{"catalogVersion":"abe-landscape-v2-atomic-contributions","constructions":[{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-DECISIONAL-BILINEAR-DIFFIE-HELLMAN-DBDH","assumption_name":"Decisional Bilinear Diffie-Hellman (DBDH)","authors":["Vipul Goyal","Omkant Pandey","Amit Sahai","Brent Waters"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"I","ggm_file":null,"id":"gpsw","large_universe":0,"multi_use_attributes":0,"paper_title":"Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data","paper_url":"https://eprint.iacr.org/2006/309","policy_class":"tree","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"m","GT":"1","note":"One element E_i = g_1^{t_i s} per ciphertext attribute, plus E' = M * Y^s in G_T."},"MPK":{"G1":"U+1","GT":"1","note":"T_1=g^{t_1}, ..., T_U=g^{t_U} plus e(g,g)^y. U = attribute universe size. Generators not counted."},"MSK":{"Zp":"U+1","note":"t_1, ..., t_U, y"},"SK":{"G2":"n1","note":"One element D_x = g_2^{q_x(0)/t_{att(x)}} per tree leaf. No G_1 pieces."},"note_on_port":"GPSW'06 is originally in symmetric pairings; the standard Type III port places the key in G_2 and CT in G_1 (per FABEO Table 5).","sources":["GPSW §4.2 construction (natural Type III port)","FABEO Table 5 (Riepel–Wee CCS 2022) row for GPSW"]},"summary":"The first KP-ABE. Shamir-style polynomial secret sharing over a monotone access tree; ciphertext carries per-attribute exponentiations. Selective security under the standard DBDH assumption.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2006-GPSW","year":2006},{"assumption_family":"GGM+ROM","assumption_id":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","assumption_name":"Generic bilinear group","authors":["John Bethencourt","Amit Sahai","Brent Waters"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*I+1","ggm_file":null,"id":"bsw","large_universe":1,"multi_use_attributes":0,"paper_title":"Ciphertext-Policy Attribute-Based Encryption","paper_url":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","policy_class":"tree","primitive":"CP-ABE","security_mode":"adaptive","security_model":"GGM+ROM","security_notion":"CPA","sizes":{"CT":{"G1":"n1","G2":"n1+1","GT":"1","note":"n1 C_y in G1 (H(rho(y))^{q_y(0)}), n1 C'_y in G2 plus C in G2, Ctilde in GT"},"MPK":{"G2":"2","GT":"1","note":"A = g_2^beta, B = g_1^{1/beta} (placed per FAME port); Y_alpha in GT. Generators not counted. H in ROM."},"MSK":{"G1":"1","Zp":"1","note":"(beta, g_1^alpha)"},"SK":{"G1":"m+1","G2":"m","note":"D in G1, m D_tau in G1 (contain H(tau)), m D'_tau in G2"},"note_on_port":"BSW'07 is originally in symmetric pairings; the numbers above are the standard Type III port quoted by FAME and re-used by FABEO for comparison.","sources":["FAME (Agrawal–Chase CCS 2017) §5, Fig 5.5","FABEO (Riepel–Wee CCS 2022) Table 5 (asymmetric port)"]},"summary":"First CP-ABE. Monotone access tree with threshold gates; large universe via ROM hash. Per-attribute fresh randomness r_tau doubles SK vs. Waters11. Proven only in GGM + ROM.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2007-BSW","year":2007},{"assumption_family":"q-type","assumption_id":"ABE-ASSUMPTION-Q-PARALLEL-BDHE","assumption_name":"q-parallel BDHE","authors":["Brent Waters"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*I+1","ggm_file":null,"id":"waters11","large_universe":0,"multi_use_attributes":0,"paper_title":"Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization","paper_url":"https://eprint.iacr.org/2008/290","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"n1","G2":"n1+1","GT":"1","note":"n1 C_i in G1, n1 D_i in G2 plus C' = g_2^s in G2, Ctilde in GT"},"MPK":{"G1":"U+1","G2":"1","GT":"1","note":"g_1^a and {h_x}_{x in U} in G1; g_2 in G2; Y_alpha in GT. Generators not counted. U = |U| = universe size."},"MSK":{"G1":"1","note":"g_1^alpha"},"SK":{"G1":"m+1","G2":"1","note":"K = g_1^alpha * g_1^{at}, m K_x = h_x^t in G1, L = g_2^t in G2"},"note_on_port":"Waters11 is originally in symmetric pairings; the numbers above are the standard Type III port quoted by FAME and re-used by FABEO for comparison.","sources":["FAME (Agrawal–Chase CCS 2017) §5, Fig 5.5","FABEO (Riepel–Wee CCS 2022) Table 5 (asymmetric port)"]},"summary":"First CP-ABE for LSSS policies with polynomial-loss selective security under a q-type assumption. Reuses a single SK randomness t across all attributes, giving SK = (m+1) G1 + 1 G2 at the cost of a one-use restriction.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2011-WATERS","year":2011},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-STATIC-SUBGROUP-DECISION-ASSUMPTIONS-1-4-OF-LW11","assumption_name":"Static subgroup-decision (Assumptions 1–4 of LW11)","authors":["Allison Lewko","Brent Waters"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"4*I","ggm_file":null,"id":"lw11_kpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Unbounded HIBE and Attribute-Based Encryption","paper_url":"https://eprint.iacr.org/2011/049","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"3*m+1","GT":"1","note":"3 elements per CT attribute (C_{s_i,1}, C_{s_i,2}, C_{s_i,3}) plus C_0 = g^s. Plus C = M * e(g,g)^{alpha*s} in GT."},"MPK":{"G1":"7","GT":"1","note":"g, u, h, v, w in G_{p_1} plus e(g,g)^alpha. All in the composite-order group; the G_1 tag here labels the one source group used."},"MSK":{"Zp":"1","note":"alpha"},"SK":{"G2":"4*n1","note":"4 elements per LSSS row: K_{x,0}, K_{x,1}, K_{x,2}, K_{x,3}. Placed here under G_2 for the Type III analogue; in the paper all in one composite-order group."},"note_on_port":"Composite-order N = p_1 p_2 p_3 groups in the original paper. Size row below is in the single composite-order group G; no prime-order port is given in this paper (later work by Okamoto–Takashima, CGKW18 provide prime-order unbounded ABE).","sources":["LW11 §5.1 KP-ABE construction"]},"summary":"First unbounded KP-ABE: O(1) MPK, no a-priori attribute universe. Uses composite-order groups (N = p_1 p_2 p_3) and nested dual-system encryption to hide ephemeral semi-functionality across key queries.","verification_status":"blocked_composite_order","work_id":"ABE-PAPER-2011-LW-UNBOUNDED","year":2011},{"assumption_family":"q-type","assumption_id":"ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-1-IN-THE-PAPER","assumption_name":"q-DPBDHE2 (called q-1 in the paper)","authors":["Yannis Rouselakis","Brent Waters"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"3*I+1","ggm_file":null,"id":"rw13_cpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Practical Constructions and New Proof Methods for Large Universe Attribute-Based Encryption","paper_url":"https://eprint.iacr.org/2012/583","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"2*n1+1","G2":"n1+1","GT":"1","note":"C_0 plus 2 per row (C_{i,1}, C_{i,2}) in G1; 1 per row (C_{i,3}) plus one master in G2; Ctilde in GT"},"MPK":{"G1":"4","GT":"1","note":"u, h, w, v in G1; Y_alpha in GT. Generators not counted."},"MSK":{"Zp":"1","note":"just alpha"},"SK":{"G1":"2*m+2","G2":"m+1","note":"K_0 and m K_{tau,3} in G1; K_1 and m K_{tau,2} in G2 (asymmetric port)"},"note_on_port":"RW13 states the scheme in symmetric pairings; the paper's own Table 2 (Charm benchmark) and FAME's Fig 5.5 both give the Type III element counts above.","sources":["RW13 (Rouselakis–Waters CCS 2013) §4.1 construction + Table 2 benchmark (element counts given as asymmetric port for Charm)","FAME (Agrawal–Chase CCS 2017) §5 (cross-checks the Type III port)"]},"summary":"First practical unbounded-universe CP-ABE without ROM. Replaces Waters11's per-attribute {h_x} with a two-element universe encoder (u, h) that maps any τ ∈ Z_p to u^τ·h. Pays factor-2 blowup in SK and 3× per-row CT for large universe + one-use LSSS + selective security under q-type.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2013-RW","year":2013},{"assumption_family":"LWE","assumption_id":"ABE-ASSUMPTION-LEARNING-WITH-ERRORS-LWE","assumption_name":"Learning With Errors (LWE)","authors":["Dan Boneh","Valeria Nikolaenko","Gil Segev"],"capabilities":["arithmetic-circuits","unbounded-fan-in","key-delegation","post-quantum"],"construction_family":"lattice","decrypt_cost":{"note":"Evaluation work scales with the arithmetic circuit; correctness is controlled by depth-dependent noise growth.","pairings":"0","primary":"key-homomorphic circuit evaluation + lattice decryption"},"decrypt_pairings":"0","ggm_file":null,"id":"bns13_arithmetic_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Attribute-Based Encryption for Arithmetic Circuits","paper_url":"https://eprint.iacr.org/2013/669","policy_class":"arithmetic_circuit","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"asymptotic":"O(L · poly(λ,d))","note":"Dual-Regev samples for the L-coordinate public attribute vector."},"MPK":{"asymptotic":"O(L · poly(λ,d))","note":"L public attribute matrices plus the lattice trapdoor public matrix; the hidden factor includes n, m and log q."},"SK":{"asymptotic":"O(d²)","note":"A single 2m × m low-norm matrix; unlike prior schemes, no multiplicative dependence on circuit size."},"sources":["BNS13 §1, Parameters and performance","BNS13 §3 construction"]},"summary":"Selectively secure LWE KP-ABE for polynomial-size arithmetic circuits, with a single matrix secret key whose asymptotic size depends on depth rather than circuit gate or wire count.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2013-BNS-ARITH","year":2013},{"assumption_family":"q-type","assumption_id":"ABE-ASSUMPTION-DECISIONAL-Q-BDHE","assumption_name":"decisional q-BDHE","authors":["Susan Hohenberger","Brent Waters"],"capabilities":["fast-decryption","large-universe","user-tunable-tradeoff"],"construction_family":"pairing","decrypt_cost":{"exponentiations":"2I","note":"For AND/OR-derived LSSS coefficients, many exponentiations have exponent 0 or 1.","pairings":"2","primary":"2 pairings + 2I exponentiations"},"decrypt_pairings":"2","ggm_file":null,"id":"hw13_fast_kpabe","large_universe":1,"multi_use_attributes":1,"paper_title":"Attribute-Based Encryption with Fast Decryption","paper_url":"https://eprint.iacr.org/2013/265","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"selective","security_model":"ROM","security_notion":"CPA","sizes":{"CT":{"G1":"m+1","GT":"1","note":"One group element per ciphertext attribute, one header, and one masked message."},"MPK":{"G1":"1","GT":"1","note":"Large-universe ROM version hashes attributes into the group; generators and the hash description are not counted."},"MSK":{"Zp":"1"},"SK":{"G1":"n1*(Gamma+1)","note":"Each LSSS row has D_i, R_i, and one helper for each other distinct policy attribute."},"sources":["HW13 §3.1–§3.3"]},"summary":"Expressive large-universe KP-ABE whose optimized path decrypts with two pairings, at the cost of a secret-key blow-up by the number of distinct attributes in the policy.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2013-HW-FAST","year":2013},{"assumption_family":"q-type","assumption_id":"ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-2-IN-THE-PAPER","assumption_name":"q-DPBDHE2 (called q-2 in the paper)","authors":["Yannis Rouselakis","Brent Waters"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"3*I+1","ggm_file":null,"id":"rw13_kpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Practical Constructions and New Proof Methods for Large Universe Attribute-Based Encryption","paper_url":"https://eprint.iacr.org/2012/583","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"2*m+1","G2":"m","GT":"1","note":"Per attribute: C_{tau,1} in G_1, C_{tau,2} in G_1, C_{tau,3} in G_2; plus C_0 in G_1 and Ctilde in G_T."},"MPK":{"G1":"4","GT":"1","note":"u, h, w, v in G_1 plus Y_alpha in G_T. Same MPK structure as RW13 CP-ABE."},"MSK":{"Zp":"1"},"SK":{"G1":"n1","G2":"2*n1+1","note":"Per LSSS row: K_{i,0} in G_2, K_{i,1} in G_1, K_{i,2} in G_2; plus K_0 in G_2. Dual of CP-ABE."},"note_on_port":"RW13 states the scheme in symmetric pairings; sizes below follow the paper's own Charm benchmark (Table 2) asymmetric port.","sources":["RW13 §4.2 KP-ABE construction","RW13 Table 2 (Charm benchmark) asymmetric element counts"]},"summary":"KP-ABE dual of the RW13 CP-ABE. Same universe encoder (u, h), same O(1) MPK, large-universe via Z_p attribute labels, no ROM. Sizes transpose: SK grows with LSSS rows, CT grows with attribute count.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2013-RW","year":2013},{"assumption_family":"q-type","assumption_id":"ABE-ASSUMPTION-Q-TYPE-COMPUTATIONAL-PES","assumption_name":"q-type (computational PES)","authors":["Nuttapong Attrapadung"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"O(1)","ggm_file":null,"id":"attrapadung14","large_universe":0,"multi_use_attributes":0,"paper_title":"Dual System Encryption via Doubly Selective Security: Framework, Fully-secure Functional Encryption for Regular Languages, and More","paper_url":"https://eprint.iacr.org/2014/428","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"O(1)","GT":"1","note":"CONSTANT ciphertext: 3–4 group elements in G_1 + 1 G_T, independent of |S| (up to bound T)."},"MPK":{"G1":"O(T)","GT":"1","note":"T is the a-priori ciphertext-attribute bound; MPK linear in T."},"SK":{"G2":"n1*T","note":"SK quadratic in policy size and ciphertext-attribute bound (short-CT KP-ABE spends SK for compact CT)."},"note_on_port":"Composite-order in the original paper; Agrawal–Chase (TCC 2016-A, FAME CCS 2017) and Chen–Gay–Wee port to prime-order. Sizes below are for the headline **short-CT** KP-ABE with ciphertext-attribute bound T.","sources":["Attrapadung Eurocrypt 2014 §6 (PES instantiations)","Agrawal–Chase TCC 2016-A 'Study of Pair Encodings' comparison tables"]},"summary":"Introduces pair encoding schemes (PES): a combinatorial object that compiles generically to adaptive ABE via dual-system encryption. This spec captures the headline \"short-CT\" KP-ABE instantiation; other instantiations (short-SK, regular languages, unbounded) also exist.","verification_status":"blocked_composite_order","work_id":"ABE-PAPER-2014-ATTRAPADUNG","year":2014},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-LEARNING-WITH-ERRORS-LWE","assumption_name":"Learning With Errors (LWE)","authors":["Dan Boneh","Craig Gentry","Sergey Gorbunov","Shai Halevi","Valeria Nikolaenko","Gil Segev","Vinod Vaikuntanathan","Dhinakaran Vinayagamurthy"],"capabilities":[],"construction_family":"lattice","decrypt_cost":{},"decrypt_pairings":"0","ggm_file":null,"id":"bgg14_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Fully Key-Homomorphic Encryption, Arithmetic Circuit ABE, and Compact Garbled Circuits","paper_url":"https://eprint.iacr.org/2014/356","policy_class":"circuit","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"note":"L LWE samples + 1 message-carrying LWE sample. poly(L, λ, d)."},"MPK":{"note":"L lattice matrices each of dim O(n*log q), where L = attribute bit-length and n = LWE dim. poly(L, λ, d)."},"SK":{"note":"Short lattice vector of dim m_total = O(L·m). Length scales as poly(d, λ); INDEPENDENT of circuit size."},"sources":["BGG+14 §4 construction","BGG+14 Theorem 4 size statement"]},"summary":"First KP-ABE for circuits from LWE. Introduces the BGG+ key-homomorphic evaluation primitive that downstream lattice ABE schemes (GVW13 KP, BV16, Tsabary19, LLL22, HLL24, Wee24, Wee25) all build on.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2014-BGGPS","year":2014},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K-ESCALA-ET-AL","assumption_name":"k-Lin (MDDH_k, Escala et al.)","authors":["Jie Chen","Romain Gay","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*(k+1)","ggm_file":null,"id":"cgw15_cpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Improved Dual System ABE in Prime-Order Groups via Predicate Encodings","paper_url":"https://eprint.iacr.org/2015/409","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"2*U+2","GT":"1","note":"SXDH (k=1). General k-Lin: (k+1)(n_1+1). Here n_1 = U due to one-use."},"MPK":{"G1":"2*U+3","GT":"1","note":"SXDH (k=1) instantiation. General k-Lin: k(k+1)(U+1)+k in G1, k in GT. U = universe size."},"SK":{"G2":"2*U+4","note":"SXDH (k=1). General k-Lin: (k+1)(U+2). SK grows with universe U, not |S|, under one-use restriction."},"sources":["CGW15 Fig. 4 (p. 6): general k-Lin and SXDH (k=1) / DLIN (k=2) instantiations","CGW15 Appendix B.2: explicit CP-ABE scheme"]},"summary":"First fully adaptive CP-ABE in prime-order groups under a static k-Lin assumption, via the predicate-encoding framework. Achieves dual-system security without composite-order groups, at (k+1)× blowup vs. selective.","verification_status":"solver_verified","work_id":"ABE-PAPER-2015-CGW","year":2015},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K-ESCALA-ET-AL","assumption_name":"k-Lin (MDDH_k, Escala et al.)","authors":["Jie Chen","Romain Gay","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*(k+1)","ggm_file":null,"id":"cgw15_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Improved Dual System ABE in Prime-Order Groups via Predicate Encodings","paper_url":"https://eprint.iacr.org/2015/409","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"2*U+2","GT":"1","note":"SXDH (k=1). General k-Lin: (k+1)(U+1). Under one-use, U acts like max CT-attribute count."},"MPK":{"G1":"2*U+3","GT":"1","note":"SXDH (k=1) instantiation; general k-Lin: k(k+1)(U+1)+k in G_1, k in GT."},"SK":{"G2":"2*n1+2","note":"SXDH (k=1). General k-Lin: (k+1)(n_1+1). Dual of CP-ABE: SK grows with LSSS rows."},"sources":["CGW15 Fig. 4 (p. 6) k-Lin / SXDH / DLIN instantiations","CGW15 §B.1 explicit KP-ABE scheme"]},"summary":"KP-ABE dual of CGW15 CP-ABE. First adaptive KP-ABE from static k-Lin in prime-order groups via predicate encodings. Fixed 2(k+1) pairings.","verification_status":"solver_verified","work_id":"ABE-PAPER-2015-CGW","year":2015},{"assumption_family":"GGM","assumption_id":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","assumption_name":"Generic bilinear group","authors":["Miguel Ambrona","Gilles Barthe","Romain Gay","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"I","ggm_file":"tests/golden/abgw17_cpabe.ggm","id":"abgw17_cpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Attribute-Based Encryption in the Generic Group Model: Automated Proofs and New Constructions","paper_url":"https://eprint.iacr.org/2017/983","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"adaptive","security_model":"GGM","security_notion":"CPA","sizes":{"CT":{"G1":"3*n1","GT":"1","note":"3 G_1 elements per LSSS row. Uses W^lambda_i v^t_i, (u^rho(i) h)^-t_i, g^t_i structure."},"MPK":{"G1":"O(1)","note":"Constant number of G_1 elements + 1 G_T. No per-attribute public material (uses rational 1/b encoding instead)."},"SK":{"G2":"m+2","note":"Uses rational encoding x_i * r / b_i per attribute plus (a-r) head. All in G_2."},"abstraction_note":"The paper's concrete scheme has 3 G_1 elements per LSSS row (a\nW^lambda_i v^t_i, (u^rho(i) h)^-t_i, g^t_i triple) and stores SK\nentries only for attributes in S (hence m+2). The PES construction\nblock below collapses these to one vector `c` of size N = n_1 and\na vector `k2` of size N (with x-gating that zeros out non-S entries),\nso the construction-block count differs from the paper sizes.\n","sources":["ABGW17 §5 CP-ABE scheme","FABEO Table 5 (Riepel–Wee CCS 2022) for the comparison row","verifiers/ggm-symbolic-solver/examples/cp_abe.ggm (used to verify in this repo)"]},"summary":"Large-universe adaptive CP-ABE with automated GGM proof via a Master Theorem; the direct basis of ggm-symbolic-solver. Rational 1/b encoding in SK quarantines Type I self-pairings, making the scheme Type I-safe.","verification_status":"solver_verified","work_id":"ABE-PAPER-2017-ABGW","year":2017},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-DECISIONAL-LINEAR-DLIN-TYPE-III","assumption_name":"Decisional Linear (DLIN, Type III)","authors":["Shashank Agrawal","Melissa Chase"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"6","ggm_file":null,"id":"fame_cpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"FAME: Fast Attribute-Based Message Encryption","paper_url":"https://eprint.iacr.org/2017/807","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"adaptive","security_model":"ROM","security_notion":"CPA","sizes":{"CT":{"G1":"3*n1","G2":"3","GT":"1","note":"3 ct_0 in G_2; per row 3 elements in G_1; 1 ct' in G_T."},"MPK":{"G2":"3","GT":"2","note":"h, H_1, H_2 in G_2; T_1, T_2 in G_T. Hash H in ROM, not counted."},"MSK":{"G1":"6","G2":"1","Zp":"4","note":"(g, h, a_1, a_2, b_1, b_2, g^d_1, g^d_2, g^d_3)"},"SK":{"G1":"3*m+3","G2":"3","note":"3 sk_0 in G_2; per attribute 3 elements in G_1 (sk_{y,1}, sk_{y,2}, g^{-sigma_y}); 3 sk' in G_1. Multi-use tau_hat duplicates attribute labels: (3*tau_hat*m+3) |G_1|."},"sources":["FAME (Agrawal–Chase CCS 2017) Figure 3.1 construction","FAME Fig 5.4 (decryption pairings)"]},"summary":"First fast, adaptive, unbounded CP-ABE from a standard (DLIN) assumption with a fixed 6-pairing decryption. Became the Charm-framework baseline. Tradeoff: each key/CT row spends 3 G_1 elements to support the DLIN proof.","verification_status":"solver_verified","work_id":"ABE-PAPER-2017-FAME","year":2017},{"assumption_family":"GGM","assumption_id":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","assumption_name":"Generic bilinear group","authors":["Miguel Ambrona","Gilles Barthe","Romain Gay","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"I","ggm_file":"tests/golden/abgw17_kpabe.ggm","id":"abgw17_kpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Attribute-Based Encryption in the Generic Group Model: Automated Proofs and New Constructions","paper_url":"https://eprint.iacr.org/2017/983","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"adaptive","security_model":"GGM","security_notion":"CPA","sizes":{"CT":{"G1":"2*m","GT":"1","note":"2 elements per CT attribute in G_1, plus 1 G_T for message blinder."},"MPK":{"G1":"O(1)","note":"Constant; same universe-encoder approach as RW13."},"SK":{"G2":"2*n1","note":"2 elements per LSSS row in G_2."},"abstraction_note":"Declared sizes are from the paper (2 elements per LSSS row, 2 per\nCT attribute). The PES construction block below collapses per-row\nentries into a single vector `k` of size N, so counted sizes will\ndiffer from declared sizes.\n","sources":["ABGW17 §5 KP-ABE scheme","FABEO Table 5 for the comparison row","verifiers/ggm-symbolic-solver/examples/kp_abe.ggm"]},"summary":"KP-ABE dual of ABGW17 CP-ABE: large-universe adaptive KP-ABE with automated GGM proof via the Master Theorem. Rational 1/b encoding makes it Type-I-safe.","verification_status":"solver_verified","work_id":"ABE-PAPER-2017-ABGW","year":2017},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-DECISIONAL-LINEAR-DLIN-TYPE-III","assumption_name":"Decisional Linear (DLIN, Type III)","authors":["Shashank Agrawal","Melissa Chase"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"6","ggm_file":null,"id":"fame_kpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"FAME: Fast Attribute-Based Message Encryption","paper_url":"https://eprint.iacr.org/2017/807","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"adaptive","security_model":"ROM","security_notion":"CPA","sizes":{"CT":{"G1":"3*m","G2":"3","GT":"1","note":"3 elements per attribute in G_1, plus 3 ct_0 in G_2, plus 1 GT. Dual of CP-ABE SK."},"MPK":{"G2":"3","GT":"2","note":"Same MPK structure as FAME CP-ABE."},"SK":{"G1":"3*n1","G2":"3","note":"3 elements per LSSS row in G_1, plus 3 sk_0 in G_2. Dual of CP-ABE CT."},"sources":["FAME §4 KP-ABE construction","FAME Fig 5.5 size table"]},"summary":"KP-ABE dual of FAME CP-ABE. Adaptive DLIN security with fixed 6-pairing decryption. Large-universe via ROM-modeled hash. Sizes transpose from the CP-ABE variant.","verification_status":"solver_verified","work_id":"ABE-PAPER-2017-FAME","year":2017},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K","assumption_name":"k-Lin (MDDH_k)","authors":["Jie Chen","Junqing Gong","Lucas Kowalczyk","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"(2*k+1)*I","ggm_file":null,"id":"cgkw18","large_universe":1,"multi_use_attributes":0,"paper_title":"Unbounded ABE via Bilinear Entropy Expansion, Revisited","paper_url":"https://eprint.iacr.org/2018/116","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"(2*k+1)*m+k","GT":"1","note":"Per CT attribute: 2k+1 elements in G_1, plus k-size header and GT mask. At SXDH: 3m+1 G_1 plus GT."},"MPK":{"G1":"O(1)","note":"O(k^2) scalar-level but constant in universe / policy size. The headline claim is O(1) MPK for an unbounded scheme."},"SK":{"G2":"(5*k+3)*n1","note":"Per row: 2k+1 + k+1 + 2k+1 = 5k+3 elements in G_2. At k=1 (SXDH): 8*n_1."},"sources":["CGKW18 §4 prime-order KP-ABE construction"]},"summary":"First adaptive unbounded KP-ABE from standard k-Lin in Type-III prime- order groups. Bilinear entropy expansion lemma shrinks vector height from 3k (OT12) to 2k+1, improving all follow-up unbounded schemes.","verification_status":"solver_verified","work_id":"ABE-PAPER-2018-CGKW","year":2018},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-DLIN","assumption_name":"DLIN","authors":["Shweta Agrawal","Monosij Maitra","Shota Yamada"],"capabilities":["dfa","uniform-computation","unbounded-input","unbounded-machine","unbounded-key-queries"],"construction_family":"compiler","decrypt_cost":{"note":"The CP orientation is obtained by swapping the two underlying ABE roles; the source does not present a single normalized pairing count.","primary":"composed MSP reconstruction"},"decrypt_pairings":"not normalized","ggm_file":null,"id":"amy19_dfa_cpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Attribute Based Encryption for Deterministic Finite Automata from DLIN","paper_url":"https://eprint.iacr.org/2019/645","policy_class":"DFA","primitive":"CP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"asymptotic":"O(|Q|² · poly(λ))","note":"Ciphertext carrying the DFA policy in the swapped compiler."},"MPK":{"asymptotic":"poly(λ)","note":"Independent of input length and DFA size through unbounded MSP components."},"SK":{"asymptotic":"O(|x|³ · poly(λ))","note":"Attribute key for an unbounded input string in the swapped compiler."},"sources":["AMY19 §1.2–§1.4 and the symmetric CP compiler"]},"summary":"Ciphertext-policy counterpart of the DLIN DFA compiler, supporting unbounded machines, inputs, and key requests by swapping its two MSP-ABE components.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2019-AMY-DFA","year":2019},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K-1","assumption_name":"k-Lin (MDDH_k^1)","authors":["Lucas Kowalczyk","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*I+1","ggm_file":null,"id":"kw19_cpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Compact Adaptively Secure ABE for NC1 from k-Lin","paper_url":"https://eprint.iacr.org/2019/224","policy_class":"NC1","primitive":"CP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"(k+1)*(2*n1+1)","GT":"1","note":"1 + 2n_1 vectors in G_1 of length k+1, plus 1 G_T. Grows with policy size n_1."},"MPK":{"G1":"k*(k+1)*(U+1)+k","GT":"1","note":"n+2 matrices in G_1 of size k x (k+1), plus 1 G_T element. U = attribute universe size."},"SK":{"G2":"(k+1)*(m+2)","note":"m+2 vectors in G_2 of length k+1. |S|-dependent, policy-size-INDEPENDENT. Compactness axis."},"sources":["KW19 Appendix A.1 CP-ABE construction","KW19 §1.1 informal parameter claims"]},"summary":"First adaptive ABE for NC1 (monotone Boolean formulas) from static k-Lin in prime-order groups with attribute multi-use and polynomial security loss. Secret key is policy-size-independent (\"compact\").","verification_status":"compiler_ok_solver_stuck","work_id":"ABE-PAPER-2019-KW","year":2019},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-DLIN","assumption_name":"DLIN","authors":["Shweta Agrawal","Monosij Maitra","Shota Yamada"],"capabilities":["dfa","uniform-computation","unbounded-input","unbounded-machine","unbounded-key-queries"],"construction_family":"compiler","decrypt_cost":{"note":"The paper's headline comparison reports total key/ciphertext asymptotics rather than one normalized pairing formula.","primary":"composed MSP reconstruction"},"decrypt_pairings":"not normalized","ggm_file":null,"id":"amy19_dfa_kpabe","large_universe":1,"multi_use_attributes":0,"paper_title":"Attribute Based Encryption for Deterministic Finite Automata from DLIN","paper_url":"https://eprint.iacr.org/2019/645","policy_class":"DFA","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"asymptotic":"O(|x|³ · poly(λ))","note":"Ciphertext for an input string x."},"MPK":{"asymptotic":"poly(λ)","note":"Independent of input length and DFA size through unbounded MSP components."},"SK":{"asymptotic":"O(|Q|² · poly(λ))","note":"Policy key for a DFA with state set Q."},"sources":["AMY19 §1.4 comparison with concurrent work"]},"summary":"First pairing-based KP-ABE for DFA from static DLIN supporting unbounded input length, machine size, and key requests; obtained through a modular MSP compiler.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2019-AMY-DFA","year":2019},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K-1","assumption_name":"k-Lin (MDDH_k^1)","authors":["Lucas Kowalczyk","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*I+1","ggm_file":null,"id":"kw19_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Compact Adaptively Secure ABE for NC1 from k-Lin","paper_url":"https://eprint.iacr.org/2019/224","policy_class":"NC1","primitive":"KP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"(k+1)*(U+2)","GT":"1","note":"COMPACT: O(k·n) CT where n = attribute length. Policy-size INDEPENDENT even in many-use."},"MPK":{"G1":"k*(U+1)*(k+1)+k","GT":"1","note":"Matrix encodings scale as k(k+1) per universe slot + const."},"SK":{"G2":"(k+1)*(2*m_formula+1)","note":"Linear in formula size m_formula = number of shares. Policy in key; grows with formula."},"sources":["KW19 §6 main KP-ABE construction","KW19 §1.1 parameter claims"]},"summary":"First compact + adaptive + many-use + k-Lin KP-ABE for NC1. CT is policy-size independent — a milestone that resolves the Lewko–Waters'11 open problem. Built from a piecewise-guessing security framework plus a refined NC1 secret-sharing scheme.","verification_status":"solver_verified","work_id":"ABE-PAPER-2019-KW","year":2019},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K","assumption_name":"k-Lin (MDDH_k)","authors":["Huijia Lin","Ji Luo"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"3*k+4","ggm_file":null,"id":"ll20b_cpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Succinct and Adaptively Secure ABE for ABP from k-Lin","paper_url":"https://eprint.iacr.org/2020/1139","policy_class":"ABP","primitive":"CP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"(k+1)*mABP*(U+2)+mABP+k+1","GT":"1","note":"Grows with mABP = ABP size (vertex count). Under SXDH: ~m_ABP*(U+2) + m_ABP + 2 G_1 elements."},"MPK":{"G1":"k*(k+1)*(U+4)+k","GT":"1","note":"U = attribute-length parameter n in paper. k-Lin parameterized; under SXDH (k=1), approx (n+4) G_1 elements."},"SK":{"G1":"3*k+4","note":"CONSTANT in policy size. Under SXDH (k=1): 7 G_1 elements. Headline result."},"sources":["LL20b Construction 37 (Section 6.2) CP-ABE for ABP","LL20b Table 2 exact element counts"]},"summary":"First ABE with CONSTANT-size secret key under a static standard assumption (k-Lin), adaptive security, prime-order groups. SK = 3k+4 group elements (7 under SXDH), independent of ABP policy size.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2020-LL","year":2020},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K","assumption_name":"k-Lin (MDDH_k)","authors":["Huijia Lin","Ji Luo"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"O(k*U*mABP)","ggm_file":null,"id":"ll20a_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Compact Adaptively Secure ABE from k-Lin: Beyond NC1 and towards NL","paper_url":"https://eprint.iacr.org/2020/318","policy_class":"ABP","primitive":"KP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"O(k*U)","GT":"1","note":"Single IPFE slotted ciphertext carrying (pad, const^t, coef_i^t) slots. Policy-size INDEPENDENT."},"MPK":{"G1":"O(k*U)","note":"Θ(kn) IPFE public slots (const, coef_i for t in [k], i in [n])."},"SK":{"G1":"O(k*U*mABP)","note":"(mABP+1) IPFE secret keys, each with O(kn) group elements. Linear in ABP size — improvement from quadratic in prior work [IW14, CGKW18]."},"sources":["LL20a Construction 26 (§6.3) KP-ABE for ABPs","LL20a Theorem 27 adaptive security"]},"summary":"First compact adaptive KP-ABE for arithmetic branching programs (beyond NC1) from standard k-Lin. CT size is independent of ABP size; SK grows linearly in ABP size (improvement over prior O(|ABP|^2) constructions).","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2020-LL-EUROCRYPT","year":2020},{"assumption_family":"standard","assumption_id":"ABE-ASSUMPTION-K-LIN-MDDH-K","assumption_name":"k-Lin (MDDH_k)","authors":["Huijia Lin","Ji Luo"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"2*k+3","ggm_file":null,"id":"ll20b_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Succinct and Adaptively Secure ABE for ABP from k-Lin","paper_url":"https://eprint.iacr.org/2020/1139","policy_class":"ABP","primitive":"KP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"2*k+3","GT":"1","note":"CONSTANT — 5 group elements under SXDH (k=1), 2k+3 in general. Headline result."},"MPK":{"G2":"O(k*U)","note":"Public IPFE slots + gradually-sim-secure machinery."},"SK":{"G2":"O(k*U*mABP)","note":"Grows with ABP size."},"sources":["LL20b §5 KP-ABE Construction 32","LL20b Table 2 exact element counts"]},"summary":"First KP-ABE with CONSTANT-size ciphertexts for a rich policy class (ABP), adaptive under static k-Lin. CT = 5 group elements at SXDH. Breaks the long-standing \"succinct implies selective or q-type\" pattern.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2020-LL","year":2020},{"assumption_family":"GGM+ROM","assumption_id":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","assumption_name":"Generic bilinear group","authors":["Doreen Riepel","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"tau+2","ggm_file":"library/abe/formalizations/fabeo_cpabe.ggm","id":"fabeo_cpabe","large_universe":1,"multi_use_attributes":1,"paper_title":"FABEO: Fast Attribute-Based Encryption with Optimal Security","paper_url":"https://eprint.iacr.org/2022/1415","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"adaptive","security_model":"GGM+ROM","security_notion":"CPA","sizes":{"CT":{"G1":"n1","G2":"tau+1","GT":"1","note":"n_1 row elements in G_1; (tau+1) in G_2 carrying shared randomness across multi-use reuse."},"MPK":{"G1":"1","G2":"1","GT":"1","note":"g_1^alpha (implicit), g_2, e(g_1,g_2)^alpha, + ROM hash H: {0,1}* -> G_1. All O(1)."},"SK":{"G1":"m+1","G2":"1","note":"Head K = g_1^{alpha+r*b_{|U|+1}} in G_1, m K_u = g_1^{r*b_u} in G_1, L = g_2^r in G_2."},"abstraction_note":"Declared sizes follow FABEO Table 5. The PES construction block\nbelow captures the τ=1 specialization with a single sp slot,\nwhich differs slightly in per-slot counting from the paper's\nparametric τ. Expected divergence in size-consistency checks.\n","sources":["FABEO §5 construction","FABEO Table 5 exact element counts"]},"summary":"Current Pareto frontier for practical pairing CP-ABE: smallest SK and CT, fewest pairings (2–3), optimal security bound O(t^2/p) matching the discrete-log lower bound, native attribute multi-use, large universe. Proven in GGM + ROM.","verification_status":"solver_verified","work_id":"ABE-PAPER-2022-FABEO","year":2022},{"assumption_family":"q-type","assumption_id":"ABE-ASSUMPTION-Q-TYPE-PAIR-ENCODING-INSTANTIATION","assumption_name":"q-type pair-encoding instantiation","authors":["Marloes Venema","Greg Alpár"],"capabilities":["unbounded","flexible-efficiency-tradeoff","non-monotone-extension","online-offline","label-reuse"],"construction_family":"pairing","decrypt_cost":{"exponentiations":"2I","note":"Changing nk and nc shifts work between key generation, encryption, and decryption.","pairings":"2+ceil(I/nk)+ceil(I/nc)","primary":"2 + ceil(I/nk) + ceil(I/nc) pairings"},"decrypt_pairings":"2+ceil(I/nk)+ceil(I/nc)","ggm_file":null,"id":"glue22_cpabe","large_universe":1,"multi_use_attributes":1,"paper_title":"GLUE: Generalizing Unbounded Attribute-Based Encryption for Flexible Efficiency Trade-Offs","paper_url":"https://eprint.iacr.org/2022/613","policy_class":"monotone_LSSS","primitive":"CP-ABE","security_mode":"adaptive","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"G1":"1+2*n1+mct","GT":"1","note":"mct = max(ceil(n1/nc), tau) ciphertext partitions."},"MPK":{"G1":"nk+2*nc","G2":"1","GT":"1","note":"Partition parameters nk and nc are selected at setup."},"MSK":{"Zp":"nk+2*nc+1"},"SK":{"G2":"2+m+mkey","note":"mkey = ceil(m/nk) key partitions."},"sources":["GLUE §4 Definition 6","GLUE Table 2"]},"summary":"Generalized, large-universe, unbounded and expressive CP-ABE whose nk/nc partition parameters expose a flexible encryption/decryption trade-off and support non-monotone and online/offline extensions.","verification_status":"deferred_scalar_pes","work_id":"ABE-PAPER-2022-VA-GLUE","year":2022},{"assumption_family":"hybrid","assumption_id":"ABE-ASSUMPTION-LWE-GENERIC-BILINEAR-GROUP-HYBRID","assumption_name":"LWE + Generic bilinear group (hybrid)","authors":["Hanjun Li","Huijia Lin","Ji Luo"],"capabilities":[],"construction_family":"hybrid","decrypt_cost":{},"decrypt_pairings":"O(1)","ggm_file":null,"id":"lll22_cpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"ABE for Circuits with Constant-Size Secret Keys and Adaptive Security","paper_url":"https://eprint.iacr.org/2022/659","policy_class":"NC1","primitive":"CP-ABE","security_mode":"selective","security_model":"GGM+LWE","security_notion":"CPA","sizes":{"CT":{"G1":"poly(U,lam)","note":"Linear in attribute length U, policy-size-INDEPENDENT. 'Double succinct' claim. U = |x| = attribute length."},"MPK":{"G1":"poly(lam,d)","note":"Lattice matrices (poly in depth d and security parameter). lam = security parameter (renamed from 'lambda' which is a Python keyword)."},"SK":{"G1":"3","note":"LITERALLY 3 GROUP ELEMENTS, independent of circuit/formula size. Hybrid lattice–pairing compression."},"sources":["Li–Lin–Luo TCC 2022 Construction 2 (CP-ABE for Boolean formulas)","Paper title + abstract: 'constant-size secret keys and adaptive security'"]},"summary":"First \"doubly succinct\" ABE: constant-size SK (3 group elements) AND policy-size-independent CT. Combines lattice (BGG+-style) attribute evaluation with pairing (GGM) compression of the short-preimage key.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2022-LLL","year":2022},{"assumption_family":"GGM+ROM","assumption_id":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","assumption_name":"Generic bilinear group","authors":["Doreen Riepel","Hoeteck Wee"],"capabilities":[],"construction_family":"pairing","decrypt_cost":{},"decrypt_pairings":"tau+1","ggm_file":"library/abe/formalizations/fabeo_kpabe.ggm","id":"fabeo_kpabe","large_universe":1,"multi_use_attributes":1,"paper_title":"FABEO: Fast Attribute-Based Encryption with Optimal Security","paper_url":"https://eprint.iacr.org/2022/1415","policy_class":"monotone_LSSS","primitive":"KP-ABE","security_mode":"adaptive","security_model":"GGM+ROM","security_notion":"CPA","sizes":{"CT":{"G1":"m","G2":"1","GT":"1","note":"m attribute elements in G_1, 1 top-level G_2, 1 GT blinder."},"MPK":{"G1":"1","G2":"1","GT":"1","note":"g_1, g_2, e(g_1,g_2)^alpha; H: {0,1}* -> G_1 in ROM. All O(1)."},"SK":{"G1":"n1","G2":"tau","note":"n_1 row elements in G_1; tau per-slot randomness in G_2. Dual of CP-ABE."},"sources":["FABEO §4 KP-ABE construction","FABEO Table 5 exact element counts"]},"summary":"KP-ABE dual of FABEO CP-ABE. Smallest SK and CT, τ+1 pairings (2 at τ=1), optimal O(t²/p) bound, native multi-use, large universe. Current Pareto frontier for practical KP-ABE.","verification_status":"solver_verified","work_id":"ABE-PAPER-2022-FABEO","year":2022},{"assumption_family":"hybrid","assumption_id":"ABE-ASSUMPTION-LWE-GENERIC-BILINEAR-GROUP-HYBRID","assumption_name":"LWE + Generic bilinear group (hybrid)","authors":["Hanjun Li","Huijia Lin","Ji Luo"],"capabilities":[],"construction_family":"hybrid","decrypt_cost":{},"decrypt_pairings":"O(1)","ggm_file":null,"id":"lll22_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"ABE for Circuits with Constant-Size Secret Keys and Adaptive Security","paper_url":"https://eprint.iacr.org/2022/659","policy_class":"circuit","primitive":"KP-ABE","security_mode":"selective","security_model":"GGM+LWE","security_notion":"CPA","sizes":{"CT":{"G1":"poly(U,d,lam)","GT":"1","note":"Linear in attribute length |x| = U, polynomial in circuit depth d."},"MPK":{"G1":"poly(lam,d)","note":"Lattice trapdoor matrix + BGG+-style per-attribute matrices + O(1) pairing material. lam = security parameter."},"SK":{"G1":"3","note":"LITERALLY 3 GROUP ELEMENTS for any circuit of bounded depth d. Pairing-side compression of lattice short preimage."},"sources":["Li–Lin–Luo TCC 2022 Construction 1 (KP-ABE for circuits)","Paper title: 'ABE for Circuits with Constant-Size Secret Keys'"]},"summary":"First KP-ABE for BOUNDED-DEPTH CIRCUITS with constant-size (3-element) secret keys. Hybrid lattice + pairing (GGM) construction: BGG+-style circuit evaluation on LWE ciphertexts, pairing compresses the lattice short preimage into 3 group elements.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2022-LLL","year":2022},{"assumption_family":"hybrid","assumption_id":"ABE-ASSUMPTION-LWE-EVASIVE-LWE","assumption_name":"LWE + evasive LWE","authors":["Yao-Ching Hsieh","Huijia Lin","Ji Luo"],"capabilities":[],"construction_family":"lattice","decrypt_cost":{},"decrypt_pairings":"0","ggm_file":null,"id":"hll24","large_universe":0,"multi_use_attributes":0,"paper_title":"A General Framework for Lattice-Based ABE Using Evasive Inner-Product Functional Encryption","paper_url":"https://eprint.iacr.org/2024/821","policy_class":"circuit","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"note":"§6: (|C|+1)·poly(λ,log M,d) — linear in CIRCUIT SIZE; §8: poly(λ,log M,d) only — succinct in DEPTH; §7: (|x|+1)·poly(λ) for DFA-CP."},"MPK":{"note":"poly(λ, log M, d) for circuits; poly(λ) for DFA. M is intermediate-value bound, d is depth."},"SK":{"note":"(|x|+1)·poly(λ,log M,d) for §6 generic; constant-poly(λ) for §8 succinct CP-ABE; (|x|+1)·poly(λ) for §7 DFA-CP."},"abstraction_note":"HLL24 contains MULTIPLE constructions with different size profiles.\nThe headline (eliminating tensor LWE vs Wee22) is the §8 succinct\nCP-ABE for circuits, where ct depends on circuit DEPTH only (via\nBGG+14 garbling instantiation).\n","sources":["HLL24 Corollary 21 (generic CP-ABE, §6)","HLL24 Corollary 29 (DFA, §7)","HLL24 Corollary 34 (succinct CP-ABE for circuits, §8 — sizes implied)"]},"summary":"General framework for lattice ABE: noisy linear garbling for class F + evasive IPFE → KP/CP-ABE for F. Yields succinct CP-ABE for circuits (eliminating tensor LWE), and the first lattice public-key ABE for uniform computation (DFA + logspace TM).","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2024-HLL","year":2024},{"assumption_family":"LWE","assumption_id":"ABE-ASSUMPTION-RING-LWE","assumption_name":"Ring-LWE","authors":["Sora Suegami","Enrico Bottazzi"],"capabilities":["nonlinear-operations","lookup-tables","arithmetic-circuits","post-quantum"],"construction_family":"lattice","decrypt_cost":{"note":"Larger B reduces repeated decryption work but increases key generation and key size by a polynomial-in-B factor.","pairings":"0","primary":"Õ(N · poly(λ,D)² / log₂B) lattice evaluation"},"decrypt_pairings":"0","ggm_file":null,"id":"sb25_nonlinear_kpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Lookup-Table Evaluation over Key-Homomorphic Encodings and KP-ABE for Nonlinear Operations","paper_url":"https://eprint.iacr.org/2025/1870","policy_class":"arithmetic_circuit","primitive":"KP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"asymptotic":"Õ(L · poly(D) / log₂B)","note":"Compatible with base-B lookup-table evaluation."},"MPK":{"asymptotic":"Õ(L · poly(D) / log₂B)","note":"Amortized expression; poly(lambda) and polylog(lambda,D) factors are hidden."},"SK":{"asymptotic":"Õ(B²N · poly(D) / (log₂B)²)","note":"Decryption-key size grows polynomially in the lookup-table base B."},"sources":["SB25 Table 1"]},"summary":"Ring-LWE KP-ABE for modulo-q arithmetic circuits that evaluates nonlinear lookup tables directly over BGG+ encodings, trading larger keys and KeyGen cost for faster repeated decryption.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2025-SB-LUT","year":2025},{"assumption_family":"succinct-LWE","assumption_id":"ABE-ASSUMPTION-POLY-LAMBDA-SUCCINCT-LWE","assumption_name":"poly(lambda)-succinct LWE","authors":["Jiaqi Liu","Yuanyi Zhang","Fang-Wei Fu"],"capabilities":["constant-ciphertext","nc1","post-quantum","broadcast-encryption"],"construction_family":"lattice","decrypt_cost":{"note":"The headline contribution is ciphertext size; the source does not reduce the result to a pairing-equivalent cost.","pairings":"0","primary":"lattice reconstruction + rounding"},"decrypt_pairings":"0","ggm_file":null,"id":"lzf26_constant_ct_cpabe","large_universe":0,"multi_use_attributes":0,"paper_title":"Ciphertext-Policy ABE for NC1 Circuits with Constant-Size Ciphertexts from Succinct LWE","paper_url":"https://eprint.iacr.org/2026/534","policy_class":"NC1","primitive":"CP-ABE","security_mode":"selective","security_model":"standard","security_notion":"CPA","sizes":{"CT":{"asymptotic":"O(poly(λ))","note":"Independent of circuit size s, input length ell, and depth d."},"MPK":{"asymptotic":"O(s · poly(λ))","note":"The uniformly random portion can be PRG-generated, yielding O(poly(lambda)) stored public parameters."},"SK":{"asymptotic":"O(ℓ · poly(λ))","note":"The finer bound depends on the number of attributes held by the user."},"sources":["LZF26 §1 contribution 1"]},"summary":"Selectively secure lattice CP-ABE for NC1 with ciphertext size poly(lambda), independent of circuit size, input length, and depth.","verification_status":"blocked_hybrid","work_id":"ABE-PAPER-2026-LZF-CONSTANT-CT","year":2026}],"edges":[{"evidenceLocator":"","evidenceUrl":"","id":"REL-1F061533C8EC48","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-001","target":"ABE-OP-004","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9B36FEA64EB2C1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-002","target":"ABE-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-292D8894775094","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-002","target":"ABE-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FE457687DB19C9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-002","target":"ABE-OP-006","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FB8B2527385481","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-002","target":"ABE-OP-012","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5673E30EBC80AE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-003","target":"ABE-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-053B00063C8899","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-003","target":"ABE-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0ED2F19474BDEA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-004","target":"ABE-OP-003","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-73EF9D3962C6E0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-004","target":"ABE-OP-007","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-29E5E654D4A8E6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-005","target":"ABE-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1202EE359156C8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-005","target":"ABE-OP-008","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-47642A73207FA4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-006","target":"ABE-OP-007","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-151DEEBBE0104E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-BARRIER-007","target":"ABE-OP-010","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BDEF437FD55AB1","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-001-01","target":"ABE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2A540DCBA4929A","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-001-02","target":"ABE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F51CFFF86E1352","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-001-03","target":"ABE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CA5B8A41B670AA","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-001-04","target":"ABE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6A26A82AFEE3A5","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-002-01","target":"ABE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-27CD71E6A7F3C2","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-002-02","target":"ABE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-317AD5D7EA10DC","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-002-03","target":"ABE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A0AC70BD2D8113","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-002-04","target":"ABE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-61FDEB719FDB5D","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-003-01","target":"ABE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-08ECC606C73699","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-003-02","target":"ABE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-71CF68889CD00A","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-003-03","target":"ABE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-875265E9E4FCFE","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-003-04","target":"ABE-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-61135E535B184D","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-004-01","target":"ABE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8BCD7BECF23DCB","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-004-02","target":"ABE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A34A295555B647","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-004-03","target":"ABE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DDBD98793C78E0","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-004-04","target":"ABE-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-19DE5F653AC492","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-005-01","target":"ABE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8B7AA085533191","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-005-02","target":"ABE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-42B549ABF3D9FB","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-005-03","target":"ABE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2B7378D21BEA93","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-005-04","target":"ABE-OP-005","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3C65ACF75DA34A","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-006-01","target":"ABE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A5BA2A47E2FD0B","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-006-02","target":"ABE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EDEA36EDC05D3A","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-006-03","target":"ABE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-ECD26950B72F1D","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-006-04","target":"ABE-OP-006","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F22840F7C148B8","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-007-01","target":"ABE-OP-007","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AABCD322BEBED0","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-007-02","target":"ABE-OP-007","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-11A2370F7E4E94","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-007-03","target":"ABE-OP-007","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7CC543CB831965","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-007-04","target":"ABE-OP-007","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9772702C43B244","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-008-01","target":"ABE-OP-008","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-373D3EB83518F5","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-008-02","target":"ABE-OP-008","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AF032DF66AEF32","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-008-03","target":"ABE-OP-008","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-563DFB8C65DD8F","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-009-01","target":"ABE-OP-009","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AFBDCB891CC575","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-009-02","target":"ABE-OP-009","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F9F88ADC34E4E8","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-009-03","target":"ABE-OP-009","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-98EFF0B9873868","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-009-04","target":"ABE-OP-009","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-532188379C3D4E","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-010-01","target":"ABE-OP-010","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5FCB040A1E7AE0","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-010-02","target":"ABE-OP-010","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D17EF23ADFD66C","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-010-03","target":"ABE-OP-010","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2B20545F163427","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-010-04","target":"ABE-OP-010","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D93421E6A474D3","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-011-01","target":"ABE-OP-011","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CECFBC356169AC","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-011-02","target":"ABE-OP-011","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-73119E1CE9E7FA","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-011-03","target":"ABE-OP-011","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FCC5D1E82294C8","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-011-04","target":"ABE-OP-011","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-09D17260010A5E","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-012-01","target":"ABE-OP-012","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1E8D8D3735B008","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-012-02","target":"ABE-OP-012","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A78C580D24A638","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-012-03","target":"ABE-OP-012","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E25FF53F4F2252","note":"","resultId":null,"reviewStatus":"source-derived","source":"ABE-MILESTONE-012-04","target":"ABE-OP-012","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4EC41BED1DBDF6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-001","target":"ABE-PAPER-2022-LLL","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FA0E7E9A447B6E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-001","target":"ABE-PAPER-2024-CW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AC1C375D59A792","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-001","target":"ABE-PAPER-2025-WEE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7D99BB4241C2CB","note":"Solves the bounded-depth plain-LWE/adaptive/all-object size core needed by the completely-unbounded endpoint.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-001","target":"ABE-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E6D6959EDEDD60","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-002","target":"ABE-PAPER-2012-OT","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CB5D9FF466E8EC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-002","target":"ABE-PAPER-2018-CGKW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CADE06D09221FE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-002","target":"ABE-PAPER-2024-CW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1FCD4E9440566E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-002","target":"ABE-PAPER-2025-WEE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A7647B32F39AFE","note":"A safe direct removal of depth bounds supplies the all-circuit expressivity component of universal ordinary ABE.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-003","target":"ABE-OP-002","type":"ENABLING_COMPONENT_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7AB097AEEC75FE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-003","target":"ABE-PAPER-2023-HLL","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5D1C16BA06FBA2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-003","target":"ABE-PAPER-2026-AMYY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-805F7408A2845A","note":"Expressive falsifiable-lattice DMPE supplies a central policy-sharing/recoding component for clean-PQ trustless ABE.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-004","target":"ABE-OP-005","type":"ENABLING_COMPONENT_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8DAF139813BC28","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-004","target":"ABE-PAPER-2026-CW-DMPE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4391230D8E9034","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-004","target":"ABE-PAPER-2026-CW-OPT-DMPE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-74C83C8DBB022D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-005","target":"ABE-PAPER-2011-LW-MAABE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-75422C0EC575F5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-005","target":"ABE-PAPER-2023-HLWW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D15B1BF9BD7E99","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-005","target":"ABE-PAPER-2023-ZZGQ-REGPE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0223021DF83D44","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-005","target":"ABE-PAPER-2025-LWW-MARABE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D4B012924BF6E6","note":"A standard-model adaptive equivocation layer would remove a central model barrier in succinct trustless ABE.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-006","target":"ABE-OP-005","type":"ENABLING_COMPONENT_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AB008F30A5B44D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-006","target":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-08452AF71EED94","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-006","target":"ABE-PAPER-2026-CW-OPT-DMPE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-91E9E9ED44C517","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-006","target":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9E543B66D49984","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-006","target":"ABE-PAPER-2026-GY-FBE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F5083489D72BCD","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-007","target":"ABE-PAPER-2023-JLL","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E9A66C77DC52D6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-007","target":"ABE-PAPER-2025-AMY-TM","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B6D94A40CD4320","note":"Direct safe RAM/TM ABE extends the unbounded-depth circuit goal to uniform computation and actual running time.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-007","target":"ABE-OP-003","type":"STRENGTHENS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-594403A9AA6F52","note":"Tests whether the static-assumption pairing branch can retain state-of-the-art concrete costs; it does not by itself solve universal ABE.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-OP-002","type":"BENCHMARK_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DDDA80CC5C847F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-PAPER-2007-BSW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4C0498B82B1D18","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-PAPER-2013-RW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3FE3C629B3728E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-PAPER-2014-CW-SEMIADAPTIVE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2731FF1A0DEC9A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-PAPER-2017-FAME","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-32D276A7B2314D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-PAPER-2019-KW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-19D800F8A67F46","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-008","target":"ABE-PAPER-2022-FABEO","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9DD876B743466E","note":"Polynomial-arity MIABE is the explicit missing primitive for the classical-certificate ABE-SKL branch.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-009","target":"ABE-OP-011","type":"ENABLING_COMPONENT_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FEF9471E0C9FB9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-009","target":"ABE-PAPER-2022-AYY-MIABE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-04BF4EE1BFBEE9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-009","target":"ABE-PAPER-2023-ARYY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9AF7A396BBB831","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-010","target":"ABE-PAPER-2010-LOSSTW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1BBC6A4811F7D3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-010","target":"ABE-PAPER-2018-CGW-IPE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F6EC06D3394E7C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-010","target":"ABE-PAPER-2020-AY-FH","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-526B7E1A482B4C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-010","target":"ABE-PAPER-2025-WBWL-PE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CDA77EDD57B539","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-011","target":"ABE-PAPER-2012-SSW-REVOCATION","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E4AA86493815C1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-011","target":"ABE-PAPER-2021-GLW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BC9B7499DF01B4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-011","target":"ABE-PAPER-2024-LYXXZPD-HRABE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7C46FCE73C6894","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-011","target":"ABE-PAPER-2025-KNP-SKL","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-30AFBEB335C981","note":"Supplies the adaptive-policy-key simulation component of universal ordinary ABE.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-OP-002","type":"ENABLING_COMPONENT_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3D7A74D93DE362","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-PAPER-2019-KW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F947F14697B2BC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-PAPER-2019-TSABARY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9BEDA8864118F3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-PAPER-2024-CW","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3003DDF48A7412","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-PAPER-2025-WEE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F49659F2E04F12","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-089E3D570F3953","note":"Isolates adaptive reusable NC1 security while allowing ordinary polynomial sizes and stronger falsifiable lattice assumptions.","resultId":null,"reviewStatus":"source-declared","source":"ABE-OP-012","target":"ABE-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F24EB5671F90A1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2005-SW","target":"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DE0E9E2AF429D3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2005-SW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-41C9E63E91CE0F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2006-GPSW","target":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B6CD1C628E0FF3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2006-GPSW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-51D719AAE30F2D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2007-BSW","target":"ABE-RESULT-2007-BSW-ADAPTIVE-GENERIC-GROUP-SECURITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C2127FC3743D83","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2007-BSW","target":"ABE-RESULT-2007-BSW-IMPLEMENTED-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6E10436926472A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2007-BSW","target":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-682B709CAE4547","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2007-BSW","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3EFBE9DE4D18AC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2010-LOSSTW","target":"ABE-RESULT-2010-LOSSTW-FIRST-FULLY-SECURE-ABE-FOR-ARBITRARY-MONOTONE-FORMULAS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F6F7D27C64E500","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2010-LOSSTW","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3BCF7D14E9E9FB","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2010-LOSSTW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-202227AD55839B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-LW-MAABE","target":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B2F0E5D93C4696","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-LW-MAABE","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2EDD047DBB8C79","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-LW-UNBOUNDED","target":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E801DA50FF5263","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-LW-UNBOUNDED","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-50888721BB713A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-WATERS","target":"ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F1CC86D72F58D9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-WATERS","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2B6709CF7B6727","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2011-WATERS","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3BB96F684EA05B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-LW","target":"ABE-RESULT-2012-LW-FULL-SECURITY-FROM-SELECTIVE-PROOF-COMPONENTS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9C34FE85F566FB","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-LW","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7E8E2E545F9579","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-LW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-21FD8EE38E1029","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-OT","target":"ABE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6DEE6D501084FC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-OT","target":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2A60100AF92701","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-OT","target":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-IPE-WITH-FULL-ATTRIBUTE-HIDING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-50AF18E7C24B88","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-OT","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-04C919232625EF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-SSW-REVOCATION","target":"ABE-OP-011","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7405ADA0AB2881","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2012-SSW-REVOCATION","target":"ABE-RESULT-2012-SSW-REVOCATION-INTRODUCED-REVOCABLE-STORAGE-ABE-AND-CIPHERTEXT-DELEGATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-53472C538FD62C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-BNS-ARITH","target":"ABE-RESULT-2013-BNS-ARITH-DEPTH-DEPENDENT-SECRET-KEYS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C8D3A837D8AFF5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-BNS-ARITH","target":"ABE-RESULT-2013-BNS-ARITH-LWE-ABE-FOR-ARITHMETIC-CIRCUITS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-27A5BCB62E7E06","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-GGHSSW","target":"ABE-RESULT-2013-GGHSSW-FIRST-GENERAL-CIRCUIT-ABE-FROM-MULTILINEAR-MAPS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3965146841DD05","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-GGHSSW","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-09C987089C4B5D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-GGHSSW","target":"ABE-OP-007","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0F66CEBF2BE3FE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-GVW","target":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-17395DF7382DC2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-GVW","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0B54CF4E68B017","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-GVW","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-88825CEC6A1D9A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-HW-FAST","target":"ABE-RESULT-2013-HW-FAST-CONSTANT-TWO-PAIRING-KP-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-230EC7F5955CF5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-HW-FAST","target":"ABE-RESULT-2013-HW-FAST-PER-USER-EFFICIENCY-TRADEOFF","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B43AC08E6C5701","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-RW","target":"ABE-OP-008","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D5A71F9A78F294","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-RW","target":"ABE-RESULT-2013-RW-EFFICIENT-LARGE-UNIVERSE-KP-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-515DB8FFFDC140","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-RW","target":"ABE-RESULT-2013-RW-PRACTICAL-LARGE-UNIVERSE-CP-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-55458CBBE8D49C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2013-RW","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0D21F1B411F0D2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-ATTRAPADUNG","target":"ABE-RESULT-2014-ATTRAPADUNG-INTRODUCED-PAIR-ENCODING-FRAMEWORK","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DDC30BA0C8E1A8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-ATTRAPADUNG","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2BE52CB94EEE06","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-BGGPS","target":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-44D6FFAB0AC406","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-BGGPS","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-91AA4A11321368","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-CW-SEMIADAPTIVE","target":"ABE-RESULT-2014-CW-SEMIADAPTIVE-CONSTANT-CIPHERTEXT-SEMI-ADAPTIVE-KPABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-879EC24E5DE4E3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-CW-SEMIADAPTIVE","target":"ABE-RESULT-2014-CW-SEMIADAPTIVE-INTRODUCED-SEMI-ADAPTIVE-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E3F0681DD1EBF6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2014-CW-SEMIADAPTIVE","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-42460B9C006D79","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2015-CGW","target":"ABE-RESULT-2015-CGW-MODULAR-ADAPTIVE-ABE-FROM-PREDICATE-ENCODINGS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-013EFA26993ACD","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2015-CGW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C8F2711DB36307","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2015-CGW","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AC9FFA215583ED","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2016-BV","target":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D39137872DA42C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2016-BV","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-562F9FE373ECFD","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2016-BV","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-76F1735358870C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2017-ABGW","target":"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-28C3B9A14488D4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2017-ABGW","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FD46097500057E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2017-FAME","target":"ABE-OP-008","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E44003C5A0814E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2017-FAME","target":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7391D25C566DBB","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2017-FAME","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-069106F7DCB39C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2018-CGKW","target":"ABE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BB4AF226A3B7A4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2018-CGKW","target":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8FFBBD08E6CDC6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2018-CGKW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3F6BE2D1DDA625","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2018-CGW-IPE","target":"ABE-OP-010","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EE056C99D141DA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2018-CGW-IPE","target":"ABE-RESULT-2018-CGW-IPE-ADAPTIVE-FULL-ATTRIBUTE-HIDING-IPE-FROM-K-LIN","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A8D53D39B8DA36","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-AMY-DFA","target":"ABE-RESULT-2019-AMY-DFA-DFA-ABE-FROM-STATIC-DLIN","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-625291148FE32F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-AMY-DFA","target":"ABE-RESULT-2019-AMY-DFA-UNBOUNDED-MACHINES-INPUTS-AND-QUERIES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D89870786A37B4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW","target":"ABE-OP-008","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-41FA8D367AB3F2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW","target":"ABE-OP-012","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4F61B445919CBC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW","target":"ABE-RESULT-2019-KW-COMPACT-ADAPTIVE-MANY-USE-ABE-FOR-NC1","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3E80B81C01E79C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EA5FB780FB41F1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-51D31B1C73D1EA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F982675C694486","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-KW-CCA","target":"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F654C4743AAFB2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-TSABARY","target":"ABE-OP-012","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-87F7C6FD67D893","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-TSABARY","target":"ABE-RESULT-2019-TSABARY-FIRST-ADAPTIVE-LATTICE-ABE-BEYOND-IBE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A6F5AD7E026C1D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-TSABARY","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E00C84D546C82B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2019-TSABARY","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-94124EE9E11C81","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AT","target":"ABE-RESULT-2020-AT-ADAPTIVE-COMPLETELY-UNBOUNDED-FORMULA-ABE-FROM-MDDH","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-ECE6277920B8A7","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AT","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E97C403F9A7548","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY","target":"ABE-RESULT-2020-AY-OPTIMAL-BROADCAST-VIA-ALL-DIMENSION-INDEPENDENT-CPABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-92833E27726956","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0D9C4B40BDDE05","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-10DC1CA15251EF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY","target":"ABE-OP-009","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5A70F9FE721933","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY-FH","target":"ABE-OP-010","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AA794CB5C92A0E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY-FH","target":"ABE-RESULT-2020-AY-FH-NATURAL-FULL-FUNCTION-HIDING-CIRCUIT-ABE-IMPLIES-IO","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6E370CE44CF74A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY-FH","target":"ABE-RESULT-2020-AY-FH-WEAKENED-FUNCTION-HIDING-PE-FROM-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B34584C4CDAC01","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-AY-FH","target":"ABE-OP-010","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A0726FE20F69DB","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-LL","target":"ABE-RESULT-2020-LL-ADAPTIVE-ABP-ABE-WITH-ONE-CONSTANT-SIDE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-96A2F0BB0F1D1D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-LL","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AB3100F5ECFB72","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-LL","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AE693D737C4688","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-LL-EUROCRYPT","target":"ABE-RESULT-2020-LL-EUROCRYPT-COMPACT-ADAPTIVE-KPABE-FOR-ABPS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-447D9E77995CE7","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-LL-EUROCRYPT","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AEFCC0726E9AAC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2020-LL-EUROCRYPT","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AC4F53191F8BEF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2021-DKW","target":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4C73B7AFB3FA25","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2021-DKW","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3E5C7BFFE33834","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2021-GLW","target":"ABE-RESULT-2021-GLW-ADAPTIVE-ABE-FROM-SEARCH-BDH-VIA-DELETION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3B1E95AC2ACAC0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2021-GLW","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1EC98DBCEE346F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2021-GLW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-262DFB1591AE1D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-AYY-MIABE","target":"ABE-OP-009","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8143F6252A6092","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-AYY-MIABE","target":"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-001E2AB28411C2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-AYY-MIABE","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AB4792BDC9FE67","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-FABEO","target":"ABE-OP-008","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1B0626E397A130","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-FABEO","target":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-88304DFF1842F0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-FABEO","target":"ABE-OP-008","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-12844D537E6D77","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-LLL","target":"ABE-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4ABEF24016AF80","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-LLL","target":"ABE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-83915666D150AF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-LLL","target":"ABE-RESULT-2022-LLL-CONSTANT-SIZE-CIRCUIT-KPABE-KEYS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9707AE2F0C95B8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-LLL","target":"ABE-RESULT-2022-LLL-DOUBLE-SUCCINCT-FORMULA-CPABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-58613156AC2283","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-LLL","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5A2FB90B2EBBB0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-LLL","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2332CE4CCE5C15","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-VA-GLUE","target":"ABE-RESULT-2022-VA-GLUE-FLEXIBLE-ENCRYPTION-DECRYPTION-TRADEOFF","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EE5ACCB619B630","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-VA-GLUE","target":"ABE-RESULT-2022-VA-GLUE-GENERALIZED-UNBOUNDED-EXPRESSIVE-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4CC0F4ED599DCB","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-WWW-MAABE","target":"ABE-RESULT-2022-WWW-MAABE-PLAIN-MODEL-MAABE-FOR-SUBSET-POLICIES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-86F7FBEF57CB36","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2022-WWW-MAABE","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6635D9DE4CE5F1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ARYY","target":"ABE-OP-009","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4EB5B464D45A97","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ARYY","target":"ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A059C6E0CC3C29","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ARYY","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C6E8220F6DD7B2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-DKW","target":"ABE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-582976576FC8D4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-DKW","target":"ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9754BDC5EEC549","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-DKW","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AE6B74F54303EC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-FWW","target":"ABE-RESULT-2023-FWW-REGISTERED-ABE-FROM-PLAIN-WITNESS-ENCRYPTION-AND-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-57B559C5B7F53C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-FWW","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-15E1052C2D45BC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-FWW","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-611479B4211108","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLL","target":"ABE-OP-003","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A72D2400DE42E6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLL","target":"ABE-RESULT-2023-HLL-CONSTANT-SIZE-GARBLING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2F85722D14A6BE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLL","target":"ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C1E4426CC44F24","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLL","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9007799D816205","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLL","target":"ABE-OP-007","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-00CA2966E86AA2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLWW","target":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2C4CF7C34DEE95","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLWW","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BEACF4AFAAC2C5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-HLWW","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A5319AF6870B9D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-JLL","target":"ABE-OP-007","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D4B62A92E049F2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-JLL","target":"ABE-RESULT-2023-JLL-CONSTANT-KEY-CIPHERTEXT-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DBD210DAE51DE0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-JLL","target":"ABE-RESULT-2023-JLL-RAM-PHFE-FROM-FE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-26D92DF3D34A06","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-JLL","target":"ABE-RESULT-2023-JLL-SPACE-TIME-LOWER-BOUNDS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DAA156217A2989","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-JLL","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4446F9915E00F8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-JLL","target":"ABE-OP-007","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-603B3830B27D9D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ZZGQ-REGPE","target":"ABE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-14BB791273CF34","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ZZGQ-REGPE","target":"ABE-RESULT-2023-ZZGQ-REGPE-GENERIC-REGISTERED-ABE-FROM-PREDICATE-ENCODINGS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0F9E858C94BAEE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ZZGQ-REGPE","target":"ABE-RESULT-2023-ZZGQ-REGPE-PRIME-ORDER-REGISTERED-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-624C7563D2738D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ZZGQ-REGPE","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-74901224448AD3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2023-ZZGQ-REGPE","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-04F2E233626B2E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8595F00F66C06B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-93BBF93D088868","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-OP-012","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8CDA6F8F0376F8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-900AB4CD731813","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8136A5DE43C431","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9EA9FD0A17203A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-CW","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7FBC809A698981","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-GLWW","target":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-228AC0920C4377","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-GLWW","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C2DC58E95DFE1B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-HLL","target":"ABE-RESULT-2024-HLL-GENERAL-LATTICE-ABE-FRAMEWORK-VIA-NOISY-LSSS-AND-EVASIVE-IPFE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EBA4504C3EF44E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-HLL","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-92BE1D78542237","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-HLL","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BAAD66803E6DAF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-HLL","target":"ABE-OP-007","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3B62DE69750341","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-LYXXZPD-HRABE","target":"ABE-OP-011","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BF519702F3444D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-LYXXZPD-HRABE","target":"ABE-RESULT-2024-LYXXZPD-HRABE-TEE-ASSISTED-REVOCATION-WITHOUT-BULK-CIPHERTEXT-DELEGATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7A025713658D58","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-LYXXZPD-HRABE","target":"ABE-OP-011","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8E735EDA13AA89","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-VB-CCA","target":"ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-54D7733401501E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WEE","target":"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4FD5CE43B278AA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WEE","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-567621DE252AF3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WEE","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-733BCC5B3E890F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WW","target":"ABE-OP-012","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F0840E17111881","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WW","target":"ABE-RESULT-2024-WW-ADAPTIVE-ABE-FROM-WITNESS-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C9C3CFC0B0C3D8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WW","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-24C0DC21B59D4B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WW","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-51187B84EE1D16","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WW","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-ED379964B4C52D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2024-WW","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EC35A2AE0C35E5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-AMY-TM","target":"ABE-OP-003","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8017A95339DF86","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-AMY-TM","target":"ABE-OP-007","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-182CC88E8367D0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-AMY-TM","target":"ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-NL","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-00D55F976D1D12","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-AMY-TM","target":"ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-TURING-MACHINES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-25E782B13C223E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-AMY-TM","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EA98DF229C0636","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-AMY-TM","target":"ABE-OP-007","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9A6A40FDD76705","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-CHW-RABE","target":"ABE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-98A744B4FCE5B8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-CHW-RABE","target":"ABE-RESULT-2025-CHW-RABE-ADAPTIVE-DISTRIBUTED-BROADCAST-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B97D757C49CC9E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-CHW-RABE","target":"ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AD0E908CEF6DB2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-CHW-RABE","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-76B4118F53F8EA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-CHW-RABE","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BE70CE08B1DB98","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","target":"ABE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4F57433D90A591","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","target":"ABE-RESULT-2025-HWW-ADAPTIVE-BE-PUBLICLY-SAMPLEABLE-PROJECTIVE-PRG","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5952A87D1589DD","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","target":"ABE-RESULT-2025-HWW-ADAPTIVE-BE-SEMI-STATIC-TO-ADAPTIVE-BE-COMPILER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F6CEF98EE413AE","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7D8A2D5A3DBB8F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A37EF9EDCB8FC9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-KNP-SKL","target":"ABE-OP-011","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CF14913D56E5AA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-KNP-SKL","target":"ABE-RESULT-2025-KNP-SKL-COLLUSION-RESISTANT-ABE-SECURE-KEY-LEASING-FROM-LWE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-81CEB296EC2127","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-KNP-SKL","target":"ABE-OP-011","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8EBE319BBEC8E9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-LWW-MARABE","target":"ABE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EC5E4B978AC95B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-LWW-MARABE","target":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7FDF1C3A1A5CE6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-LWW-MARABE","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1E3443CDA7B47B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-SB-LUT","target":"ABE-RESULT-2025-SB-LUT-LOOKUP-TABLE-EVALUATION-OVER-BGG-ENCODINGS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E9B1B86460A343","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-SB-LUT","target":"ABE-RESULT-2025-SB-LUT-RING-LWE-KP-ABE-FOR-NONLINEAR-OPERATIONS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5DEB906949F89F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WBWL-PE","target":"ABE-OP-010","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B3D8180EC11F55","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WBWL-PE","target":"ABE-RESULT-2025-WBWL-PE-SELECTIVE-FULLY-ATTRIBUTE-HIDING-BOUNDED-COLLUSION-CIRCUIT-PE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BF331FE70DA035","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WBWL-PE","target":"ABE-OP-010","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FA2136EAC7AA9E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B32C892BCF0273","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C7EB84BE194881","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-OP-012","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-597960E2F29329","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-CPABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D22D792EFD95E2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F7BC0904745925","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2343940AECD30E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-OP-002","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4AF71821AD8A9B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2025-WEE","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-96B967C5137E3C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-AMYY","target":"ABE-OP-003","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2213D2DD4FD3DC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-AMYY","target":"ABE-RESULT-2026-AMYY-UNBOUNDED-DEPTH-ABE-FROM-DOUBLY-CIRCULAR-ASSUMPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F624F234CF0E3E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-AMYY","target":"ABE-OP-003","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4956FAA5283DC1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-DMPE","target":"ABE-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-AD5939CB66CDD1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-DMPE","target":"ABE-RESULT-2026-CW-DMPE-SUCCINCT-DNF-DMPE-FROM-LATTICES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E443EF655F63C9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-DMPE","target":"ABE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6B7BD29B0C80E6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A45490738F4A87","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-444E139119F69E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-RESULT-2026-CW-OPT-DMPE-ADAPTIVE-UNBOUNDED-BROADCAST","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BA45F3EC4592FA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-RESULT-2026-CW-OPT-DMPE-OPTIMAL-DNF-DMPE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-687A316A797F5A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-RESULT-2026-CW-OPT-DMPE-PLAIN-MODEL-DMPE-TRADEOFFS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-76EF293388C675","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BADB1EFB9D64CC","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-CW-OPT-DMPE","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0DCAFD9B14FBB7","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","target":"ABE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7D892B6EBE4A39","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","target":"ABE-OP-012","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-87DC0DBDBEF725","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","target":"ABE-RESULT-2026-GY-EQUIVOCAL-BE-EQUIVOCAL-ENCRYPTION-SYSTEMS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D60E2E86CD2105","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","target":"ABE-RESULT-2026-GY-EQUIVOCAL-BE-OPTIMAL-ADAPTIVE-LATTICE-DBE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FC2DE6B1D8B6F5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-24FB3268D6EC31","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","target":"ABE-OP-012","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A883C054A73E90","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-FBE","target":"ABE-OP-006","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3F30DCFCB2843C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-FBE","target":"ABE-RESULT-2026-GY-FBE-EQUIVOCAL-MATRIX-COMMITMENTS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BCC813AFA3E889","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-FBE","target":"ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-FBE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9EED24A95A1ABD","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-FBE","target":"ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-IBBE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9408C213361D1E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-GY-FBE","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0A2BB046447807","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-LZF-CONSTANT-CT","target":"ABE-RESULT-2026-LZF-CONSTANT-CT-CONSTANT-SIZE-CIPHERTEXT-CP-ABE-FOR-NC1","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4F65314BAA4F60","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-LZF-CONSTANT-CT","target":"ABE-RESULT-2026-LZF-CONSTANT-CT-SUCCINCT-LWE-BROADCAST-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-492EDE71E3CC25","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-SWW-RABE","target":"ABE-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5F9022B2E276E0","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-SWW-RABE","target":"ABE-OP-005","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D531562D9EA778","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-SWW-RABE","target":"ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A502074DD2ECBF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-SWW-RABE","target":"ABE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C77FEA81C66124","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-SWW-RABE","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-18088E752118E7","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-WW-SILENT","target":"ABE-RESULT-2026-WW-SILENT-PLAIN-MODEL-SILENT-THRESHOLD-CRYPTOGRAPHY-FOR-EXPRESSIVE-POLICIES","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E7CC18D39967E7","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-WW-SILENT","target":"ABE-OP-004","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7620D8AA684B9B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-WW-SILENT","target":"ABE-OP-005","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-364595AEBD19B2","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-PAPER-2026-WW-SILENT","target":"ABE-OP-006","type":"TARGETS"},{"evidenceLocator":"Abstract and Section 1 (Introduction)","evidenceUrl":"https://eprint.iacr.org/2006/309.pdf","id":"REL-AD19A98A38BCD2","note":"GPSW broadened the threshold set-overlap semantics of fuzzy IBE into key-policy ABE, placing an arbitrary monotone access structure in the secret key while labeling ciphertexts by attribute sets.","resultId":"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","target":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","type":"GENERALIZES"},{"evidenceLocator":"Section 1, 'Our techniques'; Section 2, lines describing KP-ABE and CP-ABE","evidenceUrl":"https://www.cs.ucla.edu/~sahai/work/web/2007%20Publications/SSP2007.pdf","id":"REL-5BF3CE9ABAAE55","note":"BSW reverses GPSW's policy placement: attributes are attached to user keys and the encryptor places the access tree in the ciphertext, yielding a concrete CP-ABE construction.","resultId":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","target":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","type":"CHANGES_MODEL"},{"evidenceLocator":"Section 1.1, 'Our results'; comparison with BSW in Table 1","evidenceUrl":"https://eprint.iacr.org/2008/290.pdf","id":"REL-676834DE2B49EE","note":"Waters gives expressive LSSS-based CP-ABE with a selective-security reduction under concrete non-interactive assumptions in the standard model, replacing BSW's generic-group/random-oracle justification without claiming adaptive standard-model security.","resultId":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","target":"ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"Tables 1.1-1.2; Section 1.1; Section 5, especially Table 5.5","evidenceUrl":"https://eprint.iacr.org/2017/807.pdf","id":"REL-059E10456D880B","note":"FAME kept unrestricted policies and arbitrary attributes, moved to efficient Type-III pairings with full security under a standard assumption, and reports 25 percent smaller ciphertexts and keys than BSW.","resultId":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","target":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Abstract and Section 1, comparison with prior MA-ABE","evidenceUrl":"https://eprint.iacr.org/2020/1386.pdf","id":"REL-C1DA20DCA0A3CE","note":"DKW preserves Lewko-Waters' fully decentralized authority model but moves the construction from bilinear assumptions to LWE, at the price of DNF policies and continued use of the random-oracle model.","resultId":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","target":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"Section 1.1, 'Multi-authority ABE' and 'Registered multi-authority ABE'; Section 2","evidenceUrl":"https://www.cs.utexas.edu/~dwu4/papers/RegisteredMA-ABE.pdf","id":"REL-4CB5B8FBE10E37","note":"LWW imports the Lewko-Waters cross-domain, no-authority-coordination model into registered ABE, preserving policies across independently managed attribute domains while removing long-term key-issuer secrets.","resultId":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","target":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE","type":"COMBINES"},{"evidenceLocator":"Section 1.1.2, 'Unbounded IPE and ABE'","evidenceUrl":"https://eprint.iacr.org/2012/671.pdf","id":"REL-2873F16344E89F","note":"Okamoto-Takashima preserved unbounded ABE but removed the selective-only limitation of the Lewko-Waters ABE, obtaining the first fully secure unbounded ABE under DLIN in the standard model.","resultId":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","target":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","type":"EXTENDS"},{"evidenceLocator":"Abstract; Section 1, 'Our results'","evidenceUrl":"https://eprint.iacr.org/2018/116.pdf","id":"REL-3E19BB2B4A4D82","note":"CGKW revisited Lewko-Waters with a simpler entropy-expansion route and upgraded the composite-order unbounded ABE branch from selective to adaptive security.","resultId":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","target":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS","type":"EXTENDS"},{"evidenceLocator":"Abstract; Section 1, results (i)-(ii)","evidenceUrl":"https://eprint.iacr.org/2018/116.pdf","id":"REL-DE6802E40C744D","note":"In the prime-order branch, CGKW uses bilinear entropy expansion to retain adaptive unbounded ABE from k-Lin while shortening ciphertexts and keys relative to Okamoto-Takashima and extending expressivity to arithmetic branching programs.","resultId":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","target":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Abstract and Section 1, discussion of the decade-old depth-dependency question","evidenceUrl":"https://eprint.iacr.org/2023/1716.pdf","id":"REL-E1AF0C55C59346","note":"HLL attacks the setup-time depth dependence left by GVW-era lattice circuit ABE and obtains full-fledged circuit ABE for unbounded depth and size under evasive circular LWE, with a constant-size secret key.","resultId":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","target":"ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE","type":"GENERALIZES"},{"evidenceLocator":"Section 1.1, 'Our results' (the paragraph beginning 'Inspired by the work of GVW')","evidenceUrl":"https://eprint.iacr.org/2014/356.pdf","id":"REL-7007DA43005415","note":"BGGPS starts from the GVW lattice circuit-ABE direction, supports arithmetic circuits and replaces circuit-size-dependent secret keys with keys whose size depends only on circuit depth.","resultId":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","target":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Section 1, prior circuit-ABE discussion and Question Q1; construction overview","evidenceUrl":"https://eprint.iacr.org/2016/118.pdf","id":"REL-F1F3910CF92C54","note":"Brakerski-Vaikuntanathan builds on bounded circuit-ABE ideas including BGGPS to obtain the first LWE circuit ABE with unbounded attribute length, while retaining a setup-time depth bound and adding semi-adaptive security.","resultId":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","target":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"Abstract and Section 1, paragraphs on BV16 and the non-black-box drawback","evidenceUrl":"https://eprint.iacr.org/2024/1507.pdf","id":"REL-CA2E8CFCBCE6D8","note":"Cini–Wee retains BV's setup-unbounded attribute length and semi-adaptive LWE security but replaces the non-black-box homomorphic-PRF machinery with a simpler black-box construction; setup still fixes circuit depth.","resultId":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","target":"ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE","type":"CHANGES_MECHANISM"},{"evidenceLocator":"Table 1 and Section 1.1, paragraphs beginning 'FABEO subsumes' and 'Optimal security'","evidenceUrl":"https://eprint.iacr.org/2022/1415.pdf","id":"REL-D578BD6C6E3B2A","note":"FABEO combines ABGW's multi-use and generic-bilinear-group design points with the fast hash-and-randomness-reuse line, then improves ciphertext, key and runtime parameters and proves an optimal O(t^2/p) bound.","resultId":"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE","target":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY","type":"COMBINES"},{"evidenceLocator":"Table 1 and Section 1.1, 'Our Contributions'","evidenceUrl":"https://eprint.iacr.org/2022/1415.pdf","id":"REL-83631FDA1297DB","note":"FABEO retained FAME's arbitrary-attribute, hash-to-G1 and fast-decryption design points, while adding attribute multi-use, smaller objects and optimal multi-challenge generic-group security bounds.","resultId":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","target":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY","type":"COMBINES"},{"evidenceLocator":"Abstract; Section 1.1 and Figure 1, including the KW19 transformation","evidenceUrl":"https://eprint.iacr.org/2023/1947.pdf","id":"REL-E06F1AA53FDB28","note":"Venema-Botros reframes generic CPA-to-CCA conversion through predicate extension, broadens the approach across predicate encryption, and gives a lower-overhead pairing-based extension that yields the most efficient generic CCA conversion reported for CP-ABE.","resultId":"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","target":"ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Abstract and Section 1, prior-work and security-model comparison","evidenceUrl":"https://eprint.iacr.org/2022/1311.pdf","id":"REL-0F92B4E1EC6267","note":"The later DKW work defines and realizes decentralized MA-ABE with adaptive authority corruptions and adaptive user-key queries. Its main realization uses pairings and a random oracle rather than upgrading the earlier DKW LWE construction under unchanged assumptions.","resultId":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","target":"ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION","type":"CHANGES_SECURITY_MODEL"},{"evidenceLocator":"Abstract and Section 1, 'The Multi-Input Setting'","evidenceUrl":"https://eprint.iacr.org/2023/941.pdf","id":"REL-16DA198AD4F089","note":"ARYY extends AYY's two-input NC1 construction to every constant arity and removes the pairing/GGM component by using evasive LWE (and tensor LWE for the P extension), yielding a post-quantum candidate line.","resultId":"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS","target":"ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE","type":"EXTENDS"},{"evidenceLocator":"Section 1.1, 'Registered ABE' and 'Our Results'","evidenceUrl":"https://eprint.iacr.org/2025/044.pdf","id":"REL-0E426A077F721B","note":"CHW carries the registered-ABE trust model to falsifiable succinct-LWE assumptions and bounded-depth circuit policies in the random-oracle model, replacing the original pairing/formula construction line.","resultId":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","target":"ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE","type":"CHANGES_ASSUMPTION"},{"evidenceLocator":"Section 1.1, contributions, especially the pairing-construction paragraph","evidenceUrl":"https://www.cs.utexas.edu/~dwu4/papers/RegisteredMA-ABE.pdf","id":"REL-A559A326B3FD4E","note":"LWW combines HLWW's deterministic transparent registration blueprint with multi-authority ABE; its pairing construction explicitly leverages ideas from both HLWW and Lewko-Waters and supports monotone LSSS policies.","resultId":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","target":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE","type":"COMBINES"},{"evidenceLocator":"Abstract; Section 1.1; Sections 4-5","evidenceUrl":"https://eprint.iacr.org/2024/749.pdf","id":"REL-B537CC7B0C785D","note":"GLWW applies progression-free sets and a partitioning alternative to the original registered-ABE blueprint, reducing the pairing-based CRS from quadratic in users to nearly linear and optionally removing its attribute- universe dependence under the weaker static-security branch.","resultId":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","target":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Abstract and Section 1, comparison with previous pairing-based registered ABE","evidenceUrl":"https://eprint.iacr.org/2026/1062.pdf","id":"REL-5FE23B477E7378","note":"SWW advances the pairing registered-ABE setup line from GLWW's nearly linear CRS to a linear-size CRS for MSP policies. A separate large-index branch supports arbitrary-string identities and stateless key generation; those features are not simultaneous with the adaptive-security branch.","resultId":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","target":"ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"Section 1.1 and Section 1.2, 'The Wee24 KP-ABE and LFE'","evidenceUrl":"https://eprint.iacr.org/2025/509.pdf","id":"REL-55758D9D5A6666","note":"The 2025 construction explicitly starts from Wee24's KP-ABE and succinct vector commitment, recursively compresses the commitment parameters, and reduces the public-key/CRS dependence from O(ell^2) to O(1) up to poly(depth,lambda), while supplying both KP- and CP-ABE.","resultId":"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE","reviewStatus":"primary_source_checked","source":"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE","target":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F08090D9A2CFC8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-001","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D07DF927EB1B0C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-001","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-609A9335BD04E8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-001","target":"ABE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-512C3E4759F494","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-002","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EB83FEFC3EBB85","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-002","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-83BF01A1EC464A","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-003","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6686DF2FF91C8E","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-003","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BAA557FB3DE57C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-004","target":"ABE-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-31F68135946A1B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-004","target":"ABE-OP-007","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B04801F8F7886D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-005","target":"ABE-OP-004","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B47E5BE26D2196","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-006","target":"ABE-OP-004","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-44D4177A51AEE4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-006","target":"ABE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FBC40B2DA53230","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-006","target":"ABE-OP-006","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8C1D1E30D614DB","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-007","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F7D06A2B851E49","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-007","target":"ABE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9992ACCA42B0FF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-007","target":"ABE-OP-008","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3384B328DF44B8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-008","target":"ABE-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-24F4262BCBFF07","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-008","target":"ABE-OP-007","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B3F5B269DAA007","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-009","target":"ABE-OP-008","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-89D83FE1675AA5","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-010","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CFEDF00627D98C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-010","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5FC7DA9DBB116B","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-010","target":"ABE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4C882E00715F56","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-011","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5E1A231DFB25FF","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-012","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EBD810160A32F7","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-012","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0534DFBF45D696","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-012","target":"ABE-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DD5401554792CA","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-012","target":"ABE-OP-007","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2AD766ACB66FC9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-012","target":"ABE-OP-009","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7D57729543B0E9","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-013","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C5520C6034C37D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-013","target":"ABE-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1CD564BA1B47D1","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-013","target":"ABE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D28D616FC1F031","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-013","target":"ABE-OP-009","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-66E58D093C34F4","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-014","target":"ABE-OP-005","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E67804F0858507","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-014","target":"ABE-OP-006","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DF9678E172D3B8","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-015","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B627D0AE0B9B47","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-015","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0DB8D0DBA20D93","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-016","target":"ABE-OP-009","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9BD42A1C745139","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-017","target":"ABE-OP-010","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D95F44451E910C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-018","target":"ABE-OP-009","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-09736F98FAA91F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-018","target":"ABE-OP-011","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-246DC3C125AB55","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-019","target":"ABE-OP-006","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-42B274CF04326D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-020","target":"ABE-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FDEFDA51104960","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-020","target":"ABE-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E036E0D43047ED","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-020","target":"ABE-OP-012","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-692B649F02E7A6","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-ROUTE-021","target":"ABE-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A5E409F4897A2C","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-TRACK-001","target":"ABE-OP-001","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F5E84FCE9D3E2D","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-TRACK-001","target":"ABE-OP-002","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-84F8911672E54F","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-TRACK-002","target":"ABE-OP-004","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DEDBF451C2EAD3","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-TRACK-003","target":"ABE-OP-002","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-73B06D758CE413","note":"","resultId":null,"reviewStatus":"source-declared","source":"ABE-TRACK-003","target":"ABE-OP-008","type":"ADVANCES"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9107A945010072","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"abgw17_cpabe","target":"ABE-PAPER-2017-ABGW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-868A9E5EE2EB34","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"abgw17_cpabe","target":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F7C7E565206B23","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"abgw17_cpabe","target":"fabeo_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3AC6A6CD1E6B53","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"abgw17_kpabe","target":"ABE-PAPER-2017-ABGW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-04F2F52D4BD644","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"abgw17_kpabe","target":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-995222BC295BDA","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"abgw17_kpabe","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FA13DE4B7BD8E9","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"amy19_dfa_cpabe","target":"ABE-PAPER-2019-AMY-DFA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6E59996BFDCEAD","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"amy19_dfa_cpabe","target":"ABE-ASSUMPTION-DLIN","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-52F7E369C0A720","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"amy19_dfa_kpabe","target":"ABE-PAPER-2019-AMY-DFA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1315F3E8C30D2D","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"amy19_dfa_kpabe","target":"ABE-ASSUMPTION-DLIN","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EB17D5EE9DEE9B","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"attrapadung14","target":"ABE-PAPER-2014-ATTRAPADUNG","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2633A9FCAFF5C9","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"attrapadung14","target":"ABE-ASSUMPTION-Q-TYPE-COMPUTATIONAL-PES","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FDAC3F7CBF3519","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"bgg14_kpabe","target":"ABE-PAPER-2014-BGGPS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B4E4F782724E1E","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"bgg14_kpabe","target":"ABE-ASSUMPTION-LEARNING-WITH-ERRORS-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D6634B8790265F","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"bns13_arithmetic_kpabe","target":"ABE-PAPER-2013-BNS-ARITH","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-99E3F000A7946C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"bns13_arithmetic_kpabe","target":"ABE-ASSUMPTION-LEARNING-WITH-ERRORS-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3F7F51F6B1ADE4","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"bsw","target":"ABE-PAPER-2007-BSW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1CD2D7F7FEA430","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"bsw","target":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4A93361467EAA7","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"bsw","target":"fabeo_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-68EFB3B501FB5E","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"bsw","target":"fame_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B0345F1693E1CD","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"bsw","target":"waters11","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C9812D423DA8B8","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"cgkw18","target":"ABE-PAPER-2018-CGKW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-31DE1144C47500","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"cgkw18","target":"ABE-ASSUMPTION-K-LIN-MDDH-K","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-983D679DC60C68","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"cgkw18","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-184A76FBEA1349","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"cgw15_cpabe","target":"ABE-PAPER-2015-CGW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DE6F2B6EF96FE3","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"cgw15_cpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K-ESCALA-ET-AL","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-283FC091B1968C","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"cgw15_kpabe","target":"ABE-PAPER-2015-CGW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-18F562819F1C34","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"cgw15_kpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K-ESCALA-ET-AL","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3B40A070802101","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"cgw15_kpabe","target":"cgkw18","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5E9CE04CE0D45F","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"cgw15_kpabe","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-323AB09E525168","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"fabeo_cpabe","target":"ABE-PAPER-2022-FABEO","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BDBB0E39781359","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"fabeo_cpabe","target":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8654D7456B8DB0","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"fabeo_kpabe","target":"ABE-PAPER-2022-FABEO","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-9D0062AF86CD33","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"fabeo_kpabe","target":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-DA6B409969AD80","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"fame_cpabe","target":"ABE-PAPER-2017-FAME","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-74157479E2875D","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"fame_cpabe","target":"ABE-ASSUMPTION-DECISIONAL-LINEAR-DLIN-TYPE-III","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8F9CCC5492F706","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"fame_cpabe","target":"fabeo_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F0B2DA313565E3","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"fame_kpabe","target":"ABE-PAPER-2017-FAME","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BDC74A707CC0C3","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"fame_kpabe","target":"ABE-ASSUMPTION-DECISIONAL-LINEAR-DLIN-TYPE-III","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5BF002F9ADE883","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"fame_kpabe","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4EF6A6F8BE7538","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"glue22_cpabe","target":"ABE-PAPER-2022-VA-GLUE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B240D4AFE874ED","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"glue22_cpabe","target":"ABE-ASSUMPTION-Q-TYPE-PAIR-ENCODING-INSTANTIATION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B02D4729491A1E","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"gpsw","target":"ABE-PAPER-2006-GPSW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-01A98C48785D9C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"gpsw","target":"ABE-ASSUMPTION-DECISIONAL-BILINEAR-DIFFIE-HELLMAN-DBDH","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7117AD1B91A38C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"gpsw","target":"abgw17_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1AED583B1C1937","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"gpsw","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7B404DE45ED13C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"gpsw","target":"fame_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-06DF4423744641","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"hll24","target":"ABE-PAPER-2024-HLL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B06CD263D4EAAF","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"hll24","target":"ABE-ASSUMPTION-LWE-EVASIVE-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A842463F16BE69","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"hw13_fast_kpabe","target":"ABE-PAPER-2013-HW-FAST","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7946AD897178AC","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"hw13_fast_kpabe","target":"ABE-ASSUMPTION-DECISIONAL-Q-BDHE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F607A8795CE994","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"kw19_cpabe","target":"ABE-PAPER-2019-KW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-BAEDFCD591DEA2","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"kw19_cpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K-1","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7E9EB954B262C0","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"kw19_kpabe","target":"ABE-PAPER-2019-KW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-4305821B792D41","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"kw19_kpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K-1","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-34FBA5EA686268","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"ll20a_kpabe","target":"ABE-PAPER-2020-LL-EUROCRYPT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-3A8F92F8C923F2","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"ll20a_kpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-C2370B66A2FA1A","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"ll20b_cpabe","target":"ABE-PAPER-2020-LL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A55B893AD22B63","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"ll20b_cpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-0E74D091C0FCCD","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"ll20b_kpabe","target":"ABE-PAPER-2020-LL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-27F751F895BED5","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"ll20b_kpabe","target":"ABE-ASSUMPTION-K-LIN-MDDH-K","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-556E499A3119F9","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"lll22_cpabe","target":"ABE-PAPER-2022-LLL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CABA8B0A32E1D2","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lll22_cpabe","target":"ABE-ASSUMPTION-LWE-GENERIC-BILINEAR-GROUP-HYBRID","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-061C2CC13ED699","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"lll22_kpabe","target":"ABE-PAPER-2022-LLL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-28B7A2347B2EBA","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lll22_kpabe","target":"ABE-ASSUMPTION-LWE-GENERIC-BILINEAR-GROUP-HYBRID","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-A796396543D32D","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"lw11_kpabe","target":"ABE-PAPER-2011-LW-UNBOUNDED","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FE2B85B557BB65","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lw11_kpabe","target":"ABE-ASSUMPTION-STATIC-SUBGROUP-DECISION-ASSUMPTIONS-1-4-OF-LW11","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-8DD902DE001790","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lw11_kpabe","target":"cgkw18","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D6FD57E076F09C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lw11_kpabe","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-D1368484402E1C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lw11_kpabe","target":"rw13_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-6CC8981EC77324","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"lzf26_constant_ct_cpabe","target":"ABE-PAPER-2026-LZF-CONSTANT-CT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-86D9775C3B476C","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"lzf26_constant_ct_cpabe","target":"ABE-ASSUMPTION-POLY-LAMBDA-SUCCINCT-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-E8C62C325BC92D","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"rw13_cpabe","target":"ABE-PAPER-2013-RW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B16F5069952BCE","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"rw13_cpabe","target":"ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-1-IN-THE-PAPER","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-EB36F45FEE2937","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"rw13_cpabe","target":"fabeo_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-FCADC3B826833A","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"rw13_cpabe","target":"fame_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-7F4EE73CFAB135","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"rw13_kpabe","target":"ABE-PAPER-2013-RW","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-CAEA3496CBDAE7","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"rw13_kpabe","target":"ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-2-IN-THE-PAPER","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-15CBFA7C9B95D5","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"rw13_kpabe","target":"cgkw18","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-12A9EAD358A495","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"rw13_kpabe","target":"fabeo_kpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-1F9B9D149F5E58","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"sb25_nonlinear_kpabe","target":"ABE-PAPER-2025-SB-LUT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5FE8F49CB434F6","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"sb25_nonlinear_kpabe","target":"ABE-ASSUMPTION-RING-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-2BE662FC90A5A4","note":"","resultId":null,"reviewStatus":"identifier-matched","source":"waters11","target":"ABE-PAPER-2011-WATERS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-5B822F0E713648","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"waters11","target":"ABE-ASSUMPTION-Q-PARALLEL-BDHE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-B6EF899AC99493","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"waters11","target":"fabeo_cpabe","type":"SUPERSEDED_BY"},{"evidenceLocator":"","evidenceUrl":"","id":"REL-F8C5E734C51A6B","note":"","resultId":null,"reviewStatus":"scheme-declared","source":"waters11","target":"fame_cpabe","type":"SUPERSEDED_BY"}],"nodes":[{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-DLIN","keywords":["standard"],"metadata":{"family":"standard","name":"DLIN"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: DLIN.","title":"DLIN","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-DLIN"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-DECISIONAL-BILINEAR-DIFFIE-HELLMAN-DBDH","keywords":["standard"],"metadata":{"family":"standard","name":"Decisional Bilinear Diffie-Hellman (DBDH)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: Decisional Bilinear Diffie-Hellman (DBDH).","title":"Decisional Bilinear Diffie-Hellman (DBDH)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-DECISIONAL-BILINEAR-DIFFIE-HELLMAN-DBDH"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-DECISIONAL-LINEAR-DLIN-TYPE-III","keywords":["standard"],"metadata":{"family":"standard","name":"Decisional Linear (DLIN, Type III)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: Decisional Linear (DLIN, Type III).","title":"Decisional Linear (DLIN, Type III)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-DECISIONAL-LINEAR-DLIN-TYPE-III"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP","keywords":["ggm"],"metadata":{"bound":"O(t^4 / p)","family":"GGM","name":"Generic bilinear group"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"GGM","summary":"Assumption used by one or more ABE construction specifications: Generic bilinear group.","title":"Generic bilinear group","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-GENERIC-BILINEAR-GROUP"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-LWE-GENERIC-BILINEAR-GROUP-HYBRID","keywords":["hybrid"],"metadata":{"family":"hybrid","name":"LWE + Generic bilinear group (hybrid)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"hybrid","summary":"Assumption used by one or more ABE construction specifications: LWE + Generic bilinear group (hybrid).","title":"LWE + Generic bilinear group (hybrid)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-LWE-GENERIC-BILINEAR-GROUP-HYBRID"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-LWE-EVASIVE-LWE","keywords":["hybrid"],"metadata":{"family":"hybrid","name":"LWE + evasive LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"hybrid","summary":"Assumption used by one or more ABE construction specifications: LWE + evasive LWE.","title":"LWE + evasive LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-LWE-EVASIVE-LWE"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-LEARNING-WITH-ERRORS-LWE","keywords":["standard"],"metadata":{"family":"standard","name":"Learning With Errors (LWE)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: Learning With Errors (LWE).","title":"Learning With Errors (LWE)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-LEARNING-WITH-ERRORS-LWE"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-RING-LWE","keywords":["lwe"],"metadata":{"family":"LWE","name":"Ring-LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"LWE","summary":"Assumption used by one or more ABE construction specifications: Ring-LWE.","title":"Ring-LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-RING-LWE"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-STATIC-SUBGROUP-DECISION-ASSUMPTIONS-1-4-OF-LW11","keywords":["standard"],"metadata":{"family":"standard","name":"Static subgroup-decision (Assumptions 1–4 of LW11)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: Static subgroup-decision (Assumptions 1–4 of LW11).","title":"Static subgroup-decision (Assumptions 1–4 of LW11)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-STATIC-SUBGROUP-DECISION-ASSUMPTIONS-1-4-OF-LW11"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-DECISIONAL-Q-BDHE","keywords":["q-type"],"metadata":{"family":"q-type","name":"decisional q-BDHE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"q-type","summary":"Assumption used by one or more ABE construction specifications: decisional q-BDHE.","title":"decisional q-BDHE","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-DECISIONAL-Q-BDHE"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-K-LIN-MDDH-K","keywords":["standard"],"metadata":{"family":"standard","name":"k-Lin (MDDH_k)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: k-Lin (MDDH_k).","title":"k-Lin (MDDH_k)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-K-LIN-MDDH-K"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-K-LIN-MDDH-K-ESCALA-ET-AL","keywords":["standard"],"metadata":{"family":"standard","name":"k-Lin (MDDH_k, Escala et al.)