrices(e.g. V). For integral vectors and matrices (i.e., those over Z), we use the notation |v|, |V| todenote the maximum absolute value over all the entries. We use v to denote a randomsample from a distribution D, as well as v ← S to denote a uniformly random sample froma set S. We use ≈s and ≈c as the abbreviation for statistically close and computationallyindistinguishable.Tensor product.The tensor product (Kronecker product) for matrices A is defined The mixed-product property for tensor product says that(A⊗B)(C⊗D) = (AC)⊗ (BD)2.1 Lattices backgroundWe use DZ,χ to denote the discrete Gaussian distribution over Z with standard deviation χ.Learning with errors (LWE).Given n,m, q,χ ∈N, the LWEn,m,q,χ assumption states that(B,sB+e) ≈c (B,c)where B←Zn×m ,s ←Zn ,e m mq q ←DZ ,χ,c ←ZqTrapdoor and preimage sampling.n×n′Given any Z ∈Zq , σ> 0, we use B−1(Z,σ) to denote the distribution of a matrix Y sampledfrom DZm×n′ ,σ conditioned on BY = Z (mod q). We sometimes suppress σ when the contextis clear.There is an efficient algorithm TrapGen(1n ,1m , q) that, given the modulus q ≥ 2 and di-mension n and m ≥ 2n log q , outputs B ≈s U (Zn×2n log qq ) with a trapdoor T such that BT = G.Moreover, there is an efficient algorithm SamplePre(B,T,Z,σ) that given B and any T suchthat BT = outputs a sample fr −1 om B (Z,σ). Notegiven B,T such that BT = G, we have [B | B ] 0 = G; we will sometimes abuse notation andwrite T as a trapdoor for [B | B′].2.2 Homomorphic Computation on MatricesLemma 1 (EvalF,EvalFX). Fix lattice parameters n, q and m ≥ 2n log q. Let Fℓ,d ,s denote thefamily of functions f : {0,1}ℓ → {0,1} computable by circuits of depth d and size s. There exista pair of efficient algorithms (EvalF,EvalFX) where For all A ∈Zn×ℓmq , f ∈Fℓ,d ,s ,x ∈ {0,1}ℓ, the matrices A f ←EvalF(A, f ) and HA, f ,x ←EvalFX(A, f ,x)satisfy 3 ℓ-Succinct Lattice AssumptionsIn this section, we introduce the ℓ-succinct LWE assumption as well as its (weaker) SIS ana-logue ℓ-succinct SIS. The results in this work rely on the former; we state the latter in part tohighlight the connection to the BASISstruct assumption, which heavily inspired ℓ-succinctLWE.Assumption 1 (ℓ-succinct LWE) Fix security parameter λ and LWE parameters n,m, q,χwherem ≥ 2n log q. The (ℓ,m̂,σ)-succinct LWE assumption where m ≤ m̂ ≤ ℓm stipulates that(B,sB+e,W,T) ≈c (B,c,W,T)where That is, T is a random gadget trapdoor with quality σ for the matrix [Iℓ⊗B | W].We abbreviate the assumption to -succinct LWE when σ = poly(λ,ℓ,m) and fur-ther abbreviate to ℓ-succinct LWE when m̂ = m. The results in this work primarily rely on^polynomial-time hardness of ℓ-succinct LWE for modulus-to-noise ratio q / χ≈ , for some0 < ^< 1.Remark 1. It is easy to see that LWE implies (ℓ,ℓm)-succinct LWE and in particular 1-succinctLWE: the reduction samples W ← along with a trapdoor, which is used to derive atrapdoor for [Iℓ⊗B | W] with norm poly(λ,ℓ,m).SIS variant.The SIS assumption for parameters n, q,m,β says that given B ← it is hard to find anon-zero v ∈Zmq such that Bv = 0 mod q and |v| ≤ β. We also introduce the SIS analogue ofℓ-succinct LWE:Assumption 2 (ℓ-succinct SIS) Fix SIS parameters n,m, q,β. The succcinct SIS assumption such that Bv = 0 mod q and |v| ≤β) given W,T where For the same reason LWE implies SIS, we also have ℓ-succinct LWE implies ℓ-succinct SIS.4 Attribute-Based Encryption4.1 Attribute-based encryptionDefinition 1 (ABE). A (key-policy) attribute-based encryption (ABE) scheme for some class Fconsists of four algorithms:. The setup algorithm gets as input the security parameter 1λ and It outputs the master public key mpk and the master secret key msk.Enc(mpk, x,µ) → ct. The encryption algorithm gets as input mpk, an input x and a messageµ ∈ {0,1}λ. It outputs a ciphertext ct.KeyGen(mpk,msk, f ) → sk. The key generation algorithm gets as input mpk, msk and f ∈F .It outputs a secret key sk.Dec(mpk,sk, f ,ct, x) →µ. The decryption algorithm gets as input sk, f ,ct, x for which f (x) =0 along with mpk. (We follow the convention where f (x) = 0 corresponds to “authorized”.)It outputs a message µ. Correctness.For all inputs x and f with f (x) = 0 and all µ ∈ {0,1}λ, we require^ ^(mpk,msk) ← Setup(1λ(mpk,sk, f ,ct, x) =µ : sk←KeyGen(mpk,msk, ct←Enc(mpk, x,µ) Security.For a stateful adversary A , we define the advantage function^^ with the restriction that all queries f that A sent to KeyGen(mpk,msk, ·) satisfy f (x) ̸= 0. AnABE scheme is selectively secure if for all PPT adversaries A , the advantage AdvABEA (λ) is anegligible function in λ.4.2 ABE for CircuitsConstruction 1 (ABE for circuits) We construct an ABE scheme for the family Fℓ,d ,s of cir- Enc(mpk,x,m). Sample Output KeyGen(msk, f ): Compute A :=−B1(Iℓ1 ⊗T) and A f :=EvalF(A, f ). SampleD ← SamplePre([B | A f ],TB,P,σ1)Output sk := D ∈Z2m×λDec(mpk,sk= D, f ,ct= (c0,c1,c2),x): ComputeA := −B1(Iℓ1 ⊗T),HA, f ,x := EvalFX(A, f ,x) c3 := [c0 | c1] ·Tx ·HA, f ,x.Output ⌊ )⌉2 ( cλq·2 − [c0 | c3] ·D mod q ∈ {0,1}Parameters. 00 n^Fix 0 < ^< 1, where (ℓ ,m,σ )-succinct LWE is hard for a 2 modulus-to-noise ratio. We setLWE parametersn = d 1 / ^ ·poly(λ, logℓ, log s)m = O(n1+^)q = mO(d)s ·poly(ℓ) ·λω(1)χ = poly(n,λ)to satisfyq / 4 ≥ ·poly(m,λ) (correctness)^2n≥ q / χ (modulus-to-noise ratio)m ≥ 2n log q·poly (H3 ≈c H4)σ1 ≥ σ0 ·mO (m,λ) (H2 ≈s H3)χ′ ≥ χ ·σ0 ·λω(1) (H1 ≈s H2)where H1,H2,H3,H4 are defined in the proof below. This yields the following parameter sizesfor our ABE scheme: where Oλ,d (·) hides factors polynomial in λ,d 1 / ^. In particular, setting ℓ0 = ℓα,ℓ1 = ℓ1−αyields Remark 2 (Running times). The running times for encryption and decryption are essentiallythe same as that of the BGGHNSVV ABE. Encryption takes time Õ(ℓ0). Decryption takestime Õ(s+ℓ 20 ) in our scheme and Õ(s) in BGGHNSVV: they are both dominated by the timetaken to compute HA, f ,x. Here, Õ(·) hides factors polynomial in the lattice parameters andthe circuit depth, but it is the same polynomial in both schemes, and basically the samelattice parameters (q could be a polynomial factor larger in our scheme, but the runningtimes only depend on log q).Remark 3 (Polynomial hardness for NC1). For NC1 circuits, we can hope to improve the re-sult to only rely ℓ0-succinct LWE with a polynomial instead of a sub-exponential modulus-to-noise ratio. To achieve this, we rely on a variant of Lemma 1 for NC1 circuits achieving|HA, f ,x| = O(2d · s). In addition, we can avoid noise flooding in the ciphertexts by takinge1 = e0U,e2 = e0U. We omit this optimization from the current work.We begin by proving the equation we use for decompression:()Claim. Suppose [Iℓ0 ⊗B | W] · TT= Iℓ ℓ0 ⊗G. Then, for all x ∈ {0,1} , we have:Tx s Proof. Observe that Multiplying both sides of (11) on the left by −x⊗In , and observing (x⊗In)(Iℓ⊗B) = B(x⊗Im),we obtain Adding −B1(Iℓ1 ⊗T) to both sides yields the claim above. ⊓⊔Correctness.Combining 9 with (8), we have[B | B1 + (x⊗ In)(Iℓ1 ⊗W)] ·Tx ·HA, f ,x = A f − f (x)G (12)This means that whenever f (x) = 0,c3 ≈ s(A f − f (x)G) = sA f (13)[c0 | c3] ·D ≈ s[B | A f ] ·D = sPc − [c | c3] q2 0 ·D ≈ m · ⌊2 ⌋The error term in the final ≈ is given bye2 − [e0 | ([e0 | e1] ·Tx ·HA, f ,x)] ·Dwhose norm is bounded by ·poly(m,λ)Correctness follows as long as the preceding quantity is bounded by q / 4.Theoremsecure ABE Proof. We define a series of games:H0: This is the real ABE security game.H1: Same as H1, except the challenger samples B1,P as follows:1. samples U ← {0,1}m×m , and programs B1 := BU− (x⊗ In)(Iℓ1 ⊗W)2. samples U0 ← {0,1}m×λ, and programs P := BU0.H0 ≈s H1 follows readily from left-over hash lemma.H2: Same as H1, except the challenger in Enc samples c1 := c0U+e1,c2 := c0U0 +e2.H1 ≈s H2 follows readily from noise-flooding, along with c0U ≈ sBU = s(B1+ (x⊗ In)(Iℓ1 ⊗W)) and c0U0 ≈ sBU0 = sP.H3: Same asH2, except the challenger inKeyGen samples D usingSamplePre([B | A f ],instead of SamplePre([B | A f ],TB,P,σ1).H2 ≈s H3 follows from trapdoor sampling together with the following:• substituting B1 + (x⊗ In)(Iℓ1 ⊗W) = BU into (12) yields[B | BU] ·Tx ·HA, f ,x = B · [I | U] ·Tx ·HA, f ,x = A f − f (x)G H4: Same as H3, except the challenger samples c0 ←Zmq .H3 ≈c H4 follows from (ℓ0,m,σ0)-succinct LWE.H5: Same as H4, except the challenger samples c2 ←Zλq .H4 ≈s H5 follows from left-over hash lemma, which tells us (B,c0,BU0,c0U0) is statisti-cally close to uniform.In H5, the challenge bit b is perfectly hidden, so the advantage is 0. ⊓⊔4.3 Reusable Garbled CircuitsGoldwassser et al., with improvements from Boneh et al., showed that starting from (i) anABE scheme for Fℓ,d ,s with mpk, ciphertext and key sizes P (ℓ,d , s),C (ℓ,d , s),K (ℓ,d , s), and(ii) the LWE assumption (used for FHE with rate one ciphertexts), we can construct a reusablegarbling scheme for Fℓ,d ,s in the CRS model wherethe CRS has size P (ℓ′,d ′, s′);the garbled input has size ℓ′+poly(λ) ·C (ℓ′,d ′, s′);the garbled circuit has size s +poly(λ) ·K (ℓ′,d ′, s′);where ℓ′ = ℓ+ poly(λ,d),d ′ = d · poly(λ), s′ = s · poly(λ,d). Here, ℓ′ is the size of a FHE en-cryption of x ∈ {0,1}ℓ and d ′, s′ correspond to the depth and the size of the circuit perform-ing FHE homomorphic evaluation of f plus symmetric-key decryption. Combined with ourABE scheme in Construction 1, we have the following corollary:Corollary 1 (Reusable garbling scheme). Assuming (ℓ0,m)-succinct LWE with 2n^ modulus- Here, Oλ,d (·) hides factors polynomial in λ,d 1 / ^.5 Laconic Function Evaluation5.1 Definition of LFEDefinition 2 (LFE). A laconic function evaluation (LFE) scheme for some class F consists offour algorithms Setup,Compress,Enc,Dec.Setupa Compress(crs, f ) is a deterministic algorithm that takes as input crs adigest dig.Enc(crs,dig, x) takes as input crs, a digest dig and a message x and outputs a ciphertext ct.Dec(crs, f ,ct) takes as input crs, f ∈F , and a ciphertext ct and outputs a message y.Correctness.We require that for all λ,F and f ∈F :^ ^crs ← Setup(1λ,F )dig =Compress(crs, f )ct ←Enc(crs,dig, x) y ←Dec(crs, f ,ct) Selective security.We require that there exists a PPT simulator Sim such that for all stateful PPT adversary A , EXPRLFeaEl(1λ) : EXPI dealLF E (1λ) :0. (F , x) ←A (1λ) 0. (F , x) ←A (1λ)1. crs← Setup(1λ,F ) 1. crs← Setup(1λ,F )2. f ←A (crs): 2. f ←A (crs):3. dig=Compress(crs, f ) 3. dig=Compress(crs, f )4. ct←Enc(crs,dig, x) 4. ct← Sim(crs,dig, f , f (x))5. Output A (ct) 5. Output A (ct)5.2 LFE for CircuitsFollowing QWW, we start by constructing AB-LFE for circuits, which corresponds to LFE forthe following functionality: Our formalization of AB-LFE corresponds to the two-outcome variant. As in QWW:the digest is simply A f ;the ciphertext contains x along with a compression of s:(:A::−::⊗:G::), and we additionally uses:A::f to mask m0, and s:(:A:f::−::G:) to mask m1.Construction 3 (AB-LFE for circuits) We construct an AB-LFE scheme for the family Fℓ0,d ,sof circuits of depth d and size s, with parameters ℓ0,ℓ1 such that ℓ0 ·ℓ1 = ℓ, as follows:Setup(1n ,Fℓ0,d ,s): Sample Compress(crs, f ): Compute A :=−B1(Iℓ1 ⊗T) and A f :=EvalF(A, f ). Outputdig := A n×mf ∈ZEnc(crs,A f , (x,m0,m1)). Sample Compute (Here, G−1(·) denotes the standard deterministic entry-wise bit decomposition.)c0 := sB+e0 Output ()ct := x,c ,c ,c ,c ,P ℓ m ℓ1m λ 2 n×λ 20 1 2,0 2,1 0,P1 ∈ {0,1} ×Zq ×Zq × (Zq ) × (Zq )Dec(crs A:= −B1(Iℓ1 ⊗T),HA, f ,x := EvalFX(A, f ,x) c3 := [c0 | c1] ·Tx ·HA, f ,x.Output ⌊2 ( c−c ·G−1 )⌉(P λq·2, f (x) 3 f (x)) mod q ∈ {0,1}Parameters. 