Proxy Re-Encryption Key Generation for Flexible Ciphertext Designation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current conditional proxy re-encryption schemes lack flexibility in designating decryptors and conditions for re-encryption, and existing functional proxy re-encryption schemes restrict the re-encryption key's ability to re-encrypt all ciphertexts decryptable by the recipient without allowing specific ciphertext designation.
Innovation Solution
A cryptographic system that generates a re-encryption key capable of setting both decryption conditions and re-encryption conditions, allowing flexible designation of attribute information for ciphertexts and re-ciphertexts, using a system with encryption and re-encryption devices that manage attribute information and decryption keys within dual pairing vector spaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a functional proxy re-encryption scheme is used, then the system can decrypt ciphertexts with functional keys, but the re-encryption key generated by a recipient can only re-encrypt all ciphertexts that the recipient can decrypt without allowing specific ciphertext designation
Solution Approach 1:
The patent segments the re-encryption functionality by introducing separate components: a functional key for decryption and a re-encryption key for re-encryption. The re-encryption key is generated based on specific ciphertext attributes rather than granting blanket re-encryption capability, allowing selective re-encryption of designated ciphertexts while maintaining system manageability
Solution Approach 2:
The patent implements dynamic attribute-based access control where re-encryption permissions are not static but determined by matching ciphertext attributes with re-encryption key attributes. This allows the system to adaptively control which ciphertexts can be re-encrypted based on the specific attributes provided during key generation, enhancing flexibility without requiring complex hardcoding of permissions
2Adaptability or versatility
If conditional proxy re-encryption is implemented, then conditions for re-encryption can be designated, but the scheme is not a functional encryption scheme and has constraints on designation of decryptors and conditions
Solution Approach 1:
The patent merges functional encryption with proxy re-encryption to create a unified system. The functional key structure allows decryption based on attribute matching, while the re-encryption key structure enables re-encryption based on attribute matching. This combination eliminates the constraints of separate schemes and provides unified flexible control over both decryption and re-encryption conditions
Solution Approach 2:
The patent creates a universal attribute-based framework that handles multiple functions: decryption, re-encryption, and conditional access control. The same attribute matching mechanism serves all these functions, allowing the system to universally apply flexible condition designation across different operations without requiring separate constraint mechanisms for each function
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An encryption device 200 outputs a ciphertext ct including a ciphertext c and a ciphertext c~. The ciphertext c has been set with one of attribute information x and attribute information v related to each other. The ciphertext c~ has been set with one of attribute information y and attribute information z related to each other. A decryption device 300 outputs a re-encryption key rk including a decryption key k*rk, a decryption key k~*rk, and encrypted conversion information φrk. The decryption key k*rk is obtained by converting the decryption key k* which is set with the other one of attribute information x and attribute information v, with conversion information W1,t. The decryption key k~*rk has been set with the other one of the attribute information y and the attribute information z. The encrypted conversion information φrk is obtained by encrypting the conversion information W1,t by setting one of attribute information x' and attribute information v' related to each other. A re-encryption device 400 outputs a re-ciphertext rct including a ciphertext crenc and a decryption key k*renc. The ciphertext crenc is obtained by setting one of additional information H and additional information Θ to the ciphertext ct. The decryption key k*renc is obtained by setting the other one of the additional information H and the additional information Θ to the re-encryption key rk.