Key agreement system, shared-key generation apparatus, and shared-key recovery apparatus
Abstract
Provided is a content distribution system capable of preventing the derivation of different keys between an encryption device and a decryption device. The random number generator (112d) of the encryption device (110d) generates a random number, the first function unit (113d) generates a function value G(s) of the random number, and generates a verification value a and a shared key based on the function value G(s) K, the encryption unit (114d) uses the public key polynomial h to generate the first encrypted text c1 of the verification value a, and the second function unit (115d) generates the verification value a and the function value H(a, c1) of the first encrypted text c1 , The random number masking unit (116d) generates c2=s?xor?H(a, c1). The decryption device (120d) uses the secret key polynomial f to decrypt the first encrypted text to generate a decrypted verification value, and the third function unit (124d) generates a verification value a'and a function value H(a', c1), the random number removal unit (125d) generates a decrypted random number s'=c2xor?H(a', c1), and the fourth function unit (126d) generates a hash function value G(s') of the decrypted random number s' , The verification value a" and the shared key K'are generated based on the function value G(s'), and the comparison unit (127d) outputs the shared key K'when the decryption verification value a'and the verification value a" are equal.

Term
Term ended
Expired 28 November 2023, 2.8 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
42 claims: 5 independent, 37 dependent
- 1一种密钥共享系统,由共享密钥生成装置和共享密钥复原装置构成,并不让第三者 知道地生成共享密钥,其特征在于: 所述共享密钥生成装置具有: 生成种子值的种子值生成装置; 根据已生成的所述种子值生成验证值和共享密钥的第1共享密钥生成单元; 对已生成的所述验证值进行加密后再生成第1加密信息的第1加密装置; 根据已生成的所述验证值对已生成的所述种子值进行加密后再生成第2加密信息的 第2加密装置;以及 发送已生成的所述第1加密信息和所述第2加密信息的发送装置, 所述共享密钥复原装置具有: 接收所述第1加密信息和所述第2加密信息的接收装置; 将已接收的所述第1加密信息解密后生成第1解密验证值的第1解密装置; 根据已生成的所述第1解密验证值,将已接收的所述第2加密信息解密后生成解密种 子值的第2解密装置; 利用和所述第1共享密钥生成单元相同的方法,并根据已生成的所述解密种子值生成 第2解密验证值和解密共享密钥的第2共享密钥生成单元; 根据已生成的所述第1解密验证值和所述第2解密验证值判断是否输出已生成的所述 解密共享密钥的判断装置;以及 当判断要输出时输出已生成的所述解密共享密钥的输出装置。
- 2权利要求1记载的密钥共享系统,其特征在于: 所述共享密钥生成装置进而具有: 取得内容的取得装置;以及 使用已生成的所述共享密钥对已取得的内容进行加密后再生成加密内容的加密装置, 所述发送装置进而发送已生成的所述加密内容, 所述接收装置进而接收所述加密内容, 所述共享密钥复原装置进而具有: 使用已输出的所述解密共享密钥,对已接收的所述加密内容进行解密后再生成解密内 容的解密装置;以及 输出已生成的解密内容的输出装置。
- 3一种不让第三者知道地向对方装置传送共享密钥的共享密钥生成装置,其特征在 于: 具有生成种子值的种子值生成单元; 根据已生成的所述种子值生成验证值和共享密钥的共享密钥生成单元; 对已生成的所述验证值进行加密后再生成第1加密信息的第1加密装置; 根据已生成的所述验证值对已生成的所述种子值进行加密后再生成第2加密信息的 第2加密装置; 发送已生成的所述第1加密信息和第2加密信息的发送装置。
- 4权利要求3记载的共享密钥生成装置,其特征在于: 所述种子值生成单元生成随机数,通过将生成的随机数作为所述种子值来生成所述种 CN 1745537 Β 子值。
- 5权利要求3记载的共享密钥生成装置,其特征在于: 所述共享密钥生成单元对所述种子值执行单向函数来生成函数值,并根据已生成的所 述函数值生成所述验证值和所述共享密钥。
- 6权利要求5记载的共享密钥生成装置,其特征在于: 所述共享密钥生成单元对所述种子值执行作为所述单向函数的散列函数,并生成所述 函数值。
- 7权利要求5记载的共享密钥生成装置,其特征在于: 所述共享密钥生成单元将已生成的所述函数值的一部分作为所述验证值,另一部分作 为所述共享密钥,由此,生成所述验证值和所述共享密钥。 &权利要求3记载的共享密钥生成装置,其特征在于: 所述共享密钥生成单元对所述种子值执行单向函数后再生成函数值,根据已生成的所 述函数值生成所述验证值、所述共享密钥和盲值。
- 89. 权利要求8记载的共享密钥生成装置,其特征在于: 所述第1加密装置包括: 取得公开密钥的公开密钥取得部;和 使用取得的所述公开密钥和已生成的所述盲值,对所述验证值执行公开密钥加密算法 后再生成所述第1加密信息的公开密钥加密部。
- 910. 权利要求9记载的共享密钥生成装置,其特征在于: 所述公开密钥加密算法是NTRU密码方式的算法, 所述公开密钥取得部取得利用NTRU密码方式的密钥生成算法生成的公开密钥多项式 作为所述公开密钥, 所述公开密钥加密部根据所述验证值生成验证值多项式,根据所述盲值生成盲值多项 式,利用NTRU密码方式的加密算法,将所述公开密钥多项式作为密钥使用,为了搅乱所述 验证值多项式,使用所述盲值多项式加密所述验证值多项式,再生成作为多项式的所述第1 加密信息。
- 1011. 权利要求3记载的共享密钥生成装置,其特征在于: 所述第1加密装置包括: 取得公开密钥的公开密钥取得部;和 使用取得的所述公开密钥对所述验证值执行公开密钥加密算法后再生成所述第1加 密信息的公开密钥加密部。
- 1112. 权利要求11记载的共享密钥生成装置,其特征在于: 所述公开密钥加密算法是NTRU密码方式的算法, 所述公开密钥取得部取得利用NTRU密码方式的密钥生成算法生成的公开密钥多项式 作为所述公开密钥, 所述公开密钥加密部根据所述验证值生成验证值多项式,生成盲值,并根据生成的所 述盲值生成盲值多项式,利用NTRU密码方式的加密算法,将所述公开密钥多项式作为密钥 使用,为了搅乱所述验证值多项式,使用所述盲值多项式加密所述验证值多项式,再生成作 为多项式的所述第1加密信息。
- 1213. 权利要求3记载的共享密钥生成装置,其特征在于: 所述第2加密装置对所述验证值执行单向函数再生成函数值,使用生成的所述函数 值,对所述种子值执行加密算法,再生成所述第2加密信息。
- 1314. 权利要求13记载的共享密钥生成装置,其特征在于: 所述第2加密装置通过对已生成的所述函数值和所述种子值执行作为所述加密算法 的“异”运算,生成所述第2加密信息。
- 1415. 权利要求13记载的共享密钥生成装置,其特征在于: 所述第2加密装置通过对已生成的所述函数值和所述种子值执行作为所述加密算法 的公共密钥加密算法,生成所述第2加密信息。
- 1516. 权利要求13记载的共享密钥生成装置,其特征在于: 所述第2加密装置通过对已生成的所述函数值和所述种子值执行作为所述加密算法 的加法运算,生成所述第2加密信息。
- 1617. 权利要求13记载的共享密钥生成装置,其特征在于: 所述第2加密装置通过对已生成的所述函数值和所述种子值执行作为所述加密算法 的乘法运算,生成所述第2加密信息。 1&权利要求13记载的共享密钥生成装置,其特征在于: 所述第2加密装置对所述验证值执行作为所述单向函数的散列函数后再生成所述函 数值。
- 1719. 权利要求3记载的共享密钥生成装置,其特征在于: 所述第2加密装置使用所述验证值对所述种子值执行加密算法,再生成第2加密信息。
- 1820. 权利要求3记载的共享密钥生成装置,其特征在于: 所述第2加密装置使用所述验证值和所述第1加密信息,对所述种子值进行加密。
- 1921. 权利要求20记载的共享密钥生成装置,其特征在于: 所述第2加密装置对所述验证值和所述第1加密信息执行单向函数后再生成所述函数 值,使用已生成的所述函数值对所述种子值执行加密算法,生成所述第2加密信息。
- 2022. 权利要求21记载的共享密钥生成装置,其特征在于: 所述第2加密装置通过对已生成的所述函数值和所述种子值执行作为所述加密算法 的“异”运算,生成所述第2加密信息。
- 2123. 权利要求3记载的共享密钥生成装置,其特征在于: 所述共享密钥生成装置进而具有: 取得内容的取得装置;和 使用已生成的所述共享密钥对已取得的内容进行加密后再生成加密内容的加密装置, 所述发送装置进而发送已生成的所述加密内容。
- 2224. 一种不让第三者知道而从共享密钥生成装置接收共享密钥的共享密钥复原装置, 其特征在于: 所述共享密钥生成装置生成种子值,根据已生成的所述种子值生成验证值和共享密 钥,对已生成的所述验证值进行加密生成第1加密信息,根据已生成的所述验证值对已生 成的所述种子值进行加密生成第2加密信息,并发送已生成的所述第1加密信息和所述第 2加密信息, CN 1745537 Β 所述共享密钥复原装置具有: 接收所述第1加密信息和所述第2加密信息的接收装置; 将已接收的所述第1加密信息解密后生成第1解密验证值的第1解密装置; 根据已生成的所述第1解密验证值,将已接收的所述第2加密信息解密后生成解密种 子值的第2解密装置; 利用和所述共享密钥生成装置相同的方法,并根据已生成的所述解密种子值生成第2 解密验证值和解密共享密钥的共享密钥生成单元; 根据已生成的所述第1解密验证值和所述第2解密验证值判断是否输出已生成的所述 解密共享密钥的判断装置;和 当判断要输出时输出已生成的所述解密共享密钥的输出装置。
- 2325. 权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置取得公开密钥,使用已取得的所述公开密钥对所述验证值执行 公开密钥加密算法,再生成所述第1加密信息, 所述第1解密装置包括: 取得与所述公开密钥对应的秘密密钥的秘密密钥取得部; 使用取得的所述秘密密钥对已接收的所述第1加密信息执行与所述公开密钥加密算 法对应的公开密钥解密算法后再生成所述第1解密验证值的公开密钥解密部。
- 2426. 权利要求25记载的共享密钥复原装置,其特征在于: 所述公开密钥加密算法和所述公开密钥解密算法使用了 NTRU密码方式, 所述共享密钥生成装置取得利用NTRU密码方式的密钥生成算法生成的公开密钥多 项式作为所述公开密钥,根据所述验证值生成验证值多项式,生成盲值,并根据生成的所述 盲值生成盲值多项式,利用NTRU密码方式的加密算法,将所述公开密钥多项式作为密钥使 用,为了搅乱所述验证值多项式,使用所述盲值多项式加密所述验证值多项式,再生成作为 多项式的所述第1加密信息, 所述接收装置接收作为多项式的所述第1加密信息, 所述秘密密钥取得部取得利用NTRU密码方式的密钥生成算法生成的秘密密钥多项式 作为所述秘密密钥, 所述公开密钥解密部利用NTRU密码方式的与所述加密算法对应的解密算法,将所述 秘密密钥多项式作为密钥使用,对作为多项式的所述第1加密信息进行解密,生成解密验 证值多项式,根据已生成的所述解密验证值多项式生成所述第1解密验证值。
- 2527. 权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置对所述验证值执行单向函数后再生成函数值,使用生成的所述 函数值,对所述种子值执行加密算法,再生成所述第2加密信息, 所述第2解密装置对已生成的所述第1解密验证值执行所述单向函数后再生成解密函 数值,使用已生成的所述解密函数值对已接收的所述第2加密信息执行与所述加密算法对 应的解密算法,再生成所述解密种子值。 2&权利要求27记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置通过对已生成的所述函数值和所述种子值执行作为所述加密 算法的“异”运算,生成所述第2加密信息, 所述第2解密装置通过对已生成的所述解密函数值和所述第2加密信息执行作为所述 解密算法的“异”运算,生成所述解密种子值。
- 2629. 权利要求27记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置通过对已生成的所述函数值和所述种子值执行作为所述加密 算法的公共密钥加密算法,生成所述第2加密信息, 所述第2解密装置通过对已生成的所述解密函数值和所述第2加密信息执行作为所述 解密算法的、与所述公共密钥加密算法对应的公共密钥解密算法,生成所述解密种子值。
- 2730. 权利要求27记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置通过对已生成的所述函数值和所述种子值执行作为所述加密 算法的加法运算,生成所述第2加密信息,所述第2解密装置通过对已生成的所述解密函数 值和所述第2加密信息执行作为所述解密算法的减法运算,生成所述解密种子值。
- 2831. 权利要求27记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置通过对已生成的所述函数值和所述种子值执行作为所述加密 算法的乘法运算,生成所述第2加密信息, 所述第2解密装置通过对已生成的所述解密函数值和所述第2加密信息执行作为所述 解密算法的除法运算,生成所述解密种子值。
- 2932. 权利要求27记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置对所述验证值执行作为所述单向函数的散列函数,生成所述函 数值, 所述第2解密装置对已生成的所述第1解密验证值执行作为所述单向函数的所述散列 函数,生成所述解密函数值。
- 3033. 权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置使用所述验证值,对所述种子值执行加密算法,生成第2加密 信息, 所述第2解密装置使用已生成的所述第1解密验证值,对所述第2加密信息执行与所 述加密算法对应的解密算法,生成所述解密种子值。
- 3134. 权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置使用所述验证值和所述第1加密信息对所述种子值进行加密, 所述第2解密装置使用已生成的所述第1解密验证值和已接收的所述第1加密信息, 对所述第2加密信息进行解密,生成所述解密种子值。