00 n^Fix 0 < ^< 1, where (ℓ ,m,σ )-succinct LWE is hard for a 2 modulus-to-noise ratio. We willset LWE parameters as in our ABE scheme in Section 4.2n = d 1 / ^ ·poly(λ, logℓ, log s)m = O(n1+^)q = mO(d)s ·polyχ = poly(n,λ)which also satisfy the following minor modifications to the constraints pertaining to χ′′ (inplace of σ1):(correctness) (H0 ≈s H1 in proof below)This yields the following parameter sizes for our AB-LFE scheme:|crs| =Oλ,d (ℓ 20 +ℓ1), |dig| =Oλ,d (1), |ct| = ℓ+Oλ,d (ℓ1)and the encryption running time is O (ℓ) 1 / ^λ,d . Here, Oλ,d (·) hides factors polynomial in λ,d .In particular, setting ℓ0 = ℓα,ℓ1 = ℓ1−α yields Correctness.As in Section 4.2, we have from (13) that c3 ≈ s(A f − f (x)G). Therefore, The error term in the above ≈ is given by whose norm is bounded by Correctness follows as long as the preceding quantity is bounded by q / 4.Theorem 4. Under the (ℓ0,m,σ0)-succinct LWE assumption, Construction 3 is selectively se-cure.Proof. We begin by specifying the simulator:Sim(crs,dig, f , (x,z)): Compute f (x) ∈ {0,1}, and sample Compute c3 := [c0 | c1] ·Tx ·HA, f ,x∗ (same as in Dec)c := c ·G−1(P )+ q2, f (x) 3 f (x) z · ⌊2 ⌋+e2, f (x)Output ()ct := x,c0,c1,c2,0,c2,1,P0,P1We define a series of games:H0: This is the real AB-LFE security game.H1: Same as H0, except the challenger computes c3 as in Sim, and c2,0,c2,1 as follows: H0 ≈s H1 follows from• a straight-forward adaptation of (15) which tells us c2,b in H0 satisfies:c ≈ c · −1 q2,b 3 G (Pb)+mb · ⌊2 ⌋+ ( f (x)−b) ·sPb ,∀b ∈ {0,1}• noise-flooding using e2,b to flood the error term H2: Same as H1, except the challenger samples B1,P1− f (x) as follows:1. samples U ← {0,1}m×m , and programs B1 := BU− (x⊗ In)(Iℓ1 ⊗W)2. samples U1− f (x) ← {0,1}m×λ, and programs P1− f (x) = BU1− f (x).H1 ≈s H2 follows readily from left-over hash lemma.H3: Same as H2, except the challenger in Enc samples c1,c2,1− f (x) as follows:c1 := c0U+e1 H2 ≈s H3 follows readily from noise-flooding along with c0U ≈ sBU = s(B1 + (x⊗ In)(Iℓ1 ⊗W)) and c0U1− f (x) ≈ sBU1− f (x) = sP1− f (x).H4: Same as H3, except the challenger samples c0 ←Zmq .H3 ≈c H4 follows from (ℓ0,m,σ0)-succinct LWE.H5: Same as H4, except the challenger samples c1 ← ←Zλq .H4 ≈s H5 follows from left-over hash lemma, which tells us (B,c0,BU,c0U,BU1− f (x),c0U1− f (x))is statistically close to uniform.Observe that H5 is exactly the output of Sim, since z = m f (x). ⊓⊔From AB-LFE to LFE.Prior work showed —via a construction similar to that in in Section 4.3— that starting from(i) an AB-LFE scheme for Fℓ,d ,s with CRS, ciphertext and digest sizesP (ℓ,d , s),ℓ+C (ℓ,d , s),K (ℓ,d , s), and (ii) the LWE assumption (used for FHE with rate oneciphertexts), we can construct an LFE scheme for Fℓ,d ,s where|crs| = P (ℓ′,d ′, s′), |dig| = poly(λ) ·K (ℓ′,d ′, s′), |ct| = ℓ′+poly(λ) ·C (ℓ′,d ′, s′)where ℓ′ = ℓ+poly(λ,d),d ′ = poly(λ,d), s′ = s ·poly(λ,d). Combined with our AB-LFE schemein Construction 3, we have the following corollary:Corollary 2 (LFE for circuits). Assuming ℓα-succinct LWE with 2n^ modulus-to-noise ratio, and the encryption running time is Oλ,d (ℓ). Here, Oλ,d (·) hides factors polynomial in λ,d 1 / ^.System ImplementationsSystem OverviewFIG. 1 illustrates an encryption system 100 in an embodiment of the present invention.The encryption system 100 may include a setup device 125, an encryption device 140, a keygeneration device 155, and a decryption device 110. These devices may be communicablyconnected to each other via a communication network 105.A setup device 125 may be configured to execute a setup algorithm. The setup device 125may include a setup processing unit 130 and a storage unit 135. The setup processing unit130 may execute the setup algorithm as described herein. In some cases, the storage unit135 may store various types of information used in the setup algorithm, an output result ofthe setup algorithm, and related data.An encryption device 140 may be configured to execute an encryption algorithm. Theencryption device 140 may include an encryption processing unit 145 and a storage unit150. The storage unit 150 may store various types of information used in the encryptionalgorithm, an output result (e.g., the ciphertext) of the encryption algorithm, and relateddata. Akey generation device 155 may be configured to execute a key generation algorithm.The key generation device 155 may include a key generation processing unit 160 and a stor-age unit 165. In some cases, the storage unit 165 may store various types of informationused in the key generation algorithm, an output result of the key generation algorithm, andrelated data.A decryption device 110 may be configured to execute a decryption algorithm. The de-cryption device 110 may include a decryption processing unit 115 and a storage unit 120.The storage unit 120 may store various types of information used in the decryption algo-rithm, an output result of the decryption algorithm, and related data.In some cases, the encryption system 100 may comprise a first processor, a non-transitorycomputer-readable storage medium, a second processor, and a network interface devicecommunicatively coupled to the first processor. The first processor may be configured toreceive a plaintext message and ABE attributes in a computerized media. The second pro-cessor may be configured to execute a setup procedure to generate a master public-privatekey pair. The first processor may be configured to execute an encryption procedure.The network interface device may be configured to transmit the ciphertext to a recipi-ent device over the communication network 105. This configuration may allow for securetransmission of encrypted data between different components of the system.The data owner 205 may interact with the encryption system 100 to securely store andtransmit sensitive information. The encryption system 100 may provide a flexible and secureframework for attribute-based encryption, allowing for fine-grained access control over en-crypted data.Functional Encryption ArchitectureFIG. 2 illustrates an example system architecture for a functional encryption scheme.The system may include a data owner 205, a functional encryption server 210, a data user215, and a trusted authority 220. These components may interact to enable secure compu-tation on encrypted data while preserving privacy and access control.In some cases, the data owner 205 may upload encrypted data, referred to as ciphertextC, to the functional encryption server 210. The ciphertext C may be generated using an en-cryption algorithm executed by the encryption device 140 as described in relation to FIG.1. The encryption algorithm may take as input a plaintext message and attribute-based en-cryption (ABE) attributes stored in the storage unit 150.A data user 215 may request access to perform a specific function F on the encrypteddata. To obtain authorization, the data user 215 may interact with the trusted authority 220.The trusted authority 220 may be responsible for issuing function tokens that grant permis-sion to compute specific functions on the encrypted data.In some implementations, the trusted authority 220 may generate a function token TFcorresponding to the requested function F. The function token TF may be derived using akey generation algorithm executed by the key generation device 155, utilizing informationstored in the storage unit 165.Upon receiving the function token TF , the data user 215 may transmit TF to the func-tional encryption server 210. The functional encryption server 210 may then execute theauthorized function F on the available ciphertext C. This computation may be performedwithout decrypting the underlying plaintext, preserving data confidentiality.The result of the computation, denoted as RF , may be generated by the functional en-cryption server 210 in encrypted form. In some cases, the functional encryption server 210may transmit the encrypted result RF to the data user 215 over the communication network105. To access the final result, the data user 215 may utilize a decryption device 110 as de-scribed in FIG. 1. The decryption device 110 may execute a decryption algorithm using thedecryption processing unit 115 and information stored in the storage unit 120. This processmay allow the data user 215 to obtain the computed result while maintaining the security ofthe original encrypted data.The functional encryption architecture depicted in FIG. 2 may enable secure delegationof computation on encrypted data. By utilizing function tokens and maintaining encryptionthroughout the process, the system may provide fine-grained access control and preservedata privacy.In some implementations, the non-transitory computer-readable storage medium of theencryption device 140 may store instructions that, when executed by one or more proces-sors, cause the processors to perform a method for creating a smaller ciphertext compati-ble with pre-existing ABE schemes. This method may involve techniques to compress theciphertext while maintaining compatibility with existing attribute-based encryption proto-cols. The functional encryption server 210 may transmit the ciphertext to a recipient device,such as the data user 215, over the communication network 105. This transmission mayoccur after the authorized computation has been performed on the encrypted data. Thereduced size of the ciphertext may improve efficiency in data transfer and storage whilepreserving the security properties of the functional encryption scheme.Client Computing ArchitectureFIG. 