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: k-Lin (MDDH_k, Escala et al.).","title":"k-Lin (MDDH_k, Escala et al.)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-K-LIN-MDDH-K-ESCALA-ET-AL"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-K-LIN-MDDH-K-1","keywords":["standard"],"metadata":{"family":"standard","name":"k-Lin (MDDH_k^1)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"standard","summary":"Assumption used by one or more ABE construction specifications: k-Lin (MDDH_k^1).","title":"k-Lin (MDDH_k^1)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-K-LIN-MDDH-K-1"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-POLY-LAMBDA-SUCCINCT-LWE","keywords":["succinct-lwe"],"metadata":{"family":"succinct-LWE","name":"poly(lambda)-succinct LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"succinct-LWE","summary":"Assumption used by one or more ABE construction specifications: poly(lambda)-succinct LWE.","title":"poly(lambda)-succinct LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-POLY-LAMBDA-SUCCINCT-LWE"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-1-IN-THE-PAPER","keywords":["q-type"],"metadata":{"family":"q-type","name":"q-DPBDHE2 (called q-1 in the paper)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"q-type","summary":"Assumption used by one or more ABE construction specifications: q-DPBDHE2 (called q-1 in the paper).","title":"q-DPBDHE2 (called q-1 in the paper)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-1-IN-THE-PAPER"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-2-IN-THE-PAPER","keywords":["q-type"],"metadata":{"family":"q-type","name":"q-DPBDHE2 (called q-2 in the paper)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"q-type","summary":"Assumption used by one or more ABE construction specifications: q-DPBDHE2 (called q-2 in the paper).","title":"q-DPBDHE2 (called q-2 in the paper)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-Q-DPBDHE2-CALLED-Q-2-IN-THE-PAPER"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-Q-PARALLEL-BDHE","keywords":["q-type"],"metadata":{"family":"q-type","name":"q-parallel BDHE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"q-type","summary":"Assumption used by one or more ABE construction specifications: q-parallel BDHE.","title":"q-parallel BDHE","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-Q-PARALLEL-BDHE"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-Q-TYPE-COMPUTATIONAL-PES","keywords":["q-type"],"metadata":{"family":"q-type","name":"q-type (computational PES)"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"q-type","summary":"Assumption used by one or more ABE construction specifications: q-type (computational PES).","title":"q-type (computational PES)","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-Q-TYPE-COMPUTATIONAL-PES"},{"evidence":"scheme-declared","id":"ABE-ASSUMPTION-Q-TYPE-PAIR-ENCODING-INSTANTIATION","keywords":["q-type"],"metadata":{"family":"q-type","name":"q-type pair-encoding instantiation"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"q-type","summary":"Assumption used by one or more ABE construction specifications: q-type pair-encoding instantiation.","title":"q-type pair-encoding instantiation","type":"assumption","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ASSUMPTION-Q-TYPE-PAIR-ENCODING-INSTANTIATION"},{"evidence":"published","id":"ABE-BARRIER-004","keywords":["assumption-break","evasive-lwe","circular-lwe","unbounded-depth"],"metadata":{"does_not_exclude":["conditional-correctness-of-the-reduction","circular-lwe-alone","new-modular-or-doubly-circular-assumptions"],"dossier_type":"barrier","evidence":"published","excludes":["security-instantiations-relying-on-the-broken-evasive-circular-assumption"],"id":"ABE-BARRIER-004","keywords":["assumption-break","evasive-lwe","circular-lwe","unbounded-depth"],"status":"published","targets":["ABE-OP-003","ABE-OP-007"],"title":"Attack record for the evasive-circular unbounded-depth route"},"primaryUrl":null,"sections":[{"content":"Attack record for the evasive-circular unbounded-depth route","heading":"Overview"},{"content":"The 2026 doubly-circular ABE paper reports that the evasive-circular LWE assumption underlying the earlier full unbounded-depth ABE was broken by subsequent work. This card records the downstream consequence; a complete attack transcript and exact affected version still require a dedicated paper card for the attacking work.","heading":"Statement and scope"},{"content":"Treating the affected assumption as an intact foundation for a current unbounded-depth ABE security claim.","heading":"What it excludes"},{"content":"The correctness of the construction, the conditional reduction as a logical statement, one-key circular-LWE results, or new assumptions whose extra structure blocks the attack.","heading":"What it does not exclude"},{"content":"Agrawal–Modi–Yadav–Yamada, ePrint 2026/1439, abstract and full-version attack discussion.","heading":"Source"}],"status":"published","subtitle":"","summary":"The 2026 doubly-circular ABE paper reports that the evasive-circular LWE assumption underlying the earlier full unbounded-depth ABE was broken by subsequent work. This card records the downstream consequence; a complete attack transcript and exact affected version still require a dedicated paper card for the attacking work.","title":"Attack record for the evasive-circular unbounded-depth route","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-004"},{"evidence":"manual-proof-complete","id":"ABE-BARRIER-001","keywords":["threshold","lsss","lower-bound","reconstruction-height"],"metadata":{"does_not_exclude":["multi-row-lsss","wraparound-constructions-outside-the-bound","non-lsss-threshold-dmpe"],"dossier_type":"barrier","evidence":"manual-proof-complete","excludes":["bounded-height-injective-one-row-exact-threshold-lsss-in-the-stated-no-wrap-regime"],"id":"ABE-BARRIER-001","keywords":["threshold","lsss","lower-bound","reconstruction-height"],"status":"proved-on-paper","targets":["ABE-OP-004"],"title":"Exponential reconstruction height for injective one-row exact thresholds"},"primaryUrl":null,"sections":[{"content":"Exponential reconstruction height for injective one-row exact thresholds","heading":"Overview"},{"content":"For the Champion–Wu-style injective, one-row-per-party exact threshold LSSS, the repository proves a prime-power collision tradeoff. In the no-wrap regime it implies reconstruction height exponential in n-t; rank two has a matching exponential upper bound up to constants in the exponent.","heading":"Statement and scope"},{"content":"Manual theorem and finite regression artifacts: experiments/exact_threshold_lsss/README.md and RESEARCH_NOTE.md.","heading":"Evidence"},{"content":"Using a polynomial-height injective one-row exact-threshold LSSS as a black-box path to succinct lattice threshold DMPE in the stated parameter regime.","heading":"What it excludes"},{"content":"Multi-row sharing, user-level hint compression, wraparound techniques not covered by the theorem, approximate/noisy reconstruction with a different security proof, or non-LSSS threshold mechanisms.","heading":"What it does not exclude"}],"status":"proved-on-paper","subtitle":"","summary":"For the Champion–Wu-style injective, one-row-per-party exact threshold LSSS, the repository proves a prime-power collision tradeoff. In the no-wrap regime it implies reconstruction height exponential in n-t; rank two has a matching exponential upper bound up to constants in the exponent.","title":"Exponential reconstruction height for injective one-row exact thresholds","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-001"},{"evidence":"manual-proof-complete","id":"ABE-BARRIER-003","keywords":["lwe","correctness","polynomial-ratio","noise"],"metadata":{"does_not_exclude":["correlated-samplers","exact-policy-gated-release","bounded-norm-recoding"],"dossier_type":"barrier","evidence":"manual-proof-complete","excludes":["polynomial-ratio-upgrade-by-independent-stationary-row-noise"],"id":"ABE-BARRIER-003","keywords":["lwe","correctness","polynomial-ratio","noise"],"status":"proved-on-paper","targets":["ABE-OP-001","ABE-OP-002"],"title":"Modular mixing of independent stationary row noise"},"primaryUrl":null,"sections":[{"content":"Modular mixing of independent stationary row noise","heading":"Overview"},{"content":"In the current formula architecture, accumulating independent stationary row-error contributions over polynomially many rows causes modular mixing when q/chi is polynomial, yielding correctness failure rather than merely a loose proof bound.","heading":"Statement and scope"},{"content":"The scoped theorem and restart conditions are recorded in AL_POLYNOMIAL_RATIO_BREAKTHROUGH_AUDIT.md.","heading":"Evidence"},{"content":"Retuning parameters while retaining independent additive stationary noise per row as the accepting decryption channel.","heading":"What it excludes"},{"content":"Correlated full samplers, exact policy-gated partial decryption, error cancellation, or future-opening recoders with fixed output norm.","heading":"What it does not exclude"}],"status":"proved-on-paper","subtitle":"","summary":"In the current formula architecture, accumulating independent stationary row-error contributions over polynomially many rows causes modular mixing when q/chi is polynomial, yielding correctness failure rather than merely a loose proof bound.","title":"Modular mixing of independent stationary row noise","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-003"},{"evidence":"published","id":"ABE-BARRIER-007","keywords":["function-hiding","policy-hiding","indistinguishability-obfuscation","definition-barrier"],"metadata":{"does_not_exclude":["attribute-hiding-pe","weakened-function-hiding","structured-policy-privacy","leakage-profile-policy-hiding"],"dossier_type":"barrier","evidence":"published","excludes":["plain-lwe-natural-full-function-hiding-circuit-abe-without-io-level-breakthrough"],"id":"ABE-BARRIER-007","keywords":["function-hiding","policy-hiding","indistinguishability-obfuscation","definition-barrier"],"status":"published","targets":["ABE-OP-010"],"title":"Natural full function-hiding circuit ABE implies indistinguishability obfuscation"},"primaryUrl":null,"sections":[{"content":"Natural full function-hiding circuit ABE implies iO","heading":"Overview"},{"content":"Agrawal--Yamada show that the natural full function-hiding definition for circuit ABE implies indistinguishability obfuscation, even when encryption is symmetric-key. Therefore treating full policy privacy for arbitrary circuits as a routine compiler target silently asks for an iO-level breakthrough.","heading":"Statement and scope"},{"content":"Published in TCC 2020; see ABE-PAPER-2020-AY-FH and Section 5.3 of ePrint 2020/1432.","heading":"Evidence"},{"content":"It excludes positioning the natural full function-hiding circuit-ABE notion as an ordinary consequence of plain LWE unless the work also resolves the corresponding iO assumption gap.","heading":"What it excludes"},{"content":"It does not exclude attribute hiding, IPE, weakened function hiding, single-key/bounded-collusion notions, restricted function classes, or explicit leakage profiles that hide labels/polarities but reveal topology or size.","heading":"What it does not exclude"}],"status":"published","subtitle":"","summary":"Agrawal--Yamada show that the natural full function-hiding definition for circuit ABE implies indistinguishability obfuscation, even when encryption is symmetric-key. Therefore treating full policy privacy for arbitrary circuits as a routine compiler target silently asks for an iO-level breakthrough.","title":"Natural full function-hiding circuit ABE implies indistinguishability obfuscation","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-007"},{"evidence":"published","id":"ABE-BARRIER-006","keywords":["lower-bound","phfe","ram","decryption-time"],"metadata":{"does_not_exclude":["optimal-tradeoff-constructions","direct-lwe-constructions","restricted-function-classes-outside-the-lower-bound"],"dossier_type":"barrier","evidence":"published","excludes":["simultaneously-sublinear-key-and-decryption-in-the-stated-function-dimension","simultaneously-sublinear-ciphertext-and-decryption-in-the-stated-public-input-dimension"],"id":"ABE-BARRIER-006","keywords":["lower-bound","phfe","ram","decryption-time"],"status":"published","targets":["ABE-OP-007"],"title":"PHFE and ABE space-time tradeoffs"},"primaryUrl":null,"sections":[{"content":"PHFE and ABE space-time tradeoffs","heading":"Overview"},{"content":"Jain–Lin–Luo prove unconditional tradeoffs showing, in their PHFE model, that secret-key size and decryption time cannot both be sublinear in function size, and ciphertext size and decryption time cannot both be sublinear in public input size. The bounds apply even to weak one-key/one-ciphertext selective settings.","heading":"Statement and scope"},{"content":"Claims that make both representation and the corresponding computation cost sublinear in the same hidden dimension under the theorem's model.","heading":"What it excludes"},{"content":"Matching the optimal tradeoff, direct constructions from plain assumptions, or policy/function classes outside the theorem's reduction.","heading":"What it does not exclude"},{"content":"ABE-PAPER-2023-JLL, ePrint 2022/1317.","heading":"Source"}],"status":"published","subtitle":"","summary":"Jain–Lin–Luo prove unconditional tradeoffs showing, in their PHFE model, that secret-key size and decryption time cannot both be sublinear in function size, and ciphertext size and decryption time cannot both be sublinear in public input size. The bounds apply even to weak one-key/one-ciphertext selective settings.","title":"PHFE and ABE space-time tradeoffs","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-006"},{"evidence":"locally-checked","id":"ABE-BARRIER-005","keywords":["pairings","projectability","compiler","interface-barrier"],"metadata":{"does_not_exclude":["new-projectable-ipfe","non-black-box-composition","alternative-semi-functional-compilers"],"dossier_type":"barrier","evidence":"locally-checked","excludes":["the-audited-ll20b-plus-current-unbounded-ipfe-black-box-composition"],"id":"ABE-BARRIER-005","keywords":["pairings","projectability","compiler","interface-barrier"],"status":"candidate","targets":["ABE-OP-002","ABE-OP-008"],"title":"Source-group projectability mismatch in unbounded pairing compilers"},"primaryUrl":null,"sections":[{"content":"Source-group projectability mismatch in unbounded pairing compilers","heading":"Overview"},{"content":"The audited LL20b-style outer compiler needs a publicly projectable linear source-group image from the inner unbounded functional primitive. Known unbounded IPFE candidates expose the relevant value only after a target-group or nonlinear operation, so the simulator cannot form the required source-group component.","heading":"Statement and scope"},{"content":"Projectability and target-group-lift experiments are indexed from experiments/abe_unbounded_succinct/README.md.","heading":"Evidence"},{"content":"The exact audited black-box composition.","heading":"What it excludes"},{"content":"A new projectable inner primitive, a non-black-box compiler, or a different pairing proof architecture.","heading":"What it does not exclude"}],"status":"candidate","subtitle":"","summary":"The audited LL20b-style outer compiler needs a publicly projectable linear source-group image from the inner unbounded functional primitive. Known unbounded IPFE candidates expose the relevant value only after a target-group or nonlinear operation, so the simulator cannot form the required source-group component.","title":"Source-group projectability mismatch in unbounded pairing compilers","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-005"},{"evidence":"locally-checked","id":"ABE-BARRIER-002","keywords":["adaptive-security","preimages","collusion","attack"],"metadata":{"does_not_exclude":["policy-separating-endpoint-cancellation","semi-adaptive-security","fundamentally-noncanonical-states"],"dossier_type":"barrier","evidence":"locally-checked","excludes":["direct-canonical-preimage-personalization","all-row-shared-preimage-transposition"],"id":"ABE-BARRIER-002","keywords":["adaptive-security","preimages","collusion","attack"],"status":"candidate","targets":["ABE-OP-001","ABE-OP-002","ABE-OP-006"],"title":"Two-key attacks on canonical/shared adaptive preimage states"},"primaryUrl":null,"sections":[{"content":"Two-key attacks on canonical/shared adaptive preimage states","heading":"Overview"},{"content":"For challenge {a}, the legal rejecting keys for b and a AND b expose a short representative of a master-preimage difference in the direct canonical state proposal. A separate all-row shared-preimage transposition produces a joint distribution distinguishable from honest spherical preimages.","heading":"Statement and scope"},{"content":"Exact algebraic attacks and finite tests are recorded in AJ_ADAPTIVE_EQMCOM_ROW_TRANSPOSITION.md and AN_EQBE_LSSS_CANONICAL_STATE_AUDIT.md.","heading":"Evidence"},{"content":"Adaptive upgrades that assign independent canonical explanations to labels or only add correctness-small kernel rerandomization while retaining the same decryption-equivalence class.","heading":"What it excludes"},{"content":"A large policy-local pad with accepting-only endpoint cancellation, noncommitting states outside the attacked linear form, or weaker semi-adaptive games.","heading":"What it does not exclude"}],"status":"candidate","subtitle":"","summary":"For challenge {a}, the legal rejecting keys for b and a AND b expose a short representative of a master-preimage difference in the direct canonical state proposal. A separate all-row shared-preimage transposition produces a joint distribution distinguishable from honest spherical preimages.","title":"Two-key attacks on canonical/shared adaptive preimage states","type":"barrier","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-BARRIER-002"},{"evidence":"deferred_scalar_pes","id":"gpsw","keywords":["kp-abe","pairing","tree","standard"],"metadata":{"assumption":{"family":"standard","name":"Decisional Bilinear Diffie-Hellman (DBDH)"},"authors":["Vipul Goyal","Omkant Pandey","Amit Sahai","Brent Waters"],"construction_one_liner":"The first KP-ABE. Shamir-style polynomial secret sharing over a monotone access tree; ciphertext carries per-attribute exponentiations. Selective security under the standard DBDH assumption.\n","decrypt_pairings":"I","id":"gpsw","implementations":["OpenABE","Charm","RELIC"],"name":"Goyal–Pandey–Sahai–Waters KP-ABE","pairing":{"original_type":"I","type_III_port":["FAME","FABEO"]},"paper":{"eprint":"2006/309","sections_cited":["§4.2 construction","§4.3 efficiency","§4.4 Theorem 1 security"],"url":"https://eprint.iacr.org/2006/309","venue":"CCS 2006","year":2006},"pareto_notes":"Foundational. Superseded on expressiveness and security mode by every later KP-ABE, but remains the textbook baseline. Small-universe; large- universe variant via ROM is a separate §5 construction.\n","policy":{"ROM_required":false,"class":"tree","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"m","GT":"1","note":"One element E_i = g_1^{t_i s} per ciphertext attribute, plus E' = M * Y^s in G_T."},"MPK":{"G1":"U+1","GT":"1","note":"T_1=g^{t_1}, ..., T_U=g^{t_U} plus e(g,g)^y. U = attribute universe size. Generators not counted."},"MSK":{"Zp":"U+1","note":"t_1, ..., t_U, y"},"SK":{"G2":"n1","note":"One element D_x = g_2^{q_x(0)/t_{att(x)}} per tree leaf. No G_1 pieces."},"note_on_port":"GPSW'06 is originally in symmetric pairings; the standard Type III port places the key in G_2 and CT in G_1 (per FABEO Table 5).","sources":["GPSW §4.2 construction (natural Type III port)","FABEO Table 5 (Riepel–Wee CCS 2022) row for GPSW"]},"superseded_by":["fame_kpabe","abgw17_kpabe","fabeo_kpabe"],"variables":{"I":"number of leaves used at decryption","U":"attribute universe size (bounded at setup)","m":"|S|, attribute set size in the ciphertext (KP-ABE: attributes on CT)","n1":"number of access-tree leaves"},"verification":{"blocker":"inverse_exponents","ggm_file":null,"status":"deferred_scalar_pes"}},"primaryUrl":"https://eprint.iacr.org/2006/309","sections":[{"content":"GPSW introduces the pair encryption primitive: the ciphertext binds a message under $e(g_1,g_2)^{ys}$ and tags each attribute $i$ with a \"slot\" $T_i^s$; the key assigns to each leaf of a monotone access tree a group element that recovers the share $q_x(0)$ of the master secret $y$ via a pairing against the matching slot. When a satisfying subset of attributes is present, Lagrange interpolation up the tree reconstructs $e(g_1,g_2)^{ys}$ and unmasks the message. Selective security reduces to DBDH.","heading":"Intuition"},{"content":"Sample $t_1, \\ldots, t_U \\leftarrow_R \\mathbb{Z}_p$ (one per universe attribute) and $y \\leftarrow_R \\mathbb{Z}_p$. $$\\mathrm{MPK} = \\big(g_1,\\ g_2,\\ T_1 = g_1^{t_1},\\ \\ldots,\\ T_U = g_1^{t_U},\\ Y_y = e(g_1,g_2)^y\\big),\\quad \\mathrm{MSK} = (t_1, \\ldots, t_U,\\ y)$$","heading":"Setup"},{"content":"Input: monotone access tree $\\mathcal{T}$ with leaves $\\mathcal{Y}$. For each node $x$ with threshold $k_x$ and children count, pick a polynomial $q_x$ of degree $k_x-1$ with $q_{\\text{root}}(0) = y$ and $q_x(0) = q_{\\mathrm{parent}(x)}(\\mathrm{index}(x))$ for inner nodes. For each leaf $x$ with attribute label $\\mathrm{att}(x) = i$: $$D_x = g_2^{q_x(0)/t_i}\\in\\mathbb{G}_2$$ $$\\mathrm{SK} = \\{D_x\\}_{x\\in\\mathcal{Y}}$$","heading":"KeyGen"},{"content":"Input: attribute set $\\gamma\\subseteq\\mathcal{U}$, message $M\\in\\mathbb{G}_T$. Sample $s\\leftarrow_R\\mathbb{Z}_p$. $$E' = M\\cdot Y_y^s,\\quad \\text{for each } i\\in\\gamma:\\ E_i = T_i^{s} = g_1^{t_i s}$$ $$\\mathrm{CT} = (\\gamma,\\ E',\\ \\{E_i\\}_{i\\in\\gamma})$$","heading":"Encrypt"},{"content":"Find a minimal satisfying leaf subset $L$ and Lagrange coefficients $\\{f_x\\}_{x\\in L}$ with $\\sum f_x\\cdot q_x(0) = y$. Compute $$F = \\prod_{x\\in L} e(E_{\\mathrm{att}(x)},\\ D_x)^{f_x} = e(g_1,g_2)^{ys}.$$ Return $M = E'/F$. Pairings: $I = |L|$.","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"KP-ABE · 2006","summary":"The first KP-ABE. Shamir-style polynomial secret sharing over a monotone access tree; ciphertext carries per-attribute exponentiations. Selective security under the standard DBDH assumption.","title":"Goyal–Pandey–Sahai–Waters KP-ABE","type":"construction","venue":"CCS 2006","year":2006,"sourcePath":"data/abe-catalog.json#gpsw"},{"evidence":"deferred_scalar_pes","id":"bsw","keywords":["cp-abe","pairing","tree","GGM+ROM"],"metadata":{"assumption":{"family":"GGM+ROM","name":"Generic bilinear group"},"authors":["John Bethencourt","Amit Sahai","Brent Waters"],"construction_one_liner":"First CP-ABE. Monotone access tree with threshold gates; large universe via ROM hash. Per-attribute fresh randomness r_tau doubles SK vs. Waters11. Proven only in GGM + ROM.\n","decrypt_pairings":"2*I+1","id":"bsw","implementations":["OpenABE","Charm","cpabe-toolkit"],"name":"Bethencourt–Sahai–Waters CP-ABE","pairing":{"original_type":"I","type_III_port":["FAME","FABEO"]},"paper":{"eprint":null,"sections_cited":["§4.2 construction","§4.3 sizes","Appendix A Theorem 1"],"url":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","venue":"IEEE S&P 2007","year":2007},"pareto_notes":"Dominated by Waters11 on SK size (factor 2 in G2) and by FABEO on everything at comparable security. Historically the first CP-ABE and the GGM-proof baseline.\n","policy":{"ROM_required":true,"class":"tree","large_universe":true,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"bound":"O(q^2/p)","mode":"adaptive","model":"GGM+ROM","notion":"CPA"},"sizes":{"CT":{"G1":"n1","G2":"n1+1","GT":"1","note":"n1 C_y in G1 (H(rho(y))^{q_y(0)}), n1 C'_y in G2 plus C in G2, Ctilde in GT"},"MPK":{"G2":"2","GT":"1","note":"A = g_2^beta, B = g_1^{1/beta} (placed per FAME port); Y_alpha in GT. Generators not counted. H in ROM."},"MSK":{"G1":"1","Zp":"1","note":"(beta, g_1^alpha)"},"SK":{"G1":"m+1","G2":"m","note":"D in G1, m D_tau in G1 (contain H(tau)), m D'_tau in G2"},"note_on_port":"BSW'07 is originally in symmetric pairings; the numbers above are the standard Type III port quoted by FAME and re-used by FABEO for comparison.","sources":["FAME (Agrawal–Chase CCS 2017) §5, Fig 5.5","FABEO (Riepel–Wee CCS 2022) Table 5 (asymmetric port)"]},"superseded_by":["waters11","fame_cpabe","fabeo_cpabe"],"variables":{"I":"number of leaves in satisfying subtree used at decryption","m":"|S|, attribute set size in SK","n1":"number of leaves of the access tree"},"verification":{"blocker":"access_tree_conversion","ggm_file":null,"status":"deferred_scalar_pes"}},"primaryUrl":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","sections":[{"content":"Each secret key binds an attribute set $S$ via a master-key-bound head plus per-attribute limbs. The head encodes $(\\alpha + r)$ divided by a blinding scalar $\\beta$. Each limb carries the shared $r$ multiplied by $H(\\tau)^{r_\\tau}$ with fresh per-attribute randomness $r_\\tau$. A ciphertext distributes $s$ along the leaves of an access tree by polynomial secret sharing (Shamir). Decryption walks up the tree pairing matched CT/SK limbs, Lagrange-reconstructs $e(g_1,g_2)^{rs}$, then uses one top-level pairing to strip $\\alpha$. Security holds against adaptive adversaries in the generic group model with a random-oracle hash.","heading":"Intuition"},{"content":"Sample $\\alpha,\\beta \\in \\mathbb{Z}_p$. $$\\mathrm{MPK} = \\big(g_1,\\ g_2,\\ A = g_2^{\\beta},\\ Y_\\alpha = e(g_1,g_2)^\\alpha\\big),\\qquad H:\\{0,1\\}^*\\to\\mathbb{G}_1\\ (\\text{ROM})$$ $$\\mathrm{MSK} = (\\beta,\\ g_1^\\alpha)$$","heading":"Setup"},{"content":"Input: attribute set $S$. Sample $r\\in\\mathbb{Z}_p$ and $r_\\tau\\in\\mathbb{Z}_p$ for each $\\tau\\in S$. $$D = g_1^{(\\alpha + r)/\\beta}\\in\\mathbb{G}_1$$ $$\\text{for each } \\tau\\in S:\\quad D_\\tau = g_1^{r}\\cdot H(\\tau)^{r_\\tau}\\in\\mathbb{G}_1,\\quad D'_\\tau = g_2^{r_\\tau}\\in\\mathbb{G}_2$$ $$\\mathrm{SK} = \\big(D,\\ \\{D_\\tau, D'_\\tau\\}_{\\tau\\in S}\\big)$$","heading":"KeyGen"},{"content":"Input: access tree $\\mathcal{T}$ with leaves $\\mathcal{Y}$, message $M\\in\\mathbb{G}_T$. Sample $s\\in\\mathbb{Z}_p$ and distribute $s$ to leaves via Shamir sharing on $\\mathcal{T}$ to obtain a share $q_y(0)$ at each leaf $y$. $$\\widetilde C = M\\cdot Y_\\alpha^{s}\\in\\mathbb{G}_T,\\quad C = g_2^{\\beta s}\\in\\mathbb{G}_2$$ $$\\text{for each } y\\in\\mathcal{Y}:\\quad C_y = H(\\rho(y))^{q_y(0)}\\in\\mathbb{G}_1,\\quad C'_y = g_2^{q_y(0)}\\in\\mathbb{G}_2$$ $$\\mathrm{CT} = \\big(\\mathcal{T},\\ \\widetilde C,\\ C,\\ \\{C_y, C'_y\\}_{y\\in\\mathcal{Y}}\\big)$$","heading":"Encrypt"},{"content":"Let $L\\subseteq\\mathcal{Y}$ be a satisfying leaf subset, $|L|=I$. For each $y\\in L$ with attribute $\\rho(y)\\in S$, compute $$F_y = \\frac{e(D_{\\rho(y)},\\ C'_y)}{e(C_y,\\ D'_{\\rho(y)})} = e(g_1,g_2)^{r\\cdot q_y(0)}$$ (2 pairings per leaf). Lagrange-interpolate up $\\mathcal{T}$ to obtain $e(g_1,g_2)^{rs}$. One more pairing: $$e(D,\\ C) = e(g_1,g_2)^{(\\alpha+r)s} = Y_\\alpha^{s}\\cdot e(g_1,g_2)^{rs}.$$ Divide by the interpolated $e(g_1,g_2)^{rs}$ to recover $Y_\\alpha^s$; return $M = \\widetilde C / Y_\\alpha^s$. Pairings total: $2I+1$.","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"CP-ABE · 2007","summary":"First CP-ABE. Monotone access tree with threshold gates; large universe via ROM hash. Per-attribute fresh randomness r_tau doubles SK vs. Waters11. Proven only in GGM + ROM.","title":"Bethencourt–Sahai–Waters CP-ABE","type":"construction","venue":"IEEE S&P 2007","year":2007,"sourcePath":"data/abe-catalog.json#bsw"},{"evidence":"blocked_composite_order","id":"lw11_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","standard"],"metadata":{"assumption":{"family":"standard","name":"Static subgroup-decision (Assumptions 1–4 of LW11)"},"authors":["Allison Lewko","Brent Waters"],"construction_one_liner":"First unbounded KP-ABE: O(1) MPK, no a-priori attribute universe. Uses composite-order groups (N = p_1 p_2 p_3) and nested dual-system encryption to hide ephemeral semi-functionality across key queries.\n","decrypt_pairings":"4*I","id":"lw11_kpabe","name":"Lewko–Waters Unbounded KP-ABE","pairing":{"original_type":"composite","type_III_port":[]},"paper":{"eprint":"2011/049","sections_cited":["§5.1 KP-ABE construction","§5.3 Theorem 27 selective security","§2.6 Assumptions 1–4"],"url":"https://eprint.iacr.org/2011/049","venue":"Eurocrypt 2011","year":2011},"pareto_notes":"Historically the first unbounded ABE. Slower than prime-order alternatives in practice. Superseded by RW13 (prime-order q-type), CGKW18 (prime-order k-Lin, adaptive), and FABEO (prime-order GGM, optimal).\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"3*m+1","GT":"1","note":"3 elements per CT attribute (C_{s_i,1}, C_{s_i,2}, C_{s_i,3}) plus C_0 = g^s. Plus C = M * e(g,g)^{alpha*s} in GT."},"MPK":{"G1":"7","GT":"1","note":"g, u, h, v, w in G_{p_1} plus e(g,g)^alpha. All in the composite-order group; the G_1 tag here labels the one source group used."},"MSK":{"Zp":"1","note":"alpha"},"SK":{"G2":"4*n1","note":"4 elements per LSSS row: K_{x,0}, K_{x,1}, K_{x,2}, K_{x,3}. Placed here under G_2 for the Type III analogue; in the paper all in one composite-order group."},"note_on_port":"Composite-order N = p_1 p_2 p_3 groups in the original paper. Size row below is in the single composite-order group G; no prime-order port is given in this paper (later work by Okamoto–Takashima, CGKW18 provide prime-order unbounded ABE).","sources":["LW11 §5.1 KP-ABE construction"]},"superseded_by":["rw13_kpabe","cgkw18","fabeo_kpabe"],"variables":{"I":"rows used at decryption","m":"|S|, attribute set size in CT (KP-ABE: attrs on CT)","n1":"LSSS matrix rows"},"verification":{"blocker":"composite_order","ggm_file":null,"status":"blocked_composite_order"}},"primaryUrl":"https://eprint.iacr.org/2011/049","sections":[{"content":"Prior ABE schemes fixed the attribute universe size at setup; MPK grew with it. LW11 breaks this with a universe encoder $(u,h)$ (predating RW13's similar move) that maps any $s_i\\in\\mathbb{Z}_N$ to $u^{s_i}h$. The construction sits in composite-order bilinear groups of order $N = p_1 p_2 p_3$ with three subgroups (normal, semi-functional, blinding), and the security proof uses nested dual-system encryption — an intermediate \"ephemeral semi-functional\" key state that allows the hybrid argument to go through even when MPK entropy is too low to hide all nominality in one step.","heading":"Intuition"},{"content":"Composite bilinear group $G$ of order $N = p_1 p_2 p_3$; all scheme elements live in the $G_{p_1}$ subgroup. Sample $\\alpha \\leftarrow_R \\mathbb{Z}_N$, $g, u, h, v, w\\leftarrow_R G_{p_1}$. $$\\mathrm{MPK} = (N,\\ g,\\ u,\\ h,\\ v,\\ w,\\ e(g,g)^\\alpha),\\quad \\mathrm{MSK} = \\alpha$$","heading":"Setup"},{"content":"Input: LSSS $(A,\\rho)$ with $A\\in\\mathbb{Z}_N^{n_1\\times n_2}$. Pick sharing vector $\\vec\\alpha\\in\\mathbb{Z}_N^{n_2}$ with first coord $\\alpha$; per-row $r_x, y_x\\leftarrow_R\\mathbb{Z}_N$. For each row $x\\in[n_1]$ let $\\lambda_x = A_x\\cdot\\vec\\alpha$: $$K_{x,0} = g^{\\lambda_x}w^{y_x},\\quad K_{x,1} = g^{y_x},\\quad K_{x,2} = v^{y_x}(u^{\\rho(x)}h)^{r_x},\\quad K_{x,3} = g^{r_x}$$ SK: $4n_1$ group elements.","heading":"KeyGen"},{"content":"Input: attribute set $S = \\{s_1,\\ldots,s_\\ell\\}$, message $M$. Sample $s, t_1, \\ldots, t_\\ell\\leftarrow_R\\mathbb{Z}_N$: $$C = M\\cdot e(g,g)^{\\alpha s},\\quad C_0 = g^s,\\quad \\text{for each } i:\\ C_{s_i,1} = w^s v^{t_i},\\ C_{s_i,2} = g^{t_i},\\ C_{s_i,3} = (u^{s_i}h)^{t_i}$$","heading":"Encrypt"},{"content":"Find reconstruction coefficients $\\omega_x$ with $\\sum_{\\rho(x)\\in S}\\omega_x A_x = (1, 0, \\ldots, 0)$. Compute $$B = \\prod_{\\rho(x)\\in S}\\left(\\frac{e(C_0, K_{x,0})\\cdot e(C_{\\rho(x),2}, K_{x,2})}{e(C_{\\rho(x),1}, K_{x,1})\\cdot e(C_{\\rho(x),3}, K_{x,3})}\\right)^{\\omega_x}$$ Return $M = C/B$. Pairings: $4I$ where $I = |\\{x : \\rho(x)\\in S\\}|$.","heading":"Decrypt"}],"status":"blocked_composite_order","subtitle":"KP-ABE · 2011","summary":"First unbounded KP-ABE: O(1) MPK, no a-priori attribute universe. Uses composite-order groups (N = p_1 p_2 p_3) and nested dual-system encryption to hide ephemeral semi-functionality across key queries.","title":"Lewko–Waters Unbounded KP-ABE","type":"construction","venue":"Eurocrypt 2011","year":2011,"sourcePath":"data/abe-catalog.json#lw11_kpabe"},{"evidence":"deferred_scalar_pes","id":"waters11","keywords":["cp-abe","pairing","monotone_LSSS","q-type"],"metadata":{"assumption":{"family":"q-type","name":"q-parallel BDHE"},"authors":["Brent Waters"],"construction_one_liner":"First CP-ABE for LSSS policies with polynomial-loss selective security under a q-type assumption. Reuses a single SK randomness t across all attributes, giving SK = (m+1) G1 + 1 G2 at the cost of a one-use restriction.\n","decrypt_pairings":"2*I+1","id":"waters11","implementations":["OpenABE","Charm","RELIC"],"name":"Waters CP-ABE (PKC 2011)","pairing":{"original_type":"I","type_III_port":["FAME","FABEO"]},"paper":{"eprint":"2008/290","sections_cited":["§3 construction","§4 selective security proof"],"url":"https://eprint.iacr.org/2008/290","venue":"PKC 2011","year":2011},"pareto_notes":"Smaller SK than BSW (1 G2 instead of m G2) but loses adaptive security and forbids attribute reuse. Small-universe; large-universe variant uses ROM.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":false,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"n1","G2":"n1+1","GT":"1","note":"n1 C_i in G1, n1 D_i in G2 plus C' = g_2^s in G2, Ctilde in GT"},"MPK":{"G1":"U+1","G2":"1","GT":"1","note":"g_1^a and {h_x}_{x in U} in G1; g_2 in G2; Y_alpha in GT. Generators not counted. U = |U| = universe size."},"MSK":{"G1":"1","note":"g_1^alpha"},"SK":{"G1":"m+1","G2":"1","note":"K = g_1^alpha * g_1^{at}, m K_x = h_x^t in G1, L = g_2^t in G2"},"note_on_port":"Waters11 is originally in symmetric pairings; the numbers above are the standard Type III port quoted by FAME and re-used by FABEO for comparison.","sources":["FAME (Agrawal–Chase CCS 2017) §5, Fig 5.5","FABEO (Riepel–Wee CCS 2022) Table 5 (asymmetric port)"]},"superseded_by":["fame_cpabe","fabeo_cpabe"],"variables":{"I":"rows used in reconstruction","U":"|U|, attribute universe size (bounded at setup)","m":"|S|, attribute set size in SK","n1":"LSSS matrix rows","n2":"LSSS matrix columns"},"verification":{"blocker":"solver_tactics","ggm_file":null,"status":"deferred_scalar_pes"}},"primaryUrl":"https://eprint.iacr.org/2008/290","sections":[{"content":"Waters replaces BSW's access tree with a Linear Secret Sharing Scheme $(\\mathbf{M}, \\rho)$: the secret $s$ is shared linearly as $\\lambda_i = \\mathbf{M}_i\\cdot\\mathbf{v}$ where $\\mathbf{v}=(s,v_2,\\ldots,v_{n_2})$. A single SK randomness $t$ is reused across all attributes (unlike BSW's per-attribute $r_\\tau$), cutting SK in $\\mathbb{G}_2$ from $m$ to $1$. The price is a one-use restriction: each attribute must appear at most once in $\\rho$, otherwise ratios of the $K_x$ elements leak $t$. Security is proved selectively under a parametrized $q$-parallel BDHE assumption, closing the gap from BSW's generic-group-model proof.","heading":"Intuition"},{"content":"Sample $\\alpha, a \\in \\mathbb{Z}_p$ and, for each attribute $x\\in\\mathcal{U}$, a group element $h_x\\in\\mathbb{G}_1$. $$\\mathrm{MPK} = \\big(g_1,\\ g_2,\\ g_1^{a},\\ Y_\\alpha = e(g_1,g_2)^\\alpha,\\ \\{h_x\\}_{x\\in\\mathcal{U}}\\big)$$ $$\\mathrm{MSK} = g_1^{\\alpha}$$ (A large-universe variant replaces $\\{h_x\\}$ with a ROM hash $H:\\mathcal{U}\\to\\mathbb{G}_1$ and sets $h_x := H(x)$.)","heading":"Setup"},{"content":"Input: attribute set $S$. Sample $t\\in\\mathbb{Z}_p$. $$K = g_1^{\\alpha}\\cdot g_1^{at}\\in\\mathbb{G}_1,\\quad L = g_2^{t}\\in\\mathbb{G}_2,\\quad \\text{for each }x\\in S:\\ K_x = h_x^{t}\\in\\mathbb{G}_1$$ $$\\mathrm{SK} = (K,\\ L,\\ \\{K_x\\}_{x\\in S})$$","heading":"KeyGen"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$, message $M\\in\\mathbb{G}_T$. Sample $\\mathbf{v} = (s, v_2, \\ldots, v_{n_2})$ with fresh $v_j\\in\\mathbb{Z}_p$, and $t_i\\in\\mathbb{Z}_p$ per row. $$\\widetilde C = M\\cdot Y_\\alpha^{s}\\in\\mathbb{G}_T,\\quad C' = g_2^{s}\\in\\mathbb{G}_2$$ $$\\text{for each }i\\in[n_1]:\\quad C_i = g_1^{a\\lambda_i}\\cdot h_{\\rho(i)}^{-t_i}\\in\\mathbb{G}_1,\\quad D_i = g_2^{t_i}\\in\\mathbb{G}_2$$ $$\\mathrm{CT} = \\big(\\widetilde C,\\ C',\\ \\{C_i, D_i\\}_{i\\in[n_1]}\\big)$$","heading":"Encrypt"},{"content":"Let $I\\subseteq[n_1]$ be a satisfying row subset with reconstruction coefficients $\\{w_i\\}_{i\\in I}$ such that $\\sum_{i\\in I} w_i\\lambda_i = s$. Compute $$B = \\frac{e(K,\\ C')}{\\prod_{i\\in I}\\big(e(C_i,\\ L)\\cdot e(K_{\\rho(i)},\\ D_i)\\big)^{w_i}}.$$ Expanding: $e(K,C') = Y_\\alpha^s\\cdot e(g_1,g_2)^{ats}$; each row contributes $e(C_i,L)\\cdot e(K_{\\rho(i)},D_i) = e(g_1,g_2)^{at\\lambda_i}$ (the $h_{\\rho(i)}$ terms cancel). The denominator becomes $e(g_1,g_2)^{at\\sum w_i\\lambda_i} = e(g_1,g_2)^{ats}$, leaving $B = Y_\\alpha^{s}$. Recover $M = \\widetilde C / Y_\\alpha^{s}$. Pairings: $2I+1$ unoptimized; $I+2$ with row-aggregation (pre-compute $\\prod C_i^{w_i}$ and $\\prod K_{\\rho(i)}^{w_i}$ in $\\mathbb{G}_1$ before pairing).","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"CP-ABE · 2011","summary":"First CP-ABE for LSSS policies with polynomial-loss selective security under a q-type assumption. Reuses a single SK randomness t across all attributes, giving SK = (m+1) G1 + 1 G2 at the cost of a one-use restriction.","title":"Waters CP-ABE (PKC 2011)","type":"construction","venue":"PKC 2011","year":2011,"sourcePath":"data/abe-catalog.json#waters11"},{"evidence":"blocked_hybrid","id":"bns13_arithmetic_kpabe","keywords":["kp-abe","lattice","arithmetic_circuit","LWE","arithmetic-circuits","unbounded-fan-in","key-delegation","post-quantum"],"metadata":{"assumption":{"family":"LWE","name":"Learning With Errors (LWE)"},"authors":["Dan Boneh","Valeria Nikolaenko","Gil Segev"],"capabilities":["arithmetic-circuits","unbounded-fan-in","key-delegation","post-quantum"],"comparison":{"pareto_eligible":false,"reason":"Lattice matrix dimensions and bit sizes are not normalized to the pairing-group element axes used by pareto_query.py."},"construction":{"note":"Dual-Regev encryption plus deterministic key-homomorphic evaluation and lattice trapdoor preimage sampling.","schema":"hybrid_lattice","schema_version":1},"construction_family":"lattice","construction_one_liner":"Selectively secure LWE KP-ABE for polynomial-size arithmetic circuits, with a single matrix secret key whose asymptotic size depends on depth rather than circuit gate or wire count.\n","decrypt_cost":{"note":"Evaluation work scales with the arithmetic circuit; correctness is controlled by depth-dependent noise growth.","pairings":"0","primary":"key-homomorphic circuit evaluation + lattice decryption"},"decrypt_pairings":"0","id":"bns13_arithmetic_kpabe","name":"Boneh–Nikolaenko–Segev KP-ABE for Arithmetic Circuits","pairing":{"original_type":"none","type_III_port":[]},"paper":{"eprint":"2013/669","sections_cited":["§1 parameters and performance","§3 ABE construction","Theorem A.2"],"url":"https://eprint.iacr.org/2013/669","venue":"IACR ePrint 2013","year":2013},"pareto_notes":"Expands expressivity to arithmetic and unbounded-fan-in gates and supports delegation; its depth-dependent modulus and noise budget prevent a direct group-element comparison with pairing ABE.","policy":{"ROM_required":false,"class":"arithmetic_circuit","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"asymptotic":"O(L · poly(λ,d))","note":"Dual-Regev samples for the L-coordinate public attribute vector."},"MPK":{"asymptotic":"O(L · poly(λ,d))","note":"L public attribute matrices plus the lattice trapdoor public matrix; the hidden factor includes n, m and log q."},"SK":{"asymptotic":"O(d²)","note":"A single 2m × m low-norm matrix; unlike prior schemes, no multiplicative dependence on circuit size."},"sources":["BNS13 §1, Parameters and performance","BNS13 §3 construction"]},"variables":{"L":"attribute-vector length","d":"arithmetic-circuit depth","lam":"security parameter","m":"lattice column dimension, Theta(n log q)","n":"LWE dimension","q":"LWE modulus"},"verification":{"blocker":"lattice_only","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2013/669","sections":[{"content":"The scheme turns an attribute vector into a dual-Regev ciphertext under a tuple of public matrices. Anyone can deterministically evaluate an arithmetic circuit on those matrices and on the ciphertext, moving the ciphertext to a derived public key associated with the circuit output.","heading":"Intuition"},{"content":"Setup samples a trapdoor matrix and one public matrix for each coordinate of the attribute vector. The trapdoor is retained as the master secret key.","heading":"Setup"},{"content":"The authority evaluates the policy circuit on the public matrices and samples a short preimage for the output-zero matrix. The decryption key is one low-norm matrix rather than a component per circuit gate.","heading":"KeyGen"},{"content":"The encryptor produces a dual-Regev encryption under the matrix tuple selected by the public arithmetic attribute vector.","heading":"Encrypt"},{"content":"The decryptor homomorphically evaluates the circuit on the ciphertext. When the circuit evaluates to zero, the short preimage removes the LWE mask and the message is recovered by rounding.","heading":"Decrypt"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2013","summary":"Selectively secure LWE KP-ABE for polynomial-size arithmetic circuits, with a single matrix secret key whose asymptotic size depends on depth rather than circuit gate or wire count.","title":"Boneh–Nikolaenko–Segev KP-ABE for Arithmetic Circuits","type":"construction","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#bns13_arithmetic_kpabe"},{"evidence":"deferred_scalar_pes","id":"hw13_fast_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","q-type","fast-decryption","large-universe","user-tunable-tradeoff"],"metadata":{"assumption":{"family":"q-type","name":"decisional q-BDHE"},"authors":["Susan Hohenberger","Brent Waters"],"capabilities":["fast-decryption","large-universe","user-tunable-tradeoff"],"construction":{"note":"Type-I scalar pairing construction with a row-by-distinct-attribute helper matrix; normalization is deferred rather than approximated.","schema":"other","schema_version":1},"construction_family":"pairing","construction_one_liner":"Expressive large-universe KP-ABE whose optimized path decrypts with two pairings, at the cost of a secret-key blow-up by the number of distinct attributes in the policy.\n","decrypt_cost":{"exponentiations":"2I","note":"For AND/OR-derived LSSS coefficients, many exponentiations have exponent 0 or 1.","pairings":"2","primary":"2 pairings + 2I exponentiations"},"decrypt_pairings":"2","id":"hw13_fast_kpabe","name":"Hohenberger–Waters Fast-Decryption KP-ABE","pairing":{"original_type":"I","type_III_port":[]},"paper":{"eprint":"2013/265","sections_cited":["§3.1 base construction","§3.2 efficiency and tradeoffs","§3.3 large-universe realization"],"url":"https://eprint.iacr.org/2013/265","venue":"IACR ePrint 2013","year":2013},"pareto_notes":"A decryption-latency extreme rather than a universal dominance result: it preserves ciphertext size but trades larger keys and more multiplications for fewer pairings.","policy":{"ROM_required":true,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":true},"primitive":"KP-ABE","security":{"mode":"selective","model":"ROM","notion":"CPA"},"sizes":{"CT":{"G1":"m+1","GT":"1","note":"One group element per ciphertext attribute, one header, and one masked message."},"MPK":{"G1":"1","GT":"1","note":"Large-universe ROM version hashes attributes into the group; generators and the hash description are not counted."},"MSK":{"Zp":"1"},"SK":{"G1":"n1*(Gamma+1)","note":"Each LSSS row has D_i, R_i, and one helper for each other distinct policy attribute."},"sources":["HW13 §3.1–§3.3"]},"variables":{"Gamma":"number of distinct attributes occurring in the key policy","I":"number of satisfying LSSS rows used in decryption","m":"number of attributes attached to the ciphertext","n1":"number of LSSS rows in the key policy"},"verification":{"blocker":"fast_decryption_helpers_not_normalized","ggm_file":null,"note":"The scheme is pairing-based and structurally formalizable, but its per-distinct-attribute helper family has not yet been normalized to the repository PES grammar.","status":"deferred_scalar_pes"}},"primaryUrl":"https://eprint.iacr.org/2013/265","sections":[{"content":"GPSW performs a pairing for every satisfying row. HW13 adds helper values to each key row so the decryptor can aggregate all row terms before pairing. The resulting cancellation uses only two pairings.","heading":"Intuition"},{"content":"The large-universe version publishes a generator and the master pairing term. An attribute string is mapped to a group element by a random-oracle hash.","heading":"Setup"},{"content":"For each LSSS row, the authority creates the GPSW-style share components and a helper component for every other distinct attribute occurring in the policy. This is the source of the n1 * Gamma key-size term.","heading":"KeyGen"},{"content":"Encryption uses one randomness scalar for the header and all attribute components, so the ciphertext remains linear in the encrypted attribute set.","heading":"Encrypt"},{"content":"The decryptor multiplies the helpers and ciphertext attributes into two aggregates, then evaluates one numerator and one denominator pairing. Their ratio recovers the master masking term.","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"KP-ABE · 2013","summary":"Expressive large-universe KP-ABE whose optimized path decrypts with two pairings, at the cost of a secret-key blow-up by the number of distinct attributes in the policy.","title":"Hohenberger–Waters Fast-Decryption KP-ABE","type":"construction","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#hw13_fast_kpabe"},{"evidence":"deferred_scalar_pes","id":"rw13_cpabe","keywords":["cp-abe","pairing","monotone_LSSS","q-type"],"metadata":{"assumption":{"family":"q-type","name":"q-DPBDHE2 (called q-1 in the paper)"},"authors":["Yannis Rouselakis","Brent Waters"],"construction_one_liner":"First practical **unbounded**-universe CP-ABE without ROM. Replaces Waters11's per-attribute {h_x} with a two-element universe encoder (u, h) that maps any τ ∈ Z_p to u^τ·h. Pays factor-2 blowup in SK and 3× per-row CT for large universe + one-use LSSS + selective security under q-type.\n","decrypt_pairings":"3*I+1","id":"rw13_cpabe","implementations":["OpenABE","Charm","RELIC"],"name":"Rouselakis–Waters Large-Universe CP-ABE","pairing":{"original_type":"I","type_III_port":["FAME","ABGW","Charm"]},"paper":{"eprint":"2012/583","sections_cited":["§4.1 construction","Table 2 sizes"],"url":"https://eprint.iacr.org/2012/583","venue":"CCS 2013","year":2013},"pareto_notes":"The go-to \"simple, fast, selective unbounded\" baseline; widely implemented (OpenABE, Charm, RELIC). Superseded on SK size by FAME and FABEO, and on security mode (selective → adaptive) by dual-system schemes.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"2*n1+1","G2":"n1+1","GT":"1","note":"C_0 plus 2 per row (C_{i,1}, C_{i,2}) in G1; 1 per row (C_{i,3}) plus one master in G2; Ctilde in GT"},"MPK":{"G1":"4","GT":"1","note":"u, h, w, v in G1; Y_alpha in GT. Generators not counted."},"MSK":{"Zp":"1","note":"just alpha"},"SK":{"G1":"2*m+2","G2":"m+1","note":"K_0 and m K_{tau,3} in G1; K_1 and m K_{tau,2} in G2 (asymmetric port)"},"note_on_port":"RW13 states the scheme in symmetric pairings; the paper's own Table 2 (Charm benchmark) and FAME's Fig 5.5 both give the Type III element counts above.","sources":["RW13 (Rouselakis–Waters CCS 2013) §4.1 construction + Table 2 benchmark (element counts given as asymmetric port for Charm)","FAME (Agrawal–Chase CCS 2017) §5 (cross-checks the Type III port)"]},"superseded_by":["fame_cpabe","fabeo_cpabe"],"variables":{"I":"rows used in reconstruction","m":"|S|, attribute set size in SK","n1":"LSSS matrix rows","n2":"LSSS matrix columns"},"verification":{"blocker":"solver_tactics","ggm_file":null,"status":"deferred_scalar_pes"}},"primaryUrl":"https://eprint.iacr.org/2012/583","sections":[{"content":"Waters11 uses one $\\mathbb{G}_1$ element $h_x$ per attribute in MPK, which makes the universe bounded at setup. RW13's key move: replace $\\{h_x\\}_{x\\in\\mathcal{U}}$ with a two-element universe encoder $(u, h)\\in\\mathbb{G}_1^2$ that maps any $\\tau\\in\\mathbb{Z}_p$ to $u^\\tau\\cdot h$. Now attributes are arbitrary scalars, MPK is $O(1)$, and no random oracle is needed. To carry the universe encoding algebraically, each SK attribute spends two group elements $(K_{\\tau,2}, K_{\\tau,3})$ and each CT row spends three $(C_{i,1}, C_{i,2}, C_{i,3})$. The $v^{-r}$ term in $K_{\\tau,3}$ binds per-attribute randomness to the single top-level $r$, preventing mix-and-match across keys. Selective security reduces to a parametrized $q$-type assumption.","heading":"Intuition"},{"content":"Sample $\\alpha\\in\\mathbb{Z}_p$ and $u, h, w, v\\in\\mathbb{G}_1$ uniformly. $$\\mathrm{MPK} = \\big(g_1,\\ g_2,\\ u,\\ h,\\ w,\\ v,\\ Y_\\alpha = e(g_1,g_2)^\\alpha\\big)$$ $$\\mathrm{MSK} = \\alpha$$","heading":"Setup"},{"content":"Input: attribute set $S\\subset\\mathbb{Z}_p$. Sample $r\\in\\mathbb{Z}_p$ and $r_\\tau\\in\\mathbb{Z}_p$ for each $\\tau\\in S$. $$K_0 = g_1^{\\alpha}\\cdot w^{r}\\in\\mathbb{G}_1,\\quad K_1 = g_2^{r}\\in\\mathbb{G}_2$$ $$\\text{for each }\\tau\\in S:\\quad K_{\\tau,2} = g_2^{r_\\tau}\\in\\mathbb{G}_2,\\quad K_{\\tau,3} = (u^{\\tau}h)^{r_\\tau}\\cdot v^{-r}\\in\\mathbb{G}_1$$ $$\\mathrm{SK} = \\big(S,\\ K_0,\\ K_1,\\ \\{K_{\\tau,2},\\ K_{\\tau,3}\\}_{\\tau\\in S}\\big)$$","heading":"KeyGen"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$ with $\\rho:[n_1]\\to\\mathbb{Z}_p$, message $M\\in\\mathbb{G}_T$. Sample $\\mathbf{v}=(s, y_2, \\ldots, y_{n_2})$ and $t_i\\in\\mathbb{Z}_p$ per row. $$\\widetilde C = M\\cdot Y_\\alpha^{s}\\in\\mathbb{G}_T,\\quad C_0 = g_2^{s}\\in\\mathbb{G}_2$$ $$\\text{for each }i\\in[n_1]:\\quad C_{i,1} = w^{\\lambda_i}\\cdot v^{t_i}\\in\\mathbb{G}_1,\\quad C_{i,2} = (u^{\\rho(i)}h)^{-t_i}\\in\\mathbb{G}_1,\\quad C_{i,3} = g_2^{t_i}\\in\\mathbb{G}_2$$ $$\\mathrm{CT} = \\big(\\widetilde C,\\ C_0,\\ \\{C_{i,1},\\ C_{i,2},\\ C_{i,3}\\}_{i\\in[n_1]}\\big)$$","heading":"Encrypt"},{"content":"Let $I\\subseteq[n_1]$ be satisfying rows with reconstruction coefficients $\\{w_i\\}_{i\\in I}$. Compute $$B = \\frac{e(K_0,\\ C_0)}{\\prod_{i\\in I}\\big(e(C_{i,1},\\ K_1)\\cdot e(K_{\\rho(i),3},\\ C_{i,3})\\cdot e(C_{i,2},\\ K_{\\rho(i),2})\\big)^{w_i}}.$$ Expanding: $e(K_0, C_0) = Y_\\alpha^s\\cdot e(g_1,g_2)^{wrs}$ (using $w$ as a placeholder; conflicts with reconstruction coeffs, so in practice $w$ and $w_i$ are written distinctly). Each row contributes a product whose $v^{-r}\\cdot v^{t_i}$ terms cancel $e(g_1,g_2)^{v\\cdot\\ldots}$, and whose $(u^\\tau h)$ factors cancel across $K_{\\tau,3}$ and $C_{i,2}$ when $\\tau = \\rho(i)$; the net exponent in the denominator is $\\sum_i w_i(w\\cdot\\lambda_i\\cdot r) = wrs$. Thus $B = Y_\\alpha^s$; recover $M = \\widetilde C/Y_\\alpha^s$. Pairings: $3I + 1$.","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"CP-ABE · 2013","summary":"First practical unbounded-universe CP-ABE without ROM. Replaces Waters11's per-attribute {h_x} with a two-element universe encoder (u, h) that maps any τ ∈ Z_p to u^τ·h. Pays factor-2 blowup in SK and 3× per-row CT for large universe + one-use LSSS + selective security under q-type.","title":"Rouselakis–Waters Large-Universe CP-ABE","type":"construction","venue":"CCS 2013","year":2013,"sourcePath":"data/abe-catalog.json#rw13_cpabe"},{"evidence":"deferred_scalar_pes","id":"rw13_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","q-type"],"metadata":{"assumption":{"family":"q-type","name":"q-DPBDHE2 (called q-2 in the paper)"},"authors":["Yannis Rouselakis","Brent Waters"],"construction_one_liner":"KP-ABE dual of the RW13 CP-ABE. Same universe encoder (u, h), same O(1) MPK, large-universe via Z_p attribute labels, no ROM. Sizes transpose: SK grows with LSSS rows, CT grows with attribute count.\n","decrypt_pairings":"3*I+1","id":"rw13_kpabe","implementations":["OpenABE","Charm","RELIC"],"name":"Rouselakis–Waters Large-Universe KP-ABE","pairing":{"original_type":"I","type_III_port":["FAME","ABGW","Charm"]},"paper":{"eprint":"2012/583","sections_cited":["§4.2 KP-ABE construction","Table 2 sizes"],"url":"https://eprint.iacr.org/2012/583","venue":"CCS 2013","year":2013},"pareto_notes":"Practical selective large-universe KP-ABE; widely implemented. Superseded on assumption (q-type → k-Lin) by CGW15/CGKW18, on security mode (selective → adaptive) by dual-system schemes, on size by FABEO.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"2*m+1","G2":"m","GT":"1","note":"Per attribute: C_{tau,1} in G_1, C_{tau,2} in G_1, C_{tau,3} in G_2; plus C_0 in G_1 and Ctilde in G_T."},"MPK":{"G1":"4","GT":"1","note":"u, h, w, v in G_1 plus Y_alpha in G_T. Same MPK structure as RW13 CP-ABE."},"MSK":{"Zp":"1"},"SK":{"G1":"n1","G2":"2*n1+1","note":"Per LSSS row: K_{i,0} in G_2, K_{i,1} in G_1, K_{i,2} in G_2; plus K_0 in G_2. Dual of CP-ABE."},"note_on_port":"RW13 states the scheme in symmetric pairings; sizes below follow the paper's own Charm benchmark (Table 2) asymmetric port.","sources":["RW13 §4.2 KP-ABE construction","RW13 Table 2 (Charm benchmark) asymmetric element counts"]},"superseded_by":["cgkw18","fabeo_kpabe"],"variables":{"I":"rows used at decryption","m":"|S|, attribute set size in CT","n1":"LSSS matrix rows (policy size in SK)","n2":"LSSS matrix columns"},"verification":{"blocker":"solver_tactics","ggm_file":null,"status":"deferred_scalar_pes"}},"primaryUrl":"https://eprint.iacr.org/2012/583","sections":[{"content":"The KP-ABE counterpart of RW13's CP-ABE. Same universe encoder $(u^\\tau h)$ makes the universe unbounded ($\\tau\\in\\mathbb{Z}_p$) without a random oracle, same $O(1)$ MPK. The roles of key and ciphertext transpose from the CP-ABE: the LSSS lives in the key (policy-in-key), the attribute set lives in the ciphertext. Selective security reduces to a parametrized $q$-type assumption ($q$-2 in the paper, analogous to $q$-1 for the CP variant).","heading":"Intuition"},{"content":"Sample $u, h, w, v\\leftarrow_R\\mathbb{G}_1$ and $\\alpha\\leftarrow_R\\mathbb{Z}_p$. $$\\mathrm{MPK} = (g_1,\\ g_2,\\ u,\\ h,\\ w,\\ v,\\ Y_\\alpha = e(g_1,g_2)^\\alpha),\\quad \\mathrm{MSK} = \\alpha$$","heading":"Setup"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$ with $\\mathbf{M}\\in\\mathbb{Z}_p^{n_1\\times n_2}$, $\\rho:[n_1]\\to\\mathbb{Z}_p$. Sample sharing vector $\\mathbf{v} = (\\alpha, y_2, \\ldots, y_{n_2})$ and per-row $t_i\\leftarrow_R\\mathbb{Z}_p$: $$K_0 = g_2^{?},\\ \\text{(top-level share binder)}$$ $$\\text{for each row } i:\\ K_{i,0} = g_2^{\\lambda_i}\\cdot v^{t_i},\\quad K_{i,1} = (u^{\\rho(i)}h)^{-t_i}\\in\\mathbb{G}_1,\\quad K_{i,2} = g_2^{t_i}$$ where $\\lambda_i = \\mathbf{M}_i\\cdot\\mathbf{v}$. (Exact form in §4.2; the key point is the dual structure to the CP-ABE's CT.)","heading":"KeyGen"},{"content":"Input: attribute set $S\\subset\\mathbb{Z}_p$, message $M\\in\\mathbb{G}_T$. Sample $s, t_\\tau\\leftarrow_R\\mathbb{Z}_p$ per attribute: $$\\widetilde C = M\\cdot Y_\\alpha^s,\\quad C_0 = g_1^s$$ $$\\text{for each } \\tau\\in S:\\ C_{\\tau,1} = w^s\\cdot v^{t_\\tau},\\quad C_{\\tau,2} = (u^\\tau h)^{-t_\\tau},\\quad C_{\\tau,3} = g_2^{t_\\tau}$$","heading":"Encrypt"},{"content":"Reconstruction coefficients $\\{\\omega_i\\}$ as usual; combine pairings in a sum that cancels the $v^{\\pm}$ and $(u^\\tau h)$ cross-terms, yielding $Y_\\alpha^s$. Pairings: $3I+1$, the same count as RW13 CP-ABE.","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"KP-ABE · 2013","summary":"KP-ABE dual of the RW13 CP-ABE. Same universe encoder (u, h), same O(1) MPK, large-universe via Z_p attribute labels, no ROM. Sizes transpose: SK grows with LSSS rows, CT grows with attribute count.","title":"Rouselakis–Waters Large-Universe KP-ABE","type":"construction","venue":"CCS 2013","year":2013,"sourcePath":"data/abe-catalog.json#rw13_kpabe"},{"evidence":"blocked_composite_order","id":"attrapadung14","keywords":["kp-abe","pairing","monotone_LSSS","q-type"],"metadata":{"assumption":{"family":"q-type","name":"q-type (computational PES)"},"authors":["Nuttapong Attrapadung"],"construction_one_liner":"Introduces pair encoding schemes (PES): a combinatorial object that compiles generically to adaptive ABE via dual-system encryption. This spec captures the headline \"short-CT\" KP-ABE instantiation; other instantiations (short-SK, regular languages, unbounded) also exist.\n","decrypt_pairings":"O(1)","id":"attrapadung14","name":"Attrapadung Pair Encoding Framework — Short-CT KP-ABE","ontology":{"assumption_deps":{"assumption_q_type":["proof_q_type_reduction"],"assumption_subgroup_decision":["subprim_composite_order_subgroup"]},"atoms":["attr_universe_scalar","policy_LSSS_monotone","subprim_composite_order_subgroup","master_alpha_scalar_SK_linear","proof_q_type_reduction"],"features_provided":{"feature_adaptive_security":"proof_q_type_reduction"}},"pairing":{"original_type":"composite","type_III_port":["AC17","CGW15"]},"paper":{"eprint":"2014/428","sections_cited":["§3 PES definitions","§6 KP-ABE for LSSS instantiations","full version 2014/428"],"url":"https://eprint.iacr.org/2014/428","venue":"Eurocrypt 2014","year":2014},"pareto_notes":"The scaffolding paper for modern ABE. Practically every subsequent adaptive ABE (FAME, ABGW17, KW19, LL20, FABEO) is either a prime-order port or a refinement of PES. The short-CT variant here is the first adaptive constant-size-CT KP-ABE for Boolean formulas.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"O(1)","GT":"1","note":"CONSTANT ciphertext: 3–4 group elements in G_1 + 1 G_T, independent of |S| (up to bound T)."},"MPK":{"G1":"O(T)","GT":"1","note":"T is the a-priori ciphertext-attribute bound; MPK linear in T."},"SK":{"G2":"n1*T","note":"SK quadratic in policy size and ciphertext-attribute bound (short-CT KP-ABE spends SK for compact CT)."},"note_on_port":"Composite-order in the original paper; Agrawal–Chase (TCC 2016-A, FAME CCS 2017) and Chen–Gay–Wee port to prime-order. Sizes below are for the headline **short-CT** KP-ABE with ciphertext-attribute bound T.","sources":["Attrapadung Eurocrypt 2014 §6 (PES instantiations)","Agrawal–Chase TCC 2016-A 'Study of Pair Encodings' comparison tables"]},"variables":{"I":"rows used at decryption","T":"a-priori bound on ciphertext attribute set size (must be chosen at setup)","m":"|S|, attribute set size in CT","n1":"LSSS matrix rows (policy size in SK)"},"verification":{"blocker":"composite_order","ggm_file":null,"status":"blocked_composite_order"}},"primaryUrl":"https://eprint.iacr.org/2014/428","sections":[{"content":"Attrapadung14 extracts the algebraic essence of \"dual-system encryption for ABE\" into a compact combinatorial object: a pair encoding scheme (PES) consisting of two polynomial encodings $$c(\\mathbf{s},\\mathbf{b}) \\text{ (ciphertext-side)} \\qquad\\text{and}\\qquad k(\\mathbf{r}, \\boldsymbol{\\alpha}, \\mathbf{b}) \\text{ (key-side)}$$ each linear in its own randomness, with a decryption relation recovering $\\alpha\\cdot s$ when the predicate holds. Security of the encoding is defined selectively and co-selectively (hence \"doubly selective\"); the paper's main theorem shows that a doubly-selective PES lifts to an adaptively secure ABE via dual-system encryption, in composite-order bilinear groups. This is the scaffolding paper for essentially every modern ABE. Specific PES designs in the paper yield first-of-their-kind constructions: KP-ABE for LSSS (information-theoretic PES, static subgroup decision). KP-ABE with short ciphertext (computational PES, q-type). ← this spec. KP-ABE with short secret key (computational PES; short-SK at cost of CT blowup). KP-ABE for regular languages (first adaptive DFA-ABE; computational PES). Unbounded KP-ABE for LSSS (computational PES). CP-ABE variants via the duality conversion (extended in AY15).","heading":"Intuition"},{"content":"(Full construction in §6 of the ePrint.) Setup: choose a bound $T$ on the ciphertext attribute set size. MPK has $O(T)$ group elements encoding the PES common parameters $\\mathbf{b}$ over the composite-order group. KeyGen: for each LSSS row $i\\in[n_1]$, the key encoding $k_i(\\mathbf{r},\\alpha,\\mathbf{b})$ produces $O(T)$ group elements. SK has $O(n_1\\cdot T)$ elements. Encrypt: the ciphertext encoding $c(\\mathbf{s},\\mathbf{b})$ has $O(1)$ polynomials regardless of $|S|$ — the short-CT property. Plus 1 $\\mathbb{G}_T$ masking term. Decrypt: reconstructs $\\alpha\\cdot s$ via a constant number of pairings — $O(1)$.","heading":"Sketch of the short-CT KP-ABE"}],"status":"blocked_composite_order","subtitle":"KP-ABE · 2014","summary":"Introduces pair encoding schemes (PES): a combinatorial object that compiles generically to adaptive ABE via dual-system encryption. This spec captures the headline \"short-CT\" KP-ABE instantiation; other instantiations (short-SK, regular languages, unbounded) also exist.","title":"Attrapadung Pair Encoding Framework — Short-CT KP-ABE","type":"construction","venue":"Eurocrypt 2014","year":2014,"sourcePath":"data/abe-catalog.json#attrapadung14"},{"evidence":"blocked_hybrid","id":"bgg14_kpabe","keywords":["kp-abe","lattice","circuit","standard"],"metadata":{"assumption":{"family":"standard","name":"Learning With Errors (LWE)"},"authors":["Dan Boneh","Craig Gentry","Sergey Gorbunov","Shai Halevi","Valeria Nikolaenko","Gil Segev","Vinod Vaikuntanathan","Dhinakaran Vinayagamurthy"],"construction":{"note":"Pure-lattice scheme; no PES polynomials.  Construction is BGG+14:\nLWE samples per attribute bit + BGG+ key-homomorphic eval + lattice\ntrapdoor SampleD on the evaluated matrix → SK is a short preimage.\nDecryption: pair the SK preimage against the BGG+-evaluated CT (Z_q\ninner product + rounding) when f(x)=0.\n","schema":"hybrid_lattice","schema_version":1},"construction_one_liner":"First KP-ABE for circuits from LWE.  Introduces the BGG+ key-homomorphic evaluation primitive that downstream lattice ABE schemes (GVW13 KP, BV16, Tsabary19, LLL22, HLL24, Wee24, Wee25) all build on.\n","decrypt_pairings":"0","id":"bgg14_kpabe","name":"Boneh–Gentry–Gorbunov–Halevi–Nikolaenko–Segev–Vaikuntanathan–Vinayagamurthy KP-ABE for Circuits","ontology":{"assumption_deps":{"BGG_plus_homomorphism_correctness":["join: lattice_inner_product_round"],"assumption_LWE":["subprim_BGG_plus_circuit_eval","subprim_lattice_trapdoor","proof_LWE_reduction"],"assumption_SIS":["subprim_lattice_trapdoor"],"noise_budget_bounded":["join: lattice_inner_product_round"]},"atoms":["attr_binary_vector","policy_circuit_bounded_depth","subprim_BGG_plus_circuit_eval","subprim_lattice_trapdoor","master_mu_bit_LWE","proof_LWE_reduction"],"connections":[{"from":"attr_binary_vector.attribute_x","note":"encoding s^T·((A_1‖...‖A_L) - x⊗G) + e is circuit-evaluable","to":"subprim_BGG_plus_circuit_eval.attribute_x"},{"from":"policy_circuit_bounded_depth.circuit_policy","note":"circuit f passed to homomorphic evaluator","to":"subprim_BGG_plus_circuit_eval.circuit_f"},{"from":"subprim_BGG_plus_circuit_eval.evaluated_A_f","note":"SK for f is SampleD preimage of (A‖A_f) — uses trapdoor T_A","to":"subprim_lattice_trapdoor.target_matrix"}],"features_provided":{"feature_circuit_support":"subprim_BGG_plus_circuit_eval","feature_selective_security":"proof_LWE_reduction"},"joins_used":["lattice_inner_product_round"]},"pairing":{"original_type":"none","type_III_port":[]},"paper":{"eprint":"2014/356","sections_cited":["§4 KP-ABE for circuits","§5 BGG+ key-homomorphic evaluation"],"url":"https://eprint.iacr.org/2014/356","venue":"Eurocrypt 2014","year":2014},"pareto_notes":"SK is poly(d, λ) — independent of circuit size, but linear in depth. Later schemes (LLL22) compress this to literally 3 group elements via pairing-based hybridization.\n","policy":{"ROM_required":false,"class":"circuit","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"note":"L LWE samples + 1 message-carrying LWE sample. poly(L, λ, d)."},"MPK":{"note":"L lattice matrices each of dim O(n*log q), where L = attribute bit-length and n = LWE dim. poly(L, λ, d)."},"SK":{"note":"Short lattice vector of dim m_total = O(L·m). Length scales as poly(d, λ); INDEPENDENT of circuit size."},"sources":["BGG+14 §4 construction","BGG+14 Theorem 4 size statement"]},"variables":{"L":"attribute bit-length","d":"circuit depth bound","lam":"security parameter","m":"lattice column dim (≈ n·log q)","m_total":"trapdoor preimage dim (typically 2m or so)","n":"LWE dimension","q":"modulus"},"verification":{"blocker":"lattice_only","ggm_file":null,"note":"Pure lattice-based; no pairing operations. ggm-symbolic-solver and\ngga-unbounded both target pairing-based primitives. Lattice ABE\nschemes don't have a unified verification backend in this repo (a\nseparate proof-tool for LWE security would be needed).  The\n`ontology:` block is the structural decomposition; the construction\nis documented in prose only.\n","status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2014/356","sections":[{"content":"BGG+14 introduces the BGG+ key-homomorphic evaluation primitive that has become the load-bearing technique for every subsequent LWE-based ABE for circuits (GVW13 KP-ABE for arithmetic circuits, BV16, Tsabary19, LLL22, HLL24, Wee24/25). The scheme is for bounded-depth Boolean circuits with selective security under standard LWE. The key idea: each attribute bit $x_i$ is encoded as an LWE sample under a designated lattice matrix $\\mathbf{B}_i + x_i\\mathbf{G}$ where $\\mathbf{G}$ is the gadget matrix. A circuit $f$ can be homomorphically evaluated on these LWE samples — yielding a single LWE sample under the evaluated matrix $\\mathbf{B}_f$ — without knowing the secret randomness. The secret key for $f$ is a short lattice preimage that decrypts the homomorphic output when $f(x) = 0$.","heading":"Intuition"},{"content":"Setup: lattice trapdoor $(\\mathbf{A}, \\mathbf{T}_{\\mathbf{A}})$ + per-bit matrices $\\mathbf{B}_1, \\ldots, \\mathbf{B}_L$. KeyGen($f$): compute $\\mathbf{A}_f = \\mathrm{EvalF}(f, \\mathbf{A}_1, \\ldots, \\mathbf{A}_L)$ via BGG+ eval; sample short $\\mathbf{r}$ s.t. $[\\mathbf{A} \\| \\mathbf{A}_f] \\cdot \\mathbf{r} = \\mathbf{0}$ using $\\mathbf{T}_{\\mathbf{A}}$. Encrypt($\\mathbf{x}, \\mu$): per bit $i$: $\\mathbf{c}_i = \\mathbf{s}^\\top(\\mathbf{B}_i + x_i\\mathbf{G}) + \\mathbf{e}_i$; final blinder: $c_\\mu = \\mathbf{s}^\\top \\mathbf{B}_{target} + e_\\mu + \\mu \\lfloor q/2 \\rfloor$. Decrypt (when $f(\\mathbf{x}) = 0$): homomorphically evaluate $f$ on $\\{\\mathbf{c}_i\\}$ to get $\\mathbf{c}_f$; compute $\\langle \\mathbf{r}, [\\mathbf{c}_f \\| c_\\mu] \\rangle \\approx \\mu \\lfloor q/2 \\rfloor$; round.","heading":"Sketch"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2014","summary":"First KP-ABE for circuits from LWE. Introduces the BGG+ key-homomorphic evaluation primitive that downstream lattice ABE schemes (GVW13 KP, BV16, Tsabary19, LLL22, HLL24, Wee24, Wee25) all build on.","title":"Boneh–Gentry–Gorbunov–Halevi–Nikolaenko–Segev–Vaikuntanathan–Vinayagamurthy KP-ABE for Circuits","type":"construction","venue":"Eurocrypt 2014","year":2014,"sourcePath":"data/abe-catalog.json#bgg14_kpabe"},{"evidence":"solver_verified","id":"cgw15_cpabe","keywords":["cp-abe","pairing","monotone_LSSS","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k, Escala et al.)"},"authors":["Jie Chen","Romain Gay","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"alpha1 * A1 * s + alpha2 * A2 * s","group":"G_T","name":"Ctilde"},{"expr":"A1 * s","group":"G_1","name":"C01"},{"expr":"A2 * s","group":"G_1","name":"C02"},{"expr":"(M1*s + M*u) * A1 + w1 * s","group":"G_1","name":"c1","note":"First K-coord of per-row CT; adapts FABEO c to CGW-style K-lifting.","shape":"Zp^N"},{"expr":"(M1*s + M*u) * A2 + w2 * s","group":"G_1","name":"c2","note":"Second K-coord, symmetric to c1.","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0 (LSSS not satisfied)","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"Choose {w_i}_{i in I} with sum_i w_i * (M1_i, M_i) = (1, 0, ..., 0).\nRecover blinder via K-coord aggregation:\nalpha1*A1*s + alpha2*A2*s = e(L, C01) - sum_i w_i * e(Ku1_i, C01)\n                          + e(L, C02) - sum_i w_i * e(Ku2_i, C02)\n                          + sum_i w_i * (e(L, c1_i) + e(L, c2_i))\n                          - ... (schematic; the paper's formula uses\n                          matrix pairings that aggregate over the K\n                          index; at K=2 this unrolls into 2x the\n                          FABEO reconstruction pattern)\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"alpha1 + r * A1","group":"G_2","name":"K1"},{"expr":"alpha2 + r * A2","group":"G_2","name":"K2"},{"expr":"r","group":"G_2","name":"L"},{"expr":"r * diag(x) * w1","group":"G_2","name":"Ku1","note":"First K-coord; entry j is r*w1_j when x_j=1.","shape":"Zp^N"},{"expr":"r * diag(x) * w2","group":"G_2","name":"Ku2","shape":"Zp^N"}],"target":"alpha1 * A1 * s + alpha2 * A2 * s","variables":{"common":["A1","A2","w1","w2"],"ct_randomness":["s","u"],"master":["alpha1","alpha2"],"shapes":{"u":"Zp^K","w1":"Zp^N","w2":"Zp^N"},"sk_randomness":["r"]}},"construction_one_liner":"First fully adaptive CP-ABE in prime-order groups under a static k-Lin assumption, via the predicate-encoding framework. Achieves dual-system security without composite-order groups, at (k+1)× blowup vs. selective.\n","decrypt_pairings":"2*(k+1)","id":"cgw15_cpabe","name":"Chen–Gay–Wee CP-ABE","ontology":{"assumption_deps":{"assumption_k_Lin":["enc_matrix_dual_system","master_k_vector_dual_system","proof_k_Lin_reduction"]},"atoms":["attr_universe_matrix","policy_LSSS_monotone","lsss_one_use","enc_matrix_dual_system","master_k_vector_dual_system","proof_dual_system_hybrid","proof_k_Lin_reduction"],"connections":[{"from":"policy_LSSS_monotone.monotone_lsss","note":"ρ injective enables one-use simplification","to":"lsss_one_use.lsss_in"},{"from":"lsss_one_use.lsss_one_use_out","note":"LSSS feeds the dual-system matrix encoder","to":"enc_matrix_dual_system.policy_in"}],"features_provided":{"feature_adaptive_security":"proof_dual_system_hybrid","feature_standard_assumption":"proof_k_Lin_reduction","feature_type_III_pairing":"enc_matrix_dual_system"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2015/409","sections_cited":["§6 generic construction","§A.5 CP-ABE predicate encoding","Appendix B.2 full CP-ABE scheme","Fig. 4 sizes"],"url":"https://eprint.iacr.org/2015/409","venue":"Eurocrypt 2015","year":2015},"pareto_notes":"Historical milestone: proves adaptive security from k-Lin in the standard model. Loses on size to FAME and FABEO. One-use restriction; SK grows with the universe, not the attribute set — severe practical drawback.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":false,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"2*U+2","GT":"1","note":"SXDH (k=1). General k-Lin: (k+1)(n_1+1). Here n_1 = U due to one-use."},"MPK":{"G1":"2*U+3","GT":"1","note":"SXDH (k=1) instantiation. General k-Lin: k(k+1)(U+1)+k in G1, k in GT. U = universe size."},"SK":{"G2":"2*U+4","note":"SXDH (k=1). General k-Lin: (k+1)(U+2). SK grows with universe U, not |S|, under one-use restriction."},"sources":["CGW15 Fig. 4 (p. 6): general k-Lin and SXDH (k=1) / DLIN (k=2) instantiations","CGW15 Appendix B.2: explicit CP-ABE scheme"]},"variables":{"K":"LSSS matrix extra columns (= n2 - 1); note this K differs from the paper's k-Lin K (= k+1, here concretized to 2)","N":"LSSS matrix rows (= U under one-use in CGW15)","U":"attribute universe size = LSSS row count under one-use (ell in the paper)","k":"k-Lin parameter (k=1 pilot here; the paper's K := k+1 = 2 is concretized and does not appear as a spec symbol)","m":"|S|, attribute set size in SK"},"verification":{"ggm_file":null,"note":"Verified end-to-end (M1 confirmed 2026-04-23): compile_pes_to_ggm.py\nproduces a .ggm at k=1 (K=2 unrolled), the solver returns \"no\nremaining goals\". This construction block is a CGW15-inspired\nscheme with master and common parameters K-lifted but with a\nsingle FABEO-style sharing vector u instead of per-LSSS-column\naugmentation matrices U_c — NOT a faithful transcription of\nCGW15 §B.2 (which has U_c matrices per extra LSSS col).  The\nsimplification is solver-verified at K=2; faithful-§B.2\ntranscription is future work (would need per-col U_c matrices).\nSee docs/matrix_pes_generalization.md §6.\n","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2015/409","sections":[{"content":"CGW15 takes the dual-system encryption technique of Lewko–Waters (Eurocrypt 2010) — originally built on composite-order groups — and ports it to prime-order groups using matrix encodings (e.g., $[A]_1$ denotes $g_1^A$ for a matrix $A$) under the $k$-Lin (MDDH$_k$) assumption. A new predicate-encoding framework (§6) lets them instantiate ABE, IBE, inner-product encryption, and ABE-for-regular-languages uniformly; the CP-ABE for monotone span programs comes out of the LSSS predicate encoding in §A.5, fully written out in Appendix B.2. Security is adaptive under $k$-Lin with polynomial loss.","heading":"Intuition"},{"content":"Sample $A \\leftarrow_R \\mathbb{Z}_p^{(k+1)\\times k}$ and $B \\leftarrow_R \\mathbb{Z}_p^{(k+1)\\times k}$ from the $k$-Lin distribution $D_k$. Sample $W_1, \\ldots, W_U, V \\leftarrow_R \\mathbb{Z}_p^{(k+1)\\times(k+1)}$ and $\\mathbf{k} \\leftarrow_R \\mathbb{Z}_p^{k+1}$. $$\\mathrm{MPK} = \\big([A]_1,\\ [W_1^\\top A]_1, \\ldots, [W_U^\\top A]_1,\\ [V^\\top A]_1,\\ e([A]_1, [\\mathbf{k}]_2)\\big)$$ $$\\mathrm{MSK} = (\\mathbf{k},\\ B,\\ W_1, \\ldots, W_U,\\ V)$$","heading":"Setup"},{"content":"Input: attribute vector $\\mathbf{x}\\in\\{0,1\\}^U$ (characteristic vector of $S$). Sample $\\mathbf{r}\\leftarrow_R\\mathbb{Z}_p^k$. $$K_0 = [B\\mathbf{r}]_2,\\quad K_j = [x_j W_j B\\mathbf{r}]_2\\ \\text{for } j\\in[U],\\quad K_{U+1} = [\\mathbf{k} + VB\\mathbf{r}]_2$$","heading":"KeyGen"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$ with $\\mathbf{M}\\in\\mathbb{Z}_p^{U\\times n_2}$, message $m\\in\\mathbb{G}_T$. Sample $\\mathbf{s}\\leftarrow_R\\mathbb{Z}_p^k$ and $U_2,\\ldots,U_{n_2}\\leftarrow_R\\mathbb{Z}_p^{(k+1)\\times(k+1)}$. $$C_0 = [A\\mathbf{s}]_1,\\quad C'_0 = e(g_1,g_2)^{\\mathbf{k}^\\top A\\mathbf{s}}\\cdot m$$ $$C_j = \\big[(V^\\top A\\mathbf{s}\\mid U_2^\\top A\\mathbf{s}\\mid\\cdots\\mid U_{n_2}^\\top A\\mathbf{s})\\cdot \\mathbf{M}_j^\\top + W_{\\rho(j)}^\\top A\\mathbf{s}\\big]_1\\ \\text{for } j\\in[n_1]$$","heading":"Encrypt"},{"content":"With reconstruction coefficients $\\omega_j$ for the satisfying rows, $$e(g_1,g_2)^{\\mathbf{k}^\\top A\\mathbf{s}} = e(C_0,\\ K_{U+1}\\cdot\\prod_j K_j^{\\omega_j})\\cdot e(\\prod_j C_j^{-\\omega_j},\\ K_0)$$ recovers the blinder. Pairings: $2(k+1)$ scalar pairings (2 \"matrix pairings\"), independent of $|I|$.","heading":"Decrypt"}],"status":"solver_verified","subtitle":"CP-ABE · 2015","summary":"First fully adaptive CP-ABE in prime-order groups under a static k-Lin assumption, via the predicate-encoding framework. Achieves dual-system security without composite-order groups, at (k+1)× blowup vs. selective.","title":"Chen–Gay–Wee CP-ABE","type":"construction","venue":"Eurocrypt 2015","year":2015,"sourcePath":"data/abe-catalog.json#cgw15_cpabe"},{"evidence":"solver_verified","id":"cgw15_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k, Escala et al.)"},"authors":["Jie Chen","Romain Gay","Hoeteck Wee"],"construction":{"U":"attribute universe size (one-use)","ciphertext_encoding":[{"expr":"v1 * A1 * s + v2 * A2 * s","group":"G_T","name":"Ctilde"},{"expr":"s","group":"G_1","name":"Cs"},{"expr":"diag(x) * w1 * s","group":"G_1","name":"cx1","shape":"Zp^N"},{"expr":"diag(x) * w2 * s","group":"G_1","name":"cx2","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"KP dual of CGW15 CP: pair skshare_a per K-coord with Cs (to get\nM1-row-selection of v_a*s after reconstruction) and cx_a with skr\n(to cancel the w*r term via x-gated attribute matching).\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"r","group":"G_2","name":"skr"},{"expr":"M1 * v1 + M * u1 + w1 * r * A1","group":"G_2","name":"skshare1","shape":"Zp^N"},{"expr":"M1 * v2 + M * u2 + w2 * r * A2","group":"G_2","name":"skshare2","shape":"Zp^N"}],"target":"v1 * A1 * s + v2 * A2 * s","variables":{"common":["A1","A2","w1","w2"],"ct_randomness":["s"],"master":["v1","v2"],"shapes":{"u1":"Zp^K","u2":"Zp^K","w1":"Zp^N","w2":"Zp^N"},"sk_randomness":["r","u1","u2"]}},"construction_one_liner":"KP-ABE dual of CGW15 CP-ABE. First adaptive KP-ABE from static k-Lin in prime-order groups via predicate encodings. Fixed 2(k+1) pairings.\n","decrypt_pairings":"2*(k+1)","id":"cgw15_kpabe","name":"Chen–Gay–Wee KP-ABE","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2015/409","sections_cited":["§6 generic construction","§A.5 KP-ABE predicate encoding","§B.1 full KP-ABE scheme","Fig. 4 sizes"],"url":"https://eprint.iacr.org/2015/409","venue":"Eurocrypt 2015","year":2015},"pareto_notes":"Historical milestone for adaptive + standard assumption + prime-order. One-use restriction and universe-size-dependent SK (not |S|-dependent) limit practical use; superseded by CGKW18 (unbounded), KW19 (compact), FABEO (optimal size).\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"2*U+2","GT":"1","note":"SXDH (k=1). General k-Lin: (k+1)(U+1). Under one-use, U acts like max CT-attribute count."},"MPK":{"G1":"2*U+3","GT":"1","note":"SXDH (k=1) instantiation; general k-Lin: k(k+1)(U+1)+k in G_1, k in GT."},"SK":{"G2":"2*n1+2","note":"SXDH (k=1). General k-Lin: (k+1)(n_1+1). Dual of CP-ABE: SK grows with LSSS rows."},"sources":["CGW15 Fig. 4 (p. 6) k-Lin / SXDH / DLIN instantiations","CGW15 §B.1 explicit KP-ABE scheme"]},"superseded_by":["cgkw18","fabeo_kpabe"],"variables":{"I":"rows used at decryption","K":"LSSS extra cols; note: this K differs from paper's k-Lin K = k+1 (concretized to 2)","N":"LSSS matrix rows (policy size in SK); = attribute universe U under one-use","k":"k-Lin parameter (k=1 pilot)","m":"|S|, CT attribute set size"},"verification":{"ggm_file":null,"note":"Verified end-to-end (M1 confirmed 2026-04-23) at k=1 (K=2). KP dual\nof CGW15 CP pilot — same simplification: single FABEO-style aug\nvector `u` per K-coord instead of per-LSSS-col U_c matrices.\nFaithful CGW15 §B.2 transcription is future work.  See\ndocs/matrix_pes_generalization.md §6.\n","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2015/409","sections":[{"content":"The KP-ABE companion of CGW15 CP-ABE (see cgw15_cpabe.md). Same predicate-encoding framework, same matrix-in-exponent structure under $k$-Lin, same dual-system encryption proof. The roles of key and ciphertext transpose: the LSSS policy lives in SK, attributes live in CT.","heading":"Intuition"},{"content":"MPK = $(2U+3)\\cdot|\\mathbb{G}_1| + 1\\cdot|\\mathbb{G}_T|$ SK = $(2n_1+2)\\cdot|\\mathbb{G}_2|$ CT = $(2U+2)\\cdot|\\mathbb{G}_1| + 1\\cdot|\\mathbb{G}_T|$ Pairings: $2(k+1) = 4$ — constant in the number of satisfying attributes.","heading":"Sizes summary (SXDH / $k=1$)"}],"status":"solver_verified","subtitle":"KP-ABE · 2015","summary":"KP-ABE dual of CGW15 CP-ABE. First adaptive KP-ABE from static k-Lin in prime-order groups via predicate encodings. Fixed 2(k+1) pairings.","title":"Chen–Gay–Wee KP-ABE","type":"construction","venue":"Eurocrypt 2015","year":2015,"sourcePath":"data/abe-catalog.json#cgw15_kpabe"},{"evidence":"solver_verified","id":"abgw17_cpabe","keywords":["cp-abe","pairing","monotone_LSSS","GGM"],"metadata":{"assumption":{"bound":"O(t^4 / p)","family":"GGM","name":"Generic bilinear group"},"authors":["Miguel Ambrona","Gilles Barthe","Romain Gay","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"alpha * s","group":"G_T","name":"Ctilde","note":"Message blinder; target of decryption."},{"expr":"s","group":"G_1","name":"Cs","note":"Scalar CT randomness component."},{"expr":"s * (w + M1*u0 + M*u)","group":"G_1","name":"c","note":"Vector CT component — one G_1 element per LSSS row.","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0 (no reconstruction vector c exists)","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","correctness_witness":{"component_per_row":{"c_1":"s*(w_1 + u0)","c_2":"s*(w_2 + u0)","k2_1":"r*w_1","k2_2":"r*w_2"},"formula":"Cs*k3 - w_rec_1*(c_1*k1 - Cs*k2_1) - w_rec_2*(c_2*k1 - Cs*k2_2)","lsss":{"K":0,"M":"[]","M1":"[1, 1]","N":2},"w_rec":"[1, 0]","x":"[1, 1]"},"predicate":"x satisfies LSSS(M1 | M): (1,0,...,0) in rowspan({M_i : x_i=1})","reconstruction":"Choose {w_i}_{i in I} with sum_i w_i * (M1_i, M_i) = (1, 0, ..., 0), I = {i : x_i=1}.\nalpha*s = e(Cs, k3) - sum_i w_i * e(c_i, k1) - sum_i w_i * e(Cs, k2_i)  (schematic; see §5).\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N,K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"r","group":"G_2","name":"k1"},{"expr":"r * diag(x) * w","group":"G_2","name":"k2","note":"Attribute-gated: entry i is r*w_i when x_i=1, else 0.","shape":"Zp^N"},{"expr":"r*u0 + alpha","group":"G_2","name":"k3","note":"Master-key-bound head."}],"tactics":["go.","add_equation (eCsk2^T*diag(x)*M1 - 1) + eCsk2^T*diag(x)*(M1+M*c) = 0.","go.","contradiction."],"target":"alpha * s","variables":{"common":["w","u0"],"ct_randomness":["s","u"],"master":["alpha"],"shapes":{"u":"Zp^K","w":"Zp^N"},"sk_randomness":["r"]}},"construction_one_liner":"Large-universe adaptive CP-ABE with automated GGM proof via a Master Theorem; the direct basis of ggm-symbolic-solver. Rational 1/b encoding in SK quarantines Type I self-pairings, making the scheme Type I-safe.\n","decrypt_pairings":"I","id":"abgw17_cpabe","implementations":["Charm","ggm-symbolic-solver"],"name":"Ambrona–Barthe–Gay–Wee CP-ABE (GGM framework)","ontology":{"assumption_deps":{"assumption_GGM":["enc_rational_1_over_b","proof_GGM_symbolic_PES"]},"atoms":["attr_universe_polynomial_BB","policy_LSSS_monotone","lsss_one_use","enc_rational_1_over_b","master_alpha_scalar_SK_rational","proof_GGM_symbolic_PES"],"connections":[{"from":"policy_LSSS_monotone.monotone_lsss","note":"raw LSSS gets one-use decoration","to":"lsss_one_use.lsss_in"},{"from":"lsss_one_use.lsss_one_use_out","note":"per-LSSS-row c_j = s·(w_j + M1_j·u0 + (M·u)_j); 3 G_1 elts per row","to":"enc_rational_1_over_b.policy_in"}],"features_provided":{"feature_adaptive_security":"proof_GGM_symbolic_PES"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2017/983","sections_cited":["§4 ABE framework in GGM","§5 CP-ABE instantiation","ggm-symbolic-solver examples/cp_abe.ggm"],"url":"https://eprint.iacr.org/2017/983","venue":"CCS 2017","year":2017},"pareto_notes":"On asymptotics matches RW13 (CT = 3n_1 G_1) but with adaptive (not selective) GGM security instead of q-type. Superseded on SK size by FAME (fixed 3 G_2 vs. m+2) and on everything by FABEO.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"adaptive","model":"GGM","notion":"CPA"},"sizes":{"CT":{"G1":"3*n1","GT":"1","note":"3 G_1 elements per LSSS row. Uses W^lambda_i v^t_i, (u^rho(i) h)^-t_i, g^t_i structure."},"MPK":{"G1":"O(1)","note":"Constant number of G_1 elements + 1 G_T. No per-attribute public material (uses rational 1/b encoding instead)."},"SK":{"G2":"m+2","note":"Uses rational encoding x_i * r / b_i per attribute plus (a-r) head. All in G_2."},"abstraction_note":"The paper's concrete scheme has 3 G_1 elements per LSSS row (a\nW^lambda_i v^t_i, (u^rho(i) h)^-t_i, g^t_i triple) and stores SK\nentries only for attributes in S (hence m+2). The PES construction\nblock below collapses these to one vector `c` of size N = n_1 and\na vector `k2` of size N (with x-gating that zeros out non-S entries),\nso the construction-block count differs from the paper sizes.\n","sources":["ABGW17 §5 CP-ABE scheme","FABEO Table 5 (Riepel–Wee CCS 2022) for the comparison row","verifiers/ggm-symbolic-solver/examples/cp_abe.ggm (used to verify in this repo)"]},"superseded_by":["fabeo_cpabe"],"variables":{"I":"rows used in reconstruction","m":"|S|, attribute set size in SK","n1":"LSSS matrix rows"},"verification":{"ggm_file":"tests/golden/abgw17_cpabe.ggm","reference_ggm":"verifiers/ggm-symbolic-solver/examples/cp_abe.ggm","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2017/983","sections":[{"content":"ABGW17 is the scheme our ggm-symbolic-solver verifier is built around. The construction echoes RW13 (universe encoder $(u^\\tau h)$, per-row $(W^{\\lambda_i}, (u^\\tau h)^{t_i}, g^{t_i})$ structure) but the secret key uses a rational encoding with $1/b_i$ terms: each attribute contributes $x_i\\cdot r/b_i$ in the exponent rather than $r\\cdot b_i$. This $1/b$ structure is what makes the scheme provably Type-I-safe (see type_i_vs_type_iii.md): self-pairings of SK with SK have total $b$-degree $-2$ and cannot cancel with the $b$-free target $e(g_1,g_2)^{\\alpha s}$. The whole scheme's adaptive security is derived automatically via the ABGW Master Theorem + Gröbner-basis reduction in the solver.","heading":"Intuition"},{"content":"The cp_abe.ggm file in the solver's examples encodes the CP-ABE as: $$\\underbrace{c_1\\cdot\\tfrac{x_1 r}{b_1}\\cdot(m_1 s + m_3^\\top u)b_1}_{\\text{row 1 key}\\times\\text{row 1 ct}} + \\cdots + \\underbrace{c_9\\cdot(a-r)\\cdot s}_{\\text{head pairing}} \\stackrel{?}{=} \\alpha s$$ under the LSSS-not-satisfied constraints $x_i\\cdot(m_i + \\cdots\\cdot z) = 0$. The solver decides (symbolically) whether non-trivial coefficients $c_j$ exist that zero out the equation for *all* LSSS-violating attribute sets. ABGW's Master Theorem lifts symbolic security to computational GGM security with bound $O(t^4/p)$ where $t$ is the total number of group operations.","heading":"Construction (schematic)"},{"content":"MPK = $O(1)$ (generators $g_1, g_2$, attribute-universe encoder $(u, h)$, blinder base, $e(g_1,g_2)^\\alpha$). SK for attribute set $S$ = $(m+2)\\cdot|\\mathbb{G}_2|$, where the extra 2 are the head element $(a-r)$ and a random mask. No $\\mathbb{G}_1$ pieces in SK. CT for LSSS $(\\mathbf{M},\\rho)$ = $3n_1\\cdot|\\mathbb{G}_1|$, three elements per row. No $\\mathbb{G}_2$ pieces in CT. Decryption = $I$ pairings (each satisfying row contributes one pairing, plus some accounting).","heading":"Sizes"}],"status":"solver_verified","subtitle":"CP-ABE · 2017","summary":"Large-universe adaptive CP-ABE with automated GGM proof via a Master Theorem; the direct basis of ggm-symbolic-solver. Rational 1/b encoding in SK quarantines Type I self-pairings, making the scheme Type I-safe.","title":"Ambrona–Barthe–Gay–Wee CP-ABE (GGM framework)","type":"construction","venue":"CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#abgw17_cpabe"},{"evidence":"solver_verified","id":"abgw17_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","GGM"],"metadata":{"assumption":{"family":"GGM","name":"Generic bilinear group"},"authors":["Miguel Ambrona","Gilles Barthe","Romain Gay","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"alpha * s","group":"G_T","name":"Ctilde"},{"expr":"s","group":"G_1","name":"Cs"},{"expr":"s * diag(x) * w","group":"G_1","name":"c","note":"Attribute-gated vector; entry i is s*w_i when x_i=1.","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0 (no reconstruction vector c exists)","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"Choose {w_i}_{i in I} with sum_i w_i * (M1_i, M_i) = (1, 0, ..., 0), I = {i : x_i=1}.\nalpha*s = sum_i w_i * e(Cs * x_i, k_i) - e(c_i, kr)   (schematic; see §5 of ABGW paper).\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N,K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"r*(w + M*u) + M1*alpha","group":"G_2","name":"k","note":"Policy-carrying SK vector; each entry mixes common param, sharing rand, and master.","shape":"Zp^N"},{"expr":"r","group":"G_2","name":"kr"}],"tactics":["go.","add_equation (eckr^T*diag(x)*M1 + 1) + eckr^T*diag(x)*(M1+M*c) = 0.","go.","contradiction."],"target":"alpha * s","variables":{"common":["w"],"ct_randomness":["s"],"master":["alpha"],"shapes":{"u":"Zp^K","w":"Zp^N"},"sk_randomness":["r","u"]}},"construction_one_liner":"KP-ABE dual of ABGW17 CP-ABE: large-universe adaptive KP-ABE with automated GGM proof via the Master Theorem. Rational 1/b encoding makes it Type-I-safe.\n","decrypt_pairings":"I","id":"abgw17_kpabe","implementations":["ggm-symbolic-solver"],"name":"Ambrona–Barthe–Gay–Wee KP-ABE (GGM framework)","ontology":{"assumption_deps":{"assumption_GGM":["enc_rational_1_over_b","attr_universe_polynomial_BB","proof_GGM_symbolic_PES"]},"atoms":["attr_universe_polynomial_BB","policy_LSSS_monotone","lsss_one_use","enc_rational_1_over_b","master_alpha_scalar_SK_rational","proof_GGM_symbolic_PES"],"connections":[{"from":"policy_LSSS_monotone.monotone_lsss","note":"raw LSSS gets one-use decoration","to":"lsss_one_use.lsss_in"},{"from":"lsss_one_use.lsss_one_use_out","note":"policy reaches the rational encoder; KP-ABE direction (LSSS lives in SK)","to":"enc_rational_1_over_b.policy_in"}],"features_provided":{"feature_adaptive_security":"proof_GGM_symbolic_PES","feature_large_universe":"attr_universe_polynomial_BB"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2017/983","sections_cited":["§4 ABE framework in GGM","§5 KP-ABE instantiation","ggm-symbolic-solver examples/kp_abe.ggm"],"url":"https://eprint.iacr.org/2017/983","venue":"CCS 2017","year":2017},"pareto_notes":"Tighter sizes than FAME (2n_1 G_2 SK vs FAME's 3n_1 G_1 + 3 G_2) at GGM cost. Superseded on all axes by FABEO.\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"GGM","notion":"CPA"},"sizes":{"CT":{"G1":"2*m","GT":"1","note":"2 elements per CT attribute in G_1, plus 1 G_T for message blinder."},"MPK":{"G1":"O(1)","note":"Constant; same universe-encoder approach as RW13."},"SK":{"G2":"2*n1","note":"2 elements per LSSS row in G_2."},"abstraction_note":"Declared sizes are from the paper (2 elements per LSSS row, 2 per\nCT attribute). The PES construction block below collapses per-row\nentries into a single vector `k` of size N, so counted sizes will\ndiffer from declared sizes.\n","sources":["ABGW17 §5 KP-ABE scheme","FABEO Table 5 for the comparison row","verifiers/ggm-symbolic-solver/examples/kp_abe.ggm"]},"superseded_by":["fabeo_kpabe"],"variables":{"I":"rows used at decryption","m":"|S|, attribute set size in CT","n1":"LSSS matrix rows"},"verification":{"ggm_file":"tests/golden/abgw17_kpabe.ggm","reference_ggm":"verifiers/ggm-symbolic-solver/examples/kp_abe.ggm","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2017/983","sections":[{"content":"KP-ABE dual of abgw17_cpabe.md. Same automated-GGM-proof framework, same rational $1/b$ encoding in the SK that makes the scheme Type-I-safe. The construction is verified in this repo at verifiers/ggm-symbolic-solver/examples/kp_abe.ggm.","heading":"Intuition"},{"content":"MPK = $O(1)\\cdot|\\mathbb{G}_1|$ + 1 $|\\mathbb{G}_T|$ SK = $2n_1\\cdot|\\mathbb{G}_2|$ CT = $2m\\cdot|\\mathbb{G}_1| + 1\\cdot|\\mathbb{G}_T|$ Pairings: $I$ (linear in satisfying rows).","heading":"Sizes summary"}],"status":"solver_verified","subtitle":"KP-ABE · 2017","summary":"KP-ABE dual of ABGW17 CP-ABE: large-universe adaptive KP-ABE with automated GGM proof via the Master Theorem. Rational 1/b encoding makes it Type-I-safe.","title":"Ambrona–Barthe–Gay–Wee KP-ABE (GGM framework)","type":"construction","venue":"CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#abgw17_kpabe"},{"evidence":"solver_verified","id":"fame_cpabe","keywords":["cp-abe","pairing","monotone_LSSS","standard"],"metadata":{"assumption":{"family":"standard","name":"Decisional Linear (DLIN, Type III)"},"authors":["Shashank Agrawal","Melissa Chase"],"construction":{"ciphertext_encoding":[{"expr":"alpha1 * a1 * s + alpha2 * a2 * s + alpha3 * s","group":"G_T","name":"Ctilde"},{"expr":"a1 * s","group":"G_2","name":"ct01"},{"expr":"a2 * s","group":"G_2","name":"ct02"},{"expr":"s","group":"G_2","name":"ct03"},{"expr":"M1 * v1 * s + w1 * a1 * s","group":"G_1","name":"cta1","shape":"Zp^N"},{"expr":"M1 * v2 * s + w2 * a2 * s","group":"G_1","name":"cta2","shape":"Zp^N"},{"expr":"M1 * v3 * s + w3 * s","group":"G_1","name":"cta3","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0 (LSSS not satisfied)","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"3-way unrolling of FAME's 6-pairing decryption at K=3: pair\nct01..ct03 with skp1..skp3 to extract alpha terms; combine\ncta1..cta3 with sk01..sk03 using reconstruction coefficients.\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"b1 * r","group":"G_2","name":"sk01"},{"expr":"b2 * r","group":"G_2","name":"sk02"},{"expr":"r","group":"G_2","name":"sk03"},{"expr":"alpha1 + r * t1","group":"G_1","name":"skp1"},{"expr":"alpha2 + r * t2","group":"G_1","name":"skp2"},{"expr":"alpha3 + r * t3","group":"G_1","name":"skp3"},{"expr":"r * diag(x) * w1","group":"G_1","name":"sky1","shape":"Zp^N"},{"expr":"r * diag(x) * w2","group":"G_1","name":"sky2","shape":"Zp^N"},{"expr":"r * diag(x) * w3","group":"G_1","name":"sky3","shape":"Zp^N"}],"target":"alpha1 * a1 * s + alpha2 * a2 * s + alpha3 * s","variables":{"common":["a1","a2","b1","b2","t1","t2","t3","v1","v2","v3","w1","w2","w3"],"ct_randomness":["s"],"master":["alpha1","alpha2","alpha3"],"shapes":{"w1":"Zp^N","w2":"Zp^N","w3":"Zp^N"},"sk_randomness":["r"]}},"construction_one_liner":"First fast, adaptive, unbounded CP-ABE from a standard (DLIN) assumption with a fixed 6-pairing decryption. Became the Charm-framework baseline. Tradeoff: each key/CT row spends 3 G_1 elements to support the DLIN proof.\n","decrypt_pairings":"6","id":"fame_cpabe","implementations":["Charm","OpenABE","RELIC"],"name":"FAME CP-ABE (Agrawal–Chase)","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2017/807","sections_cited":["§3 Figure 3.1 CP-ABE construction","§3 one-use footnote","Theorem 4.1 security"],"url":"https://eprint.iacr.org/2017/807","venue":"CCS 2017","year":2017},"pareto_notes":"Superseded by FABEO on SK and CT size (factor 3 blowup, same multi-use strategy). Still attractive where a standard-assumption (non-GGM) proof matters. Does NOT have an SXDH variant: both G_1 and G_2 carry ciphertext and key pieces, breaking the SXDH asymmetry argument.\n","policy":{"ROM_required":true,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"bound":"(8Q+2) * Adv_DLIN + (16Q+6)/p","mode":"adaptive","model":"ROM","notion":"CPA"},"sizes":{"CT":{"G1":"3*n1","G2":"3","GT":"1","note":"3 ct_0 in G_2; per row 3 elements in G_1; 1 ct' in G_T."},"MPK":{"G2":"3","GT":"2","note":"h, H_1, H_2 in G_2; T_1, T_2 in G_T. Hash H in ROM, not counted."},"MSK":{"G1":"6","G2":"1","Zp":"4","note":"(g, h, a_1, a_2, b_1, b_2, g^d_1, g^d_2, g^d_3)"},"SK":{"G1":"3*m+3","G2":"3","note":"3 sk_0 in G_2; per attribute 3 elements in G_1 (sk_{y,1}, sk_{y,2}, g^{-sigma_y}); 3 sk' in G_1. Multi-use tau_hat duplicates attribute labels: (3*tau_hat*m+3) |G_1|."},"sources":["FAME (Agrawal–Chase CCS 2017) Figure 3.1 construction","FAME Fig 5.4 (decryption pairings)"]},"superseded_by":["fabeo_cpabe"],"variables":{"I":"rows used in reconstruction","K":"LSSS extra columns (= n_2 - 1 in paper)","N":"LSSS matrix rows (small-universe one-use pilot: N = U)","m":"|S|, attribute set size in SK","tau_hat":"multi-use bound (set to 1 in pilot)"},"verification":{"ggm_file":null,"note":"Verified end-to-end (M1 confirmed 2026-04-23) at k=2 (DLIN, K=3\nconcretized). FAME does not have an SXDH variant (k=1 breaks the\nproof), so the pilot uses k=2, unrolling each paper-level 3-vector\ninto 3 scalar entries. Simplifications: ROM hash dropped (small-\nuniverse one-use instead), tau_hat = 1, randomness s_1,s_2\ncollapsed to a single s where possible. Preserves FAME's distinctive\n3-way G_1/G_2 DLIN structure. Solver returns \"no remaining goals\".\n","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2017/807","sections":[{"content":"FAME replaces composite-order groups and $q$-type assumptions with a direct prime-order construction under standard DLIN (3-party linear) assumption. The core trick is a $3\\times 3$ \"matrix-in-the-exponent\" structure in both $\\mathbb{G}_1$ and $\\mathbb{G}_2$, so that every ciphertext component has 3 $\\mathbb{G}_1$ pieces tied to the 3-dimensional DLIN vector and every key component has 3 $\\mathbb{G}_2$ pieces. Decryption compresses into exactly 6 pairings, independent of the satisfying set size. Large-universe via a hash $H:\\{0,1\\}^*\\to\\mathbb{G}_1$ modeled as a random oracle.","heading":"Intuition"},{"content":"Sample $a_1, a_2 \\leftarrow_R \\mathbb{Z}_p^*$, $d_1, d_2, d_3 \\leftarrow_R \\mathbb{Z}_p$, $b_1, b_2 \\leftarrow_R \\mathbb{Z}_p^*$. $$\\mathrm{MPK} = \\big(h,\\ H_1 = h^{a_1},\\ H_2 = h^{a_2},\\ T_1 = e(g,h)^{d_1 a_1 + d_3},\\ T_2 = e(g,h)^{d_2 a_2 + d_3}\\big)$$ $$\\mathrm{MSK} = (g,\\ h,\\ a_1, a_2, b_1, b_2,\\ g^{d_1},\\ g^{d_2},\\ g^{d_3})$$ (paper uses $g\\in\\mathbb{G}_1, h\\in\\mathbb{G}_2$, consistent with Type III asymmetric groups)","heading":"Setup"},{"content":"Input: attribute set $S$. Sample $r_1, r_2 \\leftarrow_R \\mathbb{Z}_p$; $\\sigma_y \\leftarrow_R \\mathbb{Z}_p$ per $y\\in S$; $\\sigma' \\leftarrow_R \\mathbb{Z}_p$. $$\\mathrm{sk}_0 = \\big(h^{b_1 r_1},\\ h^{b_2 r_2},\\ h^{r_1+r_2}\\big)\\in\\mathbb{G}_2^3$$ For each $y\\in S$ and $t\\in\\{1,2\\}$: $$\\mathrm{sk}_{y,t} = H(y\\|1\\|t)^{b_1 r_1/a_t}\\cdot H(y\\|2\\|t)^{b_2 r_2/a_t}\\cdot H(y\\|3\\|t)^{(r_1+r_2)/a_t}\\cdot g^{\\sigma_y/a_t}$$ $$\\mathrm{sk}_y = (\\mathrm{sk}_{y,1},\\mathrm{sk}_{y,2},\\ g^{-\\sigma_y})\\in\\mathbb{G}_1^3$$ And the \"row-0\" key $\\mathrm{sk}'\\in\\mathbb{G}_1^3$ analogously using the label \"0\" and adding $g^{d_t}$ / $g^{d_3}$. $\\mathrm{SK} = (\\mathrm{sk}_0, \\{\\mathrm{sk}_y\\}_{y\\in S}, \\mathrm{sk}')$.","heading":"KeyGen"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$, $\\mathbf{M}\\in\\mathbb{Z}_p^{n_1\\times n_2}$, message $m$. Sample $s_1, s_2\\leftarrow_R\\mathbb{Z}_p$. $$\\mathrm{ct}_0 = \\big(H_1^{s_1},\\ H_2^{s_2},\\ h^{s_1+s_2}\\big)\\in\\mathbb{G}_2^3,\\quad \\mathrm{ct}' = T_1^{s_1}\\cdot T_2^{s_2}\\cdot m\\in\\mathbb{G}_T$$ For each row $i\\in[n_1]$ and $\\ell\\in\\{1,2,3\\}$: $$\\mathrm{ct}_{i,\\ell} = H(\\rho(i)\\|\\ell\\|1)^{s_1}\\cdot H(\\rho(i)\\|\\ell\\|2)^{s_2}\\cdot\\prod_{j=1}^{n_2}\\big[H(0\\|j\\|\\ell\\|1)^{s_1}\\cdot H(0\\|j\\|\\ell\\|2)^{s_2}\\big]^{M_{i,j}}$$","heading":"Encrypt"},{"content":"With $\\{\\gamma_i\\}$ such that $\\sum\\gamma_i \\mathbf{M}_i = (1,0,\\ldots,0)$: $$\\text{num} = \\mathrm{ct}'\\cdot\\prod_{\\ell=1}^{3}e\\big(\\prod_i\\mathrm{ct}_{i,\\ell}^{\\gamma_i},\\ \\mathrm{sk}_{0,\\ell}\\big)\\qquad(3\\text{ pairings})$$ $$\\text{den} = \\prod_{\\ell=1}^{3}e\\big(\\mathrm{sk}'_\\ell\\cdot\\prod_i\\mathrm{sk}_{\\rho(i),\\ell}^{\\gamma_i},\\ \\mathrm{ct}_{0,\\ell}\\big)\\qquad(3\\text{ pairings})$$ Output $m = \\text{num}/\\text{den}$. Exactly 6 pairings, independent of $|I|$.","heading":"Decrypt"}],"status":"solver_verified","subtitle":"CP-ABE · 2017","summary":"First fast, adaptive, unbounded CP-ABE from a standard (DLIN) assumption with a fixed 6-pairing decryption. Became the Charm-framework baseline. Tradeoff: each key/CT row spends 3 G_1 elements to support the DLIN proof.","title":"FAME CP-ABE (Agrawal–Chase)","type":"construction","venue":"CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#fame_cpabe"},{"evidence":"solver_verified","id":"fame_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","standard"],"metadata":{"assumption":{"family":"standard","name":"Decisional Linear (DLIN, Type III)"},"authors":["Shashank Agrawal","Melissa Chase"],"construction":{"ciphertext_encoding":[{"expr":"alpha1 * a1 * s + alpha2 * a2 * s + alpha3 * s","group":"G_T","name":"Ctilde"},{"expr":"a1 * s","group":"G_2","name":"ct01"},{"expr":"a2 * s","group":"G_2","name":"ct02"},{"expr":"s","group":"G_2","name":"ct03"},{"expr":"diag(x) * w1 * s","group":"G_1","name":"cx1","shape":"Zp^N"},{"expr":"diag(x) * w2 * s","group":"G_1","name":"cx2","shape":"Zp^N"},{"expr":"diag(x) * w3 * s","group":"G_1","name":"cx3","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"KP dual of FAME CP at K=3: 3-way pairing combinations.\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"b1 * r","group":"G_2","name":"sk01"},{"expr":"b2 * r","group":"G_2","name":"sk02"},{"expr":"r","group":"G_2","name":"sk03"},{"expr":"M1 * alpha1 + M * u1 + w1 * r * t1","group":"G_1","name":"sks1","shape":"Zp^N"},{"expr":"M1 * alpha2 + M * u2 + w2 * r * t2","group":"G_1","name":"sks2","shape":"Zp^N"},{"expr":"M1 * alpha3 + M * u3 + w3 * r * t3","group":"G_1","name":"sks3","shape":"Zp^N"}],"target":"alpha1 * a1 * s + alpha2 * a2 * s + alpha3 * s","variables":{"common":["a1","a2","b1","b2","t1","t2","t3","v1","v2","v3","w1","w2","w3"],"ct_randomness":["s"],"master":["alpha1","alpha2","alpha3"],"shapes":{"u1":"Zp^K","u2":"Zp^K","u3":"Zp^K","w1":"Zp^N","w2":"Zp^N","w3":"Zp^N"},"sk_randomness":["r","u1","u2","u3"]}},"construction_one_liner":"KP-ABE dual of FAME CP-ABE. Adaptive DLIN security with fixed 6-pairing decryption. Large-universe via ROM-modeled hash. Sizes transpose from the CP-ABE variant.\n","decrypt_pairings":"6","id":"fame_kpabe","implementations":["Charm","OpenABE"],"name":"FAME KP-ABE (Agrawal–Chase)","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2017/807","sections_cited":["§4 KP-ABE construction","Fig 5.5 size comparison"],"url":"https://eprint.iacr.org/2017/807","venue":"CCS 2017","year":2017},"pareto_notes":"Superseded by FABEO on size (factor 3 blowup); still the preferred standard-assumption adaptive KP-ABE. No SXDH variant possible.\n","policy":{"ROM_required":true,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"ROM","notion":"CPA"},"sizes":{"CT":{"G1":"3*m","G2":"3","GT":"1","note":"3 elements per attribute in G_1, plus 3 ct_0 in G_2, plus 1 GT. Dual of CP-ABE SK."},"MPK":{"G2":"3","GT":"2","note":"Same MPK structure as FAME CP-ABE."},"SK":{"G1":"3*n1","G2":"3","note":"3 elements per LSSS row in G_1, plus 3 sk_0 in G_2. Dual of CP-ABE CT."},"sources":["FAME §4 KP-ABE construction","FAME Fig 5.5 size table"]},"superseded_by":["fabeo_kpabe"],"variables":{"I":"rows used at decryption","K":"LSSS extra cols (= n_2 - 1)","N":"LSSS matrix rows (policy size in SK); one-use: N = U","m":"|S|, attribute set size in CT"},"verification":{"ggm_file":null,"note":"Verified end-to-end (M1 confirmed 2026-04-23) at k=2 (DLIN, K=3).\nKP dual of FAME CP pilot. Preserves FAME's 3-way asymmetric DLIN\nstructure. Solver returns \"no remaining goals\".\n","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2017/807","sections":[{"content":"KP-ABE dual of fame_cpabe.md. Same 3-dimensional DLIN structure yielding a fixed 6-pairing decryption. The ciphertext attributes now get 3 $\\mathbb{G}_1$ elements each, and the LSSS rows in the key get 3 $\\mathbb{G}_1$ elements each — roles transposed from the CP-ABE.","heading":"Intuition"},{"content":"MPK = $3\\cdot|\\mathbb{G}_2| + 2\\cdot|\\mathbb{G}_T|$ SK = $3n_1\\cdot|\\mathbb{G}_1| + 3\\cdot|\\mathbb{G}_2|$ CT = $3m\\cdot|\\mathbb{G}_1| + 3\\cdot|\\mathbb{G}_2| + 1\\cdot|\\mathbb{G}_T|$ Pairings: 6, fixed, independent of $|I|$.","heading":"Sizes summary"}],"status":"solver_verified","subtitle":"KP-ABE · 2017","summary":"KP-ABE dual of FAME CP-ABE. Adaptive DLIN security with fixed 6-pairing decryption. Large-universe via ROM-modeled hash. Sizes transpose from the CP-ABE variant.","title":"FAME KP-ABE (Agrawal–Chase)","type":"construction","venue":"CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#fame_kpabe"},{"evidence":"solver_verified","id":"cgkw18","keywords":["kp-abe","pairing","monotone_LSSS","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k)"},"authors":["Jie Chen","Junqing Gong","Lucas Kowalczyk","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"v1 * A1 * s + v2 * A2 * s","group":"G_T","name":"Ctilde"},{"expr":"s","group":"G_1","name":"Cs"},{"expr":"diag(x) * w1 * s","group":"G_1","name":"cx1","shape":"Zp^N"},{"expr":"diag(x) * w2 * s","group":"G_1","name":"cx2","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"CGKW18 pilot — same decryption pattern as CGW15 KP.\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"r","group":"G_2","name":"skr"},{"expr":"M1 * v1 + M * u1 + w1 * r * A1","group":"G_2","name":"skshare1","shape":"Zp^N"},{"expr":"M1 * v2 + M * u2 + w2 * r * A2","group":"G_2","name":"skshare2","shape":"Zp^N"}],"target":"v1 * A1 * s + v2 * A2 * s","variables":{"common":["A1","A2","w1","w2"],"ct_randomness":["s"],"master":["v1","v2"],"shapes":{"u1":"Zp^K","u2":"Zp^K","w1":"Zp^N","w2":"Zp^N"},"sk_randomness":["r","u1","u2"]}},"construction_one_liner":"First adaptive unbounded KP-ABE from standard k-Lin in Type-III prime- order groups. Bilinear entropy expansion lemma shrinks vector height from 3k (OT12) to 2k+1, improving all follow-up unbounded schemes.\n","decrypt_pairings":"(2*k+1)*I","id":"cgkw18","name":"Chen–Gong–Kowalczyk–Wee Unbounded KP-ABE","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2018/116","sections_cited":["§4 prime-order unbounded KP-ABE","bilinear entropy expansion lemma"],"url":"https://eprint.iacr.org/2018/116","venue":"Eurocrypt 2018","year":2018},"pareto_notes":"Strictly dominates LW11 (composite-order, selective) and OT12 (prime- order 3k-Lin adaptive). Superseded on SK size by FABEO under GGM. The current reference point for \"unbounded + adaptive + standard\".\n","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"(2*k+1)*m+k","GT":"1","note":"Per CT attribute: 2k+1 elements in G_1, plus k-size header and GT mask. At SXDH: 3m+1 G_1 plus GT."},"MPK":{"G1":"O(1)","note":"O(k^2) scalar-level but constant in universe / policy size. The headline claim is O(1) MPK for an unbounded scheme."},"SK":{"G2":"(5*k+3)*n1","note":"Per row: 2k+1 + k+1 + 2k+1 = 5k+3 elements in G_2. At k=1 (SXDH): 8*n_1."},"sources":["CGKW18 §4 prime-order KP-ABE construction"]},"superseded_by":["fabeo_kpabe"],"variables":{"I":"rows used at decryption","k":"k-Lin parameter; k=1 for SXDH","m":"|S|, attribute set size in CT","n1":"LSSS matrix rows"},"verification":{"ggm_file":null,"note":"Verified end-to-end (M1 confirmed 2026-04-23) at k=1 (K=2). CGKW18\nis the unbounded version of CGW15 KP (bilinear entropy expansion\nshrinks vector height from 3k to 2k+1). Pilot is structurally the\nCGW15 KP pilot adapted to CGKW18's shared-vector structure; the\nunbounded-universe aspect is collapsed to one-use for tractability.\nSolver returns \"no remaining goals\". See\ndocs/matrix_pes_generalization.md §6.\n","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2018/116","sections":[{"content":"CGKW18 achieves the \"holy grail\" combination of unbounded (O(1) MPK, no a-priori attribute universe) + adaptive security + standard static $k$-Lin assumption + prime-order Type III groups. Previous unbounded ABE was either composite-order (LW11), selective (LW11's main KP-ABE), or paid a factor of 3 in vector height (OT12's prime-order unbounded). The central technical tool is the bilinear entropy expansion lemma: from a constant-size \"seed\" of group elements under $k$-Lin, one can pseudorandomly expand, for each attribute label $y\\in\\mathbb{Z}_p$, an independent-looking pair $(r_y, s_y)$ that behaves like fresh randomness in the dual-system proof. This bootstraps a CGW15-style *bounded* scheme into an *unbounded* one by hashing each attribute into entropy-expanded slots on the fly. The lemma is tightened vs. LW14/OT12's composite-order predecessor so the per-row vector height shrinks from $3k$ to $2k+1$.","heading":"Intuition"},{"content":"Type III bilinear group $(\\mathbb{G}_1, \\mathbb{G}_2, \\mathbb{G}_T, e)$, $k$-Lin distribution $D_k$. Setup: sample small matrices $A_1\\in\\mathbb{Z}_p^{(2k+1)\\times k}$ (reduced from $3k$), seed matrix $B$ (height $k+1$), a master secret $\\mathbf{k}\\in\\mathbb{Z}_p^{2k+1}$. Publish $\\mathrm{MPK} = ([A_1]_1, [A_1 W_j]_1\\text{ for $O(1)$ fixed } W_j, [B\\cdots]_1, [\\mathbf{k}A_1]_T)$. KeyGen($(\\mathbf{M},\\rho)$): for each LSSS row, produce $5k+3$ $\\mathbb{G}_2$ elements tying the row's label $\\rho(i)\\in\\mathbb{Z}_p$ to its expanded entropy $s_{\\rho(i)}$ derived from MSK. Encrypt($S, M$): for each attribute $y\\in S$ build a ciphertext slot $[c_y]_1$ of $2k+1$ $\\mathbb{G}_1$ elements using entropy-expansion $[W(y)\\cdot\\mathbf{s}]_1$. Plus a header $[A_1\\mathbf{s}]_1$ and masked $M\\cdot[\\mathbf{k}A_1\\mathbf{s}]_T$. Decrypt: reconstruction coefficients $\\omega_i$ for satisfying rows; one $(2k+1)$-dim multi-pairing per row → $(2k+1)I$ scalar pairings.","heading":"Sketch (prime-order KP-ABE, §4 of CGKW18)"},{"content":"MPK: $O(1)$ — ~a dozen $\\mathbb{G}_1$ elements. SK: $8n_1$ $\\mathbb{G}_2$ elements. CT: $3m + 1$ $\\mathbb{G}_1$ elements + 1 $\\mathbb{G}_T$. Pairings: $3I$ (at $k=1$).","heading":"Sizes (SXDH, $k=1$)"}],"status":"solver_verified","subtitle":"KP-ABE · 2018","summary":"First adaptive unbounded KP-ABE from standard k-Lin in Type-III prime- order groups. Bilinear entropy expansion lemma shrinks vector height from 3k (OT12) to 2k+1, improving all follow-up unbounded schemes.","title":"Chen–Gong–Kowalczyk–Wee Unbounded KP-ABE","type":"construction","venue":"Eurocrypt 2018","year":2018,"sourcePath":"data/abe-catalog.json#cgkw18"},{"evidence":"blocked_hybrid","id":"amy19_dfa_cpabe","keywords":["cp-abe","compiler","DFA","standard","dfa","uniform-computation","unbounded-input","unbounded-machine","unbounded-key-queries"],"metadata":{"assumption":{"family":"standard","name":"DLIN"},"authors":["Shweta Agrawal","Monosij Maitra","Shota Yamada"],"capabilities":["dfa","uniform-computation","unbounded-input","unbounded-machine","unbounded-key-queries"],"comparison":{"pareto_eligible":false,"reason":"The source reports compiler-level asymptotics rather than normalized group-element and pairing counts."