- 3235. 权利要求34记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置对所述验证值和所述第1加密信息执行单向函数,生成函数 值,并使用已生成的所述函数值对所述种子值执行加密算法,生成所述第2加密信息, 所述第2解密装置对所述第1解密验证值和所述第1加密信息执行所述单向函数,生 成解密函数值,使用已生成的所述解密函数值,对所述第2加密信息执行与所述加密算法 对应的解密算法,生成所述解密种子值。
- 3336. 权利要求35记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置通过对已生成的所述函数值和所述种子值执行作为所述加密 算法的“异”运算,生成所述第2加密信息, CN 1745537 Β 所述第2解密装置通过对所述解密函数值和所述第2加密信息执行作为所述解密算法 的“异”运算,生成所述解密种子值。 37.权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置对所述种子值执行单向函数来生成函数值,并根据已生成的所 述函数值生成所述验证值和所述共享密钥, 所述共享密钥生成单元对已生成的所述解密种子值执行所述单向函数,生成解密函数 值,并根据已生成的所述解密函数值生成所述第2解密验证值和所述解密共享密钥。 3&权利要求37记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置对所述种子值执行作为所述单向函数的散列函数,生成所述函 数值, 所述共享密钥生成单元对已生成的所述解密种子值执行作为所述单向函数的所述散 列函数,生成所述解密函数值。
- 3439. 权利要求37记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置将已生成的所述函数值的一部分作为所述验证值,另一部分作 为所述共享密钥,由此,生成所述验证值和所述共享密钥, 所述共享密钥生成单元将已生成的所述解密函数值的一部分作为所述第2解密验证 值,另一部分作为所述解密共享密钥,由此,生成所述第2解密验证值和所述解密共享密 钥。
- 3540. 权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置对所述种子值执行单向函数后再生成函数值,根据已生成的所 述函数值生成所述验证值、所述共享密钥和盲值,取得公开密钥,使用已取得的所述公开密 钥和已生成的所述盲值,对所述验证值执行公开密钥加密算法,生成所述第1加密信息, 所述共享密钥生成单元对已生成的所述解密种子值执行所述单向函数,生成解密函数 值,并根据已生成的所述解密函数值生成所述第2解密验证值、所述解密共享密钥和解密 盲值。
- 3641. 权利要求24记载的共享密钥复原装置,其特征在于: 所述判断装置将所述第1解密验证值和所述第2解密验证值比较,当一致时,判断为输 出所述解密共享密钥。
- 3742. 权利要求24记载的共享密钥复原装置,其特征在于: 所述共享密钥生成装置进而取得内容,使用已生成的所述共享密钥,对已取得的内容 进行加密后再生成加密内容,并发送已生成的所述加密内容, 所述接收装置进而接收所述加密内容, 所述共享密钥复原装置进而具有: 使用已输出的所述解密共享密钥对已接收的所述加密内容进行解密后再生成解密内 容的解密装置;和 输出已生成的解密内容的输出装置。
- 3843. 权利要求40记载的共享密钥复原装置,其特征在于: 所述判断装置取代基于所述第1解密验证值和所述第2解密验证值的所述判断,而具 CN 1745537 Β 取得所述公开密钥的公开密钥取得部; 使用已取得的所述公开密钥和已生成的所述解密盲值对生成的所述第1解密验证值 或所述第2解密验证值执行所述公开密钥加密算法并生成再加密信息的再加密部; 根据已接收的所述第1加密信息和已生成的所述再加密信息判断是否输出已生成的 所述解密共享密钥的判断部。
- 3944. 权利要求43记载的共享密钥复原装置,其特征在于: 所述判断部将所述第1加密信息和所述再加密信息进行比较,当所述第1加密信息和 所述再加密信息一致时,判断为输出所述解密共享密钥。
- 4045. 权利要求43记载的共享密钥复原装置,其特征在于: 所述公开密钥加密算法采用NTRU密码方式, 所述共享密钥生成装置取得利用NTRU密码方式的密钥生成算法生成的公开密钥多项 式作为所述公开密钥,根据所述验证值生成验证值多项式,根据所述盲值生成盲值多项式, 利用NTRU密码方式的加密算法,将所述公开密钥多项式作为密钥使用,为了搅乱所述验证 值多项式,使用所述盲值多项式加密所述验证值多项式,再生成作为多项式的所述第1加 密信息, 所述公开密钥取得部取得所述公开密钥多项式, 所述再加密部根据所述第2解密验证值生成解密验证值多项式,根据所述解密盲值 生成解密盲值多项式,利用NTRU密码方式的加密算法,将所述公开密钥多项式作为密钥使 用,为了搅乱所述解密验证值多项式,使用所述盲值多项式加密所述解密验证值多项式,再 生成作为多项式的所述再加密信息。
- 4146. 一种共享密钥生成方法,是不让第三者知道而向对方装置传送共享密钥的共享密 钥生成装置中使用的共享密钥生成方法,其特征在于: 具有生成种子值的种子值生成步骤; 根据已生成的所述种子值生成验证值和共享密钥的共享密钥生成步骤; 对已生成的所述验证值进行加密后再生成第1加密信息的第1加密步骤; 根据已生成的所述验证值对已生成的所述种子值进行加密后再生成第2加密信息的 第2加密步骤;和 发送已生成的所述第1加密信息和第2加密信息的发送步骤。
- 4247. 一种共享密钥复原方法,是不让第三者知道而从共享密钥生成装置接收共享密钥 的共享密钥复原装置中使用的共享密钥复原方法,其特征在于: 所述共享密钥生成装置生成种子值,根据已生成的所述种子值生成验证值和共享密 钥,对已生成的所述验证值进行加密后生成第1加密信息,根据已生成的所述验证值对已 生成的所述种子值进行加密后生成第2加密信息,并发送已生成的所述第1加密信息和所 述第2加密信息, 所述共享密钥复原方法具有: 接收所述第1加密信息和所述第2加密信息的接收步骤; 将已接收的所述第1加密信息解密后生成第1解密验证值的第1解密步骤; 根据已生成的所述第1解密验证值,将已接收的所述第2加密信息解密后生成解密种 子值的第2解密步骤; 利用和所述共享密钥生成装置相同的方法,并根据已生成的所述解密种子值生成第2 解密验证值和解密共享密钥的共享密钥生成步骤; 根据已生成的所述第1解密验证值和所述第2解密验证值判断是否输出已生成的所述 解密共享密钥的判断步骤;和 当判断要输出时,输出已生成的所述解密共享密钥的输出步骤。
Independent claims42
804 paragraphs, as filed
Key sharing system, shared key generating device, and shared key recovery device technical field
[0001] The present invention relates to encryption technology as an information security technology, and particularly relates to a technology for distributing a key without letting a third party know it.
Background technique
[0002] In the past, in order to secretly transmit information from a transmitting device to a receiving device, a public key cryptographic method was used.
[0003] In the public key cryptography method, the transmitting device uses the public key of the receiving device to encrypt and then transmits the communication content. The receiving device receives the encrypted communication content and uses its own secret key to perform the communication content on the received communication content. Decrypt and get the original communication content. (For example, refer to Non-Patent Document 1).
[0004] In 1996, the NTRU cipher was proposed as a public key cipher capable of high-speed processing (for example, refer to Non-Patent Document 2). In NTRU ciphers, polynomial operations that can perform high-speed operations are used for encryption and decryption. Therefore, if it is compared with RSA ciphers for screen multiplication or elliptic curve ciphers for scalar product operations of points on the elliptic curve, software can be used for comparison. The existing public key cipher is processed at a higher speed.
[0005] However, in this NTRU cipher, when a public key is used to encrypt the plain text to produce an encrypted text, and a regular secret key is used to decrypt the encrypted text to generate a decrypted text, the decrypted text and the original plain text will be generated. Different situations. This phenomenon is called the occurrence of a decryption error. Furthermore, as a method of avoiding decryption errors, a method of adding additional information to the plaintext, encrypting it, and sending it together with the hash function value of the plaintext is disclosed (for example, refer to Non-Patent Document 1).
[0006] On the other hand, in recent years, as a new concept of public key cryptography, a method called Key Encapsulation Mechanisms has been proposed (for example, refer to Non-Patent Document 3). The key sealing mechanism is an algorithm that uses a public key password to distribute a shared key between the sending device and the receiving device. The sending device inputs the recipient's public key pk to the encryption algorithm E, and then generates the encrypted text C and shared Key K, and send the encrypted text C to the receiving device. Secondly, the receiving device inputs the secret key sk and the encrypted text C to the decryption algorithm D, and then obtains the same shared key K as the sending device.
[0007] In this way, after using the key sealing mechanism to make the sending device and the receiving device share the shared key K, the sending device uses the public key cryptography method and uses the shared key K to encrypt the plain text sent to the receiving device. , Generate an encrypted text, and send the generated encrypted text to the receiving device. The receiving device receives the encrypted text, decrypts the received encrypted text using the public key cryptographic method and the shared key K, and then generates the decrypted text.
[0008] In the past, the key sealing mechanism did not have a feature in that it sent information unidirectionally from the sender to the receiver, but the sender could not intentionally generate a shared key, thereby limiting the senders illegal behavior.
[0009] As such a key sealing mechanism, an algorithm called PSEC-KEM is disclosed (for example, refer to Non-Patent Document 3 and Non-Patent Document 4). Next, the PSEC-KEM algorithm described in Non-Patent Document 4 will be described.
[0010] (1) System parameters of PSEC-KEM
[0011] PSEC-KEM has the following system parameters.
[0012] Elliptic curve: E
[0013] Point of digit n on the elliptic curve: Ρ
[0014] Hash function: G, Η
[0015] In addition, the elliptic curve, the number of bits, and the hash function are described in detail in Non-Patent Document 1, and their description is omitted here.
[0016] (2) Public key and secret key of PSEC-KEM
[0017] Randomly select the element X of Zn, and generate W=x*P.
