International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 18 November 2014

Zhengjun Cao, Lihua Liu
ePrint Report ePrint Report
In 2010, Lewko, Sahai and Waters proposed an efficient revocation system but they neglected the security differences between one-to-one encryption and one-to-many encryption. In their system, an authority generates all users\' decryption keys once and for all. We remark that the inherent drawback results in that the system is vulnerable to an attack launched by some malicious users. These malicious users could exchange their decryption keys after they receive them from the authority in order to maximize their own interests. Thus, the Lewko-Sahai-Waters revocation system cannot truly revoke a malicious user. From the practical point of view, the flaw discounts greatly the importance of the system.

Expand

Additional news items may be found on the IACR news page.