},"construction":{"note":"CP orientation of the DFA compiler, obtained by swapping the underlying unbounded KP-ABE and CP-ABE components.","schema":"other","schema_version":1},"construction_family":"compiler","construction_one_liner":"Ciphertext-policy counterpart of the DLIN DFA compiler, supporting unbounded machines, inputs, and key requests by swapping its two MSP-ABE components.\n","decrypt_cost":{"note":"The CP orientation is obtained by swapping the two underlying ABE roles; the source does not present a single normalized pairing count.","primary":"composed MSP reconstruction"},"decrypt_pairings":"not normalized","id":"amy19_dfa_cpabe","name":"Agrawal–Maitra–Yamada CP-ABE for DFA","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2019/645","sections_cited":["Table 1","§1.2 techniques","§1.3 CP-ABE discussion","Theorem 7"],"url":"https://eprint.iacr.org/2019/645","venue":"IACR ePrint 2019","year":2019},"pareto_notes":"Included as a distinct construction because the policy-bearing object and size axes are reversed; it should not be silently merged with the KP row.","policy":{"ROM_required":false,"class":"DFA","large_universe":true,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA","qualifier":"The paper obtains CP-ABE by symmetrically swapping the underlying KP and CP components."},"sizes":{"CT":{"asymptotic":"O(|Q|² · poly(λ))","note":"Ciphertext carrying the DFA policy in the swapped compiler."},"MPK":{"asymptotic":"poly(λ)","note":"Independent of input length and DFA size through unbounded MSP components."},"SK":{"asymptotic":"O(|x|³ · poly(λ))","note":"Attribute key for an unbounded input string in the swapped compiler."},"sources":["AMY19 §1.2–§1.4 and the symmetric CP compiler"]},"variables":{"lam":"security parameter","|Q|":"number of DFA states","|x|":"input-string length"},"verification":{"blocker":"composed_msp_compiler","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2019/645","sections":[{"content":"The CP construction uses the same DFA-to-MSP decomposition as the KP scheme but swaps the roles of the two unbounded ABE components, moving the automaton policy into the ciphertext.","heading":"Intuition"},{"content":"Setup initializes both unbounded MSP-ABE building blocks with no bound on input length or machine size.","heading":"Setup"},{"content":"The user input string is converted into the attribute-side MSP encodings used by the swapped compiler.","heading":"KeyGen"},{"content":"The encryptor converts the DFA policy into the two complementary MSP relations and encrypts the message under their composition.","heading":"Encrypt"},{"content":"The composed reconstruction succeeds exactly when the DFA in the ciphertext accepts the string associated with the secret key.","heading":"Decrypt"}],"status":"blocked_hybrid","subtitle":"CP-ABE · 2019","summary":"Ciphertext-policy counterpart of the DLIN DFA compiler, supporting unbounded machines, inputs, and key requests by swapping its two MSP-ABE components.","title":"Agrawal–Maitra–Yamada CP-ABE for DFA","type":"construction","venue":"IACR ePrint 2019","year":2019,"sourcePath":"data/abe-catalog.json#amy19_dfa_cpabe"},{"evidence":"blocked_hybrid","id":"amy19_dfa_kpabe","keywords":["kp-abe","compiler","DFA","standard","dfa","uniform-computation","unbounded-input","unbounded-machine","unbounded-key-queries"],"metadata":{"assumption":{"family":"standard","name":"DLIN"},"authors":["Shweta Agrawal","Monosij Maitra","Shota Yamada"],"capabilities":["dfa","uniform-computation","unbounded-input","unbounded-machine","unbounded-key-queries"],"comparison":{"pareto_eligible":false,"reason":"The source reports compiler-level asymptotics rather than normalized group-element and pairing counts."},"construction":{"note":"Generic composition of modified unbounded KP-ABE and CP-ABE for MSP after embedding DFA computation into MSP relations.","schema":"other","schema_version":1},"construction_family":"compiler","construction_one_liner":"First pairing-based KP-ABE for DFA from static DLIN supporting unbounded input length, machine size, and key requests; obtained through a modular MSP compiler.\n","decrypt_cost":{"note":"The paper's headline comparison reports total key/ciphertext asymptotics rather than one normalized pairing formula.","primary":"composed MSP reconstruction"},"decrypt_pairings":"not normalized","id":"amy19_dfa_kpabe","name":"Agrawal–Maitra–Yamada KP-ABE for DFA","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2019/645","sections_cited":["Table 1","§1.2 techniques","Theorem 7","§1.4 concrete asymptotics"],"url":"https://eprint.iacr.org/2019/645","venue":"IACR ePrint 2019","year":2019},"pareto_notes":"Strong on modularity and CP/KP duality, but asymptotically less efficient than the concurrent direct DFA construction.","policy":{"ROM_required":false,"class":"DFA","large_universe":true,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA","qualifier":"The paper calls the compiler result selective-star security."},"sizes":{"CT":{"asymptotic":"O(|x|³ · poly(λ))","note":"Ciphertext for an input string x."},"MPK":{"asymptotic":"poly(λ)","note":"Independent of input length and DFA size through unbounded MSP components."},"SK":{"asymptotic":"O(|Q|² · poly(λ))","note":"Policy key for a DFA with state set Q."},"sources":["AMY19 §1.4 comparison with concurrent work"]},"variables":{"lam":"security parameter","|Q|":"number of DFA states","|x|":"input-string length"},"verification":{"blocker":"composed_msp_compiler","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2019/645","sections":[{"content":"The compiler splits DFA acceptance into two MSP-checkable relations and uses unbounded KP-ABE and CP-ABE components symmetrically. The combination accepts exactly when the machine accepts the input string.","heading":"Intuition"},{"content":"Setup initializes the two unbounded MSP-ABE components required by the DFA compiler. Their parameters do not bound input length or DFA size.","heading":"Setup"},{"content":"A DFA is converted into MSP material for the two complementary relations. The resulting key grows quadratically with the number of states in the generic construction.","heading":"KeyGen"},{"content":"An input string is encoded into the corresponding MSP attribute sets and encrypted under the two components. The generic conversion gives cubic dependence on input length.","heading":"Encrypt"},{"content":"Decryption evaluates the composed MSP relations and reconstructs the message exactly when the DFA accepts the input.","heading":"Decrypt"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2019","summary":"First pairing-based KP-ABE for DFA from static DLIN supporting unbounded input length, machine size, and key requests; obtained through a modular MSP compiler.","title":"Agrawal–Maitra–Yamada KP-ABE for DFA","type":"construction","venue":"IACR ePrint 2019","year":2019,"sourcePath":"data/abe-catalog.json#amy19_dfa_kpabe"},{"evidence":"compiler_ok_solver_stuck","id":"kw19_cpabe","keywords":["cp-abe","pairing","NC1","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k^1)"},"authors":["Lucas Kowalczyk","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"A1 * v1 * s + A2 * v2 * s","group":"G_T","name":"Ctilde"},{"expr":"A1 * s","group":"G_1","name":"ct11"},{"expr":"A2 * s","group":"G_1","name":"ct12"},{"expr":"M1 * (A1*U11 + A2*U21) * s + M * u * (A1*U11 + A2*U21) * 0 + s * (A1*W11 + A2*W21)","group":"G_1","name":"ct21","note":"First K-coord of ct_{2,j}. The M*u term zeroed (simplification) to match FABEO-style sharing.","shape":"Zp^N"},{"expr":"M1 * (A1*U12 + A2*U22) * s + s * (A1*W12 + A2*W22)","group":"G_1","name":"ct22","note":"Second K-coord of ct_{2,j}.","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0 (LSSS not satisfied)","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"Choose {w_i}_{i in I} with sum_i w_i * (M1_i, M_i) = (1, 0, ..., 0).\nRecover blinder via K-coord aggregation, matching KW19 Appendix A.1\ndecryption at K=2 unrolled: pair (ct11, sk11) and (ct12, sk12) for\nthe master-binding; use ct21/sk31 and ct22/sk32 per-row with\nreconstruction coefficients to cancel the W-mask.\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"v1 + (U11*B1 + U12*B2) * r","group":"G_2","name":"sk11"},{"expr":"v2 + (U21*B1 + U22*B2) * r","group":"G_2","name":"sk12"},{"expr":"B1 * r","group":"G_2","name":"sk21"},{"expr":"B2 * r","group":"G_2","name":"sk22"},{"expr":"r * diag(x) * (W11*B1 + W12*B2)","group":"G_2","name":"sk31","shape":"Zp^N"},{"expr":"r * diag(x) * (W21*B1 + W22*B2)","group":"G_2","name":"sk32","shape":"Zp^N"}],"target":"A1 * v1 * s + A2 * v2 * s","variables":{"common":["A1","A2","B1","B2","U11","U12","U21","U22","W11","W12","W21","W22"],"ct_randomness":["s","u"],"master":["v1","v2"],"shapes":{"W11":"Zp^N","W12":"Zp^N","W21":"Zp^N","W22":"Zp^N","u":"Zp^K"},"sk_randomness":["r"]}},"construction_one_liner":"First adaptive ABE for NC1 (monotone Boolean formulas) from static k-Lin in prime-order groups with attribute multi-use and polynomial security loss. Secret key is policy-size-independent (\"compact\").\n","decrypt_pairings":"2*I+1","id":"kw19_cpabe","name":"Kowalczyk–Wee CP-ABE for NC1","ontology":{"assumption_deps":{"assumption_k_Lin":["enc_matrix_dual_system","master_k_vector_dual_system","proof_k_Lin_reduction"]},"atoms":["attr_universe_matrix","policy_NC1_formula","policy_LSSS_monotone","lsss_one_use","enc_matrix_dual_system","master_k_vector_dual_system","subprim_piecewise_guessing","proof_dual_system_hybrid","proof_k_Lin_reduction"],"connections":[{"from":"policy_LSSS_monotone.monotone_lsss","to":"lsss_one_use.lsss_in"},{"from":"lsss_one_use.lsss_one_use_out","to":"enc_matrix_dual_system.policy_in"}],"features_provided":{"feature_adaptive_security":"proof_dual_system_hybrid","feature_standard_assumption":"proof_k_Lin_reduction","feature_type_III_pairing":"enc_matrix_dual_system"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2019/224","sections_cited":["§6 KP-ABE construction","Appendix A.1 CP-ABE construction","§5.1 piecewise-guessing framework"],"url":"https://eprint.iacr.org/2019/224","venue":"Eurocrypt 2019","year":2019},"pareto_notes":"Resolves the Lewko–Waters 2011 open problem: simultaneously compact + adaptive + static assumption + many-use. CT grows with policy size in the CP-ABE direction — dual KP-ABE is compact in CT. Superseded on expressiveness by LL20a/b (ABP); still a milestone for NC1.\n","policy":{"ROM_required":false,"class":"NC1","large_universe":false,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"bound":"2^{6d} * 8^d * n * Adv^{k-Lin}","mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"(k+1)*(2*n1+1)","GT":"1","note":"1 + 2n_1 vectors in G_1 of length k+1, plus 1 G_T. Grows with policy size n_1."},"MPK":{"G1":"k*(k+1)*(U+1)+k","GT":"1","note":"n+2 matrices in G_1 of size k x (k+1), plus 1 G_T element. U = attribute universe size."},"SK":{"G2":"(k+1)*(m+2)","note":"m+2 vectors in G_2 of length k+1. |S|-dependent, policy-size-INDEPENDENT. Compactness axis."},"sources":["KW19 Appendix A.1 CP-ABE construction","KW19 §1.1 informal parameter claims"]},"variables":{"I":"satisfying shares used at decryption","K":"LSSS matrix extra columns (= n2 - 1 in paper notation)","N":"LSSS share count (paper's m = number of formula leaves; here = U under one-use)","U":"attribute universe size n in paper","k":"k-Lin parameter (k=1 pilot; paper's K := k+1 = 2 concretized, not surfaced as spec symbol)","m":"|S|, attribute set size in SK"},"verification":{"ggm_file":null,"note":"Path B-hard pilot at k=1 (K=2 concretized). Pilot is\nKW19-inspired (preserves the U_0 matrix distinctive to KW19)\nbut not a faithful transcription of Appendix A.1. Simplifications:\n(1) Single FABEO-style LSSS sharing vector `u` instead of\nper-share randomness s_j and share vectors u_j;\n(2) U_0 matrix preserved — this is what distinguishes the pilot\nfrom CGW15's (which has U_c per LSSS column);\n(3) Multi-use collapsed to one-use (rho = id).\n\nVERIFICATION STATUS: validate, size_consistency, correctness,\nand compile gates all PASS. Solver gate fails with \"Contradiction\nnot found\" — the auto-generated generic adversary is stronger than\nwhat the KW19 Appendix A.1 security proof addresses, and the\nGröbner prover doesn't find a contradiction without hand-authored\ntactics. Same failure mode as fabeo_cpabe's auto-compiled spec.\n\nThis pilot therefore demonstrates: matrix_PES schema + compiler +\ncorrectness Tier 2 all work correctly on KW19-style constructions;\nthe remaining gap is solver-side tactics. Hand-written .ggm with\nadd_equation hints would likely close it, analogous to\nlibrary/abe/formalizations/fabeo_cpabe.ggm.\n","status":"compiler_ok_solver_stuck"}},"primaryUrl":"https://eprint.iacr.org/2019/224","sections":[{"content":"KW19 resolves a long-standing open problem: achieve adaptive ABE for NC1 (monotone Boolean formulas) that is simultaneously compact, many-use (no one-use restriction), polynomial security loss, and based on a static standard assumption ($k$-Lin). Prior adaptive schemes (Lewko–Waters'10, CGW15, FAME) paid for adaptivity with either a one-use restriction or a $q$-type assumption or both. The main trick is a \"piecewise-guessing\" security framework (§5) combined with a refined NC1 secret-sharing scheme from Jafargholi et al. (TCC 2017). The framework lets the security proof guess the *structure* of a satisfying assignment piece-by-piece along the formula tree rather than at the attribute-label level, giving a $2^{O(d)}\\cdot n$ loss for depth-$d$ formulas — polynomial when $d = O(\\log n)$ (i.e., NC1).","heading":"Intuition"},{"content":"Sample $A\\leftarrow_R\\mathbb{Z}_p^{k\\times 2k}$, $B\\leftarrow_R\\mathbb{Z}_p^{(k+1)\\times k}$, $U_0, W_1, \\ldots, W_n\\leftarrow_R\\mathbb{Z}_p^{2k\\times(k+1)}$, $\\mathbf{v}\\leftarrow_R\\mathbb{Z}_p^{2k}$. $$\\mathrm{MPK} = \\big([A]_1,\\ [A U_0]_1,\\ [A W_1]_1, \\ldots, [A W_n]_1,\\ e([A]_1,[\\mathbf{v}]_2)\\big)$$ $$\\mathrm{MSK} = (\\mathbf{v},\\ B,\\ U_0,\\ W_1, \\ldots, W_n)$$","heading":"Setup"},{"content":"Input: attribute vector $\\mathbf{x}\\in\\{0,1\\}^n$ (characteristic vector of $S$). Sample $\\mathbf{r}\\leftarrow_R\\mathbb{Z}_p^k$. $$\\mathrm{sk}_{\\mathbf{x}} = \\big(\\mathrm{sk}_1, \\mathrm{sk}_2, \\{\\mathrm{sk}_{3,i}\\}_{x_i=1}\\big) = \\big([\\mathbf{v} + U_0 B\\mathbf{r}]_2,\\ [B\\mathbf{r}]_2,\\ \\{[W_i B\\mathbf{r}]_2\\}_{x_i=1}\\big)$$","heading":"KeyGen"},{"content":"Input: monotone formula $f$ over $[n]$, message $m$. Run the NC1 secret-sharing scheme to produce shares $(\\{\\mathbf{u}_j\\}_{j\\in[n_1]}, \\rho)$ of $\\mathbf{s}^\\top A U_0$. Sample $\\mathbf{s}, \\mathbf{s}_1, \\ldots, \\mathbf{s}_{n_1}\\leftarrow_R\\mathbb{Z}_p^k$. $$\\mathrm{ct}_1 = [\\mathbf{s}^\\top A]_1,\\quad \\mathrm{ct}_4 = e([\\mathbf{s}^\\top A]_1, [\\mathbf{v}]_2)\\cdot m$$ For each share $j\\in[n_1]$: $$\\mathrm{ct}_{2,j} = [\\mathbf{u}_j^\\top + \\mathbf{s}_j^\\top A W_{\\rho(j)}]_1,\\quad \\mathrm{ct}_{3,j} = [\\mathbf{s}_j^\\top A]_1$$","heading":"Encrypt"},{"content":"Reconstruct $\\{\\omega_j\\}$ such that $\\mathbf{s}^\\top A U_0 = \\sum\\omega_j \\mathbf{u}_j$ (over satisfying shares); output $$\\mathrm{ct}_4\\ /\\ \\left[e(\\mathrm{ct}_1,\\mathrm{sk}_1)\\cdot\\prod_j\\big(e(\\mathrm{ct}_{2,j},\\mathrm{sk}_2)/e(\\mathrm{ct}_{3,j},\\mathrm{sk}_{3,\\rho(j)})\\big)^{\\omega_j}\\right]$$ Pairings: $2I+1$ where $I$ = number of satisfying shares used.","heading":"Decrypt"}],"status":"compiler_ok_solver_stuck","subtitle":"CP-ABE · 2019","summary":"First adaptive ABE for NC1 (monotone Boolean formulas) from static k-Lin in prime-order groups with attribute multi-use and polynomial security loss. Secret key is policy-size-independent (\"compact\").","title":"Kowalczyk–Wee CP-ABE for NC1","type":"construction","venue":"Eurocrypt 2019","year":2019,"sourcePath":"data/abe-catalog.json#kw19_cpabe"},{"evidence":"solver_verified","id":"kw19_kpabe","keywords":["kp-abe","pairing","NC1","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k^1)"},"authors":["Lucas Kowalczyk","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"A1 * v1 * s + A2 * v2 * s","group":"G_T","name":"Ctilde"},{"expr":"A1 * s","group":"G_1","name":"ct11"},{"expr":"A2 * s","group":"G_1","name":"ct12"},{"expr":"diag(x) * w1 * s","group":"G_1","name":"cx1","shape":"Zp^N"},{"expr":"diag(x) * w2 * s","group":"G_1","name":"cx2","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"KP dual of KW19 CP at K=2: 2-way matrix pairings over K-coords.\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N, K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"v1 + (U11*B1 + U12*B2) * r","group":"G_2","name":"sk11"},{"expr":"v2 + (U21*B1 + U22*B2) * r","group":"G_2","name":"sk12"},{"expr":"B1 * r","group":"G_2","name":"sk21"},{"expr":"B2 * r","group":"G_2","name":"sk22"},{"expr":"M1 * v1 + M * u1 + w1 * r * A1","group":"G_2","name":"sks1","shape":"Zp^N"},{"expr":"M1 * v2 + M * u2 + w2 * r * A2","group":"G_2","name":"sks2","shape":"Zp^N"}],"target":"A1 * v1 * s + A2 * v2 * s","variables":{"common":["A1","A2","B1","B2","U11","U12","U21","U22","w1","w2"],"ct_randomness":["s"],"master":["v1","v2"],"shapes":{"u1":"Zp^K","u2":"Zp^K","w1":"Zp^N","w2":"Zp^N"},"sk_randomness":["r","u1","u2"]}},"construction_one_liner":"First compact + adaptive + many-use + k-Lin KP-ABE for NC1. CT is policy-size independent — a milestone that resolves the Lewko–Waters'11 open problem. Built from a piecewise-guessing security framework plus a refined NC1 secret-sharing scheme.\n","decrypt_pairings":"2*I+1","id":"kw19_kpabe","name":"Kowalczyk–Wee KP-ABE for NC1","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2019/224","sections_cited":["§6 main KP-ABE construction","§5.1 piecewise guessing framework"],"url":"https://eprint.iacr.org/2019/224","venue":"Eurocrypt 2019","year":2019},"pareto_notes":"Main construction of the KW19 paper (the CP-ABE is in Appendix A). Compact CT is the headline. Only downside vs. FABEO: standard k-Lin at 2^{O(d)}·n loss vs. FABEO's GGM+ROM at optimal O(t²/p).","policy":{"ROM_required":false,"class":"NC1","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"(k+1)*(U+2)","GT":"1","note":"COMPACT: O(k·n) CT where n = attribute length. Policy-size INDEPENDENT even in many-use."},"MPK":{"G1":"k*(U+1)*(k+1)+k","GT":"1","note":"Matrix encodings scale as k(k+1) per universe slot + const."},"SK":{"G2":"(k+1)*(2*m_formula+1)","note":"Linear in formula size m_formula = number of shares. Policy in key; grows with formula."},"sources":["KW19 §6 main KP-ABE construction","KW19 §1.1 parameter claims"]},"variables":{"I":"satisfying shares used at decryption","U":"attribute universe size (= input length n)","k":"k-Lin parameter; k=1 for SXDH","m":"|S|, attribute set size in CT (= |x| attribute-vector length in a sense)","m_formula":"number of shares in the NC1 formula (policy size in SK)","n1":"alias for m_formula"},"verification":{"ggm_file":null,"note":"Verified end-to-end (M1 confirmed 2026-04-23) at k=1 (K=2). KP dual\nof KW19 CP pilot. Same simplifications: FABEO-style aug `u`,\none-use, U_0 matrix preserved (distinctive to KW19). Solver returns\n\"no remaining goals\". Notably KW19 KP passes while KW19 CP doesn't\n— see kw19_cpabe.md for the tactic gap.\n","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2019/224","sections":[{"content":"This is the main construction of KW19 (the CP-ABE is in Appendix A.1). The paper resolves a long-standing open problem from Lewko–Waters 2011: achieve adaptive ABE for NC1 that is simultaneously compact (CT independent of policy size), many-use (attributes can repeat in the formula), polynomial security loss, and based on a static standard assumption ($k$-Lin). The KP-ABE puts the NC1 formula in the key and carries the attribute vector in the ciphertext; compactness is on the CT side — CT length depends only on input length $n$ (and $k$), not on the formula's size. The dual CP-ABE (same framework, sk↔ct roles swapped) has compactness on the SK side.","heading":"Intuition"},{"content":"Symmetric to the CP-ABE variant spec kw19_cpabe.md. The same \"piecewise-guessing\" proof framework (§5.1) + refined NC1 secret-sharing (from Jafargholi et al. TCC 2017) drives both.","heading":"Setup / KeyGen / Encrypt / Decrypt"},{"content":"MPK: $O(n)\\cdot|\\mathbb{G}_1|$ (linear in universe). SK: $O(|f|)\\cdot|\\mathbb{G}_2|$ where $|f|$ = formula size = number of shares. CT: $O(n)\\cdot|\\mathbb{G}_1|$ — policy-size independent. This is the headline. Pairings: $2I+1$ where $I$ = satisfying shares.","heading":"Sizes summary (at SXDH $k=1$)"}],"status":"solver_verified","subtitle":"KP-ABE · 2019","summary":"First compact + adaptive + many-use + k-Lin KP-ABE for NC1. CT is policy-size independent — a milestone that resolves the Lewko–Waters'11 open problem. Built from a piecewise-guessing security framework plus a refined NC1 secret-sharing scheme.","title":"Kowalczyk–Wee KP-ABE for NC1","type":"construction","venue":"Eurocrypt 2019","year":2019,"sourcePath":"data/abe-catalog.json#kw19_kpabe"},{"evidence":"blocked_hybrid","id":"ll20a_kpabe","keywords":["kp-abe","pairing","ABP","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k)"},"authors":["Huijia Lin","Ji Luo"],"construction_one_liner":"First compact adaptive KP-ABE for arithmetic branching programs (beyond NC1) from standard k-Lin. CT size is independent of ABP size; SK grows linearly in ABP size (improvement over prior O(|ABP|^2) constructions).\n","decrypt_pairings":"O(k*U*mABP)","id":"ll20a_kpabe","name":"Lin–Luo Compact KP-ABE for ABP (beyond NC1)","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2020/318","sections_cited":["§6.3 Construction 26: KP-ABE for ABPs","§7 extensions to L/NL/DFA/NFA","Appendix A IPFE from k-Lin"],"url":"https://eprint.iacr.org/2020/318","venue":"Eurocrypt 2020","year":2020},"pareto_notes":"Extends KW19 from NC1 to ABP / L / NL. Two headline results: adaptive compact ABE for ABP, and first adaptive compact ABE for DFA/NFA/L/NL from standard k-Lin. LL20b (Asiacrypt 2020) further reduces to constant CT (5 elts SXDH) at the cost of SK linear in ABP size.","policy":{"ROM_required":false,"class":"ABP","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"O(k*U)","GT":"1","note":"Single IPFE slotted ciphertext carrying (pad, const^t, coef_i^t) slots. Policy-size INDEPENDENT."},"MPK":{"G1":"O(k*U)","note":"Θ(kn) IPFE public slots (const, coef_i for t in [k], i in [n])."},"SK":{"G1":"O(k*U*mABP)","note":"(mABP+1) IPFE secret keys, each with O(kn) group elements. Linear in ABP size — improvement from quadratic in prior work [IW14, CGKW18]."},"sources":["LL20a Construction 26 (§6.3) KP-ABE for ABPs","LL20a Theorem 27 adaptive security"]},"variables":{"U":"attribute-vector length n in paper","k":"k-Lin parameter; k=1 for SXDH","mABP":"number of vertices in the ABP policy"},"verification":{"blocker":"ipfe_compiler","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2020/318","sections":[{"content":"LL20a extends KW19 from NC1 (monotone Boolean formulas) to the substantially more expressive class of arithmetic branching programs (ABPs) over $\\mathbb{Z}_p$, while preserving: (a) adaptive security, (b) compact (policy-size-independent) ciphertexts, (c) static $k$-Lin assumption, (d) polynomial security loss. The construction is also extended to give the first compact adaptive KP-ABE for DFA, NFA, logspace Turing machines, and NL, from the same $k$-Lin assumption — this is the \"beyond NC1 toward NL\" of the paper's subtitle. The backbone is a function-hiding slotted inner-product functional encryption (IPFE) (Appendix A, line going back to Lin 2017 / KLM+18) plus a novel arithmetic key garbling scheme (AKGS) that encodes $\\mu\\cdot f(\\mathbf{x})$ with linear label functions satisfying a piecewise security property. Combining: (IPFE keys for per-vertex label functions) × (single IPFE ciphertext for attribute slots) → KP-ABE for ABPs with keys linear in $|\\mathrm{ABP}|$ and CT linear in $|\\mathbf{x}|$.","heading":"Intuition"},{"content":"Setup($1^n$): run IPFE.Setup to get $(\\mathrm{msk}, \\mathrm{mpk})$ over $\\Theta(kn)$ public slots: $\\{\\mathrm{pad}, \\mathrm{const}^t, \\mathrm{coef}_i^t\\}$ for $t\\in[k], i\\in[n]$. KeyGen($f$): input ABP $f:\\mathbb{Z}_p^n\\to\\mathbb{Z}_p$. Run $k$ garblings via AKGS to produce label functions $L_1^t, \\ldots, L_{m_{\\text{ABP}}}^t$ for $t\\in[k]$. Output $\\mathrm{sk} = (\\mathrm{isk}_{\\mathrm{pad}}, f, \\mathrm{isk}_1, \\ldots, \\mathrm{isk}_{m_{\\text{ABP}}})$ — $(m_{\\text{ABP}}+1)$ IPFE secret keys, each $O(kn)$ group elements. Encrypt($\\mathbf{x}, g$): sample pad $h, \\mathbf{s}\\in\\mathbb{Z}_p^k$. Output $\\mathrm{ct} = (g + [h]_T, \\mathbf{x}, \\mathrm{ict})$ where $\\mathrm{ict}$ is a single slotted IPFE ciphertext filling slots $(\\mathrm{pad} = h, \\mathrm{const}^t = \\mathbf{s}[t], \\mathrm{coef}_i^t = \\mathbf{s}[t]\\mathbf{x}[i])$. Decrypt: run IPFE.Dec on each $\\mathrm{isk}_j$ + $\\mathrm{ict}$ to get $[\\ell_j]_T$; evaluate AKGS linearly; subtract $[h]_T$ from the tag to recover $g$.","heading":"Sketch"},{"content":"MPK: $O(kn)$ group elements. SK: $O(m_{\\text{ABP}}\\cdot kn)$ — linear in ABP size (×$kn$ for the IPFE slots). CT: $O(kn)$ + 1 $\\mathbb{G}_T$ — independent of ABP size. Pairings: $O(m_{\\text{ABP}}\\cdot kn)$ — one IPFE decryption per label-function key.","heading":"Sizes"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2020","summary":"First compact adaptive KP-ABE for arithmetic branching programs (beyond NC1) from standard k-Lin. CT size is independent of ABP size; SK grows linearly in ABP size (improvement over prior O(|ABP|^2) constructions).","title":"Lin–Luo Compact KP-ABE for ABP (beyond NC1)","type":"construction","venue":"Eurocrypt 2020","year":2020,"sourcePath":"data/abe-catalog.json#ll20a_kpabe"},{"evidence":"blocked_hybrid","id":"ll20b_cpabe","keywords":["cp-abe","pairing","ABP","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k)"},"authors":["Huijia Lin","Ji Luo"],"construction_one_liner":"First ABE with CONSTANT-size secret key under a static standard assumption (k-Lin), adaptive security, prime-order groups. SK = 3k+4 group elements (7 under SXDH), independent of ABP policy size.\n","decrypt_pairings":"3*k+4","id":"ll20b_cpabe","name":"Lin–Luo Succinct CP-ABE for ABP","ontology":{"assumption_deps":{"FE_correctness":["join: FE_primitive_evaluation"],"IPFE_sim_security":["join: FE_primitive_evaluation"],"assumption_k_Lin":["subprim_pairing_IPFE","proof_k_Lin_reduction"]},"atoms":["policy_ABP","subprim_pairing_IPFE","master_in_IPFE_slot","proof_dual_system_hybrid","proof_k_Lin_reduction"],"connections":null,"features_provided":{"feature_adaptive_security":"proof_dual_system_hybrid","feature_constant_SK":"subprim_pairing_IPFE","feature_standard_assumption":"proof_k_Lin_reduction"},"joins_used":["FE_primitive_evaluation"]},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2020/1139","sections_cited":["§6 CP-ABE for ABP (Construction 37)","Theorem 38 adaptive security","§3 gradually-simulation-secure IPFE"],"url":"https://eprint.iacr.org/2020/1139","venue":"Asiacrypt 2020","year":2020},"pareto_notes":"Breakthrough on the succinctness axis. CP-ABE SK is constant but CT grows with policy size — the usual duality trade. No known extension to monotone LSSS at matching SK. Pairs with the dual KP-ABE in the same paper (constant-CT KP-ABE for ABP).\n","policy":{"ROM_required":false,"class":"ABP","large_universe":false,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"(k+1)*mABP*(U+2)+mABP+k+1","GT":"1","note":"Grows with mABP = ABP size (vertex count). Under SXDH: ~m_ABP*(U+2) + m_ABP + 2 G_1 elements."},"MPK":{"G1":"k*(k+1)*(U+4)+k","GT":"1","note":"U = attribute-length parameter n in paper. k-Lin parameterized; under SXDH (k=1), approx (n+4) G_1 elements."},"SK":{"G1":"3*k+4","note":"CONSTANT in policy size. Under SXDH (k=1): 7 G_1 elements. Headline result."},"sources":["LL20b Construction 37 (Section 6.2) CP-ABE for ABP","LL20b Table 2 exact element counts"]},"variables":{"I":"effectively mABP in decryption","U":"attribute vector length n in paper","k":"k-Lin parameter; k=1 for SXDH","m":"|S|, attribute set size in SK (= 1 here since key holds one attribute vector x, not a set)","mABP":"number of vertices in the ABP policy (policy size)"},"verification":{"blocker":"ipfe_compiler","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2020/1139","sections":[{"content":"Lin–Luo achieve the first ABE with constant-size secret keys from a static standard assumption ($k$-Lin), in prime-order groups, with adaptive security. Secret keys consume $3k+4$ group elements — just 7 under SXDH. Crucially, this is independent of the policy size (ABP vertex count). The construction combines two ingredients: (1) a gradually-simulation-secure IPFE (§3), a weaker-than-function-hiding security where only ciphertexts are simulated; this is what lets IPFE keys be succinct, which in turn makes ABE ciphertexts succinct; and (2) an arithmetic key garbling scheme (AKGS) with piecewise security (from LL20a). Composing via a carefully designed dual-system encryption transformation in both directions gives both a constant-CT KP-ABE and this constant-SK CP-ABE.","heading":"Intuition"},{"content":"Sample matrices $A\\in\\mathbb{Z}_p^{k\\times(k+2)}$, $B\\in\\mathbb{Z}_p^{k\\times(k+1)}$, $D\\in\\mathbb{Z}_p^{k\\times(k+1)}$, $W\\in\\mathbb{Z}_p^{(k+2)\\times(k+1)(n+1)}$, $U\\in\\mathbb{Z}_p^{(k+1)\\times(k+1)}$, $\\boldsymbol{\\nu}\\in\\mathbb{Z}_p^{k+1}$. $$\\mathrm{xpk} = \\big([B^\\top]_1,\\ [W(B^\\top\\otimes I_{n+1})]_1\\big),\\quad \\mathrm{fpk} = ([A]_2,\\ [AW]_2)$$ $$\\mathrm{MPK} = ([D]_2,\\ [DU]_2,\\ [D\\boldsymbol{\\nu}]_T,\\ \\mathrm{fpk}),\\quad \\mathrm{MSK} = ([UB^\\top]_1,\\ \\mathrm{xpk},\\ \\boldsymbol{\\nu})$$","heading":"Setup"},{"content":"Input: attribute vector $\\mathbf{x}\\in\\mathbb{Z}_p^n$. Sample $\\mathbf{r}\\leftarrow_R\\mathbb{Z}_p^k$. $$\\mathrm{sk}_1 = [B^\\top]_1 \\mathbf{r}\\in\\mathbb{G}_1^{k+1}$$ $$\\mathrm{sk}_2 = [W(B^\\top\\otimes I_{n+1})]_1\\cdot(\\mathbf{r}\\otimes(1,\\mathbf{x}))\\in\\mathbb{G}_1^{k+2}$$ $$\\mathrm{sk}_3 = [\\boldsymbol{\\nu}]_1 + [UB^\\top]_1\\mathbf{r}\\in\\mathbb{G}_1^{k+1}$$ Total: $(k+1) + (k+2) + (k+1) = \\boxed{3k+4}$ $\\mathbb{G}_1$ elements, independent of the eventual policy. Under SXDH ($k=1$): 7.","heading":"KeyGen"},{"content":"Input: ABP policy $y$, message $g\\in\\mathbb{G}_T$. Sample $\\mathbf{t}\\leftarrow_R\\mathbb{Z}_p^k$. $$[\\mathbf{u}^\\top]_2 = \\mathbf{t}^\\top [DU]_2,\\quad \\mathrm{ct}_{0,1} = \\mathbf{t}^\\top [D]_2,\\quad \\mathrm{ct}_{0,2} = \\mathbf{t}^\\top [D\\boldsymbol{\\nu}]_T + g$$ Garble the ABP $y$ with $[\\mathbf{u}]_2$ to produce label functions $[\\mathbf{L}_1]_2, \\ldots, [\\mathbf{L}_{m_{\\text{ABP}}}]_2$. For each $j$, sample $\\mathbf{s}_j\\leftarrow_R\\mathbb{Z}_p^k$: $$\\mathrm{ct}_{j,1} = \\mathbf{s}_j^\\top [A]_2,\\quad \\mathrm{ct}_{j,2} = \\mathbf{s}_j^\\top [AW]_2 + [\\mathbf{L}_j^\\top]_2$$ CT size: $(k+1)m_{\\text{ABP}}(n+2) + m_{\\text{ABP}} + k + 1$ $\\mathbb{G}_2$ elements + 1 $\\mathbb{G}_T$, grows linearly in both ABP size and attribute length.","heading":"Encrypt"},{"content":"Check $y(\\mathbf{x})=1$. For each $j$: compute $[\\ell_j]_T = -\\mathrm{ct}_{j,1}\\cdot\\mathrm{sk}_2 + \\mathrm{ct}_{j,2}\\cdot(\\mathrm{sk}_1\\otimes(1,\\mathbf{x}))$. Run AKGS.Eval on $\\{\\ell_j\\}$ to get $[\\mu']_T$. Output $\\mathrm{ct}_{0,2} + [\\mu']_T - \\mathrm{ct}_{0,1}\\cdot\\mathrm{sk}_3$. Pairings: $3k+4$ (matching the SK size).","heading":"Decrypt"}],"status":"blocked_hybrid","subtitle":"CP-ABE · 2020","summary":"First ABE with CONSTANT-size secret key under a static standard assumption (k-Lin), adaptive security, prime-order groups. SK = 3k+4 group elements (7 under SXDH), independent of ABP policy size.","title":"Lin–Luo Succinct CP-ABE for ABP","type":"construction","venue":"Asiacrypt 2020","year":2020,"sourcePath":"data/abe-catalog.json#ll20b_cpabe"},{"evidence":"blocked_hybrid","id":"ll20b_kpabe","keywords":["kp-abe","pairing","ABP","standard"],"metadata":{"assumption":{"family":"standard","name":"k-Lin (MDDH_k)"},"authors":["Huijia Lin","Ji Luo"],"construction_one_liner":"First KP-ABE with CONSTANT-size ciphertexts for a rich policy class (ABP), adaptive under static k-Lin. CT = 5 group elements at SXDH. Breaks the long-standing \"succinct implies selective or q-type\" pattern.\n","decrypt_pairings":"2*k+3","id":"ll20b_kpabe","name":"Lin–Luo Succinct KP-ABE for ABP (constant CT)","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2020/1139","sections_cited":["§5 KP-ABE construction (Construction 32)","Theorem 33 adaptive security","§4 CP-1-ABE building block"],"url":"https://eprint.iacr.org/2020/1139","venue":"Asiacrypt 2020","year":2020},"pareto_notes":"CT lower bound for ABE-for-ABP under standard assumptions. SK grows linearly with ABP size — dual of LL20b CP-ABE which has constant SK. No known extension to richer policy classes (NL, circuits) at matching CT.","policy":{"ROM_required":false,"class":"ABP","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA"},"sizes":{"CT":{"G1":"2*k+3","GT":"1","note":"CONSTANT — 5 group elements under SXDH (k=1), 2k+3 in general. Headline result."},"MPK":{"G2":"O(k*U)","note":"Public IPFE slots + gradually-sim-secure machinery."},"SK":{"G2":"O(k*U*mABP)","note":"Grows with ABP size."},"sources":["LL20b §5 KP-ABE Construction 32","LL20b Table 2 exact element counts"]},"variables":{"U":"attribute-vector length n","k":"k-Lin parameter; k=1 for SXDH","mABP":"ABP policy size (vertex count)"},"verification":{"blocker":"ipfe_compiler","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2020/1139","sections":[{"content":"The headline result of the LL20b paper: a KP-ABE for arithmetic branching programs with constant-size ciphertexts — just $2k+3$ group elements under $k$-Lin, i.e. 5 elements under SXDH — with adaptive security in the standard model. This breaks the long-standing pattern \"succinct ABE requires selective or $q$-type assumption or iO\" going back to Attrapadung14. The construction is built as: gradually-simulation-secure public-key IPFE (§3) — a weaker-than-function-hiding IPFE where only the ciphertext vector is simulated, keys revealed in clear; this is exactly the weakening that lets IPFE keys be succinct, which in turn makes the ABE CT succinct — composed with an information-theoretic AKGS (§2.1, from LL20a) via dual-system encryption applied to an intermediate CP-1-ABE (single-key / single-ciphertext secret-key ABE).","heading":"Intuition"},{"content":"Setup: gradually-sim-secure IPFE with $O(kn)$ slots, augmented with dual-system matrices. KeyGen: input ABP $f$. Garble $f$ with AKGS; for each of $m_{\\text{ABP}}$ label functions, issue an IPFE secret key. SK total: $O(m_{\\text{ABP}}\\cdot kn)$ group elements. Encrypt: input $\\mathbf{x}, g$. Form a single IPFE slotted ciphertext + dual-system header. Total: $2k+3$ group elements in $\\mathbb{G}_1$ + 1 $\\mathbb{G}_T$. Decrypt: reconstruct $\\mu\\cdot f(\\mathbf{x}) = \\mu$ (when $f(\\mathbf{x}) = 1$) by running AKGS evaluation in the exponent, then unmask.","heading":"Sketch"},{"content":"Under SXDH ($k=1$): CT = 5 group elements + 1 $\\mathbb{G}_T$. CONSTANT, independent of $|\\mathbf{x}|$ and of the policy that will be used for decryption. SK grows linearly in ABP size: $O(m_{\\text{ABP}}\\cdot n)$. MPK grows linearly in $n$ (attribute length). Pairings: $2k+3 = 5$ at SXDH.","heading":"Sizes"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2020","summary":"First KP-ABE with CONSTANT-size ciphertexts for a rich policy class (ABP), adaptive under static k-Lin. CT = 5 group elements at SXDH. Breaks the long-standing \"succinct implies selective or q-type\" pattern.","title":"Lin–Luo Succinct KP-ABE for ABP (constant CT)","type":"construction","venue":"Asiacrypt 2020","year":2020,"sourcePath":"data/abe-catalog.json#ll20b_kpabe"},{"evidence":"solver_verified","id":"fabeo_cpabe","keywords":["cp-abe","pairing","monotone_LSSS","GGM+ROM"],"metadata":{"assumption":{"bound":"O(t^2 / p), matches discrete-log lower bound","family":"GGM+ROM","name":"Generic bilinear group"},"authors":["Doreen Riepel","Hoeteck Wee"],"construction":{"ciphertext_encoding":[{"expr":"alpha * s","group":"G_T","name":"Ctilde"},{"expr":"s","group":"G_2","name":"Cs"},{"expr":"sp","group":"G_2","name":"Csp"},{"expr":"(M1*s + M*v) * bp + sp * b","group":"G_1","name":"c","note":"Vector of N CT elements; row i = (M1_i*s + (M*v)_i)*bp + sp*b_i.","shape":"Zp^N"}],"decryption":{"constraint":"diag(x)*M1 + diag(x)*M*c = 0 (no reconstruction vector c exists)","constraint_ggm":"diag(x)*M1 + diag(x)*M*c = 0","predicate":"x satisfies LSSS(M1 | M)","reconstruction":"Choose {w_i}_{i in I} with sum_i w_i * (M1_i, M_i) = (1, 0, ..., 0).\nalpha*s = e(K, Cs) - e(sum_i w_i * c_i, L) / bp + sum_i w_i * e(Ku_i, Csp).\n"},"parameters":{"attribute_selector":{"kind":"binary_vector","var":"x in {0,1}^N"},"policy":{"first_column":"M1 in Zp^N","kind":"LSSS","remainder":"M in Zp^(N,K)","row_labels":"rho: [N] -> universe"}},"schema":"matrix_PES","schema_version":1,"secret_key_encoding":[{"expr":"alpha + r * bp","group":"G_1","name":"K"},{"expr":"r","group":"G_2","name":"L"},{"expr":"r * diag(x) * b","group":"G_1","name":"Ku","note":"Entry i is r*b_i when x_i=1 (attribute i in S), else 0.","shape":"Zp^N"}],"target":"alpha * s","variables":{"common":["bp","b"],"ct_randomness":["s","v","sp"],"master":["alpha"],"shapes":{"b":"Zp^N","v":"Zp^K"},"sk_randomness":["r"]}},"construction_one_liner":"Current Pareto frontier for practical pairing CP-ABE: smallest SK and CT, fewest pairings (2–3), optimal security bound O(t^2/p) matching the discrete-log lower bound, native attribute multi-use, large universe. Proven in GGM + ROM.\n","decrypt_pairings":"tau+2","id":"fabeo_cpabe","implementations":["Charm","FABEO GitHub"],"name":"FABEO CP-ABE (Riepel–Wee)","ontology":{"assumption_deps":{"assumption_GGM":["enc_linear_no_inverse","proof_GGM_symbolic_PES"],"assumption_ROM":["attr_hash_ROM_G","proof_ROM_hash_idealization"]},"atoms":["attr_hash_ROM_G","policy_LSSS_monotone","lsss_multi_use_tau_slots","enc_linear_no_inverse","master_alpha_scalar_SK_linear","proof_GGM_symbolic_PES","proof_ROM_hash_idealization"],"connections":[{"from":"policy_LSSS_monotone.monotone_lsss","note":"raw LSSS gets the multi-use τ-slots decoration","to":"lsss_multi_use_tau_slots.lsss_in"},{"from":"lsss_multi_use_tau_slots.lsss_multi_use_out","note":"τ+1 G_2 sharing slots multiply CT rows","to":"enc_linear_no_inverse.policy_in"}],"features_provided":{"feature_adaptive_security":"proof_GGM_symbolic_PES","feature_large_universe":"attr_hash_ROM_G","feature_multi_use_policy":"lsss_multi_use_tau_slots","feature_type_III_pairing":"enc_linear_no_inverse"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2022/1415","sections_cited":["§5 CP-ABE scheme","Table 5 size comparison","§6 comparison discussion"],"url":"https://eprint.iacr.org/2022/1415","venue":"CCS 2022","year":2022},"pareto_notes":"Strictly dominates BSW / Waters11 / FAME / ABGW on SK, CT, and pairing count at adaptive security. Single weak spot vs. KW19/LL20: GGM + ROM instead of standard k-Lin. Formalized in ggm-symbolic-solver in this repo (`library/abe/formalizations/fabeo_cpabe.ggm`).\n","policy":{"ROM_required":true,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":true},"primitive":"CP-ABE","security":{"mode":"adaptive","model":"GGM+ROM","notion":"CPA"},"sizes":{"CT":{"G1":"n1","G2":"tau+1","GT":"1","note":"n_1 row elements in G_1; (tau+1) in G_2 carrying shared randomness across multi-use reuse."},"MPK":{"G1":"1","G2":"1","GT":"1","note":"g_1^alpha (implicit), g_2, e(g_1,g_2)^alpha, + ROM hash H: {0,1}* -> G_1. All O(1)."},"SK":{"G1":"m+1","G2":"1","note":"Head K = g_1^{alpha+r*b_{|U|+1}} in G_1, m K_u = g_1^{r*b_u} in G_1, L = g_2^r in G_2."},"abstraction_note":"Declared sizes follow FABEO Table 5. The PES construction block\nbelow captures the τ=1 specialization with a single sp slot,\nwhich differs slightly in per-slot counting from the paper's\nparametric τ. Expected divergence in size-consistency checks.\n","sources":["FABEO §5 construction","FABEO Table 5 exact element counts"]},"variables":{"I":"rows used in reconstruction","m":"|S|, attribute set size in SK","n1":"LSSS matrix rows","tau":"multi-use parameter: max times any attribute appears in the LSSS matrix"},"verification":{"ggm_file":"library/abe/formalizations/fabeo_cpabe.ggm","note":"Hand-written .ggm verifies. PES-compiled .ggm requires tactics the compiler can't yet author.","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2022/1415","sections":[{"content":"FABEO identifies the minimal structure needed for an LSSS CP-ABE to be (a) large-universe, (b) multi-use, (c) adaptively secure under a GGM + ROM proof with optimal bound $O(t^2/p)$ (matching the discrete-log lower bound), and (d) decryptable in a small constant number of pairings. The construction uses a linear pair encoding (no $1/b$): keys are $g_1^{r b_u}$ per attribute with shared randomness $r$, and ciphertexts spread share randomness across $\\tau+1$ \"slots\" in $\\mathbb{G}_2$ to support the multi-use parameter $\\tau$. A large-universe hash $H:\\{0,1\\}^*\\to\\mathbb{G}_1$ replaces per-attribute MPK elements. Because the encoding is linear (not rational), this scheme is Type-I-insecure (see type_i_vs_type_iii.md) and must be deployed strictly in Type III. The asymmetry between $\\mathbb{G}_1$ (carries keys and attribute-row CT) and $\\mathbb{G}_2$ (carries per-slot randomness) is security-critical, not just an efficiency choice.","heading":"Intuition"},{"content":"Sample $\\alpha \\leftarrow_R \\mathbb{Z}_p$. Sample $b_u \\leftarrow_R \\mathbb{Z}_p$ for each $u$ in the universe — but because the universe is large and accessed via ROM, these are defined implicitly as $b_u := H_b(u)$ via a second hash. $$\\mathrm{MPK} = (g_1,\\ g_2,\\ Y_\\alpha = e(g_1,g_2)^\\alpha,\\ H),\\qquad \\mathrm{MSK} = \\alpha$$ (In practice the scheme folds everything into one ROM hash $H$ that outputs group elements; conceptually, think of $b_u$ as derived from $H$.)","heading":"Setup"},{"content":"Input: attribute set $S$. Sample $r\\leftarrow_R\\mathbb{Z}_p$. $$K = g_1^{\\alpha}\\cdot g_1^{r\\cdot b_{*}}\\in\\mathbb{G}_1,\\quad L = g_2^r\\in\\mathbb{G}_2,\\quad \\text{for each }u\\in S:\\ K_u = g_1^{r\\cdot b_u}\\in\\mathbb{G}_1$$ $$\\mathrm{SK} = (K,\\ L,\\ \\{K_u\\}_{u\\in S})$$ Size: $(m+1)\\cdot|\\mathbb{G}_1| + 1\\cdot|\\mathbb{G}_2|$. Matches Waters11 exactly; strictly smaller than BSW, FAME, ABGW17.","heading":"KeyGen"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$ with multi-use parameter $\\tau$ (max attribute reuse), message $m$. Sample sharing vector $\\mathbf{v} = (s, v_2, \\ldots, v_{n_2})$ and per-slot randomness $s_1, \\ldots, s_\\tau\\leftarrow_R\\mathbb{Z}_p$. $$\\widetilde C = m\\cdot Y_\\alpha^s\\in\\mathbb{G}_T,\\quad C_{g,0} = g_2^s\\in\\mathbb{G}_2,\\quad C_{g,j} = g_2^{s_j}\\in\\mathbb{G}_2\\ \\text{for }j\\in[\\tau]$$ For each row $i\\in[n_1]$: assign a slot index $k_i\\in[\\tau]$ based on how many times $\\rho(i)$ has appeared so far in rows $[1..i-1]$; then $$C_i = g_1^{\\lambda_i}\\cdot H(\\rho(i))^{s_{k_i}}\\in\\mathbb{G}_1$$ CT size: $n_1\\cdot|\\mathbb{G}_1| + (\\tau+1)\\cdot|\\mathbb{G}_2| + 1\\cdot|\\mathbb{G}_T|$.","heading":"Encrypt"},{"content":"Reconstruct $\\{w_i\\}_{i\\in I}$ such that $\\sum w_i \\mathbf{M}_i = (1, 0, \\ldots, 0)$. Compute $$B = \\frac{e(K, C_{g,0})}{\\prod_i e(C_i, L)^{w_i}\\cdot\\prod_j e\\big(\\prod_{i:\\,k_i=j}K_{\\rho(i)}^{-w_i},\\ C_{g,j}\\big)}$$ The denominator uses $\\tau+1$ pairings (one per slot in $\\mathbb{G}_2$) plus the row-product pairing with $L$ — collapsing to $\\tau+2$ pairings total for CP-ABE decryption. At the standard one-use $\\tau=1$: 3 pairings.","heading":"Decrypt"}],"status":"solver_verified","subtitle":"CP-ABE · 2022","summary":"Current Pareto frontier for practical pairing CP-ABE: smallest SK and CT, fewest pairings (2–3), optimal security bound O(t^2/p) matching the discrete-log lower bound, native attribute multi-use, large universe. Proven in GGM + ROM.","title":"FABEO CP-ABE (Riepel–Wee)","type":"construction","venue":"CCS 2022","year":2022,"sourcePath":"data/abe-catalog.json#fabeo_cpabe"},{"evidence":"solver_verified","id":"fabeo_kpabe","keywords":["kp-abe","pairing","monotone_LSSS","GGM+ROM"],"metadata":{"assumption":{"bound":"O(t^2 / p), matches discrete-log lower bound","family":"GGM+ROM","name":"Generic bilinear group"},"authors":["Doreen Riepel","Hoeteck Wee"],"construction_one_liner":"KP-ABE dual of FABEO CP-ABE. Smallest SK and CT, τ+1 pairings (2 at τ=1), optimal O(t²/p) bound, native multi-use, large universe. Current Pareto frontier for practical KP-ABE.\n","decrypt_pairings":"tau+1","id":"fabeo_kpabe","implementations":["Charm","FABEO GitHub"],"name":"FABEO KP-ABE (Riepel–Wee)","ontology":{"assumption_deps":{"assumption_GGM":["enc_linear_no_inverse","proof_GGM_symbolic_PES"],"assumption_ROM":["attr_hash_ROM_G","proof_ROM_hash_idealization"]},"atoms":["attr_hash_ROM_G","policy_LSSS_monotone","lsss_multi_use_tau_slots","enc_linear_no_inverse","master_alpha_scalar_SK_linear","proof_GGM_symbolic_PES","proof_ROM_hash_idealization"],"connections":[{"from":"policy_LSSS_monotone.monotone_lsss","note":"raw LSSS gets the multi-use τ-slots decoration","to":"lsss_multi_use_tau_slots.lsss_in"},{"from":"lsss_multi_use_tau_slots.lsss_multi_use_out","note":"τ+1 G_1 sharing slots multiply SK rows (KP dual of CP-ABE's CT-side τ slots)","to":"enc_linear_no_inverse.policy_in"}],"features_provided":{"feature_adaptive_security":"proof_GGM_symbolic_PES","feature_large_universe":"attr_hash_ROM_G","feature_multi_use_policy":"lsss_multi_use_tau_slots","feature_type_III_pairing":"enc_linear_no_inverse"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2022/1415","sections_cited":["§4 KP-ABE scheme","Table 5 size comparison"],"url":"https://eprint.iacr.org/2022/1415","venue":"CCS 2022","year":2022},"pareto_notes":"Strictly dominates GPSW / FAME / ABGW17 on SK and CT at adaptive security. Single weak spot vs. KW19/LL20: GGM+ROM instead of k-Lin. Formalized in this repo (library/abe/formalizations/fabeo_kpabe.ggm).\n","policy":{"ROM_required":true,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":true},"primitive":"KP-ABE","security":{"mode":"adaptive","model":"GGM+ROM","notion":"CPA"},"sizes":{"CT":{"G1":"m","G2":"1","GT":"1","note":"m attribute elements in G_1, 1 top-level G_2, 1 GT blinder."},"MPK":{"G1":"1","G2":"1","GT":"1","note":"g_1, g_2, e(g_1,g_2)^alpha; H: {0,1}* -> G_1 in ROM. All O(1)."},"SK":{"G1":"n1","G2":"tau","note":"n_1 row elements in G_1; tau per-slot randomness in G_2. Dual of CP-ABE."},"sources":["FABEO §4 KP-ABE construction","FABEO Table 5 exact element counts"]},"variables":{"I":"rows used at decryption","m":"|S|, attribute set size in CT","n1":"LSSS matrix rows (policy size in SK)","tau":"multi-use parameter"},"verification":{"ggm_file":"library/abe/formalizations/fabeo_kpabe.ggm","status":"solver_verified"}},"primaryUrl":"https://eprint.iacr.org/2022/1415","sections":[{"content":"The KP-ABE dual of fabeo_cpabe.md. Same PES-with-multi-use structure, same large-universe ROM hash, same optimal $O(t^2/p)$ GGM+ROM bound. Sizes transpose: the LSSS policy is now in the key and produces $n_1$ $\\mathbb{G}_1$ elements plus $\\tau$ $\\mathbb{G}_2$ slot randomizers; the attribute set in the CT gives $m$ $\\mathbb{G}_1$ elements and 1 $\\mathbb{G}_2$ top-level element.","heading":"Intuition"},{"content":"MPK = $|\\mathbb{G}_1| + |\\mathbb{G}_2| + |\\mathbb{G}_T|$ + ROM hash. SK = $n_1\\cdot|\\mathbb{G}_1| + \\tau\\cdot|\\mathbb{G}_2|$. CT = $m\\cdot|\\mathbb{G}_1| + 1\\cdot|\\mathbb{G}_2| + 1\\cdot|\\mathbb{G}_T|$. Pairings: $\\tau+1$. At one-use $\\tau=1$: 2 pairings — the smallest of any practical adaptive KP-ABE.","heading":"Sizes summary (Table 5)"},{"content":"Input: LSSS $(\\mathbf{M},\\rho)$ with multi-use bound $\\tau$. Sample $r_j\\leftarrow_R\\mathbb{Z}_p$ for $j\\in[\\tau]$. For each row $i\\in[n_1]$ with slot $k_i\\in[\\tau]$ based on how often $\\rho(i)$ has appeared earlier: $$K_i = g_1^{\\lambda_i}\\cdot H(\\rho(i))^{r_{k_i}}\\in\\mathbb{G}_1$$ Plus $L_j = g_2^{r_j}\\in\\mathbb{G}_2$ for $j\\in[\\tau]$.","heading":"KeyGen"},{"content":"Input: attribute set $S$, message $M$. Sample $s\\leftarrow_R\\mathbb{Z}_p$. $$\\widetilde C = M\\cdot Y_\\alpha^s,\\quad C_0 = g_2^s\\in\\mathbb{G}_2,\\quad \\text{for each } \\tau\\in S:\\ C_\\tau = H(\\tau)^s\\cdot g_1^{\\text{(mixing term)}}$$ (Exact mixing term in §4 of the paper; matches the FABEO CP-ABE's dual structure.)","heading":"Encrypt"},{"content":"With reconstruction coefficients $\\{w_i\\}$: $$B = e(\\prod_i K_i^{w_i}\\cdot C_0^{-\\alpha'},\\ g_2^s)\\cdot\\prod_{j\\in[\\tau]}e(\\cdot, L_j)$$ collapsing to $\\tau+1$ pairings total. Recover $M = \\widetilde C / Y_\\alpha^s$.","heading":"Decrypt"}],"status":"solver_verified","subtitle":"KP-ABE · 2022","summary":"KP-ABE dual of FABEO CP-ABE. Smallest SK and CT, τ+1 pairings (2 at τ=1), optimal O(t²/p) bound, native multi-use, large universe. Current Pareto frontier for practical KP-ABE.","title":"FABEO KP-ABE (Riepel–Wee)","type":"construction","venue":"CCS 2022","year":2022,"sourcePath":"data/abe-catalog.json#fabeo_kpabe"},{"evidence":"deferred_scalar_pes","id":"glue22_cpabe","keywords":["cp-abe","pairing","monotone_LSSS","q-type","unbounded","flexible-efficiency-tradeoff","non-monotone-extension","online-offline","label-reuse"],"metadata":{"assumption":{"family":"q-type","name":"q-type pair-encoding instantiation"},"authors":["Marloes Venema","Greg Alpár"],"capabilities":["unbounded","flexible-efficiency-tradeoff","non-monotone-extension","online-offline","label-reuse"],"comparison":{"pareto_eligible":false,"reason":"GLUE is a parameterized efficiency surface in nk and nc; no benchmark point should be silently selected for the default Pareto query."},"construction":{"note":"Partitioned unbounded pair encoding from Definition 7; deferred until the compiler supports variable-sized row partitions.","schema":"other","schema_version":1},"construction_family":"pairing","construction_one_liner":"Generalized, large-universe, unbounded and expressive CP-ABE whose nk/nc partition parameters expose a flexible encryption/decryption trade-off and support non-monotone and online/offline extensions.\n","decrypt_cost":{"exponentiations":"2I","note":"Changing nk and nc shifts work between key generation, encryption, and decryption.","pairings":"2+ceil(I/nk)+ceil(I/nc)","primary":"2 + ceil(I/nk) + ceil(I/nc) pairings"},"decrypt_pairings":"2+ceil(I/nk)+ceil(I/nc)","id":"glue22_cpabe","name":"GLUE CP-ABE","pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2022/613","sections_cited":["Table 1","Table 2","§4 Definition 6","§4.1 Definition 7 and Theorem 1"],"url":"https://eprint.iacr.org/2022/613","venue":"IACR ePrint 2022","year":2022},"pareto_notes":"No single GLUE parameter point dominates: the construction is a tunable surface. This row records formulas in nk and nc instead of choosing an arbitrary benchmark point.","policy":{"ROM_required":false,"class":"monotone_LSSS","large_universe":true,"multi_use_attributes":true},"primitive":"CP-ABE","security":{"mode":"adaptive","model":"standard","notion":"CPA","qualifier":"The symbolic property supports a fully secure AC17-style instantiation; the paper also gives a selective instantiation."},"sizes":{"CT":{"G1":"1+2*n1+mct","GT":"1","note":"mct = max(ceil(n1/nc), tau) ciphertext partitions."},"MPK":{"G1":"nk+2*nc","G2":"1","GT":"1","note":"Partition parameters nk and nc are selected at setup."},"MSK":{"Zp":"nk+2*nc+1"},"SK":{"G2":"2+m+mkey","note":"mkey = ceil(m/nk) key partitions."},"sources":["GLUE §4 Definition 6","GLUE Table 2"]},"variables":{"I":"number of matching rows used in decryption","m":"number of attributes in the secret key","mct":"max(ceil(n1/nc), tau), number of ciphertext partitions","mkey":"ceil(m/nk), number of key partitions","n1":"number of LSSS rows in the ciphertext policy","nc":"maximum ciphertext-partition size selected at setup","nk":"maximum key-partition size selected at setup","tau":"maximum number of occurrences of one policy label"},"verification":{"blocker":"partitioned_multi_use_pes_not_normalized","ggm_file":null,"note":"The paper supplies an associated PES, but its partitioned multi-use families have not yet been encoded in the repository's scalar grammar.","status":"deferred_scalar_pes"}},"primaryUrl":"https://eprint.iacr.org/2022/613","sections":[{"content":"GLUE partitions repeated attributes on the key and ciphertext sides. Two setup parameters control how much polynomial material is placed in each partition, allowing an application to move work between encryption and decryption.","heading":"Intuition"},{"content":"Setup chooses asymmetric pairing groups, the master exponent, and polynomial coefficients determined by nk and nc. The public key is independent of the attribute universe and policy size.","heading":"Setup"},{"content":"The attribute set is divided into key partitions of size at most nk. Each attribute receives a polynomial evaluation component, while each partition receives one shared randomizer component.","heading":"KeyGen"},{"content":"LSSS rows are assigned to ciphertext partitions of size at most nc, with repeated labels placed in distinct partitions. Each row has two components and each partition has one shared component.","heading":"Encrypt"},{"content":"Matching row terms are aggregated within their key and ciphertext partitions. The average pairing cost is 2 + ceil(I/nk) + ceil(I/nc), exposing the main trade-off directly.","heading":"Decrypt"}],"status":"deferred_scalar_pes","subtitle":"CP-ABE · 2022","summary":"Generalized, large-universe, unbounded and expressive CP-ABE whose nk/nc partition parameters expose a flexible encryption/decryption trade-off and support non-monotone and online/offline extensions.","title":"GLUE CP-ABE","type":"construction","venue":"IACR ePrint 2022","year":2022,"sourcePath":"data/abe-catalog.json#glue22_cpabe"},{"evidence":"blocked_hybrid","id":"lll22_cpabe","keywords":["cp-abe","hybrid","NC1","hybrid"],"metadata":{"assumption":{"family":"hybrid","name":"LWE + Generic bilinear group (hybrid)"},"authors":["Hanjun Li","Huijia Lin","Ji Luo"],"construction_one_liner":"First \"doubly succinct\" ABE: constant-size SK (3 group elements) AND policy-size-independent CT. Combines lattice (BGG+-style) attribute evaluation with pairing (GGM) compression of the short-preimage key.\n","decrypt_pairings":"O(1)","id":"lll22_cpabe","name":"Li–Lin–Luo \"Doubly Succinct\" CP-ABE for Formulas (hybrid)","ontology":{"assumption_deps":{"assumption_GGM":["subprim_pairing_group_compression_GGM","proof_GGM_symbolic_PES"],"assumption_LWE":["subprim_BGG_plus_circuit_eval","subprim_lattice_trapdoor","proof_LWE_reduction"],"assumption_SIS":["subprim_lattice_trapdoor"],"pairing_IPFE_G2_layer_exposed_TBD":["view: ipfe_ciphertext[d] → G2_vector[d] (TBD soundness)"],"pairing_projection_vectors_fixed":["view: short_lattice_vector → G1_vector[3]"]},"atoms":["attr_binary_vector","policy_NC1_formula","policy_circuit_bounded_depth","subprim_BGG_plus_circuit_eval","subprim_lattice_trapdoor","subprim_pairing_group_compression_GGM","master_in_IPFE_slot","proof_LWE_reduction","proof_GGM_symbolic_PES"],"connections":[{"from":"attr_binary_vector.attribute_x","to":"subprim_BGG_plus_circuit_eval.attribute_x"},{"from":"policy_circuit_bounded_depth.circuit_policy","note":"NC1 formula → bounded-depth circuit → BGG+ eval","to":"subprim_BGG_plus_circuit_eval.circuit_f"},{"from":"subprim_BGG_plus_circuit_eval.evaluated_A_f","to":"subprim_lattice_trapdoor.target_matrix"},{"from":"subprim_lattice_trapdoor.preimage_r","to":"subprim_pairing_group_compression_GGM.compressed_input","via_view":"short_lattice_vector[m_total] → G1_vector[3] under GGM"},{"from":"master_in_IPFE_slot.encoded_in_ipfe_ct","to":"subprim_pairing_group_compression_GGM.pairing_ct_component","via_view":"ipfe_ciphertext[d] → G2_vector[d] under pairing_IPFE_G2_layer_exposed_TBD"}],"features_provided":{"feature_constant_SK":"subprim_pairing_group_compression_GGM","feature_selective_security":"proof_LWE_reduction"},"notes":"\"Doubly succinct\" = constant SK AND policy-size-independent CT (a\nPareto corner unreachable from pure pairing).  Same modeling gap as\nLLL22 KP on the pairing-side IPFE wiring; type_check will report it\nas 1 advisory error."},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2022/659","sections_cited":["Construction 2 (CP-ABE for Boolean formulas)"],"url":"https://eprint.iacr.org/2022/659","venue":"TCC 2022","year":2022},"pareto_notes":"Sits at an extreme Pareto corner (constant SK + succinct CT) that no pure pairing scheme reaches. The price: LWE+GGM hybrid assumption, selective security baseline. Policy class is Boolean formulas (NC1), not yet circuits — the paper's companion KP-ABE (Construction 1) does circuits with constant SK.\n","policy":{"ROM_required":false,"class":"NC1","large_universe":false,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"selective","model":"GGM+LWE","notion":"CPA"},"sizes":{"CT":{"G1":"poly(U,lam)","note":"Linear in attribute length U, policy-size-INDEPENDENT. 'Double succinct' claim. U = |x| = attribute length."},"MPK":{"G1":"poly(lam,d)","note":"Lattice matrices (poly in depth d and security parameter). lam = security parameter (renamed from 'lambda' which is a Python keyword)."},"SK":{"G1":"3","note":"LITERALLY 3 GROUP ELEMENTS, independent of circuit/formula size. Hybrid lattice–pairing compression."},"sources":["Li–Lin–Luo TCC 2022 Construction 2 (CP-ABE for Boolean formulas)","Paper title + abstract: 'constant-size secret keys and adaptive security'"]},"variables":{"U":"attribute length |x|","d":"formula depth (a-priori bound)","lambda":"security parameter"},"verification":{"blocker":"lattice_hybrid","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2022/659","sections":[{"content":"The Li–Lin–Luo paper gives two ABE schemes. Construction 1 is a KP-ABE for bounded-depth circuits with 3-element SK. Construction 2 (this spec) is the CP-ABE analogue for Boolean formulas (NC1), which is \"doubly succinct\": both SK constant *and* CT policy-size-independent. The compression trick is hybrid: the lattice side (BGG+14-style attribute encodings + key-homomorphic evaluation) carries the policy computation; the pairing side (in the generic group model) *compresses* what would otherwise be a lattice short-preimage vector of length $\\mathrm{poly}(d,\\lambda)$ into 3 pairing group elements. Decryption runs BGG+-style homomorphic evaluation on LWE ciphertexts down to $f(x)$, then pairs against the 3-element $\\mathrm{sk}_f$ to recover the plaintext blinder.","heading":"Intuition"},{"content":"MPK: lattice trapdoor matrix $\\mathbf{A}$ and attribute-evaluation matrices $\\mathbf{B}_1, \\ldots, \\mathbf{B}_\\ell$ (BGG+14-style), each $\\mathrm{poly}(d, \\lambda)$ in size; plus a constant number of pairing elements used as a \"compression key\". KeyGen($f$): use the lattice trapdoor to derive a short preimage for the BGG+-evaluated matrix $\\mathbf{A}_f$; encode the (otherwise long) preimage into 3 pairing group elements via an algebraic compression that is only secure in GGM. Encrypt($\\mathbf{x}, \\mu$): LWE encoding of each bit of $\\mathbf{x}$ plus a pairing component carrying a blinder of $\\mu$. CT size is $O(|\\mathbf{x}|\\cdot\\mathrm{poly}(\\lambda))$ — no dependence on the formula that will be used in the key. Decrypt: homomorphically evaluate $f(\\mathbf{x}) = 1$ on the LWE ciphertext to produce a single LWE sample under $\\mathbf{A}_f$; pair this against $\\mathrm{sk}_f$ (3 group elements) to unmask $\\mu$.","heading":"Sketch"},{"content":"MPK: $\\mathrm{poly}(d, \\lambda, |\\mathcal{U}|)$ lattice elements + $O(1)$ pairing elements. SK: 3 group elements, independent of formula depth, size, or attribute length. CT: $O(|\\mathbf{x}|\\cdot\\mathrm{poly}(\\lambda, d))$ — grows with attribute length only, policy-size independent. Decryption: dominated by the lattice evaluation; $O(1)$ pairings at the end.","heading":"Sizes"}],"status":"blocked_hybrid","subtitle":"CP-ABE · 2022","summary":"First \"doubly succinct\" ABE: constant-size SK (3 group elements) AND policy-size-independent CT. Combines lattice (BGG+-style) attribute evaluation with pairing (GGM) compression of the short-preimage key.","title":"Li–Lin–Luo \"Doubly Succinct\" CP-ABE for Formulas (hybrid)","type":"construction","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#lll22_cpabe"},{"evidence":"blocked_hybrid","id":"lll22_kpabe","keywords":["kp-abe","hybrid","circuit","hybrid"],"metadata":{"assumption":{"family":"hybrid","name":"LWE + Generic bilinear group (hybrid)"},"authors":["Hanjun Li","Huijia Lin","Ji Luo"],"construction_one_liner":"First KP-ABE for BOUNDED-DEPTH CIRCUITS with constant-size (3-element) secret keys. Hybrid lattice + pairing (GGM) construction: BGG+-style circuit evaluation on LWE ciphertexts, pairing compresses the lattice short preimage into 3 group elements.\n","decrypt_pairings":"O(1)","id":"lll22_kpabe","name":"Li–Lin–Luo KP-ABE for Circuits (constant SK, hybrid)","ontology":{"assumption_deps":{"assumption_GGM":["subprim_pairing_group_compression_GGM","proof_GGM_symbolic_PES"],"assumption_LWE":["subprim_BGG_plus_circuit_eval","subprim_lattice_trapdoor","proof_LWE_reduction"],"assumption_SIS":["subprim_lattice_trapdoor"],"pairing_IPFE_G2_layer_exposed_TBD":["view: ipfe_ciphertext[d] → G2_vector[d] (TBD soundness)"],"pairing_projection_vectors_fixed":["view: short_lattice_vector → G1_vector[3]"]},"atoms":["attr_binary_vector","policy_circuit_bounded_depth","subprim_BGG_plus_circuit_eval","subprim_lattice_trapdoor","subprim_pairing_group_compression_GGM","master_in_IPFE_slot","proof_LWE_reduction","proof_GGM_symbolic_PES"],"connections":[{"from":"attr_binary_vector.attribute_x","to":"subprim_BGG_plus_circuit_eval.attribute_x"},{"from":"policy_circuit_bounded_depth.circuit_policy","to":"subprim_BGG_plus_circuit_eval.circuit_f"},{"from":"subprim_BGG_plus_circuit_eval.evaluated_A_f","to":"subprim_lattice_trapdoor.target_matrix"},{"from":"subprim_lattice_trapdoor.preimage_r","note":"LLL22's compression: r is projected against fixed v_1, v_2, v_3 to\ngive 3 G_1 exponents.  Sound under GGM; pays GGM in scheme's deps.\n","to":"subprim_pairing_group_compression_GGM.compressed_input","via_view":"short_lattice_vector[m_total] → G1_vector[3] under GGM"},{"from":"master_in_IPFE_slot.encoded_in_ipfe_ct","note":"Master µ encoded into an IPFE ciphertext slot; the pairing layer\nof that ciphertext IS the G_2 vector that the GGM compression\natom pairs against the SK G_1 vector.  Soundness of treating\nipfe_ct as bare G_2 elements is pending review.\n","to":"subprim_pairing_group_compression_GGM.pairing_ct_component","via_view":"ipfe_ciphertext[d] → G2_vector[d] under pairing_IPFE_G2_layer_exposed_TBD"}],"features_provided":{"feature_circuit_support":"subprim_BGG_plus_circuit_eval","feature_constant_SK":"subprim_pairing_group_compression_GGM","feature_selective_security":"proof_LWE_reduction"}},"pairing":{"original_type":"III","type_III_port":[]},"paper":{"eprint":"2022/659","sections_cited":["Construction 1 (KP-ABE for circuits)"],"url":"https://eprint.iacr.org/2022/659","venue":"TCC 2022","year":2022},"pareto_notes":"Removes the poly(d, λ) SK dependence of BGG+14 / GVW13 lattice ABE. Only 3-group-element SK for any circuit size under bounded depth d. Pairs with the \"doubly succinct\" CP-ABE for formulas in the same paper.\n","policy":{"ROM_required":false,"class":"circuit","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"GGM+LWE","notion":"CPA"},"sizes":{"CT":{"G1":"poly(U,d,lam)","GT":"1","note":"Linear in attribute length |x| = U, polynomial in circuit depth d."},"MPK":{"G1":"poly(lam,d)","note":"Lattice trapdoor matrix + BGG+-style per-attribute matrices + O(1) pairing material. lam = security parameter."},"SK":{"G1":"3","note":"LITERALLY 3 GROUP ELEMENTS for any circuit of bounded depth d. Pairing-side compression of lattice short preimage."},"sources":["Li–Lin–Luo TCC 2022 Construction 1 (KP-ABE for circuits)","Paper title: 'ABE for Circuits with Constant-Size Secret Keys'"]},"variables":{"U":"attribute-vector length (= |x|)","d":"circuit depth (a-priori bounded at setup)","lambda":"security parameter"},"verification":{"blocker":"lattice_hybrid","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2022/659","sections":[{"content":"The paper's main construction: a KP-ABE for bounded-depth Boolean circuits with constant-size secret keys — literally 3 group elements, independent of the circuit. This is a dramatic improvement over prior lattice-based KP-ABE for circuits (GVW13, BGG+14), where SK size scales as $\\mathrm{poly}(d, \\lambda)$. The trick is hybrid. The lattice side (BGG+14-style attribute evaluation) carries the circuit computation: each attribute bit is encoded as an LWE ciphertext under a designated matrix $\\mathbf{B}_i$; decryption homomorphically evaluates the circuit down to a single LWE sample under the $f$-evaluated matrix $\\mathbf{A}_f$. The pairing side (in the generic group model) compresses what would otherwise be a lattice short-preimage vector of length $\\mathrm{poly}(d,\\lambda)$ into 3 pairing group elements. Decryption pairs the 3-element SK against the homomorphically-evaluated LWE sample to unmask the plaintext.","heading":"Intuition"},{"content":"Setup: sample lattice trapdoor $(\\mathbf{A}, \\mathbf{T}_{\\mathbf{A}})$ and BGG+ matrices $\\{\\mathbf{B}_i\\}_{i\\in[\\ell]}$ for each input bit (each $\\mathrm{poly}(d,\\lambda)$ in size). Sample pairing-group generators and a small set of compression material. KeyGen($f$): use the lattice trapdoor to derive a short preimage $\\mathbf{r}_f$ for the circuit-evaluated matrix $\\mathbf{A}_f$. Compress $\\mathbf{r}_f$ into 3 pairing group elements $\\mathrm{sk}_f = (s_1, s_2, s_3)$ via algebraic compression that is only secure in GGM. Encrypt($\\mathbf{x}, \\mu$): for each input bit $x_i$, produce a BGG+ LWE ciphertext under $\\mathbf{B}_i + x_i\\mathbf{G}$ where $\\mathbf{G}$ is the gadget matrix. Add a pairing-group blinder on $\\mu$. Decrypt: homomorphically evaluate $f$ on the LWE ciphertexts to get a single LWE sample under $\\mathbf{A}_f$. Pair this against $\\mathrm{sk}_f$ (just the 3 elements) to recover the pairing-group blinder and unmask $\\mu$.","heading":"Sketch"},{"content":"MPK: $\\mathrm{poly}(d, \\lambda, U)$ lattice elements + $O(1)$ pairing material. SK: 3 group elements, constant in circuit size and depth. CT: $O(U\\cdot\\mathrm{poly}(d, \\lambda))$ lattice elements + $O(1)$ pairing elements. Decryption: dominated by BGG+ homomorphic evaluation on LWE; $O(1)$ pairings at the end.","heading":"Sizes"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2022","summary":"First KP-ABE for BOUNDED-DEPTH CIRCUITS with constant-size (3-element) secret keys. Hybrid lattice + pairing (GGM) construction: BGG+-style circuit evaluation on LWE ciphertexts, pairing compresses the lattice short preimage into 3 group elements.","title":"Li–Lin–Luo KP-ABE for Circuits (constant SK, hybrid)","type":"construction","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#lll22_kpabe"},{"evidence":"blocked_hybrid","id":"hll24","keywords":["kp-abe","lattice","circuit","hybrid"],"metadata":{"assumption":{"family":"hybrid","name":"LWE + evasive LWE"},"authors":["Yao-Ching Hsieh","Huijia Lin","Ji Luo"],"construction":{"note":"Pure-lattice scheme; no PES polynomials.  HLL24's general framework\n(Construction 5): given (i) a noisy linear garbling scheme NLG for a\nfunction class F and (ii) an identity-based evasive IPFE, you get\nCP-ABE for F.  Specific instantiations:\n- §6 NLG for circuits (own construction) → generic CP-ABE for circuits\n- §7 NLG for DFA (Construction 6, adapted from LL20a/Wat12) → DFA ABE\n- §8 NLG via BGG+14 garbling (Construction 9) → succinct CP-ABE for\n  circuits (the headline result vs Wee22, eliminating tensor LWE)\n","schema":"hybrid_lattice","schema_version":1},"construction_one_liner":"General framework for lattice ABE: noisy linear garbling for class F + evasive IPFE → KP/CP-ABE for F.  Yields succinct CP-ABE for circuits (eliminating tensor LWE), and the first lattice public-key ABE for uniform computation (DFA + logspace TM).\n","decrypt_pairings":"0","id":"hll24","name":"Hsieh–Lin–Luo lattice ABE framework via evasive IPFE","ontology":{"assumption_deps":{"FE_correctness":["join: evasive_IPFE_evaluation"],"assumption_LWE":["subprim_BGG_plus_circuit_eval","subprim_noisy_LSSS"],"assumption_evasive_LWE":["subprim_evasive_IPFE","proof_evasive_LWE_reduction"],"noise_budget_bounded":["join: evasive_IPFE_evaluation"]},"atoms":["attr_binary_vector","policy_circuit_bounded_depth","policy_DFA_uniform","policy_logspace_TM_uniform","subprim_BGG_plus_circuit_eval","subprim_noisy_LSSS","subprim_evasive_IPFE","master_mu_bit_LWE","proof_evasive_LWE_reduction"],"connections":[{"from":"attr_binary_vector.attribute_x","note":"for §8 succinct: BGG+ garbling consumes attribute","to":"subprim_BGG_plus_circuit_eval.attribute_x"},{"from":"policy_circuit_bounded_depth.circuit_policy","note":"for §8 succinct: BGG+ garbling consumes circuit","to":"subprim_BGG_plus_circuit_eval.circuit_f"}],"features_provided":{"feature_circuit_support":"subprim_BGG_plus_circuit_eval","feature_selective_security":"proof_evasive_LWE_reduction","feature_uniform_computation":"policy_DFA_uniform"},"joins_used":["evasive_IPFE_evaluation"],"notes":"Modeling caveats for v0.4-v0.6:\n\n1. **Three constructions in one spec**.  Real paper has §6 generic\n   CP-ABE, §7 DFA/logspace, §8 succinct CP-ABE.  This spec captures\n   the umbrella; future Tier 2 work could split into\n   hll24_cpabe_circuits / hll24_cpabe_dfa / hll24_cpabe_succinct etc.\n2. **§8 instantiates noisy_LSSS via BGG+** — both atoms in the list,\n   but in §8 they're the same piece (BGG+ IS the noisy garbling).\n   The atom-graph doesn't currently express \"X instantiates Y\";\n   both atoms appear independently.\n3. **No KP-ABE atom modeled separately** — HLL24 has KP-ABE for circuits\n   too (§6 dual) and KP for DFA (§7).  Per primitive: in spec frontmatter\n   I list KP-ABE but the construction details cover both directions.\n4. **Adaptive variants** are NOT in this paper (selective only) — Wee\n   and follow-ups address adaptive.\n","open_questions":["Does HLL24 §8 succinct CP-ABE deserve `feature_constant_CT`? It's poly(λ, d) — succinct in depth, not literally constant in λ. Different from Wee24/25 succinct_LWE_compression which gives O(λ). Backlog: introduce a `feature_succinct_CT_in_depth` if needed.","Should `subprim_noisy_LSSS` split into per-function-class atoms (subprim_noisy_LSSS_for_circuits, _for_DFA, _for_logspace_TM)? Currently monolithic per granularity rule; would split if a second paper used noisy LSSS for one class but not others."]},"pairing":{"original_type":"none","type_III_port":[]},"paper":{"eprint":"2024/821","sections_cited":["§3 Evasive Inner-Product Functional Encryption","§5 Noisy Linear Garbling for Circuits","§6 CP-ABE from Short Noisy Linear Garbling (Construction 5)","§7 ABE for DFA (Construction 8)","§8 CP-ABE with Succinct Ciphertexts (Constructions 9, 10)"],"url":"https://eprint.iacr.org/2024/821","venue":"Eurocrypt 2024","year":2024},"pareto_notes":"Headline: succinct CP-ABE for circuits with |ct| = poly(λ, depth) only, removing tensor LWE assumption from Wee22.  Plus first public-key lattice ABE for DFA / logspace TM.  Selective security only.\n","policy":{"ROM_required":false,"class":"circuit","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"note":"§6: (|C|+1)·poly(λ,log M,d) — linear in CIRCUIT SIZE; §8: poly(λ,log M,d) only — succinct in DEPTH; §7: (|x|+1)·poly(λ) for DFA-CP."},"MPK":{"note":"poly(λ, log M, d) for circuits; poly(λ) for DFA. M is intermediate-value bound, d is depth."},"SK":{"note":"(|x|+1)·poly(λ,log M,d) for §6 generic; constant-poly(λ) for §8 succinct CP-ABE; (|x|+1)·poly(λ) for §7 DFA-CP."},"abstraction_note":"HLL24 contains MULTIPLE constructions with different size profiles.\nThe headline (eliminating tensor LWE vs Wee22) is the §8 succinct\nCP-ABE for circuits, where ct depends on circuit DEPTH only (via\nBGG+14 garbling instantiation).\n","sources":["HLL24 Corollary 21 (generic CP-ABE, §6)","HLL24 Corollary 29 (DFA, §7)","HLL24 Corollary 34 (succinct CP-ABE for circuits, §8 — sizes implied)"]},"variables":{"L":"attribute bit-length (or DFA input length)","M":"intermediate-value magnitude bound for arithmetic circuits","d":"circuit depth bound (for §6, §8)","lam":"security parameter","|C|":"circuit size (only matters for §6 generic; §8 succinct has no |C| term)","|x|":"attribute weight / set size (for KP-ABE)","|Γ|":"DFA size (number of states)"},"verification":{"blocker":"lattice_only_evasive_LWE","ggm_file":null,"note":"Pure lattice scheme; no pairing operations, so neither\nggm-symbolic-solver nor gga-unbounded apply.  The non-falsifiable\nevasive LWE assumption is also outside the scope of any verifier\nin this repo.  The `ontology:` block captures the structural\ndecomposition; construction details are documented in prose only.\n","status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2024/821","sections":[{"content":"HLL24 (Eurocrypt 2024) is a general framework for constructing lattice-based ABE schemes, reducing the task to constructing a noisy linear garbling scheme (NLG) for the desired function class. The lifting from NLG to ABE is done by a new primitive: identity-based evasive inner-product functional encryption (evasive IPFE) under evasive LWE. The paper's central insight: standard pairing-based ABE (LL20a, LL20b) can be obtained from pairing-based IPFE + a (noiseless) linear secret sharing scheme. HLL24's lattice counterpart uses evasive IPFE + a noisy LSSS, with noise growth carefully bounded to enable correctness via flooding.","heading":"Intuition"},{"content":"Given: A noisy linear garbling scheme NLG for function class $F$ (e.g., circuits or DFAs) An identity-based evasive IPFE scheme Construction 5 gives a CP-ABE for $F$ as follows. Setup samples NLG parameters and IPFE keys. KeyGen samples random vectors $\\mathbf{r}, \\mathbf{v}_0, \\mathbf{v}_\\ell$ and IPFE-encrypts them as secret keys $\\mathrm{isk}_0, \\mathrm{isk}_\\ell$. Encrypt generates an NLG instance for the policy $f$, samples a random matrix $\\mathbf{S}$ and message scalar $s_{\\mathrm{msg}}$, and produces IPFE ciphertexts $\\mathrm{ict}_{\\mathrm{msg}}, \\mathrm{ict}_t, \\mathrm{ict}_\\ell$ encrypting the appropriate vectors. Decrypt runs IPFE decryption to recover $w_{\\mathrm{msg}}, \\mathbf{t}, \\mathbf{w}_\\ell$, then evaluates the NLG to recover $w_{\\mathrm{out}}$. The bit $\\mu$ is recovered by checking whether $w_{\\mathrm{msg}} - w_{\\mathrm{out}}$ is small.","heading":"The framework (Construction 5, §6)"},{"content":"| Section | Construction | NLG instantiation | Property | |---|---|---|---| | §5/§6 | Construction 5 | Own NLG for circuits | Generic; CT linear in $\\|C\\|$ | | §7 | Construction 8 | DFA garbling (Construction 6, adapted from LL20a/Wat12) | First public-key lattice ABE for DFA + logspace TMs | | §8 | Construction 10 | NLG via BGG+14 garbling (Construction 9) | Succinct: CT poly($\\lambda, d$) only — eliminates tensor LWE vs Wee22 |","heading":"Three concrete instantiations"},{"content":"Generic CP-ABE for circuits (Corollary 21): $|\\mathrm{mpk}| = \\mathrm{poly}(\\lambda, \\log M, d)$, $|\\mathrm{sk}_x| = (|x|+1)\\,\\mathrm{poly}(\\cdot)$, $|\\mathrm{ct}_C| = (|C|+1)\\,\\mathrm{poly}(\\cdot)$. CT is linear in CIRCUIT SIZE. DFA CP-ABE (Corollary 29): $|\\mathrm{mpk}| = \\mathrm{poly}(\\lambda)$, $|\\mathrm{sk}_x| = (|x|+1)\\,\\mathrm{poly}(\\lambda)$, $|\\mathrm{ct}_\\Gamma| = (|\\Gamma|+1)\\,\\mathrm{poly}(\\lambda)$. Succinct CP-ABE for circuits (§8): all three quantities $\\mathrm{poly}(\\lambda, \\log M, d)$ — NO dependence on $|C|$. This is the headline result that beats Wee22 by removing tensor LWE.","heading":"Sizes"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2024","summary":"General framework for lattice ABE: noisy linear garbling for class F + evasive IPFE → KP/CP-ABE for F. Yields succinct CP-ABE for circuits (eliminating tensor LWE), and the first lattice public-key ABE for uniform computation (DFA + logspace TM).","title":"Hsieh–Lin–Luo lattice ABE framework via evasive IPFE","type":"construction","venue":"Eurocrypt 2024","year":2024,"sourcePath":"data/abe-catalog.json#hll24"},{"evidence":"blocked_hybrid","id":"sb25_nonlinear_kpabe","keywords":["kp-abe","lattice","arithmetic_circuit","LWE","nonlinear-operations","lookup-tables","arithmetic-circuits","post-quantum"],"metadata":{"assumption":{"family":"LWE","name":"Ring-LWE"},"authors":["Sora Suegami","Enrico Bottazzi"],"capabilities":["nonlinear-operations","lookup-tables","arithmetic-circuits","post-quantum"],"comparison":{"pareto_eligible":false,"reason":"Ring-LWE bit and polynomial costs are not normalized to pairing-group elements, and the base B is an explicit trade-off parameter."},"construction":{"note":"Ring-BGG+ key-homomorphic encodings augmented with base-B lookup-table evaluation for nonlinear operations.","schema":"hybrid_lattice","schema_version":1},"construction_family":"lattice","construction_one_liner":"Ring-LWE KP-ABE for modulo-q arithmetic circuits that evaluates nonlinear lookup tables directly over BGG+ encodings, trading larger keys and KeyGen cost for faster repeated decryption.\n","decrypt_cost":{"note":"Larger B reduces repeated decryption work but increases key generation and key size by a polynomial-in-B factor.","pairings":"0","primary":"Õ(N · poly(λ,D)² / log₂B) lattice evaluation"},"decrypt_pairings":"0","id":"sb25_nonlinear_kpabe","name":"Suegami–Bottazzi KP-ABE for Nonlinear Operations","pairing":{"original_type":"none","type_III_port":[]},"paper":{"eprint":"2025/1870","sections_cited":["Table 1","§1.2 technical overview","§5 KP-ABE","Theorem 5"],"url":"https://eprint.iacr.org/2025/1870","venue":"IACR ePrint 2025","year":2025},"pareto_notes":"Adds a new nonlinear-operation axis rather than strictly dominating Boolean or arithmetic predecessors; the base B must remain visible in comparisons.","policy":{"ROM_required":false,"class":"arithmetic_circuit","large_universe":false,"multi_use_attributes":false},"primitive":"KP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"asymptotic":"Õ(L · poly(D) / log₂B)","note":"Compatible with base-B lookup-table evaluation."},"MPK":{"asymptotic":"Õ(L · poly(D) / log₂B)","note":"Amortized expression; poly(lambda) and polylog(lambda,D) factors are hidden."},"SK":{"asymptotic":"Õ(B²N · poly(D) / (log₂B)²)","note":"Decryption-key size grows polynomially in the lookup-table base B."},"sources":["SB25 Table 1"]},"variables":{"B":"lookup-table digit base, with B squared smaller than q","D":"arithmetic-circuit depth","L":"arithmetic-circuit input length","N":"arithmetic-circuit size","lam":"security parameter","q":"ciphertext modulus"},"verification":{"blocker":"lattice_only_ring_lwe","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2025/1870","sections":[{"content":"Instead of decomposing every large integer into bits, the construction works with base-B digits and evaluates lookup tables whose noise growth is independent of the encoded integer magnitude.","heading":"Intuition"},{"content":"Setup instantiates Ring-LWE BGG+ encodings and publishes the matrices required for key-homomorphic arithmetic and lookup-table evaluation.","heading":"Setup"},{"content":"The authority evaluates the arithmetic policy over the public encodings and produces a decryption key enlarged by the base-B lookup-table machinery.","heading":"KeyGen"},{"content":"The attribute vector is encoded under the Ring-LWE public matrices in a form compatible with direct base-B evaluation.","heading":"Encrypt"},{"content":"The decryptor evaluates the policy and its nonlinear lookup tables over the ciphertext encodings, then applies lattice rounding. Increasing B reduces the number of digit levels traversed during this repeated operation.","heading":"Decrypt"}],"status":"blocked_hybrid","subtitle":"KP-ABE · 2025","summary":"Ring-LWE KP-ABE for modulo-q arithmetic circuits that evaluates nonlinear lookup tables directly over BGG+ encodings, trading larger keys and KeyGen cost for faster repeated decryption.","title":"Suegami–Bottazzi KP-ABE for Nonlinear Operations","type":"construction","venue":"IACR ePrint 2025","year":2025,"sourcePath":"data/abe-catalog.json#sb25_nonlinear_kpabe"},{"evidence":"blocked_hybrid","id":"lzf26_constant_ct_cpabe","keywords":["cp-abe","lattice","NC1","succinct-LWE","constant-ciphertext","nc1","post-quantum","broadcast-encryption"],"metadata":{"assumption":{"family":"succinct-LWE","name":"poly(lambda)-succinct LWE"},"authors":["Jiaqi Liu","Yuanyi Zhang","Fang-Wei Fu"],"capabilities":["constant-ciphertext","nc1","post-quantum","broadcast-encryption"],"comparison":{"pareto_eligible":false,"reason":"The O(1) claim hides poly(lambda) lattice dimensions and cannot be treated as zero pairing-group elements."},"construction":{"note":"Succinct-LWE CP-ABE using LSSS reconstruction and a matrix-commitment compression layer to remove policy dimensions from the ciphertext.","schema":"hybrid_lattice","schema_version":1},"construction_family":"lattice","construction_one_liner":"Selectively secure lattice CP-ABE for NC1 with ciphertext size poly(lambda), independent of circuit size, input length, and depth.\n","decrypt_cost":{"note":"The headline contribution is ciphertext size; the source does not reduce the result to a pairing-equivalent cost.","pairings":"0","primary":"lattice reconstruction + rounding"},"decrypt_pairings":"0","id":"lzf26_constant_ct_cpabe","name":"Liu–Zhang–Fu Constant-Ciphertext CP-ABE for NC1","pairing":{"original_type":"none","type_III_port":[]},"paper":{"eprint":"2026/534","sections_cited":["§1 contributions","Construction 1","Theorem 17","Theorem 18"],"url":"https://eprint.iacr.org/2026/534","venue":"IACR ePrint 2026","year":2026},"pareto_notes":"Establishes the constant-ciphertext endpoint under poly(lambda)-succinct LWE; public parameters initially grow with circuit size but their uniform portion can be compressed with a PRG.","policy":{"ROM_required":false,"class":"NC1","large_universe":false,"multi_use_attributes":false},"primitive":"CP-ABE","security":{"mode":"selective","model":"standard","notion":"CPA"},"sizes":{"CT":{"asymptotic":"O(poly(λ))","note":"Independent of circuit size s, input length ell, and depth d."},"MPK":{"asymptotic":"O(s · poly(λ))","note":"The uniformly random portion can be PRG-generated, yielding O(poly(lambda)) stored public parameters."},"SK":{"asymptotic":"O(ℓ · poly(λ))","note":"The finer bound depends on the number of attributes held by the user."},"sources":["LZF26 §1 contribution 1"]},"variables":{"d":"NC1 circuit depth","ell":"attribute input length","lam":"security parameter","s":"NC1 circuit size"},"verification":{"blocker":"lattice_only_succinct_lwe","ggm_file":null,"status":"blocked_hybrid"}},"primaryUrl":"https://eprint.iacr.org/2026/534","sections":[{"content":"The construction begins from a lattice LSSS-style CP-ABE whose ciphertext would expose one component per policy row, then uses a matrix commitment to compress those row-dependent values into a constant number of lattice objects.","heading":"Intuition"},{"content":"Setup fixes the NC1 input length and supported circuit parameters, publishes succinct-LWE material and the matrix-commitment parameters, and retains the corresponding trapdoor information.","heading":"Setup"},{"content":"A user's attribute vector is encoded into a lattice key. Key size is linear in the input length in the worst case and can be smaller for sparse attribute sets.","heading":"KeyGen"},{"content":"The encryptor represents the NC1 access policy as an LSSS and commits to the row-dependent lattice material. The opening information is compressed so the ciphertext no longer grows with the policy.","heading":"Encrypt"},{"content":"Authorized attributes supply LSSS reconstruction coefficients. The decryptor combines the committed lattice values, removes the LWE mask, and rounds to the message.","heading":"Decrypt"}],"status":"blocked_hybrid","subtitle":"CP-ABE · 2026","summary":"Selectively secure lattice CP-ABE for NC1 with ciphertext size poly(lambda), independent of circuit size, input length, and depth.","title":"Liu–Zhang–Fu Constant-Ciphertext CP-ABE for NC1","type":"construction","venue":"IACR ePrint 2026","year":2026,"sourcePath":"data/abe-catalog.json#lzf26_constant_ct_cpabe"},{"evidence":"source-derived","id":"ABE-MILESTONE-012-02","keywords":["weaker-target","lattices","adaptive-security","nc1","noncommitting-state"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-012"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-012","summary":"A bounded number of adaptive rejecting keys before unbounded polynomial collusion.","title":"A bounded number of adaptive rejecting keys before unbounded polynomial collusion.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-012-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-006-01","keywords":["weaker-target","fbe","ibbe","dmpe","adaptivity","standard-model"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-006","summary":"A publicly-sampleable projective PRG with poly(lambda,log ell) projected seed and sublinear public parameters when ell is fixed at setup.","title":"A publicly-sampleable projective PRG with poly(lambda,log ell) projected seed and sublinear public…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-006-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-006-03","keywords":["weaker-target","fbe","ibbe","dmpe","adaptivity","standard-model"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-006","summary":"A standard-model adaptive DBE with sublinear CRS and optimal ciphertext.","title":"A standard-model adaptive DBE with sublinear CRS and optimal ciphertext.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-006-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-012-01","keywords":["weaker-target","lattices","adaptive-security","nc1","noncommitting-state"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-012"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-012","summary":"Adaptive monotone formulas before signed formulas or general \\(NC^1\\).","title":"Adaptive monotone formulas before signed formulas or general \\(NC^1\\).","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-012-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-001-03","keywords":["weaker-target","lattices","circuit-abe","adaptivity","succinctness"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-001","summary":"Adaptive security from succinct/decomposed LWE with a policy-level noncommitting state. The ordinary-polynomial-size NC1 version is tracked separately as ABE-OP-012.","title":"Adaptive security from succinct/decomposed LWE with a policy-level noncommitting state. The…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-001-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-008-03","keywords":["weaker-target","pairings","efficiency","standard-model","lsss"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-008"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-008","summary":"Add tight multi-challenge security.","title":"Add tight multi-challenge security.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-008-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-003-02","keywords":["weaker-target","unbounded-depth","lattices","circular-security","post-quantum"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-003","summary":"Bounded-collusion ABE from a modular, independently testable recoding assumption.","title":"Bounded-collusion ABE from a modular, independently testable recoding assumption.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-003-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-004-02","keywords":["weaker-target","dmpe","threshold","lsss","lattices","trustless"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-004","summary":"Construct a uniform multi-row sharing family with bounded per-user hint.","title":"Construct a uniform multi-row sharing family with bounded per-user hint.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-004-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-007-01","keywords":["weaker-target","ram","turing-machines","uniform-computation","direct-constructions"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-007"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-007","summary":"Direct ABE for NL or deterministic logspace from a clean lattice assumption.","title":"Direct ABE for NL or deterministic logspace from a clean lattice assumption.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-007-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-011-01","keywords":["weaker-target","revocation","revocable-storage","public-update","secure-key-leasing","post-quantum"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-011"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-011","summary":"Do not merge user revocation, attribute revocation, ciphertext erasure, certified deletion, and secure key leasing.","title":"Do not merge user revocation, attribute revocation, ciphertext erasure, certified deletion, and secure key…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-011-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-006-04","keywords":["weaker-target","fbe","ibbe","dmpe","adaptivity","standard-model"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-006","summary":"Equivocal matrix commitment with standard-model setup under an explicit dual-mode assumption.","title":"Equivocal matrix commitment with standard-model setup under an explicit dual-mode assumption.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-006-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-002-01","keywords":["weaker-target","unbounded-abe","succinctness","adaptivity","standard-model"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-002","summary":"Extend the current compiler to a second non-formula sharing family.","title":"Extend the current compiler to a second non-formula sharing family.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-002-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-010-03","keywords":["weaker-target","policy-hiding","function-hiding","attribute-hiding","predicate-encryption","io-barrier"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-010"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-010","summary":"First support formulas with hidden labels or hidden polarity while leaking topology, then test whether topology hiding is compatible with reuse.","title":"First support formulas with hidden labels or hidden polarity while leaking topology, then test whether…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-010-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-011-03","keywords":["weaker-target","revocation","revocable-storage","public-update","secure-key-leasing","post-quantum"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-011"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-011","summary":"For SKL, first remove the polynomial-arity MIABE dependency from the classical-certificate branch or obtain a useful bounded-arity special case.","title":"For SKL, first remove the polynomial-arity MIABE dependency from the classical-certificate branch or obtain…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-011-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-011-04","keywords":["weaker-target","revocation","revocable-storage","public-update","secure-key-leasing","post-quantum"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-011"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-011","summary":"For public updates, prove an amortized lower/upper bound before claiming storage scalability.","title":"For public updates, prove an amortized lower/upper bound before claiming storage scalability.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-011-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-009-01","keywords":["weaker-target","multi-input-abe","polynomial-arity","post-quantum","witness-encryption"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-009"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-009","summary":"Formalize whether input encryption is public- or master-secret-key based in the targeted application; do not merge symmetric and public-key games.","title":"Formalize whether input encryption is public- or master-secret-key based in the targeted application; do not…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-009-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-003-03","keywords":["weaker-target","unbounded-depth","lattices","circular-security","post-quantum"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-003","summary":"Full collusion with instance-independent auxiliary information.","title":"Full collusion with instance-independent auxiliary information.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-003-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-004-01","keywords":["weaker-target","dmpe","threshold","lsss","lattices","trustless"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-004","summary":"Independently audit and publish the reconstruction-height barrier.","title":"Independently audit and publish the reconstruction-height barrier.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-004-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-004-04","keywords":["weaker-target","dmpe","threshold","lsss","lattices","trustless"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-004","summary":"Instantiate a growing-threshold DMPE special case before general MSPs.","title":"Instantiate a growing-threshold DMPE special case before general MSPs.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-004-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-005-01","keywords":["weaker-target","registered-abe","multi-authority","lattices","transparent-setup"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-005","summary":"Lattice registered ABE for formulas from decomposed/succinct LWE with a transparent setup.","title":"Lattice registered ABE for formulas from decomposed/succinct LWE with a transparent setup.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-005-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-007-04","keywords":["weaker-target","ram","turing-machines","uniform-computation","direct-constructions"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-007"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-007","summary":"Match the space-time lower bounds without general FE.","title":"Match the space-time lower bounds without general FE.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-007-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-011-02","keywords":["weaker-target","revocation","revocable-storage","public-update","secure-key-leasing","post-quantum"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-011"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-011","summary":"Normalize forward/backward security and the adversary's epoch-wise key, update-token, verification, and corruption queries.","title":"Normalize forward/backward security and the adversary's epoch-wise key, update-token, verification, and…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-011-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-008-02","keywords":["weaker-target","pairings","efficiency","standard-model","lsss"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-008"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-008","summary":"Obtain a static-assumption theorem with a small constant-factor cost.","title":"Obtain a static-assumption theorem with a small constant-factor cost.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-008-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-002-03","keywords":["weaker-target","unbounded-abe","succinctness","adaptivity","standard-model"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-002","summary":"Obtain semi-adaptive and then adaptive security.","title":"Obtain semi-adaptive and then adaptive security.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-002-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-003-01","keywords":["weaker-target","unbounded-depth","lattices","circular-security","post-quantum"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-003","summary":"One-key or laconic unbounded-depth primitive from circular LWE.","title":"One-key or laconic unbounded-depth primitive from circular LWE.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-003-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-001-01","keywords":["weaker-target","lattices","circuit-abe","adaptivity","succinctness"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-001","summary":"Polynomial-ratio selective formula ABE through a new exact accepting channel rather than accumulated stationary noise.","title":"Polynomial-ratio selective formula ABE through a new exact accepting channel rather than accumulated…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-001-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-003-04","keywords":["weaker-target","unbounded-depth","lattices","circular-security","post-quantum"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-003","summary":"Post-quantum replacement for any group/KDM component.","title":"Post-quantum replacement for any group/KDM component.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-003-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-009-02","keywords":["weaker-target","multi-input-abe","polynomial-arity","post-quantum","witness-encryption"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-009"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-009","summary":"Prove a binary composition theorem for four inputs with unbounded key collusion before claiming recursion.","title":"Prove a binary composition theorem for four inputs with unbounded key collusion before claiming recursion.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-009-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-010-02","keywords":["weaker-target","policy-hiding","function-hiding","attribute-hiding","predicate-encryption","io-barrier"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-010"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-010","summary":"Prove that a proposed leakage profile does not reconstruct an iO candidate through polynomially many key/ciphertext queries.","title":"Prove that a proposed leakage profile does not reconstruct an iO candidate through polynomially many…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-010-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-004-03","keywords":["weaker-target","dmpe","threshold","lsss","lattices","trustless"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-004","summary":"Prove the policy-recoding/lifting lemma for the required commitment API.","title":"Prove the policy-recoding/lifting lemma for the required commitment API.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-004-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-002-02","keywords":["weaker-target","unbounded-abe","succinctness","adaptivity","standard-model"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-002","summary":"Prove unconditional QROM or standard-model variants without changing the functionality claim.","title":"Prove unconditional QROM or standard-model variants without changing the functionality claim.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-002-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-007-03","keywords":["weaker-target","ram","turing-machines","uniform-computation","direct-constructions"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-007"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-007","summary":"RAM ABE with optimal object sizes but non-optimal decryption.","title":"RAM ABE with optimal object sizes but non-optimal decryption.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-007-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-012-03","keywords":["weaker-target","lattices","adaptive-security","nc1","noncommitting-state"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-012"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-012","summary":"ROM before the standard model, provided the random-oracle dependency is isolated as a removable component.","title":"ROM before the standard model, provided the random-oracle dependency is isolated as a removable component.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-012-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-008-01","keywords":["weaker-target","pairings","efficiency","standard-model","lsss"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-008"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-008","summary":"Remove ROM while keeping GGM and the concrete profile.","title":"Remove ROM while keeping GGM and the concrete profile.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-008-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-005-02","keywords":["weaker-target","registered-abe","multi-authority","lattices","transparent-setup"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-005","summary":"Remove setup bounds on users or input length.","title":"Remove setup bounds on users or input length.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-005-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-005-04","keywords":["weaker-target","registered-abe","multi-authority","lattices","transparent-setup"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-005","summary":"Replace ROM or strong lattice assumptions.","title":"Replace ROM or strong lattice assumptions.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-005-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-009-04","keywords":["weaker-target","multi-input-abe","polynomial-arity","post-quantum","witness-encryption"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-009"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-009","summary":"Replace evasive/tensor assumptions only after the arity interface is sound.","title":"Replace evasive/tensor assumptions only after the arity interface is sound.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-009-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-002-04","keywords":["weaker-target","unbounded-abe","succinctness","adaptivity","standard-model"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-002","summary":"Replace super-polynomial-ratio decomposed LWE by a polynomial-ratio or static pairing assumption.","title":"Replace super-polynomial-ratio decomposed LWE by a polynomial-ratio or static pairing assumption.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-002-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-001-04","keywords":["weaker-target","lattices","circuit-abe","adaptivity","succinctness"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-001","summary":"Replace the strong assumption after the adaptive interface is understood.","title":"Replace the strong assumption after the adaptive interface is understood.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-001-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-007-02","keywords":["weaker-target","ram","turing-machines","uniform-computation","direct-constructions"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-007"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-007","summary":"Safe unbounded-depth circuit ABE (ABE-OP-003).","title":"Safe unbounded-depth circuit ABE (ABE-OP-003).","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-007-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-001-02","keywords":["weaker-target","lattices","circuit-abe","adaptivity","succinctness"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-001","summary":"Semi-adaptive security with the current completely-unbounded interface.","title":"Semi-adaptive security with the current completely-unbounded interface.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-001-02"},{"evidence":"source-derived","id":"ABE-MILESTONE-005-03","keywords":["weaker-target","registered-abe","multi-authority","lattices","transparent-setup"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-005"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-005","summary":"Separate adaptive registration/corruption from adaptive policy selection.","title":"Separate adaptive registration/corruption from adaptive policy selection.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-005-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-010-01","keywords":["weaker-target","policy-hiding","function-hiding","attribute-hiding","predicate-encryption","io-barrier"],"metadata":{"order":1,"parent_problem_id":"ABE-OP-010"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-010","summary":"Separate attribute hiding (ciphertext input privacy) from function/policy hiding (key or ciphertext policy privacy).","title":"Separate attribute hiding (ciphertext input privacy) from function/policy hiding (key or ciphertext policy…","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-010-01"},{"evidence":"source-derived","id":"ABE-MILESTONE-012-04","keywords":["weaker-target","lattices","adaptive-security","nc1","noncommitting-state"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-012"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-012","summary":"Succinct/decomposed LWE before plain polynomial-ratio LWE.","title":"Succinct/decomposed LWE before plain polynomial-ratio LWE.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-012-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-010-04","keywords":["weaker-target","policy-hiding","function-hiding","attribute-hiding","predicate-encryption","io-barrier"],"metadata":{"order":4,"parent_problem_id":"ABE-OP-010"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-010","summary":"Track size-shape leakage and admissibility constraints explicitly.","title":"Track size-shape leakage and admissibility constraints explicitly.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-010-04"},{"evidence":"source-derived","id":"ABE-MILESTONE-009-03","keywords":["weaker-target","multi-input-abe","polynomial-arity","post-quantum","witness-encryption"],"metadata":{"order":3,"parent_problem_id":"ABE-OP-009"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-009","summary":"Track tensor dimension, reduction loss, and lattice noise under recursion.","title":"Track tensor dimension, reduction loss, and lattice noise under recursion.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-009-03"},{"evidence":"source-derived","id":"ABE-MILESTONE-006-02","keywords":["weaker-target","fbe","ibbe","dmpe","adaptivity","standard-model"],"metadata":{"order":2,"parent_problem_id":"ABE-OP-006"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward ABE-OP-006","summary":"Upgrade that pPRG to universal Setup(1^lambda) and public parameters independent of the later output length.","title":"Upgrade that pPRG to universal Setup(1^lambda) and public parameters independent of the later output length.","type":"milestone","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-MILESTONE-006-02"},{"evidence":"candidate","id":"ABE-OP-001","keywords":["lattices","circuit-abe","adaptivity","succinctness"],"metadata":{"barriers":["ABE-BARRIER-002","ABE-BARRIER-003"],"closest_results":["ABE-PAPER-2025-WEE","ABE-PAPER-2024-CW","ABE-PAPER-2022-LLL"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"Solves the bounded-depth plain-LWE/adaptive/all-object size core needed by the completely-unbounded endpoint.","relation":"stepping_stone_for","target":"ABE-OP-002"}],"hierarchy_role":"major_stepping_stone","id":"ABE-OP-001","keywords":["lattices","circuit-abe","adaptivity","succinctness"],"normalization_delta":"No cited paper asks for this exact conjunction.  The dossier combines the adaptive-security frontier, all-object succinctness, and plain polynomial-ratio LWE into one endpoint and keeps weaker one-axis upgrades as explicit intermediate targets.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Theorems 21 and 24, PDF pp. 44 and 51","paper":"ABE-PAPER-2022-LLL","relation":"theorem_frontier"},{"location":"Theorems 2 and 3, PDF pp. 10--11","paper":"ABE-PAPER-2024-CW","relation":"theorem_frontier"},{"location":"Theorems 2, 4, and 6, PDF pp. 15, 18, and 21","paper":"ABE-PAPER-2025-WEE","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Polynomial-ratio selective formula ABE through a new exact accepting channel rather than accumulated stationary noise.","Semi-adaptive security with the current completely-unbounded interface.","Adaptive security from succinct/decomposed LWE with a policy-level noncommitting state. The ordinary-polynomial-size NC1 version is tracked separately as ABE-OP-012.","Replace the strong assumption after the adaptive interface is understood."],"priority":"tier-1","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"General circuits","security":"Adaptive","setup":"Late-bound / unbounded","size":"Almost optimal"},"provenance":["ABE-PAPER-2022-LLL","ABE-PAPER-2024-CW","ABE-PAPER-2025-WEE"],"routes":["ABE-ROUTE-001","ABE-ROUTE-002","ABE-ROUTE-003"],"status":"open","title":"Adaptive almost-optimal circuit ABE from plain or polynomial-ratio LWE"},"primaryUrl":null,"sections":[{"content":"Adaptive almost-optimal circuit ABE from plain or polynomial-ratio LWE","heading":"Overview"},{"content":"Li–Lin–Luo obtained constant-size circuit KP-ABE keys and double-succinct formula CP-ABE in a hybrid lattice/pairing setting; their adaptive upgrade uses adaptive LWE. Cini–Wee obtained semi-adaptive unbounded-attribute circuit ABE from plain LWE. Wee later obtained almost-optimal KP- and CP-ABE for bounded-depth circuits from succinct LWE, with selective security.","heading":"Historical provenance"},{"content":"Construct KP-ABE or CP-ABE for bounded-depth circuits such that MPK, ciphertext, and policy key have only poly(lambda, depth) cryptographic size, while achieving adaptive challenge security and unbounded polynomial collusion from plain LWE with polynomial modulus-to-noise ratio. Meaningful intermediate targets retain succinct LWE but add adaptivity, or retain selectivity while replacing succinct/decomposed assumptions by plain LWE.","heading":"Current normalized statement"},{"content":"All notation and size accounting follow ABE-OPEN-v1. Historical Li--Lin--Luo targets Li--Lin--Luo's two centered questions on printed p. 2 are, in this notation: for circuit KP-ABE, obtain \\(\\|\\mathsf{sk}_f\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda)\\), independent of \\(S_f\\) and \\(d_f\\); and for expressive KP- or CP-ABE, simultaneously obtain a key and ciphertext whose cryptographic parts are succinct in the descriptions placed on their respective sides. The ideal endpoint stated immediately before those questions is stronger: \\[ \\|\\mathsf{sk}\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda),\\qquad \\|\\mathsf{ct}\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda), \\] with clear \\(x\\) or \\(f\\) recorded separately in \\(\\mathsf{meta}\\). Their paper resolves the two centered intermediate questions under its stated hybrid/GGM assumptions, but not this constant/constant ideal for circuits from plain LWE. Current target For every depth bound \\(d=\\operatorname{poly}(\\lambda)\\), construct ordinary reusable KP-ABE or CP-ABE for every Boolean circuit \\(f\\) with \\(d_f\\le d\\) and arbitrary polynomial \\(L_x,S_f\\), with \\[ \\begin{aligned} \\|\\mathsf{mpk}\\|_{\\rm crypt}&=\\operatorname{poly}(\\lambda,d),\\\\ \\|\\mathsf{sk}_f\\|_{\\rm crypt}, \\|\\mathsf{ct}_x\\|_{\\rm crypt}&=\\operatorname{poly}(\\lambda,d) \\quad\\text{(KP)}, \\end{aligned} \\] and the transposed bounds for CP-ABE. None of these cryptographic-core bounds may depend on \\(L_x\\) or \\(S_f\\); total size additionally includes the clear description attached to the object. Setup may take \\(d\\) but not \\(L_x,S_f\\), the universe, or a label-length bound. Security must be adaptive IND-CPA payload security with any polynomial number of legal key queries, in the standard model, from plain LWE satisfying \\(R_{\\rm LWE}=\\operatorname{poly}(\\lambda)\\). A result from succinct, decomposed, adaptive, evasive, tensor, or circular LWE is a weaker variant unless accompanied by a reduction to this plain-LWE regime. KP and CP are tracked separately; the card is fully resolved when both orientations are obtained or a property-preserving dualization proves the second from the first.","heading":"Exact normalized target"},{"content":"This would combine the best known asymptotic object sizes with the standard post-quantum assumption and security notion expected of reusable ABE. It is an assumption/security breakthrough, not merely a size optimization.","heading":"Why it matters"},{"content":"Wee 2025: almost-optimal object sizes from succinct LWE, selective. Cini–Wee 2024: plain-LWE, semi-adaptive, unbounded attribute length, with depth fixed at setup and non-almost-optimal object dependence. Li–Lin–Luo 2022: constant-key/double-succinct hybrid constructions; adaptivity from adaptive LWE.","heading":"Closest known results"},{"content":"Known routes use succinct/decomposed LWE evaluation, adaptive/noncommitting preimage states, or selective-to-adaptive compilers. In the current repository, independent stationary row noise fails correctness at polynomial ratio after sufficiently many rows, and two natural reusable preimage-state families fail exact two-key joint-distribution/collusion tests. These are scoped barriers, not impossibility results for adaptive ABE.","heading":"Known routes and barriers"},{"content":"Polynomial-ratio selective formula ABE through a new exact accepting channel rather than accumulated stationary noise. Semi-adaptive security with the current completely-unbounded interface. Adaptive security from succinct/decomposed LWE with a policy-level noncommitting state. The ordinary-polynomial-size NC1 version is tracked separately as ABE-OP-012. Replace the strong assumption after the adaptive interface is understood.","heading":"Stepping stones"},{"content":"Finite joint-distribution identities and attacks can be scripted. Current backends do not certify the complete lattice reduction, Gaussian sampling, or adaptive multi-key hybrid.","heading":"Verification boundary"}],"status":"open","subtitle":"tier-1","summary":"Construct KP-ABE or CP-ABE for bounded-depth circuits such that MPK, ciphertext, and policy key have only poly(lambda, depth) cryptographic size, while achieving adaptive challenge security and unbounded polynomial collusion from plain LWE with polynomial modulus-to-noise ratio. Meaningful intermediate targets retain succinct LWE but add adaptivity, or retain selectivity while replacing succinct/decomposed…","title":"Adaptive almost-optimal circuit ABE from plain or polynomial-ratio LWE","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-001"},{"evidence":"candidate","id":"ABE-OP-002","keywords":["unbounded-abe","succinctness","adaptivity","standard-model"],"metadata":{"barriers":["ABE-BARRIER-002","ABE-BARRIER-003","ABE-BARRIER-005"],"closest_results":["ABE-PAPER-2012-OT","ABE-PAPER-2018-CGKW","ABE-PAPER-2024-CW","ABE-PAPER-2025-WEE","ABE-PAPER-2022-LLL"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[],"hierarchy_role":"primary_north_star","id":"ABE-OP-002","keywords":["unbounded-abe","succinctness","adaptivity","standard-model"],"normalization_delta":"No source asks for the exact four-way conjunction of complete setup unboundedness, succinct objects, full adaptivity, and a clean fixed assumption.  The dossier separates this endpoint from the weaker meanings of unbounded or constant-public-parameter ABE in the cited papers.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Theorems 4--6, PDF pp. 33 and 39--40","paper":"ABE-PAPER-2012-OT","relation":"theorem_frontier"},{"location":"Theorems 2--4, PDF pp. 31, 37, and 47","paper":"ABE-PAPER-2018-CGKW","relation":"theorem_frontier"},{"location":"Theorems 2 and 3, PDF pp. 10--11","paper":"ABE-PAPER-2024-CW","relation":"theorem_frontier"},{"location":"Theorems 2, 4, and 6, PDF pp. 15, 18, and 21","paper":"ABE-PAPER-2025-WEE","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Extend the current compiler to a second non-formula sharing family.","Prove unconditional QROM or standard-model variants without changing the functionality claim.","Obtain semi-adaptive and then adaptive security.","Replace super-polynomial-ratio decomposed LWE by a polynomial-ratio or static pairing assumption."],"priority":"tier-1","profile":{"assumption":"Plain LWE / static pairing","expressivity":"General circuits","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2012-OT","ABE-PAPER-2018-CGKW","ABE-PAPER-2024-CW","ABE-PAPER-2025-WEE"],"routes":["ABE-ROUTE-001","ABE-ROUTE-002","ABE-ROUTE-003","ABE-ROUTE-007"],"status":"open","title":"Completely-unbounded succinct adaptive ordinary ABE"},"primaryUrl":null,"sections":[{"content":"Completely-unbounded succinct adaptive ordinary ABE","heading":"Overview"},{"content":"Construct ordinary centralized reusable KP-ABE or CP-ABE in which setup fixes no attribute universe, input length, policy size, or circuit depth, while the cryptographic MPK and succinct-side object are poly(lambda) and security is adaptive in the standard model under a fixed clean static or post-quantum assumption. State clear policy/attribute metadata separately.","heading":"Current normalized statement"},{"content":"Use \\(\\mathsf{Setup}(1^\\lambda)\\) with no bound on the universe, label length, \\(L_x,S_f,d_f\\), or the number of later key queries. Support all polynomial-size Boolean circuits \\(f\\); a formula-only theorem is a named weaker target. For KP-ABE require \\[ \\|\\mathsf{mpk}\\|_{\\rm crypt},\\quad \\|\\mathsf{sk}_f\\|_{\\rm crypt},\\quad \\|\\mathsf{ct}_x\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda), \\] independently of every realized dimension \\(L_x,S_f,d_f\\). The CP target uses the same equation with \\(\\mathsf{sk}_x,\\mathsf{ct}_f\\). Total sizes must separately report the late-bound clear metadata, for example \\(\\|\\mathsf{ct}_x\\|_{\\rm total}=L_x+\\operatorname{poly}(\\lambda)\\) when \\(x\\) is transmitted in the clear. The security target is adaptive IND-CPA payload security for any polynomial number of legal pre- and post-challenge key queries, in the standard model. The assumption must be fixed independently of the realized dimensions and be either plain polynomial-ratio LWE or a static falsifiable pairing assumption. ROM/QROM, GGM, knowledge, succinct/decomposed/adaptive LWE, and general FE/iO give explicitly weaker variants. KP and CP are recorded separately; complete resolution requires both orientations or a theorem-level dualization.","heading":"Exact normalized target"},{"content":"Existing results distribute these properties across different schemes. Combining them would remove the setup-bound and trust/API compromises that currently separate unbounded and succinct ABE.","heading":"Why it matters"},{"content":"Cini–Wee: unbounded attribute length from plain LWE, but depth is fixed and security is semi-adaptive. Wee: all-three almost-optimal bounded-depth circuit ABE from succinct LWE, but input length/depth are setup parameters and security is selective. Pairing-based completely-unbounded ABE: strong setup flexibility, but the succinct-side object generally grows with realized input/policy dimensions. Okamoto--Takashima: adaptive standard-model DLIN security together with setup-unbounded KP/CP-ABE, but realized keys and ciphertexts are not simultaneously succinct and the basic ABE has degree/one-use restrictions. This repository: completely late-bound signed-formula KP-ABE with constant cryptographic MPK/CT core, but selective ROM and decomposed-LWE parameters.","heading":"Closest known results"},{"content":"The CP and KP orientations, formula versus general MSP/circuit policies, and pairing versus lattice assumptions are separate variants. A selective standard-model theorem or adaptive ROM theorem would be substantial but would not close the full endpoint.","heading":"Variants and partial targets"},{"content":"Late-bound hashing plus lattice false-row completion reaches the current selective formula result. Pairing projectability routes fail when the unbounded inner primitive cannot expose the source-group linear interface required by the outer compiler. Adaptive preimage programming requires a policy-level state whose joint multi-key distribution remains honest; naive canonical states fail.","heading":"Known routes and barriers"},{"content":"Extend the current compiler to a second non-formula sharing family. Prove unconditional QROM or standard-model variants without changing the functionality claim. Obtain semi-adaptive and then adaptive security. Replace super-polynomial-ratio decomposed LWE by a polynomial-ratio or static pairing assumption.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-1","summary":"Construct ordinary centralized reusable KP-ABE or CP-ABE in which setup fixes no attribute universe, input length, policy size, or circuit depth, while the cryptographic MPK and succinct-side object are poly(lambda) and security is adaptive in the standard model under a fixed clean static or post-quantum assumption. State clear policy/attribute metadata separately.","title":"Completely-unbounded succinct adaptive ordinary ABE","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-002"},{"evidence":"candidate","id":"ABE-OP-007","keywords":["ram","turing-machines","uniform-computation","direct-constructions"],"metadata":{"barriers":["ABE-BARRIER-004","ABE-BARRIER-006"],"closest_results":["ABE-PAPER-2023-JLL","ABE-PAPER-2025-AMY-TM"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"Direct safe RAM/TM ABE extends the unbounded-depth circuit goal to uniform computation and actual running time.","relation":"strengthens","target":"ABE-OP-003"}],"hierarchy_role":"line_north_star","id":"ABE-OP-007","keywords":["ram","turing-machines","uniform-computation","direct-constructions"],"normalization_delta":"The dossier combines JLL's optimal uniform-computation interface and lower bounds with the direct lattice Turing-machine line, then asks for the same capability without generic polynomially secure FE or the current strong evasive/tensor/circular assumption stack.  