[0018] Here, Zn is a set composed of {0,1,--η-1}, and x*P represents a point on the elliptic curve obtained by adding the points P on the x elliptic curves. In addition, the method of adding points on an elliptic curve has been described in Non-Patent Document 1.
[0019] Suppose the public key pk is (EPWn), and the secret key sk is X.
[0020] (3) Encryption of PSEC-KEM
[0021] During encryption, the public key pk is input to the following encryption algorithm KemE, and then the shared key K and the encrypted text C are output.
The following describes the encryption algorithm KemEο
[0022] Randomly generate So with the same bit length as the output bit length of the hash function H
[0023] Generate G(s) and split G(s) to generate a and K. a is a bit string composed of the high-order bits of G(s), and K is a bit string composed of the remaining bits. Here, G(s) =a||K<sub>o</sub> IR is an operator that represents bit combination. That is, if a and K are combined, G(s) is obtained.
[0024] Generate R=a*P, Q=a*W.
[0025] Generate ν = sxor H(R| | Q). Here, xor means exclusive operation.
[0026] Output the shared key K and the encrypted text C = (R, ν) ο
[0027] (4) Decryption of PSEC-KEM
[0028] When decrypting, input the encrypted text C=(R,v), the public key pk and the secret key sk to the following decryption algorithm KemD, and then output the shared key K. Next, explain the decryption algorithm KemDo
[0029] Generate Q=x*R.
[0030] · Generate s = v xor H (R | IQ) ο
[0031] Generate G (s) and divide G (s) into G (s) = a I IK.
[0032] Check whether R=a*P holds. If it is established, the shared key K is output.
[0033] When the PSEC-KEM algorithm is applied to a cryptographic system for encrypted communication between a transmitting device and a receiving device, first, the transmitting device obtains the public key Pk of the receiving device of the communication destination, and the obtained public secret The key pk is input into the aforementioned encryption algorithm KemE, and then the shared key K and the encrypted text C are derived, and then the encrypted text C is sent to the receiving device.
[0034] Secondly, the receiving device receives the encrypted text C from the sending device, and inputs the received encrypted text C and its own public key pk and secret key sk into the aforementioned decryption algorithm KemD, and the derivation is the same as that derived by the sending device. Shared key Ko
[0035] Hereinafter, it will be described in further detail.
[0036] Now, the PSEC-KEM algorithm takes the input of the hash function H as (a*P | | a*W), so that the value of H(a*P| |a*W) acts on the random encryption algorithm KemE The generated element s generates ν. Then, using the secret key sk( = X) in the decryption algorithm KemD, Q = x*R = x* (a*P) = a* (x*P) = a can be obtained from R = a*P *W, therefore, by applying the value of H(a*P| |a*W) to v, the random element s generated in the encryption algorithm KemK can be obtained.
[0037] Therefore, the encryption algorithm KemE and the decryption algorithm KemD can input the same value of s into the hash function G, and can derive the same result of the shared key Ko, and the receiving device with the secret key sk can derive and send the value of the device. Export
CN 1745537 Β
The same shared key Κ.
[0038] On the other hand, even if another receiving device that does not know the secret key sk obtains the public key pk and receives the encrypted text C, it does not know the secret key sk (=X), so it cannot be based on R=a*P Calculate Q = a*W (= (ax)*P), it is impossible to derive the same shared key Ko as that derived by the sending device
[0039] This is because other receiving devices that do not know the secret key sk can only use the public key pk, and use the public key pk to replace the secret key sk (=X) in the above calculation. However, generally, according to a*P and W = x*P Finding Q = a*W( = (ax)*P) is called the Diffie-Hellman problem on the elliptic curve. If the value of a or x is not known, it is difficult to calculate ( For example, refer to Non-Patent Document 5).
[0040] That is, in the PSEC-KEM algorithm, the Diffie-Hellman problem, which is difficult to calculate a*W based on a*P without using a secret key, is used, and the shared key K is finally derived, so that if the secret key is not known , The shared key K cannot be derived.
[0041] It can be seen from the above that the sending device and the receiving device can secretly possess the shared key K, and the communication content data communicated from the sending device to the receiving device using the secret key encryption will be encrypted using the shared key K and the public key encryption. Encrypt it in the form of.
[0042] (Patent Document 1)
[0043] JP 2002-252611 Bulletin
[0044] (Non-Patent Document 1)
[0045] Okamoto Ryuaki, Yamamoto Hirosuke, "Modern Cryptography", Series/Information Science Mathematics, Industry Books, 1997
[0046] (Non-Patent Document 2)
[0047] Jeffery Hoffstein, Jill Pipher and Joseph H. Silverman, <sup>U</sup>NTRU: A ring based public key cryptosystem, Lecture Notesin Computer Science, 1423, pp. 267-288, Springer-Verlag, 1988.
[0048] (Non-Patent Document 3)
[0049] Victor Shoup, A proposal for an ISO standard for publickey encryption (version 2. 1) ", [online], December 20, 2001, [Retrieved on September 29, 2002], Internet<URL:http: //shoup. net/papers/iso-2_l. pdf>
[0050] (Non-Patent Document 4)
[0051] Tatsuaki Okamoto, ^Generic conversions for constructingIND-CCA2 public-key encryption in the random oracle model, [online],The 5th Workshop on Elliptic Curve Cryptography (ECC2001), October 30, 2001 Η, [September 2002 Retrieved on the 29th], Internet <URL :http://www. cacr. math.uwaterloo. ca/conferences/2001/ecc/okamoto. PPt>
[0052] (Non-Patent Document 5)
[0053] Neal Koblitz, Algebraic Aspects of Cryptography, Algorithms and Computation in Mathematics Vol. 3, pp. 132-133, Springer-Verlag, 1998
[0054] As described above, the existing PSEC-KEM algorithm uses &*P and &*W in the input of the hash function H, and utilizes Diffie, which is difficult to calculate &*W based on &*P without using a secret key. -Hellman problem, and finally derived the shared key K, so if the secret key is not known, the shared key Ko cannot be derived
[0055] However, in other public key ciphers that do not solve the Diffie-Hellman problem, headed by the NTRU cipher,
CN 1745537 Β
Since there are no parameters equivalent to a*P and a*W in the Diffie-Hellman problem, it is not applicable to the PSEC-KEM algorithm. That is, the NTRU cipher that can perform high-speed processing cannot use the PSEC-KEM algorithm as a key sealing mechanism to distribute the shared key. Therefore, there are sending devices and receiving devices that cannot transfer from the sending device using the shared key to the receiving device. Encrypted communication of the device.
Summary of the invention
[0056] In order to solve the above problems, the purpose of the present invention is to provide a key sharing system, a shared key generation device, a shared key recovery device, a shared key generation method, a shared key recovery method, and a shared key generation program And the shared key recovery program, even if a cryptographic method that does not solve the Diffie-Hellman problem is used, the shared key can be distributed from the shared key generation device to the shared key recovery device without letting a third party know it. , Which can prevent the derivation of different shared keys between the shared key generation device and the shared key recovery device.
[0057] In order to achieve the above object, the present invention provides a key sharing system, which is composed of a shared key generating device and a shared key recovery device that generates a shared key, and generates a shared key that is not known to a third party, The shared key generating device includes: a seed value generating device that generates a seed value, a first shared key generating device that generates a verification value and a shared key based on the generated seed value, and encrypts and regenerates the generated verification value The first encryption device that generates the first encrypted information, the second encryption device that encrypts the generated seed value based on the generated verification value to regenerate the second encrypted information, and transmits the generated first encrypted information and A second encrypted information transmitting device, wherein the shared key recovery device has: a receiving device that receives the first encrypted information and the second encrypted information, and decrypts the received first encrypted information to generate a first decryption verification value A first decryption device, a second decryption device that decrypts the received second encrypted information based on the generated first decryption verification value and generates a decryption seed value, using the same method as the first shared key generating device, The second shared key generating device that generates the second decryption verification value and the decryption shared key based on the generated decryption seed value, and determines whether the output has been output based on the generated first decryption verification value and the second decryption verification value. The generated judgment device for the above-mentioned decrypted shared key, and output when it is judged to be output An output device for the above-mentioned decrypted shared key that has been generated.
[0058] According to this configuration, the shared key generating device generates a verification value and a shared key based on a seed value, encrypts the verification value to generate first encrypted information, and encrypts the seed value based on the verification value to generate a second Encrypted information, the shared key restoration device decrypts the first encrypted information to generate a first decryption verification value, decrypts the second encrypted information based on the first decryption verification value to generate a decryption seed value, and the first shared secret Like the key generation device, it generates a second decryption verification value and a decryption shared key based on the decryption seed value, and determines whether to output the generated decryption shared key based on the generated first decryption verification value and the second decryption verification value. Therefore, it is possible to distribute a shared key that is not known to a third party from the shared key generation device to the shared key recovery device. In this case, it is possible to prevent the difference between the shared key generation device and the shared key recovery device from being derived Shared key.
[0059] Here, the shared key generating device further includes: an acquiring device for acquiring content and an encryption device for encrypting the acquired content using the generated shared key to regenerate encrypted content, and the transmitting device further transmits the generated The above-mentioned encrypted content, the above-mentioned receiving device further receives the above-mentioned encrypted content, the above-mentioned shared key recovery device further has: a decryption device that uses the outputted decryption shared key to decrypt the received encrypted content to regenerate the decrypted content, and An output device that outputs the generated decrypted content.
[0060] According to this configuration, the shared key generation device uses the generated shared key to encrypt the acquired content to regenerate the encrypted content, and the shared key recovery device uses the outputted decrypted shared key pair. receive
The above-mentioned encrypted content is decrypted to regenerate the decrypted content. Therefore, it is possible to transmit content that is not known to a third party from the shared key generation device to the shared key recovery device.
[0061] In addition, the present invention is a shared key generation device that transmits a shared key to a counterpart device without letting a third party know it, and has a seed value generation device that generates a seed value, and generates a verification value based on the generated seed value. And a shared key generating device that shares the key, a first encryption device that encrypts the generated verification value and then generates the first encrypted information, and encrypts and regenerates the generated seed value based on the generated verification value A second encryption device that becomes the second encrypted information, and a transmission device that transmits the first encrypted information and the second encrypted information that have been generated.
[0062] According to this configuration, the shared key generation device encrypts the verification value to generate the first encrypted information, and encrypts the seed value based on the verification value to generate the second encrypted information. Therefore, it can be further improved by double encryption. safety. As long as the third party does not know the encryption methods of the first and second encryption devices, they cannot obtain the shared key.
[0063] Here, the seed value generating device generates a random number, and generates the seed value by using the generated random number as the seed value.
[0064] According to this configuration, the shared key generating device generates a random number and uses the generated random number as the above-mentioned seed value. Therefore, the seed value is generated, the verification value and the shared key are generated, and the first encrypted information and the second encrypted information are generated. After encrypting the information and sending the first encrypted information and the second encrypted information, when the next seed value is generated, the next seed value that is different from the initially generated seed value can be generated. Therefore, the first encrypted information and the second encrypted information transmitted by the shared key generation device are different every time. Therefore, even if a third party eavesdrops on and records the first encrypted information and the second encrypted information sent from the shared key generating device to the counterpart device at this time, it is difficult to base each of the recorded first encrypted information and second encrypted information. Introduce the original seed value.
[0065] Here, the shared key generating device executes a one-way function on the seed value to generate a function value, and generates the verification value and the shared key based on the generated function value.
[0066] According to this configuration, a one-way function is performed on the seed value to generate the verification value. Therefore, even if a third party knows the verification value, it is difficult to obtain the seed value from the verification value. Therefore, it is practically impossible to obtain the above-mentioned seed value and thus the shared key based on the above-mentioned verification value.
[0067] Here, the shared key generation device executes a hash function as the one-way function on the seed value to generate the function value.
