EP1495573A2

Hierarchical identity-based encryption and signature schemes

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 18 March 2023, 3.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

63 claims: 7 independent, 56 dependent

  1. 1
    Claims of equivalent WO 03081780 A2 CLAIMS 1. A method of encoding and decoding a digital message between a sender and a recipient, wherein the recipient is «+1 levels below a root PKG in a hierarchical system including a plurality of PKGs, the plurality of PKGs including at least the root PKG and n lower-level PKGs in the hierarchy between the root PKG and the recipient, wherein n ≥ 1 , the method comprising:selecting a root key generation secret that is known only to the root PKG;generating a root key generation parameter based on the root key generation secret;selecting a lower-level key generation secret for each of the n lower-level PKGs, wherein each lower-level key generation secret is known only to its associated lower-level PKG;generating a lower-level key generation parameter for each of the n lower-level PKGs, wherein each lower-level key generation parameter is generated using at least the lower-level key generation secret for its associated lower-level PKG;encoding the message to form a ciphertext using at least the root key generation parameter and recipient identity information;generating a recipient private key such that the recipient private key is related to at least the root key generation secret, one or more of the n lower-level key generation secrets associated with the n lower-level PKGs in the hierarchy between the root PKG and the recipient, and the recipient identity information;and decoding the ciphertext to recover the message using at least the recipient private key.
  2. 6
    A method of encoding and decoding a message between a sender and a recipient in a system including a plurality of PKGs, the plurality of PKGs including m lower-level PKGs in the hierarchy between the root PKG and the sender, wherein m ≥ 1 , and n lower-level PKGs in the hierarchy between the root PKG and the recipient, wherein n ≥ 1 , wherein at least / of the plurality of PKGs in the hierarchy are common ancestors to both the sender and the recipient, wherein / > 1 , and wherein PKG / is a common ancestor PKG to both the sender and the recipient, the method further comprising:selecting a root key generation secret that is known only to the root PKG;generating a root key generation parameter based on the root key generation secret;selecting a lower-level key generation secret for each of the m and n lower-level PKGs, wherein each lower-level key generation secret is known only to its associated lower-level PKG;generating a lower-level key generation parameter for each of the m and n lower-level PKGs, wherein each lower-level key generation parameter is generated using at least the lower- level key generation secret for its associated lower-level PKG;generating a sender private key such that the sender private key is related to at least sender identity information, the root key generation secret, and one or more of the lower-level key generation secrets associated with the m PKGs between the root PKG and the sender;generating a recipient private key such that is related to at least recipient identity information, the root key generation secret, and one or more of the n lower-level key generation secrets associated with the n lower-level PKGs in the hierarchy between the root PKG and the recipient;encoding the message using at least the recipient identity information, the sender private key, and zero or more of the lower-level key generation parameters associated with the (m - / +1 ) PKGs between the root PKG and the sender that are at or below the level of the common ancestor PKG / , but not any of the lower-level key generation parameters that are associated with the (/ - 1) PKGs above the common ancestor PKG / ;and decoding the ciphertext using at least the recipient private key and zero or more of the lower-level key generation parameters associated with the (n - 1 + 1 ) PKGs between the root PKG and the recipient that are at or below the level of the lowest common ancestor PKG / , but not using any of the lower- level key generation parameters that are associated with the (/ - 1) PKGs that above the common ancestor PKG / .
  3. 12
    A method of generating and verifying a digital signature of a message between a sender and a recipient, wherein the sender is m+1 levels below a root PKG in a hierarchical system including a plurality of PKGs, the plurality of PKGs including at least the root PKG and m lower-level PKGs in the hierarchy between the root PKG and the sender, wherein m ≥ 1, the method comprising:selecting a root key generation secret that is known only to the root PKG;generating a root key generation parameter based on the root key generation secret;generating a lower-level key generation secret for each of the m lower-level PKGs, wherein each lower-level key generation secret is known only to its associated lower-level PKG;generating a lower-level key generation parameter for each of the m lower-level PKGs, wherein each lower-level key generation parameter is generated using at least the lower-level key generation secret for its associated lower-level PKG;generating a sender private key for the sender such that the sender private key is related to at least sender identity information, the root key generation secret, and one or more of the m lower-level key generation secrets associated with the m lower-level PKGs in the hierarchy between the root PKG and the sender;signing the message to generate the digital signature using at least the sender private key;and verifying the digital signature using at least the root key generation parameter and the sender identity information.
  4. 14
    A method of generating a private key for an entity in a system including a plurality of PKGs, the plurality of PKGs including at least a root PKG and n lower-level PKGs in the hierarchy between the root PKG and the entity, wherein n ≥ 1 , the method comprising:generating a root key generation secret that is known only to the root PKG;generating a root key generation parameter based on the root key generation secret;generating a lower-level key generation secret for each of the n lower-level PKGs, wherein each lower-level key generation secret is known only to its associated lower-level PKG;generating a lower-level key generation parameter for each of the n lower-level PKGs, wherein each lower-level key generation parameter is generated using at least the lower-level key generation secret for its associated lower-level PKG;generating a private key for the entity such that the private key is related to at least identity information associated with the entity, the root key generation secret, and one or more of the n lower-level key generation secrets associated with the n lower-level PKGs in the hierarchy between the root PKG and the entity;and providing the private key to the entity.
