Lattice Proxy Re-Encryption With Forward-Secure Attribute Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attribute-based conditional proxy re-encryption methods lack flexibility in delegation mechanisms, rely on traditional number-theoretic problems vulnerable to quantum attacks, and lack forward security for the delegatee computing device.

Innovation Solution

A forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption method is proposed, utilizing the Learning With Errors (LWE) problem on lattices to enable fine-grained transformation of re-encrypted ciphertexts with an asynchronous key update mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional number-theoretic problems are used for cryptographic security, then the encryption and decryption operations are computationally efficient, but the system becomes vulnerable to quantum computer attacks

Engineering Contradiction:
Improvequantum attack resistanceVSAvoidcryptographic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from traditional number-theoretic parameters (based on integer factorization and discrete logarithm problems) to lattice-based parameters (based on the hardness of lattice problems such as Shortest Vector Problem and Closest Vector Problem). This parameter change enables quantum attack resistance while maintaining computational efficiency through the use of lattice cryptography primitives including trapdoor functions and error-correcting codes embedded in the lattice structure

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mathematical mechanism of traditional public-key cryptography (RSA, ElGamal) with a fundamentally different mechanism based on lattice theory and geometric hardness problems. The substitution involves using lattice-based key generation, encryption, and decryption algorithms that rely on the computational difficulty of finding short vectors in high-dimensional lattices, which is resistant to both classical and quantum computational attacks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If a proxy obtains a re-encryption key, then the delegatee can decrypt all ciphertexts of the delegator, but this requires absolute trust in the proxy which is impractical in complex application scenarios

Engineering Contradiction:
Improvedelegation flexibilityVSAvoidtrust requirement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the re-encryption capability by introducing attribute-based controls that divide the proxy's power into multiple independent dimensions. Instead of a single re-encryption key that grants universal access, the system uses multiple attribute-associated keys and policies that must be satisfied simultaneously. This segmentation allows the delegator to grant fine-grained access rights based on specific attributes (e.g., department, role, clearance level) without requiring absolute trust, as the proxy cannot exceed the defined attribute boundaries

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic attribute-based policies that can be updated and modified without regenerating the entire re-encryption system. The access control structure evolves dynamically based on changing attributes and policies, allowing the delegator to adapt delegation rights over time. The system supports policy updates, attribute additions, and revocation mechanisms that maintain security while providing operational flexibility in complex scenarios

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If conditional proxy re-encryption is implemented to control the re-encryption process, then fine-grained access control is achieved, but the system lacks forward security for the delegatee computing device

Engineering Contradiction:
Improveaccess control precisionVSAvoidforward security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements periodic key update mechanisms where the delegatee's private key is refreshed at regular intervals or upon specific triggering events. The system generates time-bound or version-bound re-encryption keys that become invalid after a predetermined period, forcing periodic key rotation. This periodic action ensures that even if a key is compromised, the window of vulnerability is limited to the duration between key updates, providing forward security while maintaining precise attribute-based access control

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent incorporates preliminary security measures by pre-establishing key update schedules and revocation mechanisms before potential security breaches occur. The system pre-generates backup keys, establishes update triggers, and configures automatic key rotation policies in advance. These preliminary actions ensure that forward security is proactively maintained through pre-planned key management strategies, preventing retrospective security failures even if current keys are compromised

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260074881A1Forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption method
Publication Date: 2026.03.12 JINAN UNIVERSITY
  • US20260074881A1 patent drawing
  • US20260074881A1 patent drawing
  • US20260074881A1 patent drawing

AI summary

The present invention provides a computer-implemented method for forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption. The method includes: generating and disclosing public parameters by an authorization manager; generating public-private key pairs for delegator and delegatee; encrypting a plaintext using the delegator's public key and an attribute vector to produce a ciphertext; generating an updated public key and updated ciphertext for the delegatee; generating a re-encryption key associated with a control strategy; re-encrypting the ciphertext via a re-encryption component to produce a re-encrypted ciphertext; generating an updated private key by the delegatee; and decrypting the ciphertext or re-encrypted ciphertext using the updated private key. Based on lattice-based cryptography and an asynchronous key update mechanism, the method achieves forward security, quantum resistance, and fine-grained access control for secure data sharing.