No source is said to pose this exact conjunction.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Theorem 25, Corollaries 26--28, and Theorems 5--6 and 10--12, PDF pp. 5--8 and Section 3","paper":"ABE-PAPER-2023-JLL","relation":"theorem_frontier"},{"location":"Theorems 4.3--4.4 and 5.6--5.8, PDF pp. 28--43","paper":"ABE-PAPER-2025-AMY-TM","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Direct ABE for NL or deterministic logspace from a clean lattice assumption.","Safe unbounded-depth circuit ABE (ABE-OP-003).","RAM ABE with optimal object sizes but non-optimal decryption.","Match the space-time lower bounds without general FE."],"priority":"tier-2","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"Ordinary ABE","security":"Selective","setup":"Bounded setup allowed","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2023-JLL","ABE-PAPER-2025-AMY-TM"],"routes":["ABE-ROUTE-004","ABE-ROUTE-008"],"status":"open","title":"Direct efficient ABE for RAM and Turing machines from safe assumptions"},"primaryUrl":null,"sections":[{"content":"Direct efficient ABE for RAM and Turing machines from safe assumptions","heading":"Overview"},{"content":"Construct collusion-resistant ABE for uniform computation—RAMs or Turing machines—with input-specific running time and succinct keys/ciphertexts, from direct, well-founded assumptions rather than a generic polynomially secure FE compiler, iO, or attacked evasive/circular assumption combinations.","heading":"Current normalized statement"},{"content":"Let \\(M\\) be a polynomial-time RAM or Turing machine and \\(x\\) an input. Construct ordinary reusable KP-ABE with correctness predicate \\(M(x)=1\\) such that setup takes only \\(1^\\lambda\\) and, at most, an input-length bound; it takes no bound on \\(|M|\\) or \\(T_M(x)\\). Require \\[ \\|\\mathsf{sk}_M\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda),\\qquad \\|\\mathsf{ct}_x\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda,L_x), \\] with \\(M\\) and \\(x\\) accounted for as clear metadata, and decryption time \\[ \\operatorname{poly}(\\lambda,L_x,T_M(x)) \\] rather than a polynomial in a worst-case setup bound. A CP orientation must state the transposed object bounds explicitly. The minimum theorem has selective IND-CPA security against any polynomial number of legal keys. It must be a direct construction and may not call general polynomially secure FE, compact FE, or iO as a black box. Its assumption must be fixed and falsifiable; the preferred endpoint is plain polynomial-ratio LWE. A result using an independently stated new assumption is partial until that assumption has evidence beyond the attacked evasive/circular families. The RAM and TM variants are tracked separately.","heading":"Exact normalized target"},{"content":"Uniform computation avoids fixing circuit/input representations and supports instance-specific running time. It is a qualitatively stronger usability and expressivity goal than adding another bounded-depth circuit class.","heading":"Why it matters"},{"content":"Jain–Lin–Luo: nearly optimal PHFE/ABE for RAM from the necessary assumption of polynomially secure FE for circuits, plus unconditional space-time tradeoffs. Agrawal et al.: lattice ABE for Turing machines and unbounded-depth CP-ABE from LWE combined with evasive, tensor, and circular-tensor assumptions.","heading":"Closest known results"},{"content":"Generic FE gives feasibility but obscures direct assumption structure. Lattice uniform-computation routes need reusable computation plus policy-gated extraction and currently rely on strong assumption combinations. Jain–Lin–Luo's lower bounds rule out simultaneously sublinear key/ciphertext and decryption dimensions in specific PHFE regimes; they do not rule out the known optimal tradeoff.","heading":"Known routes and barriers"},{"content":"Direct ABE for NL or deterministic logspace from a clean lattice assumption. Safe unbounded-depth circuit ABE (ABE-OP-003). RAM ABE with optimal object sizes but non-optimal decryption. Match the space-time lower bounds without general FE.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-2","summary":"Construct collusion-resistant ABE for uniform computation—RAMs or Turing machines—with input-specific running time and succinct keys/ciphertexts, from direct, well-founded assumptions rather than a generic polynomially secure FE compiler, iO, or attacked evasive/circular assumption combinations.","title":"Direct efficient ABE for RAM and Turing machines from safe assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-007"},{"evidence":"candidate","id":"ABE-OP-012","keywords":["lattices","adaptive-security","nc1","noncommitting-state"],"metadata":{"barriers":["ABE-BARRIER-002"],"closest_results":["ABE-PAPER-2019-TSABARY","ABE-PAPER-2019-KW","ABE-PAPER-2024-CW","ABE-PAPER-2025-WEE","ABE-PAPER-2024-WW","ABE-PAPER-2026-GY-EQUIVOCAL-BE"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"Isolates adaptive reusable NC1 security while allowing ordinary polynomial sizes and stronger falsifiable lattice assumptions.","relation":"stepping_stone_for","target":"ABE-OP-001"},{"note":"Supplies the adaptive-policy-key simulation component of universal ordinary ABE.","relation":"enabling_component_for","target":"ABE-OP-002"}],"hierarchy_role":"major_stepping_stone","id":"ABE-OP-012","keywords":["lattices","adaptive-security","nc1","noncommitting-state"],"normalization_delta":"No cited paper states this exact conjunction.  The card isolates the policy- expressivity jump between adaptive lattice t-CNF/inner-product systems and NC1, while deliberately dropping OP001's all-object succinctness and plain- LWE requirements.  The 2026 broadcast result contributes a candidate proof paradigm, not an ABE theorem.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Lemma 4.2 and Sections 3.1 and 4, PDF pp. 12--16","paper":"ABE-PAPER-2019-TSABARY","relation":"theorem_frontier"},{"location":"Theorems 3 and 4, PDF pp. 26 and 34","paper":"ABE-PAPER-2019-KW","relation":"theorem_frontier"},{"location":"Theorems 2 and 3, PDF pp. 10--11","paper":"ABE-PAPER-2024-CW","relation":"theorem_frontier"},{"location":"Theorems 2, 4, and 6, PDF pp. 15, 18, and 21","paper":"ABE-PAPER-2025-WEE","relation":"theorem_frontier"},{"location":"Abstract and Introduction, ePrint 2026/792","paper":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Adaptive monotone formulas before signed formulas or general \\(NC^1\\).","A bounded number of adaptive rejecting keys before unbounded polynomial collusion.","ROM before the standard model, provided the random-oracle dependency is isolated as a removable component.","Succinct/decomposed LWE before plain polynomial-ratio LWE.","Define and realize the two-rejecting-policy toy game for challenge {a} and keys b and a AND b.","Extend to adaptive conjunctions with repeated labels and polynomial keys."],"priority":"tier-1","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"NC¹ formulas","security":"Adaptive","setup":"Bounded setup allowed","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2019-TSABARY","ABE-PAPER-2019-KW","ABE-PAPER-2024-CW","ABE-PAPER-2025-WEE","ABE-PAPER-2026-GY-EQUIVOCAL-BE"],"routes":["ABE-ROUTE-020"],"status":"open","title":"Direct fully adaptive NC1 ABE from falsifiable lattice assumptions"},"primaryUrl":null,"sections":[{"content":"Direct fully adaptive NC1 ABE from falsifiable lattice assumptions","heading":"Overview"},{"content":"Tsabary proved that adaptive lattice ABE is possible beyond IBE for constant-t CNF. Kowalczyk--Wee reached adaptive reusable \\(NC^1\\) ABE from \\(k\\)-Lin in pairing groups. Cini--Wee and Wee reach much richer lattice circuit classes but stop at semi-adaptive or selective security. Waters--Wichs give broad adaptive ABE through witness encryption; the open problem here asks for a direct lattice construction. Goyal--Yadugiri's equivocal broadcast system is the newest candidate source of adaptive-state machinery.","heading":"Historical provenance"},{"content":"Construct ordinary reusable KP-ABE or CP-ABE for Boolean formulas/equivalently nonuniform \\(NC^1\\) with fully adaptive payload security, directly from a falsifiable lattice assumption and without general witness encryption, FE, iO, or a generic obfuscation compiler.","heading":"Current normalized statement"},{"content":"For KP-ABE, run \\(\\mathsf{Setup}(1^\\lambda,1^L)\\) for an attribute-vector length bound \\(L\\), but without fixing a challenge attribute or a formula. Support every polynomial-size bounded-fan-in Boolean formula \\(f\\) of depth \\(O(\\log(\\lambda+L+S_f))\\) and every \\(x\\in\\{0,1\\}^L\\), including repeated attribute labels. Require ordinary polynomial bounds \\[ \\|\\mathsf{mpk}\\|_{\\rm crypt},\\ \\|\\mathsf{ct}_x\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda,L),\\qquad \\|\\mathsf{sk}_f\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda,L,S_f), \\] with the roles explicitly transposed for CP-ABE. This card does not require the size-independence demanded by ABE-OP-001. Security is adaptive IND-CPA for any polynomial number of reusable key queries: the challenge attribute/policy is chosen only after setup and legal pre-challenge queries, and legal post-challenge queries are allowed. All queried KP policies must reject the eventual challenge attribute. The construction must be direct and use a fixed, efficiently samplable, falsifiable lattice assumption. Succinct or decomposed LWE is admissible if its exact game and parameter ratio are stated; plain polynomial-ratio LWE is a stronger upgrade tracked by ABE-OP-001. The standard model is the resolution target. A first ROM construction is recorded as major partial progress only when oracle programming is explicit and the proof handles the joint distribution of all reusable keys.","heading":"Exact normalized target"},{"content":"This is the smallest broadly expressive policy class for which lattice ABE adaptivity remains qualitatively behind pairing ABE. It removes succinctness as a confounder and asks whether the real missing object is a lattice analogue of the joint noncommitting/dual-system state, rather than a size optimization.","heading":"Why it matters"},{"content":"Tsabary 2019: fully adaptive lattice CP-ABE for constant-t CNF. Kowalczyk--Wee 2019: fully adaptive reusable \\(NC^1\\) ABE from \\(k\\)-Lin. Cini--Wee 2024: plain-LWE circuit ABE with semi-adaptive security. Wee 2025: almost-optimal circuit ABE from succinct LWE, selective. Waters--Wichs 2024: general adaptive ABE through witness encryption. Goyal--Yadugiri 2026: optimal adaptive lattice distributed broadcast via equivocal encryption, but not reusable formula-policy ABE.","heading":"Closest known results"},{"content":"Adaptive monotone formulas before signed formulas or general \\(NC^1\\). A bounded number of adaptive rejecting keys before unbounded polynomial collusion. ROM before the standard model, provided the random-oracle dependency is isolated as a removable component. Succinct/decomposed LWE before plain polynomial-ratio LWE.","heading":"Variants and partial targets"},{"content":"The principal route is a policy-level noncommitting preimage state inspired by equivocal encryption systems. Broadcast security programs independent user coordinates and a set complement; ABE must instead jointly sample correlated rows for several rejecting policies, repeated labels, and one shared master secret. Independent per-row rerandomization has already failed exact two-key joint-distribution tests (ABE-BARRIER-002).","heading":"Known routes and barriers"},{"content":"Define and realize the two-rejecting-policy toy game for challenge {a} and keys b and a AND b. Extend to adaptive conjunctions with repeated labels and polynomial keys. Compile consistent-independent formula sharing while preserving the exact joint key distribution. Remove ROM or strong setup after the adaptive state is stable.","heading":"Stepping stones"},{"content":"Finite joint-distribution identities and collusion witnesses can be scripted. The full adaptive hybrid, Gaussian conditioning, and lattice reduction remain manual proof obligations.","heading":"Verification boundary"}],"status":"open","subtitle":"tier-1","summary":"Construct ordinary reusable KP-ABE or CP-ABE for Boolean formulas/equivalently nonuniform \\(NC^1\\) with fully adaptive payload security, directly from a falsifiable lattice assumption and without general witness encryption, FE, iO, or a generic obfuscation compiler.","title":"Direct fully adaptive NC1 ABE from falsifiable lattice assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-012"},{"evidence":"published","id":"ABE-OP-010","keywords":["policy-hiding","function-hiding","attribute-hiding","predicate-encryption","io-barrier"],"metadata":{"barriers":["ABE-BARRIER-007"],"closest_results":["ABE-PAPER-2020-AY-FH","ABE-PAPER-2025-WBWL-PE","ABE-PAPER-2018-CGW-IPE"],"dossier_type":"open_problem","evidence":"published","hierarchy_links":[],"hierarchy_role":"orthogonal_north_star","id":"ABE-OP-010","keywords":["policy-hiding","function-hiding","attribute-hiding","predicate-encryption","io-barrier"],"normalization_delta":"The natural full function-hiding target is not retained as an ordinary ABE goal because Agrawal--Yamada show an iO implication.  The dossier therefore asks for an explicit useful leakage profile below that barrier, strengthens it to public-key and unbounded-collusion operation, and requires every leaked dimension to be named.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Informal Theorems 1.1--1.2, Theorems 5.2--5.3, and Section 5.3, PDF pp. 4 and 26--27","paper":"ABE-PAPER-2020-AY-FH","relation":"barrier"},{"location":"Sections 3.4 and 4.4 and Table 1, PDF p. 2","paper":"ABE-PAPER-2018-CGW-IPE","relation":"theorem_frontier"},{"location":"Theorems 3.2 and 4.2, PDF pp. 17 and 22","paper":"ABE-PAPER-2025-WBWL-PE","relation":"theorem_frontier"}],"origin_type":"barrier_reformulation","partial_targets":["Separate attribute hiding (ciphertext input privacy) from function/policy hiding (key or ciphertext policy privacy).","Prove that a proposed leakage profile does not reconstruct an iO candidate through polynomially many key/ciphertext queries.","First support formulas with hidden labels or hidden polarity while leaking topology, then test whether topology hiding is compatible with reuse.","Track size-shape leakage and admissibility constraints explicitly."],"priority":"tier-2","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"General circuits","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2010-LOSSTW","ABE-PAPER-2018-CGW-IPE","ABE-PAPER-2020-AY-FH","ABE-PAPER-2025-WBWL-PE"],"routes":["ABE-ROUTE-017"],"status":"open","title":"Expressive public-key ABE with useful policy privacy below the iO barrier"},"primaryUrl":null,"sections":[{"content":"Expressive public-key ABE with useful policy privacy below the iO barrier","heading":"Overview"},{"content":"Adaptive full attribute hiding is well developed for inner-product PE, and lockable-obfuscation compilers extend attribute hiding to circuits. Agrawal and Yamada showed, however, that the natural full function-hiding definition for circuit ABE already implies indistinguishability obfuscation even for symmetric-key ABE. Their weakened definition and recent bounded-collusion lattice PE demonstrate that nontrivial privacy below that barrier is possible.","heading":"Historical provenance"},{"content":"Define and construct a public-key KP- or CP-ABE scheme for formulas or circuits that hides a substantively useful part of the policy/function, supports unbounded key collusion, and has adaptive payload/privacy security, without implying iO. The target definition must explicitly state leakage of policy length, shape, public metadata, and all authorized cross-evaluations. A strong target should additionally preserve at least one modern frontier: unbounded setup, succinct cryptographic objects, plain/polynomial-ratio LWE, or registered/multi-authority operation.","heading":"Current normalized statement"},{"content":"First define an efficiently computable leakage function \\(\\mathcal L(f)\\) that explicitly lists at least policy length, topology, labels, polarity, public metadata, and output/cross-evaluation leakage, marking each component as hidden or revealed. The target must hide a nontrivial component: there must be efficiently samplable \\(f_0\\ne f_1\\) with \\(\\mathcal L(f_0)=\\mathcal L(f_1)\\). Construct public-key KP- or CP-ABE for Boolean formulas, with public encryption and any polynomial number of colluding keys. Its adaptive privacy game permits challenge policies/functions \\(f_0,f_1\\) only when they have equal leakage and agree on every cross-evaluation that the adversary is legally entitled to learn. Subject to that admissibility condition, the adversary must not distinguish which policy/function was used. Adaptive payload IND-CPA security must hold in the same multi-query interface. The construction must not invoke iO or an equivalent full-function-hiding primitive. At least one of the following must be retained exactly: setup has no formula-size or label-length bound; both relevant cryptographic cores are \\(\\operatorname{poly}(\\lambda)\\) independent of \\(S_f\\); the assumption is plain polynomial-ratio LWE; or the API is registered/multi-authority with the stated adaptive corruption game. A proposal without a formal \\(\\mathcal L\\) and cross-evaluation admissibility relation is not a candidate solution.","heading":"Exact normalized target"},{"content":"Policies can reveal diagnoses, roles, organizational structure, or the purpose of an encrypted record. The existing literature shows both real positive results and a sharp complexity-theoretic barrier, making the problem suitable for principled definition design rather than ad-hoc policy obfuscation.","heading":"Why it matters"},{"content":"Separate attribute hiding (ciphertext input privacy) from function/policy hiding (key or ciphertext policy privacy). Prove that a proposed leakage profile does not reconstruct an iO candidate through polynomially many key/ciphertext queries. First support formulas with hidden labels or hidden polarity while leaking topology, then test whether topology hiding is compatible with reuse. Track size-shape leakage and admissibility constraints explicitly.","heading":"Main risks and stepping stones"},{"content":"Game syntax, leakage consistency, and small-policy attacks can be automated. The iO implication/non-implication and adaptive simulation require manual reductions or a game-based proof assistant.","heading":"Verification boundary"}],"status":"open","subtitle":"tier-2","summary":"Define and construct a public-key KP- or CP-ABE scheme for formulas or circuits that hides a substantively useful part of the policy/function, supports unbounded key collusion, and has adaptive payload/privacy security, without implying iO. The target definition must explicitly state leakage of policy length, shape, public metadata, and all authorized cross-evaluations. A strong target should additionally preserve…","title":"Expressive public-key ABE with useful policy privacy below the iO barrier","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-010"},{"evidence":"candidate","id":"ABE-OP-008","keywords":["pairings","efficiency","standard-model","lsss"],"metadata":{"barriers":["ABE-BARRIER-005"],"closest_results":["ABE-PAPER-2022-FABEO","ABE-PAPER-2017-FAME","ABE-PAPER-2019-KW","ABE-PAPER-2013-RW"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"Tests whether the static-assumption pairing branch can retain state-of-the-art concrete costs; it does not by itself solve universal ABE.","relation":"benchmark_for","target":"ABE-OP-002"}],"hierarchy_role":"supporting_benchmark","id":"ABE-OP-008","keywords":["pairings","efficiency","standard-model","lsss"],"normalization_delta":"This is a dossier-defined concrete-efficiency benchmark, not a canonical author-stated open problem.  It fixes FABEO's attractive cost profile and asks for a static-assumption, standard-model security foundation; isolated element-count improvements do not qualify.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Theorem 4.1, PDF p. 9","paper":"ABE-PAPER-2017-FAME","relation":"theorem_frontier"},{"location":"Theorems 3 and 4, PDF pp. 26 and 34","paper":"ABE-PAPER-2019-KW","relation":"theorem_frontier"},{"location":"Theorems 1--3, PDF pp. 12--15 and 31--33","paper":"ABE-PAPER-2022-FABEO","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Remove ROM while keeping GGM and the concrete profile.","Obtain a static-assumption theorem with a small constant-factor cost.","Add tight multi-challenge security."],"priority":"tier-3","profile":{"assumption":"Static pairing","expressivity":"Monotone LSSS","security":"Adaptive","setup":"Large universe","size":"FABEO concrete benchmark"},"provenance":["ABE-PAPER-2007-BSW","ABE-PAPER-2013-RW","ABE-PAPER-2014-CW-SEMIADAPTIVE","ABE-PAPER-2017-FAME","ABE-PAPER-2019-KW","ABE-PAPER-2022-FABEO"],"routes":["ABE-ROUTE-007","ABE-ROUTE-009"],"status":"open","title":"FABEO-level concrete ABE efficiency under static standard assumptions"},"primaryUrl":null,"sections":[{"content":"FABEO-level concrete ABE efficiency under static standard assumptions","heading":"Overview"},{"content":"Construct expressive large-universe reusable LSSS KP/CP-ABE matching FABEO's main concrete object and pairing counts, with adaptive multi-challenge security from a static pairing assumption and without GGM or random oracles.","heading":"Current normalized statement"},{"content":"Let \\(m\\) be the attribute-set size, \\(r_f\\) the LSSS row count, and \\(\\tau_f\\) the maximum label multiplicity. For Type-III pairing KP-ABE, match the FABEO benchmark \\[ \\begin{array}{c|ccc} & \\mathbb G_1 & \\mathbb G_2 & \\mathbb G_T\\\\ \\hline \\mathsf{mpk} & 1 & 1 & 1\\\\ \\mathsf{sk}_f & r_f & \\tau_f & 0\\\\ \\mathsf{ct}_x & m & 1 & 1 \\end{array} \\] and at most \\(\\tau_f+1\\) pairings for decryption. For CP-ABE, match \\[ \\mathsf{sk}_x:(m+1,1,0),\\qquad \\mathsf{ct}_f:(r_f,\\tau_f+1,1), \\] in \\((\\mathbb G_1,\\mathbb G_2,\\mathbb G_T)\\) and at most \\(\\tau_f+2\\) pairings. Hash descriptions and clear policies/attributes are reported separately; replacing a source-group element by a larger or nonstandard object does not count as matching. Support large-universe monotone LSSS with repeated labels and adaptive multi-challenge IND-CPA security for polynomially many key and ciphertext queries. The reduction must use a fixed static pairing assumption in the standard model: no ROM/QROM, GGM, knowledge, or query-dependent q-type assumption. A constant-factor relaxation is a named stepping stone; exact resolution requires both KP and CP benchmarks or a cost-preserving duality.","heading":"Exact normalized target"},{"content":"FABEO provides the target efficiency and adaptive multi-challenge security in GGM+ROM. FAME provides efficient adaptive expressive ABE under DLIN but uses ROM and larger objects. Kowalczyk–Wee provides adaptive NC1 ABE from static assumptions without ROM at substantially larger size/cost.","heading":"Closest known results"},{"content":"This endpoint connects conservative proof assumptions to the most attractive known concrete pairing performance. A new standard-model cancellation or dual-system mechanism would be a reusable technical contribution. An isolated one-element shave remaining in GGM+ROM is not an eventual goal.","heading":"Why it matters"},{"content":"Pair-encoding optimization, dual-system semi-functional spaces, and projectable functional-key compilers are the main routes. Existing unbounded IPFE interfaces fail the precise source-group projectability required by one natural compiler, and some apparent cancellation improvements are template-optimal rather than new schemes.","heading":"Known routes and barriers"},{"content":"Remove ROM while keeping GGM and the concrete profile. Obtain a static-assumption theorem with a small constant-factor cost. Add tight multi-challenge security.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-3","summary":"Construct expressive large-universe reusable LSSS KP/CP-ABE matching FABEO's main concrete object and pairing counts, with adaptive multi-challenge security from a static pairing assumption and without GGM or random oracles.","title":"FABEO-level concrete ABE efficiency under static standard assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-008"},{"evidence":"candidate","id":"ABE-OP-005","keywords":["registered-abe","multi-authority","lattices","transparent-setup"],"metadata":{"barriers":[],"closest_results":["ABE-PAPER-2023-ZZGQ-REGPE","ABE-PAPER-2025-CHW-RABE","ABE-PAPER-2026-SWW-RABE","ABE-PAPER-2025-LWW-MARABE","ABE-PAPER-2023-DKW"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[],"hierarchy_role":"primary_north_star","id":"ABE-OP-005","keywords":["registered-abe","multi-authority","lattices","transparent-setup"],"normalization_delta":"No cited paper poses this exact combination.  The dossier merges the decentralization goal of multi-authority ABE with registered ABE's transparent setup, modern formula/circuit expressivity, adaptive corruption, and a clean post-quantum assumption target.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Sections 2.2 and 4 and Appendices B--C, PDF pp. 7, 9, and 18--27","paper":"ABE-PAPER-2011-LW-MAABE","relation":"theorem_frontier"},{"location":"Theorems 5.6--5.9 and 6.5--6.7, PDF pp. 20--23 and 49","paper":"ABE-PAPER-2023-HLWW","relation":"theorem_frontier"},{"location":"Section 2.2 and Theorem 1, PDF pp. 9--10 and 14","paper":"ABE-PAPER-2023-ZZGQ-REGPE","relation":"theorem_frontier"},{"location":"Theorems 5.2--5.4, 6.6--6.10, and 7.7--7.11, PDF pp. 23--30, 50--54, and 61--65","paper":"ABE-PAPER-2025-LWW-MARABE","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Lattice registered ABE for formulas from decomposed/succinct LWE with a transparent setup.","Remove setup bounds on users or input length.","Separate adaptive registration/corruption from adaptive policy selection.","Replace ROM or strong lattice assumptions."],"priority":"tier-2","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"General circuits","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2011-LW-MAABE","ABE-PAPER-2023-HLWW","ABE-PAPER-2023-ZZGQ-REGPE","ABE-PAPER-2025-LWW-MARABE"],"routes":["ABE-ROUTE-001","ABE-ROUTE-006","ABE-ROUTE-010","ABE-ROUTE-013","ABE-ROUTE-014"],"status":"open","title":"General trustless ABE from clean post-quantum assumptions"},"primaryUrl":null,"sections":[{"content":"General trustless ABE from clean post-quantum assumptions","heading":"Overview"},{"content":"Construct registered or multi-authority ABE for general formulas/circuits with transparent or unbounded setup, stateless user key generation, and strong adaptive security from plain or comparably clean post-quantum assumptions, preferably without a random oracle.","heading":"Current normalized statement"},{"content":"Resolve at least one of the following named APIs; results for the two APIs are never conflated. Registered branch. Global setup takes only \\(1^\\lambda\\). Each of any late-bound \\(N=\\operatorname{poly}(\\lambda)\\) users independently generates \\((\\mathsf{pk}_i,\\mathsf{sk}_i)\\). Registration and any curator/aggregation step are public and deterministic, with no trapdoor and no stateful secret issuance. After registration, an encryptor may choose a general formula \\(P\\) over registered users. Require \\[ \\|\\mathsf{aggpk}_P\\|_{\\rm crypt},\\quad \\|\\mathsf{ct}_P\\|_{\\rm crypt},\\quad \\|\\mathsf{hint}_i\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda,\\log N), \\] independent of \\(S_P\\) and coalition size; clear registry and policy descriptions remain in total-size accounting. Multi-authority branch. There is no central master secret. Authorities join after global setup, independently issue attribute components, and a general formula/circuit may combine attributes from multiple authorities. Global public state and ciphertext cryptographic core are independent of the number of authorities except for explicit per-authority metadata. For either branch, require adaptive IND-CPA payload security with any polynomial number of legal keys, adaptive registrations, and adaptive user/authority corruptions under an explicitly stated nontrivial admissibility condition. The target is standard-model plain polynomial-ratio LWE. A ROM or succinct/decomposed-LWE construction is a major partial result; pairings or iO are separate assumption branches. A theorem resolving one named API makes the card partially solved; both APIs, or a compiler proving one from the other without losing these properties, resolves the combined card.","heading":"Exact normalized target"},{"content":"Ordinary ABE centralizes key issuance. Registered and multi-authority APIs remove or distribute that trust while retaining fine-grained policy control. The strongest current expressivity, setup, adaptivity, and PQ-assumption properties are not available simultaneously.","heading":"Why it matters"},{"content":"Waters–Wee–Wu: lattice MA-ABE for subset/DNF-style policies without ROM from evasive LWE, plus a plain-LWE ROM branch. Champion–Hsieh–Wu: bounded-depth registered ABE from succinct LWE in ROM with optimal ciphertext dependence on input length. Stracovsky–Waters–Wu: pairing registered ABE for MSPs with linear CRS; static plain-model security or adaptive ROM security. Datta–Komargodski–Waters: the first decentralized MA-ABE secure under adaptive authority corruptions, from pairings and a random oracle. Garg–Lu–Waters–Wu: nearly-linear bounded-user pairing CRS, and a static branch independent of the attribute-universe size. Zhu–Zhang–Gong–Qian: a generic prime-order pairing compiler from predicate encodings to registered ABE, but with bounded slots, explicit public-key verification, and quadratic generic CRS accounting. Lu–Waters–Wu: multi-authority registered ABE for bounded users/LSSS from pairings, and an unbounded/general iO feasibility branch.","heading":"Closest known results"},{"content":"Lattice registered ABE for formulas from decomposed/succinct LWE with a transparent setup. Remove setup bounds on users or input length. Separate adaptive registration/corruption from adaptive policy selection. Replace ROM or strong lattice assumptions.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-2","summary":"Construct registered or multi-authority ABE for general formulas/circuits with transparent or unbounded setup, stateless user key generation, and strong adaptive security from plain or comparably clean post-quantum assumptions, preferably without a random oracle.","title":"General trustless ABE from clean post-quantum assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-005"},{"evidence":"candidate","id":"ABE-OP-011","keywords":["revocation","revocable-storage","public-update","secure-key-leasing","post-quantum"],"metadata":{"barriers":[],"closest_results":["ABE-PAPER-2025-KNP-SKL","ABE-PAPER-2024-LYXXZPD-HRABE","ABE-PAPER-2012-SSW-REVOCATION"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[],"hierarchy_role":"orthogonal_north_star","id":"ABE-OP-011","keywords":["revocation","revocable-storage","public-update","secure-key-leasing","post-quantum"],"normalization_delta":"The dossier does not merge revocable storage, certified deletion, hardware revocation, and secure key leasing into one undefined primitive.  It extracts two explicit lifecycle APIs and combines their residual scalability, adaptivity, certificate, expressivity, and clean-PQ requirements.  The classical-certificate dependency on polynomial-arity MIABE is recorded as a stated limitation, not a theorem already achieved.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Theorem 3.4, Definition 4.1, and Theorems 7.1--7.2, PDF pp. 9, 17, and 19","paper":"ABE-PAPER-2012-SSW-REVOCATION","relation":"theorem_frontier"},{"location":"Theorems 6.3 and 8.3, PDF pp. 16 and 24","paper":"ABE-PAPER-2021-GLW","relation":"theorem_frontier"},{"location":"Theorems 3--4 and Definitions 7--8, PDF pp. 10--11 and 16--17","paper":"ABE-PAPER-2024-LYXXZPD-HRABE","relation":"theorem_frontier"},{"location":"Theorems 2.2, 7.13, and 8.7, PDF pp. 11, 43, and 50","paper":"ABE-PAPER-2025-KNP-SKL","relation":"stated_limitation"}],"origin_type":"normalized_lineage_gap","partial_targets":["Do not merge user revocation, attribute revocation, ciphertext erasure, certified deletion, and secure key leasing.","Normalize forward/backward security and the adversary's epoch-wise key, update-token, verification, and corruption queries.","For SKL, first remove the polynomial-arity MIABE dependency from the classical-certificate branch or obtain a useful bounded-arity special case.","For public updates, prove an amortized lower/upper bound before claiming storage scalability."],"priority":"tier-2","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"Boolean formulas","security":"Adaptive","setup":"Bounded setup allowed","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2012-SSW-REVOCATION","ABE-PAPER-2021-GLW","ABE-PAPER-2024-LYXXZPD-HRABE","ABE-PAPER-2025-KNP-SKL"],"routes":["ABE-ROUTE-018"],"status":"open","title":"Lifecycle-secure expressive ABE with scalable revocation or key leasing"},"primaryUrl":null,"sections":[{"content":"Lifecycle-secure expressive ABE with scalable revocation or key leasing","heading":"Overview"},{"content":"Revocable-storage ABE formalized public refresh of old ciphertexts and combined it with future-key revocation. Certified deletion and secure key leasing provide stronger cryptographic evidence that access has ended, while hardware revocation trades cryptographic update cost for a TEE assumption. The 2025 ABE-CR-SKL preprint reaches collusion-resistant leasing from LWE but is selective and uses quantum leased keys; classical certificates depend on polynomial-arity MIABE.","heading":"Historical provenance"},{"content":"Construct expressive public-key ABE with adaptive collusion-resistant lifecycle security that offers one of the following clearly separated APIs: public update of old stored ciphertexts with sublinear or amortized update work; or verifiable key revocation/leasing with classical certificates. The construction should use clean post-quantum assumptions and preserve succinct ciphertexts/keys or a trustless ABE API. The security definition must cover collusion across epochs and after revocation evidence is accepted.","heading":"Current normalized statement"},{"content":"Resolve one of the following APIs for formula ABE; solving one branch makes the combined card partially solved. Public-update branch. Algorithms explicitly include \\(\\mathsf{Revoke}(e,R_e)\\) and public \\(\\mathsf{UpdateCT}(e,e+1,\\mathsf{ct})\\). For \\(N\\) users, require update tokens and per-ciphertext update work \\[ \\operatorname{poly}(\\lambda,\\log N,|R_{e+1}\\setminus R_e|), \\] not \\(\\Theta(N)\\) and not a scan proportional to all nonrevoked users. The updated ciphertext core remains \\(\\operatorname{poly}(\\lambda,\\log N)\\) plus the ordinary ABE policy/attribute contribution. Correctness holds for every currently authorized, nonrevoked user and all public update histories. Classical-certificate leasing branch. A leased decryption key is followed by a classical certificate accepted by a public verification algorithm. Once accepted at epoch \\(e\\), even an adversary retaining arbitrary classical state and colluding with other users cannot decrypt later protected ciphertexts outside its remaining authorization. The certificate and verification time are \\(\\operatorname{poly}(\\lambda,\\log N)\\) and do not assume polynomial-arity MIABE unless that primitive is itself instantiated under the assumption target. For either branch, the adversary may adaptively obtain legal keys, update tokens, certificates, and corruptions across polynomially many epochs. The game must state forward and backward security separately. The target uses plain polynomial-ratio LWE or another fixed clean post-quantum assumption and supports ordinary succinct ABE or an explicitly trustless API. TEE-only security, selective single-epoch security, and quantum-only deletion evidence are named weaker variants.","heading":"Exact normalized target"},{"content":"Ordinary ABE controls initial authorization but says little about loss of access after roles or attributes change. Storage-scale update work and verifiable post-revocation loss of decryption ability are qualitative gaps, not cosmetic implementation details.","heading":"Why it matters"},{"content":"Do not merge user revocation, attribute revocation, ciphertext erasure, certified deletion, and secure key leasing. Normalize forward/backward security and the adversary's epoch-wise key, update-token, verification, and corruption queries. For SKL, first remove the polynomial-arity MIABE dependency from the classical-certificate branch or obtain a useful bounded-arity special case. For public updates, prove an amortized lower/upper bound before claiming storage scalability.","heading":"Main risks and stepping stones"},{"content":"Epoch transition correctness and query admissibility are scriptable. Quantum deletion/leasing reductions, collusion across epochs, and TEE leakage models need manual or specialized formal verification.","heading":"Verification boundary"}],"status":"open","subtitle":"tier-2","summary":"Construct expressive public-key ABE with adaptive collusion-resistant lifecycle security that offers one of the following clearly separated APIs: public update of old stored ciphertexts with sublinear or amortized update work; or verifiable key revocation/leasing with classical certificates. The construction should use clean post-quantum assumptions and preserve succinct ciphertexts/keys or a trustless ABE API. The…","title":"Lifecycle-secure expressive ABE with scalable revocation or key leasing","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-011"},{"evidence":"candidate","id":"ABE-OP-006","keywords":["fbe","ibbe","dmpe","adaptivity","standard-model"],"metadata":{"barriers":["ABE-BARRIER-002"],"closest_results":["ABE-PAPER-2026-GY-EQUIVOCAL-BE","ABE-PAPER-2025-HWW-ADAPTIVE-BE","ABE-PAPER-2026-GY-FBE","ABE-PAPER-2026-CW-OPT-DMPE"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"A standard-model adaptive equivocation layer would remove a central model barrier in succinct trustless ABE.","relation":"enabling_component_for","target":"ABE-OP-005"}],"hierarchy_role":"major_stepping_stone","id":"ABE-OP-006","keywords":["fbe","ibbe","dmpe","adaptivity","standard-model"],"normalization_delta":"The cited papers establish a plain-model generic adaptive-BE compiler, an optimal adaptive lattice-DBE endpoint with either succinct ROM CRS or long standard-model CRS, and optimal adaptive or DNF-succinct ROM endpoints. The dossier isolates their still-missing intersection: standard model, optimal succinctness, and the relevant adaptive trustless interface.  It does not attribute this exact conjunction to any one paper.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Definition 4.1, Theorems 5.3 and 5.12, and Construction 6.21 with Theorems 6.22--6.25, PDF pp. 14--19 and 30--33","paper":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","relation":"theorem_frontier"},{"location":"Abstract and Introduction, ePrint 2026/792","paper":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","relation":"theorem_frontier"},{"location":"Theorems 5.3, 5.6, 6.2--6.3, 7.4, and 8.5--8.6, PDF pp. 24--40","paper":"ABE-PAPER-2026-GY-FBE","relation":"theorem_frontier"},{"location":"Theorems 3.2--3.3, 4.2--4.3, and 5.6--5.10, PDF pp. 22--48","paper":"ABE-PAPER-2026-CW-OPT-DMPE","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["A publicly-sampleable projective PRG with poly(lambda,log ell) projected seed and sublinear public parameters when ell is fixed at setup.","Upgrade that pPRG to universal Setup(1^lambda) and public parameters independent of the later output length.","A standard-model adaptive DBE with sublinear CRS and optimal ciphertext.","Equivocal matrix commitment with standard-model setup under an explicit dual-mode assumption.","Adaptive policy but static corruptions.","Optimal parameters after the simulation interface is stable."],"priority":"tier-2","profile":{"assumption":"Fixed falsifiable assumption","expressivity":"Ordinary ABE","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2025-HWW-ADAPTIVE-BE","ABE-PAPER-2026-GY-EQUIVOCAL-BE","ABE-PAPER-2026-GY-FBE","ABE-PAPER-2026-CW-OPT-DMPE"],"routes":["ABE-ROUTE-006","ABE-ROUTE-019"],"status":"open","title":"Optimally succinct adaptive trustless encryption without random oracles"},"primaryUrl":null,"sections":[{"content":"Optimally succinct adaptive trustless encryption without random oracles","heading":"Overview"},{"content":"Remove the random oracle from optimally succinct adaptive FBE, IBBE, or DMPE while retaining transparent/unbounded setup and a falsifiable post-quantum assumption. For DMPE and registered variants, include adaptive corruptions as a separate target from adaptive policy selection.","heading":"Current normalized statement"},{"content":"For at least one of FBE, IBBE, or DMPE, global setup takes only \\(1^\\lambda\\) and the user count \\(N\\) is chosen after setup. Users register independently. After observing the public directory and making legal pre-challenge queries, the adversary may choose the challenge recipient set or policy. Require \\[ \\|\\mathsf{aggregate\\ key}\\|_{\\rm crypt},\\quad \\|\\mathsf{ct}\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda,\\log N), \\] with no hidden linear dependence on \\(N\\) or the policy description; any per-user decryption hint is also \\(\\operatorname{poly}(\\lambda,\\log N)\\). Security is adaptive IND-CPA for any polynomial query count. Adaptive policy choice is mandatory; adaptive user corruption is mandatory for the strongest DMPE/registered branch and otherwise reported separately. The proof must be in the standard model—no programmable ROM or QROM—and use a fixed falsifiable post-quantum assumption. Decomposed LWE is allowed if the exact game and ratio are stated. A standard-model sublinear construction that does not yet reach the displayed polylogarithmic bound is a weaker stepping stone, not a resolution.","heading":"Exact normalized target"},{"content":"Goyal--Yadugiri 2026/792 achieve optimal adaptive lattice distributed broadcast encryption with a succinct CRS in ROM and a long CRS in the standard model, using equivocal encryption systems. Hsieh--Waters--Wu give a plain-model semi-static-to-adaptive broadcast compiler from publicly-sampleable projective PRGs; their LWE pPRG has a succinct projected seed but public parameters linear in its output length. Goyal--Yadugiri 2026/862 achieve adaptive optimal FBE/IBBE from decomposed LWE in ROM, using equivocal matrix commitments. Champion--Wu obtain optimal adaptive-policy DNF DMPE in ROM and plain-model variants with selectivity or ciphertext-size tradeoffs.","heading":"Closest known results"},{"content":"The result would turn highly succinct trustless lattice encryption from a programmable-oracle construction into a standard-model primitive and likely yield reusable adaptive commitment/preimage techniques.","heading":"Why it matters"},{"content":"There are now two sharply separated routes. The first is a policy- or directory-level noncommitting state: commit before the challenge and later explain jointly correlated openings. The second is a publicly-sampleable projective PRG whose public parameters are independent of its output length, so the Hsieh--Waters--Wu plain-model compiler no longer contributes a linear CRS. The current ABE canonical-preimage failures show that independent rerandomization is insufficient when multiple legal rejecting keys expose a shared master difference.","heading":"Known routes and barriers"},{"content":"A publicly-sampleable projective PRG with poly(lambda,log ell) projected seed and sublinear public parameters when ell is fixed at setup. Upgrade that pPRG to universal Setup(1^lambda) and public parameters independent of the later output length. A standard-model adaptive DBE with sublinear CRS and optimal ciphertext. Equivocal matrix commitment with standard-model setup under an explicit dual-mode assumption. Adaptive policy but static corruptions. Optimal parameters after the simulation interface is stable.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-2","summary":"Remove the random oracle from optimally succinct adaptive FBE, IBBE, or DMPE while retaining transparent/unbounded setup and a falsifiable post-quantum assumption. For DMPE and registered variants, include adaptive corruptions as a separate target from adaptive policy selection.","title":"Optimally succinct adaptive trustless encryption without random oracles","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-006"},{"evidence":"candidate","id":"ABE-OP-009","keywords":["multi-input-abe","polynomial-arity","post-quantum","witness-encryption"],"metadata":{"barriers":[],"closest_results":["ABE-PAPER-2023-ARYY","ABE-PAPER-2022-AYY-MIABE"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"Polynomial-arity MIABE is the explicit missing primitive for the classical-certificate ABE-SKL branch.","relation":"enabling_component_for","target":"ABE-OP-011"}],"hierarchy_role":"line_north_star","id":"ABE-OP-009","keywords":["multi-input-abe","polynomial-arity","post-quantum","witness-encryption"],"normalization_delta":"The source line progresses from two inputs to every fixed constant arity. The dossier identifies polynomial arity as the next qualitative boundary and additionally asks for a clean falsifiable post-quantum assumption.  It does not present that exact combined target as a quotation from either paper.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Theorems 4.1, 5.6, and 6.2, PDF pp. 29, 39, and 46","paper":"ABE-PAPER-2022-AYY-MIABE","relation":"theorem_frontier"},{"location":"Theorems 4.1, 5.1, and 5.13, PDF pp. 31, 43, and 53","paper":"ABE-PAPER-2023-ARYY","relation":"theorem_frontier"}],"origin_type":"normalized_lineage_gap","partial_targets":["Formalize whether input encryption is public- or master-secret-key based in the targeted application; do not merge symmetric and public-key games.","Prove a binary composition theorem for four inputs with unbounded key collusion before claiming recursion.","Track tensor dimension, reduction loss, and lattice noise under recursion.","Replace evasive/tensor assumptions only after the arity interface is sound."],"priority":"tier-2","profile":{"assumption":"Plain / polynomial-ratio LWE","expressivity":"NC¹ formulas","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2022-AYY-MIABE","ABE-PAPER-2023-ARYY"],"routes":["ABE-ROUTE-016","ABE-ROUTE-012","ABE-ROUTE-013"],"status":"open","title":"Polynomial-arity expressive multi-input ABE from clean post-quantum assumptions"},"primaryUrl":null,"sections":[{"content":"Polynomial-arity expressive multi-input ABE from clean PQ assumptions","heading":"Overview"},{"content":"Agrawal–Yadav–Yamada formalized MIABE/MIPE and obtained two-input NC1 ABE using LWE together with a generic-group pairing or a knowledge assumption. Agrawal–Rossi–Yadav–Yamada reached every constant arity for NC1 from evasive LWE, and P with an additional tensor-LWE strengthening.","heading":"Historical provenance"},{"content":"Construct MIABE for NC1, or a comparably broad natural class, with polynomial arity and unbounded-collusion security from plain LWE or another clean, falsifiable post-quantum assumption. A meaningful intermediate target is a composition theorem from constant arity with explicit security/noise loss.","heading":"Current normalized statement"},{"content":"Global setup takes only \\(1^\\lambda\\) and no arity bound. After setup choose any \\(a=\\operatorname{poly}(\\lambda)\\), inputs \\((x_1,\\ldots,x_a)\\), and an \\(NC^1\\) function \\(f(x_1,\\ldots,x_a)\\). The MIABE algorithms produce separately generated input ciphertexts \\(\\mathsf{ct}_{j,x_j}\\) and a reusable \\(\\mathsf{sk}_f\\) such that decryption succeeds exactly when \\(f(x_1,\\ldots,x_a)=1\\). Require \\[ \\|\\mathsf{mpk}\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda),\\quad \\|\\mathsf{ct}_{j,x_j}\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda,L_{x_j}),\\quad \\|\\mathsf{sk}_f\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda,S_f,a), \\] with no setup parameter or exponential factor in \\(a\\). A stronger succinct-key theorem may remove \\(S_f,a\\) from the last bound. The minimum security target is selective challenge-tuple IND-CPA with any polynomial number of colluding function keys; adaptive tuple selection is a strengthening. The scheme must use plain polynomial-ratio LWE or another fixed falsifiable post-quantum assumption. GGM, knowledge, evasive, tensor, and extended-tensor assumptions do not resolve the clean-assumption target. Every fixed constant arity remains a weaker result even if the construction is described by one family of algorithms.","heading":"Exact normalized target"},{"content":"MIABE is a route to multi-input predicate encryption and witness-encryption compression. Polynomial arity would cross a qualitative boundary rather than improve one constant.","heading":"Why it matters"},{"content":"Formalize whether input encryption is public- or master-secret-key based in the targeted application; do not merge symmetric and public-key games. Prove a binary composition theorem for four inputs with unbounded key collusion before claiming recursion. Track tensor dimension, reduction loss, and lattice noise under recursion. Replace evasive/tensor assumptions only after the arity interface is sound.","heading":"Main risks and stepping stones"},{"content":"Finite correctness and algebraic dependency tests can be automated. The cross-input simulation and assumption reduction require a manual proof or a dedicated formal game backend.","heading":"Verification boundary"}],"status":"open","subtitle":"tier-2","summary":"Construct MIABE for NC1, or a comparably broad natural class, with polynomial arity and unbounded-collusion security from plain LWE or another clean, falsifiable post-quantum assumption. A meaningful intermediate target is a composition theorem from constant arity with explicit security/noise loss.","title":"Polynomial-arity expressive multi-input ABE from clean post-quantum assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-009"},{"evidence":"candidate","id":"ABE-OP-003","keywords":["unbounded-depth","lattices","circular-security","post-quantum"],"metadata":{"barriers":["ABE-BARRIER-004"],"closest_results":["ABE-PAPER-2023-HLL","ABE-PAPER-2026-AMYY","ABE-PAPER-2025-AMY-TM"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"A safe direct removal of depth bounds supplies the all-circuit expressivity component of universal ordinary ABE.","relation":"enabling_component_for","target":"ABE-OP-002"}],"hierarchy_role":"primary_north_star","id":"ABE-OP-003","keywords":["unbounded-depth","lattices","circular-security","post-quantum"],"normalization_delta":"The authors explicitly ask for direct unbounded-depth ABE and, after the evasive-circular assumption was broken, for a safe construction without compact FE or obfuscation.  The dossier strengthens “safe” into the auditable requirements well-founded, instance-independent, and preferably post-quantum; the 2026 candidate is therefore a closest result, not silently declared a resolution.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Abstract and Introduction, PDF pp. 1--2","paper":"ABE-PAPER-2023-HLL","relation":"explicit_open_question"},{"location":"Abstract, PDF p. 1","paper":"ABE-PAPER-2026-AMYY","relation":"explicit_open_question"}],"origin_type":"explicit_open_question","partial_targets":["One-key or laconic unbounded-depth primitive from circular LWE.","Bounded-collusion ABE from a modular, independently testable recoding assumption.","Full collusion with instance-independent auxiliary information.","Post-quantum replacement for any group/KDM component.","A lattice-only circular-decomposed refresh lemma with a separately audited policy-gating assumption."],"priority":"tier-1","profile":{"assumption":"Lattice assumption","expressivity":"General circuits","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2023-HLL","ABE-PAPER-2026-AMYY"],"routes":["ABE-ROUTE-004","ABE-ROUTE-008","ABE-ROUTE-021"],"status":"open","title":"Safe direct ABE for circuits of unbounded depth"},"primaryUrl":null,"sections":[{"content":"Safe direct ABE for circuits of unbounded depth","heading":"Overview"},{"content":"Hsieh–Lin–Luo asked whether circular-security techniques that remove depth bounds in FHE could do the same for ABE, and constructed unbounded-depth ABE from evasive circular LWE. The relevant assumption was subsequently reported broken. Agrawal–Modi–Yadav–Yamada explicitly restated the need for a safe construction without compact FE or obfuscation and proposed a doubly-circular assumption with bilinear-GGM evidence.","heading":"Historical provenance"},{"content":"Construct collusion-resistant ABE for arbitrary polynomial-size and unbounded-depth circuits without invoking general FE/iO, from an assumption that is well-founded, instance-independent, and preferably post-quantum. Adaptive security and complete input-length unboundedness are stronger goals.","heading":"Current normalized statement"},{"content":"For each polynomial input-length bound \\(L\\), run \\(\\mathsf{Setup}(1^\\lambda,1^L)\\) without a depth or circuit-size bound. For every \\(x\\in\\{0,1\\}^{\\le L}\\) and every polynomial-size circuit \\(f\\) of arbitrary polynomial depth, provide ordinary reusable KP-ABE with \\[ \\|\\mathsf{mpk}\\|_{\\rm crypt},\\|\\mathsf{ct}_x\\|_{\\rm crypt} =\\operatorname{poly}(\\lambda,L),\\qquad \\|\\mathsf{sk}_f\\|_{\\rm crypt}=\\operatorname{poly}(\\lambda), \\] or a CP construction with the roles and stated bounds explicitly transposed. No algorithm or parameter may contain a hidden \\(d_{\\max}\\). The minimum security target is selective IND-CPA with any polynomial number of legal keys; adaptive security is a strengthening, not silently assumed. The construction must be direct: it may not invoke general-purpose FE, compact FE, or iO as a black box. Its assumption must have a fixed, efficiently samplable game independent of the adversary's chosen circuit and must survive the known attack relevant to evasive circular LWE. The preferred resolution uses plain or circular LWE with a stated post-quantum rationale; a lattice-plus-bilinear or GGM-only candidate is recorded as partial progress.","heading":"Exact normalized target"},{"content":"This is the ABE analogue of removing leveled depth bounds in homomorphic encryption. It would change functionality rather than only parameters and would repair a frontier destabilized by attacks on strong circular/evasive assumptions.","heading":"Why it matters"},{"content":"Hsieh–Lin–Luo: direct full ABE from evasive circular LWE; assumption caveat. Agrawal–Modi–Yadav–Yamada: new falsifiable doubly-circular candidate with bilinear-GGM evidence; the group component prevents a clean PQ conclusion. General FE/iO compilers: feasibility under much heavier machinery. Turing-machine ABE: stronger computation model under evasive/tensor/circular assumption combinations, inheriting assumption-quality questions.","heading":"Closest known results"},{"content":"The main direct route couples recursive/circular lattice evaluation with an evasive extraction or recoding property. Separating these roles may yield a safer modular assumption; merely renaming their conjunction does not. One concrete unexplored branch is circular decomposed LWE: use decomposed LWE for a compact lattice-only recoding/refresh step and state the circular or KDM clause separately. This is not yet an assumption or construction. It is valuable only if its game is instance-independent, survives the attack on evasive circular LWE, and yields a proved depth-refresh lemma without the bilinear/GGM component of the current doubly-circular candidate. Scoped circularity-necessity question The broad statement “circularity is necessary for unbounded ABE” is not a well-formed unconditional problem: arbitrary constructions could remove depth bounds by unrelated methods. The dossier records the following precise barrier target instead. In a black-box compiler that iterates a bounded-depth lattice ABE evaluator while keeping setup and key size independent of the number of iterations, prove that either (i) the public evaluation state computationally exposes an encryption/encoding of its own secret recoding state, yielding a circular/KDM-security implication, or (ii) exhibit a compiler outside that model. A lower bound must specify the compiler model; failure to find a construction is not evidence of necessity.","heading":"Known routes and barriers"},{"content":"One-key or laconic unbounded-depth primitive from circular LWE. Bounded-collusion ABE from a modular, independently testable recoding assumption. Full collusion with instance-independent auxiliary information. Post-quantum replacement for any group/KDM component. A lattice-only circular-decomposed refresh lemma with a separately audited policy-gating assumption.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-1","summary":"Construct collusion-resistant ABE for arbitrary polynomial-size and unbounded-depth circuits without invoking general FE/iO, from an assumption that is well-founded, instance-independent, and preferably post-quantum. Adaptive security and complete input-length unboundedness are stronger goals.","title":"Safe direct ABE for circuits of unbounded depth","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-003"},{"evidence":"candidate","id":"ABE-OP-004","keywords":["dmpe","threshold","lsss","lattices","trustless"],"metadata":{"barriers":["ABE-BARRIER-001"],"closest_results":["ABE-PAPER-2026-CW-OPT-DMPE","ABE-PAPER-2026-CW-DMPE","ABE-PAPER-2026-SWW-RABE"],"dossier_type":"open_problem","evidence":"candidate","hierarchy_links":[{"note":"Expressive falsifiable-lattice DMPE supplies a central policy-sharing/recoding component for clean-PQ trustless ABE.","relation":"enabling_component_for","target":"ABE-OP-005"}],"hierarchy_role":"line_north_star","id":"ABE-OP-004","keywords":["dmpe","threshold","lsss","lattices","trustless"],"normalization_delta":"Champion--Wu explicitly ask for lattice DMPE beyond DNF and name general thresholds as a natural target.  The dossier broadens the endpoint to formulas/MSPs and adds transparent-setup, ciphertext-size, assumption, and adaptivity axes that must be reported separately.","notation":"ABE-OPEN-v1","origin_evidence":[{"location":"Introduction, subsection 'An open problem: beyond DNFs from lattices,' printed p. 11; Definition B.3","paper":"ABE-PAPER-2026-CW-DMPE","relation":"explicit_open_question"},{"location":"Theorems 3.2--3.3, 4.2--4.3, and 5.6--5.10, PDF pp. 22--48","paper":"ABE-PAPER-2026-CW-OPT-DMPE","relation":"theorem_frontier"}],"origin_type":"explicit_open_question","partial_targets":["Independently audit and publish the reconstruction-height barrier.","Construct a uniform multi-row sharing family with bounded per-user hint.","Prove the policy-recoding/lifting lemma for the required commitment API.","Instantiate a growing-threshold DMPE special case before general MSPs."],"priority":"tier-1","profile":{"assumption":"Lattice assumption","expressivity":"Monotone LSSS","security":"Adaptive","setup":"Late-bound / unbounded","size":"Succinct cryptographic core"},"provenance":["ABE-PAPER-2026-CW-DMPE","ABE-PAPER-2026-CW-OPT-DMPE"],"routes":["ABE-ROUTE-005","ABE-ROUTE-006"],"status":"open","title":"Succinct lattice DMPE beyond DNF"},"primaryUrl":null,"sections":[{"content":"Succinct lattice DMPE beyond DNF","heading":"Overview"},{"content":"Champion–Wu construct lattice DMPE for DNF policies and identify extension beyond DNF—especially general threshold policies—as a central open direction. Their lattice interface needs both small reconstruction coefficients and linear independence for unauthorized rows. Standard Shamir sharing and known small-coefficient erasure-code constructions do not provide both properties in the required form. The explicit statement appears in the introduction, subsection “An open problem: beyond DNFs from lattices,” printed p. 11; the formal interface is Definition B.3.","heading":"Historical provenance"},{"content":"Construct lattice-based DMPE for growing threshold policies, general formulas, or monotone span programs with transparent setup, unbounded users, and ciphertext size independent of or sublinear in the policy description, under a falsifiable post-quantum assumption. Record policy adaptivity and corruption adaptivity separately.","heading":"Current normalized statement"},{"content":"The first exact target is growing-threshold DMPE. Global setup fixes only \\(\\lambda\\). Any \\(N=\\operatorname{poly}(\\lambda)\\) users independently generate \\((\\mathsf{pk}_i,\\mathsf{sk}_i)\\), and after registration an encryptor chooses \\(t\\in[N]\\) and a \\(t\\)-out-of-\\(N\\) policy. Require \\[ \\begin{aligned} \\|\\mathsf{ct}_{t,N}\\|_{\\rm crypt} &=\\operatorname{poly}(\\lambda,\\log N),\\\\ \\|\\mathsf{hint}_i\\|_{\\rm crypt} &=\\operatorname{poly}(\\lambda,\\log N), \\end{aligned} \\] so neither object is linear in the policy description or coalition size. Every coalition of size at least \\(t\\) must decrypt from its hints; every coalition of size below \\(t\\) must have negligible payload advantage. The target must support a growing regime such as \\(t=\\lfloor N/2\\rfloor\\); constant \\(t\\) does not resolve it. The minimum theorem has transparent setup, late-bound \\(N\\), static registrations/corruptions, and a policy chosen after public keys are available. Policy adaptivity, adaptive corruptions, and general formulas/MSPs are separate strengthenings. The assumption must be falsifiable and post-quantum; decomposed LWE is allowed if its precise ratio is stated. A construction for the threshold target makes the card partially solved; full resolution requires a natural class strictly beyond thresholds, such as general formulas or MSPs, with an equally explicit succinctness bound.","heading":"Exact normalized target"},{"content":"This is the main expressivity bottleneck for post-quantum trustless policy encryption. The same sharing/recoding component can affect MA-ABE, registered ABE, threshold traitor tracing, and reusable computational secret sharing.","heading":"Why it matters"},{"content":"Champion–Wu 2026/1464: optimal DNF DMPE in ROM; plain-model tradeoffs for k-DNF and broadcast specializations. Pairing registered/silent-threshold work: thresholds and MSPs are possible, but not with the desired lattice/PQ assumption profile.","heading":"Closest known results"},{"content":"One-row-per-user exact-threshold LSSS with bounded reconstruction height. Multi-row LSSS compiler that gives one user hint despite repeated rows. Translation-equivocal policy commitments that program witness-dependent recoding equations. The repository proves an exponential reconstruction-height lower bound for a scoped injective one-row interface in the no-wrap regime. It rules out that compiler path, not multi-row sharing or all threshold DMPE.","heading":"Known routes and barriers"},{"content":"Independently audit and publish the reconstruction-height barrier. Construct a uniform multi-row sharing family with bounded per-user hint. Prove the policy-recoding/lifting lemma for the required commitment API. Instantiate a growing-threshold DMPE special case before general MSPs.","heading":"Stepping stones"}],"status":"open","subtitle":"tier-1","summary":"Construct lattice-based DMPE for growing threshold policies, general formulas, or monotone span programs with transparent setup, unbounded users, and ciphertext size independent of or sublinear in the policy description, under a falsifiable post-quantum assumption. Record policy adaptivity and corruption adaptivity separately.","title":"Succinct lattice DMPE beyond DNF","type":"open_problem","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-OP-004"},{"evidence":"published","id":"ABE-PAPER-2005-SW","keywords":["foundations","fuzzy-ibe","collusion-resistance"],"metadata":{"authors":["Amit Sahai","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2005-SW","keywords":["foundations","fuzzy-ibe","collusion-resistance"],"maps_to":["ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2004/086","status":"published","title":"Fuzzy Identity-Based Encryption","venue":"EUROCRYPT 2005","year":2005},"primaryUrl":"https://eprint.iacr.org/2004/086","sections":[{"content":"Sahai–Waters: the threshold-overlap starting point","heading":"Overview"},{"content":"The paper introduced fuzzy IBE: a key for one identity decrypts ciphertexts whose identities overlap in at least a threshold number of positions. It also identified error-tolerant biometric encryption and attribute-based encryption as applications.","heading":"Atomic claims"},{"content":"This is the conceptual origin of ABE, not an expressive Boolean-policy ABE. Its threshold-overlap predicate and selective-identity proof should not be confused with later KP/CP-ABE or with current succinctness questions.","heading":"Historical role and qualifier"},{"content":"The paper left open general access policies, a clean KP/CP syntax, adaptive security, and modern efficiency and setup goals.","heading":"Residual questions exposed"}],"status":"published","subtitle":"Amit Sahai, Brent Waters · 2005","summary":"The paper introduced fuzzy IBE: a key for one identity decrypts ciphertexts whose identities overlap in at least a threshold number of positions. It also identified error-tolerant biometric encryption and attribute-based encryption as applications.","title":"Fuzzy Identity-Based Encryption","type":"paper","venue":"EUROCRYPT 2005","year":2005,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2005-SW"},{"evidence":"published","id":"ABE-PAPER-2006-GPSW","keywords":["foundations","kp-abe","lsss","delegation"],"metadata":{"authors":["Vipul Goyal","Omkant Pandey","Amit Sahai","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2006-GPSW","keywords":["foundations","kp-abe","lsss","delegation"],"maps_to":["ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2006/309","status":"published","title":"Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data","venue":"ACM CCS 2006","year":2006},"primaryUrl":"https://eprint.iacr.org/2006/309","sections":[{"content":"GPSW: expressive key-policy ABE","heading":"Overview"},{"content":"GPSW formalized KP-ABE, placing an attribute set on a ciphertext and an access structure in a secret key. Its secret-sharing view became the basic algebraic language for collusion-resistant access policies and delegation.","heading":"Atomic claims"},{"content":"The construction established expressive feasibility under pairing assumptions, but predates the modern adaptive, unbounded, and succinctness axes. It is the baseline syntax and proof architecture, not a present-day frontier point.","heading":"Historical role and qualifier"},{"content":"Ciphertext-policy syntax, adaptive security, large or unbounded universes, and general circuit policies remained to be developed.","heading":"Residual questions exposed"}],"status":"published","subtitle":"Vipul Goyal, Omkant Pandey, Amit Sahai et al. · 2006","summary":"GPSW formalized KP-ABE, placing an attribute set on a ciphertext and an access structure in a secret key. Its secret-sharing view became the basic algebraic language for collusion-resistant access policies and delegation.","title":"Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data","type":"paper","venue":"ACM CCS 2006","year":2006,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2006-GPSW"},{"evidence":"published","id":"ABE-PAPER-2007-BSW","keywords":["foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"metadata":{"authors":["John Bethencourt","Amit Sahai","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2007-BSW","keywords":["foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"maps_to":["ABE-OP-008"],"primary_url":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","status":"published","title":"Ciphertext-Policy Attribute-Based Encryption","venue":"IEEE Symposium on Security and Privacy 2007","year":2007},"primaryUrl":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","sections":[{"content":"BSW: the first ciphertext-policy ABE construction","heading":"Overview"},{"content":"BSW gave the first CP-ABE construction: a ciphertext carries a monotone threshold access tree, while a user key carries a set of attributes. The paper also supplied a concrete implementation and performance measurements. Its security theorem is adaptive with respect to the challenge access tree and key queries in the paper's CPA game, but only in the generic bilinear group model together with a random oracle for hashing attributes. Theorem 1 bounds a generic adversary's advantage by $O(q^2/p)$.","heading":"Atomic claims"},{"content":"The paper established the ciphertext-policy syntax that became the dominant access-control form of ABE and demonstrated that expressive collusion-resistant ABE was implementable. It must not be cited as a standard-model or static-assumption adaptive-security result.","heading":"Historical role and qualifier"},{"content":"The construction left open security from falsifiable static assumptions, more modular LSSS support, and reductions in policy-dependent ciphertext, key, and decryption costs. These questions led to Waters11, dual-system ABE, predicate encodings, and the modern concrete-efficiency line tracked by ABE-OP-008.","heading":"Residual questions exposed"}],"status":"published","subtitle":"John Bethencourt, Amit Sahai, Brent Waters · 2007","summary":"BSW gave the first CP-ABE construction: a ciphertext carries a monotone threshold access tree, while a user key carries a set of attributes. The paper also supplied a concrete implementation and performance measurements. Its security theorem is adaptive with respect to the challenge access tree and key queries in the paper's CPA game, but only in the generic bilinear group model together with a random oracle for…","title":"Ciphertext-Policy Attribute-Based Encryption","type":"paper","venue":"IEEE Symposium on Security and Privacy 2007","year":2007,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2007-BSW"},{"evidence":"published","id":"ABE-PAPER-2010-LOSSTW","keywords":["adaptive-security","dual-system","pairings","formulas"],"metadata":{"authors":["Allison Lewko","Tatsuaki Okamoto","Amit Sahai","Katsuyuki Takashima","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2010-LOSSTW","keywords":["adaptive-security","dual-system","pairings","formulas"],"maps_to":["ABE-OP-001","ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2010/110","status":"published","title":"Fully Secure Functional Encryption: Attribute-Based Encryption and (Hierarchical) Inner Product Encryption","venue":"EUROCRYPT 2010","year":2010},"primaryUrl":"https://eprint.iacr.org/2010/110","sections":[{"content":"LOSSTW: adaptive expressive ABE via dual systems","heading":"Overview"},{"content":"The work gave the first fully secure ABE for arbitrary monotone access formulas, together with inner-product encryption, using dual-system reasoning in composite-order bilinear groups under static assumptions.","heading":"Atomic claims"},{"content":"Semi-functional keys and ciphertexts let the proof move from real objects to challenge-hiding objects without committing to the challenge at setup. This became the dominant pairing-based route to adaptive ABE.","heading":"Technical mechanism"},{"content":"The result is pairing-based, formula-level, and not a succinct or post-quantum construction. Translating the adaptive capability to lattices without paying strong assumptions remains a central fault line.","heading":"Limitations and residual questions"}],"status":"published","subtitle":"Allison Lewko, Tatsuaki Okamoto, Amit Sahai et al. · 2010","summary":"The work gave the first fully secure ABE for arbitrary monotone access formulas, together with inner-product encryption, using dual-system reasoning in composite-order bilinear groups under static assumptions.","title":"Fully Secure Functional Encryption: Attribute-Based Encryption and (Hierarchical) Inner Product Encryption","type":"paper","venue":"EUROCRYPT 2010","year":2010,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2010-LOSSTW"},{"evidence":"published","id":"ABE-PAPER-2011-WATERS","keywords":["cp-abe","lsss","pairings","standard-model"],"metadata":{"authors":["Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2011-WATERS","keywords":["cp-abe","lsss","pairings","standard-model"],"maps_to":["ABE-OP-002","ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2008/290","status":"published","title":"Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization","venue":"PKC 2011","year":2011},"primaryUrl":"https://eprint.iacr.org/2008/290","sections":[{"content":"Waters CP-ABE: the standard LSSS ciphertext-policy template","heading":"Overview"},{"content":"The paper gave expressive CP-ABE for LSSS access structures in the standard model, with ciphertext and key components attached directly to policy rows and attributes.","heading":"Atomic claims"},{"content":"Its algebra is the canonical efficient CP-ABE template and a frequent source for later prime-order, lattice-analogue, multi-authority, and automated designs.","heading":"Historical role"},{"content":"The security is selective and relies on a q-type pairing assumption. Later adaptive and static-assumption systems should be understood as replacing this proof/assumption profile, not merely renaming the syntax.","heading":"Limitations"}],"status":"published","subtitle":"Brent Waters · 2011","summary":"The paper gave expressive CP-ABE for LSSS access structures in the standard model, with ciphertext and key components attached directly to policy rows and attributes.","title":"Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization","type":"paper","venue":"PKC 2011","year":2011,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2011-WATERS"},{"evidence":"published","id":"ABE-PAPER-2011-LW-MAABE","keywords":["multi-authority","decentralized","pairings","random-oracle"],"metadata":{"authors":["Allison Lewko","Brent Waters"],"citation_key":"LW11a","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2011-LW-MAABE","keywords":["multi-authority","decentralized","pairings","random-oracle"],"maps_to":["ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2010/351","status":"published","title":"Decentralizing Attribute-Based Encryption","venue":"EUROCRYPT 2011","year":2011},"primaryUrl":"https://eprint.iacr.org/2010/351","sections":[{"content":"Lewko–Waters: decentralized multi-authority ABE","heading":"Overview"},{"content":"Any party can act as an attribute authority, and there is no trusted central authority coordinating secret-key issuance. Global user identities bind shares from different authorities and prevent cross-user collusion.","heading":"Atomic claims"},{"content":"This is multi-authority ABE, not registered ABE: authorities still issue attribute secret-key components. The construction uses composite-order pairings and a random oracle.","heading":"Exact qualifiers"},{"content":"Adaptive authority corruption, post-quantum assumptions, transparent key aggregation, and combinations with registered ABE remained open.","heading":"Residual questions"}],"status":"published","subtitle":"Allison Lewko, Brent Waters · 2011","summary":"Any party can act as an attribute authority, and there is no trusted central authority coordinating secret-key issuance. Global user identities bind shares from different authorities and prevent cross-user collusion.","title":"Decentralizing Attribute-Based Encryption","type":"paper","venue":"EUROCRYPT 2011","year":2011,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2011-LW-MAABE"},{"evidence":"published","id":"ABE-PAPER-2011-LW-UNBOUNDED","keywords":["unbounded-abe","lsss","nested-dual-system","pairings"],"metadata":{"authors":["Allison Lewko","Brent Waters"],"citation_key":"LW11b","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2011-LW-UNBOUNDED","keywords":["unbounded-abe","lsss","nested-dual-system","pairings"],"maps_to":["ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2011/049","status":"published","title":"Unbounded HIBE and Attribute-Based Encryption","venue":"EUROCRYPT 2011","year":2011},"primaryUrl":"https://eprint.iacr.org/2011/049","sections":[{"content":"Lewko–Waters: unbounded setup functionality","heading":"Overview"},{"content":"The ABE public parameters impose no a-priori universe or attribute-set-size bound. The scheme supports LSSS access structures and delegation under static pairing assumptions, with selective ABE security.","heading":"Atomic claims"},{"content":"“Unbounded” refers to setup-time functionality bounds. It does not imply constant-size keys/ciphertexts, adaptive security, unbounded circuit depth, or post-quantum security.","heading":"Exact qualifier"},{"content":"This paper is the source of the modern requirement to audit universe, input length, policy size, and depth separately rather than using “unbounded” as one undifferentiated label.","heading":"Historical role"}],"status":"published","subtitle":"Allison Lewko, Brent Waters · 2011","summary":"The ABE public parameters impose no a-priori universe or attribute-set-size bound. The scheme supports LSSS access structures and delegation under static pairing assumptions, with selective ABE security.","title":"Unbounded HIBE and Attribute-Based Encryption","type":"paper","venue":"EUROCRYPT 2011","year":2011,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2011-LW-UNBOUNDED"},{"evidence":"published","id":"ABE-PAPER-2012-SSW-REVOCATION","keywords":["revocation","ciphertext-delegation","revocable-storage","dynamic-credentials"],"metadata":{"authors":["Amit Sahai","Hakan Seyalioglu","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2012-SSW-REVOCATION","keywords":["revocation","ciphertext-delegation","revocable-storage","dynamic-credentials"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2012/437","status":"published","title":"Dynamic Credentials and Ciphertext Delegation for Attribute-Based Encryption","venue":"CRYPTO 2012","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/437","sections":[{"content":"SSW: revocable storage and public ciphertext delegation","heading":"Overview"},{"content":"The paper formalizes revocable-storage ABE, where revocation affects both new ciphertexts and previously stored ciphertexts. It introduces public ciphertext delegation to transform an encryption into an independent encryption under a more restrictive policy, and piecewise key generation for efficient revocation.","heading":"Atomic claims"},{"content":"It shows that ABE revocation is not only key expiration: a complete cloud- storage model must coordinate credential updates, ciphertext updates, and collusion security.","heading":"Historical role"},{"content":"Revocation is an orthogonal lifecycle compiler axis. It becomes a first-class eventual goal only after its overhead and security are audited against the modern succinct, adaptive, and trustless ABE frontiers.","heading":"Relation to the core map"}],"status":"published","subtitle":"Amit Sahai, Hakan Seyalioglu, Brent Waters · 2012","summary":"The paper formalizes revocable-storage ABE, where revocation affects both new ciphertexts and previously stored ciphertexts. It introduces public ciphertext delegation to transform an encryption into an independent encryption under a more restrictive policy, and piecewise key generation for efficient revocation.","title":"Dynamic Credentials and Ciphertext Delegation for Attribute-Based Encryption","type":"paper","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2012-SSW-REVOCATION"},{"evidence":"published","id":"ABE-PAPER-2012-OT","keywords":["unbounded","adaptive-security","kp-abe","cp-abe","inner-product-encryption","dual-system","dlin"],"metadata":{"authors":["Tatsuaki Okamoto","Katsuyuki Takashima"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2012-OT","keywords":["unbounded","adaptive-security","kp-abe","cp-abe","inner-product-encryption","dual-system","dlin"],"maps_to":["ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2012/671","status":"published","title":"Fully Secure Unbounded Inner-Product and Attribute-Based Encryption","venue":"ASIACRYPT 2012","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/671","sections":[{"content":"OT: adaptive unbounded ABE and IPE from DLIN","heading":"Overview"},{"content":"Okamoto and Takashima gave public-parameter-unbounded KP-ABE and CP-ABE for non-monotone access structures with adaptive payload-hiding security in the standard model under DLIN. They also gave unbounded generalized inner-product encryption with adaptive full attribute hiding. The proof introduced indexing and consistent randomness amplification to supply dual-system entropy whose distribution remains compatible with the adversary's key-query condition even though setup does not fix the realized attribute or policy dimensions.","heading":"Atomic claims"},{"content":"This result is an early positive answer to combining adaptive security and setup unboundedness under a static pairing assumption. For ABE the security claim is payload hiding, not policy or attribute hiding. The basic ABE scheme has a one-use/degree-one restriction; the modified KP-ABE supports an arbitrary application-chosen degree, but its ciphertext grows linearly with that degree.","heading":"Historical role and qualifier"},{"content":"The construction does not make the realized ciphertext and key succinct: their sizes still grow with attributes, policy rows, or degree. It therefore separates setup unboundedness from the simultaneous succinctness sought in ABE-OP-002.","heading":"Residual questions exposed"}],"status":"published","subtitle":"Tatsuaki Okamoto, Katsuyuki Takashima · 2012","summary":"Okamoto and Takashima gave public-parameter-unbounded KP-ABE and CP-ABE for non-monotone access structures with adaptive payload-hiding security in the standard model under DLIN. They also gave unbounded generalized inner-product encryption with adaptive full attribute hiding. The proof introduced indexing and consistent randomness amplification to supply dual-system entropy whose distribution remains compatible…","title":"Fully Secure Unbounded Inner-Product and Attribute-Based Encryption","type":"paper","venue":"ASIACRYPT 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2012-OT"},{"evidence":"published","id":"ABE-PAPER-2012-LW","keywords":["adaptive-security","dual-system","proof-methodology","cp-abe"],"metadata":{"authors":["Allison Lewko","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2012-LW","keywords":["adaptive-security","dual-system","proof-methodology","cp-abe"],"maps_to":["ABE-OP-001","ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2012/326","status":"published","title":"New Proof Methods for Attribute-Based Encryption: Achieving Full Security through Selective Techniques","venue":"CRYPTO 2012","year":2012},"primaryUrl":"https://eprint.iacr.org/2012/326","sections":[{"content":"Lewko–Waters: selective components inside a full-security proof","heading":"Overview"},{"content":"The paper developed a method that uses selectively secure components as a direct ingredient in an adaptive-security proof, yielding fully secure CP-ABE with efficiency matching then-current selectively secure systems.","heading":"Atomic claims"},{"content":"It showed that “selective technique” and “selective final theorem” are not the same thing. Modern adaptive-upgrade searches should therefore identify which state must remain programmable rather than dismissing a construction merely because one local component is selective.","heading":"Historical role"},{"content":"The method is rooted in pairing-based dual systems and does not automatically provide a lattice analogue or preserve current optimal succinctness targets.","heading":"Residual questions"}],"status":"published","subtitle":"Allison Lewko, Brent Waters · 2012","summary":"The paper developed a method that uses selectively secure components as a direct ingredient in an adaptive-security proof, yielding fully secure CP-ABE with efficiency matching then-current selectively secure systems.","title":"New Proof Methods for Attribute-Based Encryption: Achieving Full Security through Selective Techniques","type":"paper","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2012-LW"},{"evidence":"published","id":"ABE-PAPER-2013-BNS-ARITH","keywords":["kp-abe","lattice","arithmetic-circuits","delegation"],"metadata":{"authors":["Dan Boneh","Valeria Nikolaenko","Gil Segev"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2013-BNS-ARITH","keywords":["kp-abe","lattice","arithmetic-circuits","delegation"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2013/669","status":"published","title":"Attribute-Based Encryption for Arithmetic Circuits","venue":"IACR ePrint 2013","year":2013},"primaryUrl":"https://eprint.iacr.org/2013/669","sections":[{"content":"Boneh–Nikolaenko–Segev arithmetic-circuit ABE","heading":"Overview"},{"content":"The paper constructs selectively secure KP-ABE for polynomial-size arithmetic circuits from LWE. Its decryption key is one low-norm matrix whose size depends on circuit depth rather than circuit gate or wire count, and the construction supports key delegation.","heading":"Atomic claims"},{"content":"It develops key-homomorphic evaluation for arithmetic rather than only Boolean access computation and is an early lattice route to expressive ABE.","heading":"Historical role"},{"content":"Parameters grow with the supported circuit depth through the modulus and noise budget. The result is not directly comparable with pairing schemes by counting group elements or pairings.","heading":"Limitation"}],"status":"published","subtitle":"Dan Boneh, Valeria Nikolaenko, Gil Segev · 2013","summary":"The paper constructs selectively secure KP-ABE for polynomial-size arithmetic circuits from LWE. Its decryption key is one low-norm matrix whose size depends on circuit depth rather than circuit gate or wire count, and the construction supports key delegation.","title":"Attribute-Based Encryption for Arithmetic Circuits","type":"paper","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2013-BNS-ARITH"},{"evidence":"published","id":"ABE-PAPER-2013-GVW","keywords":["circuits","lwe","post-quantum","selective-security"],"metadata":{"authors":["Sergey Gorbunov","Vinod Vaikuntanathan","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2013-GVW","keywords":["circuits","lwe","post-quantum","selective-security"],"maps_to":["ABE-OP-001","ABE-OP-003"],"primary_url":"https://eprint.iacr.org/2013/337","status":"published","title":"Attribute-Based Encryption for Circuits","venue":"STOC 2013","year":2013},"primaryUrl":"https://eprint.iacr.org/2013/337","sections":[{"content":"GVW: general-circuit ABE from LWE","heading":"Overview"},{"content":"The paper constructed the first ABE for arbitrary polynomial-size circuits from LWE and also exposed a connection to branching programs and LOGSPACE.","heading":"Atomic claims"},{"content":"Homomorphic evaluation of LWE encodings transfers circuit computation into the decryption relation. This created the principal post-quantum branch of expressive ABE research.","heading":"Technical mechanism"},{"content":"The construction is selective and its parameters depend on circuit/input bounds. Adaptive security, unbounded setup, and succinct keys/ciphertexts are not obtained simultaneously.","heading":"Limitations and residual questions"}],"status":"published","subtitle":"Sergey Gorbunov, Vinod Vaikuntanathan, Hoeteck Wee · 2013","summary":"The paper constructed the first ABE for arbitrary polynomial-size circuits from LWE and also exposed a connection to branching programs and LOGSPACE.","title":"Attribute-Based Encryption for Circuits","type":"paper","venue":"STOC 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2013-GVW"},{"evidence":"published","id":"ABE-PAPER-2013-GGHSSW","keywords":["circuits","multilinear-maps","feasibility","selective-security"],"metadata":{"authors":["Sanjam Garg","Craig Gentry","Shai Halevi","Amit Sahai","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2013-GGHSSW","keywords":["circuits","multilinear-maps","feasibility","selective-security"],"maps_to":["ABE-OP-003","ABE-OP-007"],"primary_url":"https://eprint.iacr.org/2013/128","status":"published","title":"Attribute-Based Encryption for Circuits from Multilinear Maps","venue":"CRYPTO 2013","year":2013},"primaryUrl":"https://eprint.iacr.org/2013/128","sections":[{"content":"GGHSSW: general-circuit feasibility from multilinear maps","heading":"Overview"},{"content":"The paper gave KP- and CP-ABE for general circuits from candidate multilinear maps, under selective security. It marked the first jump from formula or span-program policies to arbitrary polynomial-size circuits.","heading":"Atomic claims"},{"content":"The work is a feasibility landmark. The concrete multilinear-map candidates underlying this era were subsequently cryptanalyzed, so this card is not evidence for a currently trusted assumption route.","heading":"Historical role and qualifier"},{"content":"General circuits from durable assumptions, adaptive security, and compactness remained separate challenges.","heading":"Residual questions"}],"status":"published","subtitle":"Sanjam Garg, Craig Gentry, Shai Halevi et al. · 2013","summary":"The paper gave KP- and CP-ABE for general circuits from candidate multilinear maps, under selective security. It marked the first jump from formula or span-program policies to arbitrary polynomial-size circuits.","title":"Attribute-Based Encryption for Circuits from Multilinear Maps","type":"paper","venue":"CRYPTO 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2013-GGHSSW"},{"evidence":"published","id":"ABE-PAPER-2013-HW-FAST","keywords":["kp-abe","fast-decryption","pairing","large-universe"],"metadata":{"authors":["Susan Hohenberger","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2013-HW-FAST","keywords":["kp-abe","fast-decryption","pairing","large-universe"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2013/265","status":"published","title":"Attribute-Based Encryption with Fast Decryption","venue":"IACR ePrint 2013","year":2013},"primaryUrl":"https://eprint.iacr.org/2013/265","sections":[{"content":"Hohenberger–Waters fast-decryption KP-ABE","heading":"Overview"},{"content":"The paper gives an expressive KP-ABE whose main decryption path uses two pairings, trading a factor proportional to the number of distinct policy attributes for a larger secret key. It also gives a continuum between the GPSW baseline and the fastest variant without changing public parameters or encryption.","heading":"Atomic claims"},{"content":"This is an early explicit treatment of decryption latency as a first-class ABE design axis rather than an incidental consequence of ciphertext or key size.","heading":"Historical role"},{"content":"The large-universe realization uses a random oracle and selective security under decisional q-BDHE; the fast path can also become unattractive for very large satisfying sets because it replaces pairings with many multiplications.","heading":"Limitation"}],"status":"published","subtitle":"Susan Hohenberger, Brent Waters · 2013","summary":"The paper gives an expressive KP-ABE whose main decryption path uses two pairings, trading a factor proportional to the number of distinct policy attributes for a larger secret key. It also gives a continuum between the GPSW baseline and the fastest variant without changing public parameters or encryption.","title":"Attribute-Based Encryption with Fast Decryption","type":"paper","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2013-HW-FAST"},{"evidence":"published","id":"ABE-PAPER-2013-RW","keywords":["large-universe","kp-abe","cp-abe","prime-order-pairings","selective-security","implementation"],"metadata":{"authors":["Yannis Rouselakis","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2013-RW","keywords":["large-universe","kp-abe","cp-abe","prime-order-pairings","selective-security","implementation"],"maps_to":["ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2012/583","status":"published","title":"Practical Constructions and New Proof Methods for Large Universe Attribute-Based Encryption","venue":"ACM CCS 2013","year":2013},"primaryUrl":"https://eprint.iacr.org/2012/583","sections":[{"content":"RW: practical large-universe ABE in prime-order groups","heading":"Overview"},{"content":"Rouselakis and Waters gave large-universe CP-ABE and KP-ABE in prime-order bilinear groups with constant-size public parameters. Attribute strings need not be enumerated at setup, and the constructions support monotone LSSS access structures. The paper implemented both schemes in Charm and reported benchmarks against prior ABE systems.","heading":"Atomic claims"},{"content":"The work made large-universe standard-model ABE concretely practical and revived program-and-cancel proof techniques. Both schemes are selectively secure under parameterized q-type assumptions: the CP theorem bounds the challenge matrix dimensions by q, while the KP theorem bounds the challenge attribute-set size by q. Thus “constant public parameters” does not mean a static assumption or adaptive security.","heading":"Historical role and qualifier"},{"content":"The main remaining directions were adaptive security under static assumptions and reductions in policy-dependent key, ciphertext, and decryption costs. Those axes lead to predicate encodings, compact ABE, and the concrete efficiency target in ABE-OP-008.","heading":"Residual questions exposed"}],"status":"published","subtitle":"Yannis Rouselakis, Brent Waters · 2013","summary":"Rouselakis and Waters gave large-universe CP-ABE and KP-ABE in prime-order bilinear groups with constant-size public parameters. Attribute strings need not be enumerated at setup, and the constructions support monotone LSSS access structures. The paper implemented both schemes in Charm and reported benchmarks against prior ABE systems.","title":"Practical Constructions and New Proof Methods for Large Universe Attribute-Based Encryption","type":"paper","venue":"ACM CCS 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2013-RW"},{"evidence":"published","id":"ABE-PAPER-2014-ATTRAPADUNG","keywords":["pair-encodings","dual-system-encryption","adaptive-security","unbounded-abe","constant-ciphertext"],"metadata":{"authors":["Nuttapong Attrapadung"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2014-ATTRAPADUNG","keywords":["pair-encodings","dual-system-encryption","adaptive-security","unbounded-abe","constant-ciphertext"],"maps_to":["ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2014/428","status":"published","title":"Dual System Encryption via Doubly Selective Security: Framework, Fully-secure Functional Encryption for Regular Languages, and More","venue":"EUROCRYPT 2014","year":2014},"primaryUrl":"https://eprint.iacr.org/2014/428","sections":[{"content":"Attrapadung: pair encodings as a dual-system framework","heading":"Overview"},{"content":"The paper introduces pair encoding schemes and doubly selective security as a generic route from predicate encodings to adaptively secure functional encryption. Its ABE instantiations include unbounded large-universe ABE and ABE with constant-size ciphertexts.","heading":"Atomic contributions"},{"content":"This card uses ePrint 2014/428, the full version associated with EUROCRYPT The previously recorded identifier 2014/515 names an unrelated, withdrawn social-secret-sharing paper and is not a version of this work.","heading":"Version identity"},{"content":"The original framework and highlighted instantiations use composite-order bilinear groups; individual compactness and assumption claims belong to the specific instantiations rather than to every pair encoding.","heading":"Scope"}],"status":"published","subtitle":"Nuttapong Attrapadung · 2014","summary":"Attrapadung: pair encodings as a dual-system framework","title":"Dual System Encryption via Doubly Selective Security: Framework, Fully-secure Functional Encryption for Regular Languages, and More","type":"paper","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2014-ATTRAPADUNG"},{"evidence":"published","id":"ABE-PAPER-2014-BGGPS","keywords":["lwe","arithmetic-circuits","short-keys","key-homomorphic-encryption"],"metadata":{"authors":["Dan Boneh","Craig Gentry","Sergey Gorbunov","Shai Halevi","Valeria Nikolaenko","Gil Segev","Vinod Vaikuntanathan","Dhinakaran Vinayagamurthy"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2014-BGGPS","keywords":["lwe","arithmetic-circuits","short-keys","key-homomorphic-encryption"],"maps_to":["ABE-OP-001"],"primary_url":"https://eprint.iacr.org/2014/356","status":"published","title":"Fully Key-Homomorphic Encryption, Arithmetic Circuit ABE, and Compact Garbled Circuits","venue":"EUROCRYPT 2014","year":2014},"primaryUrl":"https://eprint.iacr.org/2014/356","sections":[{"content":"BGG+14: depth-dependent rather than size-dependent lattice keys","heading":"Overview"},{"content":"The work developed key-homomorphic encryption techniques leading to lattice ABE for arithmetic circuits with secret-key size governed by circuit depth rather than circuit size.","heading":"Atomic claims"},{"content":"It established an early lattice succinctness point and supplied tools reused throughout later circuit-ABE constructions.","heading":"Historical role"},{"content":"The result is selective and uses subexponential-strength LWE parameters. It does not achieve the later goal of making public parameters, keys, and ciphertexts all almost optimal under plain polynomial-ratio LWE.","heading":"Limitations and residual questions"}],"status":"published","subtitle":"Dan Boneh, Craig Gentry, Sergey Gorbunov et al. · 2014","summary":"The work developed key-homomorphic encryption techniques leading to lattice ABE for arithmetic circuits with secret-key size governed by circuit depth rather than circuit size.","title":"Fully Key-Homomorphic Encryption, Arithmetic Circuit ABE, and Compact Garbled Circuits","type":"paper","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2014-BGGPS"},{"evidence":"published","id":"ABE-PAPER-2014-CW-SEMIADAPTIVE","keywords":["semi-adaptive-security","kp-abe","short-ciphertext","dual-system","delegation"],"metadata":{"authors":["Jie Chen","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2014-CW-SEMIADAPTIVE","keywords":["semi-adaptive-security","kp-abe","short-ciphertext","dual-system","delegation"],"maps_to":["ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2014/465","status":"published","title":"Semi-Adaptive Attribute-Based Encryption and Improved Delegation for Boolean Formula","venue":"SCN 2014","year":2014},"primaryUrl":"https://eprint.iacr.org/2014/465","sections":[{"content":"CW: semi-adaptive ABE as an intermediate security point","heading":"Overview"},{"content":"Chen and Wee formalized semi-adaptive KP-ABE security, where the adversary chooses the challenge attribute vector after seeing the public parameters but before making secret-key queries. They gave a composite-order construction with constant-size ciphertexts under three static assumptions and a prime-order construction under SXDH whose ciphertext grows with the attribute vector length. The resulting ABE schemes also yield publicly verifiable delegation for Boolean formulas with semi-adaptive soundness.","heading":"Atomic claims"},{"content":"Semi-adaptivity is strictly between selective and fully adaptive security and became a useful checkpoint for constructions whose simulator can react to the challenge but cannot handle earlier policy-key queries. Only the composite-order construction has constant-size ciphertexts; the prime-order SXDH construction has linear ciphertext size.","heading":"Historical role and qualifier"},{"content":"The paper leaves open retaining constant ciphertexts, static prime-order assumptions, and full adaptivity simultaneously. It is therefore a precise historical stepping stone toward standard-assumption ABE with FABEO-level concrete efficiency rather than a resolution of ABE-OP-008.","heading":"Residual questions exposed"}],"status":"published","subtitle":"Jie Chen, Hoeteck Wee · 2014","summary":"Chen and Wee formalized semi-adaptive KP-ABE security, where the adversary chooses the challenge attribute vector after seeing the public parameters but before making secret-key queries. They gave a composite-order construction with constant-size ciphertexts under three static assumptions and a prime-order construction under SXDH whose ciphertext grows with the attribute vector length. The resulting ABE schemes…","title":"Semi-Adaptive Attribute-Based Encryption and Improved Delegation for Boolean Formula","type":"paper","venue":"SCN 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2014-CW-SEMIADAPTIVE"},{"evidence":"published","id":"ABE-PAPER-2015-CGW","keywords":["predicate-encodings","dual-system","adaptive-security","pairings"],"metadata":{"authors":["Jie Chen","Romain Gay","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2015-CGW","keywords":["predicate-encodings","dual-system","adaptive-security","pairings"],"maps_to":["ABE-OP-002","ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2015/409","status":"published","title":"Improved Dual System ABE in Prime-Order Groups via Predicate Encodings","venue":"EUROCRYPT 2015","year":2015},"primaryUrl":"https://eprint.iacr.org/2015/409","sections":[{"content":"CGW: predicate encodings as a modular ABE interface","heading":"Overview"},{"content":"The paper gave a modular route from predicate encodings to adaptively secure ABE in prime-order groups under the k-linear family of assumptions, improving dual-system efficiency and generality.","heading":"Atomic claims"},{"content":"Predicate encodings isolate the algebra needed for correctness and security, allowing policy-specific encodings to plug into a common proof architecture.","heading":"Technical mechanism"},{"content":"This abstraction does not by itself solve lattice adaptivity, complete unboundedness, or optimal object sizes. It is nevertheless a key precedent for a verification-friendly construction language.","heading":"Residual questions"}],"status":"published","subtitle":"Jie Chen, Romain Gay, Hoeteck Wee · 2015","summary":"The paper gave a modular route from predicate encodings to adaptively secure ABE in prime-order groups under the k-linear family of assumptions, improving dual-system efficiency and generality.","title":"Improved Dual System ABE in Prime-Order Groups via Predicate Encodings","type":"paper","venue":"EUROCRYPT 2015","year":2015,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2015-CGW"},{"evidence":"published","id":"ABE-PAPER-2016-BV","keywords":["lwe","unbounded-attributes","semi-adaptive","delayed-programming"],"metadata":{"authors":["Zvika Brakerski","Vinod Vaikuntanathan"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2016-BV","keywords":["lwe","unbounded-attributes","semi-adaptive","delayed-programming"],"maps_to":["ABE-OP-001","ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2016/118","status":"published","title":"Circuit-ABE from LWE: Unbounded Attributes and Semi-Adaptive Security","venue":"CRYPTO 2016","year":2016},"primaryUrl":"https://eprint.iacr.org/2016/118","sections":[{"content":"Brakerski–Vaikuntanathan: delay lattice programming","heading":"Overview"},{"content":"The construction fixes only a circuit-depth bound at setup while allowing arbitrary polynomial attribute length and circuit input length. It improves selective security to semi-adaptive security from LWE.","heading":"Atomic claims"},{"content":"A succinctly represented unbounded sequence of LWE matrices lets the proof delay which matrices contain trapdoors until after public parameters are set.","heading":"Technical mechanism"},{"content":"The challenge is chosen after setup but before key queries; this is not full adaptive security. Circuit depth remains bounded and the result is not almost-optimal. Later plain-LWE unbounded work should be compared against this programming interface.","heading":"Exact qualifier and residual questions"}],"status":"published","subtitle":"Zvika Brakerski, Vinod Vaikuntanathan · 2016","summary":"The construction fixes only a circuit-depth bound at setup while allowing arbitrary polynomial attribute length and circuit input length. It improves selective security to semi-adaptive security from LWE.","title":"Circuit-ABE from LWE: Unbounded Attributes and Semi-Adaptive Security","type":"paper","venue":"CRYPTO 2016","year":2016,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2016-BV"},{"evidence":"published","id":"ABE-PAPER-2017-ABGW","keywords":["automation","generic-group-model","pair-encodings","abe"],"metadata":{"authors":["Miguel Ambrona","Gilles Barthe","Romain Gay","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2017-ABGW","keywords":["automation","generic-group-model","pair-encodings","abe"],"maps_to":["ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2017/983","status":"published","title":"Attribute-Based Encryption in the Generic Group Model: Automated Proofs and New Constructions","venue":"ACM CCS 2017","year":2017},"primaryUrl":"https://eprint.iacr.org/2017/983","sections":[{"content":"ABGW: machine-assisted algebraic ABE analysis","heading":"Overview"},{"content":"The work formalized a broad algebraic design space for pairing-based ABE and used symbolic analysis to verify security or discover attacks/constructions in the algebraic/generic group setting.","heading":"Atomic claims"},{"content":"It is the closest established precedent for this repository's propose–verify– feedback loop. It demonstrates that a restricted algebraic language can be research-productive when its model boundary is explicit.","heading":"Historical role"},{"content":"Generic/algebraic group verification does not establish a standard-assumption reduction, lattice correctness, adaptive programming, or security of an arbitrary construction outside the encoded class.","heading":"Limitation"}],"status":"published","subtitle":"Miguel Ambrona, Gilles Barthe, Romain Gay et al. · 2017","summary":"The work formalized a broad algebraic design space for pairing-based ABE and used symbolic analysis to verify security or discover attacks/constructions in the algebraic/generic group setting.","title":"Attribute-Based Encryption in the Generic Group Model: Automated Proofs and New Constructions","type":"paper","venue":"ACM CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2017-ABGW"},{"evidence":"published","id":"ABE-PAPER-2017-FAME","keywords":["concrete-efficiency","cp-abe","pairings","implementation"],"metadata":{"authors":["Shashank Agrawal","Melissa Chase"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2017-FAME","keywords":["concrete-efficiency","cp-abe","pairings","implementation"],"maps_to":["ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2017/807","status":"published","title":"FAME: Fast Attribute-Based Message Encryption","venue":"ACM CCS 2017","year":2017},"primaryUrl":"https://eprint.iacr.org/2017/807","sections":[{"content":"FAME: the practical efficiency baseline","heading":"Overview"},{"content":"FAME supplied a particularly compact and fast CP-ABE construction for general access structures, making it a long-lived implementation benchmark.","heading":"Atomic claims"},{"content":"FAME separates the concrete-efficiency question from asymptotic succinctness: a scheme with better big-O policy dependence may still be less attractive in group elements, pairings, or reduction quality.","heading":"Historical role"},{"content":"FAME is fully secure under a standard DLIN-type assumption in asymmetric pairing groups; it is not merely a GGM construction. FABEO improves the multi-challenge/tightness and concrete-efficiency profile in GGM+ROM. The remaining target is to combine that later profile with a standard-assumption proof.","heading":"Security profile and residual question"}],"status":"published","subtitle":"Shashank Agrawal, Melissa Chase · 2017","summary":"FAME supplied a particularly compact and fast CP-ABE construction for general access structures, making it a long-lived implementation benchmark.","title":"FAME: Fast Attribute-Based Message Encryption","type":"paper","venue":"ACM CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2017-FAME"},{"evidence":"published","id":"ABE-PAPER-2018-CGW-IPE","keywords":["predicate-encryption","attribute-hiding","adaptive-security","pairings"],"metadata":{"authors":["Jie Chen","Junqing Gong","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2018-CGW-IPE","keywords":["predicate-encryption","attribute-hiding","adaptive-security","pairings"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2018/833","status":"published","title":"Improved Inner-Product Encryption with Adaptive Security and Full Attribute-Hiding","venue":"ASIACRYPT 2018","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/833","sections":[{"content":"CGW: adaptive full attribute hiding for inner products","heading":"Overview"},{"content":"The paper gives adaptively secure, fully attribute-hiding inner-product encryption in prime-order groups under k-Lin, improving the public/key sizes of the prior Okamoto–Takashima line.","heading":"Atomic claims"},{"content":"This is predicate encryption for inner products, not policy-hiding ABE for arbitrary formulas or circuits. It establishes a strong privacy baseline and a modular upgrade method, but it must not be cited as solving all policy- privacy variants of expressive ABE.","heading":"Relevance and qualifier"}],"status":"published","subtitle":"Jie Chen, Junqing Gong, Hoeteck Wee · 2018","summary":"The paper gives adaptively secure, fully attribute-hiding inner-product encryption in prime-order groups under k-Lin, improving the public/key sizes of the prior Okamoto–Takashima line.","title":"Improved Inner-Product Encryption with Adaptive Security and Full Attribute-Hiding","type":"paper","venue":"ASIACRYPT 2018","year":2018,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2018-CGW-IPE"},{"evidence":"published","id":"ABE-PAPER-2018-CGKW","keywords":["unbounded-abe","adaptive-security","entropy-expansion","pairings"],"metadata":{"authors":["Jie Chen","Junqing Gong","Lucas Kowalczyk","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2018-CGKW","keywords":["unbounded-abe","adaptive-security","entropy-expansion","pairings"],"maps_to":["ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2018/116","status":"published","title":"Unbounded ABE via Bilinear Entropy Expansion, Revisited","venue":"EUROCRYPT 2018","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/116","sections":[{"content":"CGKW: adaptive unbounded ABE via entropy expansion","heading":"Overview"},{"content":"The work gave simpler adaptively secure unbounded ABE with constant-size public parameters under static bilinear assumptions, including the first such scheme for arithmetic branching programs.","heading":"Atomic claims"},{"content":"A bilinear entropy-expansion lemma derives polynomially many effective public randomness components from a constant-size public seed, compiling bounded adaptive ABE into unbounded ABE.","heading":"Technical mechanism"},{"content":"Ciphertexts or keys still scale with the realized input or policy. The paper settles an important pairing-based unboundedness question, while leaving the all-object-succinct, post-quantum, completely late-bound target open.","heading":"Limitation and present relevance"}],"status":"published","subtitle":"Jie Chen, Junqing Gong, Lucas Kowalczyk et al. · 2018","summary":"The work gave simpler adaptively secure unbounded ABE with constant-size public parameters under static bilinear assumptions, including the first such scheme for arithmetic branching programs.","title":"Unbounded ABE via Bilinear Entropy Expansion, Revisited","type":"paper","venue":"EUROCRYPT 2018","year":2018,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2018-CGKW"},{"evidence":"published","id":"ABE-PAPER-2019-AMY-DFA","keywords":["kp-abe","cp-abe","dfa","dlin","uniform-computation"],"metadata":{"authors":["Shweta Agrawal","Monosij Maitra","Shota Yamada"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2019-AMY-DFA","keywords":["kp-abe","cp-abe","dfa","dlin","uniform-computation"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2019/645","status":"published","title":"Attribute Based Encryption for Deterministic Finite Automata from DLIN","venue":"IACR ePrint 2019","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/645","sections":[{"content":"Agrawal–Maitra–Yamada DFA-ABE","heading":"Overview"},{"content":"The paper gives both KP-ABE and CP-ABE for deterministic finite automata from the static DLIN assumption. It supports unbounded input length, unbounded machine size, and unbounded key requests by compiling unbounded MSP ABE.","heading":"Atomic claims"},{"content":"It moves pairing-based DFA-ABE away from parametrized q-type assumptions and shows that KP and CP orientations can be obtained through one modular compiler.","heading":"Historical role"},{"content":"The generic construction pays higher asymptotic costs than the concurrent direct DFA construction: the paper reports cubic dependence on input length and quadratic dependence on the number of DFA states in the KP orientation.","heading":"Limitation"}],"status":"published","subtitle":"Shweta Agrawal, Monosij Maitra, Shota Yamada · 2019","summary":"The paper gives both KP-ABE and CP-ABE for deterministic finite automata from the static DLIN assumption. It supports unbounded input length, unbounded machine size, and unbounded key requests by compiling unbounded MSP ABE.","title":"Attribute Based Encryption for Deterministic Finite Automata from DLIN","type":"paper","venue":"IACR ePrint 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2019-AMY-DFA"},{"evidence":"published","id":"ABE-PAPER-2019-KW","keywords":["adaptive-security","compactness","nc1","pairings"],"metadata":{"authors":["Lucas Kowalczyk","Hoeteck Wee"],"citation_key":"KW19a","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2019-KW","keywords":["adaptive-security","compactness","nc1","pairings"],"maps_to":["ABE-OP-002","ABE-OP-008","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2019/224","status":"published","title":"Compact Adaptively Secure ABE for NC1 from k-Lin","venue":"EUROCRYPT 2019","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/224","sections":[{"content":"Kowalczyk–Wee: compact adaptive NC1 ABE","heading":"Overview"},{"content":"The KP scheme has ciphertext size linear in the attribute length and independent of policy size, including repeated attributes; the CP analogue has the dual efficiency profile. Security is adaptive under k-Lin with polynomial loss.","heading":"Atomic claims"},{"content":"This resolved the central many-use compactness problem posed by Lewko and Waters, so that raw 2011 question must not be listed as open today.","heading":"Historical role"},{"content":"Input-dependent size remains, and the result is pairing-based. Complete unboundedness plus all-object succinctness and clean post-quantum assumptions are stronger targets.","heading":"Residual questions"}],"status":"published","subtitle":"Lucas Kowalczyk, Hoeteck Wee · 2019","summary":"The KP scheme has ciphertext size linear in the attribute length and independent of policy size, including repeated attributes; the CP analogue has the dual efficiency profile. Security is adaptive under k-Lin with polynomial loss.","title":"Compact Adaptively Secure ABE for NC1 from k-Lin","type":"paper","venue":"EUROCRYPT 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2019-KW"},{"evidence":"published","id":"ABE-PAPER-2019-TSABARY","keywords":["lwe","adaptive-security","t-cnf","constrained-prf"],"metadata":{"authors":["Rotem Tsabary"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2019-TSABARY","keywords":["lwe","adaptive-security","t-cnf","constrained-prf"],"maps_to":["ABE-OP-001","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2019/365","status":"published","title":"Fully Secure Attribute-Based Encryption for t-CNF from LWE","venue":"CRYPTO 2019","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/365","sections":[{"content":"Tsabary: adaptive lattice ABE beyond IBE","heading":"Overview"},{"content":"The paper gave fully secure CP-ABE from LWE for t-CNF policies, for constant t, together with a single-key constrained PRF component.","heading":"Atomic claims"},{"content":"It was the first adaptive lattice ABE beyond point functions and established that lattice adaptivity is possible for a nontrivial but restricted class.","heading":"Historical role"},{"content":"The policy class is far below general NC1 or circuits. Extending the adaptive proof while retaining plain LWE and modern succinctness remains a central gap.","heading":"Residual questions"}],"status":"published","subtitle":"Rotem Tsabary · 2019","summary":"The paper gave fully secure CP-ABE from LWE for t-CNF policies, for constant t, together with a single-key constrained PRF component.","title":"Fully Secure Attribute-Based Encryption for t-CNF from LWE","type":"paper","venue":"CRYPTO 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2019-TSABARY"},{"evidence":"published","id":"ABE-PAPER-2019-KW-CCA","keywords":["cca-security","generic-compiler","hinting-prg","abe"],"metadata":{"authors":["Venkata Koppula","Brent Waters"],"citation_key":"KW19b","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2019-KW-CCA","keywords":["cca-security","generic-compiler","hinting-prg","abe"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2018/847","status":"published","title":"Realizing Chosen Ciphertext Security Generically in Attribute-Based Encryption and Predicate Encryption","venue":"CRYPTO 2019","year":2019},"primaryUrl":"https://eprint.iacr.org/2018/847","sections":[{"content":"Koppula–Waters: generic CCA security for ABE/PE","heading":"Overview"},{"content":"The paper gives a black-box transform from IND-CPA ABE or one-sided PE to CCA security using a hinting PRG, with instantiations from CDH or LWE.","heading":"Atomic claims"},{"content":"“CCA-secure ABE” is not a raw feasibility open problem. For a new frontier scheme, the right question is whether the generic transform preserves its unboundedness, succinctness, setup/API, tightness, and post-quantum profile.","heading":"Historical correction"},{"content":"The transform can be audited separately from the base ABE proof; this is a good example of slackness in which a generic theorem is manually checked and the backend verifies only the base algebra or finite dependency conditions.","heading":"Verification boundary"}],"status":"published","subtitle":"Venkata Koppula, Brent Waters · 2019","summary":"The paper gives a black-box transform from IND-CPA ABE or one-sided PE to CCA security using a hinting PRG, with instantiations from CDH or LWE.","title":"Realizing Chosen Ciphertext Security Generically in Attribute-Based Encryption and Predicate Encryption","type":"paper","venue":"CRYPTO 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2019-KW-CCA"},{"evidence":"published","id":"ABE-PAPER-2020-AY-FH","keywords":["function-hiding","attribute-hiding","circuit-abe","lwe","impossibility"],"metadata":{"authors":["Shweta Agrawal","Shota Yamada"],"citation_key":"AY20b","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2020-AY-FH","keywords":["function-hiding","attribute-hiding","circuit-abe","lwe","impossibility"],"maps_to":["ABE-OP-010"],"primary_url":"https://eprint.iacr.org/2020/1432","status":"published","title":"CP-ABE for Circuits (and more) in the Symmetric Key Setting","venue":"TCC 2020","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/1432","sections":[{"content":"Agrawal--Yamada: circuit CP-ABE and the function-hiding boundary","heading":"Overview"},{"content":"The paper gives symmetric-key CP-ABE for polynomial-size bounded-depth circuits from LWE and studies attribute and function privacy. Lockable obfuscation compiles ABE to attribute-hiding PE. The natural full function-hiding notion for circuit ABE implies indistinguishability obfuscation, even in the symmetric-key setting; a weakened notion avoids this implication and is constructible for KP and CP orientations.","heading":"Atomic claims"},{"content":"The unbounded-size circuit construction is symmetric-key and bounded-depth. Its public-key variant fixes a circuit-size bound at setup. The positive function-hiding theorems use a weakened definition and subexponential LWE; they do not give ordinary public-key, fully function-hiding circuit ABE from plain LWE.","heading":"Exact qualifiers"},{"content":"Find useful public-key privacy notions between visible-policy ABE and the iO-complete natural full function-hiding notion, while retaining adaptive security and modern succinctness/unboundedness.","heading":"Residual questions"}],"status":"published","subtitle":"Shweta Agrawal, Shota Yamada · 2020","summary":"The paper gives symmetric-key CP-ABE for polynomial-size bounded-depth circuits from LWE and studies attribute and function privacy. Lockable obfuscation compiles ABE to attribute-hiding PE. The natural full function-hiding notion for circuit ABE implies indistinguishability obfuscation, even in the symmetric-key setting; a weakened notion avoids this implication and is constructible for KP and CP orientations.","title":"CP-ABE for Circuits (and more) in the Symmetric Key Setting","type":"paper","venue":"TCC 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2020-AY-FH"},{"evidence":"published","id":"ABE-PAPER-2020-LL-EUROCRYPT","keywords":["compact-abe","adaptive-security","arithmetic-branching-programs","logspace","k-lin"],"metadata":{"authors":["Huijia Lin","Ji Luo"],"citation_key":"LL20b","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2020-LL-EUROCRYPT","keywords":["compact-abe","adaptive-security","arithmetic-branching-programs","logspace","k-lin"],"maps_to":["ABE-OP-002","ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2020/318","status":"published","title":"Compact Adaptively Secure ABE from k-Lin: Beyond NC1 and towards NL","venue":"EUROCRYPT 2020","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/318","sections":[{"content":"Lin–Luo: compact adaptive ABE beyond NC1","heading":"Overview"},{"content":"The paper gives compact, adaptively secure KP-ABE for arithmetic branching programs from k-Lin and extends the framework to uniform computation classes, including DFA, NFA, L, and NL with explicitly qualified size bounds.","heading":"Atomic contributions"},{"content":"This EUROCRYPT 2020 paper and ePrint 2020/318 are distinct from the ASIACRYPT 2020 Lin–Luo paper recorded as ABE-PAPER-2020-LL and ePrint 2020/1139.","heading":"Version identity"},{"content":"Compactness depends on the policy model: the ABP construction makes the ciphertext independent of ABP size, while the uniform-computation extensions retain input, time, and space dependencies stated by the paper.","heading":"Scope"}],"status":"published","subtitle":"Huijia Lin, Ji Luo · 2020","summary":"Lin–Luo: compact adaptive ABE beyond NC1","title":"Compact Adaptively Secure ABE from k-Lin: Beyond NC1 and towards NL","type":"paper","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2020-LL-EUROCRYPT"},{"evidence":"published","id":"ABE-PAPER-2020-AY","keywords":["broadcast-encryption","succinct-cpabe","pairings","lwe","ggm"],"metadata":{"authors":["Shweta Agrawal","Shota Yamada"],"citation_key":"AY20a","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2020-AY","keywords":["broadcast-encryption","succinct-cpabe","pairings","lwe","ggm"],"maps_to":["ABE-OP-002","ABE-OP-006","ABE-OP-009"],"primary_url":"https://eprint.iacr.org/2020/228","status":"published","title":"Optimal Broadcast Encryption from Pairings and LWE","venue":"EUROCRYPT 2020","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/228","sections":[{"content":"Agrawal–Yamada: succinct CP-ABE as a hub","heading":"Overview"},{"content":"The paper builds optimal broadcast encryption from pairings and LWE. Its key technical component is CP-ABE whose public key, secret key, and ciphertext sizes are independent of the supported circuit size, with security in the generic bilinear group model.","heading":"Atomic claims"},{"content":"The succinct CP-ABE architecture later became an input to multi-input ABE, illustrating how a parameter optimization can expose a new primitive rather than only shrink one scheme.","heading":"Cross-field significance"},{"content":"The proof relies on the generic group model and a hybrid pairing/LWE design; it does not provide a clean post-quantum or standard-model resolution.","heading":"Limitation"}],"status":"published","subtitle":"Shweta Agrawal, Shota Yamada · 2020","summary":"The paper builds optimal broadcast encryption from pairings and LWE. Its key technical component is CP-ABE whose public key, secret key, and ciphertext sizes are independent of the supported circuit size, with security in the generic bilinear group model.","title":"Optimal Broadcast Encryption from Pairings and LWE","type":"paper","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2020-AY"},{"evidence":"published","id":"ABE-PAPER-2020-LL","keywords":["succinct-abe","adaptive-security","arithmetic-branching-programs","pairings"],"metadata":{"authors":["Huijia Lin","Ji Luo"],"citation_key":"LL20a","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2020-LL","keywords":["succinct-abe","adaptive-security","arithmetic-branching-programs","pairings"],"maps_to":["ABE-OP-002","ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2020/1139","status":"published","title":"Succinct and Adaptively Secure ABE for ABP from k-Lin","venue":"ASIACRYPT 2020","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/1139","sections":[{"content":"Lin–Luo: succinct adaptive ABP ABE","heading":"Overview"},{"content":"The KP construction has constant-size ciphertexts and the CP construction has constant-size secret keys for arithmetic branching programs under k-Lin.","heading":"Atomic claims"},{"content":"The generic construction combines gradual-simulation-secure public-key inner-product FE with information-theoretic arithmetic key garbling.","heading":"Technical mechanism"},{"content":"Only one of key or ciphertext is constant in each dual scheme, and setup/input bounds remain relevant. This is a crucial ancestor of later all-object succinctness questions, not their final solution.","heading":"Exact qualifier and residual questions"}],"status":"published","subtitle":"Huijia Lin, Ji Luo · 2020","summary":"The KP construction has constant-size ciphertexts and the CP construction has constant-size secret keys for arithmetic branching programs under k-Lin.","title":"Succinct and Adaptively Secure ABE for ABP from k-Lin","type":"paper","venue":"ASIACRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2020-LL"},{"evidence":"published","id":"ABE-PAPER-2020-AT","keywords":["predicate-composition","completely-unbounded","adaptive-security","mddh"],"metadata":{"authors":["Nuttapong Attrapadung","Junichi Tomida"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2020-AT","keywords":["predicate-composition","completely-unbounded","adaptive-security","mddh"],"maps_to":["ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2020/231","status":"published","title":"Unbounded Dynamic Predicate Compositions in ABE from Standard Assumptions","venue":"ASIACRYPT 2020","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/231","sections":[{"content":"Attrapadung–Tomida: dynamic predicate composition","heading":"Overview"},{"content":"The framework preserves adaptive security under MDDH while dynamically and without setup bounds composing simpler predicates. Applications include monotone and non-monotone formula ABE and several one-sided constant-size variants.","heading":"Atomic claims"},{"content":"Key Encoding Indistinguishability provides a partially symmetric, composable one-key/one-ciphertext interface.","heading":"Technical mechanism"},{"content":"The applications achieve different parameter points; the paper does not put complete unboundedness, constant public parameters, constant key, and constant ciphertext into one construction. This distinction is central to OP-002.","heading":"Exact qualifier"}],"status":"published","subtitle":"Nuttapong Attrapadung, Junichi Tomida · 2020","summary":"The framework preserves adaptive security under MDDH while dynamically and without setup bounds composing simpler predicates. Applications include monotone and non-monotone formula ABE and several one-sided constant-size variants.","title":"Unbounded Dynamic Predicate Compositions in ABE from Standard Assumptions","type":"paper","venue":"ASIACRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2020-AT"},{"evidence":"published","id":"ABE-PAPER-2021-GLW","keywords":["adaptive-security","deletion","search-assumptions","pairings"],"metadata":{"authors":["Rishab Goyal","Jiahui Liu","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2021-GLW","keywords":["adaptive-security","deletion","search-assumptions","pairings"],"maps_to":["ABE-OP-001","ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2021/343","status":"published","title":"Adaptive Security via Deletion in Attribute-Based Encryption: Solutions from Search Assumptions in Bilinear Groups","venue":"ASIACRYPT 2021","year":2021},"primaryUrl":"https://eprint.iacr.org/2021/343","sections":[{"content":"Goyal–Liu–Waters: deletion as an adaptive compiler interface","heading":"Overview"},{"content":"The paper introduced ABE with deletable attributes and combined it with deletion-conforming constrained PRFs to obtain adaptive ABE for subset functionality from Search BDH, rather than the decisional source-group assumptions typical of dual-system ABE.","heading":"Atomic claims"},{"content":"Adaptivity is obtained by changing which information remains available after the challenge. This is a genuine alternative to direct dual-system programming and is relevant to policy-level noncommitting-state research.","heading":"Cross-route significance"},{"content":"The demonstrated policy class is restricted; deletion-conforming PRFs for general expressive policies and post-quantum instantiations are not supplied.","heading":"Limitation"}],"status":"published","subtitle":"Rishab Goyal, Jiahui Liu, Brent Waters · 2021","summary":"The paper introduced ABE with deletable attributes and combined it with deletion-conforming constrained PRFs to obtain adaptive ABE for subset functionality from Search BDH, rather than the decisional source-group assumptions typical of dual-system ABE.","title":"Adaptive Security via Deletion in Attribute-Based Encryption: Solutions from Search Assumptions in Bilinear Groups","type":"paper","venue":"ASIACRYPT 2021","year":2021,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2021-GLW"},{"evidence":"published","id":"ABE-PAPER-2021-DKW","keywords":["multi-authority","lwe","dnf","random-oracle"],"metadata":{"authors":["Pratish Datta","Ilan Komargodski","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2021-DKW","keywords":["multi-authority","lwe","dnf","random-oracle"],"maps_to":["ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2020/1386","status":"published","title":"Decentralized Multi-Authority ABE for DNFs from LWE","venue":"EUROCRYPT 2021","year":2021},"primaryUrl":"https://eprint.iacr.org/2020/1386","sections":[{"content":"DKW: decentralized MA-ABE from LWE","heading":"Overview"},{"content":"The paper constructed decentralized MA-ABE for DNF policies with an unbounded number of authorities from subexponential-ratio LWE in the random oracle model, with static security. It also gave a direct LSSS-based lattice CP-ABE for NC1.","heading":"Atomic claims"},{"content":"The construction isolates LSSS properties compatible with noisy lattice encodings and avoids the generic universal-circuit KP-to-CP transformation.","heading":"Technical mechanism"},{"content":"Adaptive corruptions, broader policy classes for MA-ABE, polynomial-ratio LWE, and removal of the random oracle remained open.","heading":"Residual questions"}],"status":"published","subtitle":"Pratish Datta, Ilan Komargodski, Brent Waters · 2021","summary":"The paper constructed decentralized MA-ABE for DNF policies with an unbounded number of authorities from subexponential-ratio LWE in the random oracle model, with static security. It also gave a direct LSSS-based lattice CP-ABE for NC1.","title":"Decentralized Multi-Authority ABE for DNFs from LWE","type":"paper","venue":"EUROCRYPT 2021","year":2021,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2021-DKW"},{"evidence":"published","id":"ABE-PAPER-2022-LLL","keywords":["circuit-abe","succinctness","lattices","pairings"],"metadata":{"authors":["Hanjun Li","Huijia Lin","Ji Luo"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2022-LLL","keywords":["circuit-abe","succinctness","lattices","pairings"],"maps_to":["ABE-OP-001","ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2022/659","status":"published","title":"ABE for Circuits with Constant-Size Secret Keys and Adaptive Security","venue":"TCC 2022","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/659","sections":[{"content":"Li–Lin–Luo: constant-key and double-succinct ABE","heading":"Overview"},{"content":"Circuit KP-ABE with secret-key size poly(lambda) (three group elements), while ciphertext grows with attribute length and maximum depth. Formula CP-ABE with constant-size keys and ciphertext independent of policy formula size, but dependent on attribute length. Selective security from LWE in the generic pairing-group model; adaptive security after replacing LWE with adaptive LWE.","heading":"Atomic claims"},{"content":"The paper's raw constant-key and double-succinct questions are partially answered by these constructions. Current variants ask for plain-LWE/direct standard-model assumptions, all-three almost-optimal objects, full adaptive security, and complete unboundedness.","heading":"Residual questions"},{"content":"Introduction, printed p. 2 (PDF p. 4): “Can we construct ABE for circuits with constant-size keys?” Same page: “Can we construct ABE for expressive policies with both succinct keys and succinct ciphertexts?” ePrint abstract and main theorem statements for the achieved variants.","heading":"Source locations"}],"status":"published","subtitle":"Hanjun Li, Huijia Lin, Ji Luo · 2022","summary":"Circuit KP-ABE with secret-key size poly(lambda) (three group elements), while ciphertext grows with attribute length and maximum depth. Formula CP-ABE with constant-size keys and ciphertext independent of policy formula size, but dependent on attribute length. Selective security from LWE in the generic pairing-group model; adaptive security after replacing LWE with adaptive LWE.","title":"ABE for Circuits with Constant-Size Secret Keys and Adaptive Security","type":"paper","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2022-LLL"},{"evidence":"published","id":"ABE-PAPER-2022-FABEO","keywords":["concrete-efficiency","adaptive-security","multi-challenge","ggm","random-oracle"],"metadata":{"authors":["Doreen Riepel","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2022-FABEO","keywords":["concrete-efficiency","adaptive-security","multi-challenge","ggm","random-oracle"],"maps_to":["ABE-OP-008"],"primary_url":"https://eprint.iacr.org/2022/1415","status":"published","title":"FABEO: Fast Attribute-Based Encryption with Optimal Security","venue":"ACM CCS 2022","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/1415","sections":[{"content":"FABEO: the concrete-efficiency benchmark","heading":"Overview"},{"content":"FABEO gives highly efficient KP/CP-ABE with adaptive multi-challenge security and tight or near-tight reductions in the generic bilinear group plus random oracle model, improving the security profile of FAME-like efficiency.","heading":"Atomic claims"},{"content":"It is the relevant concrete benchmark for pairing implementations; asymptotic succinctness alone does not subsume this design target.","heading":"Historical role"},{"content":"Achieving the same compact algebra and security under a falsifiable static assumption in the standard model remains open.","heading":"Residual question"}],"status":"published","subtitle":"Doreen Riepel, Hoeteck Wee · 2022","summary":"FABEO gives highly efficient KP/CP-ABE with adaptive multi-challenge security and tight or near-tight reductions in the generic bilinear group plus random oracle model, improving the security profile of FAME-like efficiency.","title":"FABEO: Fast Attribute-Based Encryption with Optimal Security","type":"paper","venue":"ACM CCS 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2022-FABEO"},{"evidence":"published","id":"ABE-PAPER-2022-VA-GLUE","keywords":["cp-abe","pairing","unbounded","non-monotone","online-offline"],"metadata":{"authors":["Marloes Venema","Greg Alpár"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2022-VA-GLUE","keywords":["cp-abe","pairing","unbounded","non-monotone","online-offline"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2022/613","status":"published","title":"GLUE: Generalizing Unbounded Attribute-Based Encryption for Flexible Efficiency Trade-Offs","venue":"IACR ePrint 2022","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/613","sections":[{"content":"GLUE","heading":"Overview"},{"content":"GLUE is a completely unbounded, large-universe CP-ABE family with configurable partition parameters controlling encryption and decryption cost. It supports attribute and label reuse, admits non-monotone extensions, and has online/offline key-generation and encryption variants.","heading":"Atomic claims"},{"content":"The construction exposes a shared polynomial structure behind several earlier unbounded schemes and turns that structure into an explicit efficiency design space.","heading":"Historical role"},{"content":"Its concrete cost depends on chosen partition parameters and the distribution of repeated labels, so a single scalar efficiency number would hide the central trade-off.","heading":"Limitation"}],"status":"published","subtitle":"Marloes Venema, Greg Alpár · 2022","summary":"GLUE is a completely unbounded, large-universe CP-ABE family with configurable partition parameters controlling encryption and decryption cost. It supports attribute and label reuse, admits non-monotone extensions, and has online/offline key-generation and encryption variants.","title":"GLUE: Generalizing Unbounded Attribute-Based Encryption for Flexible Efficiency Trade-Offs","type":"paper","venue":"IACR ePrint 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2022-VA-GLUE"},{"evidence":"published","id":"ABE-PAPER-2022-WWW-MAABE","keywords":["multi-authority","lattices","standard-model"],"metadata":{"authors":["Brent Waters","Hoeteck Wee","David J. Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2022-WWW-MAABE","keywords":["multi-authority","lattices","standard-model"],"maps_to":["ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2022/1194","status":"published","title":"Multi-Authority ABE from Lattices without Random Oracles","venue":"TCC 2022","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/1194","sections":[{"content":"Waters–Wee–Wu: lattice MA-ABE without random oracles","heading":"Overview"},{"content":"The paper gives plain-model lattice MA-ABE for subset policies, including conjunction/DNF-style policies, from evasive LWE. A modular related-trapdoor view also yields a plain-LWE construction in ROM with polynomial modulus-to-noise ratio.","heading":"Atomic claims"},{"content":"The no-ROM branch uses the stronger evasive-LWE assumption and the policy class is not general circuits/MSPs. The plain-LWE branch retains a random oracle.","heading":"Exact qualifiers"},{"content":"General policies, adaptive trust/corruption notions, transparent unbounded setup, and a plain-LWE standard-model theorem.","heading":"Residual questions"}],"status":"published","subtitle":"Brent Waters, Hoeteck Wee, David J. Wu · 2022","summary":"The paper gives plain-model lattice MA-ABE for subset policies, including conjunction/DNF-style policies, from evasive LWE. A modular related-trapdoor view also yields a plain-LWE construction in ROM with polynomial modulus-to-noise ratio.","title":"Multi-Authority ABE from Lattices without Random Oracles","type":"paper","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2022-WWW-MAABE"},{"evidence":"published","id":"ABE-PAPER-2022-AYY-MIABE","keywords":["multi-input-abe","predicate-encryption","witness-encryption","nc1"],"metadata":{"authors":["Shweta Agrawal","Anshu Yadav","Shota Yamada"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2022-AYY-MIABE","keywords":["multi-input-abe","predicate-encryption","witness-encryption","nc1"],"maps_to":["ABE-OP-003"],"primary_url":"https://eprint.iacr.org/2022/1024","status":"published","title":"Multi-Input Attribute Based Encryption and Predicate Encryption","venue":"CRYPTO 2022","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/1024","sections":[{"content":"AYY: multi-input ABE and predicate encryption","heading":"Overview"},{"content":"The paper formalized multi-input ABE/PE against unbounded collusions and gave the first two-input KP-ABE for NC1 from LWE plus pairings in the generic group model, with a knowledge-assumption standard-model variant. It also identified a connection between succinct single-input CP-ABE and multi-input KP-ABE.","heading":"Atomic claims"},{"content":"Multi-input ABE became a separate route toward witness encryption and advanced functionality, rather than a routine arity extension of ordinary ABE.","heading":"Historical role"},{"content":"The main rigorous NC1 point has arity two and nonstandard algebraic components; constant or polynomial arity from clean post-quantum assumptions remained open.","heading":"Residual questions"}],"status":"published","subtitle":"Shweta Agrawal, Anshu Yadav, Shota Yamada · 2022","summary":"The paper formalized multi-input ABE/PE against unbounded collusions and gave the first two-input KP-ABE for NC1 from LWE plus pairings in the generic group model, with a knowledge-assumption standard-model variant. It also identified a connection between succinct single-input CP-ABE and multi-input KP-ABE.","title":"Multi-Input Attribute Based Encryption and Predicate Encryption","type":"paper","venue":"CRYPTO 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2022-AYY-MIABE"},{"evidence":"published","id":"ABE-PAPER-2023-HLL","keywords":["unbounded-depth","circular-lwe","evasive-lwe"],"metadata":{"authors":["Yao-Ching Hsieh","Huijia Lin","Ji Luo"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-HLL","keywords":["unbounded-depth","circular-lwe","evasive-lwe"],"maps_to":["ABE-OP-003","ABE-OP-007"],"primary_url":"https://eprint.iacr.org/2023/1716","status":"published","title":"Attribute-Based Encryption for Circuits of Unbounded Depth from Lattices","venue":"FOCS 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/1716","sections":[{"content":"Hsieh–Lin–Luo: unbounded-depth ABE","heading":"Overview"},{"content":"The work removes predetermined circuit-depth bounds for several primitives. Full collusion-resistant ABE/PE for unbounded-depth circuits uses an evasive circular LWE assumption; one-key variants use circular-security mechanisms.","heading":"Atomic claims"},{"content":"The full ABE theorem is very selective in the paper's detailed formulation. The relevant evasive-circular assumption was later reported broken; this changes the assumption evidence, not the historical correctness of the conditional reduction.","heading":"Exact qualifiers"},{"content":"A safe, instance-independent, preferably post-quantum direct assumption for full unbounded-depth ABE without compact FE or iO.","heading":"Residual questions"}],"status":"published","subtitle":"Yao-Ching Hsieh, Huijia Lin, Ji Luo · 2023","summary":"The work removes predetermined circuit-depth bounds for several primitives. Full collusion-resistant ABE/PE for unbounded-depth circuits uses an evasive circular LWE assumption; one-key variants use circular-security mechanisms.","title":"Attribute-Based Encryption for Circuits of Unbounded Depth from Lattices","type":"paper","venue":"FOCS 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-HLL"},{"evidence":"published","id":"ABE-PAPER-2023-ARYY","keywords":["multi-input-abe","evasive-lwe","tensor-lwe","post-quantum-candidate"],"metadata":{"authors":["Shweta Agrawal","Melissa Rossi","Anshu Yadav","Shota Yamada"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-ARYY","keywords":["multi-input-abe","evasive-lwe","tensor-lwe","post-quantum-candidate"],"maps_to":["ABE-OP-003"],"primary_url":"https://eprint.iacr.org/2023/941","status":"published","title":"Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWE","venue":"CRYPTO 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/941","sections":[{"content":"ARYY: constant-arity multi-input ABE from lattice assumptions","heading":"Overview"},{"content":"For every constant arity, the paper gives MIABE for NC1 from evasive LWE and extends to P using evasive plus a strengthened tensor-LWE assumption. It also uses the AYY compiler to obtain multi-input predicate encryption.","heading":"Atomic claims"},{"content":"The arity-two barrier of the 2022 pairing route is not the current endpoint: constant arity is known under stronger lattice assumptions.","heading":"Historical correction"},{"content":"Polynomial or unbounded arity, adaptive security where applicable, and reductions to plain LWE remain open. The ePrint records a repaired lemma, so future use should cite the revised version.","heading":"Residual questions"}],"status":"published","subtitle":"Shweta Agrawal, Melissa Rossi, Anshu Yadav et al. · 2023","summary":"For every constant arity, the paper gives MIABE for NC1 from evasive LWE and extends to P using evasive plus a strengthened tensor-LWE assumption. It also uses the AYY compiler to obtain multi-input predicate encryption.","title":"Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWE","type":"paper","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-ARYY"},{"evidence":"published","id":"ABE-PAPER-2023-DKW","keywords":["multi-authority","adaptive-corruption","pairings","random-oracle"],"metadata":{"authors":["Pratish Datta","Ilan Komargodski","Brent Waters"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-DKW","keywords":["multi-authority","adaptive-corruption","pairings","random-oracle"],"maps_to":["ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2022/1311","status":"published","title":"Fully Adaptive Decentralized Multi-Authority ABE","venue":"EUROCRYPT 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2022/1311","sections":[{"content":"DKW: adaptive corruption in decentralized MA-ABE","heading":"Overview"},{"content":"The work gave the first decentralized MA-ABE schemes secure when authority corruptions and key queries occur adaptively. Its main construction uses prime-order pairings under k-Lin and a random oracle; a composite-order variant uses subgroup assumptions and a random oracle.","heading":"Atomic claims"},{"content":"“Adaptive corruption of authorities in MA-ABE” is no longer an open question without qualifiers. The remaining frontier concerns assumption/model quality, post-quantum security, efficiency, and combinations with registration.","heading":"Historical correction"}],"status":"published","subtitle":"Pratish Datta, Ilan Komargodski, Brent Waters · 2023","summary":"The work gave the first decentralized MA-ABE schemes secure when authority corruptions and key queries occur adaptively. Its main construction uses prime-order pairings under k-Lin and a random oracle; a composite-order variant uses subgroup assumptions and a random oracle.","title":"Fully Adaptive Decentralized Multi-Authority ABE","type":"paper","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-DKW"},{"evidence":"published","id":"ABE-PAPER-2023-FWW","keywords":["witness-encryption","registered-abe","function-binding-hash","trustless"],"metadata":{"authors":["Cody Freitag","Brent Waters","David Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-FWW","keywords":["witness-encryption","registered-abe","function-binding-hash","trustless"],"maps_to":["ABE-OP-005","ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2023/812","status":"published","title":"How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and More","venue":"CRYPTO 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/812","sections":[{"content":"FWW: plain witness encryption as a trustless-cryptography hub","heading":"Overview"},{"content":"The paper constructs registered ABE and flexible broadcast encryption from plain witness encryption together with LWE, replacing earlier iO-only feasibility routes for these trustless primitives.","heading":"Atomic claims"},{"content":"Function-binding hash functions statistically bind a digest to the output of a function of committed blocks, enabling useful programming of a witness- encryption statement without full obfuscation.","heading":"Technical mechanism"},{"content":"The general-policy registered ABE of Corollary 6.11 uses witness encryption for NP and plain LWE. It has transparent setup and supports an arbitrary number of users, but its standard-model guarantee is policy-selective security without corruptions. Appendix C adds corruptions in ROM while remaining policy-selective. The result therefore does not supply adaptive registered ABE, a simple falsifiable assumption, or a concretely efficient scheme.","heading":"Exact qualifiers"},{"content":"Plain witness encryption remains a strong assumption. Direct, efficient, post-quantum registered ABE under simpler assumptions is not supplied.","heading":"Residual questions"}],"status":"published","subtitle":"Cody Freitag, Brent Waters, David Wu · 2023","summary":"The paper constructs registered ABE and flexible broadcast encryption from plain witness encryption together with LWE, replacing earlier iO-only feasibility routes for these trustless primitives.","title":"How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and More","type":"paper","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-FWW"},{"evidence":"published","id":"ABE-PAPER-2023-JLL","keywords":["ram","phfe","succinctness","lower-bounds"],"metadata":{"authors":["Aayush Jain","Huijia Lin","Ji Luo"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-JLL","keywords":["ram","phfe","succinctness","lower-bounds"],"maps_to":["ABE-OP-001","ABE-OP-007"],"primary_url":"https://eprint.iacr.org/2022/1317","status":"published","title":"On the Optimal Succinctness and Efficiency of Functional Encryption and Attribute-Based Encryption","venue":"EUROCRYPT 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2022/1317","sections":[{"content":"Jain–Lin–Luo: optimal succinctness and RAM ABE","heading":"Overview"},{"content":"The work constructs nearly optimal PHFE for RAM from polynomially secure FE for circuits and derives ABE with constant-size keys and ciphertexts. It also proves unconditional space-time tradeoffs: key size and decryption time cannot both be sublinear in function size, and ciphertext size and decryption time cannot both be sublinear in public-input size in the stated PHFE setting.","heading":"Atomic claims"},{"content":"The positive construction uses general FE for circuits rather than a direct plain-LWE or pairing assumption. The lower bounds delimit efficiency; they do not prove direct construction impossible.","heading":"Exact qualifiers"},{"content":"Match the optimal tradeoff through a direct ABE construction from a clean, preferably post-quantum assumption.","heading":"Residual questions"}],"status":"published","subtitle":"Aayush Jain, Huijia Lin, Ji Luo · 2023","summary":"The work constructs nearly optimal PHFE for RAM from polynomially secure FE for circuits and derives ABE with constant-size keys and ciphertexts. It also proves unconditional space-time tradeoffs: key size and decryption time cannot both be sublinear in function size, and ciphertext size and decryption time cannot both be sublinear in public-input size in the stated PHFE setting.","title":"On the Optimal Succinctness and Efficiency of Functional Encryption and Attribute-Based Encryption","type":"paper","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-JLL"},{"evidence":"published","id":"ABE-PAPER-2023-ZZGQ-REGPE","keywords":["registered-abe","predicate-encodings","prime-order-pairings","mddh","qa-nizk"],"metadata":{"authors":["Ziqi Zhu","Kai Zhang","Junqing Gong","Haifeng Qian"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-ZZGQ-REGPE","keywords":["registered-abe","predicate-encodings","prime-order-pairings","mddh","qa-nizk"],"maps_to":["ABE-OP-005","ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2023/1383","status":"published","title":"Registered ABE via Predicate Encodings","venue":"ASIACRYPT 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/1383","sections":[{"content":"ZZGQ: registered ABE from predicate encodings","heading":"Overview"},{"content":"Zhu, Zhang, Gong, and Qian gave a generic black-box route from predicate encodings to slotted registered ABE in prime-order bilinear groups. The security theorem combines MDDH with a QA-NIZK having perfect completeness, perfect zero knowledge, and the paper's stronger unbounded simulation soundness. Instantiating the framework yields registered ABE for read-once span programs, zero inner product, and read-once arithmetic span programs capturing arithmetic branching programs. The paper then invokes the Hohenberger--Lu--Waters--Wu powers-of-two transformation from slotted to full registered ABE.","heading":"Atomic claims"},{"content":"This work showed that predicate encodings are a reusable interface for registered ABE rather than only ordinary authority-issued ABE. The slotted setup fixes an upper bound L on users/slots, its CRS grows quadratically in L in the displayed generic accounting, and public keys must pass explicit verification. The concrete span/ASP instances are read-once, and the zero-inner-product instance does not provide the attribute hiding of the nearby GGM construction.","heading":"Historical role and qualifier"},{"content":"The construction leaves transparent unbounded registration, smaller CRS, general adaptive corruption patterns, and clean post-quantum assumptions open. It is an important branch of the route toward ABE-OP-005, not a solution to the modern trustless frontier.","heading":"Residual questions exposed"}],"status":"published","subtitle":"Ziqi Zhu, Kai Zhang, Junqing Gong et al. · 2023","summary":"Zhu, Zhang, Gong, and Qian gave a generic black-box route from predicate encodings to slotted registered ABE in prime-order bilinear groups. The security theorem combines MDDH with a QA-NIZK having perfect completeness, perfect zero knowledge, and the paper's stronger unbounded simulation soundness. Instantiating the framework yields registered ABE for read-once span programs, zero inner product, and read-once…","title":"Registered ABE via Predicate Encodings","type":"paper","venue":"ASIACRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-ZZGQ-REGPE"},{"evidence":"published","id":"ABE-PAPER-2023-HLWW","keywords":["registered-abe","trustless","key-curator","pairings"],"metadata":{"authors":["Susan Hohenberger","George Lu","Brent Waters","David Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2023-HLWW","keywords":["registered-abe","trustless","key-curator","pairings"],"maps_to":["ABE-OP-005","ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2022/1500","status":"published","title":"Registered Attribute-Based Encryption","venue":"EUROCRYPT 2023","year":2023},"primaryUrl":"https://eprint.iacr.org/2022/1500","sections":[{"content":"HLWW: registered ABE without trusted key issuance","heading":"Overview"},{"content":"Users generate their own public/secret keys and register public keys plus attributes with a deterministic transparent curator, which aggregates them into an ABE master public key. The pairing construction supports LSSS/MSP policies for a bounded user population.","heading":"Atomic claims"},{"content":"The curator is transparent but the model and security of registration must be distinguished from decentralized MA-ABE. The original pairing CRS grows quadratically with the user bound and linearly with the universe size.","heading":"Exact qualifiers"},{"content":"Unbounded users, small or transparent setup, clean PQ assumptions, malicious curation guarantees, and multiple independent curators remained frontier axes.","heading":"Residual questions"}],"status":"published","subtitle":"Susan Hohenberger, George Lu, Brent Waters et al. · 2023","summary":"Users generate their own public/secret keys and register public keys plus attributes with a deterministic transparent curator, which aggregates them into an ABE master public key. The pairing construction supports LSSS/MSP policies for a bounded user population.","title":"Registered Attribute-Based Encryption","type":"paper","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2023-HLWW"},{"evidence":"published","id":"ABE-PAPER-2024-HLL","keywords":["lattice-abe","noisy-lsss","evasive-ipfe","circuits","automata"],"metadata":{"authors":["Yao-Ching Hsieh","Huijia Lin","Ji Luo"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-HLL","keywords":["lattice-abe","noisy-lsss","evasive-ipfe","circuits","automata"],"maps_to":["ABE-OP-001","ABE-OP-003","ABE-OP-007"],"primary_url":"https://eprint.iacr.org/2024/821","status":"published","title":"A General Framework for Lattice-Based ABE Using Evasive Inner-Product Functional Encryption","venue":"EUROCRYPT 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/821","sections":[{"content":"HLL: noisy LSSS plus evasive IPFE","heading":"Overview"},{"content":"The framework combines noisy linear secret sharing with evasive inner-product functional encryption. Applications include succinct CP-ABE for circuits and the first public-key lattice ABE for DFA/logspace Turing-machine policies.","heading":"Atomic claims"},{"content":"Noisy shares connect policy computation to lattice encodings while evasive IPFE supplies simulation for rejecting challenge instances.","heading":"Technical mechanism"},{"content":"The assumptions are stronger than plain LWE and security/instance-independence qualifiers matter. A direct safe-assumption route for unbounded-depth computation and plain-LWE adaptive succinct ABE remains open.","heading":"Residual questions"}],"status":"published","subtitle":"Yao-Ching Hsieh, Huijia Lin, Ji Luo · 2024","summary":"The framework combines noisy linear secret sharing with evasive inner-product functional encryption. Applications include succinct CP-ABE for circuits and the first public-key lattice ABE for DFA/logspace Turing-machine policies.","title":"A General Framework for Lattice-Based ABE Using Evasive Inner-Product Functional Encryption","type":"paper","venue":"EUROCRYPT 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-HLL"},{"evidence":"published","id":"ABE-PAPER-2024-WW","keywords":["adaptive-security","witness-encryption","compiler","third-route"],"metadata":{"authors":["Brent Waters","Daniel Wichs"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-WW","keywords":["adaptive-security","witness-encryption","compiler","third-route"],"maps_to":["ABE-OP-001","ABE-OP-002","ABE-OP-003","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2024/1486","status":"published","title":"Adaptively Secure Attribute-Based Encryption from Witness Encryption","venue":"TCC 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1486","sections":[{"content":"Waters–Wichs: a third route to adaptive ABE","heading":"Overview"},{"content":"The paper constructs adaptively secure ABE from witness encryption, statistically sound NIZKs, and one-way functions. Candidate witness encryption from evasive LWE yields a corresponding candidate post-quantum instantiation.","heading":"Atomic claims"},{"content":"Before this work, the known broad approaches to adaptive ABE were dual systems and iO. Witness encryption creates a distinct compiler route and a useful test for whether adaptive programming can be moved into an NP statement.","heading":"Historical role"},{"content":"Witness encryption is strong and the construction does not give adaptive general-circuit ABE from plain LWE or the optimal efficiency profile sought in the central lattice route.","heading":"Residual questions"}],"status":"published","subtitle":"Brent Waters, Daniel Wichs · 2024","summary":"The paper constructs adaptively secure ABE from witness encryption, statistically sound NIZKs, and one-way functions. Candidate witness encryption from evasive LWE yields a corresponding candidate post-quantum instantiation.","title":"Adaptively Secure Attribute-Based Encryption from Witness Encryption","type":"paper","venue":"TCC 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-WW"},{"evidence":"published","id":"ABE-PAPER-2025-AMY-TM","keywords":["turing-machines","uniform-computation","lattices"],"metadata":{"authors":["Shweta Agrawal","Simran Kumari","Shota Yamada"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-AMY-TM","keywords":["turing-machines","uniform-computation","lattices"],"maps_to":["ABE-OP-003","ABE-OP-007"],"primary_url":"https://eprint.iacr.org/2025/001","status":"published","title":"Attribute Based Encryption for Turing Machines from Lattices","venue":"CRYPTO 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2025/001","sections":[{"content":"Agrawal–Kumari–Yamada: lattice ABE for Turing machines","heading":"Overview"},{"content":"The paper constructs collusion-resistant ABE for Turing machines with unbounded input and machine descriptions, a dynamically chosen time bound, and input-specific decryption time. The NL result uses LWE, evasive LWE, and tensor LWE; the all-Turing-machine result additionally uses circular tensor LWE. It also yields unbounded-depth/size CP-ABE under the same assumptions.","heading":"Atomic claims"},{"content":"The assumption stack is substantially stronger than plain LWE. Claims of post-quantum security are therefore conditional on the precise evasive, tensor, and circular variants surviving cryptanalysis.","heading":"Exact qualifiers"},{"content":"Direct uniform-computation ABE from a safer and simpler assumption, and optimal succinctness/security under that assumption.","heading":"Residual questions"}],"status":"published","subtitle":"Shweta Agrawal, Simran Kumari, Shota Yamada · 2024","summary":"The paper constructs collusion-resistant ABE for Turing machines with unbounded input and machine descriptions, a dynamically chosen time bound, and input-specific decryption time. The NL result uses LWE, evasive LWE, and tensor LWE; the all-Turing-machine result additionally uses circular tensor LWE. It also yields unbounded-depth/size CP-ABE under the same assumptions.","title":"Attribute Based Encryption for Turing Machines from Lattices","type":"paper","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-AMY-TM"},{"evidence":"published","id":"ABE-PAPER-2024-WEE","keywords":["succinct-lwe","circuit-abe","short-keys","short-ciphertexts"],"metadata":{"authors":["Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-WEE","keywords":["succinct-lwe","circuit-abe","short-keys","short-ciphertexts"],"maps_to":["ABE-OP-001","ABE-OP-002"],"primary_url":"https://eprint.iacr.org/2024/1416","status":"published","title":"Circuit ABE with poly(depth, lambda)-sized Ciphertexts and Keys from Lattices","venue":"CRYPTO 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1416","sections":[{"content":"Wee: simultaneously short circuit-ABE keys and ciphertexts","heading":"Overview"},{"content":"From succinct LWE, the construction makes cryptographic ciphertext and secret key size polynomial in security and depth, independent of attribute length and circuit size, with a complementary public-parameter tradeoff.","heading":"Atomic claims"},{"content":"This paper closed a major two-object succinctness gap and set up the final all-three almost-optimal target reached in subsequent work.","heading":"Historical role"},{"content":"The assumption is succinct LWE rather than plain polynomial-ratio LWE; the security and setup qualifiers must be read with the theorem. It does not make the plain-LWE adaptive frontier disappear.","heading":"Residual questions"}],"status":"published","subtitle":"Hoeteck Wee · 2024","summary":"From succinct LWE, the construction makes cryptographic ciphertext and secret key size polynomial in security and depth, independent of attribute length and circuit size, with a complementary public-parameter tradeoff.","title":"Circuit ABE with poly(depth, lambda)-sized Ciphertexts and Keys from Lattices","type":"paper","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-WEE"},{"evidence":"published","id":"ABE-PAPER-2024-LYXXZPD-HRABE","keywords":["revocation","revocable-storage","tee","outsourced-decryption"],"metadata":{"authors":["Xiaoguo Li","Guomin Yang","Tao Xiang","Shengmin Xu","Bowen Zhao","Hwee Hwa Pang","Robert H. Deng"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-LYXXZPD-HRABE","keywords":["revocation","revocable-storage","tee","outsourced-decryption"],"maps_to":["ABE-OP-011"],"primary_url":"https://doi.org/10.1109/SP54263.2024.00100","status":"published","title":"Make Revocation Cheaper: Hardware-Based Revocable Attribute-Based Encryption","venue":"IEEE S&P 2024","year":2024},"primaryUrl":"https://doi.org/10.1109/SP54263.2024.00100","sections":[{"content":"Li et al.: hardware-based revocable ABE","heading":"Overview"},{"content":"The paper formalizes hardware-based revocable ABE and uses a trusted execution environment to avoid periodically delegating every stored ciphertext. It also supports outsourced decryption and analyzes leakage of secrets held inside the TEE.","heading":"Atomic claims"},{"content":"This is a hybrid hardware/cryptographic model, not a software-only resolution of revocable-storage ABE. Its efficiency gain depends on TEE availability and its leakage/security model. Theorem 3 proves the selective collusion notion sIND-ColA; Theorem 4 proves the separate selective corrupted-TEE notion sIND-CTA, where revocation keys may leak, assuming the underlying two-stage outsourced ABE is sIND-CHA secure. It does not imply transparent public updates or secure key leasing.","heading":"Exact qualifiers"},{"content":"Obtain comparable lifecycle guarantees without trusted hardware, or state and minimize the exact hardware trust needed when composing with succinct, post-quantum, or trustless ABE.","heading":"Residual questions"}],"status":"published","subtitle":"Xiaoguo Li, Guomin Yang, Tao Xiang et al. · 2024","summary":"The paper formalizes hardware-based revocable ABE and uses a trusted execution environment to avoid periodically delegating every stored ciphertext. It also supports outsourced decryption and analyzes leakage of secrets held inside the TEE.","title":"Make Revocation Cheaper: Hardware-Based Revocable Attribute-Based Encryption","type":"paper","venue":"IEEE S&P 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-LYXXZPD-HRABE"},{"evidence":"published","id":"ABE-PAPER-2024-GLWW","keywords":["registered-abe","crs-compression","progression-free-sets","pairings"],"metadata":{"authors":["Rachit Garg","George Lu","Brent Waters","David Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-GLWW","keywords":["registered-abe","crs-compression","progression-free-sets","pairings"],"maps_to":["ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2024/749","status":"published","title":"Reducing the CRS Size in Registered ABE Systems","venue":"CRYPTO 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/749","sections":[{"content":"GLWW: reducing registered-ABE setup size","heading":"Overview"},{"content":"Progression-free sets reduce the pairing registered-ABE CRS from quadratic to nearly linear in the bounded user population. A partitioning proof removes the universe-size dependence at the cost of static security; the techniques can be combined.","heading":"Atomic claims"},{"content":"The original quadratic-CRS barrier is no longer the best-known frontier. Current questions concern eliminating the user bound, stronger security, transparent/PQ setup, and retaining concrete efficiency simultaneously.","heading":"Historical correction"}],"status":"published","subtitle":"Rachit Garg, George Lu, Brent Waters et al. · 2024","summary":"Progression-free sets reduce the pairing registered-ABE CRS from quadratic to nearly linear in the bounded user population. A partitioning proof removes the universe-size dependence at the cost of static security; the techniques can be combined.","title":"Reducing the CRS Size in Registered ABE Systems","type":"paper","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-GLWW"},{"evidence":"published","id":"ABE-PAPER-2024-CW","keywords":["unbounded-abe","circuits","plain-lwe","semi-adaptive"],"metadata":{"authors":["Valerio Cini","Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-CW","keywords":["unbounded-abe","circuits","plain-lwe","semi-adaptive"],"maps_to":["ABE-OP-001","ABE-OP-002","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2024/1507","status":"published","title":"Unbounded ABE for Circuits from LWE, Revisited","venue":"ASIACRYPT 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1507","sections":[{"content":"Cini–Wee: unbounded attribute length from plain LWE","heading":"Overview"},{"content":"The scheme supports unbounded attribute length while only circuit depth is fixed at setup. It uses black-box access to cryptographic and lattice algorithms and achieves semi-adaptive security against unbounded collusions from plain LWE.","heading":"Atomic claims"},{"content":"“Unbounded” here does not include circuit depth. Ciphertext/encryption work still scales with realized input length; the result is not the all-three almost-optimal size point.","heading":"Exact qualifiers"},{"content":"Adaptive security, almost-optimal object sizes from plain LWE, and removal of the remaining setup depth bound.","heading":"Residual questions"}],"status":"published","subtitle":"Valerio Cini, Hoeteck Wee · 2024","summary":"The scheme supports unbounded attribute length while only circuit depth is fixed at setup. It uses black-box access to cryptographic and lattice algorithms and achieves semi-adaptive security against unbounded collusions from plain LWE.","title":"Unbounded ABE for Circuits from LWE, Revisited","type":"paper","venue":"ASIACRYPT 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-CW"},{"evidence":"published","id":"ABE-PAPER-2024-VB-CCA","keywords":["cca","predicate-encryption","pair-encodings","compiler"],"metadata":{"authors":["Marloes Venema","Leon Botros"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2024-VB-CCA","keywords":["cca","predicate-encryption","pair-encodings","compiler"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2023/1947","status":"published","title":"Using Predicate Extension for Predicate Encryption to Generically Obtain Chosen-Ciphertext Security and Signatures","venue":"IACR Communications in Cryptology 2024","year":2024},"primaryUrl":"https://eprint.iacr.org/2023/1947","sections":[{"content":"Venema--Botros: CCA through predicate extension","heading":"Overview"},{"content":"Predicate extension adds one attribute to both key and ciphertext predicates and makes existing CCA techniques apply generically to PE. A specialized instantiation for pair/predicate encodings gives the most efficient generic CCA conversion claimed for pairing-based CP-ABE.","heading":"Atomic claims"},{"content":"The best efficiency claim is for pairing schemes within the encoding frameworks. It does not establish constant-overhead, tight, post-quantum CCA preservation for the modern lattice/succinct/trustless frontier.","heading":"Exact qualifiers"},{"content":"Whether CCA can be added to current lattice and registered ABE endpoints while preserving cryptographic arity, adaptivity, assumption quality, and tightness.","heading":"Residual questions"}],"status":"published","subtitle":"Marloes Venema, Leon Botros · 2024","summary":"Predicate extension adds one attribute to both key and ciphertext predicates and makes existing CCA techniques apply generically to PE. A specialized instantiation for pair/predicate encodings gives the most efficient generic CCA conversion claimed for pairing-based CP-ABE.","title":"Using Predicate Extension for Predicate Encryption to Generically Obtain Chosen-Ciphertext Security and Signatures","type":"paper","venue":"IACR Communications in Cryptology 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2024-VB-CCA"},{"evidence":"published","id":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","keywords":["broadcast-encryption","adaptive-security","projective-prg","plain-model"],"metadata":{"authors":["Yao-Ching Hsieh","Brent Waters","David J. Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","keywords":["broadcast-encryption","adaptive-security","projective-prg","plain-model"],"maps_to":["ABE-OP-006","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2025/323","status":"published","title":"A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain Model","venue":"EUROCRYPT 2025","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/323","sections":[{"content":"Hsieh--Waters--Wu: adaptive broadcast encryption via projective PRGs","heading":"Overview"},{"content":"The paper gives a generic plain-model compiler from semi-static to adaptive broadcast encryption using a publicly-sampleable projective PRG. It constructs the required PRG from CDH, CBDH, LWE, and RSA-type assumptions and obtains the first plain-model adaptive broadcast schemes from search assumptions and from witness encryption.","heading":"Atomic claims"},{"content":"The projected seed is \\(\\operatorname{poly}(\\lambda,\\log \\ell)\\) for PRG output length \\(\\ell\\), but the LWE Construction 6.21 publishes one pair \\((c_i,z_i)\\) per output coordinate. Its public parameters are therefore linear in \\(\\ell\\), not independent of the output length. The resulting broadcast compiler also inherits the public-key/setup size of its inputs.","heading":"Exact parameter boundary"},{"content":"Construct a publicly-sampleable projective PRG whose public parameters, as well as its projected seed, are \\(\\operatorname{poly}(\\lambda,\\log\\ell)\\); the fully unbounded target uses universal \\(\\mathsf{Setup}(1^\\lambda)\\) and public parameters independent of \\(\\ell\\). Separately, determine whether the compiler's set-complement programming extends from broadcast recipients to correlated reusable ABE policy keys.","heading":"Residual questions"}],"status":"published","subtitle":"Yao-Ching Hsieh, Brent Waters, David J. Wu · 2025","summary":"The paper gives a generic plain-model compiler from semi-static to adaptive broadcast encryption using a publicly-sampleable projective PRG. It constructs the required PRG from CDH, CBDH, LWE, and RSA-type assumptions and obtains the first plain-model adaptive broadcast schemes from search assumptions and from witness encryption.","title":"A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain Model","type":"paper","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-HWW-ADAPTIVE-BE"},{"evidence":"published","id":"ABE-PAPER-2025-WEE","keywords":["circuit-abe","succinct-lwe","almost-optimal"],"metadata":{"authors":["Hoeteck Wee"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-WEE","keywords":["circuit-abe","succinct-lwe","almost-optimal"],"maps_to":["ABE-OP-001","ABE-OP-002","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2025/509","status":"published","title":"Almost Optimal KP and CP-ABE for Circuits from Succinct LWE","venue":"EUROCRYPT 2025","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/509","sections":[{"content":"Wee: almost-optimal bounded-depth circuit ABE","heading":"Overview"},{"content":"For depth-d circuits, KP- and CP-ABE have ciphertext, secret-key, and public- key sizes independent of input and circuit size, with O(·) hiding poly(d,lambda) factors. Security relies on succinct LWE.","heading":"Atomic claims"},{"content":"Input length and depth are setup parameters rather than completely late-bound dimensions. The main ABE theorem is selective. Succinct LWE is stronger than plain LWE.","heading":"Exact qualifiers"},{"content":"Adaptive security under the same assumption, a plain/polynomial-ratio LWE construction, and complete unboundedness with the same size profile.","heading":"Residual questions"}],"status":"published","subtitle":"Hoeteck Wee · 2025","summary":"For depth-d circuits, KP- and CP-ABE have ciphertext, secret-key, and public- key sizes independent of input and circuit size, with O(·) hiding poly(d,lambda) factors. Security relies on succinct LWE.","title":"Almost Optimal KP and CP-ABE for Circuits from Succinct LWE","type":"paper","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-WEE"},{"evidence":"published","id":"ABE-PAPER-2025-SB-LUT","keywords":["kp-abe","lattice","ring-lwe","arithmetic-circuits","lookup-tables"],"metadata":{"authors":["Sora Suegami","Enrico Bottazzi"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-SB-LUT","keywords":["kp-abe","lattice","ring-lwe","arithmetic-circuits","lookup-tables"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2025/1870","status":"preprint","title":"Lookup-Table Evaluation over Key-Homomorphic Encodings and KP-ABE for Nonlinear Operations","venue":"IACR ePrint 2025","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/1870","sections":[{"content":"Suegami–Bottazzi nonlinear-operation KP-ABE","heading":"Overview"},{"content":"The paper evaluates lookup tables directly over base-B BGG+ encodings and applies the technique to Ring-LWE KP-ABE for modulo-q arithmetic circuits. It reduces repeated decryption cost while increasing key-generation time and decryption-key size.","heading":"Atomic claims"},{"content":"It adds nonlinear operations to the lattice ABE design space without reducing all arithmetic to Boolean circuits or bootstrapping the encodings.","heading":"Historical role"},{"content":"The improvement is a tunable trade-off: larger base B speeds evaluation but increases key-generation work and key size polynomially in B.","heading":"Limitation"}],"status":"preprint","subtitle":"Sora Suegami, Enrico Bottazzi · 2025","summary":"The paper evaluates lookup tables directly over base-B BGG+ encodings and applies the technique to Ring-LWE KP-ABE for modulo-q arithmetic circuits. It reduces repeated decryption cost while increasing key-generation time and decryption-key size.","title":"Lookup-Table Evaluation over Key-Homomorphic Encodings and KP-ABE for Nonlinear Operations","type":"paper","venue":"IACR ePrint 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-SB-LUT"},{"evidence":"published","id":"ABE-PAPER-2025-LWW-MARABE","keywords":["registered-abe","multi-authority","trustless","pairings"],"metadata":{"authors":["George Lu","Brent Waters","David Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-LWW-MARABE","keywords":["registered-abe","multi-authority","trustless","pairings"],"maps_to":["ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2025/1279","status":"published","title":"Multi-Authority Registered Attribute-Based Encryption","venue":"EUROCRYPT 2025","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/1279","sections":[{"content":"LWW: combining registration and multiple authorities","heading":"Overview"},{"content":"The paper introduces multiple independent key curators, allowing policies to span attributes managed by different curators. The pairing construction supports an a-priori bounded number of users and LSSS policies; an iO-based construction supports unbounded users and arbitrary monotone policies.","heading":"Atomic claims"},{"content":"Combining the registered and multi-authority APIs is now feasible. The open problem is to achieve the strongest unbounded/general variant under clean, preferably post-quantum, assumptions without iO.","heading":"Historical correction"}],"status":"published","subtitle":"George Lu, Brent Waters, David Wu · 2025","summary":"The paper introduces multiple independent key curators, allowing policies to span attributes managed by different curators. The pairing construction supports an a-priori bounded number of users and LSSS policies; an iO-based construction supports unbounded users and arbitrary monotone policies.","title":"Multi-Authority Registered Attribute-Based Encryption","type":"paper","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-LWW-MARABE"},{"evidence":"candidate","id":"ABE-PAPER-2025-KNP-SKL","keywords":["secure-key-leasing","revocation","quantum-keys","collusion-resistance","lwe"],"metadata":{"authors":["Fuyuki Kitagawa","Ryo Nishimaki","Nikhil Pappu"],"dossier_type":"paper","evidence":"candidate","id":"ABE-PAPER-2025-KNP-SKL","keywords":["secure-key-leasing","revocation","quantum-keys","collusion-resistance","lwe"],"maps_to":["ABE-OP-011"],"primary_url":"https://eprint.iacr.org/2025/262","status":"preprint","title":"PKE and ABE with Collusion-Resistant Secure Key Leasing","venue":null,"year":2025},"primaryUrl":"https://eprint.iacr.org/2025/262","sections":[{"content":"Kitagawa--Nishimaki--Pappu: collusion-resistant ABE key leasing","heading":"Overview"},{"content":"The paper defines collusion-resistant secure key leasing with multiple quantum decryption-key and verification queries. It constructs selective ABE-CR-SKL from polynomially hard LWE; a classical-certificate variant is obtained from polynomial-arity multi-input ABE.","heading":"Atomic claims"},{"content":"The ABE security theorem is selective. Leased decryption keys are quantum. The classical-certificate branch is conditional on polynomial-arity MIABE, which is itself a major unresolved clean-assumption frontier in this dossier. The work is currently an ePrint preprint.","heading":"Exact qualifiers"},{"content":"Adaptive expressive ABE-CR-SKL, classical certificates from standard post-quantum assumptions, and simultaneous succinctness/trustless setup.","heading":"Residual questions"}],"status":"preprint","subtitle":"Fuyuki Kitagawa, Ryo Nishimaki, Nikhil Pappu · 2025","summary":"The paper defines collusion-resistant secure key leasing with multiple quantum decryption-key and verification queries. It constructs selective ABE-CR-SKL from polynomially hard LWE; a classical-certificate variant is obtained from polynomial-arity multi-input ABE.","title":"PKE and ABE with Collusion-Resistant Secure Key Leasing","type":"paper","venue":null,"year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-KNP-SKL"},{"evidence":"published","id":"ABE-PAPER-2025-WBWL-PE","keywords":["predicate-encryption","attribute-hiding","lattices","bounded-collusion"],"metadata":{"authors":["Yuejun Wang","Baocang Wang","Qiqi Lai","Huaxiong Wang"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-WBWL-PE","keywords":["predicate-encryption","attribute-hiding","lattices","bounded-collusion"],"maps_to":["ABE-OP-010"],"primary_url":"https://eprint.iacr.org/2025/361","status":"published","title":"Predicate Encryption from Lattices: Enhanced Compactness and Refined Functionality","venue":"PKC 2025","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/361","sections":[{"content":"Wang et al.: compact lattice predicate encryption","heading":"Overview"},{"content":"The paper gives more compact bounded-collusion lattice predicate encryption and a predicate inner-product FE refinement. The schemes support polynomial-size bounded-depth circuits and achieve selective fully attribute-hiding simulation security.","heading":"Atomic claims"},{"content":"Collusion is bounded and expansion is linear in the collusion bound. Security is selective, with semi-adaptive security available through an existing upgrade. Attribute hiding protects the encrypted input; it is not full policy/function hiding for reusable public-key circuit ABE.","heading":"Exact qualifiers"},{"content":"Unbounded-collusion adaptive attribute hiding with modern succinctness, and a useful non-iO-complete policy-privacy notion for public-key circuit ABE.","heading":"Residual questions"}],"status":"published","subtitle":"Yuejun Wang, Baocang Wang, Qiqi Lai et al. · 2025","summary":"The paper gives more compact bounded-collusion lattice predicate encryption and a predicate inner-product FE refinement. The schemes support polynomial-size bounded-depth circuits and achieve selective fully attribute-hiding simulation security.","title":"Predicate Encryption from Lattices: Enhanced Compactness and Refined Functionality","type":"paper","venue":"PKC 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-WBWL-PE"},{"evidence":"published","id":"ABE-PAPER-2025-CHW-RABE","keywords":["registered-abe","succinct-lwe","circuits","rom"],"metadata":{"authors":["Jeffrey Champion","Yao-Ching Hsieh","David J. Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2025-CHW-RABE","keywords":["registered-abe","succinct-lwe","circuits","rom"],"maps_to":["ABE-OP-005","ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2025/044","status":"published","title":"Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWE","venue":"CRYPTO 2025","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/044","sections":[{"content":"Champion–Hsieh–Wu: registered circuit ABE from succinct LWE","heading":"Overview"},{"content":"The paper constructs key-policy registered ABE for bounded-depth Boolean circuits from succinct LWE in ROM. Ciphertext size is poly(lambda,depth) and independent of input length and policy size. The techniques also yield adaptive distributed broadcast encryption.","heading":"Atomic claims"},{"content":"The result uses ROM and succinct LWE, and circuit depth remains a parameter. Registered ABE has a different trust/setup API from ordinary centralized ABE.","heading":"Exact qualifiers"},{"content":"Plain-LWE or standard-model registered ABE for general policies with transparent/unbounded setup and strong adaptive corruptions.","heading":"Residual questions"}],"status":"published","subtitle":"Jeffrey Champion, Yao-Ching Hsieh, David J. Wu · 2025","summary":"The paper constructs key-policy registered ABE for bounded-depth Boolean circuits from succinct LWE in ROM. Ciphertext size is poly(lambda,depth) and independent of input length and policy size. The techniques also yield adaptive distributed broadcast encryption.","title":"Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWE","type":"paper","venue":"CRYPTO 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2025-CHW-RABE"},{"evidence":"candidate","id":"ABE-PAPER-2026-AMYY","keywords":["unbounded-depth","circular-security","falsifiable-assumption"],"metadata":{"authors":["Shweta Agrawal","Anuja Modi","Anshu Yadav","Shota Yamada"],"dossier_type":"paper","evidence":"candidate","id":"ABE-PAPER-2026-AMYY","keywords":["unbounded-depth","circular-security","falsifiable-assumption"],"maps_to":["ABE-OP-003"],"primary_url":"https://eprint.iacr.org/2026/1439","status":"preprint","title":"ABE for Unbounded Depth Circuits from the Doubly Circular Assumption","venue":null,"year":2026},"primaryUrl":"https://eprint.iacr.org/2026/1439","sections":[{"content":"Agrawal–Modi–Yadav–Yamada: doubly-circular candidate","heading":"Overview"},{"content":"The paper proposes ABE for unbounded-depth and unbounded-width circuits from a new falsifiable assumption combining circular LWE with an ElGamal-style KDM component. It provides evidence in Shoup's bilinear generic group model and a restricted implication from SXDH plus circular LWE.","heading":"Atomic claims"},{"content":"The assumption contains a bilinear-group component and therefore is not a clean post-quantum lattice assumption. Instance dependence and the exact security timing must be read from the full theorem rather than inferred from the abstract.","heading":"Exact qualifiers"},{"content":"Replace the combined assumption by a safer modular or standard/PQ assumption, and strengthen the security/setup qualifiers.","heading":"Residual questions"}],"status":"preprint","subtitle":"Shweta Agrawal, Anuja Modi, Anshu Yadav et al. · 2026","summary":"The paper proposes ABE for unbounded-depth and unbounded-width circuits from a new falsifiable assumption combining circular LWE with an ElGamal-style KDM component. It provides evidence in Shoup's bilinear generic group model and a restricted implication from SXDH plus circular LWE.","title":"ABE for Unbounded Depth Circuits from the Doubly Circular Assumption","type":"paper","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-AMYY"},{"evidence":"candidate","id":"ABE-PAPER-2026-GY-FBE","keywords":["fbe","ibbe","adaptivity","equivocal-commitment"],"metadata":{"authors":["Rishab Goyal","Saikumar Yadugiri"],"citation_key":"GY26a","dossier_type":"paper","evidence":"candidate","id":"ABE-PAPER-2026-GY-FBE","keywords":["fbe","ibbe","adaptivity","equivocal-commitment"],"maps_to":["ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2026/862","status":"preprint","title":"Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE","venue":null,"year":2026},"primaryUrl":"https://eprint.iacr.org/2026/862","sections":[{"content":"Goyal–Yadugiri: adaptive optimal FBE/IBBE","heading":"Overview"},{"content":"The paper gives adaptive FBE and IBBE whose parameter sizes are independent of the number of users, from decomposed LWE in ROM. FBE has transparent setup. The main technical abstraction is an equivocal matrix commitment supporting adaptive equivocation of the committed matrix.","heading":"Atomic claims"},{"content":"Optimal succinctness and adaptive security rely on the random oracle. The paper concerns broadcast APIs rather than arbitrary policy ABE.","heading":"Exact qualifiers"},{"content":"Remove ROM while preserving optimal parameters and adaptive security, and test whether equivocal matrix commitments generalize to policy-level reusable ABE keys and adaptive corruptions.","heading":"Residual questions"}],"status":"preprint","subtitle":"Rishab Goyal, Saikumar Yadugiri · 2026","summary":"The paper gives adaptive FBE and IBBE whose parameter sizes are independent of the number of users, from decomposed LWE in ROM. FBE has transparent setup. The main technical abstraction is an equivocal matrix commitment supporting adaptive equivocation of the committed matrix.","title":"Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE","type":"paper","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-GY-FBE"},{"evidence":"published","id":"ABE-PAPER-2026-LZF-CONSTANT-CT","keywords":["cp-abe","lattice","succinct-lwe","nc1","constant-ciphertext"],"metadata":{"authors":["Jiaqi Liu","Yuanyi Zhang","Fang-Wei Fu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2026-LZF-CONSTANT-CT","keywords":["cp-abe","lattice","succinct-lwe","nc1","constant-ciphertext"],"maps_to":[],"primary_url":"https://eprint.iacr.org/2026/534","status":"preprint","title":"Ciphertext-Policy ABE for NC1 Circuits with Constant-Size Ciphertexts from Succinct LWE","venue":"IACR ePrint 2026","year":2026},"primaryUrl":"https://eprint.iacr.org/2026/534","sections":[{"content":"Liu–Zhang–Fu constant-ciphertext CP-ABE","heading":"Overview"},{"content":"The paper constructs selectively secure lattice CP-ABE for NC1 with ciphertext size independent of circuit size, input length, and depth up to hidden poly(lambda) factors. It also derives broadcast encryption with ciphertext size independent of the number of users.","heading":"Atomic claims"},{"content":"It places constant-size ciphertexts for CP-ABE circuits on the succinct-LWE branch and separates ciphertext succinctness from public-parameter size.","heading":"Historical role"},{"content":"The public parameters initially grow with circuit size, although their uniform portion can be generated from a PRG. Security relies on the stronger poly(lambda)-succinct LWE assumption rather than plain LWE.","heading":"Limitation"}],"status":"preprint","subtitle":"Jiaqi Liu, Yuanyi Zhang, Fang-Wei Fu · 2026","summary":"The paper constructs selectively secure lattice CP-ABE for NC1 with ciphertext size independent of circuit size, input length, and depth up to hidden poly(lambda) factors. It also derives broadcast encryption with ciphertext size independent of the number of users.","title":"Ciphertext-Policy ABE for NC1 Circuits with Constant-Size Ciphertexts from Succinct LWE","type":"paper","venue":"IACR ePrint 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-LZF-CONSTANT-CT"},{"evidence":"published","id":"ABE-PAPER-2026-CW-DMPE","keywords":["dmpe","dnf","lattices","decomposed-lwe"],"metadata":{"authors":["Jeffrey Champion","David J. Wu"],"citation_key":"CW26a","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2026-CW-DMPE","keywords":["dmpe","dnf","lattices","decomposed-lwe"],"maps_to":["ABE-OP-004"],"primary_url":"https://eprint.iacr.org/2026/318","status":"published","title":"Distributed Monotone-Policy Encryption for DNFs from Lattices","venue":"EUROCRYPT 2026","year":2026},"primaryUrl":"https://eprint.iacr.org/2026/318","sections":[{"content":"Champion–Wu: lattice DMPE for DNF policies","heading":"Overview"},{"content":"The paper constructs DMPE for DNF formulas with an unbounded number of users, transparent setup, and ciphertext size poly(lambda,log N) under decomposed LWE in ROM.","heading":"Atomic claims"},{"content":"The policy class is DNF. The general threshold/formula extension requires a sharing interface with small reconstruction coefficients and unauthorized-row independence; the paper identifies this as unresolved.","heading":"Exact qualifiers"},{"content":"Lattice DMPE for growing thresholds, formulas, and general MSPs, especially with optimal ciphertexts and stronger model/corruption guarantees.","heading":"Residual questions"},{"content":"Introduction, subsection “An open problem: beyond DNFs from lattices,” printed p. 11. Definition B.3 for the exact LSSS reconstruction and independence interface.","heading":"Source locations"}],"status":"published","subtitle":"Jeffrey Champion, David J. Wu · 2026","summary":"The paper constructs DMPE for DNF formulas with an unbounded number of users, transparent setup, and ciphertext size poly(lambda,log N) under decomposed LWE in ROM.","title":"Distributed Monotone-Policy Encryption for DNFs from Lattices","type":"paper","venue":"EUROCRYPT 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-CW-DMPE"},{"evidence":"published","id":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","keywords":["distributed-broadcast","adaptive-security","equivocal-encryption","lattices"],"metadata":{"authors":["Rishab Goyal","Saikumar Yadugiri"],"citation_key":"GY26b","dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","keywords":["distributed-broadcast","adaptive-security","equivocal-encryption","lattices"],"maps_to":["ABE-OP-006","ABE-OP-012"],"primary_url":"https://eprint.iacr.org/2026/792","status":"published","title":"Equivocal Broadcast Encryption: Adaptively-Secure Optimal Distributed Broadcast Encryption from Lattices","venue":"CRYPTO 2026","year":2026},"primaryUrl":"https://eprint.iacr.org/2026/792","sections":[{"content":"Goyal--Yadugiri: equivocal adaptive lattice broadcast encryption","heading":"Overview"},{"content":"The paper gives the first distributed broadcast encryption from a falsifiable lattice assumption that simultaneously has adaptive security and optimal parameters. It introduces equivocal encryption systems: indistinguishable real and fake modes in which fake keys and ciphertexts are jointly sampled with trapdoors, allowing a ciphertext to be explained later as encrypting the chosen challenge value.","heading":"Atomic claims"},{"content":"The succinct-CRS construction uses a random oracle. The standard-model branch retains adaptive security but has a long CRS. Thus it reaches the adaptive lattice broadcast endpoint but not the simultaneous standard-model, output-independent-CRS endpoint in ABE-OP-006.","heading":"Exact model boundary"},{"content":"Compress the standard-model CRS, and lift the joint fake-key/fake-ciphertext state from the one-dimensional broadcast-recipient relation to reusable ABE keys whose rejecting policies contain correlated rows, repeated labels, and a shared master target.","heading":"Residual questions"}],"status":"published","subtitle":"Rishab Goyal, Saikumar Yadugiri · 2026","summary":"The paper gives the first distributed broadcast encryption from a falsifiable lattice assumption that simultaneously has adaptive security and optimal parameters. It introduces equivocal encryption systems: indistinguishable real and fake modes in which fake keys and ciphertexts are jointly sampled with trapdoors, allowing a ciphertext to be explained later as encrypting the chosen challenge value.","title":"Equivocal Broadcast Encryption: Adaptively-Secure Optimal Distributed Broadcast Encryption from Lattices","type":"paper","venue":"CRYPTO 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-GY-EQUIVOCAL-BE"},{"evidence":"candidate","id":"ABE-PAPER-2026-CW-OPT-DMPE","keywords":["dmpe","dnf","optimal-succinctness","decomposed-lwe"],"metadata":{"authors":["Jeffrey Champion","David J. Wu"],"citation_key":"CW26b","dossier_type":"paper","evidence":"candidate","id":"ABE-PAPER-2026-CW-OPT-DMPE","keywords":["dmpe","dnf","optimal-succinctness","decomposed-lwe"],"maps_to":["ABE-OP-004","ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2026/1464","status":"preprint","title":"Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices","venue":null,"year":2026},"primaryUrl":"https://eprint.iacr.org/2026/1464","sections":[{"content":"Champion–Wu: optimal DNF DMPE and plain-model tradeoffs","heading":"Overview"},{"content":"Optimal DNF DMPE in ROM: parameters, user keys, and ciphertext are independent of policy size. Plain-model k-DNF DMPE with ciphertext about k sqrt(L) under the stated adaptive-policy notion, and a fully succinct selective branch. Adaptive lattice distributed broadcast with unbounded users and sublinear ciphertext under polynomial-ratio decomposed LWE in the plain model.","heading":"Atomic claims"},{"content":"Beyond-DNF expressivity, optimal adaptive plain-model parameters, and adaptive corruptions where not covered by the paper's game.","heading":"Residual questions"}],"status":"preprint","subtitle":"Jeffrey Champion, David J. Wu · 2026","summary":"Optimal DNF DMPE in ROM: parameters, user keys, and ciphertext are independent of policy size. Plain-model k-DNF DMPE with ciphertext about k sqrt(L) under the stated adaptive-policy notion, and a fully succinct selective branch. Adaptive lattice distributed broadcast with unbounded users and sublinear ciphertext under polynomial-ratio decomposed LWE in the plain model.","title":"Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices","type":"paper","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-CW-OPT-DMPE"},{"evidence":"published","id":"ABE-PAPER-2026-SWW-RABE","keywords":["registered-abe","pairings","msp","crs"],"metadata":{"authors":["Roy Stracovsky","Brent Waters","David J. Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2026-SWW-RABE","keywords":["registered-abe","pairings","msp","crs"],"maps_to":["ABE-OP-004","ABE-OP-005"],"primary_url":"https://eprint.iacr.org/2026/1062","status":"published","title":"Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRS","venue":"CRYPTO 2026","year":2026},"primaryUrl":"https://eprint.iacr.org/2026/1062","sections":[{"content":"Stracovsky–Waters–Wu: registered ABE with linear CRS","heading":"Overview"},{"content":"The paper gives pairing-based registered ABE with linear-size CRS for monotone span programs, including formulas and threshold policies. It obtains static security from a q-type assumption in the plain model and adaptive security in ROM. A separate large-index branch lets arbitrary-string user identities enable stateless key generation.","heading":"Atomic claims"},{"content":"The CRS still grows linearly with users. The result is pairing-based and therefore does not settle the post-quantum lattice threshold/DMPE frontier. Plain-model and adaptive security are achieved in different branches. More importantly, the large-index/stateless branch is index-set-selective, whereas the adaptive ROM branch uses a small index space and an a-priori policy-size bound. The paper does not simultaneously obtain adaptive security and arbitrary-string identities.","heading":"Exact qualifiers"},{"content":"Adaptive plain-model security, smaller/unbounded CRS, and clean PQ analogues for general policies.","heading":"Residual questions"}],"status":"published","subtitle":"Roy Stracovsky, Brent Waters, David J. Wu · 2026","summary":"The paper gives pairing-based registered ABE with linear-size CRS for monotone span programs, including formulas and threshold policies. It obtains static security from a q-type assumption in the plain model and adaptive security in ROM. A separate large-index branch lets arbitrary-string user identities enable stateless key generation.","title":"Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRS","type":"paper","venue":"CRYPTO 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-SWW-RABE"},{"evidence":"published","id":"ABE-PAPER-2026-WW-SILENT","keywords":["silent-threshold","expressive-policies","pairings","plain-model"],"metadata":{"authors":["Brent Waters","David Wu"],"dossier_type":"paper","evidence":"published","id":"ABE-PAPER-2026-WW-SILENT","keywords":["silent-threshold","expressive-policies","pairings","plain-model"],"maps_to":["ABE-OP-004","ABE-OP-005","ABE-OP-006"],"primary_url":"https://eprint.iacr.org/2025/1547","status":"published","title":"Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain Model","venue":"EUROCRYPT 2026","year":2026},"primaryUrl":"https://eprint.iacr.org/2025/1547","sections":[{"content":"Waters–Wu: expressive silent threshold cryptography from pairings","heading":"Overview"},{"content":"The paper gives pairing-based silent threshold signatures and encryption for expressive access policies in the plain model, with very short outputs (three group elements for signatures and four for ciphertexts in the highlighted schemes).","heading":"Atomic claims"},{"content":"This is not ordinary centralized ABE, but it is a current benchmark for trustless policy enforcement and shows that expressive threshold policies need not inherently require random oracles in pairing-based silent setup.","heading":"Relevance to ABE and DMPE"},{"content":"Comparable post-quantum constructions and transparent setup with similarly short objects remain explicitly identified directions. It does not resolve the lattice exact-threshold reconstruction/noise barriers.","heading":"Residual questions"}],"status":"published","subtitle":"Brent Waters, David Wu · 2026","summary":"The paper gives pairing-based silent threshold signatures and encryption for expressive access policies in the plain model, with very short outputs (three group elements for signatures and four for ciphertexts in the highlighted schemes).","title":"Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain Model","type":"paper","venue":"EUROCRYPT 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-PAPER-2026-WW-SILENT"},{"evidence":"independently-audited","id":"ABE-TRACK-001","keywords":["kpabe","formulas","unbounded","decomposed-lwe"],"metadata":{"artifacts":["experiments/constant_ct_unbounded_kpabe","docs/latex/completely_unbounded_dnf_kpabe.tex"],"dossier_type":"research_track","evidence":"independently-audited","id":"ABE-TRACK-001","keywords":["kpabe","formulas","unbounded","decomposed-lwe"],"next_milestone":"Resolve independent-audit obligations M1--M2; audit QROM separately; then pursue a second sharing family or adaptive noncommitting state.","status":"active","targets":["ABE-OP-001","ABE-OP-002"],"title":"Completely-unbounded signed-formula KP-ABE"},"primaryUrl":null,"sections":[{"content":"Completely-unbounded signed-formula KP-ABE","heading":"Overview"},{"content":"An ordinary centralized reusable KP-ABE for signed Boolean formulas/NC^1 from decomposed LWE in the selective classical ROM, with no setup bound on universe, realized input, formula size/depth, repeated labels, or label length. The cryptographic MPK and ciphertext core are poly(lambda); clear attributes are metadata. The formula key has two lattice pairs per leaf occurrence, with a one-pair-per-minterm DNF specialization.","heading":"Current claim"},{"content":"Paired full-row affine false-pivot completion and a consistent-independent sharing compiler move challenge-false simulation from encryption time to reusable authority key generation.","heading":"New mechanism"},{"content":"This is a substantive partial result for ABE-OP-002. It does not solve adaptive security, standard-model security, polynomial-ratio/plain LWE, or arbitrary span programs.","heading":"Field position"},{"content":"Main notebook: experiments/constant_ct_unbounded_kpabe/ Paper source: completely_unbounded_dnf_kpabe.tex Proof audit: PROOF_REPAIR_AUDIT_2026-08-03.md Independent hostile audit: INDEPENDENT_AUDIT_2026-08-03.md The independent verdict is a conditional pass for the selective classical-ROM headline: no fatal algebra, correctness, repeated-label, formula-sharing, or joint multi-key hybrid gap was found. Two submission obligations remain logged: expand the final leftover transition into its two-stage source argument and add an exact source-lemma/parameter table. The QROM appendix was not independently cleared and is not included in this evidence promotion.","heading":"Evidence and artifacts"},{"content":"Resolve the two classical audit obligations and commission a separate QROM review. After that, pursue either: a second non-DKW sharing family demonstrating compiler generality; or the finite PSEC/OEAP adaptive interface passing the two-rejecting-key test.","heading":"Next milestone"}],"status":"active","subtitle":"","summary":"An ordinary centralized reusable KP-ABE for signed Boolean formulas/NC^1 from decomposed LWE in the selective classical ROM, with no setup bound on universe, realized input, formula size/depth, repeated labels, or label length. The cryptographic MPK and ciphertext core are poly(lambda); clear attributes are metadata. The formula key has two lattice pairs per leaf occurrence, with a one-pair-per-minterm DNF…","title":"Completely-unbounded signed-formula KP-ABE","type":"research_track","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-TRACK-001"},{"evidence":"manual-proof-complete","id":"ABE-TRACK-002","keywords":["threshold","lsss","dmpe","lower-bound"],"metadata":{"artifacts":["experiments/exact_threshold_lsss"],"dossier_type":"research_track","evidence":"manual-proof-complete","id":"ABE-TRACK-002","keywords":["threshold","lsss","dmpe","lower-bound"],"next_milestone":"Audit the new standard-privacy set-pair lower bound and close the log-log versus log multi-row gap, or construct an O(log n)-row large-prime uniform scheme.","status":"active","targets":["ABE-OP-004"],"title":"Exact-threshold LSSS and lattice DMPE"},"primaryUrl":null,"sections":[{"content":"Exact-threshold LSSS and lattice DMPE","heading":"Overview"},{"content":"The track establishes a prime-power collision tradeoff for injective one-row exact-threshold LSSS. In the no-wrap regime, reconstruction height is exponential in n-t; rank two has an exponential upper bound of matching order up to constants in the exponent. A new multi-row theorem uses a Bollobas set-pair reduction and only ordinary span-program privacy: if the reconstruction alphabet has size D and every party has at most h rows, then n-t+2 <= binom(2 D^h,D^h). Thus a fixed alphabet forces Omega(log log(n-t+2)) rows per party, and Omega(n log log n) total rows at middle thresholds, over every field. It also records a local-smudging barrier for a scoped compiler class.","heading":"Current claims"},{"content":"This directly attacks the sharing bottleneck identified by Champion–Wu for lattice DMPE beyond DNF. The one-row theorem is a negative/framework result. The set-pair theorem extends the mathematical scope to arbitrary row multiplicity under standard privacy, but it is a lower bound only for a fixed reconstruction alphabet, not for unrestricted secret sharing.","heading":"Field position"},{"content":"multi-row sharing plus one-hint-per-user compression; closing the standard-privacy Omega(log log n) versus digit-expansion O(log n) gap; an O(log n)-row exact-threshold construction over large odd prime fields with unauthorized-row full rank; a translation-equivocal policy commitment producing short witness-dependent recoding openings. Both remain incomplete.","heading":"Positive routes"},{"content":"experiments/exact_threshold_lsss/ contains theorem drafts, finite enumerations, matching constructions, and conditional compiler notes.","heading":"Evidence and artifacts"},{"content":"External proof and novelty audit of the set-pair theorem. Then either exploit the additive structure of bounded-combination sets for an Omega(log n) lower bound, or build a minimal growing-threshold O(log n)-row instance with the exact unauthorized independence property before adding lattice commitments.","heading":"Next milestone"}],"status":"active","subtitle":"","summary":"The track establishes a prime-power collision tradeoff for injective one-row exact-threshold LSSS. In the no-wrap regime, reconstruction height is exponential in n-t; rank two has an exponential upper bound of matching order up to constants in the exponent. A new multi-row theorem uses a Bollobas set-pair reduction and only ordinary span-program privacy: if the reconstruction alphabet has size D and every party has…","title":"Exact-threshold LSSS and lattice DMPE","type":"research_track","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-TRACK-002"},{"evidence":"machine-verified-scoped","id":"ABE-TRACK-003","keywords":["pairings","compilers","projectability","fabeo"],"metadata":{"artifacts":["experiments/abe_unbounded_succinct"],"dossier_type":"research_track","evidence":"machine-verified-scoped","id":"ABE-TRACK-003","keywords":["pairings","compilers","projectability","fabeo"],"next_milestone":"Exhibit a publicly projectable unbounded source-group functional-key interface or a static-assumption proof for one verified cancellation.","status":"paused","targets":["ABE-OP-002","ABE-OP-008"],"title":"Pairing compiler and concrete-efficiency exploration"},"primaryUrl":null,"sections":[{"content":"Pairing compiler and concrete-efficiency exploration","heading":"Overview"},{"content":"This track contains a separate FABEO Pareto candidate, GGM/PES checks, projectability audits, and barriers to composing existing unbounded IPFE with an LL20b-style outer ABE compiler.","heading":"Current position"},{"content":"It probes the pairing/static-assumption branch of completely-unbounded succinct ABE and FABEO-level concrete efficiency. No complete construction currently closes either endpoint.","heading":"Field position"},{"content":"experiments/abe_unbounded_succinct/ contains the projectability checker, late-bound compiler work, target-group lift audits, and concrete candidate notes. Backend passes cover only the encoded generic-group components.","heading":"Evidence and artifacts"}],"status":"paused","subtitle":"","summary":"It probes the pairing/static-assumption branch of completely-unbounded succinct ABE and FABEO-level concrete efficiency. No complete construction currently closes either endpoint.","title":"Pairing compiler and concrete-efficiency exploration","type":"research_track","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-TRACK-003"},{"evidence":"published","id":"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","keywords":["atomic-result","foundations","fuzzy-ibe","collusion-resistance"],"metadata":{"claim_slug":"introduced-fuzzy-ibe-and-the-abe-view","contribution_kind":"definition","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before SW05, identity-based encryption normally treated an identity as one exact lookup value. Sahai and Waters changed that interface: a key associated with one descriptive set could decrypt a ciphertext associated with another when their overlap crossed a threshold. The construction was framed as fuzzy IBE, motivated in part by noisy biometric identities, but the paper also articulated the attribute-based encryption interpretation. That interpretation was the durable contribution for the later ABE literature: attributes could become the public description of an authorization condition rather than merely an imperfect identity. GPSW06 subsequently separated the attribute set from an explicit access policy and turned this opening into the KP-ABE syntax.","prior_boundary":"Identity-based encryption tied decryption to an exact identity and did not directly express error-tolerant matching over several descriptive attributes.","significance_at_publication":"Created the conceptual bridge from identity-bound encryption to collusion-resistant encryption governed by collections of attributes.","technical_delta":"Replaced exact identity equality with threshold overlap and identified attribute-based access control as a use of the resulting interface."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","keywords":["foundations","fuzzy-ibe","collusion-resistance"],"limitations":["not expressive Boolean-policy ABE","efficiency is linear in the number of identity attributes"],"paper_id":"ABE-PAPER-2005-SW","qualifiers":["threshold-overlap predicate","selective-identity security","decisional BDH"],"source_locator":{"dossier_section":"ABE-PAPER-2005-SW § Atomic claims","primary_source":"Theorem 2 and Sections 6.2–6.3, PDF p. 11","primary_source_url":"https://eprint.iacr.org/2004/086","status":"theorem_checked"},"statement":"A secret key for one attribute set decrypts ciphertexts whose attribute set overlaps it in at least a specified threshold, giving fuzzy IBE and the conceptual precursor of ABE.","statement_status":"source_normalized_statement","status":"published","title":"Threshold-overlap decryption opened the ABE view","work_id":"ABE-PAPER-2005-SW"},"primaryUrl":"https://eprint.iacr.org/2004/086","sections":[{"content":"Fuzzy IBE → ABE","heading":"Overview"},{"content":"introduced-fuzzy-ibe-and-the-abe-view is the atomic contribution identifier normalized from ABE-PAPER-2005-SW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fuzzy Identity-Based Encryption","summary":"A secret key for one attribute set decrypts ciphertexts whose attribute set overlaps it in at least a specified threshold, giving fuzzy IBE and the conceptual precursor of ABE.","title":"Threshold-overlap decryption opened the ABE view","type":"result","venue":"EUROCRYPT 2005","year":2005,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW"},{"evidence":"published","id":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","keywords":["atomic-result","foundations","kp-abe","lsss","delegation"],"metadata":{"claim_slug":"introduced-kp-abe-for-access-structures","contribution_kind":"definition","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"SW05 showed that decryption could depend on several attributes, but its threshold-overlap relation was still a narrow policy language. GPSW06 made the policy placement explicit: ciphertexts carry attribute sets, while secret keys carry access structures. Its linear-secret-sharing view also explained how to distribute reconstruction shares so that one authorized policy can recover the message while attributes pooled across different users do not. This was more than a new construction; it supplied the KP-ABE interface and an algebraic template reused throughout the field. BSW07 later reversed where the policy lives, and subsequent pairing systems generalized the GPSW pattern to richer policies, larger universes, delegation, and stronger security notions.","prior_boundary":"Fuzzy IBE supported threshold overlap but did not provide a general syntax for placing expressive authorization policies in decryption keys.","significance_at_publication":"Established the policy/attribute duality and the secret-sharing language that became a basic design vocabulary for pairing-based ABE.","technical_delta":"Introduced the KP-ABE orientation and used linear secret sharing to represent monotone access structures and bind randomized key shares."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","keywords":["foundations","kp-abe","lsss","delegation"],"limitations":["the first main construction is small-universe","adaptive security is not obtained"],"paper_id":"ABE-PAPER-2006-GPSW","qualifiers":["KP-ABE orientation","monotone access structures","Attribute-Based Selective-Set security"],"source_locator":{"dossier_section":"ABE-PAPER-2006-GPSW § Atomic claims","primary_source":"Theorem 1, PDF p. 10; Sections 4 and 6","primary_source_url":"https://eprint.iacr.org/2006/309","status":"theorem_checked"},"statement":"GPSW formalized KP-ABE by placing an attribute set on each ciphertext and an access structure in each secret key, with collusion resistance expressed through secret sharing.","statement_status":"source_normalized_statement","status":"published","title":"Key-policy ABE for expressive access structures","work_id":"ABE-PAPER-2006-GPSW"},"primaryUrl":"https://eprint.iacr.org/2006/309","sections":[{"content":"Key-policy ABE","heading":"Overview"},{"content":"introduced-kp-abe-for-access-structures is the atomic contribution identifier normalized from ABE-PAPER-2006-GPSW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data","summary":"GPSW formalized KP-ABE by placing an attribute set on each ciphertext and an access structure in each secret key, with collusion resistance expressed through secret sharing.","title":"Key-policy ABE for expressive access structures","type":"result","venue":"ACM CCS 2006","year":2006,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES"},{"evidence":"published","id":"ABE-RESULT-2007-BSW-ADAPTIVE-GENERIC-GROUP-SECURITY","keywords":["atomic-result","foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"metadata":{"claim_slug":"adaptive-generic-group-security","contribution_kind":"security_analysis","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The first CP-ABE construction needed to show that users could not combine attributes from separately randomized keys and that adaptive key requests would not reveal the challenge message. BSW07 supplied that analysis in the generic bilinear group model, with hashing to attributes treated as a random oracle, and bounded a generic adversary's advantage. This is therefore a security-analysis contribution distinct from the CP-ABE syntax and construction itself. It established meaningful evidence for the proposed algebraic design, but not a reduction to a falsifiable static assumption. The gap shaped the next phase of the literature: Waters11 and dual-system work sought expressive CP-ABE with standard-model proofs and explicit assumptions.","prior_boundary":"The new CP-ABE interface needed a collusion-resistance argument when the adversary could adapt its challenge policy and key requests.","significance_at_publication":"Showed that the CP-ABE architecture could support an adaptive security game, while leaving standard-model reductions as a central next problem.","technical_delta":"Proved a generic-group advantage bound for the construction while isolating the random-oracle and idealized-group assumptions."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2007-BSW-ADAPTIVE-GENERIC-GROUP-SECURITY","keywords":["foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"limitations":["generic bilinear group model","random oracle","no static-assumption reduction"],"paper_id":"ABE-PAPER-2007-BSW","qualifiers":["adaptive challenge-policy and key-query CPA game","generic advantage O(q^2/p)"],"source_locator":{"dossier_section":"ABE-PAPER-2007-BSW § Atomic claims","primary_source":"Security game in Section 3.1, PDF pp. 3–4; Theorem 1, PDF p. 12","primary_source_url":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","status":"theorem_checked"},"statement":"BSW analyzed its CP-ABE construction in an adaptive challenge-policy and key-query CPA game in the generic bilinear group model, with the attribute hash modeled as a random oracle.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive CP-ABE analysis in the generic group model","work_id":"ABE-PAPER-2007-BSW"},"primaryUrl":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","sections":[{"content":"Generic-group analysis","heading":"Overview"},{"content":"adaptive-generic-group-security is the atomic contribution identifier normalized from ABE-PAPER-2007-BSW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Ciphertext-Policy Attribute-Based Encryption","summary":"BSW analyzed its CP-ABE construction in an adaptive challenge-policy and key-query CPA game in the generic bilinear group model, with the attribute hash modeled as a random oracle.","title":"Adaptive CP-ABE analysis in the generic group model","type":"result","venue":"IEEE Symposium on Security and Privacy 2007","year":2007,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2007-BSW-ADAPTIVE-GENERIC-GROUP-SECURITY"},{"evidence":"published","id":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","keywords":["atomic-result","foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"metadata":{"claim_slug":"introduced-cp-abe-construction","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"GPSW06 made expressive ABE possible, but its key-policy orientation left the authority choosing the decryption rule when issuing a key. BSW07 moved the policy to the ciphertext: an encryptor selected a monotone threshold access tree, while each user held a key for an attribute set. That reversal matched a common access-control workflow in which the data owner, rather than the key issuer, determines the policy for each object. The paper's construction was not a standard-assumption adaptive result—it used the generic bilinear group model and a random oracle—but it established the CP-ABE interface. Later standard-model, large-universe, efficient, and post-quantum lines all treat this policy placement as a primary ABE orientation.","prior_boundary":"KP-ABE placed the access rule in the key, which was awkward when a data owner wanted the ciphertext itself to state who could decrypt.","significance_at_publication":"Made encrypted access control align with the data owner's policy choice and established CP-ABE as a distinct, widely studied interface.","technical_delta":"Reversed the GPSW orientation by attaching the access tree to the ciphertext and the descriptive attributes to each user's key."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","keywords":["foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"limitations":["generic bilinear group proof","random oracle for hashing attributes"],"paper_id":"ABE-PAPER-2007-BSW","qualifiers":["monotone threshold access trees","adaptive challenge-policy and key-query CPA game"],"source_locator":{"dossier_section":"ABE-PAPER-2007-BSW § Atomic claims","primary_source":"CP-ABE syntax in Section 3.1, PDF pp. 3–4; construction in Section 4, PDF pp. 4–7","primary_source_url":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","status":"section_checked"},"statement":"BSW constructed CP-ABE in which a ciphertext carries a monotone threshold access tree and a user's secret key carries an attribute set.","statement_status":"source_normalized_statement","status":"published","title":"The first ciphertext-policy ABE construction","work_id":"ABE-PAPER-2007-BSW"},"primaryUrl":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","sections":[{"content":"Ciphertext-policy ABE","heading":"Overview"},{"content":"introduced-cp-abe-construction is the atomic contribution identifier normalized from ABE-PAPER-2007-BSW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Ciphertext-Policy Attribute-Based Encryption","summary":"BSW constructed CP-ABE in which a ciphertext carries a monotone threshold access tree and a user's secret key carries an attribute set.","title":"The first ciphertext-policy ABE construction","type":"result","venue":"IEEE Symposium on Security and Privacy 2007","year":2007,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION"},{"evidence":"published","id":"ABE-RESULT-2007-BSW-IMPLEMENTED-ABE","keywords":["atomic-result","foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"metadata":{"claim_slug":"implemented-abe","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The CP-ABE syntax would have been much less useful without evidence that its policy operations could run on real pairing groups. BSW07 therefore accompanied the construction with an implementation and performance evaluation. This contribution should not be merged with the theoretical construction: it established realizability and exposed how costs scale with policy and attribute components, but it did not strengthen the generic-group and random-oracle security theorem. As a historical baseline, it lets later systems state concretely whether they reduce pairings, object sizes, or policy-dependent work; that comparison does not by itself establish a technical inheritance edge. Numerical comparisons require normalization for curves, hardware, security levels, and software generations.","prior_boundary":"Early ABE work was largely a feasibility theory, and an implementation had not yet established the concrete cost of policy-bearing keys, ciphertexts, and pairing-based decryption.","significance_at_publication":"Opened the practical CP-ABE line and supplied an empirical baseline, without changing the construction's idealized security assumptions.","technical_delta":"Turned the proposed CP-ABE algorithms into working software and measured their dependence on policy and attribute size."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2007-BSW-IMPLEMENTED-ABE","keywords":["foundations","cp-abe","access-trees","generic-group-model","random-oracle","implementation"],"limitations":["historical hardware and pairing library context","does not strengthen the security proof"],"paper_id":"ABE-PAPER-2007-BSW","qualifiers":["implementation of the paper's CP-ABE construction","reported performance evaluation"],"source_locator":{"dossier_section":"ABE-PAPER-2007-BSW § Atomic claims","primary_source":"Section 5, PDF pp. 7–10; performance measurements in Section 5.3 and Figure 3","primary_source_url":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","status":"section_checked"},"statement":"BSW implemented its CP-ABE construction and reported measurements, demonstrating that ciphertext-policy access control could be realized with then-available pairing libraries.","statement_status":"source_normalized_statement","status":"published","title":"The first implemented CP-ABE system","work_id":"ABE-PAPER-2007-BSW"},"primaryUrl":"https://www.cs.utexas.edu/~bwaters/publications/papers/cp-abe.pdf","sections":[{"content":"First CP-ABE implementation","heading":"Overview"},{"content":"implemented-abe is the atomic contribution identifier normalized from ABE-PAPER-2007-BSW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Ciphertext-Policy Attribute-Based Encryption","summary":"BSW implemented its CP-ABE construction and reported measurements, demonstrating that ciphertext-policy access control could be realized with then-available pairing libraries.","title":"The first implemented CP-ABE system","type":"result","venue":"IEEE Symposium on Security and Privacy 2007","year":2007,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2007-BSW-IMPLEMENTED-ABE"},{"evidence":"published","id":"ABE-RESULT-2010-LOSSTW-FIRST-FULLY-SECURE-ABE-FOR-ARBITRARY-MONOTONE-FORMULAS","keywords":["atomic-result","adaptive-security","dual-system","pairings","formulas"],"metadata":{"claim_slug":"first-fully-secure-abe-for-arbitrary-monotone-formulas","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before LOSSTW10, expressive ABE could represent useful policies, but standard proofs generally required the adversary to commit to the challenge attributes or policy before setup. LOSSTW used dual-system encryption to create carefully distributed semi-functional keys and ciphertexts, allowing a hybrid proof to accommodate adaptive choices. The resulting KP/CP-ABE covered arbitrary monotone formulas in composite-order bilinear groups under the paper's static assumptions. The historical contribution is both the feasibility boundary and the proof paradigm: later ABE work repeatedly adapted dual-system reasoning to prime-order groups, unbounded universes, compact objects, and modular predicate encodings. It did not itself provide prime-order, concretely fast, or post-quantum adaptive ABE.","prior_boundary":"Expressive ABE constructions were predominantly selectively secure or justified in idealized models, leaving adaptive challenge choices outside standard proofs.","significance_at_publication":"Changed adaptive expressive ABE from an open feasibility question into a proof-method program that later constructions refined and modularized.","technical_delta":"Introduced dual-system semi-functional modes that enabled adaptive security for formula ABE and related inner-product encryption."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2010-LOSSTW-FIRST-FULLY-SECURE-ABE-FOR-ARBITRARY-MONOTONE-FORMULAS","keywords":["adaptive-security","dual-system","pairings","formulas"],"limitations":["pairing-based","formula-level rather than general-circuit ABE","not post-quantum"],"paper_id":"ABE-PAPER-2010-LOSSTW","qualifiers":["fully adaptive security","arbitrary monotone formulas","composite-order bilinear groups"],"source_locator":{"dossier_section":"ABE-PAPER-2010-LOSSTW § Atomic claims","primary_source":"Theorems 11 and 18, PDF pp. 17 and 24","primary_source_url":"https://eprint.iacr.org/2010/110","status":"theorem_checked"},"statement":"LOSSTW constructed the first fully secure KP/CP-ABE for arbitrary monotone formulas using dual-system techniques in composite-order bilinear groups under static assumptions.","statement_status":"source_normalized_statement","status":"published","title":"Fully secure ABE for arbitrary monotone formulas","work_id":"ABE-PAPER-2010-LOSSTW"},"primaryUrl":"https://eprint.iacr.org/2010/110","sections":[{"content":"First Fully Secure ABE For Arbitrary Monotone Formulas","heading":"Overview"},{"content":"first-fully-secure-abe-for-arbitrary-monotone-formulas is the atomic contribution identifier normalized from ABE-PAPER-2010-LOSSTW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fully Secure Functional Encryption: Attribute-Based Encryption and (Hierarchical) Inner Product Encryption","summary":"LOSSTW constructed the first fully secure KP/CP-ABE for arbitrary monotone formulas using dual-system techniques in composite-order bilinear groups under static assumptions.","title":"Fully secure ABE for arbitrary monotone formulas","type":"result","venue":"EUROCRYPT 2010","year":2010,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2010-LOSSTW-FIRST-FULLY-SECURE-ABE-FOR-ARBITRARY-MONOTONE-FORMULAS"},{"evidence":"published","id":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","keywords":["atomic-result","multi-authority","decentralized","pairings","random-oracle"],"metadata":{"claim_slug":"decentralized-multi-authority-abe-without-central-authority","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Single-authority ABE concentrated all attribute certification and master-key trust in one issuer. Lewko and Waters changed the trust topology: multiple independent authorities could issue attributes without a central coordinator, while global user identities tied their randomized shares to one recipient and blocked simple cross-user pooling. The construction used composite-order groups, a random oracle for identities, and static assumptions; the original treatment also needed a transformation to support repeated attributes cleanly. Its durable contribution was the decentralized MA-ABE interface, not merely another CP-ABE scheme. Subsequent work pursued lattice instantiations and security against authorities corrupted adaptively after the system was running.","prior_boundary":"Earlier ABE systems assumed one master authority, creating a single trust and issuance bottleneck even when attributes naturally belonged to different organizations.","significance_at_publication":"Established decentralized MA-ABE as a separate trust architecture and made adaptive authority corruption and post-quantum realization later targets.","technical_delta":"Allowed any party to act as an attribute authority and bound independently issued key shares to a common global user identity."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","keywords":["multi-authority","decentralized","pairings","random-oracle"],"limitations":["composite-order groups","random oracle for identities","not registered ABE"],"paper_id":"ABE-PAPER-2011-LW-MAABE","qualifiers":["independent attribute authorities","global user identities for collusion resistance"],"source_locator":{"dossier_section":"ABE-PAPER-2011-LW-MAABE § Atomic claims","primary_source":"Section 2.2, PDF p. 7; Section 4, PDF p. 9; Appendices B–C, PDF pp. 18–27","primary_source_url":"https://eprint.iacr.org/2010/351","status":"section_checked"},"statement":"Lewko and Waters constructed decentralized multi-authority ABE in which independent parties issue attributes and global user identities prevent cross-user collusion without a coordinating central authority.","statement_status":"source_normalized_statement","status":"published","title":"Decentralized multi-authority ABE without a central issuer","work_id":"ABE-PAPER-2011-LW-MAABE"},"primaryUrl":"https://eprint.iacr.org/2010/351","sections":[{"content":"Decentralized MA-ABE","heading":"Overview"},{"content":"decentralized-multi-authority-abe-without-central-authority is the atomic contribution identifier normalized from ABE-PAPER-2011-LW-MAABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Decentralizing Attribute-Based Encryption","summary":"Lewko and Waters constructed decentralized multi-authority ABE in which independent parties issue attributes and global user identities prevent cross-user collusion without a coordinating central authority.","title":"Decentralized multi-authority ABE without a central issuer","type":"result","venue":"EUROCRYPT 2011","year":2011,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY"},{"evidence":"published","id":"ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL","keywords":["atomic-result","cp-abe","lsss","pairings","standard-model"],"metadata":{"claim_slug":"expressive-cp-abe-in-the-standard-model","contribution_kind":"security_analysis","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"BSW07 established ciphertext-policy encryption but justified it only in the generic group model with a random oracle. Waters11 gave a direct standard-model construction for monotone LSSS access structures, attaching ciphertext components to policy rows and key components to attributes. The result remained selectively secure and used a parameterized q-type assumption whose parameter had to cover the challenge policy and queried-key dimensions. Even with those qualifications, it supplied a clean, expressive CP-ABE baseline under an explicit reduction rather than an idealized analysis. The construction became a recurring point of comparison for large-universe and efficient pairing ABE, while dual-system work addressed the separate goal of fully adaptive security.","prior_boundary":"The original CP-ABE construction relied on a generic-group proof and a random oracle, while standard-model alternatives had narrower or less direct policy support.","significance_at_publication":"Provided a durable standard-model CP-ABE template, while leaving adaptive security and static-assumption efficiency for later work.","technical_delta":"Gave a direct LSSS-based CP-ABE construction with a standard-model selective-security reduction under decisional q-BDHE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL","keywords":["cp-abe","lsss","pairings","standard-model"],"limitations":["parameterized q-BDHE assumption","challenge-policy and queried-key bounds enter the assumption parameter"],"paper_id":"ABE-PAPER-2011-WATERS","qualifiers":["monotone LSSS access structures","standard model","selective security"],"source_locator":{"dossier_section":"ABE-PAPER-2011-WATERS § Atomic claims","primary_source":"Section 3; Theorem B.1, PDF p. 27","primary_source_url":"https://eprint.iacr.org/2008/290","status":"theorem_checked"},"statement":"Waters constructed CP-ABE for LSSS access structures in the standard model, with ciphertext and key components attached directly to policy rows and attributes.","statement_status":"source_normalized_statement","status":"published","title":"Expressive standard-model CP-ABE","work_id":"ABE-PAPER-2011-WATERS"},"primaryUrl":"https://eprint.iacr.org/2008/290","sections":[{"content":"Standard-model CP-ABE","heading":"Overview"},{"content":"expressive-cp-abe-in-the-standard-model is the atomic contribution identifier normalized from ABE-PAPER-2011-WATERS. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization","summary":"Waters constructed CP-ABE for LSSS access structures in the standard model, with ciphertext and key components attached directly to policy rows and attributes.","title":"Expressive standard-model CP-ABE","type":"result","venue":"PKC 2011","year":2011,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL"},{"evidence":"published","id":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","keywords":["atomic-result","unbounded-abe","lsss","nested-dual-system","pairings"],"metadata":{"claim_slug":"removed-setup-bound-on-abe-universe-and-attribute-set-size","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier small-universe ABE systems encoded an anticipated attribute vocabulary into public parameters, and even large-universe designs could retain setup-time bounds on realized dimensions. LW11 removed the a-priori universe and attribute-count limits for its KP-ABE while preserving LSSS policies and delegation. The result was selectively secure in composite-order groups under the stated assumptions, so “unbounded” here does not mean constant-size objects or full adaptivity. Its historical importance was to separate setup extensibility from policy expressiveness: a system could admit future attributes without being rebuilt. OT12 and CGKW18 later strengthened the security and public-parameter sides of this line, while lattice work pursued different meanings of unbounded input and depth.","prior_boundary":"Many ABE setups fixed the attribute universe or maximum realized attribute count in advance, forcing system-wide parameters to anticipate future policy vocabulary.","significance_at_publication":"Clarified unboundedness as a distinct ABE objective and enabled later work to combine late-bound universes with adaptive security and compact parameters.","technical_delta":"Removed those setup-time bounds through an unbounded dual-system construction while retaining expressive LSSS policies and delegated keys."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","keywords":["unbounded-abe","lsss","nested-dual-system","pairings"],"limitations":["composite-order bilinear groups","object sizes still depend on realized inputs","not adaptive security"],"paper_id":"ABE-PAPER-2011-LW-UNBOUNDED","qualifiers":["setup-unbounded attribute universe","LSSS policies","delegation","selective security"],"source_locator":{"dossier_section":"ABE-PAPER-2011-LW-UNBOUNDED § Atomic claims","primary_source":"KP-ABE construction in Section 5; Theorem 27, PDF p. 38","primary_source_url":"https://eprint.iacr.org/2011/049","status":"theorem_checked"},"statement":"Lewko and Waters constructed KP-ABE whose public parameters do not impose an a-priori attribute universe or attribute-set-size bound, while supporting LSSS policies and delegation.","statement_status":"source_normalized_statement","status":"published","title":"Setup-unbounded KP-ABE with delegation","work_id":"ABE-PAPER-2011-LW-UNBOUNDED"},"primaryUrl":"https://eprint.iacr.org/2011/049","sections":[{"content":"Unbounded universe","heading":"Overview"},{"content":"removed-setup-bound-on-abe-universe-and-attribute-set-size is the atomic contribution identifier normalized from ABE-PAPER-2011-LW-UNBOUNDED. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Unbounded HIBE and Attribute-Based Encryption","summary":"Lewko and Waters constructed KP-ABE whose public parameters do not impose an a-priori attribute universe or attribute-set-size bound, while supporting LSSS policies and delegation.","title":"Setup-unbounded KP-ABE with delegation","type":"result","venue":"EUROCRYPT 2011","year":2011,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE"},{"evidence":"published","id":"ABE-RESULT-2012-LW-FULL-SECURITY-FROM-SELECTIVE-PROOF-COMPONENTS","keywords":["atomic-result","adaptive-security","dual-system","proof-methodology","cp-abe"],"metadata":{"claim_slug":"full-security-from-selective-proof-components","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"LOSSTW10 established that dual-system modes could prove adaptive ABE, but the resulting designs did not make selective techniques feel like reusable building blocks. LW12 showed that a selectively secure mechanism could be embedded directly into a full-security proof, producing CP-ABE with efficiency matching contemporary selective constructions in the paper's composite-order setting. The result is best understood as a proof-method contribution rather than a new ABE syntax. It changed how later designers approached adaptive security: instead of discarding efficient selective algebra, they could ask which components needed to be wrapped in semi-functional modes. Predicate-encoding compilers later pushed this modular viewpoint further in prime-order groups.","prior_boundary":"Adaptive ABE proofs often required bespoke semi-functional constructions whose complexity appeared tied to the final scheme rather than reusable selective ingredients.","significance_at_publication":"Made adaptive-security design more modular and narrowed the perceived efficiency gap between selective and fully secure pairing ABE.","technical_delta":"Developed a proof method that imports selective techniques as components within an adaptive hybrid argument."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2012-LW-FULL-SECURITY-FROM-SELECTIVE-PROOF-COMPONENTS","keywords":["adaptive-security","dual-system","proof-methodology","cp-abe"],"limitations":["pairing-specific proof architecture","no automatic lattice analogue"],"paper_id":"ABE-PAPER-2012-LW","qualifiers":["fully secure CP-ABE","composite-order dual-system proof"],"source_locator":{"dossier_section":"ABE-PAPER-2012-LW § Atomic claims","primary_source":"Theorem 4, PDF p. 11","primary_source_url":"https://eprint.iacr.org/2012/326","status":"theorem_checked"},"statement":"Lewko and Waters showed how selectively secure components could be embedded inside a dual-system proof to obtain fully secure CP-ABE with efficiency comparable to selective systems.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive CP-ABE security assembled from selective proof components","work_id":"ABE-PAPER-2012-LW"},"primaryUrl":"https://eprint.iacr.org/2012/326","sections":[{"content":"Adaptive CP-ABE security assembled from selective proof components","heading":"Overview"},{"content":"full-security-from-selective-proof-components is the atomic contribution identifier normalized from ABE-PAPER-2012-LW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"New Proof Methods for Attribute-Based Encryption: Achieving Full Security through Selective Techniques","summary":"Lewko and Waters showed how selectively secure components could be embedded inside a dual-system proof to obtain fully secure CP-ABE with efficiency comparable to selective systems.","title":"Adaptive CP-ABE security assembled from selective proof components","type":"result","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2012-LW-FULL-SECURITY-FROM-SELECTIVE-PROOF-COMPONENTS"},{"evidence":"published","id":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","keywords":["atomic-result","unbounded","adaptive-security","kp-abe","cp-abe","inner-product-encryption","dual-system","dlin"],"metadata":{"claim_slug":"adaptive-unbounded-abe-from-dlin","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"LW11 removed setup bounds but gave selective security, whereas dual-system systems provided adaptive security with other setup and policy restrictions. OT12 combined these axes: its KP/CP-ABE public parameters do not fix the realized predicate or attribute dimensions, and its payload-hiding security is adaptive in the standard model under DLIN. Indexing and consistent-randomness amplification supplied entropy compatible with the adversary's key-query condition. The result also supports non-monotone access structures, subject to the paper's degree and one-use qualifications and the modified arbitrary-degree variant's linear ciphertext cost. Thus it closed a major pairing feasibility gap without implying constant-size keys, ciphertexts, or hidden policies.","prior_boundary":"Unbounded ABE and fully adaptive ABE had been achieved along separate pairing lines, but their combination with non-monotone policies under a static prime-order assumption remained unresolved.","significance_at_publication":"Demonstrated that setup-unboundedness and adaptive security could coexist under a static assumption, while retaining degree and size qualifications.","technical_delta":"Combined indexing and consistent-randomness amplification to support late-bound dimensions and adaptive key queries under DLIN."