Pairing-Based Broadcast Encryption Beyond the √N Parameter Barrier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing broadcast encryption schemes face challenges in achieving short parameters, particularly short ciphertexts and public keys, while maintaining adaptive security against unbounded collusions, with prior work being limited to O(√{square root over (N)})-sized parameters.

Innovation Solution

A pairing-based broadcast encryption scheme with O(N1/3)-sized parameters is developed, utilizing a novel approach that encodes set membership as a degree 3 polynomial and employs quadratic reconstruction techniques, achieving adaptive security through the bilateral k-Lin assumption in prime-order bilinear groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If pairing-based broadcast encryption schemes are designed with short parameters, then ciphertext and key sizes are reduced, but security against unbounded collusions deteriorates

Engineering Contradiction:
Improveparameter sizeVSAvoidsecurity against collusions
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The patent transitions from traditional pairing-based approaches to lattice-based cryptography, representing a fundamental dimension change in the cryptographic primitive. This allows achieving o(√N) parameter sizes while maintaining adaptive security against unbounded collusions, breaking the long-standing √N barrier that constrained previous schemes

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Length of stationary object

If public key size is reduced in broadcast encryption, then system efficiency improves, but the ability to maintain adaptive security deteriorates

Engineering Contradiction:
Improvepublic key sizeVSAvoidadaptive security
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The patent changes the underlying cryptographic parameters from pairing-based assumptions to lattice-based assumptions (specifically the k-Lin assumption in bilinear groups). This parameter change enables public key sizes of O(N1/3) while maintaining adaptive security, as the lattice-based framework provides stronger security guarantees with shorter parameters compared to traditional pairing-based approaches

Inventive Principle:
Principle #35Parameter changes

3Length of stationary object

If ciphertext size is minimized in broadcast encryption, then transmission efficiency improves, but security guarantees against collusions are weakened

Engineering Contradiction:
Improveciphertext sizeVSAvoidsecurity guarantees
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The patent replaces the mechanical structure of traditional broadcast encryption schemes with a fundamentally different lattice-based mechanism. By using polynomial evaluation over lattices and bilinear maps, the system achieves compact ciphertexts of O(N1/3) size while the mathematical structure of lattice-based cryptography inherently provides adaptive security against unbounded collusions, substituting the old mechanical pairing-based approach with a more efficient lattice-based system

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12388801B2Broadcast encryption with improved resource utilization
Publication Date: 2025.08.12 NTT RESEARCH INC
  • US12388801B2 patent drawing
  • US12388801B2 patent drawing
  • US12388801B2 patent drawing

AI summary

A broadcast network can use a pairing-based broadcast encryption scheme for N users with O(N1/3)-sized parameters. A pairing-based ciphertext-policy attribute-based encryption (CP-ABE) scheme for the class of degree 3 polynomials can be implemented with compact parameters. The public key, ciphertext and secret keys comprise O(n) group elements, where n is input length for the function. The constructions achieve adaptive security against unbounded collusions, and rely on the (bilateral) k-Lin assumption in prime-order bilinear groups.