  5. 15
    A method of generating a private key for a recipient z in a system, wherein the recipient z is n+1 levels below a root PKG in the hierarchy, and wherein the recipient is associated with a recipient ID-tuple (ID z ι, . . . , ID z(n+1) ) that includes identity information ID Z( „+i ) associated with the recipient and identity information ID Z , associated with each of n lower-level PKGs in the hierarchy between the root PKG and the recipient, the --.,,-_,, PCT/US03/08010 -41- method comprising:generating a first cyclic group r*ι of elements and a second cyclic group r 2 of elements;selecting a function e capable of generating an element of the second cyclic group r 2 from two elements of the first cyclic group r-,;selecting a root generator -P 0 of the first cyclic group IN, selecting a random root key generation secret so associated with and known only to the root PKG;generating a root key generation parameter Q = SQP O ;selecting a function H-i capable of generating an element of the first cyclic group r*ι from a first string of binary digits;generating a public element P zι for each of the n lower- level PKGs, wherein P zι = H^(\D^, . . . , ID Zi ) for 1 ≤ i ≤ n;selecting a lower-level key generation secret s zl for each of the n lower-level PKGs, wherein each lower-level key generation secret s zl is known only to its associated lower-level PKG;generating a lower-level secret element S zι for each of the n lower-level PKGs, wherein S zι = S Z (,.ι> + s z(l .- \) P zl for 1 ≤ i ≤ n, wherein s z o = so, and wherein S z o is defined to be zero;generating a lower-level key generation parameter Q zι for each of the n lower-level PKGs, wherein Q zl = s zl P 0 for ≤ i ≤ n;generating a recipient public element P z ( n +.) = ι(ID z ι, . . . , ID Z („ +1) ) associated with the recipient, wherein P Z („+i) is an element of the first cyclic group Η;and generating a recipient private key S Il→ = S_ n + s_ + » = " = + 2(I . , ) *P, associated with the recipient.
  6. 20
    21. A method of encoding and decoding a digital message M as in claim 20, wherein:both the first group Tι and the second group r 2 are of the same prime order q.
  7. 25
    26. A method of encoding and decoding a digital message M as in claim 25, wherein:both the first group r*ι and the second group r 2 are of the same prime order q.
  8. 30
    31. A method of encoding and decoding a digital message M as in claim 30, wherein:both the first cyclic group r-i and the second cyclic group r 2 are of the same prime order q.
  9. 35
    36. A method of encoding and decoding a digital message M between a sendery and a recipient z in a system including a plurality of PKGs, the plurality of PKGs including m lower-level PKGs in the hierarchy between the root PKG and the sendery, wherein m ≥ 1 , and n lower level PKGs in the hierarchy between the root PKG and the recipient z, wherein n ≥ 1 , wherein at least / of the PKGs in the hierarchy are common ancestors to both the sendery and the recipient z, wherein / > 1 , wherein PKG / is a common ancestor PKG to both the sender and the recipient, wherein the sendery is associated with a sender ID-tuple (ID y ι, . . . , ID^-i)) that includes identity information ID („, + i) associated with the sendery and identity information ID^, associated with each of m lower-level PKGs in the hierarchy between the root PKG and the sendery, and wherein the recipient is associated with a recipient ID-tuple (ID z ι, . . . , ID 2( „ +1) ) that includes identity information ID z( „+i ) associated with the recipient and identity information ID 2 , associated with each of n lower-level PKGs in the hierarchy between the root PKG and the recipient, the method further comprising:generating a first cyclic group r-i of elements and a second cyclic group r 2 of elements;selecting a function e capable of generating an element of the second cyclic group r 2 from two elements of the first cyclic group IY selecting a root generator P 0 of the first cyclic group IY selecting a random root key generation secret so associated with and known only to the root PKG;generating a root key generation parameter Q 0 = soPo, selecting a first function H-i capable of generating an element of the first cyclic group n from a first string of binary digits;selecting a second function H 2 capable of generating a second string of binary digits from an element of the second cyclic group r 2 ;generating a public element P yi for each of the m lower- level PKGs, wherein P yi = Hι(ID ι, . . . , ID ι ) for 1 ≤ i ≤ m, and wherein P yi = _P Z , for all i ≤ I;generating a public element P zi for each of the n lower- level PKGs, wherein P zi = Hι(ID 1 ID Z ,) for 1 ≤ i ≤ n;selecting a lower-level key generation secret s yι for each of the m lower-level PKGs, wherein s yι = s zι for all < /;selecting a lower-level key generation secret s zι for each of the n lower-level PKGs, wherein each lower-level key generation secret s zl is known only to its associated lower-level PKG;generating a lower-level secret element S y , for each of the m lower-level PKGs, wherein S yι = S y (,.