Thread Links Date Links
Thread Prev Thread Next Thread Index Date Prev Date Next Date Index

Re: [P1363:] HIBE Scheme



Dear list,

I do not agree that the Boneh-Boyen HIBE framework [BBG-HIBE]
outperforms the Gentry-Silverberg [GS-HIBE] by every criterion.

First, [GS-HIBE] is more efficient than [BBG-HIBE] at least for
encryption.  [GS-HIBE] is more efficient than [BBG-HIBE] also for
decryption if t< 3, where t is the depth of hierarchy.

Second, the security assumption of [GS-HIBE] differs from that of
[BBG-HIBE].  That is, [GS-HIBE] is secure in the Random Oracle model
assuming the BDH assumption, where [BBG-HIBE] is secure in the generic
model assuming the l-BDH assumption.  I cannot say which outperforms the
other.

[GS-HIBE] Hierarchical ID-Based Cryptography,  C.Gentry, A.Silverberg,
ASIACRYPT2002
 Security: random oracle model, BDH assumption
 Efficiency for encryption: (t-1) EC-Scalar Mults
 Efficiency for decryption:  t Pairings

[BBG-HIBE] Hierachical Identity Based Encryption with Constant Size
Ciphertext,   D.Boneh, X.Boyen, E.Goh, EUROCRYPT2005
 Security: generic model, l-BDH assumption
 Efficiency for encryption:  1 Pairing + t EC-Scalar Mults
 Efficiency for decryption:  2 Pairings + (2t+4) EC-Scalar Mults


> On May 20, 2009, at 10:49 PM, kobayashi.tetsutaro wrote:
> 
> > B) Scheme
> > P1363.3 D1 should have a scheme for HIBE primitives. For example, we  
> > propose as follows.
> >
> > 8.5 The GS-HIBE Scheme
> > GS-HIBE uses the P-GS-HIBE family of primitives to construct an HIBE  
> > scheme
> > that has a security reduction to the Bilinear Diffie-Hellman (BDH)  
> > problem.
> > This HIBE scheme is based on the work of GS02 and YKZHMI06.
> 
> 
> As I understand things, the Boneh-Boyen HIBE framework outperforms  
> Gentry-Silverberg by every criterion.  Why do you prefer GS to BB?   
> Unless there are legacy uses of GS we want to capture, I'd strongly  
> prefer sticking to one or both of BB HIBE and Boyen's Eurocrypt '07  
> HIBE for BB2/SK.  (This assuming we decide HIBE is something we want  
> to consider in the first go-round of .3.)
> 
> -hs.
> 
> ______________________________________________________________________
> To unsubscribe, mail LISTSERV@xxxxxxxxxxxxxxxxx with
> the body of the message containing: SIGNOFF STDS-P1363-DISCUSS
> Send any concerns to STDS-P1363-DISCUSS-request@xxxxxxxxxxxxxxxxx,
> or manage subscriptions at http://listserv.ieee.org/cgi-bin/wa
> Visit IEEE P1363 on the web at: http://grouper.ieee.org/groups/1363
> ______________________________________________________________________

-- 
Kobayashi Tetsutaro <kobayashi.tetsutaro@xxxxxxxxxxxxx>
TEL: 0422-59-3462     FAX: 0422-59-4015

______________________________________________________________________
To unsubscribe, mail LISTSERV@xxxxxxxxxxxxxxxxx with
the body of the message containing: SIGNOFF STDS-P1363-DISCUSS
Send any concerns to STDS-P1363-DISCUSS-request@xxxxxxxxxxxxxxxxx,
or manage subscriptions at http://listserv.ieee.org/cgi-bin/wa
Visit IEEE P1363 on the web at: http://grouper.ieee.org/groups/1363
______________________________________________________________________