International Association for Cryptologic Research (IACR)
Abstract
In this paper, we suggest a new selective secure
functional encryption scheme
for degree d polynomial.
The number of ciphertexts for a message with length ℓ in our scheme
is O(ℓ) regardless of d,
while it is at least ℓd/2 in the previous works.
Our main idea is to generically combine two abstract encryption schemes
that satisfies some special properties.
We also gives an instantiation of our scheme by
combining ElGamal scheme and Ring-LWE based homomorphic encryption scheme,
whose ciphertext length is exactly 2ℓ+1, for any degree $d.