Constructing Certificateless Encryption and ID-Based Encryption from ID-Based Key Agreement
We discuss the relationship between ID-based key agreement protocols, certificateless encryption and ID-based key encapsulation mechanisms. In particular we show how in some sense ID-based key agreement is a primitive from which all others can be derived. In doing so we focus on distinctions between what we term pure ID-based schemes and non-pure schemes, in various security models. We present security models for ID-based key agreement which do not ”look natural” when considered as analogues of normal key agreement schemes, but which look more natural when considered in terms of the models used in certificateless encryption. Our work highlights distinctions between the two approaches to certificateless encryption, and adds to the debate about what is the ”correct” security model for certificateless encryption.
KeywordsSecurity Model Forward Secrecy Certificateless Encryption
Unable to display preview. Download preview PDF.
- 2.Al-Riyami, S.S.: Cryptographic schemes based on elliptic curve pairings. Ph.D. Thesis, University of London (2004)Google Scholar
- 6.Bellare, M., Rogaway, P.: Entity authentication and key distribution. In: Stinson, D.R. (ed.) CRYPTO 1993. LNCS, vol. 773, pp. 232–249. Springer, Heidelberg (1993)Google Scholar
- 7.Blake-Wilson, S., Johnson, D., Menezes, A.: Key agreement protocols and their security analysis. In: Darnell, M.J. (ed.) Cryptography and Coding 1997. LNCS, vol. 1355, pp. 30–45. Springer, Heidelberg (1997)Google Scholar
- 9.Canetti, R., Goldreich, O., Goldwasser, S., Micali, S.: Resettable Zero-Knowledge. Weizmann Science Press, Israel (1999)Google Scholar
- 12.Chen, L., Kudla, C.: Identity based authenticated key agreement from pairings. In: IEEE Computer Security Foundations Workshop, pp. 219–233 (2003); The modified version of this paper is available at Cryptology ePrint Archive, Report 2002/184Google Scholar
- 18.Scott, M.: Authenticated ID-based key exchange and remote log-in with insecure token and PIN number. Cryptology ePrint Archive, Report 2002/164Google Scholar