[0068] According to this configuration, the above-mentioned one-way function is a hash function, so its algorithm is familiar to everyone and easy to use.
[0069] Here, the shared key generating device uses a part of the generated function value as the verification value and the other part as the shared key, thereby generating the verification value and the shared key.
[0070] According to this configuration, a part of the function value is used as the verification value and the other part is used as the shared key. Therefore, it is easy to generate the verification value and the shared key.
[0071] Here, the shared key generating device performs a one-way function on the seed value to regenerate a function value, and generates the verification value, the shared key, and the blind value based on the generated function value.
[0072] According to this configuration, a one-way function is performed on the seed value to generate the verification value. Therefore, even if a third party knows the verification value, it is difficult to obtain the seed value based on the verification value. Therefore, it is practically impossible to obtain the seed value and thus the shared key based on the above verification value.
[0073] Here, the first encryption device includes a public key acquisition unit that acquires a public key, and uses the acquired public key and the generated blind value to execute a public key encryption algorithm on the verification value to regenerate the first 1 Public key encryption part of encrypted information.
CN 1745537 Β
[0074] In addition, the first encryption device includes a public key acquisition unit that acquires a public key, and uses the acquired public key to execute a public key encryption algorithm on the verification value to regenerate a public key for the first encrypted information Encryption Department.
[0075] According to this configuration, the first encryption device uses the public key encryption method, and therefore, it is easier to manage the keys compared to the case of using the shared key encryption method.
[0076] Here, the public key encryption algorithm is an NTRU encryption method, the public key acquisition unit acquires a public key polynomial generated by a key generation algorithm of the NTRU encryption method as the public key, and the public key encryption unit Generate a verification value polynomial based on the above verification value, generate a blind value polynomial based on the above blind value, use the NTRU encryption algorithm to use the above public key polynomial as a key, and use the above blind value polynomial to encrypt the above verification value polynomial The verification value polynomial is used to generate the first encrypted information as a polynomial.
[0077] In addition, the public key encryption algorithm is an NTRU encryption method, the public key acquisition unit acquires a public key polynomial generated by a key generation algorithm of the NTRU encryption method as the public key, and the public key encryption unit Generate a verification value polynomial based on the verification value, generate a blind value and generate a blind value polynomial based on the generated blind value, use the NTRU encryption algorithm to use the public key polynomial as a key, in order to disrupt the verification value polynomial, Use the blind value polynomial to encrypt the verification value polynomial, and then generate the first encrypted information as a polynomial.
[0078] According to this configuration, the NTRU password can be used.
[0079] Here, the second encryption device performs a one-way function on the verification value to regenerate a function value, uses the generated function value to perform an encryption algorithm on the seed value, and regenerates the second encrypted information.
[0080] According to this configuration, the function value obtained by executing the one-way function on the verification value is used to execute the encryption algorithm on the seed value, and then the second encrypted information is generated. Therefore, as long as the third party does not know the one-way function Function and the above encryption algorithm, the above seed value cannot be obtained from the above second encrypted information.
[0081] Here, the second encryption device generates the second encrypted information by performing an exclusive operation as the encryption algorithm on the generated function value and the seed value.
[0082] According to this configuration, since the above-mentioned encryption algorithm is an exclusive operation, it is easy to use. In addition, the inverse operation can also be performed.
[0083] Here, the second encryption device generates the second encrypted information by executing a public key encryption algorithm as the encryption algorithm on the generated function value and the seed value.
[0084] According to this configuration, since the above-mentioned encryption algorithm is a well-known public key encryption algorithm, it is easy to use. In addition, the inverse operation can also be performed.
[0085] Here, the second encryption device generates the second encrypted information by performing an addition operation as the encryption algorithm on the generated function value and the seed value.
[0086] According to this configuration, since the above-mentioned encryption algorithm is an addition operation, it is easy to use. In addition, the inverse operation can also be performed.
[0087] Here, the second encryption device generates the second encrypted information by performing a multiplication operation as the encryption algorithm on the generated function value and the seed value.
[0088] According to this configuration, since the above-mentioned encryption algorithm is a multiplication operation, it is easy to use. In addition, the inverse operation can also be performed.
[0089] Here, the second encryption device performs a hash function regeneration as the one-way function on the verification value
CN 1745537 Β
The above function value.
[0090] According to this configuration, the above-mentioned one-way function is a hash function, and its algorithm is familiar to everyone, so it is easy to use.
[0091] Here, the second encryption device uses the verification value to execute an encryption algorithm on the seed value, and then generates second encrypted information.
[0092] According to this configuration, the encryption algorithm is executed on the seed value using the verification value, which is easy to use due to simple calculations.
[0093] Here, the second encryption device encrypts the seed value using the verification value and the first encryption information.
[0094] According to this configuration, the seed value is encrypted using the verification value and the first encrypted information. Therefore, if an illegal third party does not know the verification value and the first encrypted information, they will not be able to obtain Seed value, thereby improving security.
[0095] Here, the second encryption device performs a one-way function on the verification value and the first encrypted information to generate the function value, and uses the generated function value to perform an encryption algorithm on the seed value to generate the second encryption information.
[0096] According to this configuration, a one-way function and encryption algorithm are used. Therefore, even if an illegal third party knows the first encrypted information and the second encrypted information, at least if one does not know the one-way function and encryption algorithm, it will not be obtained. Seed value, thereby improving safety.
[0097] Here, the second encryption device generates the second encrypted information by performing an exclusive operation as the encryption algorithm on the generated function value and the seed value.
[0098] According to this configuration, since the above-mentioned encryption algorithm is an exclusive operation, the operation is easy. In addition, you can also perform inverse operations.
[0099] Here, the shared key generating device further includes: an acquiring device for acquiring content and an encryption device for encrypting the acquired content using the generated shared key to regenerate encrypted content, and the transmitting device further transmits the generated The above encrypted content.
[0100] According to this configuration, the shared key generation device can transmit content to the counterpart device without letting a third party know it.
[0101] Here, it is a shared key restoration device that receives the shared key from the shared key generation device without letting a third party know it. The shared key generation device generates a seed value, and generates a verification value based on the generated seed value. And the shared key, encrypt the generated verification value to generate first encrypted information, encrypt the generated seed value based on the generated verification value to generate second encrypted information, and send the generated first encrypted information Encrypted information and the second encrypted information, and the shared key restoration device has: a receiving device that receives the first encrypted information and the second encrypted information, and decrypts the received first encrypted information to generate a first decryption verification value The first decryption device, the second decryption device that generates the decryption seed value after decrypting the received second encrypted information based on the generated first decryption verification value, uses the same method as the shared key generation device, and A shared key generating device that generates a second decryption verification value and a decryption shared key based on the generated decryption seed value, and determines whether to output the generated first decryption verification value and the second decryption verification value based on the generated first decryption verification value and the second decryption verification value. A judging device for the decrypted shared key, and an output device that outputs the generated decrypted shared key when it is judged to be output.
[0102] According to this configuration, it is possible to receive the shared key from the shared key generation device without letting a third party know it. In this case, it is also possible to prevent the difference between the shared key generation device and the shared key recovery device from being derived. Shared key.
[0103] Here, the shared key generating device obtains a public key, and uses the obtained public key to pair the
The verification value executes a public key encryption algorithm to regenerate the first encrypted information. The first decryption device includes a secret key acquisition unit that acquires a secret key corresponding to the public key, and uses the acquired secret key pair The received first encrypted information executes the public key decryption algorithm corresponding to the public key encryption algorithm, and then generates the public key decryption unit for the first decrypted verification value.
[0104] According to this configuration, the first decryption device uses the public key encryption method, and therefore, it is easier to manage the key compared with the case of using the shared key encryption method.
[0105] Here, the public key encryption algorithm and the public key decryption algorithm use the NTRU cryptographic method, and the shared key generation device obtains the public key polynomial generated by the NTRU cryptographic key generation algorithm as the public key Key, generate a verification value polynomial based on the verification value, generate a blind value and generate a blind value polynomial based on the generated blind value, use the NTRU encryption algorithm to use the public key polynomial as a key, in order to disrupt the verification value Polynomial, encrypting the verification value polynomial using the blind value polynomial, and regenerating the first encrypted information as a polynomial, the receiving device receives the first encrypted information as a polynomial, and the secret key acquisition unit acquires the encryption using the NTRU encryption method The secret key polynomial generated by the key generation algorithm is used as the secret key, and the public key decryption unit uses the decryption algorithm corresponding to the encryption algorithm in the NTRU encryption method to use the secret key polynomial as the key. The first encrypted information is decrypted to generate a decryption verification value polynomial, and the first decryption verification value is generated based on the generated decryption verification value polynomial.
[0106] According to this configuration, NTRU passwords can be used.
[0107] Here, the shared key generation device performs a one-way function on the verification value to regenerate a function value, uses the generated function value to perform an encryption algorithm on the seed value, and then generates the second encrypted information, the second The decryption device performs the one-way function on the generated first decryption verification value to regenerate a decryption function value, and uses the generated decryption function value to perform a decryption algorithm corresponding to the encryption algorithm on the received second encrypted information, Then generate the decryption seed value described above.
[0108] According to this configuration, the second decryption device uses a two-stage operation method of a one-way function and a decryption algorithm. Therefore, even if an illegal third party knows the first encrypted information and the second encrypted information, at least if one does not know the one-way The function and decryption algorithm also cannot get the seed value, thus improving the security.
[0109] Here, the public key generation device generates the second encrypted information by performing an exclusive operation as the encryption algorithm on the generated function value and the seed value, and the second decryption device generates the second encrypted information by performing an exclusive operation on the generated function value and the seed value. The decryption function value and the second encrypted information perform an exclusive operation as the decryption algorithm to generate the decryption seed value.
[0110] According to this configuration, since the above-mentioned decryption algorithm is an "exclusive" operation, the operation is easy, and it is also the inverse operation of the above-mentioned encryption algorithm.
[0111] Here, the shared key generation device generates the second encrypted information by executing the public key encryption algorithm as the encryption algorithm on the generated function value and the seed value, and the second decryption device generates the second encrypted information by The generated decryption function value and the second encrypted information execute a public key decryption algorithm corresponding to the public key encryption algorithm as the decryption algorithm to generate the decryption seed value.
[0112] According to this configuration, since the above-mentioned decryption algorithm is a well-known shared key decryption algorithm, it is easy to use, and it is also the inverse operation of the above-mentioned encryption algorithm.
[0113] Here, the public key generation device generates the second encrypted information by performing the addition operation as the encryption algorithm on the generated function value and the seed value, and the second decryption device generates the second encrypted information by performing an addition operation on the generated function value and the seed value.
CN 1745537 Β
The decryption function value and the second encrypted information are subtracted as the decryption algorithm to generate the decryption seed value.
[0114] According to this configuration, since the above-mentioned decryption algorithm is a subtraction operation, the operation is easy, and it is also the inverse operation of the above-mentioned encryption algorithm.
[0115] Here, the shared key generation device generates the second encrypted information by performing a multiplication operation as the encryption algorithm on the generated function value and the seed value, and the second decryption device generates the second encrypted information by performing a multiplication operation on the generated function value and the seed value. The decryption function value and the second encrypted information perform a division operation as the decryption algorithm to generate the decryption seed value.
[0116] According to this configuration, since the above-mentioned decryption algorithm is a division operation, the operation is easy, and it is also the inverse operation of the above-mentioned encryption algorithm.
[0117] Here, the shared key generation device executes a hash function as the one-way function on the verification value to generate the function value, and the second decryption device executes the generated first decryption verification value as the single To the hash function of the function, the decryption function value is generated.
[0118] According to this configuration, since the above-mentioned one-way function is a hash function and is a familiar algorithm, it is easy to use.
[0119] Here, the shared key generation device uses the verification value to execute an encryption algorithm on the seed value to generate the second encrypted information, and the second decryption device uses the generated first decryption verification value to perform the verification on the second The encrypted information executes a decryption algorithm corresponding to the encryption algorithm to generate the decryption seed value.