^ + S y ^yP y , for 1 ≤ i ≤ m, and wherein S yι = S zι for all i ≤ I;generating a lower-level secret element S zι for each of the n lower-level PKGs, wherein S z , = S Z (,-*i) + -? z (,.i)P z , for ≤ i ≤ n, wherein 5 z o = so. and wherein S z o is defined to be zero;generating a lower-level key generation parameter Q yι for each of the m lower-level PKGs, wherein Q yι = s yι P 0 for 1 ≤ i ≤ m , and wherein Q yι = Q zι for all i ≤ I, generating a lower-level key generation parameter Q zl for each of the n lower-level PKGs, wherein Q zl = s zl Po for 1 < i ≤ n;generating a sender public element ydn +1) = - ι(IDyi IDytø+i)) associated with the sendery;generating a recipient public element P z ( « +i) = ι(ID z ι, . . . , ID Z („ +1) ) associated with the recipient;generating a sender secret element S y( ,m ,+,\) = S ym + s ym P y(.m „+, 1) = a ** n ,= + ! | s y ,(ι- n I)P yi associated with the sender;generating a recipient secret element S z ,(n φ + l) = S zn + s zn P z(,n φ + l l) = "* " ι=, 1'-s z,(ι- , 1,) z/ associated with the recipient;encoding the message to generate a ciphertext C using at least the lower-level key generation parameters Q yι for I < i ≤ m and the sender secret element S y ( m +- \) , but not using the lower-level key generation parameters Q yi for i < I;and decoding the ciphertext C to recover the message M using at least the lower-level key generation parameters Q zι for I < i ≤ n and the recipient secret element S z („+-i), but not using the lower-level key generation parameters Q zι for i < I.
  10. 36
    37. A method of encoding and decoding a digital message M as in claim 36, wherein encoding the message M further includes using the lower level key generation parameter Q y ι.
  11. 43
    45. A method of encoding and decoding a digital message M as in claim 43, wherein:the first cyclic group r*ι is an additive group of points on a supersingular elliptic curve or abelian variety, and the second cyclic group r 2 is a multiplicative subgroup of a finite field.
  12. 49
    51. A method of encoding and decoding a digital message M as in claim 49, wherein:both the first cyclic group r-i and the second cyclic group r 2 are of the same prime order q.
  13. 54
    56. A method of generating and verifying a digital signature Sig of a digital message M communicated between a sender and a recipient, wherein the sender is m+1 levels below a root PKG in a hierarchical system, and wherein the sender is associated with a sender ID-tuple (ID y ι, . . . , ID y ( m+ -i)) that includes identity information associated with the sender and identity information \D yi associated with each of m lower-level PKGs in the hierarchy between the root PKG and the sender, the method comprising:generating a first cyclic group r-i of elements and a second cyclic group r 2 of elements;selecting a bilinear, non-degenerate pairing e capable of generating an element of the second cyclic group r 2 from two elements of the first cyclic group IY, selecting a root generator Po of the first cyclic group IY selecting a random root key generation secret so associated with and known only to the root PKG;generating a root key generation parameter Qo = SQP O ', selecting a first function Hi capable of generating an element of the first cyclic group Y- \ from a first string of binary digits;generating a public element P yi for each of the m lower- level PKGs, wherein P yi = Hι(ID ι, . . . , ID^,) for ^ ≤ i ≤ m;selecting a lower-level key generation secret s yi for each of the n lower-level PKGs, wherein each lower-level key generation secret s yi is known only to its associated lower-level PKG;generating a lower-level secret element S yi for each of the m lower-level PKGs, wherein S yi = S y (,.*i) + *S y (,-ι> y ,- for 1 < i ≤ m,;generating a lower-level key generation parameter Q yι for each of the m lower-level PKGs, wherein Q yι = s yι P 0 for 1 ≤ i ≤ m, generating a sender public element P y ( m +1) = Hι(ID ι, . . . , associated with the sender;generating a sender secret element S y ,(m ^ +,l) = S ym + s ym P y ,(m „+,\.) = a "* ι=, 1 s y ,(ι- , 1).P yi associated with the sender;signing the message M to generate a digital signature Sig using at least the sender secret element S yim+ ^;and verifying the digital signature Sig using at least the root key generation parameter Qo and the lower-level key generation parameters Q yι .
  14. 56
    58. A method of generating and verifying a digital signature Sig as in claim 56, wherein:the first cyclic group r-i is an additive group of points on a supersingular elliptic curve or abelian variety, and the second cyclic group r 2 is a multiplicative subgroup of a finite field.
  15. 61
    63. A method of generating and verifying a digital signature Sig as in claim 61 , wherein:the first cyclic group r*ι is an additive group of points on a supersingular elliptic curve or abelian variety, and the second cyclic group r 2 is a multiplicative subgroup of a finite field.