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","keywords":["unbounded","adaptive-security","kp-abe","cp-abe","inner-product-encryption","dual-system","dlin"],"limitations":["ABE does not hide attributes or policies","basic scheme has degree-one and one-use restrictions","realized object sizes are not constant"],"paper_id":"ABE-PAPER-2012-OT","qualifiers":["adaptive payload hiding","setup-unbounded dimensions","non-monotone access structures","DLIN"],"source_locator":{"dossier_section":"ABE-PAPER-2012-OT § Atomic claims","primary_source":"ABE Theorems 4–6, PDF pp. 33 and 39–40","primary_source_url":"https://eprint.iacr.org/2012/671","status":"theorem_checked"},"statement":"Okamoto and Takashima constructed public-parameter-unbounded KP/CP-ABE for non-monotone access structures with adaptive payload-hiding security in the standard model under DLIN.","statement_status":"source_normalized_statement","status":"published","title":"Adaptively secure setup-unbounded ABE from DLIN","work_id":"ABE-PAPER-2012-OT"},"primaryUrl":"https://eprint.iacr.org/2012/671","sections":[{"content":"Adaptive unbounded ABE","heading":"Overview"},{"content":"adaptive-unbounded-abe-from-dlin is the atomic contribution identifier normalized from ABE-PAPER-2012-OT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fully Secure Unbounded Inner-Product and Attribute-Based Encryption","summary":"Okamoto and Takashima constructed public-parameter-unbounded KP/CP-ABE for non-monotone access structures with adaptive payload-hiding security in the standard model under DLIN.","title":"Adaptively secure setup-unbounded ABE from DLIN","type":"result","venue":"ASIACRYPT 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN"},{"evidence":"published","id":"ABE-RESULT-2012-SSW-REVOCATION-INTRODUCED-REVOCABLE-STORAGE-ABE-AND-CIPHERTEXT-DELEGATION","keywords":["atomic-result","revocation","ciphertext-delegation","revocable-storage","dynamic-credentials"],"metadata":{"claim_slug":"introduced-revocable-storage-abe-and-ciphertext-delegation","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Conventional revocable ABE primarily controlled future encryptions; it did not automatically revoke access to ciphertexts already placed in storage. SSW12 formalized revocable-storage ABE and used public ciphertext delegation to transform an existing ciphertext into an independently distributed encryption under a more restrictive policy. Together with piecewise key generation, this allowed time updates to affect both new and old data. The compiler carries important scope conditions, including its injective-LSSS starting point and the distributional requirement on delegated ciphertexts. Its influence is architectural: later revocation systems can be compared by who performs updates, whether every ciphertext must be touched, and what additional trust replaces public delegation.","prior_boundary":"Revocation mechanisms could stop access to new ciphertexts yet leave already stored ciphertexts decryptable by a revoked user's old key.","significance_at_publication":"Defined the stronger stored-data revocation target and supplied a compiler pattern for comparing later proxy, hardware, and key-leasing approaches.","technical_delta":"Combined time-aware piecewise key generation with public delegation that refreshes old ciphertexts without exposing plaintext."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2012-SSW-REVOCATION-INTRODUCED-REVOCABLE-STORAGE-ABE-AND-CIPHERTEXT-DELEGATION","keywords":["revocation","ciphertext-delegation","revocable-storage","dynamic-credentials"],"limitations":["compiler starts from injective LSSS matrices","delegated ciphertexts must be distributed as independent fresh encryptions"],"paper_id":"ABE-PAPER-2012-SSW-REVOCATION","qualifiers":["revocable-storage ABE","public ciphertext delegation","piecewise key generation"],"source_locator":{"dossier_section":"ABE-PAPER-2012-SSW-REVOCATION § Atomic claims","primary_source":"Theorem 3.4 and Definition 4.1, PDF p. 9; Theorems 7.1–7.2, PDF pp. 17 and 19","primary_source_url":"https://eprint.iacr.org/2012/437","status":"theorem_checked"},"statement":"Sahai, Seyalioglu, and Waters formalized revocable-storage ABE and introduced public ciphertext delegation so stored ciphertexts can be updated to independent encryptions under more restrictive policies.","statement_status":"source_normalized_statement","status":"published","title":"Revocable-storage ABE with public ciphertext delegation","work_id":"ABE-PAPER-2012-SSW-REVOCATION"},"primaryUrl":"https://eprint.iacr.org/2012/437","sections":[{"content":"Introduced Revocable Storage ABE And Ciphertext Delegation","heading":"Overview"},{"content":"introduced-revocable-storage-abe-and-ciphertext-delegation is the atomic contribution identifier normalized from ABE-PAPER-2012-SSW-REVOCATION. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Dynamic Credentials and Ciphertext Delegation for Attribute-Based Encryption","summary":"Sahai, Seyalioglu, and Waters formalized revocable-storage ABE and introduced public ciphertext delegation so stored ciphertexts can be updated to independent encryptions under more restrictive policies.","title":"Revocable-storage ABE with public ciphertext delegation","type":"result","venue":"CRYPTO 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2012-SSW-REVOCATION-INTRODUCED-REVOCABLE-STORAGE-ABE-AND-CIPHERTEXT-DELEGATION"},{"evidence":"published","id":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-IPE-WITH-FULL-ATTRIBUTE-HIDING","keywords":["atomic-result","unbounded","adaptive-security","kp-abe","cp-abe","inner-product-encryption","dual-system","dlin"],"metadata":{"claim_slug":"adaptive-unbounded-ipe-with-full-attribute-hiding","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Ordinary ABE security protects the payload while allowing attributes or policies to remain visible. OT12's companion IPE result addressed a different privacy axis: generalized inner-product attributes could be fully hidden, with dimensions not fixed in public parameters and security maintained against adaptive key queries. The construction used the same broad indexing and randomness-amplification program as the paper's unbounded ABE, but this card remains separate because full attribute hiding is not inherited by the ABE theorem. Later prime-order IPE work, including CGW18, improved object sizes and assumptions against this benchmark. The result should not be read as general policy-hiding formula or circuit ABE.","prior_boundary":"Payload-hiding ABE concealed the message but generally exposed ciphertext attributes, and earlier IPE did not simultaneously provide late-bound dimensions and adaptive full attribute hiding.","significance_at_publication":"Established a strong privacy point for the IPE branch and a benchmark for later compact prime-order attribute-hiding systems.","technical_delta":"Extended the paper's indexing and entropy-amplification machinery to hide the inner-product attributes themselves under adaptive queries."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-IPE-WITH-FULL-ATTRIBUTE-HIDING","keywords":["unbounded","adaptive-security","kp-abe","cp-abe","inner-product-encryption","dual-system","dlin"],"limitations":["not general policy-hiding formula or circuit ABE"],"paper_id":"ABE-PAPER-2012-OT","qualifiers":["generalized IPE","adaptive full attribute hiding","setup-unbounded dimensions","DLIN"],"source_locator":{"dossier_section":"ABE-PAPER-2012-OT § Atomic claims","primary_source":"IPE Theorems 1–3, PDF pp. 16 and 30–31","primary_source_url":"https://eprint.iacr.org/2012/671","status":"theorem_checked"},"statement":"Okamoto and Takashima constructed unbounded generalized inner-product encryption with adaptive full attribute hiding in the standard model under DLIN.","statement_status":"source_normalized_statement","status":"published","title":"Unbounded IPE with adaptive full attribute hiding","work_id":"ABE-PAPER-2012-OT"},"primaryUrl":"https://eprint.iacr.org/2012/671","sections":[{"content":"Attribute-hiding IPE","heading":"Overview"},{"content":"adaptive-unbounded-ipe-with-full-attribute-hiding is the atomic contribution identifier normalized from ABE-PAPER-2012-OT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fully Secure Unbounded Inner-Product and Attribute-Based Encryption","summary":"Okamoto and Takashima constructed unbounded generalized inner-product encryption with adaptive full attribute hiding in the standard model under DLIN.","title":"Unbounded IPE with adaptive full attribute hiding","type":"result","venue":"ASIACRYPT 2012","year":2012,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-IPE-WITH-FULL-ATTRIBUTE-HIDING"},{"evidence":"published","id":"ABE-RESULT-2013-HW-FAST-PER-USER-EFFICIENCY-TRADEOFF","keywords":["atomic-result","kp-abe","fast-decryption","pairing","large-universe"],"metadata":{"claim_slug":"per-user-efficiency-tradeoff","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The headline two-pairing construction is one endpoint of a broader contribution. Hohenberger and Waters allowed an authority to issue different users keys at different points between a GPSW-like baseline and the fastest decryption variant, without changing public parameters or the encryption algorithm. Users can therefore trade larger policy-dependent keys for fewer online pairings according to their own constraints. This is distinct from merely optimizing one implementation: it is a protocol-level continuum that preserves a shared ciphertext ecosystem. The contribution must therefore be compared on two coordinates—key size and decryption work— rather than summarized by a single speed label. Its security and large-universe qualifications remain those of the underlying selectively secure random-oracle construction.","prior_boundary":"ABE efficiency points were usually fixed globally by the scheme, even though users could have very different storage and decryption budgets.","significance_at_publication":"Introduced a per-recipient optimization surface and separated system-wide compatibility from user-specific performance tuning.","technical_delta":"Parameterized how much policy computation is embedded in each user's key while keeping the common system and ciphertext format unchanged."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-HW-FAST-PER-USER-EFFICIENCY-TRADEOFF","keywords":["kp-abe","fast-decryption","pairing","large-universe"],"limitations":["inherits selective-security","random-oracle","and q-BDHE qualifications"],"paper_id":"ABE-PAPER-2013-HW-FAST","qualifiers":["per-user tradeoff","unchanged public parameters and encryption algorithm"],"source_locator":{"dossier_section":"ABE-PAPER-2013-HW-FAST § Atomic claims","primary_source":"Sections 3.1–3.3 and Theorem 4.1","primary_source_url":"https://eprint.iacr.org/2013/265","status":"section_checked"},"statement":"The Hohenberger-Waters construction exposes per-user choices between GPSW-like key size and the two-pairing endpoint without changing public parameters or encryption.","statement_status":"source_normalized_statement","status":"published","title":"A per-user KP-ABE tradeoff between key size and decryption work","work_id":"ABE-PAPER-2013-HW-FAST"},"primaryUrl":"https://eprint.iacr.org/2013/265","sections":[{"content":"A per-user KP-ABE tradeoff between key size and decryption work","heading":"Overview"},{"content":"per-user-efficiency-tradeoff is the atomic contribution identifier normalized from ABE-PAPER-2013-HW-FAST. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption with Fast Decryption","summary":"The Hohenberger-Waters construction exposes per-user choices between GPSW-like key size and the two-pairing endpoint without changing public parameters or encryption.","title":"A per-user KP-ABE tradeoff between key size and decryption work","type":"result","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-HW-FAST-PER-USER-EFFICIENCY-TRADEOFF"},{"evidence":"published","id":"ABE-RESULT-2013-BNS-ARITH-DEPTH-DEPENDENT-SECRET-KEYS","keywords":["atomic-result","kp-abe","lattice","arithmetic-circuits","delegation"],"metadata":{"claim_slug":"depth-dependent-secret-keys","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The same BNS13 construction that enabled arithmetic policies also changed which measure of circuit complexity appears in a secret key. Instead of storing material proportional to every gate or wire, the key is represented by a low-norm matrix whose dimensions and noise budget depend on maximum depth. This does not make the key independent of all policy complexity: the modulus and parameters still grow with the leveled depth, and the theorem remains selectively secure. For comparison with subsequent succinct ABE, the dimensions must remain separate: keys, ciphertexts, and public parameters may independently depend on circuit size, input length, or depth. Its significance is to expose that size coordinate, rather than to claim that every later succinct construction inherits the same mechanism.","prior_boundary":"Expressive circuit keys could grow with the full circuit description, making the cost of large but shallow policies track gate count directly.","significance_at_publication":"Introduced an early circuit-succinctness point and clarified depth as the governing resource for leveled lattice ABE.","technical_delta":"Compressed the evaluated policy into a low-norm matrix while moving the remaining dependence into depth-sensitive lattice parameters."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-BNS-ARITH-DEPTH-DEPENDENT-SECRET-KEYS","keywords":["kp-abe","lattice","arithmetic-circuits","delegation"],"limitations":["size and noise remain depth-dependent","selective CPA security"],"paper_id":"ABE-PAPER-2013-BNS-ARITH","qualifiers":["one low-norm matrix secret key","size independent of gate and wire count"],"source_locator":{"dossier_section":"ABE-PAPER-2013-BNS-ARITH § Atomic claims","primary_source":"Section 1, Parameters and performance; Section 3; Theorem A.2","primary_source_url":"https://eprint.iacr.org/2013/669","status":"theorem_checked"},"statement":"The BNS arithmetic-circuit KP-ABE represents a decryption key by one low-norm matrix whose size depends on circuit depth rather than the number of gates or wires.","statement_status":"source_normalized_statement","status":"published","title":"Arithmetic-circuit ABE keys depend on depth, not gate count","work_id":"ABE-PAPER-2013-BNS-ARITH"},"primaryUrl":"https://eprint.iacr.org/2013/669","sections":[{"content":"Depth Dependent Secret Keys","heading":"Overview"},{"content":"depth-dependent-secret-keys is the atomic contribution identifier normalized from ABE-PAPER-2013-BNS-ARITH. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Arithmetic Circuits","summary":"The BNS arithmetic-circuit KP-ABE represents a decryption key by one low-norm matrix whose size depends on circuit depth rather than the number of gates or wires.","title":"Arithmetic-circuit ABE keys depend on depth, not gate count","type":"result","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-BNS-ARITH-DEPTH-DEPENDENT-SECRET-KEYS"},{"evidence":"published","id":"ABE-RESULT-2013-HW-FAST-CONSTANT-TWO-PAIRING-KP-ABE","keywords":["atomic-result","kp-abe","fast-decryption","pairing","large-universe"],"metadata":{"claim_slug":"constant-two-pairing-kp-abe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Prior expressive KP-ABE systems evaluated a secret-sharing reconstruction with pairing work that scaled with the satisfying policy. Hohenberger and Waters moved much of that work into user-specific key material, obtaining a main decryption path with two pairings in the fastest endpoint. The recorded large-universe variant is selectively CPA secure in the random oracle model under decisional q-BDHE, and the secret key grows with the number of distinct attributes appearing in the policy. This is therefore not a universal efficiency dominance claim. Its importance is the concrete resource trade: when keys are issued infrequently but decryption is latency-sensitive, more key material can reduce expensive pairings.","prior_boundary":"Expressive KP-ABE decryption typically performed pairings proportional to the number of policy rows or satisfied attributes.","significance_at_publication":"Made online decryption latency an explicit ABE optimization objective and demonstrated that key size can buy fewer pairings.","technical_delta":"Precomputed more policy-dependent material in the secret key so successful decryption could aggregate to two pairings."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-HW-FAST-CONSTANT-TWO-PAIRING-KP-ABE","keywords":["kp-abe","fast-decryption","pairing","large-universe"],"limitations":["random oracle","decisional q-BDHE","secret-key growth in distinct policy attributes"],"paper_id":"ABE-PAPER-2013-HW-FAST","qualifiers":["large-universe KP-ABE","two-pairing main decryption path","selective CPA security"],"source_locator":{"dossier_section":"ABE-PAPER-2013-HW-FAST § Atomic claims","primary_source":"Sections 3.1–3.3 and Theorem 4.1","primary_source_url":"https://eprint.iacr.org/2013/265","status":"section_checked"},"statement":"Hohenberger and Waters constructed expressive large-universe KP-ABE whose main decryption path uses two pairings, at the cost of larger user secret keys.","statement_status":"source_normalized_statement","status":"published","title":"Expressive KP-ABE with a two-pairing decryption path","work_id":"ABE-PAPER-2013-HW-FAST"},"primaryUrl":"https://eprint.iacr.org/2013/265","sections":[{"content":"Constant Two Pairing KP-ABE","heading":"Overview"},{"content":"constant-two-pairing-kp-abe is the atomic contribution identifier normalized from ABE-PAPER-2013-HW-FAST. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption with Fast Decryption","summary":"Hohenberger and Waters constructed expressive large-universe KP-ABE whose main decryption path uses two pairings, at the cost of larger user secret keys.","title":"Expressive KP-ABE with a two-pairing decryption path","type":"result","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-HW-FAST-CONSTANT-TWO-PAIRING-KP-ABE"},{"evidence":"published","id":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","keywords":["atomic-result","circuits","lwe","post-quantum","selective-security"],"metadata":{"claim_slug":"first-general-circuit-abe-from-lwe","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"GGHSSW13 established arbitrary-circuit ABE through multilinear maps, but a durable lattice route was still missing. GVW13 constructed ABE for arbitrary polynomial-size circuits from LWE, with setup parameters tied to a maximum circuit depth and selective security. Its homomorphic evaluation view also connected ABE to branching programs and LOGSPACE. This was the foundational feasibility result for lattice circuit ABE: later work improved key succinctness, unbounded attribute length, policy classes, and object sizes by changing how evaluation and recoding are represented. It did not solve unbounded depth or adaptive security; those limitations became distinct research programs rather than reasons to weaken the general-circuit contribution.","prior_boundary":"The first arbitrary-circuit ABE relied on candidate multilinear maps, while lattice ABE had not yet supported general circuit policies.","significance_at_publication":"Opened the post-quantum general-circuit ABE line and exposed depth, noise, and succinctness as its central resources.","technical_delta":"Adapted homomorphic lattice evaluation and key delegation to enforce bounded-depth circuit predicates under LWE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","keywords":["circuits","lwe","post-quantum","selective-security"],"limitations":["parameters depend on maximum circuit depth","not adaptive","not unbounded-depth ABE"],"paper_id":"ABE-PAPER-2013-GVW","qualifiers":["LWE","arbitrary polynomial-size circuits within a setup depth bound","selective security"],"source_locator":{"dossier_section":"ABE-PAPER-2013-GVW § Atomic claims","primary_source":"Informal Theorems 2.1 and 2.3, PDF p. 3; formal Theorem 6.1, PDF p. 16","primary_source_url":"https://eprint.iacr.org/2013/337","status":"theorem_checked"},"statement":"Gorbunov, Vaikuntanathan, and Wee constructed the first ABE for arbitrary polynomial-size bounded-depth circuits from LWE.","statement_status":"source_normalized_statement","status":"published","title":"General-circuit ABE from LWE","work_id":"ABE-PAPER-2013-GVW"},"primaryUrl":"https://eprint.iacr.org/2013/337","sections":[{"content":"General circuit ABE","heading":"Overview"},{"content":"first-general-circuit-abe-from-lwe is the atomic contribution identifier normalized from ABE-PAPER-2013-GVW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Circuits","summary":"Gorbunov, Vaikuntanathan, and Wee constructed the first ABE for arbitrary polynomial-size bounded-depth circuits from LWE.","title":"General-circuit ABE from LWE","type":"result","venue":"STOC 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE"},{"evidence":"published","id":"ABE-RESULT-2013-BNS-ARITH-LWE-ABE-FOR-ARITHMETIC-CIRCUITS","keywords":["atomic-result","kp-abe","lattice","arithmetic-circuits","delegation"],"metadata":{"claim_slug":"lwe-abe-for-arithmetic-circuits","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"General-circuit ABE had opened a path beyond formulas, but arithmetic computation required different algebra and noise accounting. Boneh, Nikolaenko, and Segev constructed KP-ABE from LWE for polynomial-size arithmetic circuits, so a key could authorize decryption according to an arithmetic computation on ciphertext attributes. The result was selectively CPA secure, its parameters were leveled by the supported depth, and it supported key delegation. This capability contribution is distinct from the paper's compact-key observation: the construction determines what policies can be evaluated, while the companion card identifies which circuit dimension controls the secret-key representation. The result established an arithmetic-functionality point, but it does not by itself show that later arithmetic or lookup-table mechanisms inherit this construction.","prior_boundary":"Circuit ABE work concentrated on Boolean computation, while arithmetic policies over rings or fields lacked a comparable lattice-based ABE construction.","significance_at_publication":"Extended the computational meaning of lattice ABE beyond Boolean policies and connected ABE to arithmetic-circuit encodings.","technical_delta":"Used homomorphic lattice evaluation to bind decryption to an arithmetic circuit's output and support delegated keys."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-BNS-ARITH-LWE-ABE-FOR-ARITHMETIC-CIRCUITS","keywords":["kp-abe","lattice","arithmetic-circuits","delegation"],"limitations":["modulus and noise budget depend on supported circuit depth"],"paper_id":"ABE-PAPER-2013-BNS-ARITH","qualifiers":["KP-ABE","polynomial-size arithmetic circuits","selective CPA security","LWE","key delegation"],"source_locator":{"dossier_section":"ABE-PAPER-2013-BNS-ARITH § Atomic claims","primary_source":"Section 1, Parameters and performance; Section 3; Theorem A.2","primary_source_url":"https://eprint.iacr.org/2013/669","status":"theorem_checked"},"statement":"Boneh, Nikolaenko, and Segev constructed selectively secure KP-ABE for polynomial-size arithmetic circuits from LWE, with delegation.","statement_status":"source_normalized_statement","status":"published","title":"LWE-based KP-ABE for arithmetic circuits","work_id":"ABE-PAPER-2013-BNS-ARITH"},"primaryUrl":"https://eprint.iacr.org/2013/669","sections":[{"content":"LWE ABE For Arithmetic Circuits","heading":"Overview"},{"content":"lwe-abe-for-arithmetic-circuits is the atomic contribution identifier normalized from ABE-PAPER-2013-BNS-ARITH. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Arithmetic Circuits","summary":"Boneh, Nikolaenko, and Segev constructed selectively secure KP-ABE for polynomial-size arithmetic circuits from LWE, with delegation.","title":"LWE-based KP-ABE for arithmetic circuits","type":"result","venue":"IACR ePrint 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-BNS-ARITH-LWE-ABE-FOR-ARITHMETIC-CIRCUITS"},{"evidence":"published","id":"ABE-RESULT-2013-RW-PRACTICAL-LARGE-UNIVERSE-CP-ABE","keywords":["atomic-result","large-universe","kp-abe","cp-abe","prime-order-pairings","selective-security","implementation"],"metadata":{"claim_slug":"practical-large-universe-cp-abe","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The CP orientation makes the data owner choose the access policy, so a fixed setup vocabulary is especially restrictive in evolving deployments. RW13 gave a prime-order large-universe CP-ABE in which arbitrary attribute strings can appear after setup, policies are monotone LSSS structures, and public parameters stay constant size. The paper also implemented the scheme in Charm and reported comparisons with prior ABE systems. Its contribution combines construction and realizability, but the security theorem is selective under a parameterized q-type assumption; constant public parameters do not turn that assumption into a static one. Later efficient systems such as FAME improve other coordinates while RW remains a key large-universe baseline.","prior_boundary":"CP-ABE deployments needed arbitrary attribute names without a setup enumeration, but existing expressive or unbounded systems were not a simple practical prime-order baseline.","significance_at_publication":"Established a practical large-universe CP-ABE reference point, subject to selective q-type security.","technical_delta":"Combined arbitrary-string attributes, LSSS ciphertext policies, constant public parameters, and a Charm implementation with reported benchmarks."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-RW-PRACTICAL-LARGE-UNIVERSE-CP-ABE","keywords":["large-universe","kp-abe","cp-abe","prime-order-pairings","selective-security","implementation"],"limitations":["selective security","parameterized q-type assumption","not adaptive"],"paper_id":"ABE-PAPER-2013-RW","qualifiers":["large-universe CP-ABE","monotone LSSS policies","constant public parameters","Charm implementation"],"source_locator":{"dossier_section":"ABE-PAPER-2013-RW § Atomic claims","primary_source":"CP-ABE Theorem 4.1, PDF p. 8; implementation and benchmarks in Section 5","primary_source_url":"https://eprint.iacr.org/2012/583","status":"theorem_checked"},"statement":"Rouselakis and Waters constructed and implemented large-universe CP-ABE for monotone LSSS policies with constant-size public parameters in prime-order bilinear groups.","statement_status":"source_normalized_statement","status":"published","title":"Practical large-universe CP-ABE in prime-order groups","work_id":"ABE-PAPER-2013-RW"},"primaryUrl":"https://eprint.iacr.org/2012/583","sections":[{"content":"Practical Large Universe CP-ABE","heading":"Overview"},{"content":"practical-large-universe-cp-abe is the atomic contribution identifier normalized from ABE-PAPER-2013-RW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Practical Constructions and New Proof Methods for Large Universe Attribute-Based Encryption","summary":"Rouselakis and Waters constructed and implemented large-universe CP-ABE for monotone LSSS policies with constant-size public parameters in prime-order bilinear groups.","title":"Practical large-universe CP-ABE in prime-order groups","type":"result","venue":"ACM CCS 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-RW-PRACTICAL-LARGE-UNIVERSE-CP-ABE"},{"evidence":"published","id":"ABE-RESULT-2013-RW-EFFICIENT-LARGE-UNIVERSE-KP-ABE","keywords":["atomic-result","large-universe","kp-abe","cp-abe","prime-order-pairings","selective-security","implementation"],"metadata":{"claim_slug":"efficient-large-universe-kp-abe","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"LW11 showed that setup-unbounded ABE was theoretically possible, but practical prime-order systems still needed a clean way to admit arbitrary attributes without publishing one parameter per vocabulary item. RW13 supplied that point for KP-ABE: ciphertexts can use arbitrary attribute strings, keys carry monotone LSSS policies, and the public parameters remain constant size. The proof is selective and uses a parameterized q-type assumption whose bound covers the challenge attribute set, so the result should not be relabeled as static-assumption adaptive ABE. Alongside its CP orientation and Charm implementation, it made large-universe design a concrete baseline that later efficient pairing systems could implement and compare.","prior_boundary":"Small-universe systems enumerated attributes at setup, while earlier unbounded constructions carried heavier composite-order or proof costs.","significance_at_publication":"Made large-universe KP-ABE a practical construction family, though under selective q-type assumptions rather than static adaptive security.","technical_delta":"Mapped arbitrary strings into the KP-ABE ciphertext interface while retaining constant public parameters and an implementable prime-order design."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-RW-EFFICIENT-LARGE-UNIVERSE-KP-ABE","keywords":["large-universe","kp-abe","cp-abe","prime-order-pairings","selective-security","implementation"],"limitations":["selective security","parameterized q-type assumption","not adaptive"],"paper_id":"ABE-PAPER-2013-RW","qualifiers":["large-universe KP-ABE","monotone LSSS policies","constant public parameters","prime-order groups"],"source_locator":{"dossier_section":"ABE-PAPER-2013-RW § Atomic claims","primary_source":"KP-ABE Theorem C.1, PDF p. 20; implementation in Section 5","primary_source_url":"https://eprint.iacr.org/2012/583","status":"theorem_checked"},"statement":"Rouselakis and Waters constructed large-universe KP-ABE for monotone LSSS policies in prime-order groups with constant-size public parameters and arbitrary attribute strings.","statement_status":"source_normalized_statement","status":"published","title":"Practical large-universe KP-ABE with constant public parameters","work_id":"ABE-PAPER-2013-RW"},"primaryUrl":"https://eprint.iacr.org/2012/583","sections":[{"content":"Efficient Large Universe KP-ABE","heading":"Overview"},{"content":"efficient-large-universe-kp-abe is the atomic contribution identifier normalized from ABE-PAPER-2013-RW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Practical Constructions and New Proof Methods for Large Universe Attribute-Based Encryption","summary":"Rouselakis and Waters constructed large-universe KP-ABE for monotone LSSS policies in prime-order groups with constant-size public parameters and arbitrary attribute strings.","title":"Practical large-universe KP-ABE with constant public parameters","type":"result","venue":"ACM CCS 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-RW-EFFICIENT-LARGE-UNIVERSE-KP-ABE"},{"evidence":"published","id":"ABE-RESULT-2013-GGHSSW-FIRST-GENERAL-CIRCUIT-ABE-FROM-MULTILINEAR-MAPS","keywords":["atomic-result","circuits","multilinear-maps","feasibility","selective-security"],"metadata":{"claim_slug":"first-general-circuit-abe-from-multilinear-maps","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Formula and span-program ABE cannot reuse intermediate computations in the way arbitrary circuits can, so the jump to general circuits was a genuine expressiveness boundary. GGHSSW13 crossed it using candidate graded multilinear maps, giving both KP and CP orientations under selective security. The result showed that ABE could in principle enforce every polynomial-size circuit rather than only formula-like policies. Its historical role remains important even though the underlying multilinear-map candidates later proved unsuitable as a stable assumption base. In parallel, GVW13 reached bounded-depth general circuits from LWE, creating the more durable post-quantum branch. The two works separate feasibility of the functionality from the long-term credibility of a concrete foundation.","prior_boundary":"ABE policies had reached formulas and span programs, but arbitrary circuits with reusable intermediate computation lay beyond bilinear-map techniques.","significance_at_publication":"Established general-circuit ABE feasibility, while tying the construction to candidate multilinear maps that did not become durable assumptions.","technical_delta":"Used graded multilinear encodings to represent wire values across circuit levels and enforce decryption only at an accepting output."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2013-GGHSSW-FIRST-GENERAL-CIRCUIT-ABE-FROM-MULTILINEAR-MAPS","keywords":["circuits","multilinear-maps","feasibility","selective-security"],"limitations":["candidate graded multilinear maps","not a current standard-assumption instantiation"],"paper_id":"ABE-PAPER-2013-GGHSSW","qualifiers":["KP-ABE and CP-ABE","arbitrary polynomial-size circuits","selective security"],"source_locator":{"dossier_section":"ABE-PAPER-2013-GGHSSW § Atomic claims","primary_source":"Theorems 4.1 and 6.1, PDF pp. 11 and 19","primary_source_url":"https://eprint.iacr.org/2013/128","status":"theorem_checked"},"statement":"GGHSSW constructed selectively secure KP- and CP-ABE for arbitrary polynomial-size circuits using candidate multilinear maps.","statement_status":"source_normalized_statement","status":"published","title":"The first arbitrary-circuit ABE from candidate multilinear maps","work_id":"ABE-PAPER-2013-GGHSSW"},"primaryUrl":"https://eprint.iacr.org/2013/128","sections":[{"content":"The first arbitrary-circuit ABE from candidate multilinear maps","heading":"Overview"},{"content":"first-general-circuit-abe-from-multilinear-maps is the atomic contribution identifier normalized from ABE-PAPER-2013-GGHSSW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Circuits from Multilinear Maps","summary":"GGHSSW constructed selectively secure KP- and CP-ABE for arbitrary polynomial-size circuits using candidate multilinear maps.","title":"The first arbitrary-circuit ABE from candidate multilinear maps","type":"result","venue":"CRYPTO 2013","year":2013,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2013-GGHSSW-FIRST-GENERAL-CIRCUIT-ABE-FROM-MULTILINEAR-MAPS"},{"evidence":"published","id":"ABE-RESULT-2014-CW-SEMIADAPTIVE-CONSTANT-CIPHERTEXT-SEMI-ADAPTIVE-KPABE","keywords":["atomic-result","semi-adaptive-security","kp-abe","short-ciphertext","dual-system","delegation"],"metadata":{"claim_slug":"constant-ciphertext-semi-adaptive-kpabe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The semi-adaptive definition was accompanied by a concrete compactness result. Chen and Wee's composite-order KP-ABE keeps ciphertext size constant while allowing the adversary to choose the challenge attribute vector after seeing public parameters. This point depends on three static composite-order assumptions. The paper's prime-order SXDH construction has a different size profile—its ciphertext grows with the attribute-vector length—so the two branches must not be conflated. Historically, the result demonstrated that moving beyond selective security need not automatically sacrifice ciphertext succinctness. Later work pursued the harder combinations: prime-order groups, full adaptivity, unbounded dimensions, and simultaneous compactness of keys, ciphertexts, and public parameters.","prior_boundary":"Constant ciphertexts were known at weaker security points, while adaptive improvements often reintroduced dependence on the attribute-vector length.","significance_at_publication":"Showed that stronger challenge timing and ciphertext succinctness could coexist, while prime-order and fully adaptive variants remained separate goals.","technical_delta":"Combined the new semi-adaptive timing model with a composite-order construction whose ciphertext has constant group-element count."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2014-CW-SEMIADAPTIVE-CONSTANT-CIPHERTEXT-SEMI-ADAPTIVE-KPABE","keywords":["semi-adaptive-security","kp-abe","short-ciphertext","dual-system","delegation"],"limitations":["three static composite-order assumptions","prime-order SXDH variant has linear ciphertext size","not fully adaptive"],"paper_id":"ABE-PAPER-2014-CW-SEMIADAPTIVE","qualifiers":["semi-adaptive KP-ABE","constant group-element ciphertext count","composite-order groups"],"source_locator":{"dossier_section":"ABE-PAPER-2014-CW-SEMIADAPTIVE § Atomic claims","primary_source":"Theorem 1, PDF p. 9; prime-order comparison in Theorem 2, PDF p. 21","primary_source_url":"https://eprint.iacr.org/2014/465","status":"theorem_checked"},"statement":"Chen and Wee constructed semi-adaptively secure KP-ABE with constant-size ciphertexts in composite-order groups under static assumptions.","statement_status":"source_normalized_statement","status":"published","title":"Constant-ciphertext semi-adaptive KP-ABE","work_id":"ABE-PAPER-2014-CW-SEMIADAPTIVE"},"primaryUrl":"https://eprint.iacr.org/2014/465","sections":[{"content":"Constant Ciphertext Semi Adaptive Kpabe","heading":"Overview"},{"content":"constant-ciphertext-semi-adaptive-kpabe is the atomic contribution identifier normalized from ABE-PAPER-2014-CW-SEMIADAPTIVE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Semi-Adaptive Attribute-Based Encryption and Improved Delegation for Boolean Formula","summary":"Chen and Wee constructed semi-adaptively secure KP-ABE with constant-size ciphertexts in composite-order groups under static assumptions.","title":"Constant-ciphertext semi-adaptive KP-ABE","type":"result","venue":"SCN 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2014-CW-SEMIADAPTIVE-CONSTANT-CIPHERTEXT-SEMI-ADAPTIVE-KPABE"},{"evidence":"published","id":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","keywords":["atomic-result","lwe","arithmetic-circuits","short-keys","key-homomorphic-encryption"],"metadata":{"claim_slug":"lattice-abe-for-arithmetic-circuits-with-depth-dependent-keys","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"GVW13 and BNS13 established that LWE could support circuit and arithmetic-policy ABE, but succinct representation of the authorized computation remained central. BGGPS14 developed fully key-homomorphic encryption and used it to derive arithmetic-circuit ABE whose secret-key size is governed by maximum depth rather than the number of gates. The construction is selectively secure, leveled, and in its concrete form uses subexponential LWE, so depth and assumption strength remain visible costs. The contribution is the reusable key-homomorphic mechanism and its compactness consequence, not an unqualified constant-size result. It helped define the route toward later lattice ABE in which object sizes progressively shed circuit-size and input-length dependencies.","prior_boundary":"Early lattice circuit ABE achieved expressiveness but left large policy descriptions and leveled noise as major object-size constraints.","significance_at_publication":"Strengthened the lattice succinctness route and supplied techniques connected to compact garbling and homomorphic encodings.","technical_delta":"Introduced key-homomorphic evaluation that compresses an arithmetic circuit into depth-governed key material."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","keywords":["lwe","arithmetic-circuits","short-keys","key-homomorphic-encryption"],"limitations":["selective security","leveled maximum depth","subexponential LWE in the concrete instantiation"],"paper_id":"ABE-PAPER-2014-BGGPS","qualifiers":["arithmetic-circuit ABE","fully key-homomorphic encryption","depth-dependent secret keys"],"source_locator":{"dossier_section":"ABE-PAPER-2014-BGGPS § Atomic claims","primary_source":"Theorems 3.2 and 6.1, PDF pp. 14 and 31","primary_source_url":"https://eprint.iacr.org/2014/356","status":"theorem_checked"},"statement":"BGGPS used fully key-homomorphic encryption to construct selectively secure lattice ABE for arithmetic circuits whose secret-key size depends on depth rather than circuit size.","statement_status":"source_normalized_statement","status":"published","title":"Key-homomorphic lattice ABE with depth-dependent keys","work_id":"ABE-PAPER-2014-BGGPS"},"primaryUrl":"https://eprint.iacr.org/2014/356","sections":[{"content":"Arithmetic-circuit ABE","heading":"Overview"},{"content":"lattice-abe-for-arithmetic-circuits-with-depth-dependent-keys is the atomic contribution identifier normalized from ABE-PAPER-2014-BGGPS. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fully Key-Homomorphic Encryption, Arithmetic Circuit ABE, and Compact Garbled Circuits","summary":"BGGPS used fully key-homomorphic encryption to construct selectively secure lattice ABE for arithmetic circuits whose secret-key size depends on depth rather than circuit size.","title":"Key-homomorphic lattice ABE with depth-dependent keys","type":"result","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS"},{"evidence":"published","id":"ABE-RESULT-2014-ATTRAPADUNG-INTRODUCED-PAIR-ENCODING-FRAMEWORK","keywords":["atomic-result","pair-encodings","dual-system-encryption","adaptive-security","abe"],"metadata":{"claim_slug":"introduced-pair-encoding-framework","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this work, dual-system encryption was powerful but largely expressed through predicate-specific constructions, and important targets such as fully secure regular-language functional encryption remained outside its apparent reach. Attrapadung factored the algebra into pair encoding schemes and introduced doubly selective security as the condition a generic dual-system compiler could amplify to adaptive security. The framework then supported several distinct instantiations, including unbounded large-universe ABE and ABE with constant-size ciphertexts. Its historical importance is therefore methodological as well as constructive: it supplied a reusable intermediate language for later pairing ABE design, while each instantiation retained its own composite-order and compactness tradeoffs.","prior_boundary":"Dual-system encryption had produced fully secure functional encryption for several predicates, but its predicate-specific exponent manipulations lacked a reusable abstraction and did not cover regular languages or several compact ABE targets.","significance_at_publication":"The framework turned a family of hand-built dual-system arguments into a reusable construction interface and yielded new regular-language, unbounded-ABE, and constant-ciphertext instantiations.","technical_delta":"Pair encodings isolate the predicate algebra and a doubly selective security condition that a generic dual-system construction lifts to adaptive functional-encryption security."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2014-ATTRAPADUNG-INTRODUCED-PAIR-ENCODING-FRAMEWORK","keywords":["pair-encodings","dual-system-encryption","adaptive-security","abe"],"limitations":["does not make every instantiation compact","original highlighted constructions use composite-order groups"],"paper_id":"ABE-PAPER-2014-ATTRAPADUNG","qualifiers":["generic pair-encoding framework","doubly selective security","composite-order instantiations"],"source_locator":{"dossier_section":"ABE-PAPER-2014-ATTRAPADUNG § Atomic contributions","primary_source":"Abstract; Sections 3 and 6 of ePrint 2014/428","primary_source_url":"https://eprint.iacr.org/2014/428","status":"section_checked"},"statement":"Attrapadung introduced pair encoding schemes with doubly selective security and a generic dual-system compiler to adaptively secure functional encryption, including unbounded and constant-ciphertext ABE instantiations.","statement_status":"source_normalized_statement","status":"published","title":"Pair-encoding framework for adaptively secure functional encryption","work_id":"ABE-PAPER-2014-ATTRAPADUNG"},"primaryUrl":"https://eprint.iacr.org/2014/428","sections":[{"content":"Pair encodings","heading":"Overview"}],"status":"published","subtitle":"Dual System Encryption via Doubly Selective Security: Framework, Fully-secure Functional Encryption for Regular Languages, and More","summary":"Attrapadung introduced pair encoding schemes with doubly selective security and a generic dual-system compiler to adaptively secure functional encryption, including unbounded and constant-ciphertext ABE instantiations.","title":"Pair-encoding framework for adaptively secure functional encryption","type":"result","venue":"EUROCRYPT 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2014-ATTRAPADUNG-INTRODUCED-PAIR-ENCODING-FRAMEWORK"},{"evidence":"published","id":"ABE-RESULT-2014-CW-SEMIADAPTIVE-INTRODUCED-SEMI-ADAPTIVE-ABE","keywords":["atomic-result","semi-adaptive-security","kp-abe","short-ciphertext","dual-system","delegation"],"metadata":{"claim_slug":"introduced-semi-adaptive-abe","contribution_kind":"definition","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"ABE security notions differ primarily in when the adversary commits to the challenge relative to setup and key queries. Selective security commits before public parameters are seen; full adaptivity allows a richer interaction. Chen and Wee isolated an intermediate point: the challenge attribute vector is chosen after setup but before secret-key queries. This semi-adaptive notion is strictly more informative than selective security while remaining weaker than full adaptive security. Treating it as its own contribution prevents later construction results from being overstated. The notion became especially useful in lattice and compact ABE, where late-bound attributes could be supported before techniques existed for arbitrary adaptive query histories.","prior_boundary":"Selective security fixed the challenge before setup, while full adaptive security permitted interleaved key queries and a later challenge; no standard intermediate target captured late challenge choice alone.","significance_at_publication":"Created a meaningful intermediate security milestone subsequently used when full lattice or compact adaptivity was out of reach.","technical_delta":"Defined a timing model between selective and fully adaptive security that allows setup-dependent challenge selection but orders it before key queries."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2014-CW-SEMIADAPTIVE-INTRODUCED-SEMI-ADAPTIVE-ABE","keywords":["semi-adaptive-security","kp-abe","short-ciphertext","dual-system","delegation"],"limitations":["strictly weaker than fully adaptive security"],"paper_id":"ABE-PAPER-2014-CW-SEMIADAPTIVE","qualifiers":["challenge chosen after setup","challenge fixed before secret-key queries"],"source_locator":{"dossier_section":"ABE-PAPER-2014-CW-SEMIADAPTIVE § Atomic claims","primary_source":"Definition 2, PDF p. 6","primary_source_url":"https://eprint.iacr.org/2014/465","status":"section_checked"},"statement":"Chen and Wee formalized semi-adaptive KP-ABE security, where the adversary chooses the challenge attribute vector after setup but before making secret-key queries.","statement_status":"source_normalized_statement","status":"published","title":"The semi-adaptive ABE security notion","work_id":"ABE-PAPER-2014-CW-SEMIADAPTIVE"},"primaryUrl":"https://eprint.iacr.org/2014/465","sections":[{"content":"Introduced Semi Adaptive ABE","heading":"Overview"},{"content":"introduced-semi-adaptive-abe is the atomic contribution identifier normalized from ABE-PAPER-2014-CW-SEMIADAPTIVE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Semi-Adaptive Attribute-Based Encryption and Improved Delegation for Boolean Formula","summary":"Chen and Wee formalized semi-adaptive KP-ABE security, where the adversary chooses the challenge attribute vector after setup but before making secret-key queries.","title":"The semi-adaptive ABE security notion","type":"result","venue":"SCN 2014","year":2014,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2014-CW-SEMIADAPTIVE-INTRODUCED-SEMI-ADAPTIVE-ABE"},{"evidence":"published","id":"ABE-RESULT-2015-CGW-MODULAR-ADAPTIVE-ABE-FROM-PREDICATE-ENCODINGS","keywords":["atomic-result","predicate-encodings","dual-system","adaptive-security","pairings"],"metadata":{"claim_slug":"modular-adaptive-abe-from-predicate-encodings","contribution_kind":"transform","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Dual-system techniques had delivered adaptive ABE, but each policy family still appeared to require custom algebra and proof. CGW15 factored that work into predicate encodings plus explicit left/right subgroup-indistinguishability conditions. A qualifying encoding could then be compiled to adaptively secure ABE in prime-order groups under the k-linear family, with the reduction loss stated in terms of queries and encoding size. The contribution is therefore a modular mechanism, not one isolated scheme. It influenced later automation and registered-ABE compilers by making the policy algebra an inspectable intermediate object. The framework's conditions and reduction costs still have to be checked for each encoding; the compiler does not certify arbitrary symbolic formulas automatically.","prior_boundary":"Dual-system ABE proofs were effective but often entwined the policy algebra, semi-functional distributions, and reduction in one bespoke construction.","significance_at_publication":"Turned a family of pairing-based ABE proofs into a reusable construction-and-proof framework and improved their analyzability.","technical_delta":"Separated predicate representation from adaptive-security lifting through explicit left/right subgroup-indistinguishability properties."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2015-CGW-MODULAR-ADAPTIVE-ABE-FROM-PREDICATE-ENCODINGS","keywords":["predicate-encodings","dual-system","adaptive-security","pairings"],"limitations":["query- and encoding-size-dependent reduction loss","encoding conditions require per-instance verification"],"paper_id":"ABE-PAPER-2015-CGW","qualifiers":["prime-order groups","k-linear assumption family","qualifying predicate encodings"],"source_locator":{"dossier_section":"ABE-PAPER-2015-CGW § Atomic claims","primary_source":"Theorem 1 in Section 6.2, PDF p. 17","primary_source_url":"https://eprint.iacr.org/2015/409","status":"theorem_checked"},"statement":"Chen, Gay, and Wee gave a modular compiler from suitable predicate encodings to adaptively secure ABE in prime-order groups under the k-linear assumption family.","statement_status":"source_normalized_statement","status":"published","title":"A predicate-encoding compiler for adaptive ABE","work_id":"ABE-PAPER-2015-CGW"},"primaryUrl":"https://eprint.iacr.org/2015/409","sections":[{"content":"Modular Adaptive ABE From Predicate Encodings","heading":"Overview"},{"content":"modular-adaptive-abe-from-predicate-encodings is the atomic contribution identifier normalized from ABE-PAPER-2015-CGW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Improved Dual System ABE in Prime-Order Groups via Predicate Encodings","summary":"Chen, Gay, and Wee gave a modular compiler from suitable predicate encodings to adaptively secure ABE in prime-order groups under the k-linear assumption family.","title":"A predicate-encoding compiler for adaptive ABE","type":"result","venue":"EUROCRYPT 2015","year":2015,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2015-CGW-MODULAR-ADAPTIVE-ABE-FROM-PREDICATE-ENCODINGS"},{"evidence":"published","id":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","keywords":["atomic-result","lwe","unbounded-attributes","semi-adaptive","delayed-programming"],"metadata":{"claim_slug":"unbounded-attribute-length-and-semi-adaptive-circuit-abe-from-lwe","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The original LWE circuit-ABE feasibility result was selective and parameterized setup by the relevant circuit dimensions. BV16 removed the setup bound on attribute and circuit-input length while retaining only a maximum depth bound, and it strengthened the challenge timing to semi-adaptive security. The construction relies on the paper's lattice hardness parameterization, and its key and ciphertext sizes still grow with realized input dimensions, so “unbounded” is about late binding rather than constant size. This distinction became the baseline for later revisitations such as Cini–Wee24, which sought a cleaner black-box use of LWE machinery, and for separate work on size-independent keys and ciphertexts.","prior_boundary":"GVW-style lattice circuit ABE fixed both depth and attribute dimensions at setup and provided only selective security.","significance_at_publication":"Opened the unbounded-attribute lattice line and supplied a benchmark later revisited with more black-box use of LWE machinery.","technical_delta":"Delayed trapdoor programming so attributes can be chosen after setup while retaining a leveled depth bound and strengthening security to semi-adaptive."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","keywords":["lwe","unbounded-attributes","semi-adaptive","delayed-programming"],"limitations":["not fully adaptive","key and ciphertext sizes depend on realized input length","subexponential lattice approximation factor in the stated parameterization"],"paper_id":"ABE-PAPER-2016-BV","qualifiers":["LWE-based circuit ABE","setup fixes maximum depth only","semi-adaptive security"],"source_locator":{"dossier_section":"ABE-PAPER-2016-BV § Atomic claims","primary_source":"Theorem 4.2, PDF p. 17","primary_source_url":"https://eprint.iacr.org/2016/118","status":"theorem_checked"},"statement":"Brakerski and Vaikuntanathan constructed LWE-based circuit ABE that fixes only a depth bound at setup, allows arbitrary polynomial attribute and input length, and achieves semi-adaptive security.","statement_status":"source_normalized_statement","status":"published","title":"Semi-adaptive lattice circuit ABE with unbounded attributes","work_id":"ABE-PAPER-2016-BV"},"primaryUrl":"https://eprint.iacr.org/2016/118","sections":[{"content":"Unbounded lattice ABE","heading":"Overview"},{"content":"unbounded-attribute-length-and-semi-adaptive-circuit-abe-from-lwe is the atomic contribution identifier normalized from ABE-PAPER-2016-BV. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Circuit-ABE from LWE: Unbounded Attributes and Semi-Adaptive Security","summary":"Brakerski and Vaikuntanathan constructed LWE-based circuit ABE that fixes only a depth bound at setup, allows arbitrary polynomial attribute and input length, and achieves semi-adaptive security.","title":"Semi-adaptive lattice circuit ABE with unbounded attributes","type":"result","venue":"CRYPTO 2016","year":2016,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE"},{"evidence":"published","id":"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE","keywords":["atomic-result","automation","generic-group-model","pair-encodings","abe"],"metadata":{"claim_slug":"automated-analysis-and-synthesis-of-pairing-abe","contribution_kind":"transform","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"By 2017, pairing-based ABE had many related exponent patterns, but small algebraic mistakes could invalidate security and the design space was difficult to search manually. ABGW formalized these patterns as pair encodings, supplied symbolic security criteria, and connected qualifying encodings to generic bilinear group guarantees. Their tooling could validate candidate encodings, find attacks on invalid ones, and help synthesize new constructions. This changed the research workflow rather than merely improving one parameter. It also established an important evidence boundary: a symbolic or generic-group pass proves only the stated algebraic model and does not automatically give a standard-model reduction for every generated scheme. Later work reused this intermediate-language perspective.","prior_boundary":"Pairing ABE design relied on delicate exponent relations and hand-built generic-group arguments that were hard to audit or systematically explore.","significance_at_publication":"Made mechanized exploration a first-class ABE methodology while keeping the boundary between symbolic evidence and standard-model reductions explicit.","technical_delta":"Encoded the algebraic design space symbolically and connected symbolic security conditions to generic-group security theorems."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE","keywords":["automation","generic-group-model","pair-encodings","abe"],"limitations":["does not automatically establish a standard-model reduction","applies only to the encoded algebraic class"],"paper_id":"ABE-PAPER-2017-ABGW","qualifiers":["symbolic pair encodings","generic bilinear group security","automated verification and synthesis"],"source_locator":{"dossier_section":"ABE-PAPER-2017-ABGW § Atomic claims","primary_source":"Theorems 2 and 3, PDF pp. 9 and 12, together with Lemma 2","primary_source_url":"https://eprint.iacr.org/2017/983","status":"theorem_checked"},"statement":"Ambrona, Barthe, Gay, and Wee formalized pair encodings and used symbolic tools to verify, attack, and synthesize pairing-based ABE in the algebraic and generic group setting.","statement_status":"source_normalized_statement","status":"published","title":"Automated analysis and synthesis of pairing ABE","work_id":"ABE-PAPER-2017-ABGW"},"primaryUrl":"https://eprint.iacr.org/2017/983","sections":[{"content":"Pair-encoding synthesis","heading":"Overview"},{"content":"automated-analysis-and-synthesis-of-pairing-abe is the atomic contribution identifier normalized from ABE-PAPER-2017-ABGW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption in the Generic Group Model: Automated Proofs and New Constructions","summary":"Ambrona, Barthe, Gay, and Wee formalized pair encodings and used symbolic tools to verify, attack, and synthesize pairing-based ABE in the algebraic and generic group setting.","title":"Automated analysis and synthesis of pairing ABE","type":"result","venue":"ACM CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE"},{"evidence":"published","id":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","keywords":["atomic-result","concrete-efficiency","cp-abe","pairings","implementation"],"metadata":{"claim_slug":"fast-concretely-efficient-cp-abe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Adaptive expressive CP-ABE was already feasible, but prior dual-system constructions were often too heavy to serve as a practical default. FAME targeted concrete object and operation counts, producing a compact CP-ABE for general access structures with efficient encryption and decryption. Its theorem is IND-CPA under DLIN in asymmetric pairing groups and uses a random oracle; the reduction depends on the number of key queries. The scheme's historical role is as an efficiency reference point: implementations and later constructions repeatedly compare against its small algebraic footprint. FABEO22 then asked whether comparable efficiency could be paired with adaptive multi-challenge security and tighter reductions rather than treating speed and proof quality as interchangeable.","prior_boundary":"Expressive fully secure CP-ABE existed, but its group-element counts and pairing costs left a gap between proof strength and practical deployment.","significance_at_publication":"Became a long-lived practical benchmark and motivated later work to preserve FAME-level efficiency under stronger multi-challenge security guarantees.","technical_delta":"Reduced the concrete algebraic footprint of keys, ciphertext components, and decryption while retaining general access structures."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","keywords":["concrete-efficiency","cp-abe","pairings","implementation"],"limitations":["random oracle model","reduction depends on the number of key queries"],"paper_id":"ABE-PAPER-2017-FAME","qualifiers":["fully secure CP-ABE","general access structures","DLIN","asymmetric pairing groups"],"source_locator":{"dossier_section":"ABE-PAPER-2017-FAME § Atomic claims","primary_source":"Theorem 4.1, PDF p. 9","primary_source_url":"https://eprint.iacr.org/2017/807","status":"theorem_checked"},"statement":"FAME constructed a compact and concretely efficient fully secure CP-ABE for general access structures under DLIN in asymmetric pairings and the random oracle model.","statement_status":"source_normalized_statement","status":"published","title":"FAME: compact, fast CP-ABE for general access structures","work_id":"ABE-PAPER-2017-FAME"},"primaryUrl":"https://eprint.iacr.org/2017/807","sections":[{"content":"FAME","heading":"Overview"},{"content":"fast-concretely-efficient-cp-abe is the atomic contribution identifier normalized from ABE-PAPER-2017-FAME. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"FAME: Fast Attribute-Based Message Encryption","summary":"FAME constructed a compact and concretely efficient fully secure CP-ABE for general access structures under DLIN in asymmetric pairings and the random oracle model.","title":"FAME: compact, fast CP-ABE for general access structures","type":"result","venue":"ACM CCS 2017","year":2017,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE"},{"evidence":"published","id":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS","keywords":["atomic-result","unbounded-abe","adaptive-security","entropy-expansion","pairings"],"metadata":{"claim_slug":"adaptive-unbounded-abe-with-constant-public-parameters","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"OT12 showed that adaptive security and setup-unbounded dimensions could coexist, but compact public setup remained a separate target. CGKW18 revisited bilinear entropy expansion and obtained adaptively secure unbounded KP/CP-ABE with constant-size public parameters under the MDDH family, including k-Lin. The framework also reached arithmetic span programs. “Constant public parameters” applies only to setup: keys and ciphertexts still carry the dimensions of their policies or attributes, and the result remains pairing-based. This contribution sharpened the compactness vocabulary by showing that setup size can be optimized independently of policy-bearing objects. Later work pursued constant or size-independent keys and ciphertexts, including lattice analogues under succinct assumptions.","prior_boundary":"Unbounded and adaptive ABE existed, but compact public setup and broader arithmetic policy expressivity remained separate efficiency targets.","significance_at_publication":"Advanced the pairing frontier to simultaneous adaptivity, unboundedness, and compact setup, while leaving policy-bearing objects nonconstant.","technical_delta":"Used bilinear entropy expansion to generate the proof entropy needed for late-bound policies from constant-size public parameters."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS","keywords":["unbounded-abe","adaptive-security","entropy-expansion","pairings"],"limitations":["keys and ciphertexts still scale with realized policies or attributes","pairing-based"],"paper_id":"ABE-PAPER-2018-CGKW","qualifiers":["adaptive security","setup-unbounded KP-ABE and CP-ABE","constant-size public parameters","MDDH and k-Lin family"],"source_locator":{"dossier_section":"ABE-PAPER-2018-CGKW § Atomic claims","primary_source":"Theorems 2–4, PDF pp. 31, 37, and 47","primary_source_url":"https://eprint.iacr.org/2018/116","status":"theorem_checked"},"statement":"Chen, Gong, Kowalczyk, and Wee constructed adaptively secure unbounded KP/CP-ABE with constant-size public parameters under the MDDH and k-Lin family, including arithmetic-span-program policies.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive unbounded ABE with constant public parameters","work_id":"ABE-PAPER-2018-CGKW"},"primaryUrl":"https://eprint.iacr.org/2018/116","sections":[{"content":"Constant public parameters","heading":"Overview"},{"content":"adaptive-unbounded-abe-with-constant-public-parameters is the atomic contribution identifier normalized from ABE-PAPER-2018-CGKW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Unbounded ABE via Bilinear Entropy Expansion, Revisited","summary":"Chen, Gong, Kowalczyk, and Wee constructed adaptively secure unbounded KP/CP-ABE with constant-size public parameters under the MDDH and k-Lin family, including arithmetic-span-program policies.","title":"Adaptive unbounded ABE with constant public parameters","type":"result","venue":"EUROCRYPT 2018","year":2018,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS"},{"evidence":"published","id":"ABE-RESULT-2018-CGW-IPE-ADAPTIVE-FULL-ATTRIBUTE-HIDING-IPE-FROM-K-LIN","keywords":["atomic-result","predicate-encryption","attribute-hiding","adaptive-security","pairings"],"metadata":{"claim_slug":"adaptive-full-attribute-hiding-ipe-from-k-lin","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Full attribute hiding protects more than the payload: the ciphertext's inner-product attribute is concealed subject to the predicate constraints. OT12 established a strong unbounded feasibility point, and CGW18 improved the prime-order efficiency landscape with adaptively secure constructions offering different k-Lin and XDLIN tradeoffs. The public parameters and keys are smaller than in the prior line, as recorded in the paper's comparison table. This contribution belongs to IPE rather than general ABE; it cannot be cited as a solution to arbitrary policy hiding. Its significance is to show how stronger privacy and concrete algebraic compactness can be improved together within a structured predicate family.","prior_boundary":"OT12 achieved unbounded adaptive full attribute hiding, but its object sizes left room for cleaner prime-order efficiency points.","significance_at_publication":"Set a stronger efficiency benchmark for IPE privacy, without implying hidden policies for general formula or circuit ABE.","technical_delta":"Applied improved prime-order encoding techniques to reduce key and public-parameter costs while preserving adaptive full attribute hiding."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2018-CGW-IPE-ADAPTIVE-FULL-ATTRIBUTE-HIDING-IPE-FROM-K-LIN","keywords":["predicate-encryption","attribute-hiding","adaptive-security","pairings"],"limitations":["construction variants have different k-Lin and XDLIN tradeoffs","not general policy-hiding ABE"],"paper_id":"ABE-PAPER-2018-CGW-IPE","qualifiers":["inner-product encryption","adaptive security","full attribute hiding","prime-order groups"],"source_locator":{"dossier_section":"ABE-PAPER-2018-CGW-IPE § Atomic claims","primary_source":"Sections 3.4 and 4.4; comparison in Table 1, PDF p. 2","primary_source_url":"https://eprint.iacr.org/2018/833","status":"section_checked"},"statement":"Chen, Gong, and Wee constructed adaptively secure fully attribute-hiding IPE in prime-order groups with improved public-parameter and key sizes under k-Lin and XDLIN tradeoffs.","statement_status":"source_normalized_statement","status":"published","title":"More compact adaptively attribute-hiding IPE","work_id":"ABE-PAPER-2018-CGW-IPE"},"primaryUrl":"https://eprint.iacr.org/2018/833","sections":[{"content":"Adaptive Full Attribute Hiding IPE From K Lin","heading":"Overview"},{"content":"adaptive-full-attribute-hiding-ipe-from-k-lin is the atomic contribution identifier normalized from ABE-PAPER-2018-CGW-IPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Improved Inner-Product Encryption with Adaptive Security and Full Attribute-Hiding","summary":"Chen, Gong, and Wee constructed adaptively secure fully attribute-hiding IPE in prime-order groups with improved public-parameter and key sizes under k-Lin and XDLIN tradeoffs.","title":"More compact adaptively attribute-hiding IPE","type":"result","venue":"ASIACRYPT 2018","year":2018,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2018-CGW-IPE-ADAPTIVE-FULL-ATTRIBUTE-HIDING-IPE-FROM-K-LIN"},{"evidence":"published","id":"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","keywords":["atomic-result","cca-security","generic-compiler","hinting-prg","abe"],"metadata":{"claim_slug":"black-box-cpa-to-cca-transform-for-abe-and-one-sided-pe","contribution_kind":"transform","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Most ABE constructions target CPA security, and adding a decryption oracle creates policy-dependent malleability problems that ordinary PKE transforms do not directly solve. Koppula and Waters supplied a black-box compiler using hinting PRGs, with instantiations from CDH or LWE, for ABE and one-sided PE satisfying the required perfect-correctness and randomness-decryptability conditions. The transform uses roughly 2λ base encryptions, so it does not preserve constant cryptographic arity or the best concrete efficiency points. Its durable contribution is modularity: a base policy system can be separated from the CCA wrapper. Later predicate-extension work pursued a more efficient generic specialization for pairing-based CP-ABE.","prior_boundary":"Chosen-ciphertext security for ABE was usually obtained through construction-specific modifications that did not preserve a generic underlying policy system.","significance_at_publication":"Made CCA security a reusable compiler target while exposing nonconstant overhead and correctness prerequisites for later transforms to improve.","technical_delta":"Wrapped a base ABE or one-sided PE with hinting-PRG structure, instantiated from CDH or LWE, to authenticate decryption behavior against malformed ciphertexts."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","keywords":["cca-security","generic-compiler","hinting-prg","abe"],"limitations":["requires randomness-decryptability preprocessing","about 2 lambda base encryptions","does not preserve constant cryptographic arity"],"paper_id":"ABE-PAPER-2019-KW-CCA","qualifiers":["black-box transform","perfectly correct IND-CPA ABE or one-sided PE","hinting PRG from CDH or LWE"],"source_locator":{"dossier_section":"ABE-PAPER-2019-KW-CCA § Atomic claims","primary_source":"Section 1.1, PDF pp. 2–6; construction and proof, PDF pp. 18–27","primary_source_url":"https://eprint.iacr.org/2018/847","status":"section_checked"},"statement":"Koppula and Waters gave a black-box transform from perfectly correct IND-CPA ABE or one-sided predicate encryption to CCA security using a hinting PRG.","statement_status":"source_normalized_statement","status":"published","title":"A black-box CPA-to-CCA transform for ABE","work_id":"ABE-PAPER-2019-KW-CCA"},"primaryUrl":"https://eprint.iacr.org/2018/847","sections":[{"content":"Black-box CCA transform","heading":"Overview"},{"content":"black-box-cpa-to-cca-transform-for-abe-and-one-sided-pe is the atomic contribution identifier normalized from ABE-PAPER-2019-KW-CCA. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Realizing Chosen Ciphertext Security Generically in Attribute-Based Encryption and Predicate Encryption","summary":"Koppula and Waters gave a black-box transform from perfectly correct IND-CPA ABE or one-sided predicate encryption to CCA security using a hinting PRG.","title":"A black-box CPA-to-CCA transform for ABE","type":"result","venue":"CRYPTO 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE"},{"evidence":"published","id":"ABE-RESULT-2019-KW-COMPACT-ADAPTIVE-MANY-USE-ABE-FOR-NC1","keywords":["atomic-result","adaptive-security","compactness","nc1","pairings"],"metadata":{"claim_slug":"compact-adaptive-many-use-abe-for-nc1","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"For policy ABE, saying “compact” is incomplete unless one states which side carries the policy. KW19 gave adaptively secure monotone-NC1 constructions under k-Lin with dual profiles: KP ciphertexts are linear in attribute length and independent of policy size, while the CP analogue moves the large dimension to the ciphertext and keeps the key compact. Repeated attributes are handled explicitly, and the reduction has polynomial loss. The result is many-use and adaptive, but it is not arbitrary general-circuit ABE. It provided a clean pairing benchmark for later work seeking simultaneous key and ciphertext succinctness and for lattice results that make both objects independent of input and circuit size under succinct LWE.","prior_boundary":"Adaptive expressive ABE and compact one-sided objects existed, but repeated attributes and many-use NC1 policies resisted a clean prime-order size profile.","significance_at_publication":"Established a compact adaptive NC1 benchmark and clarified the orientation-dependent trade between attribute and policy representation.","technical_delta":"Designed dual KP and CP constructions that keep the ciphertext or key independent of policy size while explicitly supporting repeated attributes."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2019-KW-COMPACT-ADAPTIVE-MANY-USE-ABE-FOR-NC1","keywords":["adaptive-security","compactness","nc1","pairings"],"limitations":["orientation-dependent compactness","linear dependence on the short input side","polynomial reduction loss","not general-circuit ABE"],"paper_id":"ABE-PAPER-2019-KW","qualifiers":["adaptive security","monotone NC1","repeated attributes","prime-order groups under k-Lin"],"source_locator":{"dossier_section":"ABE-PAPER-2019-KW § Atomic claims","primary_source":"Theorems 3 and 4, PDF pp. 26 and 34","primary_source_url":"https://eprint.iacr.org/2019/224","status":"theorem_checked"},"statement":"Kowalczyk and Wee constructed adaptively secure KP/CP-ABE for monotone NC1 under k-Lin, with each orientation linear in the short input side and independent of the opposite policy size.","statement_status":"source_normalized_statement","status":"published","title":"Compact adaptively secure ABE for NC1","work_id":"ABE-PAPER-2019-KW"},"primaryUrl":"https://eprint.iacr.org/2019/224","sections":[{"content":"Compact Adaptive Many Use ABE For Nc1","heading":"Overview"},{"content":"compact-adaptive-many-use-abe-for-nc1 is the atomic contribution identifier normalized from ABE-PAPER-2019-KW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Compact Adaptively Secure ABE for NC1 from k-Lin","summary":"Kowalczyk and Wee constructed adaptively secure KP/CP-ABE for monotone NC1 under k-Lin, with each orientation linear in the short input side and independent of the opposite policy size.","title":"Compact adaptively secure ABE for NC1","type":"result","venue":"EUROCRYPT 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2019-KW-COMPACT-ADAPTIVE-MANY-USE-ABE-FOR-NC1"},{"evidence":"published","id":"ABE-RESULT-2019-AMY-DFA-UNBOUNDED-MACHINES-INPUTS-AND-QUERIES","keywords":["atomic-result","kp-abe","cp-abe","dfa","dlin","uniform-computation"],"metadata":{"claim_slug":"unbounded-machines-inputs-and-queries","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The existence of DFA-based ABE does not by itself say when the automaton size, string length, or number of issued keys must be fixed. AMY19's second contribution is that all three quantities are unbounded in the setup sense: the public parameters need not anticipate the realized machines, inputs, or key-query count. This comes through an unbounded MSP compiler under static DLIN, with ciphertext and key costs still polynomial in the actual input and state dimensions. The result therefore improves extensibility, not asymptotic constancy. That distinction became important when HLL24 later constructed public-key lattice ABE for DFA and logspace policies and had to state its own assumption and succinctness profile.","prior_boundary":"Earlier automata ABE interfaces commonly fixed input or machine dimensions, limiting their use as a genuinely extensible policy system.","significance_at_publication":"Separated automata expressiveness from setup bounds and supplied a baseline for later public-key lattice DFA ABE.","technical_delta":"Built the DFA schemes from an unbounded MSP substrate so machines, strings, and query counts can be selected after setup."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2019-AMY-DFA-UNBOUNDED-MACHINES-INPUTS-AND-QUERIES","keywords":["kp-abe","cp-abe","dfa","dlin","uniform-computation"],"limitations":["object costs remain polynomial in realized input and state dimensions","selective-star security"],"paper_id":"ABE-PAPER-2019-AMY-DFA","qualifiers":["setup-unbounded input length","setup-unbounded automaton size","unbounded key requests"],"source_locator":{"dossier_section":"ABE-PAPER-2019-AMY-DFA § Atomic claims","primary_source":"Table 1, Section 1.2, and Theorem 7","primary_source_url":"https://eprint.iacr.org/2019/645","status":"section_checked"},"statement":"Agrawal, Maitra, and Yamada's DFA ABE supports unbounded input length, automaton size, and number of key requests without fixing those realized quantities at setup.","statement_status":"source_normalized_statement","status":"published","title":"DFA ABE with unbounded machines, inputs, and key queries","work_id":"ABE-PAPER-2019-AMY-DFA"},"primaryUrl":"https://eprint.iacr.org/2019/645","sections":[{"content":"Unbounded Machines Inputs And Queries","heading":"Overview"},{"content":"unbounded-machines-inputs-and-queries is the atomic contribution identifier normalized from ABE-PAPER-2019-AMY-DFA. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute Based Encryption for Deterministic Finite Automata from DLIN","summary":"Agrawal, Maitra, and Yamada's DFA ABE supports unbounded input length, automaton size, and number of key requests without fixing those realized quantities at setup.","title":"DFA ABE with unbounded machines, inputs, and key queries","type":"result","venue":"IACR ePrint 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2019-AMY-DFA-UNBOUNDED-MACHINES-INPUTS-AND-QUERIES"},{"evidence":"published","id":"ABE-RESULT-2019-AMY-DFA-DFA-ABE-FROM-STATIC-DLIN","keywords":["atomic-result","kp-abe","cp-abe","dfa","dlin","uniform-computation"],"metadata":{"claim_slug":"dfa-abe-from-static-dlin","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"DFA policies let authorization depend on whether a machine accepts an input string, a natural step beyond fixed formula syntax. Agrawal, Maitra, and Yamada constructed both KP and CP orientations from the static DLIN assumption by compiling an unbounded MSP-based ABE mechanism. The result is selectively-star secure in the standard model; its generic compiler has substantial polynomial costs in input and machine size, so the contribution is expressive feasibility rather than concrete optimality. It also supports late-bound machines and strings, recorded separately in the companion unboundedness card. Later lattice work reached DFA and logspace policies through noisy secret sharing and evasive IPFE, providing a post-quantum but differently assumed branch.","prior_boundary":"Automata-policy ABE either inherited bounded dimensions or relied on assumption and construction machinery less direct than static prime-order pairings.","significance_at_publication":"Established a static-assumption pairing route for regular-language policies and connected unbounded ABE to automata computation.","technical_delta":"Compiled unbounded monotone span-program ABE into DFA predicates in both policy orientations under DLIN."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2019-AMY-DFA-DFA-ABE-FROM-STATIC-DLIN","keywords":["kp-abe","cp-abe","dfa","dlin","uniform-computation"],"limitations":["generic KP compiler has cubic input-length and quadratic state-count costs"],"paper_id":"ABE-PAPER-2019-AMY-DFA","qualifiers":["KP-ABE and CP-ABE","deterministic finite automata","static DLIN","selective-star security"],"source_locator":{"dossier_section":"ABE-PAPER-2019-AMY-DFA § Atomic claims","primary_source":"Table 1, Section 1.2, and Theorem 7","primary_source_url":"https://eprint.iacr.org/2019/645","status":"theorem_checked"},"statement":"Agrawal, Maitra, and Yamada constructed KP- and CP-ABE for deterministic finite automata from the static DLIN assumption.","statement_status":"source_normalized_statement","status":"published","title":"DFA-based KP/CP-ABE from static DLIN","work_id":"ABE-PAPER-2019-AMY-DFA"},"primaryUrl":"https://eprint.iacr.org/2019/645","sections":[{"content":"Dfa ABE From Static Dlin","heading":"Overview"},{"content":"dfa-abe-from-static-dlin is the atomic contribution identifier normalized from ABE-PAPER-2019-AMY-DFA. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute Based Encryption for Deterministic Finite Automata from DLIN","summary":"Agrawal, Maitra, and Yamada constructed KP- and CP-ABE for deterministic finite automata from the static DLIN assumption.","title":"DFA-based KP/CP-ABE from static DLIN","type":"result","venue":"IACR ePrint 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2019-AMY-DFA-DFA-ABE-FROM-STATIC-DLIN"},{"evidence":"published","id":"ABE-RESULT-2019-TSABARY-FIRST-ADAPTIVE-LATTICE-ABE-BEYOND-IBE","keywords":["atomic-result","lwe","adaptive-security","t-cnf","constrained-prf"],"metadata":{"claim_slug":"first-adaptive-lattice-abe-beyond-ibe","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"By 2019, lattice ABE could express general bounded-depth circuits, but its reusable-key security was selective or semi-adaptive. Tsabary crossed the adaptive boundary for a restricted policy class: CP-ABE for t-CNF with constant t, built from decisional LWE and a matching conforming constrained PRF. The number of clauses may grow polynomially, but clause width remains fixed, so this is not fully adaptive general-circuit ABE. The result matters precisely because it separates two difficulties. Lattice assumptions can support adaptive ABE beyond IBE; the unresolved problem is extending the joint simulation to substantially richer policy classes without relying on stronger or less falsifiable mechanisms.","prior_boundary":"Lattice ABE supported general bounded-depth circuits only selectively or semi-adaptively; full adaptivity beyond identity-like predicates remained open.","significance_at_publication":"Proved that fully adaptive post-quantum ABE was feasible beyond IBE while isolating policy generality as the remaining barrier.","technical_delta":"Used a specialized constrained-PRF interface to obtain adaptive security for the restricted but nontrivial class of constant-width CNF policies."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2019-TSABARY-FIRST-ADAPTIVE-LATTICE-ABE-BEYOND-IBE","keywords":["lwe","adaptive-security","t-cnf","constrained-prf"],"limitations":["t is constant","policy class is far below general NC1 or circuits"],"paper_id":"ABE-PAPER-2019-TSABARY","qualifiers":["fully adaptive CP-ABE","constant-t CNF","decisional LWE","conforming single-key constrained PRF"],"source_locator":{"dossier_section":"ABE-PAPER-2019-TSABARY § Atomic claims","primary_source":"Lemma 4.2 and Sections 3.1 and 4, PDF pp. 12–16","primary_source_url":"https://eprint.iacr.org/2019/365","status":"theorem_checked"},"statement":"Tsabary constructed fully secure LWE-based CP-ABE for constant-t CNF policies, together with a conforming single-key constrained PRF component.","statement_status":"source_normalized_statement","status":"published","title":"Fully adaptive lattice CP-ABE for constant-t CNF policies","work_id":"ABE-PAPER-2019-TSABARY"},"primaryUrl":"https://eprint.iacr.org/2019/365","sections":[{"content":"Fully adaptive lattice CP-ABE for constant-t CNF policies","heading":"Overview"},{"content":"first-adaptive-lattice-abe-beyond-ibe is the atomic contribution identifier normalized from ABE-PAPER-2019-TSABARY. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fully Secure Attribute-Based Encryption for t-CNF from LWE","summary":"Tsabary constructed fully secure LWE-based CP-ABE for constant-t CNF policies, together with a conforming single-key constrained PRF component.","title":"Fully adaptive lattice CP-ABE for constant-t CNF policies","type":"result","venue":"CRYPTO 2019","year":2019,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2019-TSABARY-FIRST-ADAPTIVE-LATTICE-ABE-BEYOND-IBE"},{"evidence":"published","id":"ABE-RESULT-2020-LL-ADAPTIVE-ABP-ABE-WITH-ONE-CONSTANT-SIDE","keywords":["atomic-result","succinct-abe","adaptive-security","arithmetic-branching-programs","pairings"],"metadata":{"claim_slug":"adaptive-abp-abe-with-one-constant-side","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this result, adaptively secure expressive pairing ABE and compact special cases were known, but a clean constant-size side for arithmetic branching programs remained unresolved. Lin and Luo gave two distinct orientations: KP-ABE with constant-size ciphertexts and CP-ABE with constant-size secret keys, combining gradual-simulation-secure inner-product FE with arithmetic key garbling. The constant object is not the same in both schemes, and the result does not make the opposite object or setup universally constant; input and setup bounds still matter. Its publication-time significance was to turn one-sided ABP succinctness into a concrete achievable point under k-Lin-family pairing assumptions, thereby sharpening the later target of simultaneous key, ciphertext, and public-parameter succinctness.","prior_boundary":"Adaptive pairing ABE for expressive policies was known, but making the policy-independent side constant size for arithmetic branching programs remained a central succinctness target.","significance_at_publication":"The work established strong one-sided succinctness under pairing assumptions and became a clear predecessor to later questions asking for both sides, or all public and secret objects, to be short simultaneously.","technical_delta":"Separate dual constructions give constant-size ciphertexts for KP-ABE and constant-size secret keys for CP-ABE, using gradual-simulation inner-product FE and information-theoretic arithmetic key garbling."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2020-LL-ADAPTIVE-ABP-ABE-WITH-ONE-CONSTANT-SIDE","keywords":["succinct-abe","adaptive-security","arithmetic-branching-programs","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2020-LL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2020-LL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2020/1139","status":"not_normalized"},"statement":"Under k-Lin-family assumptions, the KP orientation has constant-size ciphertexts and the CP orientation has constant-size secret keys for arithmetic branching programs.","statement_status":"source_normalized_statement","status":"published","title":"Adaptively secure ABP ABE with one constant-size side","work_id":"ABE-PAPER-2020-LL"},"primaryUrl":"https://eprint.iacr.org/2020/1139","sections":[{"content":"Adaptively secure ABP ABE with one constant-size side","heading":"Overview"},{"content":"adaptive-abp-abe-with-one-constant-side is the atomic contribution identifier normalized from ABE-PAPER-2020-LL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Succinct and Adaptively Secure ABE for ABP from k-Lin","summary":"Under k-Lin-family assumptions, the KP orientation has constant-size ciphertexts and the CP orientation has constant-size secret keys for arithmetic branching programs.","title":"Adaptively secure ABP ABE with one constant-size side","type":"result","venue":"ASIACRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2020-LL-ADAPTIVE-ABP-ABE-WITH-ONE-CONSTANT-SIDE"},{"evidence":"published","id":"ABE-RESULT-2020-AT-ADAPTIVE-COMPLETELY-UNBOUNDED-FORMULA-ABE-FROM-MDDH","keywords":["atomic-result","predicate-composition","completely-unbounded","adaptive-security","mddh"],"metadata":{"claim_slug":"adaptive-completely-unbounded-formula-abe-from-mddh","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this work, pairing-based ABE could remove important setup bounds, but there was no general way to assemble an arbitrary late-bound formula from predicate components while retaining adaptive security. Attrapadung and Tomida introduced Key Encoding Indistinguishability, a composable interface that supports dynamic predicate composition, and used it to obtain monotone and non-monotone formula ABE under MDDH. Here “completely unbounded” concerns the realized composition and attribute dimensions not being fixed by setup; it does not mean that every cryptographic object is constant size. The result therefore settled an important pairing-based expressivity and setup boundary, while exposing simultaneous succinctness, cleaner post-quantum assumptions, and stronger computation models as distinct later targets.","prior_boundary":"Earlier unbounded pairing ABE removed particular setup bounds, but building a formula from an arbitrary number of predicate components while preserving adaptive security still lacked a general compositional interface.","significance_at_publication":"It closed the pairing-based feasibility question for completely unbounded formula composition, while leaving simultaneous constant-size public parameters, keys, and ciphertexts as a separate frontier.","technical_delta":"Key Encoding Indistinguishability makes predicate encodings dynamically composable and instantiates adaptively secure monotone and non-monotone formula ABE under MDDH without fixing the realized composition at setup."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2020-AT-ADAPTIVE-COMPLETELY-UNBOUNDED-FORMULA-ABE-FROM-MDDH","keywords":["predicate-composition","completely-unbounded","adaptive-security","mddh"],"limitations":[],"paper_id":"ABE-PAPER-2020-AT","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2020-AT § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2020/231","status":"not_normalized"},"statement":"Dynamic predicate composition yields adaptively secure monotone and non-monotone formula ABE without setup-time bounds on the realized formula and attribute dimensions, under MDDH.","statement_status":"source_normalized_statement","status":"published","title":"Adaptively secure, completely unbounded formula ABE from MDDH","work_id":"ABE-PAPER-2020-AT"},"primaryUrl":"https://eprint.iacr.org/2020/231","sections":[{"content":"Adaptively secure, completely unbounded formula ABE from MDDH","heading":"Overview"},{"content":"adaptive-completely-unbounded-formula-abe-from-mddh is the atomic contribution identifier normalized from ABE-PAPER-2020-AT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Unbounded Dynamic Predicate Compositions in ABE from Standard Assumptions","summary":"Dynamic predicate composition yields adaptively secure monotone and non-monotone formula ABE without setup-time bounds on the realized formula and attribute dimensions, under MDDH.","title":"Adaptively secure, completely unbounded formula ABE from MDDH","type":"result","venue":"ASIACRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2020-AT-ADAPTIVE-COMPLETELY-UNBOUNDED-FORMULA-ABE-FROM-MDDH"},{"evidence":"published","id":"ABE-RESULT-2020-AY-OPTIMAL-BROADCAST-VIA-ALL-DIMENSION-INDEPENDENT-CPABE","keywords":["atomic-result","broadcast-encryption","succinct-cpabe","pairings","lwe","ggm"],"metadata":{"claim_slug":"optimal-broadcast-via-all-dimension-independent-cpabe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier expressive CP-ABE constructions typically exposed the supported circuit size in at least one public key, user key, or ciphertext, which was incompatible with the succinct component required for optimal broadcast encryption. Agrawal and Yamada constructed a pairing/LWE CP-ABE whose three cryptographic object sizes are independent of circuit size and used it to derive optimal broadcast encryption. The independence is specifically from circuit size, not automatically from circuit input length or depth, and the decisive security argument is in the generic bilinear group model. At publication this was more than a local compression result: it demonstrated that changing the ABE size profile could unlock another primitive, and the same succinct single-input architecture later fed the multi-input ABE line.","prior_boundary":"Expressive CP-ABE normally paid for the supported policy or circuit in at least one cryptographic object, preventing its direct use as the succinct component needed for optimal broadcast encryption.","significance_at_publication":"It showed that a simultaneous parameter improvement in single-input ABE can enable a new primitive; the succinct component later became an input to the multi-input ABE route.","technical_delta":"The paper builds a hybrid pairing/LWE CP-ABE architecture with public key, secret-key, and ciphertext sizes independent of supported circuit size and uses that component to obtain optimal broadcast encryption."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2020-AY-OPTIMAL-BROADCAST-VIA-ALL-DIMENSION-INDEPENDENT-CPABE","keywords":["broadcast-encryption","succinct-cpabe","pairings","lwe","ggm"],"limitations":[],"paper_id":"ABE-PAPER-2020-AY","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2020-AY § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2020/228","status":"not_normalized"},"statement":"A CP-ABE component whose public key, secret keys, and ciphertexts are independent of supported circuit size is used to construct optimal broadcast encryption from pairings and LWE.","statement_status":"source_normalized_statement","status":"published","title":"Circuit-size-independent CP-ABE yields optimal broadcast encryption","work_id":"ABE-PAPER-2020-AY"},"primaryUrl":"https://eprint.iacr.org/2020/228","sections":[{"content":"Circuit-size-independent CP-ABE yields optimal broadcast encryption","heading":"Overview"},{"content":"optimal-broadcast-via-all-dimension-independent-cpabe is the atomic contribution identifier normalized from ABE-PAPER-2020-AY. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Optimal Broadcast Encryption from Pairings and LWE","summary":"A CP-ABE component whose public key, secret keys, and ciphertexts are independent of supported circuit size is used to construct optimal broadcast encryption from pairings and LWE.","title":"Circuit-size-independent CP-ABE yields optimal broadcast encryption","type":"result","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2020-AY-OPTIMAL-BROADCAST-VIA-ALL-DIMENSION-INDEPENDENT-CPABE"},{"evidence":"published","id":"ABE-RESULT-2020-LL-EUROCRYPT-COMPACT-ADAPTIVE-KPABE-FOR-ABPS","keywords":["atomic-result","compact-abe","arithmetic-branching-programs","adaptive-security","k-lin"],"metadata":{"claim_slug":"compact-adaptive-kpabe-for-abps","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Prior compact, adaptively secure ABE from static pairing assumptions was limited to Boolean formula policies, leaving arithmetic branching programs and uniform computation beyond the established construction boundary. Lin and Luo combined arithmetic key garbling with slotted inner-product functional encryption to obtain KP-ABE for ABPs whose ciphertext no longer scales with the ABP description, while the secret key grows linearly with it. This moved compact ABE beyond NC1 under k-Lin and also enabled separately qualified constructions for automata, L, and NL. The advance did not make every uniform-computation ciphertext constant: input length, running time, and especially space remain relevant in those extensions.","prior_boundary":"Compact adaptively secure ABE from static pairing assumptions supported Boolean-formula policies, while more expressive arithmetic branching programs and uniform logspace computations lacked a comparable construction.","significance_at_publication":"The result moved standard-assumption compact ABE beyond NC1 and opened carefully qualified extensions to automata and deterministic or nondeterministic logspace computation.","technical_delta":"Arithmetic key garbling and slotted inner-product functional encryption extend compact adaptive KP-ABE to ABPs, with ciphertexts independent of ABP size and keys linear in that size."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2020-LL-EUROCRYPT-COMPACT-ADAPTIVE-KPABE-FOR-ABPS","keywords":["compact-abe","arithmetic-branching-programs","adaptive-security","k-lin"],"limitations":["secret keys remain linear in ABP size","uniform-computation extensions retain input/time/space dependencies","setup fixes the attribute dimension"],"paper_id":"ABE-PAPER-2020-LL-EUROCRYPT","qualifiers":["KP-ABE for arithmetic branching programs","adaptive security","standard k-Lin assumption"],"source_locator":{"dossier_section":"ABE-PAPER-2020-LL-EUROCRYPT § Atomic contributions","primary_source":"Section 6.3, Construction 26 and Theorem 27; abstract for uniform-computation extensions","primary_source_url":"https://eprint.iacr.org/2020/318","status":"theorem_checked"},"statement":"Lin and Luo constructed adaptively secure KP-ABE for arithmetic branching programs from k-Lin with ciphertext size independent of the ABP description size and secret keys linear in that description size.","statement_status":"source_normalized_statement","status":"published","title":"Compact adaptively secure KP-ABE for arithmetic branching programs","work_id":"ABE-PAPER-2020-LL-EUROCRYPT"},"primaryUrl":"https://eprint.iacr.org/2020/318","sections":[{"content":"Compact ABP KP-ABE","heading":"Overview"}],"status":"published","subtitle":"Compact Adaptively Secure ABE from k-Lin: Beyond NC1 and towards NL","summary":"Lin and Luo constructed adaptively secure KP-ABE for arithmetic branching programs from k-Lin with ciphertext size independent of the ABP description size and secret keys linear in that description size.","title":"Compact adaptively secure KP-ABE for arithmetic branching programs","type":"result","venue":"EUROCRYPT 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2020-LL-EUROCRYPT-COMPACT-ADAPTIVE-KPABE-FOR-ABPS"},{"evidence":"published","id":"ABE-RESULT-2020-AY-FH-NATURAL-FULL-FUNCTION-HIDING-CIRCUIT-ABE-IMPLIES-IO","keywords":["atomic-result","function-hiding","attribute-hiding","circuit-abe","lwe","impossibility"],"metadata":{"claim_slug":"natural-full-function-hiding-circuit-abe-implies-io","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Prior attribute-hiding results for inner products and bounded-depth predicates suggested that policy privacy might extend naturally to circuit ABE. This paper showed that the straightforward endpoint is much stronger: its natural full function-hiding notion for circuit ABE implies indistinguishability obfuscation, even in the symmetric-key setting. The contribution is a boundary theorem, not a construction or an impossibility result for every useful form of policy privacy. It rules out treating full function hiding as a routine strengthening under ordinary ABE assumptions. At publication, that distinction separated an iO-level goal from more credible leakage-aware definitions, motivating later work to state exactly which policy features remain visible rather than claiming unrestricted function privacy.","prior_boundary":"Attribute-hiding inner-product and bounded-depth predicate encryption showed that useful privacy beyond payload hiding was possible, but it was unclear whether a natural circuit-policy analogue could remain substantially weaker than obfuscation.","significance_at_publication":"The implication turned full circuit-policy hiding into an explicit hardness boundary and redirected plausible work toward carefully stated leakage profiles or weakened notions.","technical_delta":"The paper formalizes a natural full function-hiding circuit-ABE notion and proves that realizing it already implies indistinguishability obfuscation, even when encryption uses a symmetric master secret."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2020-AY-FH-NATURAL-FULL-FUNCTION-HIDING-CIRCUIT-ABE-IMPLIES-IO","keywords":["function-hiding","attribute-hiding","circuit-abe","lwe","impossibility"],"limitations":[],"paper_id":"ABE-PAPER-2020-AY-FH","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2020-AY-FH § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2020/1432","status":"not_normalized"},"statement":"Agrawal and Yamada prove that their natural full function-hiding notion for circuit ABE implies indistinguishability obfuscation, even for symmetric-key ABE.","statement_status":"source_normalized_statement","status":"published","title":"Natural full function-hiding circuit ABE implies iO","work_id":"ABE-PAPER-2020-AY-FH"},"primaryUrl":"https://eprint.iacr.org/2020/1432","sections":[{"content":"Natural full function-hiding circuit ABE implies iO","heading":"Overview"},{"content":"natural-full-function-hiding-circuit-abe-implies-io is the atomic contribution identifier normalized from ABE-PAPER-2020-AY-FH. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"CP-ABE for Circuits (and more) in the Symmetric Key Setting","summary":"Agrawal and Yamada prove that their natural full function-hiding notion for circuit ABE implies indistinguishability obfuscation, even for symmetric-key ABE.","title":"Natural full function-hiding circuit ABE implies iO","type":"result","venue":"TCC 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2020-AY-FH-NATURAL-FULL-FUNCTION-HIDING-CIRCUIT-ABE-IMPLIES-IO"},{"evidence":"published","id":"ABE-RESULT-2020-AY-FH-WEAKENED-FUNCTION-HIDING-PE-FROM-LWE","keywords":["atomic-result","function-hiding","attribute-hiding","circuit-abe","lwe","impossibility"],"metadata":{"claim_slug":"weakened-function-hiding-pe-from-lwe","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The same work that exposes the iO barrier also asks what privacy remains constructible below it. The authors define a weaker function-hiding notion and instantiate it in both KP- and CP-oriented predicate-encryption forms from subexponential LWE. This is not ordinary public-key, fully function-hiding circuit ABE from plain LWE: the positive result changes the security definition, and its assumption is stronger than standard polynomial-hardness LWE. Its importance at publication was conceptual as well as constructive. It showed that the iO implication applies to a particular natural endpoint rather than every useful privacy profile, and established that future claims must expose the exact leakage and challenge game instead of using “function hiding” as an undifferentiated label.","prior_boundary":"The natural full function-hiding definition for circuit ABE crosses an iO boundary, while visible-policy ABE reveals more than many applications need; a constructible intermediate definition was missing.","significance_at_publication":"It demonstrated that the boundary theorem does not eliminate all meaningful policy privacy, but also made the definition and assumption strength part of the claim rather than interchangeable details.","technical_delta":"The paper weakens the privacy experiment so that it no longer triggers the stated iO implication and constructs KP- and CP-oriented predicate-encryption variants from subexponential LWE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2020-AY-FH-WEAKENED-FUNCTION-HIDING-PE-FROM-LWE","keywords":["function-hiding","attribute-hiding","circuit-abe","lwe","impossibility"],"limitations":[],"paper_id":"ABE-PAPER-2020-AY-FH","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2020-AY-FH § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2020/1432","status":"not_normalized"},"statement":"A weakened function-hiding definition avoids the paper's iO implication and is instantiated for KP and CP orientations from subexponential LWE.","statement_status":"source_normalized_statement","status":"published","title":"Weakened function-hiding predicate encryption from LWE","work_id":"ABE-PAPER-2020-AY-FH"},"primaryUrl":"https://eprint.iacr.org/2020/1432","sections":[{"content":"Weakened function-hiding predicate encryption from LWE","heading":"Overview"},{"content":"weakened-function-hiding-pe-from-lwe is the atomic contribution identifier normalized from ABE-PAPER-2020-AY-FH. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"CP-ABE for Circuits (and more) in the Symmetric Key Setting","summary":"A weakened function-hiding definition avoids the paper's iO implication and is instantiated for KP and CP orientations from subexponential LWE.","title":"Weakened function-hiding predicate encryption from LWE","type":"result","venue":"TCC 2020","year":2020,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2020-AY-FH-WEAKENED-FUNCTION-HIDING-PE-FROM-LWE"},{"evidence":"published","id":"ABE-RESULT-2021-GLW-ADAPTIVE-ABE-FROM-SEARCH-BDH-VIA-DELETION","keywords":["atomic-result","adaptive-security","deletion","search-assumptions","pairings"],"metadata":{"claim_slug":"adaptive-abe-from-search-bdh-via-deletion","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this work, the main route to adaptive ABE relied on directly programming dual-system modes. Goyal, Liu, and Waters changed the API instead: attributes can be deleted, and a deletion-conforming constrained PRF ensures that information incompatible with the eventual challenge no longer remains available. Combining that interface with selectively secure deletion KP-ABE yields adaptively secure subset ABE from Search BDH. The result is not a generic adaptive compiler for arbitrary ABE policies; its concrete endpoint is the subset functionality and its security relies on the paper's deletion model. At publication it provided a genuine alternative to dual systems and suggested that adaptivity may come from controlling persistent state, while leaving expressive and post-quantum versions open.","prior_boundary":"Adaptive ABE was dominated by direct dual-system programming, while restricted pairing constructions under search assumptions did not yet have a general mechanism for handling post-challenge information.","significance_at_publication":"It established a distinct route to adaptivity from Search BDH for subset functionality, but did not extend the compiler to general expressive policies or provide a post-quantum instantiation.","technical_delta":"The work adds an attribute-deletion interface and combines it with a deletion-conforming constrained PRF, so the simulator can erase precisely the state that would conflict with an adaptive challenge."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2021-GLW-ADAPTIVE-ABE-FROM-SEARCH-BDH-VIA-DELETION","keywords":["adaptive-security","deletion","search-assumptions","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2021-GLW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2021-GLW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2021/343","status":"not_normalized"},"statement":"Deletable attributes and deletion-conforming constrained PRFs compile selectively secure deletion KP-ABE into adaptively secure subset ABE from Search BDH.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive subset ABE from Search BDH via attribute deletion","work_id":"ABE-PAPER-2021-GLW"},"primaryUrl":"https://eprint.iacr.org/2021/343","sections":[{"content":"Adaptive subset ABE from Search BDH via attribute deletion","heading":"Overview"},{"content":"adaptive-abe-from-search-bdh-via-deletion is the atomic contribution identifier normalized from ABE-PAPER-2021-GLW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Adaptive Security via Deletion in Attribute-Based Encryption: Solutions from Search Assumptions in Bilinear Groups","summary":"Deletable attributes and deletion-conforming constrained PRFs compile selectively secure deletion KP-ABE into adaptively secure subset ABE from Search BDH.","title":"Adaptive subset ABE from Search BDH via attribute deletion","type":"result","venue":"ASIACRYPT 2021","year":2021,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2021-GLW-ADAPTIVE-ABE-FROM-SEARCH-BDH-VIA-DELETION"},{"evidence":"published","id":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","keywords":["atomic-result","multi-authority","lwe","dnf","random-oracle"],"metadata":{"claim_slug":"first-decentralized-maabe-from-lwe","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Decentralized multi-authority ABE previously had a mature pairing-based blueprint, but no lattice construction preserving its no-central-issuer model. Datta, Komargodski, and Waters supplied that missing branch for DNF policies and an unbounded number of authorities, using a direct noisy-LSSS approach from subexponential-ratio LWE in the random-oracle model. The theorem is statically secure: it does not cover authorities corrupted adaptively during the system lifetime, and DNF is not general circuit or MSP expressivity. At publication the result established that decentralized MA-ABE was not inherently tied to pairings. It also cleanly exposed the remaining work—broader policies, adaptive corruptions, polynomial-ratio LWE, and removal of the random oracle—which later papers address only along selected axes.","prior_boundary":"Decentralized MA-ABE was established in bilinear groups, but the same no-central-issuer authority model had no lattice construction, especially one avoiding a generic universal-circuit conversion.","significance_at_publication":"It opened the post-quantum-candidate MA-ABE branch while making policy class, corruption timing, random-oracle use, and LWE parameters explicit residual axes rather than solved features.","technical_delta":"The paper gives a direct lattice MA-ABE for DNF policies with an unbounded number of authorities, using subexponential-ratio LWE and a random oracle; its security is static."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","keywords":["multi-authority","lwe","dnf","random-oracle"],"limitations":[],"paper_id":"ABE-PAPER-2021-DKW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2021-DKW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2020/1386","status":"not_normalized"},"statement":"A statically secure decentralized multi-authority ABE for DNF policies supports an unbounded number of authorities from subexponential-ratio LWE in the random-oracle model.","statement_status":"source_normalized_statement","status":"published","title":"First decentralized MA-ABE for DNF policies from LWE","work_id":"ABE-PAPER-2021-DKW"},"primaryUrl":"https://eprint.iacr.org/2020/1386","sections":[{"content":"First decentralized MA-ABE for DNF policies from LWE","heading":"Overview"},{"content":"first-decentralized-maabe-from-lwe is the atomic contribution identifier normalized from ABE-PAPER-2021-DKW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Decentralized Multi-Authority ABE for DNFs from LWE","summary":"A statically secure decentralized multi-authority ABE for DNF policies supports an unbounded number of authorities from subexponential-ratio LWE in the random-oracle model.","title":"First decentralized MA-ABE for DNF policies from LWE","type":"result","venue":"EUROCRYPT 2021","year":2021,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE"},{"evidence":"published","id":"ABE-RESULT-2022-VA-GLUE-GENERALIZED-UNBOUNDED-EXPRESSIVE-ABE","keywords":["atomic-result","cp-abe","pairing","unbounded","non-monotone","online-offline"],"metadata":{"claim_slug":"generalized-unbounded-expressive-abe","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"By 2022, pairing-based unbounded ABE was a feasibility result rather than an open question, but the literature contained several constructions whose shared polynomial structure and label-reuse behavior were difficult to compare. GLUE extracts a generalized large-universe CP-ABE family that is completely unbounded in its setup interface, supports repeated attributes and labels, and admits non-monotone extensions. This contribution is distinct from GLUE's efficiency tradeoff: it identifies the common expressive and reuse-capable construction framework, while the partition parameters choose a cost point within it. At publication the framework made earlier schemes legible as related instances and broadened the available policy semantics, without implying constant-size objects or a single efficiency point that is optimal for every workload.","prior_boundary":"Existing unbounded CP-ABE results removed setup bounds under differing polynomial encodings, but repeated labels, non-monotone extensions, and a unified construction interface were not captured together.","significance_at_publication":"It unified several construction patterns without collapsing their concrete tradeoffs, making reuse semantics and policy extensions first-class comparison coordinates.","technical_delta":"GLUE factors the shared polynomial mechanism into one completely unbounded large-universe family with explicit attribute/label reuse and extensions to non-monotone policies."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-VA-GLUE-GENERALIZED-UNBOUNDED-EXPRESSIVE-ABE","keywords":["cp-abe","pairing","unbounded","non-monotone","online-offline"],"limitations":[],"paper_id":"ABE-PAPER-2022-VA-GLUE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-VA-GLUE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/613","status":"not_normalized"},"statement":"GLUE gives a completely unbounded, large-universe CP-ABE family that supports attribute and label reuse and admits non-monotone extensions.","statement_status":"source_normalized_statement","status":"published","title":"Completely unbounded large-universe CP-ABE with reusable labels","work_id":"ABE-PAPER-2022-VA-GLUE"},"primaryUrl":"https://eprint.iacr.org/2022/613","sections":[{"content":"Completely unbounded large-universe CP-ABE with reusable labels","heading":"Overview"},{"content":"generalized-unbounded-expressive-abe is the atomic contribution identifier normalized from ABE-PAPER-2022-VA-GLUE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"GLUE: Generalizing Unbounded Attribute-Based Encryption for Flexible Efficiency Trade-Offs","summary":"GLUE gives a completely unbounded, large-universe CP-ABE family that supports attribute and label reuse and admits non-monotone extensions.","title":"Completely unbounded large-universe CP-ABE with reusable labels","type":"result","venue":"IACR ePrint 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-VA-GLUE-GENERALIZED-UNBOUNDED-EXPRESSIVE-ABE"},{"evidence":"published","id":"ABE-RESULT-2022-VA-GLUE-FLEXIBLE-ENCRYPTION-DECRYPTION-TRADEOFF","keywords":["atomic-result","cp-abe","pairing","unbounded","non-monotone","online-offline"],"metadata":{"claim_slug":"flexible-encryption-decryption-tradeoff","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier completely unbounded CP-ABE constructions appeared as separate schemes with fixed cost profiles, even when their algebra reflected a common polynomial structure. GLUE makes that structure explicit through partition parameters n_k and n_c, allowing a deployer to trade encryption and ciphertext work against decryption and key work while accounting for label reuse. The contribution is therefore not a new security notion or a claim that one setting dominates every predecessor; its central object is the configurable efficiency surface. Online/offline key-generation and encryption variants extend that surface to latency-sensitive settings. At publication this made concrete comparison more faithful: workloads and repeated-label distributions determine the useful point, so reporting a single “GLUE cost” would hide the paper's main design contribution.","prior_boundary":"Unbounded CP-ABE schemes were usually presented as isolated fixed parameter points, obscuring the common polynomial structure and the cost of repeated labels in a concrete application.","significance_at_publication":"It reframed efficiency as an application-dependent Pareto choice and supplied online/offline variants, rather than claiming one universally optimal scalar benchmark.","technical_delta":"GLUE parameterizes the shared construction structure by key-side and ciphertext-side partitions, making encryption/decryption costs and object sizes an explicit configurable surface."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-VA-GLUE-FLEXIBLE-ENCRYPTION-DECRYPTION-TRADEOFF","keywords":["cp-abe","pairing","unbounded","non-monotone","online-offline"],"limitations":[],"paper_id":"ABE-PAPER-2022-VA-GLUE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-VA-GLUE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/613","status":"not_normalized"},"statement":"GLUE exposes partition parameters n_k and n_c that continuously trade encryption work and ciphertext structure against decryption and key costs within one completely unbounded CP-ABE family.","statement_status":"source_normalized_statement","status":"published","title":"Configurable encryption–decryption tradeoffs in unbounded CP-ABE","work_id":"ABE-PAPER-2022-VA-GLUE"},"primaryUrl":"https://eprint.iacr.org/2022/613","sections":[{"content":"Configurable encryption–decryption tradeoffs in unbounded CP-ABE","heading":"Overview"},{"content":"flexible-encryption-decryption-tradeoff is the atomic contribution identifier normalized from ABE-PAPER-2022-VA-GLUE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"GLUE: Generalizing Unbounded Attribute-Based Encryption for Flexible Efficiency Trade-Offs","summary":"GLUE exposes partition parameters n_k and n_c that continuously trade encryption work and ciphertext structure against decryption and key costs within one completely unbounded CP-ABE family.","title":"Configurable encryption–decryption tradeoffs in unbounded CP-ABE","type":"result","venue":"IACR ePrint 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-VA-GLUE-FLEXIBLE-ENCRYPTION-DECRYPTION-TRADEOFF"},{"evidence":"published","id":"ABE-RESULT-2022-LLL-CONSTANT-SIZE-CIRCUIT-KPABE-KEYS","keywords":["atomic-result","circuit-abe","succinctness","lattices","pairings"],"metadata":{"claim_slug":"constant-size-circuit-kpabe-keys","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier circuit ABE either carried circuit-size or depth information in user keys, while one-sided succinct pairing results covered more restricted computation models. Li, Lin, and Luo gave circuit KP-ABE whose secret key is three group elements, hence poly(lambda) and independent of circuit size. The ciphertext still grows with the attribute vector and maximum supported depth, so “constant-size key” does not mean a fully size-independent ABE system. The plain-LWE theorem is selective in the generic pairing-group model; the adaptive variant replaces LWE with adaptive LWE. At publication this resolved a sharply stated key-size problem and clarified the remaining simultaneous-succinctness target that later constructions attack on both key and ciphertext sides.","prior_boundary":"Lattice circuit ABE had reduced key dependence from circuit size to depth, and pairing ABP schemes achieved one-sided succinctness, but constant secret keys for general circuit KP-ABE remained open.","significance_at_publication":"It answered the constant-key question for this API but did not solve simultaneous key/ciphertext succinctness or remove the generic-pairing and adaptive-LWE qualifiers.","technical_delta":"The construction gives circuit KP-ABE with three-group-element secret keys of size poly(lambda), while leaving attribute-length and setup-depth dependence in the ciphertext side."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-LLL-CONSTANT-SIZE-CIRCUIT-KPABE-KEYS","keywords":["circuit-abe","succinctness","lattices","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2022-LLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-LLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/659","status":"not_normalized"},"statement":"Circuit KP-ABE secret keys contain three group elements and have size poly(lambda), independent of circuit size; ciphertexts still depend on attribute length and the maximum depth.","statement_status":"source_normalized_statement","status":"published","title":"Constant-size secret keys for circuit KP-ABE","work_id":"ABE-PAPER-2022-LLL"},"primaryUrl":"https://eprint.iacr.org/2022/659","sections":[{"content":"Constant-size secret keys for circuit KP-ABE","heading":"Overview"},{"content":"constant-size-circuit-kpabe-keys is the atomic contribution identifier normalized from ABE-PAPER-2022-LLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"ABE for Circuits with Constant-Size Secret Keys and Adaptive Security","summary":"Circuit KP-ABE secret keys contain three group elements and have size poly(lambda), independent of circuit size; ciphertexts still depend on attribute length and the maximum depth.","title":"Constant-size secret keys for circuit KP-ABE","type":"result","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-LLL-CONSTANT-SIZE-CIRCUIT-KPABE-KEYS"},{"evidence":"published","id":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY","keywords":["atomic-result","concrete-efficiency","adaptive-security","multi-challenge","ggm","random-oracle"],"metadata":{"claim_slug":"fame-level-efficiency-with-adaptive-multi-challenge-security","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"FAME had made fully secure pairing-based CP-ABE concretely attractive, but efficiency, attribute multi-use, multi-challenge security, and reduction quality did not yet coincide at one benchmark point. FABEO combines the fast hash-to-group and randomness-reuse line with multi-use design ideas, reduces ciphertext and key costs, and proves adaptive multi-challenge security with tight or near-tight bounds for its variants. The guarantee is explicitly in the generic bilinear group plus random-oracle model, and the exact reduction loss depends on the chosen variant and query counts. Its significance at publication was therefore concrete rather than merely asymptotic: it became a FAME-level implementation target with a stronger security profile, while preserving a clear open question about matching it in the standard model under a falsifiable assumption.","prior_boundary":"FAME established an influential concrete-efficiency point, while nearby generic-group constructions offered stronger multi-use or security analyses with less favorable object sizes or runtimes.","significance_at_publication":"It became the relevant concrete pairing benchmark for efficient KP/CP-ABE, while leaving comparable efficiency under a falsifiable static assumption in the standard model unresolved.","technical_delta":"FABEO combines the fast hash-and-randomness-reuse architecture with multi-use attributes, smaller objects, and adaptive multi-challenge security whose generic-group bounds are tight or near-tight."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY","keywords":["concrete-efficiency","adaptive-security","multi-challenge","ggm","random-oracle"],"limitations":[],"paper_id":"ABE-PAPER-2022-FABEO","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-FABEO § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1415","status":"not_normalized"},"statement":"FABEO combines FAME-like compact pairing operations with adaptive multi-challenge KP/CP-ABE security and tight or near-tight reductions in the generic bilinear group and random-oracle models.","statement_status":"source_normalized_statement","status":"published","title":"FAME-level efficiency with adaptive multi-challenge security","work_id":"ABE-PAPER-2022-FABEO"},"primaryUrl":"https://eprint.iacr.org/2022/1415","sections":[{"content":"FAME-level efficiency with adaptive multi-challenge security","heading":"Overview"},{"content":"fame-level-efficiency-with-adaptive-multi-challenge-security is the atomic contribution identifier normalized from ABE-PAPER-2022-FABEO. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"FABEO: Fast Attribute-Based Encryption with Optimal Security","summary":"FABEO combines FAME-like compact pairing operations with adaptive multi-challenge KP/CP-ABE security and tight or near-tight reductions in the generic bilinear group and random-oracle models.","title":"FAME-level efficiency with adaptive multi-challenge security","type":"result","venue":"ACM CCS 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY"},{"evidence":"published","id":"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS","keywords":["atomic-result","multi-input-abe","predicate-encryption","witness-encryption","nc1"],"metadata":{"claim_slug":"initiated-miabe-and-gave-two-input-nc1-constructions","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Standard ABE evaluates a policy against one encrypted attribute input, so simply placing several ciphertexts side by side did not define a secure multi-input primitive. Agrawal, Yadav, and Yamada formalized multi-input ABE and predicate encryption against unbounded collusions and built the first two-input KP-ABE for NC1. Their main construction combines LWE with pairings in the generic group model; a standard-model alternative uses a knowledge assumption. The paper also identifies a compiler connection from succinct single-input CP-ABE. At publication this created a new research axis—input arity—rather than merely extending ordinary ABE syntax. Later work extends the endpoint to every fixed constant arity, but this contribution itself is specifically two-input and does not provide polynomial or unbounded arity.","prior_boundary":"Ordinary ABE binds one ciphertext input to one policy evaluation; a reusable encryption primitive whose decryption jointly depends on multiple independently encrypted inputs had no established ABE definition and NC1 construction.","significance_at_publication":"It opened a separate arity frontier and a route toward witness encryption, while leaving constant or polynomial arity and clean post-quantum assumptions unresolved.","technical_delta":"The work formalizes multi-input ABE/PE and constructs two-input KP-ABE for NC1 with unbounded collusion, connecting succinct single-input CP-ABE to the new multi-input primitive."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS","keywords":["multi-input-abe","predicate-encryption","witness-encryption","nc1"],"limitations":[],"paper_id":"ABE-PAPER-2022-AYY-MIABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-AYY-MIABE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1024","status":"not_normalized"},"statement":"The first two-input KP-ABE for NC1 is secure against unbounded collusions and is constructed from LWE with pairings in the generic group model.","statement_status":"source_normalized_statement","status":"published","title":"First two-input KP-ABE for NC1 with unbounded collusions","work_id":"ABE-PAPER-2022-AYY-MIABE"},"primaryUrl":"https://eprint.iacr.org/2022/1024","sections":[{"content":"First two-input KP-ABE for NC1 with unbounded collusions","heading":"Overview"},{"content":"initiated-miabe-and-gave-two-input-nc1-constructions is the atomic contribution identifier normalized from ABE-PAPER-2022-AYY-MIABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Multi-Input Attribute Based Encryption and Predicate Encryption","summary":"The first two-input KP-ABE for NC1 is secure against unbounded collusions and is constructed from LWE with pairings in the generic group model.","title":"First two-input KP-ABE for NC1 with unbounded collusions","type":"result","venue":"CRYPTO 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS"},{"evidence":"published","id":"ABE-RESULT-2022-LLL-DOUBLE-SUCCINCT-FORMULA-CPABE","keywords":["atomic-result","circuit-abe","succinctness","lattices","pairings"],"metadata":{"claim_slug":"double-succinct-formula-cpabe","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"One-sided succinct ABE had shown that either a key or a ciphertext could be constant for expressive restricted models, but making both objects short at once remained a central gap. Li, Lin, and Luo constructed formula CP-ABE in which secret keys and ciphertexts are constant with respect to the policy formula size. The objects can still depend on attribute length, so the result is “double succinct” along a specific coordinate rather than independent of every input and setup dimension. As with the companion circuit-KP result, the security theorem is selective from LWE in the generic pairing-group model, with adaptivity requiring adaptive LWE. At publication it provided a concrete simultaneous-succinctness milestone and sharpened the subsequent all-object, input-independent target.","prior_boundary":"Prior expressive ABE results could make one policy-bearing side constant, but obtaining succinct secret keys and ciphertexts together for formula policies remained unresolved.","significance_at_publication":"It established a double-succinct formula endpoint and separated formula-size independence from the stronger goal of input-size-independent objects and succinct public parameters.","technical_delta":"The CP construction makes both secret keys and ciphertexts independent of the policy-formula size, although their sizes can still depend on the attribute length and setup parameters."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-LLL-DOUBLE-SUCCINCT-FORMULA-CPABE","keywords":["circuit-abe","succinctness","lattices","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2022-LLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-LLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/659","status":"not_normalized"},"statement":"Formula CP-ABE has constant-size secret keys and ciphertexts independent of the policy-formula size, while both may still depend on the attribute length.","statement_status":"source_normalized_statement","status":"published","title":"Formula CP-ABE with both succinct keys and ciphertexts","work_id":"ABE-PAPER-2022-LLL"},"primaryUrl":"https://eprint.iacr.org/2022/659","sections":[{"content":"Formula CP-ABE with both succinct keys and ciphertexts","heading":"Overview"},{"content":"double-succinct-formula-cpabe is the atomic contribution identifier normalized from ABE-PAPER-2022-LLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"ABE for Circuits with Constant-Size Secret Keys and Adaptive Security","summary":"Formula CP-ABE has constant-size secret keys and ciphertexts independent of the policy-formula size, while both may still depend on the attribute length.","title":"Formula CP-ABE with both succinct keys and ciphertexts","type":"result","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-LLL-DOUBLE-SUCCINCT-FORMULA-CPABE"},{"evidence":"published","id":"ABE-RESULT-2022-WWW-MAABE-PLAIN-MODEL-MAABE-FOR-SUBSET-POLICIES","keywords":["atomic-result","multi-authority","lattices","standard-model"],"metadata":{"claim_slug":"plain-model-maabe-for-subset-policies","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The 2021 lattice MA-ABE construction established post-quantum-candidate feasibility but retained a random oracle and a restricted policy family. Waters, Wee, and Wu removed the random oracle for subset-style policies by using evasive LWE and a related-trapdoor framework. Their companion branch reaches polynomial-ratio plain LWE only in the random-oracle model and with an a priori attribute/policy-length bound. These are separate theorem points, not interchangeable qualifiers of one construction. At publication the plain-model branch showed that lattice MA-ABE need not inherently depend on a random oracle, while also revealing the cost of that removal in the assumption. General circuits or MSPs, adaptive authority corruption, and a plain-LWE standard-model realization remained outside the result.","prior_boundary":"The first lattice decentralized MA-ABE supported DNF policies from subexponential-ratio LWE but still used a random oracle, leaving a clean standard-model construction unresolved.","significance_at_publication":"The result removed the random oracle only by changing the assumption, making assumption quality, setup bounds, and policy expressivity separate frontier coordinates.","technical_delta":"Waters, Wee, and Wu give a plain-model lattice MA-ABE for subset-style policies from evasive LWE, plus a distinct random-oracle construction from polynomial-ratio plain LWE with a priori length bounds."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2022-WWW-MAABE-PLAIN-MODEL-MAABE-FOR-SUBSET-POLICIES","keywords":["multi-authority","lattices","standard-model"],"limitations":[],"paper_id":"ABE-PAPER-2022-WWW-MAABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2022-WWW-MAABE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1194","status":"not_normalized"},"statement":"Waters, Wee, and Wu give lattice multi-authority ABE for setup-unbounded subset policies from evasive LWE without a random oracle.","statement_status":"source_normalized_statement","status":"published","title":"Plain-model lattice MA-ABE for subset policies","work_id":"ABE-PAPER-2022-WWW-MAABE"},"primaryUrl":"https://eprint.iacr.org/2022/1194","sections":[{"content":"Plain-model lattice MA-ABE for subset policies","heading":"Overview"},{"content":"plain-model-maabe-for-subset-policies is the atomic contribution identifier normalized from ABE-PAPER-2022-WWW-MAABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Multi-Authority ABE from Lattices without Random Oracles","summary":"Waters, Wee, and Wu give lattice multi-authority ABE for setup-unbounded subset policies from evasive LWE without a random oracle.","title":"Plain-model lattice MA-ABE for subset policies","type":"result","venue":"TCC 2022","year":2022,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2022-WWW-MAABE-PLAIN-MODEL-MAABE-FOR-SUBSET-POLICIES"},{"evidence":"published","id":"ABE-RESULT-2023-JLL-CONSTANT-KEY-CIPHERTEXT-ABE","keywords":["atomic-result","ram","phfe","succinctness","lower-bounds"],"metadata":{"claim_slug":"constant-key-ciphertext-abe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Prior ABE succinctness results could make one object constant or remove dependence on a formula-size coordinate, but a general construction with both constant-size keys and ciphertexts remained elusive. Jain, Lin, and Luo obtained this endpoint as a corollary of their nearly optimal partially hiding FE for RAM: the ABE key and ciphertext are poly(lambda), while decryption performs the function and input work required by the model. The construction inherits the PHFE public-input convention and ultimately uses general FE for circuits, so it is not a direct ABE from plain LWE or pairings. At publication it established that simultaneous constant objects are feasible when computation time carries the unavoidable dependence, clarifying rather than eliminating the frontier for direct constructions under cleaner assumptions.","prior_boundary":"Earlier succinct ABE made one side constant or removed dependence on a formula coordinate, but constant-size keys and ciphertexts together for the paper's general PHFE-derived API had not been achieved.","significance_at_publication":"It reached a simultaneous two-object optimum in the PHFE-derived setting, but relied on general FE for circuits rather than a direct plain-LWE or pairing construction.","technical_delta":"Specializing nearly optimal RAM PHFE gives ABE whose key and ciphertext sizes are poly(lambda), while decryption retains the function/input work required by the model's space-time lower bounds."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-JLL-CONSTANT-KEY-CIPHERTEXT-ABE","keywords":["ram","phfe","succinctness","lower-bounds"],"limitations":[],"paper_id":"ABE-PAPER-2023-JLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-JLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1317","status":"not_normalized"},"statement":"Jain, Lin, and Luo's nearly optimal RAM PHFE implies ABE with both secret keys and ciphertexts of size poly(lambda), together with decryption time matching the stated lower-bound tradeoff.","statement_status":"source_normalized_statement","status":"published","title":"ABE with constant-size keys and ciphertexts from RAM PHFE","work_id":"ABE-PAPER-2023-JLL"},"primaryUrl":"https://eprint.iacr.org/2022/1317","sections":[{"content":"ABE with constant-size keys and ciphertexts from RAM PHFE","heading":"Overview"},{"content":"constant-key-ciphertext-abe is the atomic contribution identifier normalized from ABE-PAPER-2023-JLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"On the Optimal Succinctness and Efficiency of Functional Encryption and Attribute-Based Encryption","summary":"Jain, Lin, and Luo's nearly optimal RAM PHFE implies ABE with both secret keys and ciphertexts of size poly(lambda), together with decryption time matching the stated lower-bound tradeoff.","title":"ABE with constant-size keys and ciphertexts from RAM PHFE","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-JLL-CONSTANT-KEY-CIPHERTEXT-ABE"},{"evidence":"published","id":"ABE-RESULT-2023-ZZGQ-REGPE-GENERIC-REGISTERED-ABE-FROM-PREDICATE-ENCODINGS","keywords":["atomic-result","registered-abe","predicate-encodings","prime-order-pairings","mddh","qa-nizk"],"metadata":{"claim_slug":"generic-registered-abe-from-predicate-encodings","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The original registered-ABE construction demonstrated the trust model but did not expose a general way to reuse the mature predicate-encoding toolkit. Zhu, Zhang, Gong, and Qian supplied that interface: a predicate encoding is compiled black-box into slotted registered ABE in prime-order bilinear groups, with MDDH security and a QA-NIZK whose stronger unbounded simulation soundness handles malicious registered keys. The powers-of-two transformation then lifts the slotted object to the paper's full registered interface. The setup still fixes a slot bound L, the generic CRS is quadratic in L, and public keys require verification. At publication the compiler made registered ABE modular across predicates, without solving transparent unbounded registration or general adaptive corruption.","prior_boundary":"Registered ABE had a concrete pairing blueprint, but lacked a reusable interface that could transfer the large catalog of predicate encodings into the registration setting.","significance_at_publication":"It made predicate encodings a modular source of registered schemes, while retaining a fixed slot bound, slot-dependent CRS, and explicit verification requirements.","technical_delta":"The paper gives a black-box compiler from predicate encodings to slotted registered ABE, adding public-key verification through a QA-NIZK and invoking the prior powers-of-two transformation for the full interface."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-ZZGQ-REGPE-GENERIC-REGISTERED-ABE-FROM-PREDICATE-ENCODINGS","keywords":["registered-abe","predicate-encodings","prime-order-pairings","mddh","qa-nizk"],"limitations":[],"paper_id":"ABE-PAPER-2023-ZZGQ-REGPE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-ZZGQ-REGPE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/1383","status":"not_normalized"},"statement":"A predicate encoding, MDDH, and a QA-NIZK with the required unbounded simulation soundness compile black-box into slotted registered ABE in prime-order bilinear groups.","statement_status":"source_normalized_statement","status":"published","title":"Black-box registered ABE compiler from predicate encodings","work_id":"ABE-PAPER-2023-ZZGQ-REGPE"},"primaryUrl":"https://eprint.iacr.org/2023/1383","sections":[{"content":"Black-box registered ABE compiler from predicate encodings","heading":"Overview"},{"content":"generic-registered-abe-from-predicate-encodings is the atomic contribution identifier normalized from ABE-PAPER-2023-ZZGQ-REGPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Registered ABE via Predicate Encodings","summary":"A predicate encoding, MDDH, and a QA-NIZK with the required unbounded simulation soundness compile black-box into slotted registered ABE in prime-order bilinear groups.","title":"Black-box registered ABE compiler from predicate encodings","type":"result","venue":"ASIACRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-ZZGQ-REGPE-GENERIC-REGISTERED-ABE-FROM-PREDICATE-ENCODINGS"},{"evidence":"published","id":"ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE","keywords":["atomic-result","multi-input-abe","evasive-lwe","tensor-lwe","post-quantum-candidate"],"metadata":{"claim_slug":"constant-arity-miabe-for-nc1-from-evasive-lwe","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"AYY22 established NC1 multi-input ABE only for two ciphertext inputs and used a hybrid LWE/pairing construction in the generic group model. Agrawal, Rossi, Yadav, and Yamada extended the functionality to every fixed constant arity and replaced that pairing component with a lattice route based on LWE and evasive LWE. Their stronger P-level construction additionally invokes tensor or extended tensor LWE and should not be merged into the NC1 claim. At publication this corrected the idea that two inputs were the current endpoint and created a post-quantum-candidate constant-arity line. It still does not provide arity growing polynomially with the security parameter, and reuse of the proof must account for the revised ePrint's correction to Lemma 3.4.","prior_boundary":"The first NC1 multi-input ABE supported two inputs and combined LWE with pairings in the generic group model, leaving both larger arity and a lattice-only route open.","significance_at_publication":"It removed the arity-two and pairing/GGM boundaries for constant arity, while leaving polynomial or unbounded arity and reduction to plain LWE as distinct unresolved goals.","technical_delta":"ARYY gives NC1 MIABE for every fixed constant number of inputs from LWE and evasive LWE; stronger tensor-LWE variants separately extend the supported computation to P."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE","keywords":["multi-input-abe","evasive-lwe","tensor-lwe","post-quantum-candidate"],"limitations":[],"paper_id":"ABE-PAPER-2023-ARYY","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-ARYY § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/941","status":"not_normalized"},"statement":"For every fixed constant arity, the paper constructs multi-input ABE for NC1 from LWE and evasive LWE, removing the earlier pairing/GGM component.","statement_status":"source_normalized_statement","status":"published","title":"Constant-arity MIABE for NC1 from evasive LWE","work_id":"ABE-PAPER-2023-ARYY"},"primaryUrl":"https://eprint.iacr.org/2023/941","sections":[{"content":"Constant-arity MIABE for NC1 from evasive LWE","heading":"Overview"},{"content":"constant-arity-miabe-for-nc1-from-evasive-lwe is the atomic contribution identifier normalized from ABE-PAPER-2023-ARYY. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWE","summary":"For every fixed constant arity, the paper constructs multi-input ABE for NC1 from LWE and evasive LWE, removing the earlier pairing/GGM component.","title":"Constant-arity MIABE for NC1 from evasive LWE","type":"result","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE"},{"evidence":"published","id":"ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION","keywords":["atomic-result","multi-authority","adaptive-corruption","pairings","random-oracle"],"metadata":{"claim_slug":"first-maabe-secure-under-adaptive-authority-corruption","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier decentralized MA-ABE removed a central issuer, but its proofs fixed authority corruptions or key-query structure too early to model a system attacked adaptively over time. Datta, Komargodski, and Waters introduced a model in which authority corruptions and user-key queries occur adaptively and gave the first constructions meeting it. The realizations use either composite-order subgroup assumptions or prime-order MDDH-style assumptions, and both rely on a random oracle. This adaptivity concerns the multi-authority corruption and query interface; it should not be silently transferred to a lattice or registered-ABE setting. At publication the result closed a major trust-model gap, while leaving post-quantum assumptions, standard-model security, efficiency, and transparent user-generated registration as independent open dimensions.","prior_boundary":"Decentralized MA-ABE distributed key issuance, including a lattice branch, but its security did not allow authorities and key queries to be selected adaptively throughout the system lifetime.","significance_at_publication":"It closed the unqualified adaptive-corruption question for decentralized MA-ABE, shifting the frontier to assumption/model quality, post-quantum security, efficiency, and combination with registration.","technical_delta":"The paper defines and realizes adaptive authority corruption together with adaptive key queries, using composite- and prime-order pairing variants that both retain a random oracle."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION","keywords":["multi-authority","adaptive-corruption","pairings","random-oracle"],"limitations":[],"paper_id":"ABE-PAPER-2023-DKW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-DKW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1311","status":"not_normalized"},"statement":"The first decentralized MA-ABE security model and constructions allowing authority corruptions and user-key queries to occur adaptively are realized in pairing groups with a random oracle.","statement_status":"source_normalized_statement","status":"published","title":"Decentralized MA-ABE with adaptive authority corruption","work_id":"ABE-PAPER-2023-DKW"},"primaryUrl":"https://eprint.iacr.org/2022/1311","sections":[{"content":"Decentralized MA-ABE with adaptive authority corruption","heading":"Overview"},{"content":"first-maabe-secure-under-adaptive-authority-corruption is the atomic contribution identifier normalized from ABE-PAPER-2023-DKW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Fully Adaptive Decentralized Multi-Authority ABE","summary":"The first decentralized MA-ABE security model and constructions allowing authority corruptions and user-key queries to occur adaptively are realized in pairing groups with a random oracle.","title":"Decentralized MA-ABE with adaptive authority corruption","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION"},{"evidence":"published","id":"ABE-RESULT-2023-HLL-CONSTANT-SIZE-GARBLING","keywords":["atomic-result","unbounded-depth","circular-lwe","evasive-lwe"],"metadata":{"claim_slug":"constant-size-garbling","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this work, reusable garbling, laconic functional evaluation, and one-key FE/ABE inherited a predetermined circuit-depth parameter, while the only known way around that dependence used iO. Hsieh, Lin, and Luo applied circular-security techniques to unbounded-depth and unbounded-size circuits and obtained reusable garbling whose garbled circuit and function digest are constant with respect to circuit parameters for Boolean outputs. Input encodings remain linear in input length, and the result belongs to the one-key/reusable-garbling branch rather than full collusion-resistant ABE. At publication it was the first constant-size garbled-circuit result without iO and supplied a compact mechanism that helped explain how circularity can remove depth dependence, while leaving stronger multi-key security to a separate theorem and stronger assumption.","prior_boundary":"Reusable garbling and related one-key functional primitives retained polynomial dependence on a predetermined circuit-depth bound; removing that dependence was known only through iO-based approaches.","significance_at_publication":"It supplied the first constant-size garbled circuits without iO and provided a one-key mechanism adjacent to, but weaker than, the paper's full collusion-resistant ABE result.","technical_delta":"Circular-security techniques produce reusable garbling for unbounded-depth and unbounded-size circuits whose garbled circuit and function digest are constant in circuit parameters for Boolean outputs."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-HLL-CONSTANT-SIZE-GARBLING","keywords":["unbounded-depth","circular-lwe","evasive-lwe"],"limitations":[],"paper_id":"ABE-PAPER-2023-HLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-HLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/1716","status":"not_normalized"},"statement":"Under a circular-security assumption, reusable garbling for Boolean-output circuits has garbled-circuit and function-digest sizes independent of circuit depth and size, without using iO.","statement_status":"source_normalized_statement","status":"published","title":"First constant-size reusable garbled circuits without iO","work_id":"ABE-PAPER-2023-HLL"},"primaryUrl":"https://eprint.iacr.org/2023/1716","sections":[{"content":"First constant-size reusable garbled circuits without iO","heading":"Overview"},{"content":"constant-size-garbling is the atomic contribution identifier normalized from ABE-PAPER-2023-HLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Circuits of Unbounded Depth from Lattices","summary":"Under a circular-security assumption, reusable garbling for Boolean-output circuits has garbled-circuit and function-digest sizes independent of circuit depth and size, without using iO.","title":"First constant-size reusable garbled circuits without iO","type":"result","venue":"FOCS 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-HLL-CONSTANT-SIZE-GARBLING"},{"evidence":"published","id":"ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE","keywords":["atomic-result","unbounded-depth","circular-lwe","evasive-lwe"],"metadata":{"claim_slug":"unbounded-depth-abe","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Since the first lattice circuit-ABE constructions, setup had fixed a maximum circuit depth and key, ciphertext, or public parameters grew with that level, much like leveled homomorphic encryption. Hsieh, Lin, and Luo used an evasive circular LWE assumption to construct full collusion-resistant ABE for circuits whose depth and size are not predetermined, with constant-size secret keys. “Unbounded depth” does not imply adaptive security: the detailed full-ABE theorem is very selective, and input-length costs remain. At publication this was the first conditional removal of the decade-old depth boundary for reusable ABE. The evasive-circular assumption was later reported broken, so the contribution remains historically important but not a safe-assumption endpoint for current construction work.","prior_boundary":"Lattice circuit ABE had remained leveled for a decade: setup fixed a maximum depth, and cryptographic object sizes grew polynomially with that bound.","significance_at_publication":"It conditionally removed the setup-depth boundary for full ABE, but the detailed theorem is very selective and the underlying evasive-circular assumption was later reported broken.","technical_delta":"The construction supports full collusion-resistant ABE for circuits of unbounded depth and size under evasive circular LWE, with secret keys independent of circuit parameters."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE","keywords":["unbounded-depth","circular-lwe","evasive-lwe"],"limitations":[],"paper_id":"ABE-PAPER-2023-HLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-HLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/1716","status":"not_normalized"},"statement":"Evasive circular LWE yields full collusion-resistant ABE for circuits whose depth and size are not predetermined at setup, with constant-size secret keys.","statement_status":"source_normalized_statement","status":"published","title":"Full ABE for circuits of unbounded depth and size","work_id":"ABE-PAPER-2023-HLL"},"primaryUrl":"https://eprint.iacr.org/2023/1716","sections":[{"content":"Full ABE for circuits of unbounded depth and size","heading":"Overview"},{"content":"unbounded-depth-abe is the atomic contribution identifier normalized from ABE-PAPER-2023-HLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute-Based Encryption for Circuits of Unbounded Depth from Lattices","summary":"Evasive circular LWE yields full collusion-resistant ABE for circuits whose depth and size are not predetermined at setup, with constant-size secret keys.","title":"Full ABE for circuits of unbounded depth and size","type":"result","venue":"FOCS 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE"},{"evidence":"published","id":"ABE-RESULT-2023-JLL-RAM-PHFE-FROM-FE","keywords":["atomic-result","ram","phfe","succinctness","lower-bounds"],"metadata":{"claim_slug":"ram-phfe-from-fe","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier FE and ABE constructions evaluated circuit descriptions, so their cost did not naturally track the instance-sensitive running time of a RAM program. Jain, Lin, and Luo constructed the first partially hiding FE for RAM solely from FE for circuits. Function keys are poly(lambda), ciphertexts have rate two in the private input and are independent of the public-input length, and decryption is linear in the instance RAM time plus the function and input descriptions, up to security factors. This is a PHFE result with a public/private input split, not an ordinary ABE theorem by itself. At publication it provided the technical engine for constant-key, constant-ciphertext ABE and showed how near-optimal space can coexist with the computation time that the paper's lower bounds require.","prior_boundary":"Functional-encryption evaluation was usually expressed through circuits, making ciphertext/key succinctness and evaluation time difficult to align with the instance-sensitive efficiency of random-access computation.","significance_at_publication":"It supplied the computational engine behind the paper's constant-object ABE corollary and nearly matched the accompanying unconditional space-time limits.","technical_delta":"The construction builds PHFE directly for RAM from FE for circuits, with constant keys, ciphertext length 2|y|+poly(lambda), independent of public input length, and near-linear instance running time."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-JLL-RAM-PHFE-FROM-FE","keywords":["ram","phfe","succinctness","lower-bounds"],"limitations":[],"paper_id":"ABE-PAPER-2023-JLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-JLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1317","status":"not_normalized"},"statement":"FE for circuits suffices for the first PHFE for RAM with constant-size function keys, rate-2 ciphertexts in the private input, and decryption linear in the instance RAM time plus description lengths.","statement_status":"source_normalized_statement","status":"published","title":"Nearly optimal partially hiding FE for RAM from circuit FE","work_id":"ABE-PAPER-2023-JLL"},"primaryUrl":"https://eprint.iacr.org/2022/1317","sections":[{"content":"Nearly optimal partially hiding FE for RAM from circuit FE","heading":"Overview"},{"content":"ram-phfe-from-fe is the atomic contribution identifier normalized from ABE-PAPER-2023-JLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"On the Optimal Succinctness and Efficiency of Functional Encryption and Attribute-Based Encryption","summary":"FE for circuits suffices for the first PHFE for RAM with constant-size function keys, rate-2 ciphertexts in the private input, and decryption linear in the instance RAM time plus description lengths.","title":"Nearly optimal partially hiding FE for RAM from circuit FE","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-JLL-RAM-PHFE-FROM-FE"},{"evidence":"published","id":"ABE-RESULT-2023-ZZGQ-REGPE-PRIME-ORDER-REGISTERED-ABE","keywords":["atomic-result","registered-abe","predicate-encodings","prime-order-pairings","mddh","qa-nizk"],"metadata":{"claim_slug":"prime-order-registered-abe","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Registered ABE initially offered a trustless issuance model but only a narrow set of concrete policy realizations. Applying their generic compiler, Zhu, Zhang, Gong, and Qian obtained prime-order registered ABE for read-once span programs, zero inner product, and read-once arithmetic span programs capturing arithmetic branching programs. These are concrete instantiations, distinct from the compiler theorem itself. The span and arithmetic encodings are read-once, the zero-inner-product scheme does not automatically inherit nearby attribute-hiding guarantees, and every instance retains the slotted setup, public-key verification, MDDH, and QA-NIZK requirements. At publication the result expanded registered ABE beyond its initial formula construction and established the first registered ABP point, without providing general circuits or unbounded transparent registration.","prior_boundary":"Registered ABE was known from the original construction, but prime-order realizations for span programs and zero inner product and any registered ABP instantiation were absent.","significance_at_publication":"It broadened the concrete prime-order registered-policy catalog, subject to the compiler's bounded-slot CRS, verification, MDDH, and QA-NIZK conditions.","technical_delta":"Concrete predicate encodings instantiate the generic compiler for read-once span programs, zero inner product, and read-once arithmetic span programs that capture arithmetic branching programs."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-ZZGQ-REGPE-PRIME-ORDER-REGISTERED-ABE","keywords":["registered-abe","predicate-encodings","prime-order-pairings","mddh","qa-nizk"],"limitations":[],"paper_id":"ABE-PAPER-2023-ZZGQ-REGPE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-ZZGQ-REGPE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/1383","status":"not_normalized"},"statement":"Instantiating the predicate-encoding compiler gives prime-order registered ABE for read-once span programs, zero inner product, and read-once arithmetic span programs capturing ABPs.","statement_status":"source_normalized_statement","status":"published","title":"Prime-order registered ABE for span, inner-product, and ABP predicates","work_id":"ABE-PAPER-2023-ZZGQ-REGPE"},"primaryUrl":"https://eprint.iacr.org/2023/1383","sections":[{"content":"Prime-order registered ABE for span, inner-product, and ABP predicates","heading":"Overview"},{"content":"prime-order-registered-abe is the atomic contribution identifier normalized from ABE-PAPER-2023-ZZGQ-REGPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Registered ABE via Predicate Encodings","summary":"Instantiating the predicate-encoding compiler gives prime-order registered ABE for read-once span programs, zero inner product, and read-once arithmetic span programs capturing ABPs.","title":"Prime-order registered ABE for span, inner-product, and ABP predicates","type":"result","venue":"ASIACRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-ZZGQ-REGPE-PRIME-ORDER-REGISTERED-ABE"},{"evidence":"published","id":"ABE-RESULT-2023-FWW-REGISTERED-ABE-FROM-PLAIN-WITNESS-ENCRYPTION-AND-LWE","keywords":["atomic-result","witness-encryption","registered-abe","function-binding-hash","trustless"],"metadata":{"claim_slug":"registered-abe-from-plain-witness-encryption-and-lwe","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Registered ABE had just supplied a transparent alternative to trusted key issuance, but its concrete pairing construction fixed the user population and carried a large CRS, while earlier general feasibility arguments used indistinguishability obfuscation. Freitag, Waters, and Wu introduced function-binding hashes and used them with plain witness encryption and LWE to obtain general-policy registered ABE with transparent setup and an arbitrary number of users. The standard-model theorem is policy-selective and excludes corruptions; Appendix C adds corruptions only in the random-oracle model and remains policy-selective. At publication this created a qualitatively new unbounded-user trustless route, but witness encryption for NP remains a strong primitive and the result is neither adaptively secure nor a concretely efficient direct construction.","prior_boundary":"The original registered-ABE blueprint used a bounded user population and a setup whose pairing CRS grew quadratically in that bound; earlier broad trustless feasibility routes relied on iO.","significance_at_publication":"It replaced an iO-only feasibility route with plain witness encryption and exposed an unbounded-user branch, but did not supply adaptive security, a simple falsifiable assumption, or concrete efficiency.","technical_delta":"Function-binding hashes let plain witness encryption and LWE realize general-policy registered ABE with transparent setup and no fixed user bound; corruptions are added only in a policy-selective ROM variant."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-FWW-REGISTERED-ABE-FROM-PLAIN-WITNESS-ENCRYPTION-AND-LWE","keywords":["witness-encryption","registered-abe","function-binding-hash","trustless"],"limitations":[],"paper_id":"ABE-PAPER-2023-FWW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-FWW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/812","status":"not_normalized"},"statement":"Plain witness encryption for NP together with LWE yields registered ABE for general policies, transparent setup, and arbitrarily many users, with policy-selective standard-model security without corruptions.","statement_status":"source_normalized_statement","status":"published","title":"Registered ABE from plain witness encryption and LWE","work_id":"ABE-PAPER-2023-FWW"},"primaryUrl":"https://eprint.iacr.org/2023/812","sections":[{"content":"Registered ABE from plain witness encryption and LWE","heading":"Overview"},{"content":"registered-abe-from-plain-witness-encryption-and-lwe is the atomic contribution identifier normalized from ABE-PAPER-2023-FWW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and More","summary":"Plain witness encryption for NP together with LWE yields registered ABE for general policies, transparent setup, and arbitrarily many users, with policy-selective standard-model security without corruptions.","title":"Registered ABE from plain witness encryption and LWE","type":"result","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-FWW-REGISTERED-ABE-FROM-PLAIN-WITNESS-ENCRYPTION-AND-LWE"},{"evidence":"published","id":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","keywords":["atomic-result","registered-abe","trustless","key-curator","pairings"],"metadata":{"claim_slug":"introduced-registered-abe-with-transparent-curation","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Multi-authority ABE distributed trust among issuers but did not remove the fact that an authority generates user decryption material. Hohenberger, Lu, Waters, and Wu introduced registered ABE: each user generates a public and secret key, registers the public key with attributes, and a deterministic transparent curator aggregates registrations into the ABE master public key. The concrete pairing construction supports LSSS/MSP policies for a bounded user population. Its CRS grows quadratically in that bound and linearly with the attribute universe. At publication the new API separated transparent aggregation from secret key issuance and opened a trustless ABE research program. It should not be conflated with decentralized MA-ABE, where multiple authorities still issue keys for their domains.","prior_boundary":"Conventional and multi-authority ABE still entrusted authorities with issuing long-term user decryption keys, so distributing issuers did not remove key escrow or malicious key-generation risk.","significance_at_publication":"It created a new trustless ABE API distinct from decentralized MA-ABE; the concrete pairing scheme still fixed the user bound and had a CRS quadratic in users and linear in the universe size.","technical_delta":"Registered ABE lets users generate their own key pairs and replaces secret issuance with deterministic public-key/attribute registration and transparent aggregation by a curator."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","keywords":["registered-abe","trustless","key-curator","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2023-HLWW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-HLWW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1500","status":"not_normalized"},"statement":"Users generate their own keys and register public keys plus attributes with a deterministic transparent curator, which aggregates them into a master public key for ABE decryption.","statement_status":"source_normalized_statement","status":"published","title":"Registered ABE with deterministic transparent curation","work_id":"ABE-PAPER-2023-HLWW"},"primaryUrl":"https://eprint.iacr.org/2022/1500","sections":[{"content":"Registered ABE with deterministic transparent curation","heading":"Overview"},{"content":"introduced-registered-abe-with-transparent-curation is the atomic contribution identifier normalized from ABE-PAPER-2023-HLWW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Registered Attribute-Based Encryption","summary":"Users generate their own keys and register public keys plus attributes with a deterministic transparent curator, which aggregates them into a master public key for ABE decryption.","title":"Registered ABE with deterministic transparent curation","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION"},{"evidence":"published","id":"ABE-RESULT-2023-JLL-SPACE-TIME-LOWER-BOUNDS","keywords":["atomic-result","ram","phfe","succinctness","lower-bounds"],"metadata":{"claim_slug":"space-time-lower-bounds","contribution_kind":"boundary_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"ABE and FE succinctness was frequently discussed object by object, leaving unclear whether function or input dependence could disappear everywhere at once. Jain, Lin, and Luo proved unconditional space-time tradeoffs for their partially hiding FE model: a function key and decryption time cannot both be sublinear in the function description, and a ciphertext and decryption time cannot both be sublinear in the public-input length. The lower bounds already hold for very weak secret-key, one-key, one-ciphertext selective settings. Their scope is nevertheless the stated PHFE API and public-input convention; they do not prove that every direct ABE construction is impossible. At publication the results converted vague “fully succinct and fast” ambitions into explicit Pareto constraints and explained why the companion RAM construction moves unavoidable dependence into evaluation time.","prior_boundary":"Succinctness goals often asked to shrink keys or ciphertexts without specifying where the removed function or public-input dependence must reappear in evaluation time.","significance_at_publication":"The bounds supplied a principled efficiency frontier for PHFE-derived ABE, while not excluding every ABE API or direct construction outside the stated public-input model.","technical_delta":"The paper proves unconditional tradeoffs ruling out simultaneous sublinear key/decryption dependence on function size and simultaneous sublinear ciphertext/decryption dependence on public-input size, even for weak PHFE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2023-JLL-SPACE-TIME-LOWER-BOUNDS","keywords":["ram","phfe","succinctness","lower-bounds"],"limitations":[],"paper_id":"ABE-PAPER-2023-JLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2023-JLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2022/1317","status":"not_normalized"},"statement":"In the stated PHFE model, key size and decryption time cannot both be sublinear in function size, and ciphertext size and decryption time cannot both be sublinear in public-input size.","statement_status":"source_normalized_statement","status":"published","title":"Unconditional space–time lower bounds for PHFE","work_id":"ABE-PAPER-2023-JLL"},"primaryUrl":"https://eprint.iacr.org/2022/1317","sections":[{"content":"Unconditional space–time lower bounds for PHFE","heading":"Overview"},{"content":"space-time-lower-bounds is the atomic contribution identifier normalized from ABE-PAPER-2023-JLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"On the Optimal Succinctness and Efficiency of Functional Encryption and Attribute-Based Encryption","summary":"In the stated PHFE model, key size and decryption time cannot both be sublinear in function size, and ciphertext size and decryption time cannot both be sublinear in public-input size.","title":"Unconditional space–time lower bounds for PHFE","type":"result","venue":"EUROCRYPT 2023","year":2023,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2023-JLL-SPACE-TIME-LOWER-BOUNDS"},{"evidence":"published","id":"ABE-RESULT-2024-WW-ADAPTIVE-ABE-FROM-WITNESS-ENCRYPTION","keywords":["atomic-result","adaptive-security","witness-encryption","compiler","third-route"],"metadata":{"claim_slug":"adaptive-abe-from-witness-encryption","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"For broad policy classes, adaptive ABE had largely followed dual-system encryption or the much stronger iO route, while deletion-based adaptivity covered a restricted functionality. Waters and Wichs instead encode the simulator's adaptive choice into a witness-encryption statement, combined with statistically sound NIZKs, statistically binding commitments, and one-way functions. This yields a generic adaptively secure ABE construction. Candidate witness encryption from evasive LWE gives a corresponding candidate post-quantum instantiation, but the result does not reduce general-circuit adaptive ABE to plain LWE or provide the optimal size profile. At publication it established a third conceptual route to adaptivity and made “which NP statement enables delayed programming?” a concrete component question rather than another variant of direct dual-system simulation.","prior_boundary":"Broad adaptive ABE was obtained mainly through dual-system encryption or iO-based constructions; the deletion route demonstrated an alternative only for restricted subset functionality.","significance_at_publication":"It established a third broad conceptual route to adaptive ABE and a candidate post-quantum path through evasive-LWE witness encryption, but not adaptive general-circuit ABE from plain LWE.","technical_delta":"Waters and Wichs move adaptive programming into a witness-encryption/NIZK statement, giving a general compiler from witness encryption and basic proof/commitment primitives to adaptive ABE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-WW-ADAPTIVE-ABE-FROM-WITNESS-ENCRYPTION","keywords":["adaptive-security","witness-encryption","compiler","third-route"],"limitations":[],"paper_id":"ABE-PAPER-2024-WW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-WW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2024/1486","status":"not_normalized"},"statement":"Witness encryption for NP, statistically sound NIZKs, statistically binding commitments, and one-way functions generically yield adaptively secure ABE.","statement_status":"source_normalized_statement","status":"published","title":"Adaptively secure ABE from witness encryption","work_id":"ABE-PAPER-2024-WW"},"primaryUrl":"https://eprint.iacr.org/2024/1486","sections":[{"content":"Adaptively secure ABE from witness encryption","heading":"Overview"},{"content":"adaptive-abe-from-witness-encryption is the atomic contribution identifier normalized from ABE-PAPER-2024-WW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Adaptively Secure Attribute-Based Encryption from Witness Encryption","summary":"Witness encryption for NP, statistically sound NIZKs, statistically binding commitments, and one-way functions generically yield adaptively secure ABE.","title":"Adaptively secure ABE from witness encryption","type":"result","venue":"TCC 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-WW-ADAPTIVE-ABE-FROM-WITNESS-ENCRYPTION"},{"evidence":"published","id":"ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE","keywords":["atomic-result","unbounded-abe","circuits","plain-lwe","semi-adaptive"],"metadata":{"claim_slug":"unbounded-attribute-circuit-abe-from-lwe","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Brakerski–Vaikuntanathan had shown that lattice circuit ABE could accept attribute vectors whose realized length was not fixed at setup, but their construction used non-black-box homomorphic-PRF machinery. Cini and Wee revisit that endpoint with black-box access to the cryptographic and lattice algorithms, retaining semi-adaptive security against unbounded collusions from plain LWE and bringing costs close to the bounded-depth BGGPS baseline. “Unbounded” here is strictly attribute length: setup still fixes the maximum circuit depth, and encryption and ciphertext size scale with the realized input length. At publication the work simplified a central lattice route and removed a non-black-box obstacle, while leaving full adaptivity, depth unboundedness, and almost-optimal object sizes as separate goals.","prior_boundary":"BV16 obtained semi-adaptive LWE circuit ABE with setup-unbounded attribute length, but relied on non-black-box homomorphic-PRF machinery and retained a substantial gap from the bounded-depth baseline.","significance_at_publication":"It made the unbounded-attribute lattice route cleaner and near the bounded baseline, but did not remove the setup-time depth bound or achieve full adaptive security and all-object succinctness.","technical_delta":"Cini and Wee preserve unbounded attribute length and semi-adaptive security from plain LWE while replacing the non-black-box component with a simpler black-box construction."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE","keywords":["unbounded-abe","circuits","plain-lwe","semi-adaptive"],"limitations":[],"paper_id":"ABE-PAPER-2024-CW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-CW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2024/1507","status":"not_normalized"},"statement":"A black-box lattice construction gives semi-adaptively secure circuit ABE for attribute vectors of setup-unbounded length and unbounded collusions from plain LWE, while setup still fixes circuit depth.","statement_status":"source_normalized_statement","status":"published","title":"Black-box unbounded-attribute circuit ABE from plain LWE","work_id":"ABE-PAPER-2024-CW"},"primaryUrl":"https://eprint.iacr.org/2024/1507","sections":[{"content":"Black-box unbounded-attribute circuit ABE from plain LWE","heading":"Overview"},{"content":"unbounded-attribute-circuit-abe-from-lwe is the atomic contribution identifier normalized from ABE-PAPER-2024-CW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Unbounded ABE for Circuits from LWE, Revisited","summary":"A black-box lattice construction gives semi-adaptively secure circuit ABE for attribute vectors of setup-unbounded length and unbounded collusions from plain LWE, while setup still fixes circuit depth.","title":"Black-box unbounded-attribute circuit ABE from plain LWE","type":"result","venue":"ASIACRYPT 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE"},{"evidence":"published","id":"ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER","keywords":["atomic-result","cca","predicate-encryption","pair-encodings","compiler"],"metadata":{"claim_slug":"predicate-extension-cpa-to-cca-compiler","contribution_kind":"transform","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Generic CCA security for ABE existed, but the earlier black-box route used roughly 2lambda base encryptions and did not preserve the compact structure of modern pairing schemes. Venema and Botros introduce predicate extension: one coordinated attribute is added to key and ciphertext predicates so that established CCA techniques apply across predicate encryption. Specializing the interface to pair and predicate encodings yields the paper's most efficient generic CCA conversion for pairing-based CP-ABE. The efficiency claim is framework-specific; it does not prove constant overhead, tightness, or post-quantum preservation for lattice, succinct, or registered ABE endpoints. At publication the work converted CCA hardening from an ABE-specific wrapper into a predicate-level transformation and sharply reduced overhead in its intended pairing setting.","prior_boundary":"Earlier black-box ABE CPA-to-CCA conversion used many base encryptions and did not preserve the compact algebra of efficient pairing-based predicate-encoding schemes.","significance_at_publication":"It gave the most efficient generic pairing-based CP-ABE conversion claimed by the paper, without establishing constant-overhead or post-quantum preservation for lattice or registered ABE.","technical_delta":"Predicate extension augments both sides of the predicate by one attribute, enabling generic CCA transformations and a specialized low-overhead compiler for pair/predicate encodings."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER","keywords":["cca","predicate-encryption","pair-encodings","compiler"],"limitations":[],"paper_id":"ABE-PAPER-2024-VB-CCA","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-VB-CCA § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2023/1947","status":"not_normalized"},"statement":"Adding one coordinated attribute to key and ciphertext predicates makes generic CCA techniques apply to predicate encryption and yields a low-overhead pairing-based CP-ABE specialization.","statement_status":"source_normalized_statement","status":"published","title":"CPA-to-CCA predicate-encryption compiler via predicate extension","work_id":"ABE-PAPER-2024-VB-CCA"},"primaryUrl":"https://eprint.iacr.org/2023/1947","sections":[{"content":"CPA-to-CCA predicate-encryption compiler via predicate extension","heading":"Overview"},{"content":"predicate-extension-cpa-to-cca-compiler is the atomic contribution identifier normalized from ABE-PAPER-2024-VB-CCA. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Using Predicate Extension for Predicate Encryption to Generically Obtain Chosen-Ciphertext Security and Signatures","summary":"Adding one coordinated attribute to key and ciphertext predicates makes generic CCA techniques apply to predicate encryption and yields a low-overhead pairing-based CP-ABE specialization.","title":"CPA-to-CCA predicate-encryption compiler via predicate extension","type":"result","venue":"IACR Communications in Cryptology 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER"},{"evidence":"published","id":"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE","keywords":["atomic-result","succinct-lwe","circuit-abe","short-keys","short-ciphertexts"],"metadata":{"claim_slug":"circuit-abe-with-key-and-ciphertext-independent-of-input-and-circuit-size","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier succinct ABE results made one side constant or removed dependence on formula size, but circuit size and input length still appeared across keys and ciphertexts. Wee constructed circuit ABE in which both object sizes are poly(depth, lambda), independent of policy-circuit size and attribute/input length, with a complementary tradeoff on the public-parameter side. The theorem is selectively secure under succinct LWE, not fully adaptive from plain polynomial-ratio LWE, and depth remains an explicit parameter. At publication this closed a central two-object succinctness gap rather than every compactness goal. The construction became the explicit starting point for the 2025 work that recursively compresses the remaining public-parameter dependence and reaches an all-three almost-optimal profile.","prior_boundary":"Constant-key and double-succinct ABE removed selected size dependencies, but no lattice circuit-ABE point made both keys and ciphertexts independent of circuit size and input length together.","significance_at_publication":"It closed a major two-object succinctness gap and became the direct starting point for the later all-three almost-optimal construction, while relying on succinct LWE and selective security.","technical_delta":"Wee's construction compresses both objects to poly(depth, lambda), leaving neither circuit size nor attribute-input length in keys or ciphertexts and exposing a complementary public-parameter tradeoff."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE","keywords":["succinct-lwe","circuit-abe","short-keys","short-ciphertexts"],"limitations":[],"paper_id":"ABE-PAPER-2024-WEE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-WEE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2024/1416","status":"not_normalized"},"statement":"From succinct LWE, circuit ABE has secret-key and ciphertext sizes poly(depth, lambda), independent of the circuit size and attribute-input length, under selective security.","statement_status":"source_normalized_statement","status":"published","title":"Circuit ABE with input- and circuit-size-independent keys and ciphertexts","work_id":"ABE-PAPER-2024-WEE"},"primaryUrl":"https://eprint.iacr.org/2024/1416","sections":[{"content":"Circuit ABE with input- and circuit-size-independent keys and ciphertexts","heading":"Overview"},{"content":"circuit-abe-with-key-and-ciphertext-independent-of-input-and-circuit-size is the atomic contribution identifier normalized from ABE-PAPER-2024-WEE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Circuit ABE with poly(depth, lambda)-sized Ciphertexts and Keys from Lattices","summary":"From succinct LWE, circuit ABE has secret-key and ciphertext sizes poly(depth, lambda), independent of the circuit size and attribute-input length, under selective security.","title":"Circuit ABE with input- and circuit-size-independent keys and ciphertexts","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE"},{"evidence":"published","id":"ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-NL","keywords":["atomic-result","turing-machines","uniform-computation","lattices"],"metadata":{"claim_slug":"lattice-abe-for-nl","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this work, lattice ABE had progressed from bounded circuits to automata and unbounded-depth circuit models, but those interfaces did not directly let an encryptor and key holder supply unbounded Turing-machine descriptions with a running-time bound chosen after setup. The NL branch constructs collusion-resistant ABE for that uniform-computation setting from LWE, evasive LWE, and tensor LWE, with decryption time tied to the particular machine, input, and chosen time bound. At publication, this was an important intermediate point between circuit ABE and ABE for arbitrary Turing machines. It should be kept separate from the paper's stronger all-machine result, which additionally assumes circular tensor LWE.","prior_boundary":"Lattice ABE had reached bounded circuits, automata, and unbounded-depth circuit models, but did not directly expose a uniform Turing-machine interface with descriptions and running time chosen after setup.","significance_at_publication":"Moves lattice ABE from nonuniform circuit descriptions toward uniform computation for the NL class without invoking the circular tensor-LWE assumption needed by the paper's all-Turing-machine branch.","technical_delta":"Constructs the NL branch of Turing-machine ABE using LWE together with evasive and tensor-LWE variants, while allowing unbounded descriptions and a dynamically selected time bound."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-NL","keywords":["turing-machines","uniform-computation","lattices"],"limitations":[],"paper_id":"ABE-PAPER-2025-AMY-TM","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-AMY-TM § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/001","status":"not_normalized"},"statement":"Collusion-resistant lattice ABE supports NL Turing machines with unbounded input and machine descriptions, a dynamically chosen running-time bound, and input-specific decryption time under LWE, evasive LWE, and tensor LWE.","statement_status":"source_normalized_statement","status":"published","title":"Lattice ABE for NL Turing machines","work_id":"ABE-PAPER-2025-AMY-TM"},"primaryUrl":"https://eprint.iacr.org/2025/001","sections":[{"content":"Lattice ABE for NL Turing machines","heading":"Overview"},{"content":"lattice-abe-for-nl is the atomic contribution identifier normalized from ABE-PAPER-2025-AMY-TM. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute Based Encryption for Turing Machines from Lattices","summary":"Collusion-resistant lattice ABE supports NL Turing machines with unbounded input and machine descriptions, a dynamically chosen running-time bound, and input-specific decryption time under LWE, evasive LWE, and tensor LWE.","title":"Lattice ABE for NL Turing machines","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-NL"},{"evidence":"published","id":"ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-TURING-MACHINES","keywords":["atomic-result","turing-machines","uniform-computation","lattices"],"metadata":{"claim_slug":"lattice-abe-for-turing-machines","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Circuit ABE and earlier machine-oriented constructions did not provide a direct lattice-based interface for arbitrary Turing machines whose descriptions and running-time bounds remain unbounded at setup. This contribution supplies that interface: collusion-resistant ABE supports an arbitrary machine, an unbounded input description, and a dynamically selected time bound, with decryption work depending on the concrete computation. The extension beyond the paper's NL construction requires circular tensor LWE in addition to LWE, evasive LWE, and tensor LWE. Its publication-time importance is therefore a feasibility boundary for uniform computation, not a clean-assumption endpoint; the circular tensor assumption remains an essential qualifier rather than a minor proof detail.","prior_boundary":"Earlier lattice ABE handled circuit or restricted machine classes; the same paper's NL branch avoided circular tensor LWE but did not cover arbitrary Turing-machine computation.","significance_at_publication":"Establishes a direct lattice-based feasibility result for ABE over arbitrary time-bounded Turing-machine computations, while making the additional circular-assumption cost explicit.","technical_delta":"Extends the uniform Turing-machine ABE interface from NL to arbitrary machines by adding circular tensor LWE to the LWE, evasive-LWE, and tensor-LWE assumption stack."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-TURING-MACHINES","keywords":["turing-machines","uniform-computation","lattices"],"limitations":[],"paper_id":"ABE-PAPER-2025-AMY-TM","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-AMY-TM § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/001","status":"not_normalized"},"statement":"Collusion-resistant lattice ABE supports arbitrary Turing machines with unbounded input and machine descriptions, dynamically chosen running time, and input-specific decryption time under LWE, evasive LWE, tensor LWE, and circular tensor LWE.","statement_status":"source_normalized_statement","status":"published","title":"Lattice ABE for arbitrary Turing machines","work_id":"ABE-PAPER-2025-AMY-TM"},"primaryUrl":"https://eprint.iacr.org/2025/001","sections":[{"content":"Lattice ABE for arbitrary Turing machines","heading":"Overview"},{"content":"lattice-abe-for-turing-machines is the atomic contribution identifier normalized from ABE-PAPER-2025-AMY-TM. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Attribute Based Encryption for Turing Machines from Lattices","summary":"Collusion-resistant lattice ABE supports arbitrary Turing machines with unbounded input and machine descriptions, dynamically chosen running time, and input-specific decryption time under LWE, evasive LWE, tensor LWE, and circular tensor LWE.","title":"Lattice ABE for arbitrary Turing machines","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-AMY-TM-LATTICE-ABE-FOR-TURING-MACHINES"},{"evidence":"published","id":"ABE-RESULT-2024-HLL-GENERAL-LATTICE-ABE-FRAMEWORK-VIA-NOISY-LSSS-AND-EVASIVE-IPFE","keywords":["atomic-result","lattice-abe","noisy-lsss","evasive-ipfe","circuits","automata"],"metadata":{"claim_slug":"general-lattice-abe-framework-via-noisy-lsss-and-evasive-ipfe","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier lattice ABE constructions tied each supported policy class to specialized homomorphic evaluation and trapdoor techniques. Hsieh, Lin, and Luo isolate a more modular interface: noisy linear garbling or secret sharing represents policy computation, while identity-based evasive inner-product FE supplies simulation for rejecting challenge instances. Instantiations yield succinct CP-ABE for circuits and the first public-key lattice ABE for DFA and logspace Turing-machine policies. The applications have different size profiles and use the paper's evasive-LWE/evasive-IPFE assumptions with selective security; the framework is not plain-LWE adaptive circuit ABE. At publication it widened the lattice policy catalog and provided a reusable decomposition, making the noisy-sharing and evasive simulation components explicit targets for later improvement.","prior_boundary":"Lattice ABE for circuits was built through specialized homomorphic-evaluation and trapdoor machinery, and public-key lattice ABE for uniform DFA/logspace computation was not known.","significance_at_publication":"It supplied a reusable lattice construction interface and the first public-key lattice ABE for DFA/logspace, but its applications remain selective and rely on evasive-LWE-family assumptions.","technical_delta":"The paper factors construction into a noisy linear garbling/LSSS component and identity-based evasive IPFE, then instantiates it for succinct circuits, DFA, and logspace Turing-machine policies."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-HLL-GENERAL-LATTICE-ABE-FRAMEWORK-VIA-NOISY-LSSS-AND-EVASIVE-IPFE","keywords":["lattice-abe","noisy-lsss","evasive-ipfe","circuits","automata"],"limitations":[],"paper_id":"ABE-PAPER-2024-HLL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-HLL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2024/821","status":"not_normalized"},"statement":"Noisy linear secret sharing combined with evasive inner-product FE gives a general lattice ABE framework, including succinct circuit CP-ABE and public-key ABE for DFA and logspace policies.","statement_status":"source_normalized_statement","status":"published","title":"Lattice ABE framework from noisy LSSS and evasive IPFE","work_id":"ABE-PAPER-2024-HLL"},"primaryUrl":"https://eprint.iacr.org/2024/821","sections":[{"content":"Lattice ABE framework from noisy LSSS and evasive IPFE","heading":"Overview"},{"content":"general-lattice-abe-framework-via-noisy-lsss-and-evasive-ipfe is the atomic contribution identifier normalized from ABE-PAPER-2024-HLL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"A General Framework for Lattice-Based ABE Using Evasive Inner-Product Functional Encryption","summary":"Noisy linear secret sharing combined with evasive inner-product FE gives a general lattice ABE framework, including succinct circuit CP-ABE and public-key ABE for DFA and logspace policies.","title":"Lattice ABE framework from noisy LSSS and evasive IPFE","type":"result","venue":"EUROCRYPT 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-HLL-GENERAL-LATTICE-ABE-FRAMEWORK-VIA-NOISY-LSSS-AND-EVASIVE-IPFE"},{"evidence":"published","id":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","keywords":["atomic-result","registered-abe","crs-compression","progression-free-sets","pairings"],"metadata":{"claim_slug":"nearly-linear-registered-abe-crs","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"HLWW's registered-ABE API removed trusted key issuance, but its concrete pairing construction paid a CRS quadratic in the configured user bound and linear in the attribute universe. Garg, Lu, Waters, and Wu use progression-free sets to reduce the user-dependent term to N^(1+o(1)). A separate partitioning branch removes universe-size dependence under static security, and the two techniques can be combined. These branches carry different security and assumption conditions, and the nearly linear asymptotic has large constants; it is not a claim of a practical linear CRS. At publication the work replaced the quadratic setup point as the best pairing-based frontier, while leaving the user bound itself, stronger security, and transparent post-quantum setup unresolved.","prior_boundary":"The original concrete registered-ABE construction required a CRS quadratic in the maximum number of users and linear in the attribute universe, making setup the dominant scaling bottleneck.","significance_at_publication":"It moved the pairing registered-ABE setup frontier below quadratic, while retaining a bounded population and large asymptotic constants rather than delivering a practical linear or unbounded CRS.","technical_delta":"Progression-free sets reduce user-bound dependence to N^(1+o(1)); a partitioning proof separately removes universe-size dependence at the cost of static security, and the techniques can be combined."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","keywords":["registered-abe","crs-compression","progression-free-sets","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2024-GLWW","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-GLWW § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2024/749","status":"not_normalized"},"statement":"Progression-free sets reduce the registered-ABE CRS from quadratic to N^(1+o(1)) in the bounded user population; a separate static-security branch removes attribute-universe dependence.","statement_status":"source_normalized_statement","status":"published","title":"Nearly linear CRS for pairing-based registered ABE","work_id":"ABE-PAPER-2024-GLWW"},"primaryUrl":"https://eprint.iacr.org/2024/749","sections":[{"content":"Nearly linear CRS for pairing-based registered ABE","heading":"Overview"},{"content":"nearly-linear-registered-abe-crs is the atomic contribution identifier normalized from ABE-PAPER-2024-GLWW. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Reducing the CRS Size in Registered ABE Systems","summary":"Progression-free sets reduce the registered-ABE CRS from quadratic to N^(1+o(1)) in the bounded user population; a separate static-security branch removes attribute-universe dependence.","title":"Nearly linear CRS for pairing-based registered ABE","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS"},{"evidence":"published","id":"ABE-RESULT-2024-LYXXZPD-HRABE-TEE-ASSISTED-REVOCATION-WITHOUT-BULK-CIPHERTEXT-DELEGATION","keywords":["atomic-result","revocation","revocable-storage","tee","outsourced-decryption"],"metadata":{"claim_slug":"tee-assisted-revocation-without-bulk-ciphertext-delegation","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Revocable-storage ABE provided cryptographic time-based access control, but periodically delegating every stored ciphertext made updates expensive at cloud scale. Li and coauthors introduced hardware-based revocable ABE, using a trusted execution environment to avoid that bulk delegation and to support outsourced decryption. The security analysis separates selective collusion security from a selective corrupted-TEE notion in which revocation keys may leak, with the latter relying on the underlying two-stage outsourced ABE. This is therefore not a software-only solution, transparent public update, or secure key leasing result. At publication its contribution was to trade corpus-wide update work for an explicit hardware and leakage assumption, creating a practical lifecycle point whose trust boundary can be compared honestly with purely cryptographic revocation schemes.","prior_boundary":"Revocable-storage ABE could update access over time, but periodic public delegation of the stored ciphertext corpus made revocation cost scale with all protected data.","significance_at_publication":"It changed the lifecycle cost profile through a hardware trust assumption, not through a software-only public-update compiler, and made that trust and leakage boundary explicit.","technical_delta":"The system moves revocation assistance into a TEE, avoids bulk ciphertext delegation, and separately models server/revoked-user collusion and leakage of revocation keys from a corrupted enclave."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2024-LYXXZPD-HRABE-TEE-ASSISTED-REVOCATION-WITHOUT-BULK-CIPHERTEXT-DELEGATION","keywords":["revocation","revocable-storage","tee","outsourced-decryption"],"limitations":[],"paper_id":"ABE-PAPER-2024-LYXXZPD-HRABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2024-LYXXZPD-HRABE § Atomic claims","primary_source":null,"primary_source_url":"https://doi.org/10.1109/SP54263.2024.00100","status":"not_normalized"},"statement":"Hardware-based revocable ABE uses a trusted execution environment to avoid periodically delegating every stored ciphertext and supports outsourced decryption under explicit selective collusion and TEE-leakage notions.","statement_status":"source_normalized_statement","status":"published","title":"TEE-assisted ABE revocation without bulk ciphertext delegation","work_id":"ABE-PAPER-2024-LYXXZPD-HRABE"},"primaryUrl":"https://doi.org/10.1109/SP54263.2024.00100","sections":[{"content":"TEE-assisted ABE revocation without bulk ciphertext delegation","heading":"Overview"},{"content":"tee-assisted-revocation-without-bulk-ciphertext-delegation is the atomic contribution identifier normalized from ABE-PAPER-2024-LYXXZPD-HRABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Make Revocation Cheaper: Hardware-Based Revocable Attribute-Based Encryption","summary":"Hardware-based revocable ABE uses a trusted execution environment to avoid periodically delegating every stored ciphertext and supports outsourced decryption under explicit selective collusion and TEE-leakage notions.","title":"TEE-assisted ABE revocation without bulk ciphertext delegation","type":"result","venue":"IEEE S&P 2024","year":2024,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2024-LYXXZPD-HRABE-TEE-ASSISTED-REVOCATION-WITHOUT-BULK-CIPHERTEXT-DELEGATION"},{"evidence":"published","id":"ABE-RESULT-2025-CHW-RABE-ADAPTIVE-DISTRIBUTED-BROADCAST-ENCRYPTION","keywords":["atomic-result","registered-abe","succinct-lwe","circuits","rom"],"metadata":{"claim_slug":"adaptive-distributed-broadcast-encryption","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Prior succinct lattice broadcast schemes required the challenge recipient set to be fixed selectively, and the known adaptive lattice construction passed through witness encryption. Standard complexity leveraging was not an adequate upgrade because it would destroy succinctness. CHW adapts the techniques behind its registered-ABE construction to obtain adaptively secure distributed broadcast encryption from succinct LWE in the random-oracle model. Ciphertexts remain succinct relative to an a-priori user bound, although the CRS and public-key costs still scale with that bound. This result opened a cleaner falsifiable-lattice adaptive broadcast branch. It does not establish adaptive security for the paper's registered circuit ABE, nor does it support an unbounded user population.","prior_boundary":"Earlier succinct lattice broadcast constructions were selective, while the known adaptive lattice route used witness encryption; complexity leveraging did not preserve the required succinctness.","significance_at_publication":"Provides an adaptive lattice distributed-broadcast result from a falsifiable succinct-LWE assumption, but it is a broadcast theorem with a bounded user universe rather than adaptive circuit ABE.","technical_delta":"Adapts the paper's registered-ABE machinery into a distributed broadcast scheme with adaptive security and succinct ciphertexts under succinct LWE in ROM."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-CHW-RABE-ADAPTIVE-DISTRIBUTED-BROADCAST-ENCRYPTION","keywords":["registered-abe","succinct-lwe","circuits","rom"],"limitations":[],"paper_id":"ABE-PAPER-2025-CHW-RABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-CHW-RABE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/044","status":"not_normalized"},"statement":"In ROM, succinct LWE yields adaptively secure distributed broadcast encryption for an a-priori bounded user population, with ciphertext size polylogarithmic in that bound and independent of the recipient-set size.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive distributed broadcast encryption from succinct LWE","work_id":"ABE-PAPER-2025-CHW-RABE"},"primaryUrl":"https://eprint.iacr.org/2025/044","sections":[{"content":"Adaptive distributed broadcast encryption from succinct LWE","heading":"Overview"},{"content":"adaptive-distributed-broadcast-encryption is the atomic contribution identifier normalized from ABE-PAPER-2025-CHW-RABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWE","summary":"In ROM, succinct LWE yields adaptively secure distributed broadcast encryption for an a-priori bounded user population, with ciphertext size polylogarithmic in that bound and independent of the recipient-set size.","title":"Adaptive distributed broadcast encryption from succinct LWE","type":"result","venue":"CRYPTO 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-CHW-RABE-ADAPTIVE-DISTRIBUTED-BROADCAST-ENCRYPTION"},{"evidence":"published","id":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-CPABE","keywords":["atomic-result","circuit-abe","succinct-lwe","almost-optimal"],"metadata":{"claim_slug":"almost-optimal-cpabe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"For ciphertext-policy ABE, the policy circuit is carried by the ciphertext while user keys correspond to attributes, so the compactness obligations differ from the key-policy orientation. Wee25 applies its recursively compressed succinct-LWE framework to this CP-ABE API. For depth-d circuits, public keys, attribute secret keys, and policy ciphertexts are independent of the input length and circuit size, with the stated O(1) counts suppressing factors polynomial in d and the security parameter. At publication this supplied the CP-ABE half of the almost-optimal three-object result rather than merely relabeling the KP construction. The theorem is selective, relies on succinct LWE, and still fixes supported input length and depth through setup parameters.","prior_boundary":"Lattice CP-ABE for circuits had not simultaneously made its public key, attribute keys, and policy ciphertexts independent of input and circuit size under the same succinct construction framework.","significance_at_publication":"Establishes the almost-optimal three-object size profile for CP-ABE circuits, separately from the KP-ABE result, but does not add adaptive security or remove setup-time depth bounds.","technical_delta":"Derives the CP-ABE orientation of the recursively compressed succinct-LWE framework, placing the policy in a ciphertext without making any of the three cryptographic objects scale with policy or attribute length."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-CPABE","keywords":["circuit-abe","succinct-lwe","almost-optimal"],"limitations":[],"paper_id":"ABE-PAPER-2025-WEE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-WEE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/509","status":"not_normalized"},"statement":"Under succinct LWE, selectively secure CP-ABE for depth-d circuits has public keys, attribute secret keys, and policy ciphertexts whose sizes are independent of input length and circuit size up to factors polynomial in d and the security parameter.","statement_status":"source_normalized_statement","status":"published","title":"Almost-optimal succinct CP-ABE for bounded-depth circuits","work_id":"ABE-PAPER-2025-WEE"},"primaryUrl":"https://eprint.iacr.org/2025/509","sections":[{"content":"Almost-optimal succinct CP-ABE for bounded-depth circuits","heading":"Overview"},{"content":"almost-optimal-cpabe is the atomic contribution identifier normalized from ABE-PAPER-2025-WEE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Almost Optimal KP and CP-ABE for Circuits from Succinct LWE","summary":"Under succinct LWE, selectively secure CP-ABE for depth-d circuits has public keys, attribute secret keys, and policy ciphertexts whose sizes are independent of input length and circuit size up to factors polynomial in d and the security parameter.","title":"Almost-optimal succinct CP-ABE for bounded-depth circuits","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-CPABE"},{"evidence":"published","id":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE","keywords":["atomic-result","circuit-abe","succinct-lwe","almost-optimal"],"metadata":{"claim_slug":"almost-optimal-kpabe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Wee24 had already made the ciphertext and circuit secret key of lattice KP-ABE independent of the represented input and circuit size, but its public-key or CRS parameters retained quadratic dependence on the input length. Wee25 recursively compresses the underlying succinct vector commitment and removes that remaining dependence. For depth-d circuits, the public key, ciphertext, and secret key are all independent of input length and circuit size, with the O(1) notation hiding factors polynomial in d and the security parameter. This established the almost-optimal three-object size point for KP-ABE. The result remains selectively secure, assumes succinct LWE, and treats input length and supported depth as setup parameters rather than fully late-bound dimensions.","prior_boundary":"Wee24 made KP-ABE ciphertexts and keys succinct but left the public-key or CRS dependence quadratic in the input length through its vector-commitment parameters.","significance_at_publication":"Reaches the almost-optimal three-object size profile for KP-ABE circuits, while retaining selective security, bounded setup depth, and the stronger succinct-LWE assumption.","technical_delta":"Recursively compresses the Wee24 commitment parameters so the public key joins ciphertexts and secret keys in being independent of input and circuit size, modulo depth and security factors."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE","keywords":["circuit-abe","succinct-lwe","almost-optimal"],"limitations":[],"paper_id":"ABE-PAPER-2025-WEE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-WEE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/509","status":"not_normalized"},"statement":"Under succinct LWE, selectively secure KP-ABE for depth-d circuits has public keys, ciphertexts, and circuit secret keys whose sizes are independent of input length and circuit size up to factors polynomial in d and the security parameter.","statement_status":"source_normalized_statement","status":"published","title":"Almost-optimal succinct KP-ABE for bounded-depth circuits","work_id":"ABE-PAPER-2025-WEE"},"primaryUrl":"https://eprint.iacr.org/2025/509","sections":[{"content":"Almost-optimal succinct KP-ABE for bounded-depth circuits","heading":"Overview"},{"content":"almost-optimal-kpabe is the atomic contribution identifier normalized from ABE-PAPER-2025-WEE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Almost Optimal KP and CP-ABE for Circuits from Succinct LWE","summary":"Under succinct LWE, selectively secure KP-ABE for depth-d circuits has public keys, ciphertexts, and circuit secret keys whose sizes are independent of input length and circuit size up to factors polynomial in d and the security parameter.","title":"Almost-optimal succinct KP-ABE for bounded-depth circuits","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE"},{"evidence":"candidate","id":"ABE-RESULT-2025-SB-LUT-LOOKUP-TABLE-EVALUATION-OVER-BGG-ENCODINGS","keywords":["atomic-result","kp-abe","lattice","ring-lwe","arithmetic-circuits","lookup-tables"],"metadata":{"claim_slug":"lookup-table-evaluation-over-bgg-encodings","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"BGG+-style key-homomorphic encodings were well suited to additive and linear manipulations, but nonlinear operations generally had to be represented through Boolean circuits or other generic machinery. This preprint introduces direct lookup-table evaluation over base-B BGG+ encodings. The lookup mechanism converts a bounded input into its encoded table output and exposes a tunable tradeoff: increasing B reduces repeated evaluation or decryption work, while increasing key-generation work and decryption-key size polynomially in B. On its preprint release, the contribution mattered as a reusable encoding-level operation and as the technical core of the accompanying Ring-LWE KP-ABE construction. It should not be merged with that construction or described as bootstrapping.","prior_boundary":"BGG+-style key-homomorphic encodings naturally supported linear operations, while nonlinear arithmetic was typically represented through Booleanization or heavier generic evaluation machinery.","significance_at_publication":"Supplies the reusable mechanism behind the paper's nonlinear Ring-LWE KP-ABE application without treating that application and the encoding technique as the same contribution.","technical_delta":"Adds direct base-B lookup-table evaluation over the encodings, with an explicit parameter tradeoff between repeated evaluation cost and the size and generation cost of the associated keys."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-SB-LUT-LOOKUP-TABLE-EVALUATION-OVER-BGG-ENCODINGS","keywords":["kp-abe","lattice","ring-lwe","arithmetic-circuits","lookup-tables"],"limitations":[],"paper_id":"ABE-PAPER-2025-SB-LUT","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-SB-LUT § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/1870","status":"not_normalized"},"statement":"Evaluates base-B lookup tables directly over key-homomorphic BGG+ encodings, providing a tunable mechanism for nonlinear operations whose larger base reduces repeated evaluation work at the cost of key-generation time and key size.","statement_status":"source_normalized_statement","status":"preprint","title":"Lookup-table evaluation over BGG+ encodings","work_id":"ABE-PAPER-2025-SB-LUT"},"primaryUrl":"https://eprint.iacr.org/2025/1870","sections":[{"content":"Lookup-table evaluation over BGG+ encodings","heading":"Overview"},{"content":"lookup-table-evaluation-over-bgg-encodings is the atomic contribution identifier normalized from ABE-PAPER-2025-SB-LUT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Lookup-Table Evaluation over Key-Homomorphic Encodings and KP-ABE for Nonlinear Operations","summary":"Evaluates base-B lookup tables directly over key-homomorphic BGG+ encodings, providing a tunable mechanism for nonlinear operations whose larger base reduces repeated evaluation work at the cost of key-generation time and key size.","title":"Lookup-table evaluation over BGG+ encodings","type":"result","venue":"IACR ePrint 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-SB-LUT-LOOKUP-TABLE-EVALUATION-OVER-BGG-ENCODINGS"},{"evidence":"published","id":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE","keywords":["atomic-result","registered-abe","multi-authority","trustless","pairings"],"metadata":{"claim_slug":"introduced-multi-authority-registered-abe","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Decentralized multi-authority ABE allowed policies to span independently administered attribute domains, but each authority still held secret issuing state. Registered ABE removed that long-term issuer secret through transparent curation, yet had been formulated around a single curator. LWW combines the two APIs: independent curators register users and support cross-domain policies without a central master authority retaining the usual secret state. Its pairing construction handles an a-priori bounded user population and monotone LSSS policies; the branch with unbounded users and arbitrary monotone policies instead relies on iO. The contribution settled basic compatibility of the trust models, but not their strongest simultaneous realization from clean or post-quantum assumptions.","prior_boundary":"Decentralized multi-authority ABE allowed cross-domain policies but retained authority-held master secrets, while registered ABE removed long-term issuer secrets only in a single-curator setting.","significance_at_publication":"Establishes that the multi-authority and registered trust models can coexist, while leaving clean-assumption, post-quantum, unbounded general-policy realization open.","technical_delta":"Combines independent multi-authority management with deterministic transparent registration, giving a bounded-user pairing construction for LSSS policies and an iO-based unbounded-user construction for arbitrary monotone policies."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE","keywords":["registered-abe","multi-authority","trustless","pairings"],"limitations":[],"paper_id":"ABE-PAPER-2025-LWW-MARABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-LWW-MARABE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/1279","status":"not_normalized"},"statement":"Introduces multi-authority registered ABE in which independently managed key curators jointly support cross-domain policies without retaining long-term issuer secrets; the pairing and iO branches have different user and policy bounds.","statement_status":"source_normalized_statement","status":"published","title":"Multi-authority registered ABE with independent curators","work_id":"ABE-PAPER-2025-LWW-MARABE"},"primaryUrl":"https://eprint.iacr.org/2025/1279","sections":[{"content":"Multi-authority registered ABE with independent curators","heading":"Overview"},{"content":"introduced-multi-authority-registered-abe is the atomic contribution identifier normalized from ABE-PAPER-2025-LWW-MARABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Multi-Authority Registered Attribute-Based Encryption","summary":"Introduces multi-authority registered ABE in which independently managed key curators jointly support cross-domain policies without retaining long-term issuer secrets; the pairing and iO branches have different user and policy bounds.","title":"Multi-authority registered ABE with independent curators","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE"},{"evidence":"published","id":"ABE-RESULT-2025-HWW-ADAPTIVE-BE-SEMI-STATIC-TO-ADAPTIVE-BE-COMPILER","keywords":["atomic-result","broadcast-encryption","adaptive-security","projective-prg","plain-model"],"metadata":{"claim_slug":"semi-static-to-adaptive-be-compiler","contribution_kind":"transform","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Semi-static broadcast encryption lets the adversary commit to the challenge recipient set before seeing public parameters, so it does not capture the late-set choice allowed by full adaptive security. HWW closes this timing gap with a generic plain-model compiler that combines a semi-static broadcast scheme and a publicly sampleable projective PRG. The compiler programs the complement of the eventual challenge set through the PRG's projection interface, yielding adaptive broadcast constructions from several search assumptions and from witness encryption. At publication, the value was both the generic upgrade and its plain-model realizations. The programming argument is specific to recipient-set complements; it is not evidence for an automatic extension to correlated, reusable ABE policy keys.","prior_boundary":"Semi-static broadcast security fixes the challenge recipient set before public parameters are seen, leaving a timing gap to the adaptive game in which the set is chosen later.","significance_at_publication":"Turns several semi-static constructions into the first plain-model adaptive broadcast schemes from search assumptions and from witness encryption, without claiming a generic adaptive ABE compiler.","technical_delta":"Uses a publicly sampleable projective PRG to program the complement of the eventual challenge set and generically upgrades a semi-static broadcast scheme to adaptive security in the plain model."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-HWW-ADAPTIVE-BE-SEMI-STATIC-TO-ADAPTIVE-BE-COMPILER","keywords":["broadcast-encryption","adaptive-security","projective-prg","plain-model"],"limitations":[],"paper_id":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-HWW-ADAPTIVE-BE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/323","status":"not_normalized"},"statement":"A generic plain-model compiler combines semi-statically secure broadcast encryption with a publicly sampleable projective PRG to obtain adaptively secure broadcast encryption.","statement_status":"source_normalized_statement","status":"published","title":"Plain-model compiler from semi-static to adaptive broadcast encryption","work_id":"ABE-PAPER-2025-HWW-ADAPTIVE-BE"},"primaryUrl":"https://eprint.iacr.org/2025/323","sections":[{"content":"Plain-model compiler from semi-static to adaptive broadcast encryption","heading":"Overview"},{"content":"semi-static-to-adaptive-be-compiler is the atomic contribution identifier normalized from ABE-PAPER-2025-HWW-ADAPTIVE-BE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain Model","summary":"A generic plain-model compiler combines semi-statically secure broadcast encryption with a publicly sampleable projective PRG to obtain adaptively secure broadcast encryption.","title":"Plain-model compiler from semi-static to adaptive broadcast encryption","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-HWW-ADAPTIVE-BE-SEMI-STATIC-TO-ADAPTIVE-BE-COMPILER"},{"evidence":"published","id":"ABE-RESULT-2025-HWW-ADAPTIVE-BE-PUBLICLY-SAMPLEABLE-PROJECTIVE-PRG","keywords":["atomic-result","broadcast-encryption","adaptive-security","projective-prg","plain-model"],"metadata":{"claim_slug":"publicly-sampleable-projective-prg","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier routes to adaptive broadcast encryption did not isolate a compact, publicly generated object that could reveal selected pseudorandom coordinates while preserving the distribution needed to program a late challenge set. HWW defines publicly sampleable projective PRGs and gives constructions from CDH, CBDH, LWE, and RSA-type assumptions. Their projected seeds have size polynomial in the security parameter and the logarithm of the output length, which is the interface used by the paper's broadcast compiler. The abstraction mattered because it separated the adaptive-security mechanism from any one broadcast construction. For the LWE instantiation, however, the public parameters still contain one pair per output coordinate, so the contribution is not an output-independent public-parameter result.","prior_boundary":"Generic adaptive-broadcast compilers lacked a compact public primitive that could expose selected pseudorandom coordinates while preserving the distribution needed to program a late challenge set.","significance_at_publication":"Isolates the adaptive-programming step as a reusable primitive, while showing that projected-seed succinctness does not by itself make the LWE public parameters output-length independent.","technical_delta":"Introduces a publicly sampleable projective-PRG abstraction and supplies multiple assumption-based instantiations whose projected seed is polynomial in the security parameter and logarithm of the output length."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-HWW-ADAPTIVE-BE-PUBLICLY-SAMPLEABLE-PROJECTIVE-PRG","keywords":["broadcast-encryption","adaptive-security","projective-prg","plain-model"],"limitations":[],"paper_id":"ABE-PAPER-2025-HWW-ADAPTIVE-BE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-HWW-ADAPTIVE-BE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/323","status":"not_normalized"},"statement":"Defines publicly sampleable projective PRGs and instantiates them from CDH, CBDH, LWE, and RSA-type assumptions; their projected seeds are succinct enough to drive the paper's semi-static-to-adaptive broadcast compiler.","statement_status":"source_normalized_statement","status":"published","title":"Publicly sampleable projective PRGs for adaptive broadcast encryption","work_id":"ABE-PAPER-2025-HWW-ADAPTIVE-BE"},"primaryUrl":"https://eprint.iacr.org/2025/323","sections":[{"content":"Publicly sampleable projective PRGs for adaptive broadcast encryption","heading":"Overview"},{"content":"publicly-sampleable-projective-prg is the atomic contribution identifier normalized from ABE-PAPER-2025-HWW-ADAPTIVE-BE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain Model","summary":"Defines publicly sampleable projective PRGs and instantiates them from CDH, CBDH, LWE, and RSA-type assumptions; their projected seeds are succinct enough to drive the paper's semi-static-to-adaptive broadcast compiler.","title":"Publicly sampleable projective PRGs for adaptive broadcast encryption","type":"result","venue":"EUROCRYPT 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-HWW-ADAPTIVE-BE-PUBLICLY-SAMPLEABLE-PROJECTIVE-PRG"},{"evidence":"candidate","id":"ABE-RESULT-2025-SB-LUT-RING-LWE-KP-ABE-FOR-NONLINEAR-OPERATIONS","keywords":["atomic-result","kp-abe","lattice","ring-lwe","arithmetic-circuits","lookup-tables"],"metadata":{"claim_slug":"ring-lwe-kp-abe-for-nonlinear-operations","contribution_kind":"research_result","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Existing lattice KP-ABE could represent arithmetic through circuit compilation, but did not directly evaluate nonlinear lookup tables over the native key-homomorphic encodings. This preprint applies its base-B BGG+ lookup mechanism to Ring-LWE KP-ABE for modulo-q arithmetic circuits. The resulting scheme is selectively CPA secure and can reduce repeated decryption work for nonlinear operations. That reduction is not free: increasing the lookup base raises key-generation cost and decryption-key size polynomially in the base. The contribution therefore added a new operation-level design point for lattice ABE rather than an across-the-board asymptotic improvement. Its claim is about KP-ABE for the stated arithmetic API, not arbitrary circuit ABE or homomorphic evaluation.","prior_boundary":"Lattice KP-ABE supported circuit evaluation, but nonlinear arithmetic was normally compiled into lower-level circuit operations rather than evaluated as lookup tables over the native encodings.","significance_at_publication":"Adds a direct nonlinear-operation point to the lattice ABE design space, but it is a selective-CPA preprint and an efficiency tradeoff rather than a universal improvement over circuit ABE.","technical_delta":"Instantiates the paper's base-B lookup mechanism inside Ring-LWE KP-ABE for modulo-q arithmetic circuits, trading larger decryption keys and slower key generation for faster repeated decryption."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-SB-LUT-RING-LWE-KP-ABE-FOR-NONLINEAR-OPERATIONS","keywords":["kp-abe","lattice","ring-lwe","arithmetic-circuits","lookup-tables"],"limitations":[],"paper_id":"ABE-PAPER-2025-SB-LUT","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-SB-LUT § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/1870","status":"not_normalized"},"statement":"The preprint applies direct lookup-table evaluation over BGG+ encodings to selectively secure Ring-LWE KP-ABE for modulo-q arithmetic circuits, reducing repeated decryption work through a base-dependent key-size tradeoff.","statement_status":"source_normalized_statement","status":"preprint","title":"Ring-LWE KP-ABE for modulo-q nonlinear arithmetic","work_id":"ABE-PAPER-2025-SB-LUT"},"primaryUrl":"https://eprint.iacr.org/2025/1870","sections":[{"content":"Ring-LWE KP-ABE for modulo-q nonlinear arithmetic","heading":"Overview"},{"content":"ring-lwe-kp-abe-for-nonlinear-operations is the atomic contribution identifier normalized from ABE-PAPER-2025-SB-LUT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Lookup-Table Evaluation over Key-Homomorphic Encodings and KP-ABE for Nonlinear Operations","summary":"The preprint applies direct lookup-table evaluation over BGG+ encodings to selectively secure Ring-LWE KP-ABE for modulo-q arithmetic circuits, reducing repeated decryption work through a base-dependent key-size tradeoff.","title":"Ring-LWE KP-ABE for modulo-q nonlinear arithmetic","type":"result","venue":"IACR ePrint 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-SB-LUT-RING-LWE-KP-ABE-FOR-NONLINEAR-OPERATIONS"},{"evidence":"candidate","id":"ABE-RESULT-2025-KNP-SKL-COLLUSION-RESISTANT-ABE-SECURE-KEY-LEASING-FROM-LWE","keywords":["atomic-result","secure-key-leasing","revocation","quantum-keys","collusion-resistance","lwe"],"metadata":{"claim_slug":"collusion-resistant-abe-secure-key-leasing-from-lwe","contribution_kind":"security_result","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Conventional ABE revocation controls future key validity but does not prove that a recipient has relinquished a usable copy of a decryption key. Earlier secure-key-leasing formulations also did not cover the paper's combination of multiple leased-key and verification queries with collusion-resistant ABE. KNP defines that stronger lifecycle game and gives a selectively secure construction from polynomially hard LWE whose leased decryption keys are quantum states. A second route provides classical deletion certificates only under polynomial-arity multi-input ABE, itself a substantial unresolved assumption on the current frontier. The preprint therefore establishes a concrete ABE leasing feasibility result, not a drop-in classical revocation mechanism or an adaptively secure ABE theorem.","prior_boundary":"Earlier ABE revocation and secure-leasing results did not provide a model tolerating multiple leased-key and verification queries while preserving collusion resistance for expressive ABE.","significance_at_publication":"Extends ABE into cryptographically enforced key return under collusion, but remains a preprint with selective security and quantum-key requirements rather than ordinary classical revocation.","technical_delta":"Defines collusion-resistant secure key leasing and realizes selective ABE-CR-SKL from polynomially hard LWE with quantum leased keys, plus a conditional classical-certificate route through polynomial-arity MIABE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-KNP-SKL-COLLUSION-RESISTANT-ABE-SECURE-KEY-LEASING-FROM-LWE","keywords":["secure-key-leasing","revocation","quantum-keys","collusion-resistance","lwe"],"limitations":[],"paper_id":"ABE-PAPER-2025-KNP-SKL","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-KNP-SKL § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/262","status":"not_normalized"},"statement":"The preprint constructs selectively secure ABE with collusion-resistant secure key leasing from polynomially hard LWE, using quantum leased decryption keys; classical deletion certificates additionally require polynomial-arity multi-input ABE.","statement_status":"source_normalized_statement","status":"preprint","title":"Selective ABE with collusion-resistant secure key leasing from LWE","work_id":"ABE-PAPER-2025-KNP-SKL"},"primaryUrl":"https://eprint.iacr.org/2025/262","sections":[{"content":"Selective ABE with collusion-resistant secure key leasing from LWE","heading":"Overview"},{"content":"collusion-resistant-abe-secure-key-leasing-from-lwe is the atomic contribution identifier normalized from ABE-PAPER-2025-KNP-SKL. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"PKE and ABE with Collusion-Resistant Secure Key Leasing","summary":"The preprint constructs selectively secure ABE with collusion-resistant secure key leasing from polynomially hard LWE, using quantum leased decryption keys; classical deletion certificates additionally require polynomial-arity multi-input ABE.","title":"Selective ABE with collusion-resistant secure key leasing from LWE","type":"result","venue":null,"year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-KNP-SKL-COLLUSION-RESISTANT-ABE-SECURE-KEY-LEASING-FROM-LWE"},{"evidence":"published","id":"ABE-RESULT-2025-WBWL-PE-SELECTIVE-FULLY-ATTRIBUTE-HIDING-BOUNDED-COLLUSION-CIRCUIT-PE","keywords":["atomic-result","predicate-encryption","attribute-hiding","lattices","bounded-collusion"],"metadata":{"claim_slug":"selective-fully-attribute-hiding-bounded-collusion-circuit-pe","contribution_kind":"security_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier lattice predicate-encryption constructions traded circuit functionality, compactness, and hiding strength, while fully general policy or function hiding for reusable public-key ABE encounters much stronger barriers. Wang and coauthors give predicate encryption for polynomial-size bounded-depth circuits with selective, fully attribute-hiding simulation security against a bounded number of colluding keys. The price is explicit: parameters expand linearly with the collusion bound, and the theorem is selective rather than fully adaptive. At publication this sharpened the lattice PE frontier by protecting the encrypted attribute under a precise leakage profile. It must not be advertised as full policy-hiding ABE, because the reusable predicate or function carried by the key is not the hidden object.","prior_boundary":"Lattice predicate-encryption compactness and circuit functionality did not simultaneously provide the paper's fully attribute-hiding simulation guarantee; stronger general policy hiding for reusable ABE remains iO-complete in broad formulations.","significance_at_publication":"Advances hidden-attribute lattice PE while locating a useful point below the general policy-hiding boundary; it does not hide the reusable policy or function embedded in a decryption key.","technical_delta":"Achieves selective full attribute hiding for bounded-depth circuit predicates under bounded collusion, with ciphertext expansion that grows linearly with the permitted collusion bound."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-WBWL-PE-SELECTIVE-FULLY-ATTRIBUTE-HIDING-BOUNDED-COLLUSION-CIRCUIT-PE","keywords":["predicate-encryption","attribute-hiding","lattices","bounded-collusion"],"limitations":[],"paper_id":"ABE-PAPER-2025-WBWL-PE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-WBWL-PE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/361","status":"not_normalized"},"statement":"Constructs lattice predicate encryption for polynomial-size bounded-depth circuits with selective fully attribute-hiding simulation security against a bounded number of colluding keys, with expansion linear in the collusion bound.","statement_status":"source_normalized_statement","status":"published","title":"Selective fully attribute-hiding circuit PE with bounded collusion","work_id":"ABE-PAPER-2025-WBWL-PE"},"primaryUrl":"https://eprint.iacr.org/2025/361","sections":[{"content":"Selective fully attribute-hiding circuit PE with bounded collusion","heading":"Overview"},{"content":"selective-fully-attribute-hiding-bounded-collusion-circuit-pe is the atomic contribution identifier normalized from ABE-PAPER-2025-WBWL-PE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Predicate Encryption from Lattices: Enhanced Compactness and Refined Functionality","summary":"Constructs lattice predicate encryption for polynomial-size bounded-depth circuits with selective fully attribute-hiding simulation security against a bounded number of colluding keys, with expansion linear in the collusion bound.","title":"Selective fully attribute-hiding circuit PE with bounded collusion","type":"result","venue":"PKC 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-WBWL-PE-SELECTIVE-FULLY-ATTRIBUTE-HIDING-BOUNDED-COLLUSION-CIRCUIT-PE"},{"evidence":"published","id":"ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE","keywords":["atomic-result","registered-abe","succinct-lwe","circuits","rom"],"metadata":{"claim_slug":"registered-circuit-abe","contribution_kind":"construction","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Registered ABE had removed long-lived issuer secrets through transparent curation, but general-policy realizations relied on pairings, witness encryption, or iO and did not offer this lattice succinctness profile. CHW constructs key-policy registered ABE for bounded-depth Boolean circuits from succinct LWE in the random-oracle model. Its ciphertext size depends on the security parameter and circuit depth, not on the attribute length or policy size, while the supported user population is fixed in advance. At publication this created a falsifiable-lattice registered-ABE branch for circuit policies. The theorem is attribute-selective; adaptive security in the paper belongs to a distinct distributed-broadcast construction and must not be transferred to this ABE card.","prior_boundary":"Registered ABE had transparent key curation, but general-policy constructions followed pairing, witness-encryption, or iO routes and their ciphertexts scaled with the represented attribute or policy computation.","significance_at_publication":"Gives the first registered ABE for general circuit constraints from a falsifiable lattice assumption with succinct ciphertexts, without turning its separate adaptive broadcast application into an ABE security claim.","technical_delta":"Carries the registered-ABE API to bounded-depth circuit policies from succinct LWE in ROM, with ciphertext size depending on security and depth rather than attribute length or circuit size."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE","keywords":["registered-abe","succinct-lwe","circuits","rom"],"limitations":[],"paper_id":"ABE-PAPER-2025-CHW-RABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2025-CHW-RABE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/044","status":"not_normalized"},"statement":"In the random-oracle model, succinct LWE yields attribute-selective registered KP-ABE for bounded-depth Boolean circuits whose ciphertext size is independent of attribute length and policy size, for an a-priori bounded user population.","statement_status":"source_normalized_statement","status":"published","title":"Succinct registered KP-ABE for bounded-depth circuits","work_id":"ABE-PAPER-2025-CHW-RABE"},"primaryUrl":"https://eprint.iacr.org/2025/044","sections":[{"content":"Succinct registered KP-ABE for bounded-depth circuits","heading":"Overview"},{"content":"registered-circuit-abe is the atomic contribution identifier normalized from ABE-PAPER-2025-CHW-RABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Registered ABE and Adaptively-Secure Broadcast Encryption from Succinct LWE","summary":"In the random-oracle model, succinct LWE yields attribute-selective registered KP-ABE for bounded-depth Boolean circuits whose ciphertext size is independent of attribute length and policy size, for an a-priori bounded user population.","title":"Succinct registered KP-ABE for bounded-depth circuits","type":"result","venue":"CRYPTO 2025","year":2025,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE"},{"evidence":"candidate","id":"ABE-RESULT-2026-CW-OPT-DMPE-ADAPTIVE-UNBOUNDED-BROADCAST","keywords":["atomic-result","dmpe","dnf","optimal-succinctness","decomposed-lwe"],"metadata":{"claim_slug":"adaptive-unbounded-broadcast","contribution_kind":"research_result","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Earlier adaptive lattice distributed-broadcast schemes in the plain model assumed an a-priori bound on the number of users, even when they achieved ciphertexts independent of the recipient-set size. Champion and Wu instead specialize their distributed-policy techniques to broadcast membership and allow an unbounded population of independently registering users. Under polynomial-ratio decomposed LWE, the ciphertext grows as the two-thirds power of the selected recipient-set size and the construction is adaptively secure in the plain model. In this preprint, the result establishes the first unbounded-user adaptive lattice point in that model, trading optimal ciphertext size for population flexibility. The result is distributed broadcast encryption; its adaptive theorem cannot be carried over to the accompanying DNF-DMPE constructions.","prior_boundary":"Adaptive plain-model lattice distributed broadcast either fixed a user bound in advance or lacked this sublinear ciphertext point for an unbounded population.","significance_at_publication":"Opens the unbounded-user adaptive plain-model lattice broadcast regime, but the adaptive guarantee belongs to DBE and not to the paper's DNF-DMPE theorems.","technical_delta":"Specializes the DMPE machinery to broadcast membership, obtaining adaptive security, no a-priori user bound, and recipient-set ciphertext size to the two-thirds power under polynomial-ratio decomposed LWE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-CW-OPT-DMPE-ADAPTIVE-UNBOUNDED-BROADCAST","keywords":["dmpe","dnf","optimal-succinctness","decomposed-lwe"],"limitations":[],"paper_id":"ABE-PAPER-2026-CW-OPT-DMPE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-CW-OPT-DMPE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/1464","status":"not_normalized"},"statement":"In the plain model, the preprint specializes its techniques to adaptively secure distributed broadcast encryption for an a-priori unbounded user population with ciphertext size proportional to the two-thirds power of the recipient-set size under polynomial-ratio decomposed LWE.","statement_status":"source_normalized_statement","status":"preprint","title":"Adaptive unbounded-user distributed broadcast from decomposed LWE","work_id":"ABE-PAPER-2026-CW-OPT-DMPE"},"primaryUrl":"https://eprint.iacr.org/2026/1464","sections":[{"content":"Adaptive unbounded-user distributed broadcast from decomposed LWE","heading":"Overview"},{"content":"adaptive-unbounded-broadcast is the atomic contribution identifier normalized from ABE-PAPER-2026-CW-OPT-DMPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices","summary":"In the plain model, the preprint specializes its techniques to adaptively secure distributed broadcast encryption for an a-priori unbounded user population with ciphertext size proportional to the two-thirds power of the recipient-set size under polynomial-ratio decomposed LWE.","title":"Adaptive unbounded-user distributed broadcast from decomposed LWE","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-CW-OPT-DMPE-ADAPTIVE-UNBOUNDED-BROADCAST"},{"evidence":"candidate","id":"ABE-RESULT-2026-LZF-CONSTANT-CT-CONSTANT-SIZE-CIPHERTEXT-CP-ABE-FOR-NC1","keywords":["atomic-result","cp-abe","lattice","succinct-lwe","nc1","constant-ciphertext"],"metadata":{"claim_slug":"constant-size-ciphertext-cp-abe-for-nc1","contribution_kind":"optimization","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Lattice CP-ABE had obtained increasingly succinct policy ciphertexts, but the NC1 setting still lacked a construction whose ciphertext stopped scaling with circuit size, input length, and depth. This preprint obtains that ciphertext profile from poly(lambda)-succinct LWE under selective security, with the usual constant-size notation hiding factors polynomial in the security parameter. The public parameters are not simultaneously constant: they initially grow linearly with circuit size, although their uniformly random portion can be generated from a PRG. On its preprint release, the contribution cleanly separated ciphertext succinctness from setup succinctness and established the former for NC1. It is not an adaptive theorem, a plain-LWE construction, or a claim that every cryptographic object is circuit-size independent.","prior_boundary":"Succinct lattice CP-ABE reduced policy-dependent ciphertext growth, but constant ciphertext size for NC1 while separating ciphertext succinctness from public-parameter size remained unresolved.","significance_at_publication":"Places constant-size policy ciphertexts on the succinct-LWE lattice branch, without claiming constant-size public parameters, adaptive security, or plain-LWE security.","technical_delta":"Gives an NC1 CP-ABE construction whose ciphertext is independent of circuit size, input length, and depth, while its public parameters initially remain linear in circuit size except for a PRG-generatable uniform portion."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-LZF-CONSTANT-CT-CONSTANT-SIZE-CIPHERTEXT-CP-ABE-FOR-NC1","keywords":["cp-abe","lattice","succinct-lwe","nc1","constant-ciphertext"],"limitations":[],"paper_id":"ABE-PAPER-2026-LZF-CONSTANT-CT","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-LZF-CONSTANT-CT § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/534","status":"not_normalized"},"statement":"The preprint constructs selectively secure lattice CP-ABE for NC1 from poly(lambda)-succinct LWE whose ciphertext size is independent of circuit size, input length, and depth up to hidden polynomial-in-security factors.","statement_status":"source_normalized_statement","status":"preprint","title":"Constant-size ciphertext CP-ABE for NC1 from succinct LWE","work_id":"ABE-PAPER-2026-LZF-CONSTANT-CT"},"primaryUrl":"https://eprint.iacr.org/2026/534","sections":[{"content":"Constant-size ciphertext CP-ABE for NC1 from succinct LWE","heading":"Overview"},{"content":"constant-size-ciphertext-cp-abe-for-nc1 is the atomic contribution identifier normalized from ABE-PAPER-2026-LZF-CONSTANT-CT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Ciphertext-Policy ABE for NC1 Circuits with Constant-Size Ciphertexts from Succinct LWE","summary":"The preprint constructs selectively secure lattice CP-ABE for NC1 from poly(lambda)-succinct LWE whose ciphertext size is independent of circuit size, input length, and depth up to hidden polynomial-in-security factors.","title":"Constant-size ciphertext CP-ABE for NC1 from succinct LWE","type":"result","venue":"IACR ePrint 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-LZF-CONSTANT-CT-CONSTANT-SIZE-CIPHERTEXT-CP-ABE-FOR-NC1"},{"evidence":"published","id":"ABE-RESULT-2026-GY-EQUIVOCAL-BE-EQUIVOCAL-ENCRYPTION-SYSTEMS","keywords":["atomic-result","distributed-broadcast","adaptive-security","equivocal-encryption","lattices"],"metadata":{"claim_slug":"equivocal-encryption-systems","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Selective lattice broadcast proofs could prepare for a fixed challenge set, whereas adaptive security forces the simulator to answer correlated key requests before the eventual challenge message and recipient set are known. Goyal and Yadugiri introduce equivocal encryption systems to address that causal ordering. Indistinguishable real and fake modes jointly sample keys and ciphertexts with auxiliary trapdoors; the fake ciphertext can later be explained as encrypting the selected challenge value. This mechanism enabled the paper's optimal adaptive distributed-broadcast construction and offered a proof paradigm distinct from dual-system encryption. Its demonstrated theorem is still broadcast-specific: matching one-dimensional recipient relations does not by itself handle correlated rows and repeated labels in reusable ABE policy keys.","prior_boundary":"Selective lattice broadcast proofs could commit to the challenge recipient set early, but adaptive security required simulating correlated keys and a ciphertext before the challenge message was known.","significance_at_publication":"Supplies the proof mechanism behind optimal adaptive lattice DBE and a candidate alternative to dual-system reasoning, but its policy-level generalization to reusable ABE keys is only a research direction.","technical_delta":"Defines jointly sampled real and fake encryption modes with auxiliary trapdoors, so the simulator can later equivocate the fake ciphertext to the chosen challenge value while preserving the key-ciphertext distribution."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-GY-EQUIVOCAL-BE-EQUIVOCAL-ENCRYPTION-SYSTEMS","keywords":["distributed-broadcast","adaptive-security","equivocal-encryption","lattices"],"limitations":[],"paper_id":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-GY-EQUIVOCAL-BE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/792","status":"not_normalized"},"statement":"Introduces equivocal encryption systems with indistinguishable real and fake modes that jointly sample fake keys and ciphertexts with trapdoors, allowing a challenge ciphertext to be explained later as an adaptively chosen message.","statement_status":"source_normalized_statement","status":"published","title":"Equivocal encryption systems for adaptive lattice broadcast","work_id":"ABE-PAPER-2026-GY-EQUIVOCAL-BE"},"primaryUrl":"https://eprint.iacr.org/2026/792","sections":[{"content":"Equivocal encryption systems for adaptive lattice broadcast","heading":"Overview"},{"content":"equivocal-encryption-systems is the atomic contribution identifier normalized from ABE-PAPER-2026-GY-EQUIVOCAL-BE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Equivocal Broadcast Encryption: Adaptively-Secure Optimal Distributed Broadcast Encryption from Lattices","summary":"Introduces equivocal encryption systems with indistinguishable real and fake modes that jointly sample fake keys and ciphertexts with trapdoors, allowing a challenge ciphertext to be explained later as an adaptively chosen message.","title":"Equivocal encryption systems for adaptive lattice broadcast","type":"result","venue":"CRYPTO 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-GY-EQUIVOCAL-BE-EQUIVOCAL-ENCRYPTION-SYSTEMS"},{"evidence":"candidate","id":"ABE-RESULT-2026-GY-FBE-EQUIVOCAL-MATRIX-COMMITMENTS","keywords":["atomic-result","fbe","ibbe","adaptivity","equivocal-commitment"],"metadata":{"claim_slug":"equivocal-matrix-commitments","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The earlier equivocal-encryption framework solved adaptive security for a slotted DBE matrix whose user positions were bounded in advance. Flexible registration and identity-based broadcast instead require a structure that can accommodate dynamically arriving keys or identities from a much larger space. This preprint introduces equivocal matrix commitments, adding fake-setup and adaptive equivocation capabilities to the committed matrix, and uses the abstraction inside generic FBE and IBBE compilers. On its preprint release, the mechanism isolated the technical step that removes the fixed-slot restriction while preserving adaptive simulation under decomposed LWE in ROM. The demonstrated applications are broadcast APIs; extension to matrices encoding correlated, reusable ABE policies is a curator-identified research direction rather than a theorem of the paper.","prior_boundary":"Equivocal encryption handled a slotted DBE matrix with an a-priori user bound, but flexible registration and super-polynomial identity spaces required the committed matrix to grow and be programmed adaptively.","significance_at_publication":"Abstracts the step from fixed slotted broadcast to dynamic unbounded user spaces, while broader applicability to correlated ABE policy matrices remains conjectural.","technical_delta":"Strengthens matrix commitments with equivocal setup and adaptive opening behavior and composes that interface with generic compilers for FBE and IBBE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-GY-FBE-EQUIVOCAL-MATRIX-COMMITMENTS","keywords":["fbe","ibbe","adaptivity","equivocal-commitment"],"limitations":[],"paper_id":"ABE-PAPER-2026-GY-FBE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-GY-FBE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/862","status":"not_normalized"},"statement":"The preprint introduces equivocal matrix commitments that strengthen matrix commitments with fake-setup and adaptive equivocation capabilities, enabling the paper's flexible and identity-based broadcast compilers for unbounded dynamic user spaces.","statement_status":"source_normalized_statement","status":"preprint","title":"Equivocal matrix commitments for dynamic broadcast systems","work_id":"ABE-PAPER-2026-GY-FBE"},"primaryUrl":"https://eprint.iacr.org/2026/862","sections":[{"content":"Equivocal matrix commitments for dynamic broadcast systems","heading":"Overview"},{"content":"equivocal-matrix-commitments is the atomic contribution identifier normalized from ABE-PAPER-2026-GY-FBE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE","summary":"The preprint introduces equivocal matrix commitments that strengthen matrix commitments with fake-setup and adaptive equivocation capabilities, enabling the paper's flexible and identity-based broadcast compilers for unbounded dynamic user spaces.","title":"Equivocal matrix commitments for dynamic broadcast systems","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-GY-FBE-EQUIVOCAL-MATRIX-COMMITMENTS"},{"evidence":"published","id":"ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS","keywords":["atomic-result","registered-abe","pairings","msp","crs"],"metadata":{"claim_slug":"linear-crs-registered-abe-for-msps","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Pairing-based registered ABE had improved the original quadratic common reference string to nearly linear size, but had not reached a genuinely linear CRS while supporting expressive monotone policies. SWW gives registered ABE for monotone span programs, including formulas and thresholds, with a CRS linear in the user bound. It also develops a large-index branch in which arbitrary-string identities permit stateless key generation. The security points must remain separated: static security is obtained in the plain model under a q-type assumption, while the adaptive ROM transformation uses a small index space and an a-priori policy bound; the large-index branch is index-set selective. Thus adaptive security and arbitrary-string identities are not simultaneous.","prior_boundary":"The pairing registered-ABE line had reduced its CRS from quadratic to nearly linear, but a genuinely linear CRS for formulas, thresholds, and general MSP policies was not available with the paper's registration features.","significance_at_publication":"Reaches the linear-CRS pairing milestone for expressive registered ABE, but adaptive security and arbitrary-string stateless identities are not obtained in the same branch.","technical_delta":"Achieves linear CRS size for MSP policies and adds a large-index arbitrary-string identity branch with stateless key generation, alongside separate static plain-model and adaptive ROM instantiations."