International Journal of Information Security

, Volume 11, Issue 1, pp 1–22

Relations between the security models for certificateless encryption and ID-based key agreement

Regular Contribution

DOI: 10.1007/s10207-011-0149-y

Cite this article as:
Fiore, D., Gennaro, R. & Smart, N.P. Int. J. Inf. Secur. (2012) 11: 1. doi:10.1007/s10207-011-0149-y


We discuss the relationship between ID-based key agreement protocols, certificateless encryption and ID-based key encapsulation mechanisms. In particular we show how in some sense ID-based key agreement is a primitive from which all others can be derived. In doing so we focus on distinctions between what we term pure ID-based schemes and non-pure schemes, in various security models. We present security models for ID-based key agreement which do not “look natural” when considered as analogues of normal key agreement schemes, but which look more natural when considered in terms of the models used in certificateless encryption. We illustrate our models and constructions with two running examples, one pairing based and one non-pairing based. Our work highlights distinctions between the two approaches to certificateless encryption and adds to the debate about what is the “correct” security model for certificateless encryption.


Key agreementCertificateless encryptionIdentity-based key agreement

Copyright information

© Springer-Verlag 2011

Authors and Affiliations

  1. 1.École Normale Supérieure, CNRS-INRIAParisFrance
  2. 2.IBM T.J. Watson Research CenterHawthorneUSA
  3. 3.Department Computer ScienceUniversity of BristolBristolUK