[0120] According to this configuration, the second encrypted information is decrypted using the first decryption verification value, so the calculation is easy.
[0121] Here, the shared key generation device encrypts the seed value using the verification value and the first encryption information, and the second decryption device uses the generated first decryption verification value and the received first decryption value. The encrypted information decrypts the second encrypted information to generate the decryption seed value.
[0122] According to this configuration, the second encrypted information is decrypted using the first decrypted verification value and the first encrypted information, so if an illegal third party does not know the first decrypted verification value and the first encrypted information , The seed value cannot be obtained, thus improving the safety.
[0123] Here, the shared key generation device performs a one-way function on the verification value and the first encryption information to generate a function value, and uses the generated function value to perform an encryption algorithm on the seed value to generate the second encryption Information, the second decryption device executes the one-way function on the first decryption verification value and the first encrypted information to generate a decryption function value, and uses the generated decryption function value to perform the encryption on the second encrypted information The decryption algorithm corresponding to the algorithm generates the decryption seed value described above.
[0124] According to this configuration, the second decryption device uses a two-stage calculation method of a one-way function and a decryption algorithm. Therefore, even if an illegal third party knows the first encrypted information and the second encrypted information, at least if they do not know The one-way function and decryption algorithm also cannot obtain the seed value, which improves the security.
[0125] Here, the shared key generation device generates the second encrypted information by performing an exclusive operation as the encryption algorithm on the generated function value and the seed value, and the second decryption device generates the second encrypted information by decrypting the generated function value and the seed value. The function value and the second encrypted information perform an exclusive operation as the decryption algorithm to generate the decryption seed value.
[0126] According to this configuration, the above-mentioned decryption algorithm is an "exclusive" operation, so the operation is easy, and it is also the inverse operation of the above-mentioned encryption algorithm.
[0127] Here, the shared key generation device performs a one-way function on the seed value to generate a function value, and generates the verification value and the shared key based on the generated function value, and the shared key generation device has Generated
The decryption seed value executes the one-way function to generate a decryption function value, and generates the second decryption verification value and the decryption shared key based on the generated decryption function value.
[0128] According to this configuration, a one-way function is performed on the decryption seed value to generate the second decryption verification value. Therefore, even if a third party knows the second decryption verification value, it is difficult to perform the decryption based on the second decryption verification value. The verification value finds the above-mentioned seed value. Therefore, it is practically impossible to obtain the seed value and thus the shared key based on the second decryption verification value. [0129] Here, the shared key generation device executes a hash function as the one-way function on the seed value to generate the function value, and the shared key generation device executes the generated decryption seed value as the one-way function value. The above-mentioned hash function of the function generates the above-mentioned decryption function value.
[0130] According to this configuration, the above-mentioned one-way function is a hash function, so its algorithm is familiar to everyone and easy to use.
[0131] Here, the shared key generating device uses part of the generated function value as the verification value and the other part as the shared key, thereby generating the verification value and the shared key, and the shared key The generating device uses a part of the generated decryption function value as the second decryption verification value and the other part as the decryption shared key, thereby generating the second decryption verification value and the decryption shared key.
[0132] According to this configuration, a part of the decryption function value is used as the second decryption verification value and the other part is used as the decryption shared key. Therefore, it is easy to generate the second decryption verification value and the decryption shared key.
[0133] Here, the shared key generating device performs a one-way function on the seed value to regenerate the function value, generates the verification value, the shared key, and the blind value based on the generated function value, obtains the public key, and uses The obtained public key and the generated blind value, the public key encryption algorithm is executed on the verification value to generate the first encrypted information, and the shared key generation device executes the above list on the generated decryption seed value. To the function, a decryption function value is generated, and the second decryption verification value, the decryption shared key, and the decryption blind value are generated based on the generated decryption function value.
[0134] According to this configuration, a one-way function is performed on the decryption seed value to generate the second decryption verification value. Therefore, even if a third party knows the second decryption verification value, it is difficult to perform the decryption based on the second decryption verification value. The verification value finds the above-mentioned seed value. Therefore, it is practically impossible to obtain the seed value and thus the shared key based on the second decryption verification value described above.
[0135] Here, the shared key generating unit obtains a public key and uses the obtained public key and the generated blind value to execute a public key encryption algorithm on the verification value to generate the first encrypted information, the The judgment device replaces the judgment based on the first decryption verification value and the second decryption verification value, and includes: a public key obtaining unit that obtains the public key, using the obtained public key and the generated decryption blind A re-encryption unit that executes the public-key encryption algorithm to generate re-encrypted information based on the generated first decryption verification value or the second decryption verification value generated, based on the received first encrypted information and the generated re-encryption The information determines whether to output the generated decryption shared key.
[0136] According to this configuration, it is determined whether to output the generated decryption shared key based on the received first encrypted information and the generated re-encrypted information. Therefore, it is possible to prevent the third party from knowing it, and the receiving slave The shared key from the shared key generating device can also prevent the derivation of different shared keys between the shared key generating device and the shared key receiving device at this time.
[0137] Here, the judgment unit compares the first encrypted information with the re-encrypted information, and when the first encrypted information and the re-encrypted information match, judge to output the decryption shared key. In addition, the determination unit compares the first decryption verification value with the second decryption verification value, and when they match, determines that the decryption shared key is output.
[0138] According to this configuration, when the first encrypted information and the re-encrypted information match, the decryption shared key is output. Therefore,
CN 1745537 Β
The Π/47 page can reliably determine whether to output the decrypted shared key.
[0139] Here, the public key encryption algorithm adopts the NTRU cryptographic method, and the shared key generation device obtains a public key polynomial generated by the NTRU cryptographic key generation algorithm as the public key, and generates verification based on the verification value. Value polynomial, generate a blind value polynomial based on the above blind value, use the NTRU encryption algorithm to use the above public key polynomial as a key, in order to disturb the above verification value polynomial, use the above blind value polynomial to encrypt the verification value polynomial, and regenerate The first encrypted information is formed as a polynomial, the public key acquisition unit acquires the public key polynomial, the re-encryption unit generates a decryption verification value polynomial based on the second decryption verification value, and generates a decryption blind value polynomial based on the decryption blind value Using the NTRU encryption algorithm to use the public key polynomial as a key, in order to disrupt the decryption verification value polynomial, the blind value polynomial is used to encrypt the decryption verification value polynomial, and then the re-encrypted information as a polynomial is generated.
[0140] According to this configuration, NTRU passwords can be used.
[0141] Here, the shared key generating device further obtains content, encrypts the obtained content using the generated shared key to regenerate encrypted content, and transmits the generated encrypted content, and the receiving device further receives the For encrypted content, the shared key restoration device further includes a decryption device that decrypts the received encrypted content using the output decryption shared key and then generates the decrypted content, and an output device that outputs the generated decrypted content.
[0142] According to this configuration, the shared key generating device uses the generated shared key to encrypt the acquired content to regenerate the encrypted content, and the shared key recovery device uses the outputted decrypted shared key pair. The received encrypted content is decrypted to regenerate the decrypted content. Therefore, it is possible to transmit content that is not known to a third party from the shared key generation device to the shared key recovery device.
Description of the drawings
[0143] FIG. 1 is a conceptual diagram showing the configuration of the content distribution system 10 and the connection form between the constituent elements. [0144] FIG. 2 is a block diagram showing the configuration of the encryption device 110.
[0145] FIG. 3 is a block diagram showing the configuration of the decryption device 120.
4 is a processing system diagram showing the operations of the encryption device 110 and the decryption device 120.
[0147] FIG. 5 is a flowchart showing the operations of the encryption device 110 and the decryption device 120.
[0148] FIG. 6 is a block diagram showing the configuration of the encryption device 110b.
[0149] FIG. 7 is a block diagram showing the configuration of the decryption device 120b.
[0150] FIG. 8 is a processing system diagram showing the operations of the encryption device 110b and the decryption device 120b.
[0151] FIG. 9 is a block diagram showing the configuration of the encryption device 110c.
[0152] FIG. 10 is a block diagram showing the configuration of the decryption device 120c.
[0153] FIG. 11 is a processing system diagram showing the operations of the encryption device 110c and the decryption device 120c.
[0154] FIG. 12 is a processing system diagram showing the operation of a modification of the encryption device 110c and the decryption device 120c.
[0155] FIG. 13 is a block diagram showing the configuration of the encryption device 110d.
[0156] FIG. 14 is a block diagram showing the configuration of the decryption device 120d.
15 is a flowchart showing the operations of the encryption device 110d and the decryption device 120d.
[0158] FIG. 16 is a processing system diagram showing the operations of the encryption device 110d and the decryption device 120d.
[0159] FIG. 17 is a block diagram showing the configuration of the encryption device 110e.
CN 1745537 Β
[0160] FIG. 18 is a block diagram showing the configuration of the decryption device 120e.
[0161] FIG. 19 is a processing system diagram showing the operations of the encryption device 110e and the decryption device 120e.
[0162] FIG. 20 is a processing system diagram showing the operations of the encryption device 110e and the decryption device 120e.
Detailed ways
[0163] Embodiment 1
[0164] The content distribution system 10 as one embodiment of the present invention will be described. The content distribution system 10 is used
An encrypted communication system in which the NTRU password performs the key distribution of the key sealing mechanism and then performs encrypted communication.
[0165] 1. 1NTRU password method
[0166] The NTRU encryption method used in the content distribution system 10 is briefly described. The NTRU encryption method is a public key encryption method that uses polynomial operations for encryption and decryption.
[0167] Furthermore, the NTRU encryption method and the method of generating the public key and the secret key in the NTRU encryption method are described in detail in Non-Patent Document 2.
[0168] (1) System parameters of NTRU password mode
[0169] In the NTRU encryption method, there are integer system parameters N, p, and q, and the encryption device and decryption device described later have such system parameters.
[0170] In the above-mentioned documents, as examples of system parameters, (N, p, q) = (107, 3, 64), (N, p, q) = (167, 3, 128), (N, p, q) = (503,3,256) 3 examples.
[0171] Hereafter, in this embodiment, the system parameter N=167 is taken as an example for description.
[0172] (2) Polynomial operation of NTRU encryption method
[0173] As described above, the NTRU encryption method is a public key encryption method that uses polynomial operations for encryption and decryption.
[0174] The polynomial processed by the NTRU cryptographic method is a polynomial below the N1 power of the above-mentioned system parameter N. For example, when N = 5, it is a polynomial such as X~4+X~3+l. Here,'X'a means X to the power of a.
[0175] In addition, the public key h, secret key f, plain text m, random number, and encrypted text c used during encryption or decryption can all be expressed by polynomials below the power of N-1 (hereinafter referred to as Make public key polynomial h, secret key polynomial f, plain text polynomial m, random number polynomial r, encrypted text polynomial c) ο
[0176] In the polynomial calculation, for the above-mentioned system parameter Ν, the relational expression Χ~Ν=1 is used, so that the calculation result is always a polynomial below the power of Ν-1.
[0177] For example, if X is used to represent the product of a polynomial and a polynomial, and is used to represent the product of an integer and a polynomial. According to the relationship of X~5=1, when N=5, the polynomial X~4+X~2+1 and The product of the polynomial X'3+X becomes
[0178] (X~4+X~2+1) X (Χ~3+Χ)
[0179] = X~7+2 · X~5+2 · X~3+X
[0180] = X~7+2 · X~5+2 · X~3+X
[0181] = 2 · X~3+X~2+X+2
[0182] In this way, in a polynomial operation, it is always calculated as a polynomial below the power of N-1.
[0183] (3) Encryption by NTRU password
[0184] The encryption device described later performs NTRU encryption as shown below.