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS","keywords":["registered-abe","pairings","msp","crs"],"limitations":[],"paper_id":"ABE-PAPER-2026-SWW-RABE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-SWW-RABE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/1062","status":"not_normalized"},"statement":"Pairing-based registered ABE supports monotone span programs with a CRS linear in the user bound; static plain-model, adaptive ROM, and large-index stateless-key branches provide different and non-simultaneous security and identity guarantees.","statement_status":"source_normalized_statement","status":"published","title":"Linear-CRS registered ABE for monotone span programs","work_id":"ABE-PAPER-2026-SWW-RABE"},"primaryUrl":"https://eprint.iacr.org/2026/1062","sections":[{"content":"Linear-CRS registered ABE for monotone span programs","heading":"Overview"},{"content":"linear-crs-registered-abe-for-msps is the atomic contribution identifier normalized from ABE-PAPER-2026-SWW-RABE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRS","summary":"Pairing-based registered ABE supports monotone span programs with a CRS linear in the user bound; static plain-model, adaptive ROM, and large-index stateless-key branches provide different and non-simultaneous security and identity guarantees.","title":"Linear-CRS registered ABE for monotone span programs","type":"result","venue":"CRYPTO 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS"},{"evidence":"candidate","id":"ABE-RESULT-2026-CW-OPT-DMPE-OPTIMAL-DNF-DMPE","keywords":["atomic-result","dmpe","dnf","optimal-succinctness","decomposed-lwe"],"metadata":{"claim_slug":"optimal-dnf-dmpe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The first Champion-Wu lattice DNF-DMPE result established transparent setup and unbounded users with polylogarithmic-in-user ciphertext overhead, but did not make every principal object independent of policy size. This preprint refines that branch in the random-oracle model: public parameters, user public keys, and ciphertexts no longer scale with the size of the DNF policy. That is the paper's optimal succinctness criterion and marks a sharper endpoint for trustless DNF encryption from decomposed LWE. The main DMPE theorem is statically secure; an appendix studies weaker selective timing variants, while the paper's adaptive theorem belongs to a separate distributed-broadcast specialization. General formulas, thresholds, and monotone span programs remain outside this contribution.","prior_boundary":"The earlier Champion-Wu DNF-DMPE construction supported transparent setup and unbounded users but retained polylogarithmic dependence on the user population rather than policy-size-independent parameters throughout.","significance_at_publication":"Reaches the paper's defined optimal succinctness point for DNF DMPE, without solving fully adaptive DMPE or extending the result to general monotone policies.","technical_delta":"Refines the decomposed-LWE construction so public parameters, user keys, and ciphertexts are independent of DNF size in ROM under the paper's static security theorem."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-CW-OPT-DMPE-OPTIMAL-DNF-DMPE","keywords":["dmpe","dnf","optimal-succinctness","decomposed-lwe"],"limitations":[],"paper_id":"ABE-PAPER-2026-CW-OPT-DMPE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-CW-OPT-DMPE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/1464","status":"not_normalized"},"statement":"In ROM, the preprint gives statically secure DNF distributed monotone-policy encryption from decomposed LWE whose public parameters, user keys, and ciphertext size are all independent of the DNF policy size.","statement_status":"source_normalized_statement","status":"preprint","title":"Optimal DNF DMPE from decomposed LWE in ROM","work_id":"ABE-PAPER-2026-CW-OPT-DMPE"},"primaryUrl":"https://eprint.iacr.org/2026/1464","sections":[{"content":"Optimal DNF DMPE from decomposed LWE in ROM","heading":"Overview"},{"content":"optimal-dnf-dmpe is the atomic contribution identifier normalized from ABE-PAPER-2026-CW-OPT-DMPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices","summary":"In ROM, the preprint gives statically secure DNF distributed monotone-policy encryption from decomposed LWE whose public parameters, user keys, and ciphertext size are all independent of the DNF policy size.","title":"Optimal DNF DMPE from decomposed LWE in ROM","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-CW-OPT-DMPE-OPTIMAL-DNF-DMPE"},{"evidence":"candidate","id":"ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-FBE","keywords":["atomic-result","fbe","ibbe","adaptivity","equivocal-commitment"],"metadata":{"claim_slug":"optimal-adaptive-fbe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Optimal adaptive lattice DBE had been achieved only in a slotted model with an a-priori user structure. Flexible broadcast encryption changes the API: users generate and register their own keys asynchronously, so neither fixed slots nor a bounded enrollment schedule can be assumed. This preprint combines equivocal matrix commitments with a generic FBE compiler to obtain adaptive security, transparent setup, and public keys, secret keys, and ciphertexts whose sizes are independent of the number of users, from decomposed LWE in the random-oracle model. In this preprint, the result removes the fixed-slot restriction without giving up optimal succinctness. The result remains a flexible-broadcast theorem, not arbitrary-policy ABE, and it does not provide the same guarantees in the standard model.","prior_boundary":"Optimal adaptive lattice DBE still used an a-priori slotted user structure, while flexible broadcast requires users to sample and register keys asynchronously without fixed positions.","significance_at_publication":"Reaches the optimal adaptive lattice point for the flexible broadcast API, not for general ABE, and leaves removal of the random oracle unresolved.","technical_delta":"Combines equivocal matrix commitments with an FBE compiler to remove the slotted population bound while retaining transparent setup, adaptive security, and user-count-independent parameters under decomposed LWE in ROM."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-FBE","keywords":["fbe","ibbe","adaptivity","equivocal-commitment"],"limitations":[],"paper_id":"ABE-PAPER-2026-GY-FBE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-GY-FBE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/862","status":"not_normalized"},"statement":"In ROM, the preprint constructs transparent-setup flexible broadcast encryption from decomposed LWE with adaptive security and all parameter sizes independent of the number of asynchronously registering users.","statement_status":"source_normalized_statement","status":"preprint","title":"Optimal adaptively secure flexible broadcast encryption","work_id":"ABE-PAPER-2026-GY-FBE"},"primaryUrl":"https://eprint.iacr.org/2026/862","sections":[{"content":"Optimal adaptively secure flexible broadcast encryption","heading":"Overview"},{"content":"optimal-adaptive-fbe is the atomic contribution identifier normalized from ABE-PAPER-2026-GY-FBE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE","summary":"In ROM, the preprint constructs transparent-setup flexible broadcast encryption from decomposed LWE with adaptive security and all parameter sizes independent of the number of asynchronously registering users.","title":"Optimal adaptively secure flexible broadcast encryption","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-FBE"},{"evidence":"candidate","id":"ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-IBBE","keywords":["atomic-result","fbe","ibbe","adaptivity","equivocal-commitment"],"metadata":{"claim_slug":"optimal-adaptive-ibbe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Slotted distributed broadcast assigns recipients fixed positions and does not provide the identity-based interface in which a trusted authority issues keys for names from a super-polynomial space. This preprint uses equivocal matrix commitments with an IBBE compiler to obtain adaptively secure identity-based broadcast encryption from decomposed LWE in the random-oracle model. Public parameters, user keys, and ciphertexts are independent of the number of users, achieving the paper's optimal size target while accommodating the large identity space. The contribution is distinct from the accompanying FBE result: IBBE retains a trusted key issuer and does not inherit FBE's transparent, user-generated registration API. It is also broadcast encryption rather than general predicate or ABE.","prior_boundary":"Slotted lattice DBE required fixed user positions, whereas identity-based broadcast must let a trusted authority issue keys for identities in a super-polynomial space without user-count-dependent parameters.","significance_at_publication":"Extends optimal adaptive lattice broadcast to the identity-based API, but unlike FBE it retains a trusted issuing authority and does not have transparent user-generated setup.","technical_delta":"Uses equivocal matrix commitments and an IBBE compiler to obtain adaptive security and optimal user-count-independent sizes under decomposed LWE in ROM."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-IBBE","keywords":["fbe","ibbe","adaptivity","equivocal-commitment"],"limitations":[],"paper_id":"ABE-PAPER-2026-GY-FBE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-GY-FBE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/862","status":"not_normalized"},"statement":"In ROM, the preprint constructs identity-based broadcast encryption from decomposed LWE with adaptive security and all parameter sizes independent of the number of users, for identities drawn from a super-polynomially large space.","statement_status":"source_normalized_statement","status":"preprint","title":"Optimal adaptively secure identity-based broadcast encryption","work_id":"ABE-PAPER-2026-GY-FBE"},"primaryUrl":"https://eprint.iacr.org/2026/862","sections":[{"content":"Optimal adaptively secure identity-based broadcast encryption","heading":"Overview"},{"content":"optimal-adaptive-ibbe is the atomic contribution identifier normalized from ABE-PAPER-2026-GY-FBE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE","summary":"In ROM, the preprint constructs identity-based broadcast encryption from decomposed LWE with adaptive security and all parameter sizes independent of the number of users, for identities drawn from a super-polynomially large space.","title":"Optimal adaptively secure identity-based broadcast encryption","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-GY-FBE-OPTIMAL-ADAPTIVE-IBBE"},{"evidence":"published","id":"ABE-RESULT-2026-GY-EQUIVOCAL-BE-OPTIMAL-ADAPTIVE-LATTICE-DBE","keywords":["atomic-result","distributed-broadcast","adaptive-security","equivocal-encryption","lattices"],"metadata":{"claim_slug":"optimal-adaptive-lattice-dbe","contribution_kind":"optimization","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Before this work, falsifiable lattice constructions of distributed broadcast encryption did not simultaneously provide adaptive security and optimal parameters independent of the user count. Goyal and Yadugiri use equivocal encryption systems to obtain transparent-setup DBE with adaptive security, short public and secret keys, and succinct ciphertexts. The construction has two model points: a random-oracle instantiation with a succinct CRS and a standard-model instantiation whose CRS is long. At publication this closed the adaptive-versus-optimality gap for the slotted DBE API. It did not simultaneously achieve a succinct CRS in the standard model, remove the slotted or bounded-population structure, or establish an adaptive theorem for arbitrary reusable ABE policies.","prior_boundary":"No lattice DBE from a falsifiable assumption simultaneously achieved adaptive security and optimal user-count-independent parameters; existing routes sacrificed adaptivity, succinctness, or the standard model.","significance_at_publication":"Reaches the adaptive optimal-parameter endpoint for slotted lattice DBE, while leaving simultaneous standard-model and succinct-CRS realization and policy-level ABE generalization open.","technical_delta":"Applies equivocal encryption systems to obtain transparent-setup adaptive DBE with short keys and ciphertexts, offering a succinct-CRS ROM branch and a standard-model branch with a long CRS."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-GY-EQUIVOCAL-BE-OPTIMAL-ADAPTIVE-LATTICE-DBE","keywords":["distributed-broadcast","adaptive-security","equivocal-encryption","lattices"],"limitations":[],"paper_id":"ABE-PAPER-2026-GY-EQUIVOCAL-BE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-GY-EQUIVOCAL-BE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/792","status":"not_normalized"},"statement":"From a falsifiable lattice assumption, the paper constructs transparent-setup distributed broadcast encryption with adaptive security and parameter sizes independent of the user count, using either a succinct CRS in ROM or a long CRS in the standard model.","statement_status":"source_normalized_statement","status":"published","title":"Optimal adaptively secure lattice DBE","work_id":"ABE-PAPER-2026-GY-EQUIVOCAL-BE"},"primaryUrl":"https://eprint.iacr.org/2026/792","sections":[{"content":"Optimal adaptively secure lattice DBE","heading":"Overview"},{"content":"optimal-adaptive-lattice-dbe is the atomic contribution identifier normalized from ABE-PAPER-2026-GY-EQUIVOCAL-BE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Equivocal Broadcast Encryption: Adaptively-Secure Optimal Distributed Broadcast Encryption from Lattices","summary":"From a falsifiable lattice assumption, the paper constructs transparent-setup distributed broadcast encryption with adaptive security and parameter sizes independent of the user count, using either a succinct CRS in ROM or a long CRS in the standard model.","title":"Optimal adaptively secure lattice DBE","type":"result","venue":"CRYPTO 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-GY-EQUIVOCAL-BE-OPTIMAL-ADAPTIVE-LATTICE-DBE"},{"evidence":"candidate","id":"ABE-RESULT-2026-CW-OPT-DMPE-PLAIN-MODEL-DMPE-TRADEOFFS","keywords":["atomic-result","dmpe","dnf","optimal-succinctness","decomposed-lwe"],"metadata":{"claim_slug":"plain-model-dmpe-tradeoffs","contribution_kind":"research_result","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"The paper's optimal DNF-DMPE construction obtains policy-size-independent objects in the random-oracle model, leaving open what survives when that oracle is removed. Its plain-model branch gives k-DNF DMPE with ciphertext size approximately k times the square root of the number of minterms, a sublinear but not fully succinct point. A separate branch makes the ciphertext independent of DNF size only after adopting a substantially weaker selective security notion. This contribution mattered because it exposed the exact price of plain-model realization instead of conflating model removal, adaptivity, and succinctness. The main DMPE results are not fully adaptive, and the parameters must be read together with the stated security game rather than as an unconditional optimization.","prior_boundary":"The optimal DNF-DMPE construction used a random oracle, while removing it without changing security timing or policy-size dependence was not known from the same lattice assumption.","significance_at_publication":"Makes the ROM-removal cost explicit as a security-succinctness tradeoff rather than presenting plain-model and optimal adaptive guarantees as simultaneous.","technical_delta":"Provides a plain-model k-DNF construction with sublinear k-sqrt-L ciphertext and a separate policy-size-independent construction after weakening the security notion."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-CW-OPT-DMPE-PLAIN-MODEL-DMPE-TRADEOFFS","keywords":["dmpe","dnf","optimal-succinctness","decomposed-lwe"],"limitations":[],"paper_id":"ABE-PAPER-2026-CW-OPT-DMPE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-CW-OPT-DMPE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/1464","status":"not_normalized"},"statement":"From decomposed LWE in the plain model, the preprint gives k-DNF DMPE with ciphertext size about k times the square root of the number of minterms, and a fully succinct branch only under a much weaker selective security notion.","statement_status":"source_normalized_statement","status":"preprint","title":"Plain-model k-DNF DMPE succinctness tradeoff","work_id":"ABE-PAPER-2026-CW-OPT-DMPE"},"primaryUrl":"https://eprint.iacr.org/2026/1464","sections":[{"content":"Plain-model k-DNF DMPE succinctness tradeoff","heading":"Overview"},{"content":"plain-model-dmpe-tradeoffs is the atomic contribution identifier normalized from ABE-PAPER-2026-CW-OPT-DMPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices","summary":"From decomposed LWE in the plain model, the preprint gives k-DNF DMPE with ciphertext size about k times the square root of the number of minterms, and a fully succinct branch only under a much weaker selective security notion.","title":"Plain-model k-DNF DMPE succinctness tradeoff","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-CW-OPT-DMPE-PLAIN-MODEL-DMPE-TRADEOFFS"},{"evidence":"published","id":"ABE-RESULT-2026-WW-SILENT-PLAIN-MODEL-SILENT-THRESHOLD-CRYPTOGRAPHY-FOR-EXPRESSIVE-POLICIES","keywords":["atomic-result","silent-threshold","expressive-policies","pairings","plain-model"],"metadata":{"claim_slug":"plain-model-silent-threshold-cryptography-for-expressive-policies","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Trustless threshold and distributed-policy encryption had strong succinct special cases, but expressive policies frequently required random oracles or larger policy-dependent outputs. Waters and Wu construct pairing-based silent threshold signatures and encryption for expressive access policies in the plain model. The highlighted schemes use three group elements for a signature and four for an encryption ciphertext, with static unforgeability or tag-based CCA security under the paper's N-extended bilinear assumptions. At publication this showed that expressive trustless policy enforcement and very short outputs can coexist without a random oracle in the pairing setting. It is not centralized ABE, does not remove policy-dependent setup or assumption parameters, and does not solve the post-quantum lattice DMPE reconstruction and noise barriers.","prior_boundary":"Trustless threshold and policy encryption often used random oracles or paid policy-dependent output cost, and lattice DMPE covered only restricted policies with different setup and security tradeoffs.","significance_at_publication":"Demonstrates that expressive trustless policy enforcement and very short outputs can coexist in a pairing-based plain-model API, without resolving ordinary ABE or the post-quantum lattice DMPE frontier.","technical_delta":"Gives pairing-based silent threshold signatures and encryption for expressive policies in the plain model with constant group-element output counts under the paper's N-extended assumptions."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-WW-SILENT-PLAIN-MODEL-SILENT-THRESHOLD-CRYPTOGRAPHY-FOR-EXPRESSIVE-POLICIES","keywords":["silent-threshold","expressive-policies","pairings","plain-model"],"limitations":[],"paper_id":"ABE-PAPER-2026-WW-SILENT","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-WW-SILENT § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2025/1547","status":"not_normalized"},"statement":"From pairing-based N-extended assumptions, the paper constructs plain-model silent threshold signatures and tag-based CCA-secure encryption for expressive access policies, with highlighted outputs of three and four group elements respectively under static security notions.","statement_status":"source_normalized_statement","status":"published","title":"Plain-model silent threshold cryptography for expressive policies","work_id":"ABE-PAPER-2026-WW-SILENT"},"primaryUrl":"https://eprint.iacr.org/2025/1547","sections":[{"content":"Plain-model silent threshold cryptography for expressive policies","heading":"Overview"},{"content":"plain-model-silent-threshold-cryptography-for-expressive-policies is the atomic contribution identifier normalized from ABE-PAPER-2026-WW-SILENT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain Model","summary":"From pairing-based N-extended assumptions, the paper constructs plain-model silent threshold signatures and tag-based CCA-secure encryption for expressive access policies, with highlighted outputs of three and four group elements respectively under static security notions.","title":"Plain-model silent threshold cryptography for expressive policies","type":"result","venue":"EUROCRYPT 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-WW-SILENT-PLAIN-MODEL-SILENT-THRESHOLD-CRYPTOGRAPHY-FOR-EXPRESSIVE-POLICIES"},{"evidence":"published","id":"ABE-RESULT-2026-CW-DMPE-SUCCINCT-DNF-DMPE-FROM-LATTICES","keywords":["atomic-result","dmpe","dnf","lattices","decomposed-lwe"],"metadata":{"claim_slug":"succinct-dnf-dmpe-from-lattices","contribution_kind":"research_result","dossier_type":"contribution","evidence":"published","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Distributed broadcast and silent-threshold encryption covered restricted access relations, but did not provide a lattice-based trustless encryption API for general DNF policies with transparent setup and an unbounded user population. Champion and Wu construct distributed monotone-policy encryption for DNFs from decomposed LWE in the random-oracle model. Users generate their own keys, the setup is transparent, and ciphertext overhead is polynomial in the security parameter and logarithm of the user count. At publication this created a concrete lattice DMPE branch beyond simple recipient membership. Its security is semi-policy-and-query-selective, not fully adaptive, and the proof's small-reconstruction and unauthorized-row conditions do not automatically extend from DNFs to thresholds, formulas, or arbitrary monotone span programs.","prior_boundary":"Trustless distributed encryption had succinct broadcast and threshold special cases, but lacked a lattice construction for DNF access policies with transparent setup and no a-priori user bound.","significance_at_publication":"Establishes the first audited lattice DNF-DMPE point in this dossier, while leaving general formulas, thresholds, MSPs, and fully adaptive policy-and-query security unresolved.","technical_delta":"Constructs DNF distributed monotone-policy encryption from decomposed LWE in ROM with transparent setup, unbounded users, and polylogarithmic-in-user ciphertext overhead."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-CW-DMPE-SUCCINCT-DNF-DMPE-FROM-LATTICES","keywords":["dmpe","dnf","lattices","decomposed-lwe"],"limitations":[],"paper_id":"ABE-PAPER-2026-CW-DMPE","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-CW-DMPE § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/318","status":"not_normalized"},"statement":"In ROM, decomposed LWE yields distributed monotone-policy encryption for DNF formulas with transparent setup, an unbounded user population, and ciphertext overhead polynomial in the security parameter and logarithm of the user count.","statement_status":"source_normalized_statement","status":"published","title":"Succinct DNF DMPE from decomposed LWE","work_id":"ABE-PAPER-2026-CW-DMPE"},"primaryUrl":"https://eprint.iacr.org/2026/318","sections":[{"content":"Succinct DNF DMPE from decomposed LWE","heading":"Overview"},{"content":"succinct-dnf-dmpe-from-lattices is the atomic contribution identifier normalized from ABE-PAPER-2026-CW-DMPE. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"published","subtitle":"Distributed Monotone-Policy Encryption for DNFs from Lattices","summary":"In ROM, decomposed LWE yields distributed monotone-policy encryption for DNF formulas with transparent setup, an unbounded user population, and ciphertext overhead polynomial in the security parameter and logarithm of the user count.","title":"Succinct DNF DMPE from decomposed LWE","type":"result","venue":"EUROCRYPT 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-CW-DMPE-SUCCINCT-DNF-DMPE-FROM-LATTICES"},{"evidence":"candidate","id":"ABE-RESULT-2026-AMYY-UNBOUNDED-DEPTH-ABE-FROM-DOUBLY-CIRCULAR-ASSUMPTION","keywords":["atomic-result","unbounded-depth","circular-security","falsifiable-assumption"],"metadata":{"claim_slug":"unbounded-depth-abe-from-doubly-circular-assumption","contribution_kind":"research_result","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Lattice ABE had reached unbounded-depth circuits, but the known routes depended on evasive or circular variants and did not settle simultaneous unbounded depth and width from a clean standard assumption. This preprint proposes a new doubly circular assumption combining a circular-LWE side with an ElGamal-style bilinear component, and uses it together with slotted IPFE properties to construct ABE for unbounded-depth and unbounded-width circuits. It also supplies generic-bilinear-group evidence and a restricted implication from SXDH plus circular LWE. The contribution is therefore a concrete falsifiable-assumption candidate for the fully unbounded frontier, not a theorem from plain LWE and not a purely post-quantum result; the evidentiary reductions and the construction theorem must remain distinct.","prior_boundary":"Earlier lattice unbounded-depth ABE relied on evasive or circular lattice variants and did not provide this simultaneous unbounded-depth-and-width construction under a single explicitly falsifiable assumption package.","significance_at_publication":"Offers a new falsifiable-assumption route to fully unbounded circuit structure, while its generic-group evidence and restricted implications are not a reduction from plain LWE or a purely post-quantum foundation.","technical_delta":"Introduces a doubly circular assumption combining lattice and bilinear-group components and uses it with slotted IPFE to support circuits whose depth and width are not fixed at setup."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-AMYY-UNBOUNDED-DEPTH-ABE-FROM-DOUBLY-CIRCULAR-ASSUMPTION","keywords":["unbounded-depth","circular-security","falsifiable-assumption"],"limitations":[],"paper_id":"ABE-PAPER-2026-AMYY","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-AMYY § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/1439","status":"not_normalized"},"statement":"The preprint constructs ABE for unbounded-depth and unbounded-width circuits from a new doubly circular LWE and ElGamal-style assumption together with slotted-IPFE properties, and provides generic-group and restricted SXDH-plus-circular-LWE evidence for that assumption.","statement_status":"source_normalized_statement","status":"preprint","title":"Unbounded-depth and width ABE from a doubly circular assumption","work_id":"ABE-PAPER-2026-AMYY"},"primaryUrl":"https://eprint.iacr.org/2026/1439","sections":[{"content":"Unbounded-depth and width ABE from a doubly circular assumption","heading":"Overview"},{"content":"unbounded-depth-abe-from-doubly-circular-assumption is the atomic contribution identifier normalized from ABE-PAPER-2026-AMYY. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"ABE for Unbounded Depth Circuits from the Doubly Circular Assumption","summary":"The preprint constructs ABE for unbounded-depth and unbounded-width circuits from a new doubly circular LWE and ElGamal-style assumption together with slotted-IPFE properties, and provides generic-group and restricted SXDH-plus-circular-LWE evidence for that assumption.","title":"Unbounded-depth and width ABE from a doubly circular assumption","type":"result","venue":null,"year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-AMYY-UNBOUNDED-DEPTH-ABE-FROM-DOUBLY-CIRCULAR-ASSUMPTION"},{"evidence":"candidate","id":"ABE-RESULT-2026-LZF-CONSTANT-CT-SUCCINCT-LWE-BROADCAST-ENCRYPTION","keywords":["atomic-result","cp-abe","lattice","succinct-lwe","nc1","constant-ciphertext"],"metadata":{"claim_slug":"succinct-lwe-broadcast-encryption","contribution_kind":"research_result","dossier_type":"contribution","evidence":"candidate","facet_status":"not_normalized","facets":{},"historical_context":{"narrative":"Broadcast encryption specializes policy encryption to recipient membership, so the constant-ciphertext NC1 CP-ABE construction immediately raises a distinct user-count question. The preprint derives a lattice broadcast scheme whose ciphertext size is independent of the number of users under succinct LWE. This is a separate API-level corollary rather than another formulation of the CP-ABE theorem: broadcast keys and recipient sets have their own comparison axes. On its preprint release, it added a strong ciphertext succinctness point to the lattice broadcast landscape. The card does not establish adaptive security, distributed user-generated keys, or transparent setup, and it inherits the parent construction's selective security and public-parameter qualifications. User-count-independent ciphertexts should not be read as all-parameter optimality.","prior_boundary":"Lattice broadcast encryption commonly paid recipient- or population-dependent ciphertext cost, and the paper's CP-ABE result suggested a membership-policy specialization with a different API.","significance_at_publication":"Records the broadcast consequence as a separate technical object so its user-count succinctness is visible without mislabeling it as adaptive, distributed, or transparent-setup broadcast.","technical_delta":"Specializes constant-ciphertext NC1 CP-ABE to broadcast membership, yielding ciphertext size independent of the number of users under succinct LWE."},"historical_context_status":"curator_synthesis","id":"ABE-RESULT-2026-LZF-CONSTANT-CT-SUCCINCT-LWE-BROADCAST-ENCRYPTION","keywords":["cp-abe","lattice","succinct-lwe","nc1","constant-ciphertext"],"limitations":[],"paper_id":"ABE-PAPER-2026-LZF-CONSTANT-CT","qualifiers":[],"source_locator":{"dossier_section":"ABE-PAPER-2026-LZF-CONSTANT-CT § Atomic claims","primary_source":null,"primary_source_url":"https://eprint.iacr.org/2026/534","status":"not_normalized"},"statement":"Specializing the preprint's constant-ciphertext NC1 CP-ABE yields selectively secure lattice broadcast encryption from succinct LWE whose ciphertext size is independent of the number of users, while the CP-ABE public-parameter qualifications remain.","statement_status":"source_normalized_statement","status":"preprint","title":"User-count-independent broadcast ciphertexts from succinct LWE","work_id":"ABE-PAPER-2026-LZF-CONSTANT-CT"},"primaryUrl":"https://eprint.iacr.org/2026/534","sections":[{"content":"User-count-independent broadcast ciphertexts from succinct LWE","heading":"Overview"},{"content":"succinct-lwe-broadcast-encryption is the atomic contribution identifier normalized from ABE-PAPER-2026-LZF-CONSTANT-CT. The concise statement above preserves the existing dossier claim; it does not add a stronger theorem interpretation.","heading":"Normalized statement"},{"content":"The parent paper remains the provenance object. source_locator.status records whether an exact primary-source location has already been normalized; not_normalized is explicit curation debt, not permission to infer a locator.","heading":"Evidence and locator"},{"content":"Use the parent paper card until contribution-specific qualifiers and limitations are normalized here.","heading":"Qualifiers and limitations"}],"status":"preprint","subtitle":"Ciphertext-Policy ABE for NC1 Circuits with Constant-Size Ciphertexts from Succinct LWE","summary":"Specializing the preprint's constant-ciphertext NC1 CP-ABE yields selectively secure lattice broadcast encryption from succinct LWE whose ciphertext size is independent of the number of users, while the CP-ABE public-parameter qualifications remain.","title":"User-count-independent broadcast ciphertexts from succinct LWE","type":"result","venue":"IACR ePrint 2026","year":2026,"sourcePath":"data/abe-catalog.json#ABE-RESULT-2026-LZF-CONSTANT-CT-SUCCINCT-LWE-BROADCAST-ENCRYPTION"},{"evidence":"published","id":"ABE-ROUTE-011","keywords":["entropy-expansion","predicate-composition","unbounded-abe","pairings"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-011","keywords":["entropy-expansion","predicate-composition","unbounded-abe","pairings"],"next_milestone":"Extract a model-independent late-binding interface and test whether lattice encodings can satisfy it without accumulated noise.","prerequisites":["adaptive-bounded-abe","composable-key-encoding"],"status":"completed","targets":["ABE-OP-002"],"title":"Bilinear entropy expansion and dynamic predicate composition"},"primaryUrl":null,"sections":[{"content":"Bilinear entropy expansion and dynamic predicate composition","heading":"Overview"},{"content":"Bilinear entropy expansion compiles bounded adaptive ABE into constant-public- parameter unbounded ABE. Dynamic predicate composition builds completely unbounded monotone/nonmonotone formulas from simple predicate components while preserving adaptive security under MDDH.","heading":"Established capability"},{"content":"These routes settle major pairing-based unboundedness questions but do not make all cryptographic objects succinct simultaneously and are not post- quantum.","heading":"Present boundary"},{"content":"The useful abstraction is late generation/composition of correlated policy entropy. A lattice analogue must control correctness noise and reusable-key correlations, not merely reproduce the algebraic composition graph.","heading":"Transfer question"}],"status":"completed","subtitle":"","summary":"Bilinear entropy expansion and dynamic predicate composition","title":"Bilinear entropy expansion and dynamic predicate composition","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-011"},{"evidence":"candidate","id":"ABE-ROUTE-018","keywords":["secure-key-leasing","certified-deletion","revocation","multi-input-abe"],"metadata":{"dossier_type":"route","evidence":"candidate","id":"ABE-ROUTE-018","keywords":["secure-key-leasing","certified-deletion","revocation","multi-input-abe"],"next_milestone":"A two-input classical-certificate ABE-SKL special case with an explicit reduction and size accounting","prerequisites":["collusion-resistant-key-leasing","epoch-query-game"],"status":"proposed","targets":["ABE-OP-011","ABE-OP-009"],"title":"Certified-deletion and leasing compilers for ABE lifecycle security"},"primaryUrl":null,"sections":[{"content":"Certified-deletion and leasing compilers for ABE lifecycle security","heading":"Overview"},{"content":"Use BB84/certified-deletion state to represent a revocable decryption capability, then bind ABE policy authorization to the leasing verification game. For classical certificates, isolate the exact multi-input computation currently supplied by polynomial-arity MIABE and search for a lower-arity or policy-specific replacement.","heading":"Core mechanism"},{"content":"Certified-deletion ABE supplies the deletion interface; the EUROCRYPT 2025 secure-key-leasing framework simplifies classical revocation for basic primitives; Kitagawa--Nishimaki--Pappu obtain selective collusion-resistant ABE-SKL from LWE and identify polynomial-arity MIABE as the classical- certificate dependency.","heading":"Human precedents"},{"content":"adaptive ABE-SKL security under many key and verification queries; a classical certificate path not requiring general polynomial-arity MIABE; an explicit policy/collusion binding across leased keys; and parameter accounting compatible with succinct or registered ABE.","heading":"Required new components"},{"content":"Returning a classical ABE key cannot certify loss of copies. Treating secure key leasing as ordinary epoch revocation omits quantum-state and verification- oracle attacks.","heading":"Known failures"},{"content":"Extract the exact MIABE relation used in the classical-certificate compiler and test whether conjunction or DNF ABE reduces it to two inputs.","heading":"Next bounded milestone"}],"status":"proposed","subtitle":"","summary":"Use BB84/certified-deletion state to represent a revocable decryption capability, then bind ABE policy authorization to the leasing verification game. For classical certificates, isolate the exact multi-input computation currently supplied by polynomial-arity MIABE and search for a lower-arity or policy-specific replacement.","title":"Certified-deletion and leasing compilers for ABE lifecycle security","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-018"},{"evidence":"idea","id":"ABE-ROUTE-021","keywords":["circular-lwe","decomposed-lwe","unbounded-depth","recoding"],"metadata":{"dossier_type":"route","evidence":"idea","id":"ABE-ROUTE-021","keywords":["circular-lwe","decomposed-lwe","unbounded-depth","recoding"],"next_milestone":"State a minimal circular decomposed-LWE game and derive one depth-refresh step without a bilinear/GGM component.","prerequisites":["circular-decomposed-lwe-game","depth-refresh","policy-gated-recoding"],"status":"proposed","targets":["ABE-OP-003"],"title":"Circular decomposed-LWE recursion for unbounded-depth ABE"},"primaryUrl":null,"sections":[{"content":"Circular decomposed-LWE recursion for unbounded-depth ABE","heading":"Overview"},{"content":"Try to use the structured compact-recoding power of decomposed LWE as the lattice-only component that carries one recursive ABE evaluation step, while a separately stated circular/KDM clause makes that step reusable without fixing the final circuit depth.","heading":"Core mechanism"},{"content":"Hsieh--Lin--Luo use evasive circular LWE to remove depth bounds, but the assumption was attacked. Agrawal--Modi--Yadav--Yamada replace it with a doubly-circular LWE/ElGamal-style assumption whose evidence still couples a lattice part to a bilinear-group/GGM part. Modern decomposed-LWE ABE and distributed-encryption schemes show that compact recoding is available in a falsifiable lattice game at bounded depth.","heading":"Human precedents"},{"content":"a fixed circular decomposed-LWE game, independent of the adversary's chosen policy or circuit instance; one correctness-preserving refresh/recoding step with stable noise; policy-gated extraction for rejecting keys under polynomial collusion; and a reduction or independent evidence separating circularity from evasiveness.","heading":"Required new components"},{"content":"Simply conjoining circular LWE with a recoding assumption can hide the same zeroizing or instance-dependent weakness as evasive circular LWE. Likewise, bounded-depth decomposed evaluation does not become recursive merely because its output is short.","heading":"Known failures"},{"content":"Write the assumption as three explicit distributions—real decomposed samples, circular auxiliary material, and policy-gated challenge—and prove a single refresh lemma. Then test whether deleting any one clause either preserves the lemma or produces a concrete attack. This modular audit precedes a full ABE construction.","heading":"Next bounded milestone"}],"status":"proposed","subtitle":"","summary":"Try to use the structured compact-recoding power of decomposed LWE as the lattice-only component that carries one recursive ABE evaluation step, while a separately stated circular/KDM clause makes that step reusable without fixing the final circuit depth.","title":"Circular decomposed-LWE recursion for unbounded-depth ABE","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-021"},{"evidence":"published","id":"ABE-ROUTE-004","keywords":["circular-security","unbounded-depth","turing-machines"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-004","keywords":["circular-security","unbounded-depth","turing-machines"],"next_milestone":"Separate the circular evaluation and evasive recoding roles into independently testable assumptions.","prerequisites":["reusable-evaluation","policy-gated-extraction"],"status":"active","targets":["ABE-OP-003","ABE-OP-007"],"title":"Circular recursion for unbounded computation"},"primaryUrl":null,"sections":[{"content":"Circular recursion for unbounded computation","heading":"Overview"},{"content":"Circular security enables cryptographic evaluation material to refresh or consume encryptions of its own secret state, removing a fixed depth budget. Full ABE additionally needs an evasive/policy-gated extraction property. HLL and lattice Turing-machine ABE instantiate combinations of these roles.","heading":"Core mechanism and precedents"},{"content":"The evasive-circular assumption used for one full ABE route was reported broken. New combined assumptions need more than generic evidence: each role, instance dependence, and quantum status must be explicit.","heading":"Known failures"},{"content":"Factor a recent unbounded-depth proof into a circular evaluation lemma and a minimal policy-recoding lemma, then determine whether the latter has a standalone lattice formulation unaffected by the known attack.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Circular security enables cryptographic evaluation material to refresh or consume encryptions of its own secret state, removing a fixed depth budget. Full ABE additionally needs an evasive/policy-gated extraction property. HLL and lattice Turing-machine ABE instantiate combinations of these roles.","title":"Circular recursion for unbounded computation","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-004"},{"evidence":"published","id":"ABE-ROUTE-015","keywords":["adaptive-security","deletion","constrained-prf","compiler"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-015","keywords":["adaptive-security","deletion","constrained-prf","compiler"],"next_milestone":"Test whether a nontrivial formula family admits deletion conformity while preserving compact reusable keys.","prerequisites":["attribute-deletion","deletion-conforming-prf"],"status":"proposed","targets":["ABE-OP-001","ABE-OP-002"],"title":"Deletion-conforming adaptive-security compiler"},"primaryUrl":null,"sections":[{"content":"Deletion-conforming adaptive-security compiler","heading":"Overview"},{"content":"For subset functionality, deleting challenge attributes and using a deletion- conforming constrained PRF yields adaptive ABE from a search pairing assumption, outside the standard dual-system route.","heading":"Established capability"},{"content":"The mechanism changes the information available after the challenge rather than equivocating all earlier keys. A broader deletion-conforming function class could provide a significant adaptive-security compiler.","heading":"Research potential"},{"content":"General formulas can query or recombine many coordinates, and deletion may destroy correctness or leak the accepting branch. The right first target is a bounded formula class, not arbitrary circuits.","heading":"Main risk"}],"status":"proposed","subtitle":"","summary":"Deletion-conforming adaptive-security compiler","title":"Deletion-conforming adaptive-security compiler","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-015"},{"evidence":"published","id":"ABE-ROUTE-010","keywords":["dual-system","predicate-encodings","adaptive-security","pairings"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-010","keywords":["dual-system","predicate-encodings","adaptive-security","pairings"],"next_milestone":"Identify a lattice state that realizes the joint semi-functional key/ciphertext invariants rather than copying group syntax.","prerequisites":["semi-functional-subspaces","nominal-semi-functionality"],"status":"completed","targets":["ABE-OP-001","ABE-OP-002","ABE-OP-005"],"title":"Dual-system encryption and predicate encodings"},"primaryUrl":null,"sections":[{"content":"Dual-system encryption and predicate encodings","heading":"Overview"},{"content":"Dual-system encryption solved adaptive security for expressive pairing ABE by moving through semi-functional keys and ciphertexts. Predicate encodings then made the required algebra modular and portable across policy classes.","heading":"Established capability"},{"content":"The reusable insight is a sequence of indistinguishable modes with controlled failure only at accepting pairs. Composite/prime-order subgroup algebra does not directly translate to noisy lattice preimages or their multi-key joint distribution.","heading":"What transfers and what does not"},{"content":"Specify the smallest lattice analogue of one nominally semi-functional hybrid for two rejecting keys and one accepting key, including the honest joint kernel entropy.","heading":"Next bounded milestone"}],"status":"completed","subtitle":"","summary":"Specify the smallest lattice analogue of one nominally semi-functional hybrid for two rejecting keys and one accepting key, including the honest joint kernel entropy.","title":"Dual-system encryption and predicate encodings","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-010"},{"evidence":"published","id":"ABE-ROUTE-006","keywords":["equivocation","matrix-commitments","adaptive-security"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-006","keywords":["equivocation","matrix-commitments","adaptive-security"],"next_milestone":"Realize one threshold witness-dependent recoding equation with jointly equivocal short openings.","prerequisites":["joint-equivocation","short-openings","policy-recoding-equation"],"status":"active","targets":["ABE-OP-004","ABE-OP-005","ABE-OP-006"],"title":"Equivocal matrix and policy commitments"},"primaryUrl":null,"sections":[{"content":"Equivocal matrix and policy commitments","heading":"Overview"},{"content":"Commit before a late directory/policy/challenge is known, then open the same state consistently to the correlated matrix or preimage required by the security simulation. Equivocal matrix commitments already support adaptive FBE/IBBE in ROM.","heading":"Core mechanism and precedents"},{"content":"Threshold DMPE needs a policy commitment whose opening directly satisfies the witness-dependent lattice recoding equation, with all coalition openings jointly simulatable and short. Ordinary mercurial functional commitments open the opposite input/function direction and do not supply this equation.","heading":"Required new component"},{"content":"Specify a two-coalition threshold toy commitment and either construct it from an existing dual-mode matrix commitment or derive a concrete conflicting- opening/SIS barrier.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Commit before a late directory/policy/challenge is known, then open the same state consistently to the correlated matrix or preimage required by the security simulation. Equivocal matrix commitments already support adaptive FBE/IBBE in ROM.","title":"Equivocal matrix and policy commitments","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-006"},{"evidence":"candidate","id":"ABE-ROUTE-020","keywords":["equivocal-encryption","adaptive-abe","nc1","joint-distributions"],"metadata":{"dossier_type":"route","evidence":"candidate","id":"ABE-ROUTE-020","keywords":["equivocal-encryption","adaptive-abe","nc1","joint-distributions"],"next_milestone":"Pass the challenge-{a}, keys-b-and-(a-AND-b) joint real/fake distribution test.","prerequisites":["policy-level-noncommitting-state","joint-key-ciphertext-sampling","honest-kernel-entropy"],"status":"active","targets":["ABE-OP-012","ABE-OP-001","ABE-OP-002"],"title":"Equivocal-encryption lift from broadcast sets to reusable NC1 policies"},"primaryUrl":null,"sections":[{"content":"Equivocal-encryption lift from broadcast sets to reusable NC1 policies","heading":"Overview"},{"content":"Use the real/fake timing of Goyal--Yadugiri's equivocal encryption systems: sample fake public state, keys, and ciphertexts jointly before the late challenge, retain auxiliary trapdoors, and only then explain the challenge ciphertext. Replace the broadcast recipient predicate by a formula/LSSS policy relation while preserving honest kernel entropy in every issued key.","heading":"Core mechanism"},{"content":"Goyal--Yadugiri 2026/792 demonstrates the timing mechanism for optimal adaptive lattice distributed broadcast encryption. Pairing dual-system ABE demonstrates that a reusable policy key can carry a hidden semi-functional mode. The current repository's formula construction and consistent- independent LSSS compiler expose the exact correlated-row channel that a lattice lift must reproduce.","heading":"Human precedents"},{"content":"one fake state that supports polynomially many adaptively selected rejecting policies, rather than independent recipient coordinates; exact joint sampling of repeated-label and shared-target rows; post-challenge openings/keys distributed as honest spherical cosets; and an accepting channel whose correctness noise does not grow beyond the scheme's bound.","heading":"Required new components"},{"content":"Independent canonical preimages can be individually distributed correctly while their difference exposes the shared master offset to two legal keys. Similarly, a commitment that equivocates messages but cannot jointly sample the corresponding short row preimages does not instantiate this route.","heading":"Known failures"},{"content":"Formalize an EES-style toy system for challenge attribute {a} with reusable keys for b and a AND b. Require equality of the complete joint transcript, not only marginal key distributions. A construction or an explicit distinguishing/SIS witness decides the first branch before scaling to formulas.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Use the real/fake timing of Goyal--Yadugiri's equivocal encryption systems: sample fake public state, keys, and ciphertexts jointly before the late challenge, retain auxiliary trapdoors, and only then explain the challenge ciphertext. Replace the broadcast recipient predicate by a formula/LSSS policy relation while preserving honest kernel entropy in every issued key.","title":"Equivocal-encryption lift from broadcast sets to reusable NC1 policies","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-020"},{"evidence":"manual-proof-complete","id":"ABE-ROUTE-002","keywords":["lattice-abe","share-completion","selective-security"],"metadata":{"dossier_type":"route","evidence":"manual-proof-complete","id":"ABE-ROUTE-002","keywords":["lattice-abe","share-completion","selective-security"],"next_milestone":"Instantiate a second non-DKW sharing family or derive a semi-adaptive version.","prerequisites":["consistent-independent-sharing","explainable-gaussian-sampling"],"status":"active","targets":["ABE-OP-001","ABE-OP-002"],"title":"False-pivot share completion"},"primaryUrl":null,"sections":[{"content":"False-pivot share completion","heading":"Overview"},{"content":"Generate matched shares first, sample the global sharing vector from their affine fiber, and complete each challenge-false row at its prescribed correlated share. This transposes an encryption-time false-user simulation into reusable authority key generation.","heading":"Core mechanism"},{"content":"The route combines lattice preimage sampling, false-user programming from distributed encryption, and consistent-independent LSSS structure. The paired full-row affine completion mechanism is the repository's new synthesis.","heading":"Human precedents"},{"content":"The proof currently uses selective challenge knowledge and programmable oracles. It is instantiated for DKW formulas and signed DNF, not arbitrary span programs.","heading":"Known limitation"},{"content":"Provide one natural polynomial-row consistent-independent sharing family not efficiently represented by DKW formulas, then rerun the correlation and Gaussian proof audit.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Generate matched shares first, sample the global sharing vector from their affine fiber, and complete each challenge-false row at its prescribed correlated share. This transposes an encryption-time false-user simulation into reusable authority key generation.","title":"False-pivot share completion","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-002"},{"evidence":"published","id":"ABE-ROUTE-008","keywords":["functional-encryption","obfuscation","feasibility"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-008","keywords":["functional-encryption","obfuscation","feasibility"],"next_milestone":"Extract the weakest direct primitive actually used by the compiler for one ABE endpoint.","prerequisites":["polynomially-secure-fe-or-io"],"status":"completed","targets":["ABE-OP-003","ABE-OP-007"],"title":"Generic FE or obfuscation compiler"},"primaryUrl":null,"sections":[{"content":"Generic FE or obfuscation compiler","heading":"Overview"},{"content":"Invoke general FE, compact FE, witness encryption, or iO to obtain expressive, unbounded, or optimally succinct ABE. This is an established feasibility route and supplies upper bounds on what is possible.","heading":"Core mechanism"},{"content":"It moves the main construction problem into a stronger primitive and therefore does not settle open problems explicitly asking for a direct LWE/pairing construction. It remains valuable as a blueprint for the minimal interface a direct construction must emulate.","heading":"Limitation"},{"content":"For RAM ABE, isolate one compiler component weaker than general FE and state a standalone security definition that could plausibly be built from lattices.","heading":"Next bounded milestone"}],"status":"completed","subtitle":"","summary":"Invoke general FE, compact FE, witness encryption, or iO to obtain expressive, unbounded, or optimally succinct ABE. This is an established feasibility route and supplies upper bounds on what is possible.","title":"Generic FE or obfuscation compiler","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-008"},{"evidence":"published","id":"ABE-ROUTE-012","keywords":["lwe","homomorphic-evaluation","delayed-programming","noisy-lsss"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-012","keywords":["lwe","homomorphic-evaluation","delayed-programming","noisy-lsss"],"next_milestone":"Separate one proof into evaluation, delayed-programming, and rejecting-instance interfaces and replace exactly one strong component.","prerequisites":["trapdoor-delegation","noise-control","rejecting-instance-simulation"],"status":"active","targets":["ABE-OP-001","ABE-OP-002","ABE-OP-003","ABE-OP-007"],"title":"Homomorphic lattice evaluation, delayed programming, and noisy LSSS"},"primaryUrl":null,"sections":[{"content":"Homomorphic lattice evaluation, delayed programming, and noisy LSSS","heading":"Overview"},{"content":"GVW and BGG+ encode circuit evaluation into LWE matrices. Brakerski– Vaikuntanathan delay challenge programming to obtain unbounded attributes and semi-adaptivity. HLL combine noisy LSSS with evasive IPFE for succinct circuits and automata; succinct/decomposed LWE later improves object sizes.","heading":"Historical progression"},{"content":"Plain LWE gives strong feasibility but not the best adaptivity and size point. The strongest succinct/general results use strengthened recoding or evasive assumptions. The route must therefore be decomposed by function, not treated as one monolithic “lattice ABE technique.”","heading":"Present boundary"}],"status":"active","subtitle":"","summary":"Homomorphic lattice evaluation, delayed programming, and noisy LSSS","title":"Homomorphic lattice evaluation, delayed programming, and noisy LSSS","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-012"},{"evidence":"published","id":"ABE-ROUTE-017","keywords":["policy-hiding","attribute-hiding","lockable-obfuscation","predicate-encryption"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-017","keywords":["policy-hiding","attribute-hiding","lockable-obfuscation","predicate-encryption"],"next_milestone":"A formula-ABE game hiding labels and polarity while leaking topology, plus an iO-implication audit","prerequisites":["explicit-policy-leakage-function","adaptive-cross-query-consistency"],"status":"proposed","targets":["ABE-OP-010"],"title":"Leakage-profile compilers for policy-private ABE"},"primaryUrl":null,"sections":[{"content":"Leakage-profile compilers for policy-private ABE","heading":"Overview"},{"content":"Start from the lockable-obfuscation ABE-to-PE compiler and from weakened function-hiding definitions, but make the allowed leakage a first-class function. Hide labels, polarity, or selected subformulas while deliberately leaking topology/size, so the construction does not promise the iO-complete natural full function-hiding notion.","heading":"Core mechanism"},{"content":"LOSSTW and Chen--Gong--Wee establish adaptive attribute hiding for IPE. Agrawal--Yamada give the circuit compiler, the iO implication, and a weakened positive notion. Wang et al. show selective fully attribute-hiding lattice PE for bounded-collusion bounded-depth circuits.","heading":"Human precedents"},{"content":"a public, composable leakage function; a simulator consistent across repeated labels and arbitrary key queries; an admissibility rule that is useful but does not encode full iO; and size preservation for one modern succinct/unbounded ABE base.","heading":"Required new components"},{"content":"Demanding the natural full function-hiding circuit-ABE game crosses the iO barrier. Merely encrypting textual policy labels does not hide topology or prevent dictionary attacks.","heading":"Known failures"},{"content":"Define a signed-formula game that leaks formula topology but hides leaf labels and polarity. Either give a compiler for conjunctions under adaptive key queries or derive an explicit reconstruction/iO-style attack.","heading":"Next bounded milestone"}],"status":"proposed","subtitle":"","summary":"Start from the lockable-obfuscation ABE-to-PE compiler and from weakened function-hiding definitions, but make the allowed leakage a first-class function. Hide labels, polarity, or selected subformulas while deliberately leaking topology/size, so the construction does not promise the iO-complete natural full function-hiding notion.","title":"Leakage-profile compilers for policy-private ABE","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-017"},{"evidence":"machine-verified-scoped","id":"ABE-ROUTE-009","keywords":["pair-encodings","ggm","concrete-efficiency"],"metadata":{"dossier_type":"route","evidence":"machine-verified-scoped","id":"ABE-ROUTE-009","keywords":["pair-encodings","ggm","concrete-efficiency"],"next_milestone":"Produce a standard-model semi-functional explanation for one GGM-optimal cancellation.","prerequisites":["correct-pair-encoding","adaptive-proof-interface"],"status":"active","targets":["ABE-OP-008"],"title":"Pair-encoding efficiency and cancellation search"},"primaryUrl":null,"sections":[{"content":"Pair-encoding efficiency and cancellation search","heading":"Overview"},{"content":"Search algebraic encodings for fewer group elements/pairings while preserving LSSS correctness, then use GGM/PES backends to reject trivial leakage and template gaming.","heading":"Core mechanism"},{"content":"An algebraic GGM pass does not supply an adaptive standard-model reduction. Some improvements are optimal only inside a fixed template and have no new cryptographic mechanism.","heading":"Known limitation"},{"content":"Take one verified cancellation and construct the semi-functional key and ciphertext subspaces needed for a static-assumption hybrid, or prove a scoped dimension obstruction.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Search algebraic encodings for fewer group elements/pairings while preserving LSSS correctness, then use GGM/PES backends to reject trivial leakage and template gaming.","title":"Pair-encoding efficiency and cancellation search","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-009"},{"evidence":"locally-checked","id":"ABE-ROUTE-003","keywords":["adaptive-security","noncommitting-state","preimages"],"metadata":{"dossier_type":"route","evidence":"locally-checked","id":"ABE-ROUTE-003","keywords":["adaptive-security","noncommitting-state","preimages"],"next_milestone":"Pass the {b, a AND b} rejecting-key test while an accepting conjunction cancels a large pad.","prerequisites":["joint-multi-key-simulation","policy-separating-cancellation"],"status":"active","targets":["ABE-OP-001","ABE-OP-002"],"title":"Policy-level noncommitting preimage state"},"primaryUrl":null,"sections":[{"content":"Policy-level noncommitting preimage state","heading":"Overview"},{"content":"Commit to a reusable hidden state before the challenge, then after the challenge explain all legal keys with the same correlated distribution as honest key generation. A policy-local pad must survive every rejecting key combination and cancel only at an accepting reconstruction endpoint.","heading":"Core mechanism"},{"content":"Dual-system encryption, noncommitting encryption, lossy/trapdoor modes, equivocal encryption, and equivocal matrix commitments all solve related timing problems. None directly supplies the required reusable ABE joint multi-policy distribution.","heading":"Human precedents"},{"content":"Independent canonical preimages and shared-preimage rerandomization fail exact two-key tests: legal rejecting keys can recover a short master-difference representative or induce a distinguishable joint channel. Kernel entropy fixes individual marginals but not policy-level collusion.","heading":"Known failures"},{"content":"Construct or rule out the smallest algebraic PSEC/OEAP interface for challenge {a} with rejecting keys for b and a AND b and one accepting key.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Commit to a reusable hidden state before the challenge, then after the challenge explain all legal keys with the same correlated distribution as honest key generation. A policy-local pad must survive every rejecting key combination and cancel only at an accepting reconstruction endpoint.","title":"Policy-level noncommitting preimage state","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-003"},{"evidence":"locally-checked","id":"ABE-ROUTE-007","keywords":["pairings","projectability","unbounded-abe"],"metadata":{"dossier_type":"route","evidence":"locally-checked","id":"ABE-ROUTE-007","keywords":["pairings","projectability","unbounded-abe"],"next_milestone":"Find an unbounded inner primitive exposing the exact source-group linear image needed by the outer ABE compiler.","prerequisites":["source-group-projectability","semi-functional-subspace"],"status":"blocked","targets":["ABE-OP-002","ABE-OP-005","ABE-OP-008"],"title":"Projectable inner-primitive pairing compiler"},"primaryUrl":null,"sections":[{"content":"Projectable inner-primitive pairing compiler","heading":"Overview"},{"content":"Use a function-hiding inner primitive with a publicly projectable source-group image to bind late attributes or policies while keeping public parameters compact. This is one specific outer-compiler route, not the historical dual-system paradigm as a whole.","heading":"Core mechanism"},{"content":"The currently audited unbounded IPFE candidates do not expose the source-group projectability needed by the outer LL20b-style compiler. Target-group lifts and nonlinear templates lose the linear image required for simulation.","heading":"Known failure"},{"content":"A different inner primitive, non-reroutable public composition, or new semi-functional subspace could satisfy the interface. Historical dual-system ABE is successful and is recorded separately in ABE-ROUTE-010; this scoped failure is not an impossibility for pairing-based completely-unbounded succinct ABE.","heading":"What remains possible"},{"content":"Before proposing a full scheme, exhibit a two-coordinate unbounded functional key whose source-group output is publicly projectable and whose false-policy distribution has a static-assumption proof.","heading":"Next bounded milestone"}],"status":"blocked","subtitle":"","summary":"Use a function-hiding inner primitive with a publicly projectable source-group image to bind late attributes or policies while keeping public parameters compact. This is one specific outer-compiler route, not the historical dual-system paradigm as a whole.","title":"Projectable inner-primitive pairing compiler","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-007"},{"evidence":"published","id":"ABE-ROUTE-014","keywords":["registered-abe","key-aggregation","transparent-curation","trustless"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-014","keywords":["registered-abe","key-aggregation","transparent-curation","trustless"],"next_milestone":"Normalize bounded-user, curator, corruption, and setup assumptions across the pairing and lattice registered-ABE schemes.","prerequisites":["malicious-key-handling","compact-directory-commitment","policy-decryption"],"status":"active","targets":["ABE-OP-005","ABE-OP-006"],"title":"Registration, transparent curation, and key aggregation"},"primaryUrl":null,"sections":[{"content":"Registration, transparent curation, and key aggregation","heading":"Overview"},{"content":"Registered ABE replaces trusted issuance with user-generated keys and a deterministic curator. Pairing schemes introduced the API; progression-free sets compressed the CRS; witness-encryption and succinct-LWE branches expanded functionality/assumptions; multi-authority registered ABE combined independent curators.","heading":"Historical progression"},{"content":"No known construction simultaneously has unbounded users, general policies, small transparent setup, strong adaptive security, and a clean post-quantum assumption without iO or a random oracle.","heading":"Present boundary"}],"status":"active","subtitle":"","summary":"Registration, transparent curation, and key aggregation","title":"Registration, transparent curation, and key aggregation","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-014"},{"evidence":"candidate","id":"ABE-ROUTE-005","keywords":["lsss","threshold","small-coefficients","multi-row"],"metadata":{"dossier_type":"route","evidence":"candidate","id":"ABE-ROUTE-005","keywords":["lsss","threshold","small-coefficients","multi-row"],"next_milestone":"Construct a growing-threshold multi-row LSSS satisfying the exact DMPE independence interface.","prerequisites":["unauthorized-row-independence","bounded-reconstruction-norm","one-hint-per-user"],"status":"active","targets":["ABE-OP-004"],"title":"Small-coefficient multi-row sharing compiler"},"primaryUrl":null,"sections":[{"content":"Small-coefficient multi-row sharing compiler","heading":"Overview"},{"content":"Permit several LSSS rows per user to escape the one-row reconstruction-height barrier, then compress the user's repeated occurrences into one public hint or key contribution. The compiler must preserve small reconstruction norm and unauthorized-row independence simultaneously.","heading":"Core mechanism"},{"content":"Binary/small-coefficient secret sharing, erasure-code constructions, and Champion–Wu's repeated-user/single-hint DNF technique provide separate pieces. Their generic composition is not known.","heading":"Human precedents"},{"content":"Small coefficients alone do not imply the independence property used by the lattice reduction. Reusing one hint across rows can introduce correlations that invalidate security or amplify noise.","heading":"Known failures"},{"content":"Give an explicit t(n) growing-threshold family, its row-to-user map, and a proof of the exact authorized reconstruction and unauthorized independence conditions before adding cryptographic commitments.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Permit several LSSS rows per user to escape the one-row reconstruction-height barrier, then compress the user's repeated occurrences into one public hint or key contribution. The compiler must preserve small reconstruction norm and unauthorized-row independence simultaneously.","title":"Small-coefficient multi-row sharing compiler","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-005"},{"evidence":"published","id":"ABE-ROUTE-016","keywords":["multi-input-abe","succinctness","witness-encryption","lattices"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-016","keywords":["multi-input-abe","succinctness","witness-encryption","lattices"],"next_milestone":"Determine whether constant-arity evasive-LWE MIABE composes recursively without an exponential security or noise loss.","prerequisites":["cross-input-collusion-resistance","compact-encoding","arity-composition"],"status":"active","targets":["ABE-OP-009"],"title":"Succinct single-input to multi-input ABE connection"},"primaryUrl":null,"sections":[{"content":"Succinct single-input to multi-input ABE connection","heading":"Overview"},{"content":"Techniques developed for succinct CP-ABE unexpectedly yield two-input KP-ABE; evasive/tensor LWE later extends NC1 to every constant arity. Multi-input ABE also improves witness-encryption compression and compiles to multi-input PE.","heading":"Established capability"},{"content":"Known clean rigorous points stop at constant arity or use nonstandard algebraic/knowledge assumptions. Polynomial arity is not a formal corollary of repeating a constant-arity scheme because keys and security games couple all inputs.","heading":"Present boundary"}],"status":"active","subtitle":"","summary":"Succinct single-input to multi-input ABE connection","title":"Succinct single-input to multi-input ABE connection","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-016"},{"evidence":"published","id":"ABE-ROUTE-019","keywords":["projective-prg","adaptive-security","crs-compression","lattices"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-019","keywords":["projective-prg","adaptive-security","crs-compression","lattices"],"next_milestone":"Either compress the LWE pPRG public parameters below linear in the output length, with a path to universal setup, or prove a scoped black-box lower bound.","prerequisites":["public-sampleability","adaptive-pseudorandomness","succinct-projected-seeds"],"status":"proposed","targets":["ABE-OP-006"],"title":"Succinct-public-parameter publicly-sampleable projective PRGs"},"primaryUrl":null,"sections":[{"content":"Succinct-public-parameter publicly-sampleable projective PRGs","heading":"Overview"},{"content":"Hsieh--Waters--Wu compile semi-static broadcast encryption into adaptive security using a projective PRG whose seed can be projected to a late chosen recipient set and whose projected seed can also be sampled publicly. A PRG with output length \\(\\ell\\) and the weaker succinct bounds \\[ |\\mathsf{pp}|,|\\widehat\\sigma_S| =\\operatorname{poly}(\\lambda,\\log\\ell) \\] would remove the linear setup term from this route and is a concrete candidate for the standard-model succinct-CRS branch of ABE-OP-006. The full late-bound target is stronger: run \\(\\mathsf{Setup}(1^\\lambda)\\) once and obtain \\(|\\mathsf{pp}|=\\operatorname{poly}(\\lambda)\\) while choosing \\(\\ell\\) only later. A setup that takes \\(1^\\ell\\) and emits \\(\\operatorname{poly}(\\lambda,\\log\\ell)\\) bits is a valuable intermediate result, not a resolution of transparent unbounded setup.","heading":"Core mechanism"},{"content":"Definition 4.1 and Theorem 5.3 of Hsieh--Waters--Wu isolate correctness, sampling indistinguishability, and adaptive pseudorandomness as the compiler interface. Their LWE Construction 6.21 and Theorems 6.22--6.25 realize it, but \\(\\mathsf{pp}=(A,d,\\{c_i,z_i\\}_{i\\in[\\ell]})\\) is linear in \\(\\ell\\). Goyal--Yadugiri 2026/792 reaches optimal adaptive lattice DBE with a succinct CRS in ROM and a long CRS in the standard model, exposing the same missing compression axis.","heading":"Human precedents"},{"content":"public sampling of a projection for an arbitrary late set \\(S\\); adaptive pseudorandomness after evaluation leakage outside \\(S\\); a public description that does not list one independently programmable object per output coordinate; and for the strongest endpoint, a universal setup whose distribution does not depend on the later output length; compatibility with a falsifiable post-quantum assumption.","heading":"Required new components"},{"content":"A conventional succinct PRG is not enough: encryption must publicly sample a projected seed consistent with the hidden full seed distribution. Merely hashing the \\((c_i,z_i)\\) table does not give the evaluator authenticated local access without reintroducing a random oracle, a Merkle opening per recipient, or a stronger proof system.","heading":"Known failures"},{"content":"Replace the explicit coordinate table in Construction 6.21 by one structured matrix/PRF seed and test all three Definition 4.1 properties. In parallel, formulate a black-box model in which public sampleability plus adaptive evaluation forces \\(\\Omega(\\ell)\\) public information; either outcome is a useful route decision. If sublinear compression succeeds, next test whether the setup can be made universal rather than merely logarithmic in a fixed \\(\\ell\\).","heading":"Next bounded milestone"}],"status":"proposed","subtitle":"","summary":"Hsieh--Waters--Wu compile semi-static broadcast encryption into adaptive security using a projective PRG whose seed can be projected to a late chosen recipient set and whose projected seed can also be sampled publicly. A PRG with output length \\(\\ell\\) and the weaker succinct bounds \\[ |\\mathsf{pp}|,|\\widehat\\sigma_S| =\\operatorname{poly}(\\lambda,\\log\\ell) \\] would remove the linear setup term from this route and…","title":"Succinct-public-parameter publicly-sampleable projective PRGs","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-019"},{"evidence":"published","id":"ABE-ROUTE-001","keywords":["succinct-lwe","decomposed-lwe","lattice-evaluation"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-001","keywords":["succinct-lwe","decomposed-lwe","lattice-evaluation"],"next_milestone":"Identify a plain-LWE replacement for one exact succinct/decomposed recoding interface.","prerequisites":["succinct-lattice-evaluation","short-preimage-sampling"],"status":"active","targets":["ABE-OP-001","ABE-OP-002","ABE-OP-005"],"title":"Succinct/decomposed lattice evaluation"},"primaryUrl":null,"sections":[{"content":"Succinct/decomposed lattice evaluation","heading":"Overview"},{"content":"Succinct or decomposed LWE supplies compact evaluation/recoding objects that prevent public parameters or ciphertexts from scaling with the full input or policy. It underlies almost-optimal circuit ABE, registered ABE, DMPE, and adaptive broadcast results.","heading":"Core mechanism and precedents"},{"content":"A plain-LWE route must replace the exact compact recoding capability, not only reduce noise. Candidate replacements include policy-gated exact release, bounded-norm future-opening recoders, or a more local assumption with an independent reduction.","heading":"Required new component"},{"content":"In the current formula construction, independent stationary row noise mixes modulo q at polynomial modulus/noise ratio as rows grow. Parameter tuning inside that architecture cannot supply polynomial-ratio correctness.","heading":"Known failures"},{"content":"Write one accepting-row channel whose total decryption noise is independent of formula size, then prove its rejecting rows reveal no master preimage in the one-key toy game.","heading":"Next bounded milestone"}],"status":"active","subtitle":"","summary":"Succinct or decomposed LWE supplies compact evaluation/recoding objects that prevent public parameters or ciphertexts from scaling with the full input or policy. It underlies almost-optimal circuit ABE, registered ABE, DMPE, and adaptive broadcast results.","title":"Succinct/decomposed lattice evaluation","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-001"},{"evidence":"published","id":"ABE-ROUTE-013","keywords":["witness-encryption","adaptive-security","registered-abe","function-binding"],"metadata":{"dossier_type":"route","evidence":"published","id":"ABE-ROUTE-013","keywords":["witness-encryption","adaptive-security","registered-abe","function-binding"],"next_milestone":"Identify whether the policy-level accepting/rejecting statement used by the compiler admits a direct lattice realization weaker than witness encryption.","prerequisites":["witness-encryption","statistically-sound-nizk","function-binding-hash"],"status":"active","targets":["ABE-OP-002","ABE-OP-003","ABE-OP-005"],"title":"Witness-encryption compilers and function-binding hashes"},"primaryUrl":null,"sections":[{"content":"Witness-encryption compilers and function-binding hashes","heading":"Overview"},{"content":"Plain witness encryption plus auxiliary primitives gives a third route to adaptive ABE and removes iO from feasibility constructions of registered ABE and flexible broadcast encryption. Function-binding hashes permit statements to be bound at the function-output level.","heading":"Established capability"},{"content":"Witness encryption is substantially stronger than plain LWE and current efficient ABE assumptions. The route is most valuable as a specification of the noncommitting policy statement a direct construction must emulate.","heading":"Present boundary"}],"status":"active","subtitle":"","summary":"Witness-encryption compilers and function-binding hashes","title":"Witness-encryption compilers and function-binding hashes","type":"route","venue":null,"year":null,"sourcePath":"data/abe-catalog.json#ABE-ROUTE-013"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW":{"anchor_roles":["model_definition","first_feasibility"],"group":"foundation","label":"Fuzzy IBE → ABE","lane_rationale":"Introduces threshold-overlap decryption and the attribute-based interpretation, establishing the research object rather than merely improving a later scheme.","lenses":["policy_expressiveness"],"primary":true,"selection_rationale":"Starting the history at later policy systems would hide the conceptual move from exact identity matching to decryption governed by overlapping descriptive attributes. This node records the interface change that made ABE a recognizable research program.","thread":"roots_policy","visibility":"backbone"},"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES":{"anchor_roles":["model_definition","first_feasibility","reusable_mechanism"],"group":"foundation","label":"Key-policy ABE","lane_rationale":"Formalizes the key-policy interface and expressive access-structure contract; its primary map role is defining KP-ABE.","lenses":["policy_expressiveness"],"primary":true,"selection_rationale":"GPSW fixes the KP-ABE orientation and the linear-secret-sharing language used to express collusion-resistant policies. Omitting it would make later access structures look like an incremental extension of fuzzy thresholds rather than a new policy interface.","thread":"roots_policy","visibility":"backbone"},"ABE-RESULT-2007-BSW-ADAPTIVE-GENERIC-GROUP-SECURITY":{"group":"foundation","label":"Generic-group analysis","lane_rationale":"Separately records the adaptive generic-group security analysis and its random-oracle boundary, not a stronger-secure replacement scheme.","lenses":["adaptive_cca_security"],"selection_rationale":"The adaptive generic-group argument is kept as a separate security contribution so the map does not silently promote the original CP-ABE construction to a standard-model theorem. It exposes the idealized group and random-oracle boundary of the 2007 result.","thread":"pairing_constructions","visibility":"reviewed_related"},"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION":{"anchor_roles":["model_definition","first_feasibility","capability_boundary"],"group":"construction","label":"Ciphertext-policy ABE","lane_rationale":"The atomic claim is the first concrete CP-ABE construction with ciphertext access trees and attribute-bearing keys; first realization alone does not imply Foundation.","lenses":["policy_expressiveness"],"primary":true,"selection_rationale":"This construction reverses the KP placement of policy and attributes so that an encryptor can state the access rule in the ciphertext. Without it, the map would not explain why CP-ABE became a distinct interface rather than merely another pairing instantiation.","thread":"pairing_constructions","visibility":"backbone"},"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY":{"anchor_roles":["model_definition","first_feasibility","capability_boundary"],"group":"construction","label":"Decentralized MA-ABE","lane_rationale":"Realizes decentralized issuance through independent authorities and identity-bound shares; the concrete authority architecture is the principal claim.","lenses":["authority_registration"],"primary":true,"selection_rationale":"This node changes the trust architecture from one master issuer to independent attribute authorities whose shares are bound to a global identity. Without it, later lattice, adaptive-corruption, and registered multi-authority work would appear to optimize ordinary ABE.","thread":"authority_architectures","visibility":"backbone"},"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE":{"anchor_roles":["model_definition","first_feasibility","capability_boundary"],"group":"construction","label":"Unbounded universe","lane_rationale":"Constructs KP-ABE admitting setup-unbounded attribute universes and attribute counts while retaining LSSS policies and delegation.","lenses":["unbounded_succinct"],"primary":true,"selection_rationale":"Lewko–Waters isolates setup-unboundedness by removing advance bounds on the attribute universe and realized attribute-set size. Omitting it would make later constant-parameter results appear to introduce unboundedness and compact setup simultaneously.","thread":"pairing_constructions","visibility":"backbone"},"ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL":{"anchor_roles":["capability_boundary","reusable_mechanism"],"group":"construction","label":"Standard-model CP-ABE","lane_rationale":"Gives a direct LSSS-based CP-ABE construction with selective standard-model security; the changed proof conditions qualify the scheme.","lenses":["policy_expressiveness","adaptive_cca_security"],"primary":true,"selection_rationale":"Waters11 replaces the original generic-group/random-oracle justification with a direct LSSS construction and selective standard-model reduction. Omitting it would collapse two materially different proof contracts into one CP-ABE lineage.","thread":"pairing_constructions","visibility":"backbone"},"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN":{"group":"construction","label":"Adaptive unbounded ABE","lane_rationale":"Constructs adaptively secure unbounded KP/CP-ABE under DLIN; achieving the stronger guarantee is a scheme contribution, not an assumption lane.","lenses":["unbounded_succinct","adaptive_cca_security"],"primary":true,"selection_rationale":"OT12 is retained because it combines setup-unboundedness, non-monotone policies, and adaptive payload hiding under a static prime-order assumption. It marks a stronger security point than LW11 without being confused with the later constant-public-parameter optimization.","thread":"pairing_constructions","visibility":"reviewed_related"},"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-IPE-WITH-FULL-ATTRIBUTE-HIDING":{"group":"construction","label":"Attribute-hiding IPE","lane_rationale":"Gives an unbounded IPE construction with adaptive full attribute hiding, distinct from the same paper's payload-hiding ABE.","lenses":["adaptive_cca_security"],"selection_rationale":"This same-paper contribution changes what the ciphertext reveals rather than merely extending the ABE policy class. Keeping it separate prevents payload-hiding ABE and full attribute-hiding inner-product encryption from being treated as the same security guarantee.","thread":"pairing_constructions","visibility":"reviewed_related"},"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"construction","label":"General circuit ABE","lane_rationale":"Constructs LWE-based ABE for bounded-depth general circuits using homomorphic lattice evaluation and key delegation.","lenses":["policy_expressiveness","unbounded_succinct"],"primary":true,"selection_rationale":"GVW13 is the first lattice construction supporting arbitrary polynomial-size bounded-depth circuit policies. Without it, the lattice thread would begin with later succinctness refinements and conceal the original expressiveness breakthrough and its leveled-depth boundary.","thread":"lattice_constructions","visibility":"backbone"},"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS":{"group":"efficiency","label":"Arithmetic-circuit ABE","lane_rationale":"The node's distinguishing result replaces circuit-size-dependent secret keys with depth-dependent keys for arithmetic-circuit ABE.","lenses":["policy_expressiveness"],"primary":true,"selection_rationale":"BGGPS14 is retained as the key-homomorphic mechanism that changes lattice key size from circuit- size dependence to depth dependence. That technical delta is distinct from GVW13's first general-circuit capability and from later removal of setup-time bounds.","thread":"lattice_constructions","visibility":"reviewed_related"},"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE":{"group":"construction","label":"Unbounded lattice ABE","lane_rationale":"Constructs semi-adaptive circuit ABE allowing late-bound input length while retaining a setup depth bound; this is a capability/security realization.","lenses":["unbounded_succinct","adaptive_cca_security"],"primary":true,"selection_rationale":"This node records the first lattice circuit-ABE point where attribute length is not fixed at setup and the challenge is chosen semi-adaptively. It prevents later black-box refinements from being mistaken for the origin of the unbounded-attribute branch.","thread":"lattice_constructions","visibility":"reviewed_related"},"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE":{"group":"construction","label":"Pair-encoding synthesis","lane_rationale":"Supplies a reusable symbolic pair-encoding analysis and synthesis method for a specified algebraic class, not an artifact-release claim.","lenses":["policy_expressiveness","concrete_efficiency"],"primary":true,"selection_rationale":"ABGW17 changes the research method by turning pairing exponent patterns into a symbolic language that can be checked, attacked, and synthesized. It remains reviewed-related because symbolic and generic-group validation is not itself a new standard-model ABE construction.","thread":"compiler_transforms","visibility":"reviewed_related"},"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE":{"anchor_roles":["reusable_mechanism","practice_transition"],"group":"efficiency","label":"FAME","lane_rationale":"Reduces concrete key, ciphertext and decryption costs for expressive pairing ABE under the stated DLIN/random-oracle contract.","lenses":["concrete_efficiency"],"primary":true,"selection_rationale":"FAME establishes the compact algebraic and decryption-cost point that made expressive CP-ABE a concrete engineering target. Omitting it would jump from the first implementation to later multi-challenge security without showing the practical construction those works preserve.","thread":"pairing_constructions","visibility":"backbone"},"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS":{"group":"efficiency","label":"Constant public parameters","lane_rationale":"The selected delta is constant-size public parameters for adaptively secure unbounded ABE, while realized keys and ciphertexts remain input dependent.","lenses":["unbounded_succinct","adaptive_cca_security"],"primary":true,"selection_rationale":"CGKW18 isolates constant public parameters within adaptive setup-unbounded ABE. It is shown as a separate efficiency contribution so compact setup is not conflated with constant keys, ciphertexts, or the later all-object succinctness frontier.","thread":"pairing_constructions","visibility":"reviewed_related"},"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE":{"anchor_roles":["capability_boundary","reusable_mechanism"],"group":"construction","label":"Black-box CCA transform","lane_rationale":"Gives a reusable CPA-to-CCA compiler using a hinting PRG; CCA is the target guarantee of the transform.","lenses":["adaptive_cca_security"],"primary":true,"selection_rationale":"Koppula–Waters turns chosen-ciphertext security from a construction-specific repair into a reusable black-box compiler for perfectly correct ABE and one-sided PE. Without it, the map would make the later predicate-extension compiler appear to introduce the generic CCA route.","thread":"compiler_transforms","visibility":"backbone"},"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE":{"group":"construction","label":"Lattice MA-ABE","lane_rationale":"Realizes decentralized DNF-policy MA-ABE from LWE with static security and a random oracle, changing the instantiation rather than proving an assumption ordering.","lenses":["authority_registration"],"primary":true,"selection_rationale":"DKW21 opens the lattice branch of decentralized multi-authority ABE with a direct DNF-policy construction. Its static security, random oracle, and subexponential-ratio LWE assumptions are visible here so post-quantum candidacy is not presented as a drop-in replacement for LW11.","thread":"lattice_constructions","visibility":"reviewed_related"},"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS":{"anchor_roles":["model_definition","first_feasibility","capability_boundary"],"group":"foundation","label":"Multi-input ABE","lane_rationale":"Introduces the multi-input ABE/PE research object and its input-composition contract, with two-input feasibility as the first realization of that new notion.","lenses":["policy_expressiveness"],"primary":true,"selection_rationale":"This contribution defines multi-input ABE and gives the first two-input NC1 construction with unbounded collusions. Leaving it out would make later constant-arity work look like an ordinary expressiveness improvement inside single-ciphertext ABE rather than a new composition API.","thread":"multi_input_composition","visibility":"backbone"},"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY":{"anchor_roles":["current_frontier"],"group":"construction","label":"FABEO","lane_rationale":"Combines compact pairing operations, multi-use attributes and adaptive multi-challenge security in one KP/CP-ABE design; the principal claim is the combined security/functionality realization.","lenses":["concrete_efficiency","adaptive_cca_security"],"primary":true,"selection_rationale":"FABEO is the reviewed endpoint that combines FAME-level algebraic efficiency with adaptive multi-challenge security and tight or near-tight generic-group bounds. Omitting it would leave the concrete pairing thread at a weaker single-challenge security contract.","thread":"compiler_transforms","visibility":"backbone"},"ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE":{"group":"construction","label":"Constant-arity MIABE","lane_rationale":"Constructs NC1 multi-input ABE for each fixed constant arity using LWE/evasive LWE, with a separate stronger-assumption computation extension.","lenses":["policy_expressiveness"],"primary":true,"selection_rationale":"ARYY23 removes both the arity-two restriction and the pairing/GGM component for every fixed constant number of inputs. It remains reviewed-related because polynomial or unbounded arity and a reduction to plain LWE are still outside this result.","thread":"multi_input_composition","visibility":"reviewed_related"},"ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION":{"group":"construction","label":"Adaptive authority corruption","lane_rationale":"The mapped claim realizes adaptive authority corruptions and adaptive user-key queries through new pairing-based MA-ABE constructions.","lenses":["authority_registration","adaptive_cca_security"],"primary":true,"selection_rationale":"This node strengthens decentralized MA-ABE by allowing authorities and user-key queries to be corrupted adaptively over the system lifetime. Keeping it separate prevents the original decentralized trust architecture from silently inheriting a later corruption guarantee.","thread":"authority_architectures","visibility":"reviewed_related"},"ABE-RESULT-2023-HLL-CONSTANT-SIZE-GARBLING":{"group":"efficiency","label":"Constant-size garbling","lane_rationale":"The independently stated garbling delta makes the garbled circuit and function digest independent of circuit depth and size for Boolean outputs.","lenses":["unbounded_succinct"],"selection_rationale":"The garbling theorem is separated from the paper's full ABE result because it is a reusable one-key mechanism with a different collusion contract. Its presence explains the construction route without implying that constant-size garbling alone is full ABE.","thread":"lattice_constructions","visibility":"reviewed_related"},"ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE":{"anchor_roles":["first_feasibility","capability_boundary"],"group":"construction","label":"Unbounded-depth ABE","lane_rationale":"Constructs fully collusion-resistant ABE for circuits without setup-time depth/size bounds under evasive circular LWE.","lenses":["policy_expressiveness","unbounded_succinct"],"primary":true,"selection_rationale":"HLL23 is the first full collusion-resistant ABE construction whose supported circuit depth and size are not fixed at setup. It must remain visible to show the conditional capability boundary, while its very selective theorem and broken evasive-circular assumption prevent overstatement.","thread":"lattice_constructions","visibility":"backbone"},"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION":{"anchor_roles":["model_definition","first_feasibility","capability_boundary"],"group":"foundation","label":"Registered ABE","lane_rationale":"Defines the registered-ABE interface in which users generate keys and a transparent curator aggregates registrations without secret issuance.","lenses":["authority_registration"],"primary":true,"selection_rationale":"Registered ABE replaces authority-generated long-term decryption keys with user-generated keys and transparent deterministic curation. Omitting it would misclassify later CRS reductions and circuit constructions as optimizations of decentralized MA-ABE rather than a new trust API.","thread":"authority_architectures","visibility":"backbone"},"ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE":{"group":"construction","label":"Unbounded-attribute circuit ABE","lane_rationale":"Replaces non-black-box homomorphic-PRF machinery with a black-box circuit-ABE construction while preserving unbounded attributes and semi-adaptive LWE security.","lenses":["policy_expressiveness","unbounded_succinct"],"primary":true,"selection_rationale":"Cini–Wee24 revisits the BV16 capability with a black-box construction from plain LWE. The node is retained because simplifying the mechanism and assumption use is a different contribution from first obtaining unbounded attribute length or removing the circuit-depth bound.","thread":"lattice_constructions","visibility":"reviewed_related"},"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS":{"group":"efficiency","label":"Nearly-linear RABE CRS","lane_rationale":"Reduces registered-ABE CRS dependence on the bounded user population from quadratic to nearly linear; separate branches have different security conditions.","lenses":["authority_registration","concrete_efficiency"],"primary":true,"selection_rationale":"GLWW24 reduces the registered-ABE CRS from quadratic to nearly linear in the bounded population. It remains visible as the direct efficiency predecessor to the linear-CRS result and keeps the large-constant and bounded-user qualifications attached to the right step.","thread":"authority_architectures","visibility":"reviewed_related"},"ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER":{"group":"construction","label":"Predicate-extension CCA","lane_rationale":"Introduces predicate extension as a reusable CPA-to-CCA compilation method; the lower-overhead pairing specialization is a qualified property of that method.","lenses":["adaptive_cca_security"],"primary":true,"selection_rationale":"Predicate extension lowers the overhead of generic CCA conversion for pairing-based predicate encodings by coordinating one extra attribute on both sides. It is related rather than backbone because KW19 already anchors the reusable compiler program and this result narrows its cost.","thread":"compiler_transforms","visibility":"reviewed_related"},"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE":{"anchor_roles":["capability_boundary","reusable_mechanism"],"group":"efficiency","label":"Size-independent circuit ABE","lane_rationale":"Compresses circuit-ABE keys and ciphertexts to dependence only on depth/security parameters, with public-parameter costs kept separate.","lenses":["policy_expressiveness","unbounded_succinct","concrete_efficiency"],"primary":true,"selection_rationale":"Wee24 is the first lattice circuit-ABE point where both keys and ciphertexts lose dependence on circuit size and attribute-input length. It is retained separately from the 2025 endpoint because it introduces the two-object compression route and exposes the remaining public-parameter cost.","thread":"pairing_constructions","visibility":"backbone"},"ABE-RESULT-2025-CHW-RABE-ADAPTIVE-DISTRIBUTED-BROADCAST-ENCRYPTION":{"group":"construction","label":"Adaptive distributed BE","lane_rationale":"Constructs adaptive distributed broadcast encryption from succinct LWE; this is a distinct stronger-secure broadcast object, not adaptive registered circuit ABE.","lenses":["authority_registration","adaptive_cca_security"],"selection_rationale":"The distributed-broadcast theorem is kept separate from the same paper's registered circuit ABE: it adds adaptive security and recipient-set-independent ciphertext size for a broadcast task, not an adaptive circuit-ABE guarantee.","thread":"authority_architectures","visibility":"reviewed_related"},"ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE":{"group":"construction","label":"Registered circuit ABE","lane_rationale":"Realizes registered KP-ABE for bounded-depth circuits from succinct LWE in ROM with attribute-selective security and a bounded user population.","lenses":["authority_registration","policy_expressiveness"],"primary":true,"selection_rationale":"This contribution carries registered key curation to bounded-depth circuit policies under succinct LWE with ciphertext size independent of attribute and circuit size. It remains related because the bounded user population, ROM, and attribute-selective theorem qualify the transition.","thread":"authority_architectures","visibility":"reviewed_related"},"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE":{"group":"foundation","label":"Multi-authority RABE","lane_rationale":"Introduces the combined multi-authority registration model with independent transparent curators and cross-domain policies; branch-specific realizations witness its feasibility.","lenses":["authority_registration"],"primary":true,"selection_rationale":"MARABE combines independent authority domains with user-generated keys and transparent registration. It is kept as a composition result so neither decentralized MA-ABE nor single- curator registered ABE is read as already supporting the combined trust model.","thread":"authority_architectures","visibility":"reviewed_related"},"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-CPABE":{"group":"efficiency","label":"Almost-optimal CP-ABE","lane_rationale":"Establishes the corresponding three-object succinctness profile for the distinct CP-ABE policy placement under bounded-depth selective succinct-LWE conditions.","lenses":["policy_expressiveness","unbounded_succinct","concrete_efficiency"],"selection_rationale":"The CP-ABE theorem is a separate atomic contribution because placing the circuit policy in the ciphertext changes which object carries the succinct policy computation. It is displayed beside, but not merged into, the primary KP-ABE result from the same paper.","thread":"pairing_constructions","visibility":"reviewed_related"},"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE":{"anchor_roles":["capability_boundary","current_frontier"],"group":"efficiency","label":"Almost-optimal KP-ABE","lane_rationale":"Removes the remaining input/circuit-size dependence from the KP-ABE public key as well as ciphertext and secret key, up to depth/security factors.","lenses":["policy_expressiveness","unbounded_succinct","concrete_efficiency"],"primary":true,"selection_rationale":"Wee25 closes the remaining public-parameter dependence for bounded-depth KP-ABE so public keys, ciphertexts, and circuit keys are all independent of input and circuit size up to depth and security factors. Omitting it would leave the succinctness thread one object short of its endpoint.","thread":"pairing_constructions","visibility":"backbone"},"ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS":{"anchor_roles":["capability_boundary","current_frontier"],"group":"efficiency","label":"Linear-CRS registered ABE","lane_rationale":"Advances pairing registered-ABE setup from nearly linear to linear CRS for MSP policies; static, adaptive and large-index branches are not conflated.","lenses":["authority_registration","concrete_efficiency"],"primary":true,"selection_rationale":"SWW26 reaches a genuinely linear CRS for registered ABE over monotone span programs and therefore marks the current pairing-based setup frontier. Its separate static, adaptive-ROM, and stateless- identity branches remain visible so the map does not combine non-simultaneous guarantees.","thread":"authority_architectures","visibility":"backbone"}},"overview_reading_path":["ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL","ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE"],"problems":[{"id":"policy_expressiveness","label":"Policy expressiveness","question":"How far can access policies grow, from threshold trees to general and unbounded circuits?","reading_path":["ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE"]},{"id":"unbounded_succinct","label":"Unbounded and succinct ABE","question":"Can universes, attributes, circuits, keys, and ciphertexts avoid setup-time or input-size bounds?","reading_path":["ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS","ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE","ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE"]},{"id":"adaptive_cca_security","label":"Adaptive and CCA security","question":"Which constructions achieve stronger adaptive or chosen-ciphertext guarantees under clear assumptions?","reading_path":["ABE-RESULT-2007-BSW-ADAPTIVE-GENERIC-GROUP-SECURITY","ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL","ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER"]},{"id":"authority_registration","label":"Authority and registration","question":"How can ABE distribute trust while retaining adaptive security and compact public infrastructure?","reading_path":["ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS"]},{"id":"concrete_efficiency","label":"Concrete and asymptotic efficiency","question":"Which ideas reduce the actual or asymptotic cost of expressive ABE without weakening the target?","reading_path":["ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY","ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-CPABE"]}],"relations":[{"change_dimensions":["model","functionality"],"evidence_locator":"Abstract and Section 1 (Introduction)","evidence_url":"https://eprint.iacr.org/2006/309.pdf","id":"LIN-001","map_relation":"lineage","predecessor":"ABE-RESULT-2005-SW-INTRODUCED-FUZZY-IBE-AND-THE-ABE-VIEW","relation_basis":"model_relation","relation_type":"GENERALIZES","review_status":"primary_source_checked","statement":"GPSW broadened the threshold set-overlap semantics of fuzzy IBE into key-policy ABE, placing an arbitrary monotone access structure in the secret key while labeling ciphertexts by attribute sets.","successor":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES"},{"change_dimensions":["model","functionality"],"evidence_locator":"Section 1, 'Our techniques'; Section 2, lines describing KP-ABE and CP-ABE","evidence_url":"https://www.cs.ucla.edu/~sahai/work/web/2007%20Publications/SSP2007.pdf","id":"LIN-002","map_relation":"lineage","predecessor":"ABE-RESULT-2006-GPSW-INTRODUCED-KP-ABE-FOR-ACCESS-STRUCTURES","relation_basis":"model_relation","relation_type":"CHANGES_MODEL","review_status":"primary_source_checked","statement":"BSW reverses GPSW's policy placement: attributes are attached to user keys and the encryptor places the access tree in the ciphertext, yielding a concrete CP-ABE construction.","successor":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION"},{"change_dimensions":["assumption","security","mechanism"],"evidence_locator":"Section 1.1, 'Our results'; comparison with BSW in Table 1","evidence_url":"https://eprint.iacr.org/2008/290.pdf","id":"LIN-003","map_relation":"lineage","predecessor":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","relation_basis":"result_progression","relation_type":"CHANGES_ASSUMPTION","review_status":"primary_source_checked","statement":"Waters gives expressive LSSS-based CP-ABE with a selective-security reduction under concrete non-interactive assumptions in the standard model, replacing BSW's generic-group/random-oracle justification without claiming adaptive standard-model security.","successor":"ABE-RESULT-2011-WATERS-EXPRESSIVE-CP-ABE-IN-THE-STANDARD-MODEL"},{"change_dimensions":["efficiency","mechanism","assumption","security"],"evidence_locator":"Tables 1.1-1.2; Section 1.1; Section 5, especially Table 5.5","evidence_url":"https://eprint.iacr.org/2017/807.pdf","id":"LIN-004","map_relation":"lineage","predecessor":"ABE-RESULT-2007-BSW-INTRODUCED-CP-ABE-CONSTRUCTION","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"FAME kept unrestricted policies and arbitrary attributes, moved to efficient Type-III pairings with full security under a standard assumption, and reports 25 percent smaller ciphertexts and keys than BSW.","successor":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE"},{"change_dimensions":["mechanism","functionality","security","efficiency"],"evidence_locator":"Table 1 and Section 1.1, 'Our Contributions'","evidence_url":"https://eprint.iacr.org/2022/1415.pdf","id":"LIN-005","map_relation":"lineage","predecessor":"ABE-RESULT-2017-FAME-FAST-CONCRETELY-EFFICIENT-CP-ABE","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"FABEO retained FAME's arbitrary-attribute, hash-to-G1 and fast-decryption design points, while adding attribute multi-use, smaller objects and optimal multi-challenge generic-group security bounds.","successor":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY"},{"change_dimensions":["mechanism","security","efficiency"],"evidence_locator":"Table 1 and Section 1.1, paragraphs beginning 'FABEO subsumes' and 'Optimal security'","evidence_url":"https://eprint.iacr.org/2022/1415.pdf","id":"LIN-006","map_relation":"lineage","predecessor":"ABE-RESULT-2017-ABGW-AUTOMATED-ANALYSIS-AND-SYNTHESIS-OF-PAIRING-ABE","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"FABEO combines ABGW's multi-use and generic-bilinear-group design points with the fast hash-and-randomness-reuse line, then improves ciphertext, key and runtime parameters and proves an optimal O(t^2/p) bound.","successor":"ABE-RESULT-2022-FABEO-FAME-LEVEL-EFFICIENCY-WITH-ADAPTIVE-MULTI-CHALLENGE-SECURITY"},{"change_dimensions":["security","assumption","functionality"],"evidence_locator":"Section 1.1.2, 'Unbounded IPE and ABE'","evidence_url":"https://eprint.iacr.org/2012/671.pdf","id":"LIN-007","map_relation":"lineage","predecessor":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","relation_basis":"result_progression","relation_type":"EXTENDS","review_status":"primary_source_checked","statement":"Okamoto-Takashima preserved unbounded ABE but removed the selective-only limitation of the Lewko-Waters ABE, obtaining the first fully secure unbounded ABE under DLIN in the standard model.","successor":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN"},{"change_dimensions":["mechanism","security","efficiency"],"evidence_locator":"Abstract; Section 1, 'Our results'","evidence_url":"https://eprint.iacr.org/2018/116.pdf","id":"LIN-008","map_relation":"lineage","predecessor":"ABE-RESULT-2011-LW-UNBOUNDED-REMOVED-SETUP-BOUND-ON-ABE-UNIVERSE-AND-ATTRIBUTE-SET-SIZE","relation_basis":"technical_dependency","relation_type":"EXTENDS","review_status":"primary_source_checked","statement":"CGKW revisited Lewko-Waters with a simpler entropy-expansion route and upgraded the composite-order unbounded ABE branch from selective to adaptive security.","successor":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS"},{"change_dimensions":["efficiency","functionality","assumption"],"evidence_locator":"Abstract; Section 1, results (i)-(ii)","evidence_url":"https://eprint.iacr.org/2018/116.pdf","id":"LIN-009","map_relation":"lineage","predecessor":"ABE-RESULT-2012-OT-ADAPTIVE-UNBOUNDED-ABE-FROM-DLIN","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"In the prime-order branch, CGKW uses bilinear entropy expansion to retain adaptive unbounded ABE from k-Lin while shortening ciphertexts and keys relative to Okamoto-Takashima and extending expressivity to arithmetic branching programs.","successor":"ABE-RESULT-2018-CGKW-ADAPTIVE-UNBOUNDED-ABE-WITH-CONSTANT-PUBLIC-PARAMETERS"},{"change_dimensions":["efficiency","functionality","mechanism"],"evidence_locator":"Section 1.1, 'Our results' (the paragraph beginning 'Inspired by the work of GVW')","evidence_url":"https://eprint.iacr.org/2014/356.pdf","id":"LIN-010","map_relation":"lineage","predecessor":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"BGGPS starts from the GVW lattice circuit-ABE direction, supports arithmetic circuits and replaces circuit-size-dependent secret keys with keys whose size depends only on circuit depth.","successor":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS"},{"change_dimensions":["mechanism","functionality","security"],"evidence_locator":"Section 1, prior circuit-ABE discussion and Question Q1; construction overview","evidence_url":"https://eprint.iacr.org/2016/118.pdf","id":"LIN-011","map_relation":"lineage","predecessor":"ABE-RESULT-2014-BGGPS-LATTICE-ABE-FOR-ARITHMETIC-CIRCUITS-WITH-DEPTH-DEPENDENT-KEYS","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"primary_source_checked","statement":"Brakerski-Vaikuntanathan builds on bounded circuit-ABE ideas including BGGPS to obtain the first LWE circuit ABE with unbounded attribute length, while retaining a setup-time depth bound and adding semi-adaptive security.","successor":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Abstract and Section 1, paragraphs on BV16 and the non-black-box drawback","evidence_url":"https://eprint.iacr.org/2024/1507.pdf","id":"LIN-012","map_relation":"lineage","predecessor":"ABE-RESULT-2016-BV-UNBOUNDED-ATTRIBUTE-LENGTH-AND-SEMI-ADAPTIVE-CIRCUIT-ABE-FROM-LWE","relation_basis":"technical_dependency","relation_type":"CHANGES_MECHANISM","review_status":"primary_source_checked","statement":"Cini–Wee retains BV's setup-unbounded attribute length and semi-adaptive LWE security but replaces the non-black-box homomorphic-PRF machinery with a simpler black-box construction; setup still fixes circuit depth.","successor":"ABE-RESULT-2024-CW-UNBOUNDED-ATTRIBUTE-CIRCUIT-ABE-FROM-LWE"},{"change_dimensions":["functionality","assumption","efficiency"],"evidence_locator":"Abstract and Section 1, discussion of the decade-old depth-dependency question","evidence_url":"https://eprint.iacr.org/2023/1716.pdf","id":"LIN-013","map_relation":"lineage","predecessor":"ABE-RESULT-2013-GVW-FIRST-GENERAL-CIRCUIT-ABE-FROM-LWE","relation_basis":"result_progression","relation_type":"GENERALIZES","review_status":"primary_source_checked","statement":"HLL attacks the setup-time depth dependence left by GVW-era lattice circuit ABE and obtains full-fledged circuit ABE for unbounded depth and size under evasive circular LWE, with a constant-size secret key.","successor":"ABE-RESULT-2023-HLL-UNBOUNDED-DEPTH-ABE"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Section 1.1 and Section 1.2, 'The Wee24 KP-ABE and LFE'","evidence_url":"https://eprint.iacr.org/2025/509.pdf","id":"LIN-014","map_relation":"lineage","predecessor":"ABE-RESULT-2024-WEE-CIRCUIT-ABE-WITH-KEY-AND-CIPHERTEXT-INDEPENDENT-OF-INPUT-AND-CIRCUIT-SIZE","relation_basis":"technical_dependency","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"The 2025 construction explicitly starts from Wee24's KP-ABE and succinct vector commitment, recursively compresses the commitment parameters, and reduces the public-key/CRS dependence from O(ell^2) to O(1) up to poly(depth,lambda), while supplying both KP- and CP-ABE.","successor":"ABE-RESULT-2025-WEE-ALMOST-OPTIMAL-KPABE"},{"change_dimensions":["assumption","functionality","mechanism"],"evidence_locator":"Abstract and Section 1, comparison with prior MA-ABE","evidence_url":"https://eprint.iacr.org/2020/1386.pdf","id":"LIN-015","map_relation":"lineage","predecessor":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","relation_basis":"model_relation","relation_type":"CHANGES_ASSUMPTION","review_status":"primary_source_checked","statement":"DKW preserves Lewko-Waters' fully decentralized authority model but moves the construction from bilinear assumptions to LWE, at the price of DNF policies and continued use of the random-oracle model.","successor":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE"},{"change_dimensions":["model","security","assumption"],"evidence_locator":"Abstract and Section 1, prior-work and security-model comparison","evidence_url":"https://eprint.iacr.org/2022/1311.pdf","id":"LIN-016","map_relation":"lineage","predecessor":"ABE-RESULT-2021-DKW-FIRST-DECENTRALIZED-MAABE-FROM-LWE","relation_basis":"model_relation","relation_type":"CHANGES_SECURITY_MODEL","review_status":"primary_source_checked","statement":"The later DKW work defines and realizes decentralized MA-ABE with adaptive authority corruptions and adaptive user-key queries. Its main realization uses pairings and a random oracle rather than upgrading the earlier DKW LWE construction under unchanged assumptions.","successor":"ABE-RESULT-2023-DKW-FIRST-MAABE-SECURE-UNDER-ADAPTIVE-AUTHORITY-CORRUPTION"},{"change_dimensions":["mechanism","efficiency","security"],"evidence_locator":"Abstract; Section 1.1; Sections 4-5","evidence_url":"https://eprint.iacr.org/2024/749.pdf","id":"LIN-017","map_relation":"lineage","predecessor":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","relation_basis":"technical_dependency","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"GLWW applies progression-free sets and a partitioning alternative to the original registered-ABE blueprint, reducing the pairing-based CRS from quadratic in users to nearly linear and optionally removing its attribute- universe dependence under the weaker static-security branch.","successor":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS"},{"change_dimensions":["efficiency","functionality","security"],"evidence_locator":"Abstract and Section 1, comparison with previous pairing-based registered ABE","evidence_url":"https://eprint.iacr.org/2026/1062.pdf","id":"LIN-018","map_relation":"lineage","predecessor":"ABE-RESULT-2024-GLWW-NEARLY-LINEAR-REGISTERED-ABE-CRS","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"SWW advances the pairing registered-ABE setup line from GLWW's nearly linear CRS to a linear-size CRS for MSP policies. A separate large-index branch supports arbitrary-string identities and stateless key generation; those features are not simultaneous with the adaptive-security branch.","successor":"ABE-RESULT-2026-SWW-RABE-LINEAR-CRS-REGISTERED-ABE-FOR-MSPS"},{"change_dimensions":["assumption","functionality","efficiency"],"evidence_locator":"Section 1.1, 'Registered ABE' and 'Our Results'","evidence_url":"https://eprint.iacr.org/2025/044.pdf","id":"LIN-019","map_relation":"lineage","predecessor":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","relation_basis":"model_relation","relation_type":"CHANGES_ASSUMPTION","review_status":"primary_source_checked","statement":"CHW carries the registered-ABE trust model to falsifiable succinct-LWE assumptions and bounded-depth circuit policies in the random-oracle model, replacing the original pairing/formula construction line.","successor":"ABE-RESULT-2025-CHW-RABE-REGISTERED-CIRCUIT-ABE"},{"change_dimensions":["model","functionality","security"],"evidence_locator":"Section 1.1, 'Multi-authority ABE' and 'Registered multi-authority ABE'; Section 2","evidence_url":"https://www.cs.utexas.edu/~dwu4/papers/RegisteredMA-ABE.pdf","id":"LIN-020","map_relation":"lineage","predecessor":"ABE-RESULT-2011-LW-MAABE-DECENTRALIZED-MULTI-AUTHORITY-ABE-WITHOUT-CENTRAL-AUTHORITY","relation_basis":"model_relation","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"LWW imports the Lewko-Waters cross-domain, no-authority-coordination model into registered ABE, preserving policies across independently managed attribute domains while removing long-term key-issuer secrets.","successor":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE"},{"change_dimensions":["model","mechanism","functionality"],"evidence_locator":"Section 1.1, contributions, especially the pairing-construction paragraph","evidence_url":"https://www.cs.utexas.edu/~dwu4/papers/RegisteredMA-ABE.pdf","id":"LIN-021","map_relation":"lineage","predecessor":"ABE-RESULT-2023-HLWW-INTRODUCED-REGISTERED-ABE-WITH-TRANSPARENT-CURATION","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"LWW combines HLWW's deterministic transparent registration blueprint with multi-authority ABE; its pairing construction explicitly leverages ideas from both HLWW and Lewko-Waters and supports monotone LSSS policies.","successor":"ABE-RESULT-2025-LWW-MARABE-INTRODUCED-MULTI-AUTHORITY-REGISTERED-ABE"},{"change_dimensions":["functionality","assumption","mechanism"],"evidence_locator":"Abstract and Section 1, 'The Multi-Input Setting'","evidence_url":"https://eprint.iacr.org/2023/941.pdf","id":"LIN-022","map_relation":"lineage","predecessor":"ABE-RESULT-2022-AYY-MIABE-INITIATED-MIABE-AND-GAVE-TWO-INPUT-NC1-CONSTRUCTIONS","relation_basis":"result_progression","relation_type":"EXTENDS","review_status":"primary_source_checked","statement":"ARYY extends AYY's two-input NC1 construction to every constant arity and removes the pairing/GGM component by using evasive LWE (and tensor LWE for the P extension), yielding a post-quantum candidate line.","successor":"ABE-RESULT-2023-ARYY-CONSTANT-ARITY-MIABE-FOR-NC1-FROM-EVASIVE-LWE"},{"change_dimensions":["mechanism","functionality","efficiency"],"evidence_locator":"Abstract; Section 1.1 and Figure 1, including the KW19 transformation","evidence_url":"https://eprint.iacr.org/2023/1947.pdf","id":"LIN-023","map_relation":"lineage","predecessor":"ABE-RESULT-2019-KW-CCA-BLACK-BOX-CPA-TO-CCA-TRANSFORM-FOR-ABE-AND-ONE-SIDED-PE","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"Venema-Botros reframes generic CPA-to-CCA conversion through predicate extension, broadens the approach across predicate encryption, and gives a lower-overhead pairing-based extension that yields the most efficient generic CCA conversion reported for CP-ABE.","successor":"ABE-RESULT-2024-VB-CCA-PREDICATE-EXTENSION-CPA-TO-CCA-COMPILER"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"From fuzzy identity matching to key-policy and ciphertext-policy ABE.","id":"roots_policy","label":"Policy-encryption roots"},{"color":"#2f718e","description":"Expressive and increasingly efficient ABE from bilinear-map techniques.","id":"pairing_constructions","label":"Pairing constructions"},{"color":"#4f7b60","description":"Circuit and multi-authority ABE based on LWE and lattice mechanisms.","id":"lattice_constructions","label":"Lattice constructions"},{"color":"#b65358","description":"Security transforms, pair encodings, and automated construction methods.","id":"compiler_transforms","label":"Compilers and synthesis"},{"color":"#73549a","description":"Decentralized, registered, and multi-authority trust models.","id":"authority_architectures","label":"Authority architectures"},{"color":"#9a6c2d","description":"ABE that composes policies or ciphertext inputs across authorities or users.","id":"multi_input_composition","label":"Multi-input composition"}]},"stats":{"constructions":32,"countsByType":{"assumption":19,"barrier":7,"construction":32,"milestone":47,"open_problem":12,"paper":70,"research_track":3,"result":96,"route":21},"entities":307,"lineageRelationships":23,"propertyAssertions":320,"relationships":508,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}