3 illustrates a client computing architecture 1100 that may be utilized in some im-plementations of the encryption system 100. The client computing architecture 1100 maycomprise several interconnected subsystems, including a processing subsystem 1105, a mem-ory subsystem 1135, a storage subsystem 1150, and a client I / O subsystem 1170. These sub-systems may communicate with each other via a system bus 1195.A processing subsystem 1105 may include various processing components for execut-ing instructions and performing computations. In some cases, the processing subsystem1105 may comprise a central processing unit 1110, which may serve as the primary pro-cessor for the client computing architecture 1100. The central processing unit 1110 may beconnected to a memory management unit 1115, which may handle memory allocation andvirtual memory operations.The processing subsystem 1105 may also include a cache memory 1120, which may pro-vide fast access to frequently used data and instructions. In some implementations, the pro-cessing subsystem 1105 may further comprise specialized processing units such as a graph-ics processing unit 1125 for handling graphics-intensive tasks and an AI / ML processing unit1130 for accelerating artificial intelligence and machine learning computations.A memory subsystem 1135 may provide temporary storage for data and instructions be-ing processed by the processing subsystem 1105. The memory subsystem 1135 may includea system memory 1140, which may be implemented as dynamic random-access memory(DRAM) for fast read and write operations. In some cases, the memory subsystem 1135 mayalso include a non-volatile memory 1145 for storing data that needs to persist across systemreboots or power cycles.A storage subsystem 1150 may provide long-term storage capabilities for the client com-puting architecture 1100. The storage subsystem 1150 may include a storage controller 1155that manages data storage and retrieval operations. In some implementations, the storagesubsystem 1150 may comprise a solid state storage 1160 for fast access to frequently useddata and a hard disk storage 1165 for larger capacity storage needs.A client I / O subsystem 1170 may facilitate communication between the client comput-ing architecture 1100 and external devices or networks. The client I / O subsystem 1170 mayinclude an I / O controller 1175 that manages various input and output operations. In somecases, the client I / O subsystem 1170 may comprise a network interface controller 1180 forconnecting to the communication network 105, a display interface 1185 for outputting vi-sual information, and user input devices 1190 for receiving user commands and data.The system bus 1195 may serve as a central communication pathway, allowing data andcontrol signals to be exchanged between the various subsystems of the client computingarchitecture 1100. In some implementations, the system bus 1195 may use a standardizedprotocol to ensure efficient and reliable data transfer between components.In some cases, the client computing architecture 1100 may be utilized to implement theencryption device 140, the decryption device 110, the setup device 125, or the key generationdevice 155 of the encryption system 100. For example, when implementing the encryptiondevice 140, the processing subsystem 1105 may execute encryption algorithms stored in thememory subsystem 1135 or the storage subsystem 1150.The client computing architecture 1100 may be configured to receive a plaintext messageand ABE attributes in a computerized media. In some implementations, this may involve theclient I / O subsystem 1170 receiving data through the network interface controller 1180 orthe user input devices 1190. The received data may then be stored in the memory subsystem1135 or the storage subsystem 1150 for further processing.The processing subsystem 1105 may be configured to receive L bits x1, ... , xL correspond-ing to the ABE attributes. These bits may represent various attributes associated with theplaintext message and may be used in the encryption process. The central processing unit1110 or the AI / ML processing unit 1130 may process these bits as part of the attribute-basedencryption scheme.In some cases, the client computing architecture 1100 may be used to encrypt the plain-text message using the ciphertext and a symmetric encryption key. This encryption processmay be performed by the central processing unit 1110 or a specialized encryption mod-ule within the processing subsystem 1105. The encryption algorithm may utilize the ABEattributes and the symmetric encryption key to generate the ciphertext, which may thenbe stored in the storage subsystem 1150 or transmitted via the network interface controller1180. The client computing architecture 1100 provides a flexible and powerful platform forimplementing various components of the encryption system 100. Its modular design allowsfor efficient processing of encryption and decryption tasks while providing secure storageand communication capabilities.Server-Client Network ArchitectureFIG. 4 illustrates a server client network architecture 1200 that may be utilized in someimplementations of the encryption system. The server client network architecture 1200 maycomprise several interconnected components, including a network infrastructure 1210, clientsystems 1235, server systems 1250, cloud services 1280, and data flow services 1325.A network infrastructure 1210 may form the backbone of the server client network archi-tecture 1200. In some cases, the network infrastructure 1210 may include a router gateway1215 that connects to both a local area network 1220 and a wide area network 1225. Thewide area network 1225 may be connected to a content delivery network 1230, which mayhelp distribute content efficiently across the network.Client systems 1235 may represent various end-user devices that interact with the serverclient network architecture 1200. In some implementations, the client systems 1235 mayinclude a mobile client 1240 and a desktop client 1245. These client systems may connectto the network infrastructure 1210 through the local area network 1220 or the wide areanetwork 1225.Server systems 1250 may provide various services and resources to the client systems1235. In some cases, the server systems 1250 may include a web browser client 1255, whichmay allow users to access web-based services. The server systems 1250 may also comprisean application server 1260, a web server 1265, a database server 1270, and a file storageserver 1275. These servers may work together to process requests, store data, and serve con-tent to the client systems 1235.Cloud services 1280 may offer scalable and flexible computing resources within the serverclient network architecture 1200. In some implementations, the cloud services 1280 may in-clude a load balancer 1285 that distributes incoming network traffic across multiple serversor services. The cloud services 1280 may also comprise cloud compute 1290 resources, whichmay include virtual machines 1295, container services 1300, and serverless functions 1305.An api gateway 1310 may manage and route API requests within the cloud services 1280.The cloud services 1280 may also include cloud storage 1315 for data storage and a databaseservice 1320 for managing structured data.Data flow services 1325 may facilitate the movement and processing of data within theserver client network architecture 1200. In some cases, the data flow services 1325 may in-clude a message queue 1330 for asynchronous communication between components. Thedata flow services 1325 may also comprise stream processing 1335 for real-time data anal-ysis, batch processing 1340 for handling large volumes of data, and an etl pipeline 1345 forextracting, transforming, and loading data between systems.In some implementations, the server client network architecture 1200 may be utilizedto support the encryption system described in relation to FIG. 1. For example, the encryp-tion device 140 may be implemented as part of the cloud compute 1290 resources, utilizingvirtual machines 1295 or container services 1300 to perform encryption operations.The key generation device 155 may be implemented within the server systems 1250,possibly as part of the application server 1260 or a dedicated server for cryptographic op-erations. The storage unit 165 associated with the key generation device 155 may be imple-mented using the database server 1270 or the cloud storage 1315, depending on the specificrequirements for security and accessibility.The decryption device 110 may be implemented on the client systems 1235, such as themobile client 1240 or the desktop client 1245, allowing users to decrypt data locally. Alterna-tively, the decryption device 110 may be implemented as a serverless function 1305 withinthe cloud services 1280, providing on-demand decryption capabilities.In some cases, the communication network 105 described in FIG. 1 may be realizedthrough the combination of the local area network 1220, wide area network 1225, and con-tent delivery network 1230 within the network infrastructure 1210. This multi-layered net-work approach may provide robust connectivity and efficient data transfer between the var-ious components of the encryption system.The server client network architecture 1200 may be designed to accommodate the secu-rity parameters and modulus selection described in the encryption scheme. For instance,the security parameters n and m may be selected based on the desired security level andcomputational efficiency of the overall system. In some implementations, the value of mmay be chosen to be at least twice the value of n log q , where q represents the modulus.The modulus q may be selected to be sufficiently large to accommodate the noise growthduring encryption and decryption operations while maintaining security against knownlattice-based attacks. This selection may impact the design and configuration of the cloudcompute 1290 resources, ensuring that the virtual machines 1295, container services 1300,and serverless functions 1305 have adequate computational power to handle the crypto-graphic operations efficiently.The data flow services 1325 may play a crucial role in