[0185] During encryption, the following random number polynomial r and public key polynomial h are used to perform operations on the plaintext polynomial m
CN 1745537 Β
For the encryption algorithm E of the polynomial operation, generate the encrypted text polynomial c = E (m, r, h).
[0186] Here, E (m, r, h) is a polynomial operation result obtained by inputting a plaintext polynomial m, a random number polynomial r, and a public key polynomial h to the encryption algorithm E of the NTRU cryptographic method. The encryption algorithm E is described in detail in Non-Patent Document 2, and its description is omitted here.
[0187] Furthermore, in the NTRU encryption method, the parameter d used to generate the random number polynomial r is determined in advance. Choose in this way, so that among the terms of the random number polynomial r, the coefficients of d terms are 1, and the coefficients of the remaining d terms are'T', and the coefficients of the remaining terms are '0'. .
[0188] That is, the random number polynomial r is a polynomial of the power of N-1 or less, and there are N coefficients for N terms from the power of 0 (constant term) to the power of NT. The random number polynomial r can be selected such that among the N coefficients, d coefficients are '1', and d coefficients are (N-2d) coefficients are '0'.
[0189] According to Non-Patent Document 2, when the parameter N=167, d=18. That is, the random number polynomial r is selected as
Eighteen coefficients are one coefficient (=167-36) and one coefficient is '0'.
[0190] (4) Decryption of NTRU password
[0191] The decryption device described later performs NTRU encryption decryption as shown below.
[0192] During decryption, the secret key polynomial f is used to execute the decryption algorithm E as a polynomial operation on the encrypted text polynomial c, and the decrypted text polynomial m is generated.<sup>,</sup> = D (c, f).
[0193] Here, D(c, f) is a polynomial operation result obtained by inputting the encrypted text polynomial c and the secret key polynomial f to the decryption algorithm D of the NTRU encryption method. The decryption algorithm D is described in detail in Non-Patent Document 2, and its description is omitted here.
[0194] (5) Decryption error of NTRU password
[0195] In this NTRU encryption method, it occurs that the generated decrypted text polynomial m is different from the plain text polynomial m. At this time, the plaintext polynomial m cannot be obtained correctly during decryption. This phenomenon is called a decryption error.
[0196] 1.2 Configuration of content distribution system 10
[0197] As shown in FIG. 1, the content distribution system 10 is composed of a content service device 140, an encryption device 110, a decryption device 120, a reproduction device 150, and a monitor 155. The content service device 140 and the encryption device 110 are connected via a dedicated line 20, The encryption device 110 and the decryption device 120 are connected via the Internet 130. The reproduction device 150 is connected to a monitor 155 in which a decryption device 120 and a speaker are incorporated. The encryption device 110 is equipped with a memory card 160, and the decryption device 120 is equipped with a memory card 170.
[0198] The content service device 140 sends content such as movies and sounds composed of images and sounds to the decryption device 110 via the dedicated line 20.
[0199] The encryption device 110 and the decryption device 120 generate the same shared key K and the shared key K, respectively. Next, the encryption device 110 uses the shared key K to encrypt the content received from the content server device 140, generates encrypted content, and sends the generated encrypted content, and the decryption device 120 receives the encrypted content and decrypts the received encrypted content. The reproduced content is generated, the reproduction device 150 generates an image signal and a sound signal based on the reproduced content, and the monitor 155 displays images and outputs sound.
[0200] 1.3 Composition of content service device 140
[0201] The content service device 140 is a computer system (not shown) composed of a microprocessor, a ROM, a RAM, a hard disk unit, a display unit, a communication unit, a keyboard, a mouse, and the like. A computer program is stored on the RAM or the hard disk unit. The content server 140 realizes a part of its functions by causing the microprocessor to operate in accordance with the computer program.
[0202] The content service device 140 stores the above-mentioned content in advance, and the above-mentioned content is composed of multiple partial contents.
CN 1745537 Β
mi(l W i Wn) constitutes. The content service device 140 reads part of the content mi according to the request of the encryption device 110, and sends the read part of the content mi to the encryption device 110 via the dedicated line 20.
[0203] 1.4 Composition of the memory card 160 and the memory card 170
[0204] The memory card 160 is a card-type storage device that uses a flash memory as a storage medium, and stores a public key polynomial h in advance.
[0205] In addition, the memory card 170 is a card-type storage device similar to the memory card 160, and stores a secret key polynomial f and a public key polynomial h in advance.
[0206] Here, the secret key polynomial f and the public key polynomial h are polynomials generated using NTRU cryptography, and they correspond to each other.
[0207] 1.5 Configuration of Encryption Device 110
[0208] As shown in FIG. 2, the encryption device 110 is composed of a public key input unit 111, a random number generation unit 112, and a first function unit.
113, an encryption unit 114, a first transmission unit 117, a public key encryption unit 118, and a second transmission unit 119 are constituted.
[0209] Specifically, the encryption device 110 is a computer system composed of a microprocessor, a ROM, a RAM, and a communication unit. Computer programs are stored in the aforementioned RAM. The encryption device 110 realizes its function by causing the microprocessor to operate in accordance with the computer program.
[0210] (1) Public key input unit 111
[0211] The public key input unit 111 reads the public key polynomial h of the decryption device 120 from the memory card 160, and outputs the read public key polynomial h to the encryption unit 114.
[0212] (2) Random number generating unit 112
[0213] The random number generation unit 112 generates a random number s as a seed value used to generate the basis of the shared key K, and outputs the generated random number s to the first function unit 113 and the encryption unit 114.
[0214] (3) First function part 113
[0215] The first function unit 113 receives the random number s from the random number generation unit 112, and generates a function value G(s) of the random number s. Here, the function G is a hash function whose output length is 2k bits. Furthermore, the hash function is a one-way function. Secondly, the first function unit 113 uses the high-order k bits of the function value G(s) as a random value u, and uses the low-order k bits of G(s) as the shared key K. Thus, according to the generated function value G(s) The shared key K and the random value u are generated, the generated random value u is output to the encryption unit 114, and the generated shared key K is output to the public key encryption unit 118.
[0216] (4) Encryption Unit 114
[0217] The encryption unit 114 receives the public key polynomial h from the public key input unit 111, receives the random number s from the random number generation unit 112, and receives the random value u from the first function unit 113. Next, as shown below, the first encrypted text cl of the random number s is generated by using the NTRU cipher and using the public key polynomial h and the random value u. Here, the random value u is a blind value, and is used to make the random number s that is the object of encryption unknown.
[0218] The encryption unit 114 generates a random number polynomial r uniquely obtained from a random value u. For the parameter d of the NTRU cipher, the coefficients of the d terms of the random number polynomial r are q\ and the coefficients of the d terms are -1 ', the coefficient of the remaining term is '0,.
[0219] For example, the encryption unit 114 sets the random value u as the initial value (random number seed) of the simulated random number series, and generates 2d non-repeated simulations based on {0.1...N-ι} Random numbers, let the coefficients of the d-th power terms represented by the first d simulated random numbers be, and the coefficients of the d-th power terms represented by the remaining d pseudo-random numbers are ' Τ', the coefficients of the remaining power terms are '0'
[0220] Next, the encryption unit 114 constructs a random number s in order to apply the random number s to the encryption algorithm E of the NTRU cipher.
The number polynomial sp corresponds to the value of each bit of the N-bit bit string when the random number s is expressed in binary with the coefficients of each item of the random number polynomial sp. For example, suppose that the value of the lower b-th bit of the random number s is the coefficient of the term X6. Specifically, when s = 10010 (expressed in bits), generate a random number polynomial sp = X~5+X~2o
[0221] Next, the encryption unit 114 uses the public key polynomial h and the random number polynomial r to execute the aforementioned encryption algorithm E on the random number polynomial sp, and generates the first encrypted text cl=encrypted text polynomial E (sp, r, h).
[0222] Next, the encryption unit 114 outputs the generated first encrypted text c1 to the first transmission unit 117.
[0223] In addition, in FIG. 2, each block representing each component of the encryption device 110 is connected to other blocks by a connecting line. Here, each connection line represents a signal or information transmission path. In addition, among the plurality of connection lines connected to the box indicating the encryption unit 114, the line with the key mark on the connection line indicates the path through which the key information is transmitted to the encryption unit 114. The same is true for the block representing the public key encryption unit 118. In addition, the other diagrams are the same.
[0224] (5) First transmission unit 117
[0225] The first transmission unit 117 receives the first encrypted text c1 from the encryption unit 114, and sends the first encrypted text c1 to the decryption device 120 via the Internet 130.
[0226] (6) Public key encryption unit 118
[0227] The public key encryption unit 118 has, for example, a public key encryption algorithm Sym such as the DES encryption method.
[0228] Generally, in public key encryption, the device on the encryption side uses the encryption key K to execute the public key encryption algorithm sym on the plaintext m to generate the encrypted text c=Sym(m, k). Here, if the encryption key K used when the encrypted text is generated is the same as the encryption key K used when the decrypted text is generated, then m = m. In addition, since the public key encryption and DES encryption methods are described in detail in Non-Patent Document 1, their description is omitted.
[0229] The public key encryption unit 118 receives a plurality of plaintext (partial content) mi(1 w i w n) from the content service device 140, receives the shared key K from the first function unit 113, and uses the received shared key Κ executes the public key encryption algorithm Sym on the plain text mi (1 W i W η) to generate a public key encryption text Ci = Sym(mi, k) (1 W i W η).
[0230] Next, the public key encryption unit 118 sends the public key encrypted text Ci (1 W i W n) to the second transmission unit 119.
[0231] (7) Second transmission unit 119
[0232] The second transmitting unit 119 receives the public key encrypted text Ci (1 W i W n) from the public key encryption unit 118, and transmits the received public key encrypted text Ci (1 W i W n) via the Internet 130. Send to the decryption device 120.
[0233] 1.6 Composition of the decryption device 120
[0234] As shown in FIG. 3, the decryption device 120 is composed of a secret key input unit 121, a first receiving unit 122, a decryption unit 123, and a second
The second function unit 126, the comparison unit 127, the public key decryption unit 128, and the second reception unit 129 are constituted.
[0235] The decryption device 120 is a computer system similar to the encryption device 110. The decryption device 120 realizes its function by causing the microprocessor to operate in accordance with a computer program.
[0236] (1) Secret key input unit 121
[0237] The secret key input unit 121 reads the secret key polynomial f and public key polynomial h of the decryption device 120 from the memory card 170, and outputs the read secret key polynomial f to the decryption unit 123, and reads out the secret key polynomial f and public key polynomial h. The public key polynomial h of is output to the comparison unit 127.
[0238] (2) First receiving unit 122
[0239] The first receiving unit 122 receives the first encrypted text c1 from the encryption device 110 via the Internet 130, and outputs the received first encrypted text c1 to the decrypting unit 123.
[0240] (3) Decryption unit 123
[0241] The decryption unit 123 receives the secret key polynomial f from the secret key input unit 121, and receives the first encrypted text C1 from the first receiving unit 122. As shown below, using the NTRU cipher and the secret key polynomial f, The first encrypted text C1 is decrypted, and a decrypted random number V is generated.
[0242] The decryption unit 123 executes the above-mentioned decryption algorithm D on the first encrypted text cl using the secret key polynomial f, and generates a decrypted random number polynomial sp=D(cl, f). Secondly, the decrypted random number polynomial sp is the decrypted text of the NTRU cipher expressed by polynomials. Therefore, the decrypted random number s is generated so that the coefficients of each item of the decrypted random number polynomial sp' and the decrypted random number s in binary Each value of the N-bit column corresponds to each value. For example, the coefficient of the term X~b of the b-th power of the decrypted random number polynomial sp, becomes the low-order b-th value of the decrypted random number s,.
[0243] Specifically, when the decrypted random number polynomial sp'=X~5+X~2, the decrypted random number S is generated = 10010 (expressed in bits).
