Lattice Proxy Re-Encryption With Forward-Secure Attribute Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attribute-based conditional proxy re-encryption methods lack flexibility in delegation mechanisms, rely on traditional number-theoretic problems vulnerable to quantum attacks, and lack forward security for the delegatee computing device.
Innovation Solution
A forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption method is proposed, utilizing the Learning With Errors (LWE) problem on lattices to enable fine-grained transformation of re-encrypted ciphertexts with an asynchronous key update mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional number-theoretic problems are used for cryptographic security, then the encryption and decryption operations are computationally efficient, but the system becomes vulnerable to quantum computer attacks
Solution Approach 1:
The patent transitions from traditional number-theoretic parameters (based on integer factorization and discrete logarithm problems) to lattice-based parameters (based on the hardness of lattice problems such as Shortest Vector Problem and Closest Vector Problem). This parameter change enables quantum attack resistance while maintaining computational efficiency through the use of lattice cryptography primitives including trapdoor functions and error-correcting codes embedded in the lattice structure
Solution Approach 2:
The patent replaces the mathematical mechanism of traditional public-key cryptography (RSA, ElGamal) with a fundamentally different mechanism based on lattice theory and geometric hardness problems. The substitution involves using lattice-based key generation, encryption, and decryption algorithms that rely on the computational difficulty of finding short vectors in high-dimensional lattices, which is resistant to both classical and quantum computational attacks
2Ease of operation
If a proxy obtains a re-encryption key, then the delegatee can decrypt all ciphertexts of the delegator, but this requires absolute trust in the proxy which is impractical in complex application scenarios
Solution Approach 1:
The patent segments the re-encryption capability by introducing attribute-based controls that divide the proxy's power into multiple independent dimensions. Instead of a single re-encryption key that grants universal access, the system uses multiple attribute-associated keys and policies that must be satisfied simultaneously. This segmentation allows the delegator to grant fine-grained access rights based on specific attributes (e.g., department, role, clearance level) without requiring absolute trust, as the proxy cannot exceed the defined attribute boundaries
Solution Approach 2:
The patent introduces dynamic attribute-based policies that can be updated and modified without regenerating the entire re-encryption system. The access control structure evolves dynamically based on changing attributes and policies, allowing the delegator to adapt delegation rights over time. The system supports policy updates, attribute additions, and revocation mechanisms that maintain security while providing operational flexibility in complex scenarios
3Adaptability or versatility
If conditional proxy re-encryption is implemented to control the re-encryption process, then fine-grained access control is achieved, but the system lacks forward security for the delegatee computing device
Solution Approach 1:
The patent implements periodic key update mechanisms where the delegatee's private key is refreshed at regular intervals or upon specific triggering events. The system generates time-bound or version-bound re-encryption keys that become invalid after a predetermined period, forcing periodic key rotation. This periodic action ensures that even if a key is compromised, the window of vulnerability is limited to the duration between key updates, providing forward security while maintaining precise attribute-based access control
Solution Approach 2:
The patent incorporates preliminary security measures by pre-establishing key update schedules and revocation mechanisms before potential security breaches occur. The system pre-generates backup keys, establishes update triggers, and configures automatic key rotation policies in advance. These preliminary actions ensure that forward security is proactively maintained through pre-planned key management strategies, preventing retrospective security failures even if current keys are compromised
Data Source
AI summary
The present invention provides a computer-implemented method for forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption. The method includes: generating and disclosing public parameters by an authorization manager; generating public-private key pairs for delegator and delegatee; encrypting a plaintext using the delegator's public key and an attribute vector to produce a ciphertext; generating an updated public key and updated ciphertext for the delegatee; generating a re-encryption key associated with a control strategy; re-encrypting the ciphertext via a re-encryption component to produce a re-encrypted ciphertext; generating an updated private key by the delegatee; and decrypting the ciphertext or re-encrypted ciphertext using the updated private key. Based on lattice-based cryptography and an asynchronous key update mechanism, the method achieves forward security, quantum resistance, and fine-grained access control for secure data sharing.