managing the encrypted data andassociated metadata. The message queue 1330 may be utilized to handle asynchronous en-cryption and decryption requests, while the stream processing 1335 component may beemployed for real-time analysis of encrypted data streams. The batch processing 1340 ca-pabilities may be leveraged for large-scale encryption or decryption operations, and the etlpipeline 1345 may facilitate the secure transfer of encrypted data between different compo-nents of the system.In some implementations, the load balancer 1285 may be configured to distribute en-cryption and decryption tasks across multiple instances of the encryption device 140 anddecryption device 110, respectively. This distribution may help optimize the utilization ofcomputational resources and maintain system performance under varying load conditions.The api gateway 1310 may provide a secure interface for external systems to interactwith the encryption services, ensuring that only authorized requests are processed and thatthe integrity of the cryptographic operations is maintained. The cloud storage 1315 anddatabase service 1320 may be utilized to store encrypted data, cryptographic keys, and othersensitive information, with appropriate access controls and encryption mechanisms in placeto protect the stored data.By leveraging the various components of the server client network architecture 1200, theencryption system may achieve a balance between security, scalability, and performance.The architecture may allow for flexible deployment options, ranging from on-premises in-stallations using the server systems 1250 to fully cloud-based implementations utilizing thecloud services 1280.Attribute-Based Encryption SystemAn attribute encryption system 1000 may be utilized to implement secure and fine-grainedaccess control over encrypted data. The attribute encryption system 1000 may comprise ahierarchical structure with multiple modules arranged to perform specific functions in theencryption process.In some cases, the attribute encryption system 1000 may include a setup module posi-tioned at the top level of the hierarchy. The setup module may be responsible for initializingthe system parameters and generating the master public-private key pair. The setup modulemay execute a set-up procedure that involves several key steps.One step in the setup procedure may involve sampling a random learning with errors(LWE) matrix B and a correlated gadget trapdoor for B . The LWE matrix B may be a matrixfor security parameters n, m, and modulus q . These security parameters may be selectedbased on the desired security level and computational efficiency of the system.Another step in the setup procedure may involve sampling L random LWE matricesW1, ...,WL . These matrices may be used in conjunction with the LWE matrix B to establishthe encryption scheme’s structure.The setup module may also sample a random LWE matrix B1. This matrix may play acrucial role in the subsequent encryption and decryption processes.A key component of the setup procedure may be establishing a gadget trapdoor T fora matrix related to B ,W1, ... ,WL . The gadget trapdoor T may be constructed using a ran-domized algorithm that ensures the trapdoor has a low norm. This low norm property mayfacilitate efficient preimage sampling operations during the encryption and key generationprocedures. After establishing the gadget trapdoor T , the setup module may compute L matricesA1, ... , AL by right-multiplying B1 by a submatrix of T . These matrices may form part of themaster public key in the attribute-based encryption scheme.Below the setup module in the hierarchical structure, the attribute encryption system1000 may include an encryption module. The encryption module may be responsible forexecuting an encryption procedure to generate ciphertexts from plaintext messages and as-sociated attributes.The encryption procedure may involve generating the ciphertext from an LWE samplec. This process may utilize the matrices and parameters established during the setup pro-cedure. In some cases, the ciphertext generated by this encryption procedure may have asize that is reduced by a factor of L compared to a ciphertext generated according to a pre-existing attribute-based encryption scheme.The attribute encryption system 1000 may also include a key generation module posi-tioned at a lower level of the hierarchy. The key generation module may be responsible forgenerating secret keys associated with specific access policies or attributes.At the bottom level of the hierarchy, the attribute encryption system 1000 may include adecryption module. The decryption module may be responsible for decrypting ciphertextsusing the appropriate secret keys and satisfying the required access policies.In some implementations, the attribute encryption system 1000 may support expand-ing the ciphertext into a form compatible with a pre-existing attribute-based encryptionscheme. This expansion process may involve right-multiplying c by a low-norm matrix de-rived from the gadget trapdoor T and the attribute bits. The expanded ciphertext compat-ible with the pre-existing ABE scheme may comprise an LWE sample matrix obtained byconcatenating A1 ·G , ... , AL −xL ·G , where G is a gadget matrix.It is worth noting that while the expanded ciphertext may be compatible with pre-existingschemes, the expanded ciphertext may have a size that is increased by a factor of L com-pared to the ABE ciphertext prior to expansion. This trade-off between compatibility andciphertext size may be considered when deciding whether to use the expanded form in spe-cific applications.The attribute encryption system 1000 may be designed to operate within the broadercontext of the server client network architecture 1200 described earlier. For instance, thesetup module and encryption module may be implemented as part of the cloud compute1290 resources, utilizing virtual machines 1295 or container services 1300 to perform theirrespective operations securely and efficiently.The key generation module may be implemented within the server systems 1250, pos-sibly as part of the application server 1260 or a dedicated cryptographic server. The storageunits associated with each module may be implemented using the database server 1270 orthe cloud storage 1315, depending on the specific requirements for security and accessibil-ity. The decryption module may be implemented on the client systems 1235, such as themobile client 1240 or the desktop client 1245, allowing users to decrypt data locally. Alterna-tively, the decryption module may be implemented as a serverless function 1305 within thecloud services 1280, providing on-demand decryption capabilities.By leveraging the various components of the server client network architecture 1200,the attribute encryption system 1000 may achieve a balance between security, scalability,and performance. The system may allow for flexible deployment options, ranging from on-premises installations using the server systems 1250 to fully cloud-based implementationsutilizing the cloud services 1280.Reduced-Size Ciphertext Generation SystemFIG. 6 illustrates a ciphertext generation system 600 for creating a ciphertext having arelatively smaller size that is compatible with pre-existing attribute-based encryption (ABE)schemes. The ciphertext generation system 600 may comprise several interconnected mod-ules arranged in a hierarchical structure to implement the encryption functionality.In some cases, the ciphertext generation system 600 may include a setup module 602positioned at the top level of the hierarchy. The setup module 602 may be responsible forexecuting a set-up procedure to generate a master public-private key pair. The setup module602 may contain three components arranged vertically: an lwe matrix sampler 604, a gadgettrapdoor establisher 606, and a master key generator 608.The lwe matrix sampler 604 may be configured to sample random learning with errors(LWE) matrices. In some implementations, the lwe matrix sampler 604 may sample a ran-dom LWE matrix B and L random LWE matrices W1, ...,WL . The LWE matrix B may be amatrix for security parameters n, m, and modulus q . These security parameters may be se-lected based on the desired security level and computational efficiency of the system.The gadget trapdoor establisher 606 may be responsible for establishing a gadget trap-door T for a matrix related to B ,W1, ... ,WL . In some cases, the gadget trapdoor T may beconstructed using a randomized algorithm that ensures the trapdoor has a low norm. Thislow norm property may facilitate efficient preimage sampling operations during the encryp-tion and key generation procedures.The master key generator 608 may be configured to compute L matrices A1, ... , AL byright-multiplying B1 by a submatrix of T . These matrices may form part of the master pub-lic key in the attribute-based encryption scheme. The master key generator 608 may alsooutput and store the master public key, which may comprise B ,B1,T,W1, ..,WL , A1, ... , AL .Below the setup module 602 in the hierarchical structure, the ciphertext generation sys-tem 600 may include an encryption module 610. The encryption module 610 may be respon-sible for executing an encryption procedure to generate ciphertexts from plaintext messagesand associated attributes. The encryption module 610 may contain two components: an lwesample generator 612 and a ciphertext constructor 614.The lwe sample generator 612 may be configured to generate an LWE sample c for aconcatenation of B and ·W1+ ... +xL ·WL . In some implementations, the lwe samplegenerator 612 may receive L bits x1, ... , xL corresponding to the ABE attributes, where eachbit xi is either 0 or 1.The ciphertext constructor 614 may be responsible for generating the ciphertext fromthe LWE sample produced by the lwe sample generator 612. In some cases, the ciphertextconstructor 614 may also encrypt the plaintext message using the ciphertext and a symmet-ric encryption key derived from the LWE sample.The ciphertext generation system 600 may also include a storage module 616 connectedto the ciphertext constructor 614. The storage module 616 may be configured to store thegenerated ciphertext. In some implementations, the storage module 616 may be realizedusing the storage subsystem 1150 of the client computing architecture 1100, which may in-clude solid