[0244] Next, the decryption unit 123 compares the received first encrypted text c1 and the generated decryption random number s<sup>,</sup>Output to the comparison section
127. Output the generated decrypted random number s'to the second function unit 126.
[0245] (4) Second function unit 126
[0246] The second function unit 126 has the same function G algorithm as that of the first function unit 113.
[0247] The second function unit 126 receives the decrypted random number s from the decryption unit 123, and, like the first function unit 113, generates a function value G(s,) of the decrypted random number s, and secondly, based on the function value G(s ,) Generate a random value u and a shared key K, and output the generated random value u and the shared key K to the comparison unit 127.
(5) Comparison unit 127
[0249] As shown in FIG. 3, the comparison unit 127 is composed of an encryption unit 127x and a comparison operation unit 127y.
[0250] The encryption unit 127x receives the public key polynomial h from the secret key input unit 121, receives the decrypted random number V from the decryption unit 123, and receives the random value u'from the second function unit 126. Next, as with the encryption unit 114, use the public key polynomial h and the random value "to encrypt the decrypted random number S to generate the first re-encrypted text c", and output the generated first re-encrypted text cl' to the comparison The arithmetic unit 127y.
[0251] The comparison operation unit 127y receives the first encrypted text c1 from the decryption unit 123, the shared key K'from the second function unit 126, and the first re-encrypted text c1' from the encryption unit 127x. Next, compare the first encrypted text cl and the first re-encrypted text cl' to determine whether they are the same. When the judgment is the same, the received shared key K is output to the public key decryption unit
128. When it is judged to be inconsistent, the received shared key K, is not output.
[0252] (6) Second receiving unit 129
[0253] The second receiving unit 129 receives the public key encrypted text Ci (1 W i W n) from the encryption device 110 via the Internet 130, and outputs the received public key encrypted text Ci (1 W i W n) to the public key. The key decryption unit 128.
[0254] (7) Public key decryption unit 128
[0255] The public key decryption unit 128 has in advance a public key encryption algorithm possessed by the public key encryption unit 118
Sym is the same public key encryption algorithm Sym.
[0256] The public key decryption unit 128 receives the shared key K from the comparison unit 127, receives the public key encrypted text Ci (1 W i W n) from the second receiving unit 129, and uses the received shared key K, For the received public key encrypted text Ci (1 W i W η), execute the public key encryption algorithm Sym, and generate a decrypted text mi, = Sym(C, i, K) (1 W i W η). [0257] Next, the public key decryption unit 128 outputs the generated decrypted text mi' (1 W i W n) to the playback device 150.
[0258] 1.7 Reproduction device 150 and monitor 155
[0259] The reproduction device 150 receives the decrypted text mi' (1 W i W η) from the decryption device 120, and generates an image signal and a sound signal based on the received decrypted text mi, (1 W i W η), and generates the image signal and sound The signal is output to the monitor 155. [0260] The monitor 155 receives an image signal and a sound signal from the reproduction device 150, and uses the received image signal and sound signal to display an image and output sound.
[0261] 1.8 Operations of Encryption Device 110 and Decryption Device 120
[0262] The operations of the encryption device 110 and the decryption device 120 will be described using the processing system shown in FIG. 4 and the flowchart shown in FIG. 5.
[0263] The public key input unit 111 of the encryption device 110 reads the public key polynomial h of the decryption device 120 from the memory card 160, and outputs the read public key polynomial h to the encryption unit 114 (step S101).
[0264] Next, the random number generation unit 112 generates a random number s, and outputs the generated random number s to the first function unit 113 and the encryption unit 114 (step S102).
[0265] Next, the first function unit 113 receives the random number s from the random number generation unit 112, and generates a function value G(s) of the random number s (step S103). Next, the first function unit 113 generates a function value G(s) based on the function value G(s). ) Generate a random value u and a shared key K, output the random value u to the encryption unit 114, and output the shared key K to the public key encryption unit 118 (step S104).
[0266] Next, the encryption unit 114 receives the public key polynomial h from the public key input unit 111, receives the random number s from the random number generation unit 112, receives the random value u from the first function unit 113, and uses the public key polynomial h. And the random value u to generate the first encrypted text cl of the random number s, and output the first encrypted text cl to the first transmitting unit 117 (step S105).
[0267] Next, the first transmission unit 117 receives the first encrypted text c1 from the encryption unit 114, and transmits the first encrypted text c1 to the decryption device 120 via the Internet 130 (step S106).
[0268] Next, the secret key input unit 121 of the decryption device 120 reads the secret key polynomial f and the public key polynomial h of the decryption device 120 from the memory card 170, and outputs the read secret key polynomial f to the decryption unit. 123. Output the read public key polynomial h to the comparison unit 127 (step S151) ο
[0269] Next, the first receiving unit 122 receives the first encrypted text c1 from the encryption device 110 via the Internet 130, and outputs the first encrypted text c1 to the decrypting unit 123 (step S106).
[0270] Next, the decryption unit 123 receives the secret key polynomial f from the secret key input unit 121, receives the first encrypted text c1 from the first receiving unit 122, and then performs the first encrypted text c1 using the secret key polynomial f Decrypt, generate a decrypted random number V, output the first encrypted text cl and the decrypted random number s to the comparison unit 127, and output the decrypted random number s to the second function unit 126 (step S152) ο
[0271] Next, the second function unit 126 receives the decrypted random number s from the decryption unit 123, generates a function value G(s,) of the decrypted random number s, (step S153), and generates a random number based on the function value G(s,) The value u'and the shared key K, and the random value u'and the shared key K are output to the comparison unit 127 (step S154).
[0272] Next, the comparison unit 127 receives the first encrypted text c1 from the decryption unit 123, receives the random value u and the shared key K from the second function unit 126, and generates the first re-decrypted text c1' (step S155), Check whether the first encrypted text cl uses the random value u, the decrypted random number s<sup>,</sup>The encrypted text, if the first encrypted text cl is not a decrypted random number s<sup>,</sup>(Step S156), the decryption device 120 ends the process.
[0273] The public key encryption unit 118 receives a plurality of plain text mi (1 W i W n) from the outside, receives the shared key K from the first function unit 113, and uses the shared key K to compare the plain text mi (1 W i W η) Execute the public key encryption algorithm Sym, generate a public key encrypted text Ci = Sym (mi, Κ) (1 W i W η), and output the public key encrypted text Ci (1 W i W n) to the first 2 The transmission unit 119 (step S107).
CN 1745537 Β
[0274] Next, the second sending unit 119 receives the public key encrypted text Ci (1 W i W n) from the public key encryption unit 118, sends it to the decryption device 120 via the Internet 130 (step S108), and ends the process.
[0275] If the first encrypted text c1 is an encrypted text for decrypting the random number s'(step S156), the comparison unit 127 outputs the shared key K'to the public key decryption unit 128 (step S156), and the comparison unit 127 sends the shared key K'to the public key decryption unit 128 (step S156). The key decryption unit 128 outputs the shared key K'(step S157). Next, the second receiving unit 129 receives the encrypted text Ci (1 W i W η) from the encryption device 110 via the Internet 130, and outputs it to the public key decryption unit 128 (step S108).
[0276] Next, the public key decryption unit 128 receives the shared key K from the comparison unit 127, receives the public key encrypted text Ci (1 W i W n) from the second receiving unit 129, and uses the shared key K to pair The public key encrypted text Ci (1 W i W η) executes the public key encryption algorithm Sym to generate the decrypted text mi, = Sym(Ci, K) (1 W i W η), the decrypted text mi, (l W i W η) is output to the reproduction device 150 (step S158), and the process ends.
[0277] 1.9 Action Check of Content Distribution System
[0278] Next, the overall operation of the content distribution system 10 of the first embodiment will be described.
[0279] First, the encryption device 110 takes the public key polynomial h of the decryption device 120 as input, generates a random number s, and derives the random value u and the shared key K from the function value G(s). Next, the encryption device 110 uses the public key polynomial h and the random value u, and encrypts the random number s with the NTRU cipher, generates a first encrypted text cl, and sends the first encrypted text cl to the decryption device 120 via the Internet 130.
[0280] That is, the encryption device 110 performs the following processing and sends the first encrypted text c1 to the decryption device 120.
[0281] Generate a random number s.
[0282] Generate G (s), and generate u and K based on G (s).
[0283] Use the public key polynomial h and the random value u to generate the first ciphertext clo of the random number s
[0284] Output the shared key K and the first encrypted text cl.
[0285] Next, the encryption device 110 uses the derived shared key K to encrypt the plain text mi (1 W i W η) input from the outside with a public key cipher to generate an encrypted text Ci (1 W i W η) , And sent to the decryption device 120 via the Internet 130.
[0286] On the other hand, the decryption device 120 receives the secret key polynomial f and the public key polynomial h of the decryption device 120 as inputs, receives the first encrypted text c1 from the encryption device 110 via the Internet 130, and uses the secret key polynomial f to The first encrypted text cl is decrypted, and a decrypted random number V is generated. Secondly, according to the function value G(s,) of the decrypted random number s, derive the random value u, and the shared key K, to encrypt the decrypted random number s, and generate the first re-encrypted text c ", if cl'= cl, then output the shared key K'.
[0287] That is, the decryption device 120 performs the following processing and derives the shared key K'.
[0288] Use the secret key polynomial f to decrypt the first encrypted text cl to generate s, ο
[0289] Generate G(s'), and generate u'and K'according to G (s').
[0290] Use the public key polynomial h and the random value u to generate the first re-encrypted text cl of s.
[0291] Check whether cl'=cl is established, and if so, output the shared key K'.
[0292] Here, if the correct secret key polynomial f corresponding to the public key polynomial h used in the encryption device 110 is used in the decryption device 120, the first decrypted text c1 is correctly decrypted and becomes a decrypted random number V, therefore, from G(s<sup>,</sup>) The derived random value u, = u, the shared key K, = Ko and, because s, = s and u, = u are established, so cP = cl is established, the decryption device 120 can derive the same shared secret as the encryption device 110 Key Ko
[0293] Secondly, the decryption device 120 uses the derived shared key K, (=K), from the encryption device 110 via the Internet
The public key encrypted text Ci (1 W i W η) is decrypted with the public key cipher to generate the decrypted text mi' (1 W i W η), and then output to the outside. Here, since the cipher key K used when generating the public key encrypted text is the same as the cipher key Kused when generating the decrypted text, the decryption device 120 can correctly obtain mi=mi(l W i W η).
[0294] Furthermore, when a decryption error occurs, because the decrypted random number s is different from the random number s, the random number u'derived from G(s0) and the shared key K'are different from u and K, respectively. However, this When s'and u'are different from s and u, respectively, the first re-encrypted text cl is different from the first encrypted text cl. Therefore, the decryption device 120 does not output the shared key K. [0295] 1. 10 implementation Effect of form 1
[0296] In the existing RSA-KEM algorithm, the element s that cannot be derived from the encrypted text C unless the secret key is known is input into the hash function G, and the shared key K is derived. However, if the NTRU cipher is used and the RSA-KEM algorithm as the key sealing mechanism is used to distribute the shared key, a decryption error may sometimes occur, so even if the secret key is used, the element s cannot be derived. Therefore, the export may be incorrect. The shared key K,.
[0297] However, in the content distribution system, encryption device, and decryption device of Embodiment 1, the shared key and the random value u are generated based on the hash function G(s) of the random number s, and the decryption device uses the random value u and the public The key polynomial h re-encrypts the decrypted random number s to generate the first re-encrypted text cl. As long as the first re-encrypted text cl and the first encrypted text c are different values, the shared key is not output, so , When a decryption error occurs, it can prevent the encryption device and the decryption device from deriving different keys.
[0298] In addition, the method of the present invention can use the same method as the verification method described in Non-Patent Document 3 to theoretically prove its safety.
[0299] 1.11 Modifications
[0300] The first embodiment described above is an example of carrying out the present invention, and the present invention is not limited to this embodiment, and various aspects can be implemented without departing from the spirit thereof. The present invention also includes the following cases.
