Identity-Based Encryption Extensions via Multi-Instance Construction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponent inversion class of identity-based encryption (IBE) schemes lacks extensions, limiting their flexibility and functionality compared to other pairing-based IBE schemes, despite being computationally efficient and requiring minimal bandwidth.

Innovation Solution

The development of IBE extensions for the exponent inversion class, including hierarchical, fuzzy, and attribute-based extensions, by transforming linear IBE schemes into these forms while preserving security properties and efficiency, using a generic construction template that supports multiple instances and parallel simulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If exponent inversion IBE schemes are used, then computational efficiency and bandwidth usage are improved, but functionality and flexibility are limited due to lack of extensions

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidfunctionality
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal construction template that enables exponent inversion IBE schemes to support multiple extension types (hierarchical, attribute-based, fuzzy, threshold) that were previously only available in other IBE schemes. This makes the exponent inversion scheme multi-functional while preserving its efficiency advantages.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the identity into multiple components and applies separate IBE instances to each component, then combines the results. This segmentation approach enables complex identity constructs and extensions while maintaining the efficiency of the underlying exponent inversion scheme.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If IBE extensions are added to enhance functionality, then adaptability is improved, but system complexity increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a generic construction template as an intermediary layer that sits between the basic exponent inversion IBE scheme and the various extensions (hierarchical, attribute-based, fuzzy, threshold). This template absorbs the complexity of extensions while preserving the simplicity and efficiency of the core scheme.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a dimensional layer to the IBE system by introducing multiple IBE instances and combining them through a generic construction template. This dimensional approach enables extensions without fundamentally complicating the underlying scheme structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If multiple IBE instances are used to create extensions, then functionality is enhanced, but computational overhead increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidcomputational overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent changes parameters such as the number of IBE instances and the structure of identity components to achieve desired functionality. By carefully selecting and optimizing these parameters, the system gains extension capabilities while controlling computational overhead through efficient parameter choices.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8023646B2Identity-based-encryption extensions formed using multiple instances of an identity based encryption scheme
Publication Date: 2011.09.20 MICRO FOCUS LLC
  • US8023646B2 patent drawing
  • US8023646B2 patent drawing
  • US8023646B2 patent drawing

AI summary

IBE extensions to IBE schemes may be provided by creating multiple instances of the same IBE scheme, where each instance has an associated IBE master key and corresponding IBE public parameters. During encryption, an IBE extension identity for each instance of the IBE scheme may be mapped to a corresponding component identity. A message may be encrypted using the component identities to create multiple ciphertexts. The ciphertexts can be combined and sent to a recipient. The recipient can request a private key. The private key may be generated by mapping the IBE extension identity into a component identity in each instance, by extracting private keys for each of the component identities, and by combining the private keys into a single IBE extension private key.