state storage 1160 or hard disk storage 1165.A transmission module 618, represented by a communication tower symbol, may beconnected to both the storage module 616 and ciphertext constructor 614. The transmis-sion module 618 may be configured to enable the transmission of the generated ciphertext.In some cases, the transmission module 618 may utilize the network interface controller1180 of the client computing architecture 1100 to transmit the ciphertext to a recipient de-vice over the communication network 105.The components of the ciphertext generation system 600 may be arranged to show theflow of operations from initial setup through encryption and transmission. The modulesmay be connected by lines indicating data flow paths between different components of thesystem 600.In some implementations, the ciphertext generation system 600 may support expand-ing the ciphertext into a form compatible with a pre-existing ABE scheme. This expansionprocess may involve right-multiplying c by a low-norm matrix derived from the gadget trap-door T and the attribute bits x1, ..., xL . The expanded ciphertext compatible with the pre-existing ABE scheme may comprise an LWE sample matrix obtained by concatenating A1 −x1 ·G , ... , AL −xL ·G , where G is a gadget matrix.The ciphertext generation system 600 may be designed to operate within the broadercontext of the server client network architecture 1200. For instance, the setup module 602and encryption module 610 may be implemented as part of the cloud compute 1290 re-sources, utilizing virtual machines 1295 or container services 1300 to perform their respec-tive operations securely and efficiently.The storage module 616 may be implemented using the database server 1270 or thecloud storage 1315, depending on the specific requirements for security and accessibility.The transmission module 618 may leverage the network infrastructure 1210, including thelocal area network 1220 and wide area network 1225, to transmit the generated ciphertext toauthorized recipients.By utilizing the various components of the server client network architecture 1200, theciphertext generation system 600 may achieve a balance between security, scalability, andperformance. The system may allow for flexible deployment options, ranging from on-premisesinstallations using the server systems 1250 to fully cloud-based implementations utilizingthe cloud services 1280.Throughout this disclosure, various terms and phrases are used to describe features ofthe disclosed technology. It is to be understood that these terms and phrases may encom-pass a variety of meanings and definitions, as is common in the field of technology andpatent law. The definitions of these terms may vary depending on the context in which theyare used, the specific embodiment being described, or the interpretation of the technologyby those skilled in the art.In various embodiments, certain variable names, symbols, or labels may be used in theclaims to represent various elements, components, or steps of the described methods, sys-tems, and apparatuses. These variable names, symbols, or labels are provided for conve-nience and clarity in describing the claimed subject matter. However, it should be under-stood that the use of such variable names, symbols, or labels in the claims does not nec-essarily limit these elements, components, or steps to being the same specific entities de-scribed in the specification or in other parts of the disclosure. The variable names, symbols,or labels used in the claims should be interpreted broadly and may encompass various im-plementations, variations, or equivalents of the described elements, components, or steps,unless explicitly stated otherwise or clearly limited by the context of the claim. As such, thescope of the claims is not confined to the specific examples or embodiments described inthe specification, but rather extends to the full breadth of the inventive concepts disclosedherein. For instance, terms such as "computing device," "processor," "memory," and "network"may refer to a wide range of devices, components, systems, and configurations known in theart, and their specific definitions may differ based on the implementation or design of thesystem. Similarly, phrases like "securely storing," "computing a vector," and "generating amessage" may involve various methods, techniques, and processes that achieve the same orsimilar outcomes but may be executed in different manners.It is also to be understood that the use of terms in the singular or plural form is notintended to limit the scope of the claims. For example, the mention of "a computing device"does not preclude the presence of multiple computing devices within a system. Likewise,references to "a network" may include various interconnected networks or a single networkcomprising multiple segments or layers.Furthermore, the use of the term "may" in relation to an action or feature indicates thatthe action or feature is possible, but not necessarily mandatory. This term is used to describeoptional or alternative aspects of the disclosed technology that provide flexibility in how thetechnology may be implemented or utilized.The definitions provided herein are intended to serve as examples and are not exhaus-tive. Those skilled in the art may ascribe different meanings to these terms based on thecontext, the specific technology being described, or the advancements in the field. There-fore, the definitions of the terms and phrases used in this disclosure and the claims are to beinterpreted broadly and in a manner consistent with the understanding of those skilled inthe relevant art.The use of the word "a" or "an" when used in conjunction with the claims herein is tobe interpreted as including one or more than one of the element it introduces. Similarly, theuse of the term "or" is intended to be inclusive, such that the phrase "A or B" is intended toinclude A, B, or both A and B, unless explicitly stated otherwise.Reference throughout the specification to "one embodiment," "another embodiment,""an embodiment," and so forth, means that a particular feature, structure, or characteris-tic described in connection with the embodiment is included in at least one embodimentof the present disclosure, and may not necessarily be present in all embodiments. Further-more, the particular features, structures, or characteristics may be combined in any suitablemanner in one or more embodiments without limitation.The use of the terms "first," "second," and the like does not imply any order or se-quence, but are used to distinguish one element from another, and the terms "top," "bot-tom," "front," "back," "leading," "trailing," and the like are used for descriptive purposesand are not necessarily to be construed as limiting.As used herein, the term "processor" refers to any computing entity capable of execut-ing instructions to perform a specific set of operations, whether implemented in hardware,firmware, software, or any combination thereof. This definition includes a broad range ofprocessing technologies and architectures. The term encompasses general-purpose proces-sors such as Central Processing Units (CPUs), specialized processors such as Graphics Pro-cessing Units (GPUs), as well as highly specialized hardware accelerators such as NeuralProcessing Units (NPUs) for artificial intelligence applications and Tensor Processing Units(TPUs) for machine learning workloads.The term also encompasses reconfigurable computing architectures such as Field - Pro-grammable Gate Arrays (FPGAs) for applications requiring specialized processing configu-rations, Application - Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs),Systolic Array Processors, and emerging computing paradigms such as Quantum Proces-sors that leverage principles of quantum mechanics. System on Chip (SoC) designs, het-erogeneous computing systems, Edge Computing Processors for distributed network ap-plications, cloud-based and distributed processors, multi-core and parallel processors, andNeuromorphic processors that draw inspiration from biological neural architectures are allencompassed within this definition.The term "processor" also encompasses the associated memory hierarchies, includingprimary memory (such as RAM), secondary storage (such as hard drives and SSDs), andcache memory, which work in conjunction with the processor to store and retrieve data nec-essary for executing instructions. In this patent application, any reference to a "processor"should be interpreted broadly to include any type of processing unit capable of performingthe described functions, regardless of its specific implementation, architecture, or physicalform. As used herein, the term "messages" may refer to any form of data or information thatcan be processed, transmitted, or stored in a digital format. Messages may include arbitrary-length plaintext messages, pre-hashed messages, concatenated messages, binary data, net-work protocol messages, database records, and time-stamped messages. Messages may becomposed of characters, symbols, or binary data and may represent various forms of con-tent such as text, numbers, multimedia, executable code, or any other data that can be dig-itally encoded. Messages may be used as input for cryptographic functions, such as keyedhash functions, where they are transformed into a fixed-size hash value influenced by a se-cret cryptographic key.The term "messages" encompasses a wide range of data types and structures, from sim-ple text strings to complex structured data, and may include metadata, headers, footers, orother information that facilitates the processing, transmission, or interpretation of the con-tent. Messages may be generated by users, systems, or processes and may be intended forvarious purposes, including communication, authentication, verification, logging, or anyother function that involves the use of digital data.Messages may also include data formats specific to artificial intelligence and machinelearning applications, such as tensors, feature vectors, embeddings, model parameters, acti-vation maps, training examples, and inference requests. In distributed and edge computingcontexts, the term "messages" further extends to include event streams, state updates, ser-vice requests, synchronization messages, and smart contract transactions used in blockchainplatforms. As used herein, the terms "store," "storing," "storage," or variants thereof refer to anymeans, methods, systems, or processes for recording, retaining, or preserving data in a re-trievable format. This terminology encompasses a broad spectrum of technologies and mech-anisms that may be employed to maintain information for future access or reference.The term includes traditional electronic storage technologies such as magnetic storage(including hard disk drives, magnetic tape, and floppy disks), optical storage (including op-tical discs, holographic storage, and optical tape), and solid-state storage (including solid-state drives, flash memory, static random-access memory, dynamic random-access mem-ory, and read-only memory). It also encompasses emerging storage technologies such asDNA storage, molecular storage, quantum storage, and photonic storage.Storage terminology may refer to various architectural organizations and hierarchies ofdata repositories. This includes primary storage (main memory, cache memory) designedfor rapid access during processing operations; secondary storage providing non-volatile re-tention of larger data volumes; and tertiary storage for archival purposes. The terminologyextends to distributed storage architectures such as network-attached storage (NAS), stor-age area networks (SAN), direct-attached storage (DAS), and object storage systems. It alsoincludes cloud-based storage configurations, including public, private, and hybrid cloudstorage implementations; edge storage systems located at network peripheries; and fog stor-age systems distributed between centralized and edge locations.The definition encompasses storage virtualization technologies that abstract physicalstorage resources and present them as logical storage units, including virtual disks, software-defined storage, and storage hypervisors. It also includes storage orchestration systems thatmanage data placement, replication, and migration across distributed infrastructures.The terminology extends to various data organization and management paradigms. Thisincludes file systems that organize data into files and directories; block storage systems thatmanage data as fixed-sized blocks; object storage systems that handle data as discrete ob-jects with metadata; and content-addressable storage systems that retrieve data based oncontent rather than location. It also includes specialized storage structures such as databases,data lakes, data warehouses, and knowledge repositories.Storage terminology encompasses various operational characteristics and capabilities ofstorage systems. This includes persistent storage that maintains data integrity across powercycles; volatile storage that requires continuous power to retain data; and non-volatile stor-age that preserves data without power. It also includes immutable storage that preventsmodification of stored data; append-only storage that allows additions but not modifica-tions; and version-controlled storage that maintains historical states of data. The term fur-ther encompasses encrypted storage that protects data confidentiality; redundant storagethat duplicates data to prevent loss; and resilient storage that maintains availability despitecomponent failures.In specialized computing contexts, storage terminology may refer to domain-specificstorage mechanisms. For blockchain and distributed ledger technologies, this includes on-chain storage within the blockchain itself and off-chain storage that maintains referencesto externally stored data. For neural networks and artificial intelligence systems, it includesweight storage for maintaining learned parameters and activation storage for intermediatecomputational results. For quantum computing systems, it refers to quantum state storagethat preserves quantum information, while for edge computing, it includes transient storagefor temporary data processing at network boundaries.The term "storage" also encompasses the protocols, interfaces, and access methods usedto interact with stored data. This includes file access protocols (such as NFS, SMB, andHDFS), block access protocols (such as iSCSI, Fibre Channel, and ATA), and object accessprotocols (such as S3, Swift, and CDMI). It also includes direct memory access mechanisms,memory-mapped file interfaces, and storage controller interfaces.The term "database" should be construed to mean a blockchain, distributed ledger tech-nology, key-value store, document-oriented database, graph database, time-series database,in-memory database, columnar database, object-oriented database, hierarchical database,network database, or any other structured data storage system capable of storing and re-trieving information. This may include traditional relational database management systems(RDBMS), NoSQL databases, NewSQL databases, or hybrid database systems that combinemultiple database paradigms. The database may be centralized, distributed, or decentral-ized, and may employ various data models, indexing strategies, and query languages to or-ganize and access the stored information. It may also incorporate features such as ACID(Atomicity, Consistency, Isolation, Durability) compliance, eventual consistency, sharding,replication, or partitioning to ensure data integrity, availability, and scalability. The databasemay be hosted on-premises, in the cloud, or in a hybrid environment, and may support var-ious access methods including direct queries, API calls, or event-driven architectures.The term "database" further encompasses specialized data storage and managementsystems designed for particular domains or use cases. This includes blockchain and dis-tributed ledger technologies used for secure, decentralized transaction records, edge databasesoptimized for resource-constrained environments, vector databases for high-dimensionaldata, time-series databases for temporal data management, knowledge graphs for repre-senting interconnected information, federated databases for integrating autonomous sys-tems, and emerging paradigms such as quantum databases that leverage quantum comput-ing principles.The terms "connected," "coupled," or any variant thereof, mean any direct or indirectconnection or coupling between two or more elements, and may encompass the presenceof one or more intermediate elements between the two elements that are connected or cou-pled to each other.In the context of modern computing architectures and network topologies, these termsmay also refer to various connection modalities. This includes physical connections throughwired or wireless interfaces, logical connections operating independently of the physicallayer, API connections allowing software components to communicate, and microserviceconnections in distributed architectures. The terminology extends to edge-to-cloud con-nections for distributed processing environments, blockchain connections for distributedledger systems, quantum connections for secure communication, and neural network con-nections for artificial intelligence systems.nyuAs used herein, the term "display" or "displaying" refers to any means, method, appa-ratus, or process for visually presenting or otherwise conveying information to a user. Thisterminology encompasses a broad spectrum of technologies and presentation modalitiesthat may be employed to render content perceivable by a user. The term includes tradi-tional display technologies such as cathode ray tubes (CRTs), liquid crystal displays (LCDs),light-emitting diode (LED) displays, organic light-emitting diode (OLED) displays, micro-LED displays, and electronic paper displays. It also encompasses specialized display typessuch as transparent displays, flexible displays, foldable displays, stretchable displays, andholographic displays.The term "display" may also refer to projection systems, including traditional projectors,laser projectors, pico projectors, and holographic projection systems. It further includes im-mersive display technologies such as head-mounted displays (HMDs), virtual reality (VR)headsets, augmented reality (AR) glasses, mixed reality (MR) systems, and smart contactlenses. The terminology extends to ambient display methods that integrate visual informa-tion into the environment, such as smart mirrors, interactive surfaces, projection mappingsystems, and volumetric displays.The definition also encompasses non-visual display modalities that may complement orsubstitute for visual displays. This includes auditory displays such as speech output systems,sonification interfaces, and spatial audio; haptic displays that communicate through tactilefeedback, vibration patterns, or force feedback; and other sensory output mechanisms suchas olfactory displays and thermotactile interfaces. Multimodal displays that combine multi-ple sensory channels for information presentation are also included within this terminology.The term "display" further encompasses the software and computational componentsinvolved in rendering information. This includes rendering engines, graphics processingpipelines, display servers, and compositing systems. It also includes specialized display ren-dering techniques such as rasterization, ray tracing, vector graphics, procedural genera-tion, and neural rendering. The term extends to user interface paradigms such as graphicaluser interfaces (GUIs), natural user interfaces (NUIs), voice user interfaces (VUIs), brain-computer interfaces (BCIs), and ambient intelligence systems.In the context of accessibility, the term "display" includes assistive technologies and al-ternative display methods designed to accommodate diverse user needs. This encompassesscreen readers, braille displays, audio descriptions, high-contrast modes, color-shifted pre-sentations, and other adaptive display mechanisms. The terminology also includes displaypersonalization techniques such as adaptive interfaces, contextual displays, and user-specificrendering optimizations.The description of the embodiments of the present disclosure is intended to be illustra-tive, and not to limit the scope of the claims. Many alternatives, modifications, and varia-tions will be apparent to those skilled in the art. A number of implementations have beendescribed. Nevertheless, it will be understood that various modifications may be made with-out departing from the spirit and scope of the disclosure. Accordingly, other implementa-tions are within the scope of the following claims.

