Trace and revoke systems with short ciphertexts


Trace and revoke systems are motivated by content protection on various platforms such as DVD players, satellite radio receivers and PCs, which provide both broadcast encryption and traitor tracing mechanisms. So far, the best existing system requires ciphertext size sub-linear in the number of users. In communications, as system scale increases, it brings up a high bandwidth requirement which cannot be satisfied by current network condition. In this paper, we present a new fully collusion resistant trace and revoke system which has only constant size ciphertexts. The system is CPA secure against static adversaries with public broadcast key and secret tracing key. It can be efficiently applied in DRM fields where network bandwidth is limited.

DOI: 10.1145/1626195.1626212

