Securely Obfuscating Re-Encryption Susan Hohenberger¤ Guy N. Rothblumy abhi shelatz Vinod Vaikuntanathanx December 1, 2008 Abstract We present a positive obfuscation result for a traditional cryptographic functionality. This posi- tive result stands in contrast to well-known impossibility results [3] for general obfuscation and recent impossibility and improbability [13] results for obfuscation of many cryptographic functionalities. Whereas other positive obfuscation results in the standard model apply to very simple point func- tions, our obfuscation result applies to the signi¯cantly more complex and widely-used re-encryption functionality. This functionality takes a ciphertext for message m encrypted under Alice's public key and transforms it into a ciphertext for the same message m under Bob's public key. To overcome impossibility results and to make our results meaningful for cryptographic functionalities, our scheme satis¯es a de¯nition of obfuscation which incorporates more security-aware provisions. ¤Johns Hopkins University,
[email protected]. Research partially performed at IBM Zurich Research Laboratory, Switzer- land. yMIT CSAIL,
[email protected]. Research supported by NSF grant CNS-0430450 and NSF grant CFF-0635297. zUniversity of Virginia,
[email protected]. Research performed at IBM Zurich Research Laboratory, Switzerland. xMIT CSAIL,
[email protected] 1 1 Introduction A recent line of research in theoretical cryptography aims to understand whether it is possible to obfuscate programs so that a program's code becomes unintelligible while its functionality remains unchanged. A general method for obfuscating programs would lead to the solution of many open problems in cryptography. Unfortunately, Barak, Goldreich, Impagliazzo, Rudich, Sahai, Vadhan and Yang [3] show that for many notions of obfuscation, a general program obfuscator does not exist|i.e., they exhibit a class of circuits which cannot be obfuscated.