Claims

CLAIMS1. A method for creating a ciphertext having a relatively smaller size that is compatible withpre-existing attribute-based encryption (ABE) schemes, the method comprising:(a) receiving, by a first processor, a plaintext message and ABE attributes in acomputerized media;(b) storing, by the first processor, the plaintext message and the ABE attributes in anon-transitory computer-readable storage medium;(c) executing, by a second processor, a set-up procedure to generate a masterpublic-private key pair, the set-up procedure further comprising:(i) sampling a random learning with errors (LWE) matrix B and a correlated gadgettrapdoor for B , wherein the LWE matrix B is a matrix for security parameters n,m, and modulus q ;(ii) sampling L random LWE matrices W1, ...,WL ;(iii) sampling a random LWE matrix B1;(iv) establishing a gadget trapdoor T for a matrix related to B ,W1, ... ,WL ;(v) computing L matrices A1, ... , AL by right-multiplying B1 by a submatrix of T ;(vi) outputting the master public key, the master public key comprisingB ,B1,T,W1, ..,WL , A1, ... , AL , wherein A1, ... , AL is a master public key from thepre-existing ABE scheme; and(vii) storing the master public key in the non-transitory computer-readable storagemedium, wherein the master private key is the gadget trapdoor for B ;(d) executing, by the first processor, an encryption procedure, the encryption procedurecomprising: (i) receiving L bits x1, ... , xL corresponding to the ABE attributes, wherein each bitxi is either 0 or 1;(ii) generating the ciphertext from an LWE sample c for a concatenation of B andB1 +x1 ·W1 + ... +xL ·WL ; and(iii) encrypting the plaintext message using the ciphertext and a symmetricencryption key derived from the LWE sample;(e) storing, by the first processor, the ciphertext in the non-transitory computer-readablestorage medium; and(f) transmitting, by a network interface device communicatively coupled to the firstprocessor, the ciphertext to a recipient device over a communication network.

2. The method of claim 1, wherein the ciphertext has a size that is reduced by a factor of Lcompared to a ciphertext generated according to the pre-existing scheme.

3. The method of claim 1, further comprising:(a) expanding the ciphertext into a form compatible with the pre-existing ABE scheme byright-multiplying c by a low-norm matrix derived from the gadget trapdoor T and theattribute bits x1, ..., xL , wherein the expanded ciphertext compatible with thepre-existing ABE scheme comprises an LWE sample matrix obtained by concatenatingA1 −x1 ·G , ... , AL −xL ·G , wherein G is a gadget matrix; and(b) storing the expanded ciphertext in a non-transitory computer-readable storagemedium.

4. The method of claim 3, wherein the expanded ciphertext has a size that is increased by afactor of L compared to the ABE ciphertext prior to expansion.

5. The method of claim 1, wherein the security parameters n and m are selected based on adesired security level and computational efficiency, with m being at least twice the value ofn log q .

6. The method of claim 1, wherein the modulus q is selected to be sufficiently large toaccommodate the noise growth during encryption and decryption operations whilemaintaining security against known lattice-based attacks.

7. The method of claim 1, wherein the gadget trapdoor T is constructed using arandomized algorithm that ensures the trapdoor has a low norm, facilitating efficientpreimage sampling operations during the encryption and key generation procedures.

8. The method of claim 1, wherein the gadget trapdoor T is a low-norm matrix that enablesefficient preimage sampling and satisfies the relation [IL ⊗B |W ] ·T = IL ⊗G , where IL is theL×L identity matrix, ⊗ denotes the tensor product, W is the concatenation of matricesW1, ...,WL , and G is a gadget matrix in Zn×mq with a public, fixed structure that enablesefficient decomposition operations.

9. A system for creating a ciphertext having a relatively smaller size that is compatible withpre-existing attribute-based encryption (ABE) schemes, the system comprising:(a) a first processor;(b) a non-transitory computer-readable storage medium;(c) a second processor;(d) a network interface device communicatively coupled to the first processor;(e) the first processor configured to:(i) receive a plaintext message and ABE attributes in a computerized media;(ii) store the plaintext message and the ABE attributes in the non-transitorycomputer-readable storage medium;(f) the second processor configured to execute a set-up procedure to generate a masterpublic-private key pair, the set-up procedure comprising:(i) sampling a random learning with errors (LWE) matrix B and a correlated gadgettrapdoor for B , wherein the LWE matrix B is a matrix for security parameters n,m, and modulus q ;(ii) sampling L random LWE matrices W1, ...,WL ;(iii) sampling a random LWE matrix B1;(iv) establishing a gadget trapdoor T for a matrix related to B ,W1, ... ,WL ;(v) computing L matrices A1, ... , AL by right-multiplying B1 by a submatrix of T ;(vi) outputting the master public key, the master public key comprisingB ,B1,T,W1, ..,WL , A1, ... , AL , wherein A1, ... , AL is a master public key from thepre-existing ABE scheme; and(vii) storing the master public key in the non-transitory computer-readable storagemedium, wherein the master private key is the gadget trapdoor for B ;(g) the first processor further configured to execute an encryption procedure, theencryption procedure comprising:(i) receiving L bits x1, ... , xL corresponding to the ABE attributes, wherein each bitxi is either 0 or 1;(ii) generating the ciphertext from an LWE sample c for a concatenation of B andB1 +x1 ·W1 + ... +xL ·WL ; and(iii) encrypting the plaintext message using the ciphertext and a symmetricencryption key derived from the LWE sample;(h) the first processor further configured to store the ciphertext in the non-transitorycomputer-readable storage medium; and(i) the network interface device configured to transmit the ciphertext to a recipientdevice over a communication network.

10. The system of claim 9, wherein the ciphertext has a size that is reduced by a factor of Lcompared to a ciphertext generated according to the pre-existing scheme.

11. The system of claim 9, wherein:(a) the first processor is further configured to expand the ciphertext into a formcompatible with the pre-existing ABE scheme by right-multiplying c by a low-normmatrix derived from the gadget trapdoor T and the attribute bits x1, ..., xL , wherein theexpanded ciphertext compatible with the pre-existing ABE scheme comprises an LWEsample matrix obtained by concatenating A1 −x1 ·G , ... , AL −xL ·G , wherein G is agadget matrix; and(b) the non-transitory computer-readable storage medium is configured to store theexpanded ciphertext.

12. The system of claim 11, wherein the expanded ciphertext has a size that is increased bya factor of L compared to the ABE ciphertext prior to expansion.

13. The system of claim 9, wherein the security parameters n and m are selected based on adesired security level and computational efficiency, with m being at least twice the value ofn log q .

14. The system of claim 9, wherein the modulus q is selected to be sufficiently large toaccommodate the noise growth during encryption and decryption operations whilemaintaining security against known lattice-based attacks.

15. The system of claim 9, wherein the gadget trapdoor T is constructed using arandomized algorithm that ensures the trapdoor has a low norm, facilitating efficientpreimage sampling operations during the encryption and key generation procedures.

16. The system of claim 9, wherein the gadget trapdoor T is a low-norm matrix that enablesefficient preimage sampling and satisfies the relation [IL ⊗B |W ] ·T = IL ⊗G , where IL is theL×L identity matrix, ⊗ denotes the tensor product, W is the concatenation of matricesW1, ...,WL , and G is a gadget matrix in Zn×mq with a public, fixed structure that enablesefficient decomposition operations.

17. A non-transitory computer-readable storage medium storing instructions that, whenexecuted by one or more processors, cause the one or more processors to perform amethod for creating a ciphertext having a relatively smaller size that is compatible withpre-existing attribute-based encryption (ABE) schemes, the method comprising:(a) receiving a plaintext message and ABE attributes in a computerized media;(b) storing the plaintext message and the ABE attributes in a non-transitorycomputer-readable storage medium;(c) executing a set-up procedure to generate a master public-private key pair, the set-upprocedure further comprising:(i) sampling a random learning with errors (LWE) matrix B and a correlated gadgettrapdoor for B , wherein the LWE matrix B is a matrix for security parameters n,m, and modulus q ;(ii) sampling L random LWE matrices W1, ...,WL ;(iii) sampling a random LWE matrix B1;(iv) establishing a gadget trapdoor T for a matrix related to B ,W1, ... ,WL ;(v) computing L matrices A1, ... , AL by right-multiplying B1 by a submatrix of T ;(vi) outputting the master public key, the master public key comprisingB ,B1,T,W1, ..,WL , A1, ... , AL , wherein A1, ... , AL is a master public key from thepre-existing ABE scheme; and(vii) storing the master public key in the non-transitory computer-readable storagemedium, wherein the master private key is the gadget trapdoor for B ;(d) executing an encryption procedure, the encryption procedure comprising:(i) receiving L bits x1, ... , xL corresponding to the ABE attributes, wherein each bitxi is either 0 or 1;(ii) generating the ciphertext from an LWE sample c for a concatenation of B andB1 +x1 ·W1 + ... +xL ·WL ; and(iii) encrypting the plaintext message using the ciphertext and a symmetricencryption key derived from the LWE sample;(e) storing the ciphertext in the non-transitory computer-readable storage medium; and(f) transmitting the ciphertext to a recipient device over a communication network.

18. The non-transitory computer-readable storage medium of claim 17, wherein theciphertext has a size that is reduced by a factor of L compared to a ciphertext generatedaccording to the pre-existing scheme.

19. The non-transitory computer-readable storage medium of claim 17, wherein themethod further comprises:(a) expanding the ciphertext into a form compatible with the pre-existing ABE scheme byright-multiplying c by a low-norm matrix derived from the gadget trapdoor T and theattribute bits x1, ..., xL , wherein the expanded ciphertext compatible with thepre-existing ABE scheme comprises an LWE sample matrix obtained by concatenatingA1 −x1 ·G , ... , AL −xL ·G , wherein G is a gadget matrix; and(b) storing the expanded ciphertext in a non-transitory computer-readable storagemedium.

20. The non-transitory computer-readable storage medium of claim 17, wherein the gadgettrapdoor T is a low-norm matrix that enables efficient preimage sampling and satisfies therelation [IL ⊗B |W ] ·T = IL ⊗G , where IL is the L×L identity matrix, ⊗ denotes the tensorproduct, W is the concatenation of matrices W1, ...,WL , and G is a gadget matrix in Zn×mqwith a public, fixed structure that enables efficient decomposition operations.

Citation Information

Patent Citations

  • Compressible (F)HE with Applications to PIR

    US20210111865A1

  • Obfuscation of executable instruction sets for enhanced security

    US20230315821A1

  • Decentralized multi-authority attribute-based encryption

    US20230379153A1