[0301] (1) The parameters of the NTRU password used are not limited to N=167. The parameter N can also take other values.
[0302] (2) The conversion method between each bit value of the bit string and the coefficient of each term of the polynomial performed by the encryption unit 114 and the decryption unit 123 is not limited to the above-described method, and other conversion methods may be used.
[0303] For example, the transformation from the random number s to the random number polynomial sp can be performed by using a function in which the value of each bit of the bit string and the coefficient of each term of the polynomial are in one-to-one correspondence. The value of the bit corresponds to the coefficient of each term of the polynomial, and the stored function value table is transformed.
[0304] In addition, to transform from a random value u to a random number polynomial r, it is only necessary to obtain r uniquely from u, and set the coefficients of the d-th power term of r as'l', and the coefficient of the d-th power term as 'T', the coefficients of other power terms are '0, then other transformation methods are also possible. For example, a function corresponding to a random value u and a polynomial can also be used, or a function value table can be used for transformation.
[0305] (3) If the public key encryption method used by the encryption unit 114 and the decryption unit 123 can be used in the encryption unit 114 to encrypt the random number s using the public key and the random value u to generate the first encrypted text cl, In the decryption unit 123, the first encrypted text cl is decrypted using the secret key, and then a decrypted random number s equal to the random number s is generated.<sup>,</sup>That's it.
[0306] Therefore, the public key cipher used by the encryption unit 114 and the decryption unit 123 can use any public key cipher except the NTRU cipher.
[0307] For example, if the ElGamal cipher is used, h and f can be used as the public key and secret key of the ElGamal cipher, respectively. In the encryption unit 114, the random number s is encrypted using h and u to generate cl, and then it is decrypted. In section 123, use f to decrypt cl and regenerate s'.
CN 1745537 Β
[0308] In addition, since the ElGamal cipher is described in detail in Non-Patent Document 1, the description is omitted here.
[0309] (4) The first function unit 113 uses the high-order k bits of the function value G(s) as the random value u, and the low-order k bits as the shared key K. In addition, it only needs to derive the random value u from the function value G(s). With the shared key K, other methods can also be used.
[0310] For example, the upper k/2 bits of the function value G(s) may be used as the random value u, and the lower k×3/2 bits may be used as the shared key K. In addition, among the 2k bits of the function value G(s), k bits can be selected every other bit as the random value u, and the remaining k bits can be used as the shared key Ko
[0311] (5) In addition to generating the random value u by the first function unit 113 and the second function unit 126, as long as the same value can be obtained in the encryption device 110 and the decryption device 120, other generation methods may be used.
[0312] For example, for any function Func, u=Func (s) may be set, so that the encryption device 110 and the decryption device 120 can obtain the same value. That is, in the encryption device 110 and the decryption device 120,
[0313] · Generate G (s), generate Ko according to G (s)
[0314] Generate Func (s) such that u = Func (s).
[0315] (6) In addition to being generated by the first function unit 113 and the second function unit 126, the random value u is only required to obtain the same value in the encryption device 110 and the decryption device 120, so the encryption device 110 also The random value u can be sent directly to the decryption device 120b.
[0316] That is, the first encrypted text c1 and the random value u may be sent to the decryption device 120 as follows. At this time, the random value u can also be sent after encryption.
[0317] In the encryption device 110,
[0318] · Generate G (s), generate Ko according to G (s)
[0319] The random value u is sent from the encryption device 110 to the decryption device 120 through another channel.
[0320] Receive a random value U
[0321] Instead of the random value u, use the received random value u to generate the first re-encrypted text cl\
[0322] At this time, it is also possible that the encryption device 110 encrypts the random value U before sending it, and the decryption device 120 decrypts the encrypted random value U.
[0323] (7) The random value u only needs to be able to obtain the same value from the encryption device 110 and the decryption device 120, so the first function unit 113 and the second function unit 126 may also be used to generate partial information of a part of the random value u , The partial information of the remaining part of the random value u is directly sent from the encryption device 110 to the decryption device 120.
[0324] For example, the encryption device 110 may transmit the first encrypted text c1 and the random value u2 to the decryption device 120 as follows.
[0325] In the encryption device 110,
[0326] (a) Generate G (s), and generate K and ul according to G (s).
[0327] (b) Generate a random value u2, and send it to the decryption device 120 through another channel.
[0328] (c) Generate a random value u according to u=ul xor u2.
[0329] (d) Use a random value u to generate the first encrypted text c1.
[0330] In the decryption device 120,
[0331] (e) Receive a random value u2.
[0332] (f) G(s') is generated, and K'and ul' are generated according to G(s').
[0333] (g) Generate a random value u'according to u'=ul' xor u2.
[0334] (h) Use the generated random value u to generate the first re-encrypted text cl\
[0335] At this time, the encryption device 110 may encrypt the random value u2 and then send it, and the decryption device 120 may decrypt the encrypted random value u2.
[0336] In addition, in (c) and (g), other operations may be performed instead of "exclusive" xor. For example, in (c) and (g), addition and subtraction may be used, respectively, and in addition, multiplication and division may also be used.
[0337] (8) In order to prevent a decryption error from deriving a different shared key between the encryption device 110 and the decryption device 120, when the first re-decrypted text c1 is the same as the first encrypted text c1, it is not output immediately Shared key K, so that the encryption device 110 generates a hash function value for any more than one random number s, random value u, or shared key K, and sends the generated hash function value to the decryption device 120, through The decryption device 120 verifies the hash function value to determine whether to output the shared key K. For example, as the hash function value, the hash function value H(s) of the random number s may be generated for an arbitrary hash function H, or the random number s, the random value u, and the shared key K may be combined to generate the hash function value H(s). The column function value H(s |u| k) or the hash function value H (u II k), etc.
[0338] In addition, at this time, the first function unit 113 of the encryption device 110 may not derive the random value u and the shared key K from the function value G(s), but only derive the shared key K from G(s).
[0339] Next, specific examples will be described.
[0340] The content distribution system 10 does not include an encryption device 110 and a decryption device 120, but includes an encryption device 110b and a decryption device 120b. As shown in FIG. 6, the encryption device 110b is composed of a public key input unit 111, a random number generation unit 112, The first function unit 113b, the encryption unit 114b, the first transmission unit 117b, the public key encryption unit 118, and the second transmission unit 119 are constituted. The decryption device 120, as shown in FIG. 7, is composed of a secret key input unit 121 and a first receiver. The unit 122b, the decryption unit 123b, the second function unit 126b, the comparison unit 127b, the public key decryption unit 128, and the second reception unit 129 are constituted. The comparison unit 127b includes a third function unit 127u and a comparison operation unit 127v<sub>o</sub>
[0341] The encryption device 110b generates a hash function value of the random number s, and when the decryption device 120b verifies the hash function value, in the encryption device 110b, as shown in the processing system diagram of FIG. 8, the first function unit 113b generates G(s) (step S103), generate K based on G(s) (step S104) ο
[0342] Next, the encryption unit 114b generates a random value u, generates a random number polynomial r based on the generated random value u, and uses the random number polynomial r and the public key polynomial h to generate the first encrypted text cl of the random number s (step S105) , Generate hash function value H(s) (step Slll) o
[0343] Next, the first transmission unit 117b transmits the first encrypted text c1 (step S106), and transmits the hash function value H(s) (step S112).
[0344] Next, in the decryption device 120b, the first receiving unit 122b receives the first encrypted text c1 (step S106), and receives the hash function value H (s) (step S112)
[0345] Next, the decryption unit 123b uses the secret key polynomial f to decrypt the first encrypted text c1 and then generates V (step S152).
[0346] Next, the second function unit 126 generates G(s') (step S153), and generates K'based on G(s') (step S154). [0347] Next, the comparison unit 127 uses the third function unit 127u to generate H(s') (step S154), and uses the comparison operation unit 127v to check whether H(s')=H(s) holds (step S162). Then, the shared key K'is output (step S157). [0348] In addition, at this time, in order to further improve the security, the method disclosed in Patent Document 1 may be used to encrypt the random number s to which the additional information is added to generate the first encrypted text c1. That is, in FIG. 6, the encryption unit 114b generates additional information Ra, encrypts the value of s and the bit combination s|| Ra of Ra, and generates the first encrypted text cl. In FIG. 7, the decryption unit 123b Decrypt the first encrypted text cl and generate s<sup>,</sup> | |Ra\Remove Ra, and then generate decrypted random number s.
CN 1745537 Β
[0349] In addition, as disclosed in Patent Document 1, instead of using the value of s||Ra, the value of the reversible transformation F(s, Ra) of s and Ra may be used.
2. Embodiment 2
[0351] A content distribution system 10c (not shown) as another embodiment of the present invention will be described.
[0352] The content distribution system 10c is a system modified on the basis of the content distribution system 10. The difference from the content distribution system 10 is that according to the function value G (s), the random value u and the shared key K are divided In addition, it also generates a verification value a; instead of generating and sending the first cipher text cl encrypted with the random number s, the encryption device generates and sends the first cipher text cl encrypted with the verification value a and the verification value a The second encrypted text c2 after encrypting the random number s.
[0353] Hereinafter, the content distribution system 10co will be described in detail centering on the above-mentioned differences.
[0354] 2.1 Configuration of content distribution system 10c
[0355] The content distribution system 10c has the same configuration as the content distribution system 10, instead of the encryption device 110 and the decryption device 120, it includes the encryption device 110c and the decryption device 120co. The other components are the same as the content distribution system 10, so they are omitted. Description.
[0356] 2.2 Configuration of Encryption Device 110c
[0357] As shown in FIG. 9, the encryption device 110c has the same configuration as the encryption device 110, instead of the random number generation unit 112, the first function unit 113, the encryption unit 114, and the first transmission unit 117, it includes random number generation. Section 112c, first function section 113c, encryption section 114c, random number mask section 116c, and first transmission section 117c.
[0358] Here, the random number generating unit 112c, the first function unit 113c, the encryption unit 114c, the random number masking unit 116c, and the first transmitting unit 117co will be described.
[0359] (1) Random number generation unit 112c
[0360] The random number generating unit 112c generates a random number s as a seed value for generating the shared key K, and outputs the generated random number s to the first function unit 113b and the random number masking unit 116co
[0361] (2) First function part 113c
[0362] The first function unit 113c receives the random number s from the random number generation unit 112c, and generates a function value G(s) of the random number s. Secondly, according to the generated function value G(s), a verification value a, a shared key K and a random value u are generated.
[0363] Here, the function G is a hash function with an output length of 3k bits, and the first function unit 113c uses the upper k bits of the function value G(s) as the verification value a, and the middle k bits of the function value G(s) As the shared key K, the low-order k bits of the function value G(s) are used as the random value u.
[0364] Next, the first function unit 113c outputs the generated verification value a and random value u to the encryption unit 114c, and outputs the generated shared key K to the public key encryption unit 118. The generated verification value a is output to the random number mask 116c.
[0365] (3) Encryption unit 114c
[0366] The encryption unit 114c receives the public key polynomial h from the public key input unit 111, and receives the verification value a and the random value u from the first function unit 113c. And as shown below, the first encrypted text cl of the verification value a is generated using the public key polynomial h and the random value u. Here, the first encrypted text cl is an encrypted text of the NTRU password.
[0367] The encryption unit 114c generates a random number polynomial r uniquely obtained from a random value u. For the parameter d of the NTRU cipher, each coefficient of the d items of the random number polynomial r is '1', and each of the remaining d items The coefficient is'-1, and the coefficients of the remaining terms are '0'. Specifically, the random value u is set as the initial value (random number seed) of the simulated random number series, and 2d non-repeated simulated random numbers are selected from {0.1...Ν-l}, Suppose the first d analog random number table
CN 1745537 Β
The coefficient of the power term shown is '1', and the coefficients of the power term represented by the remaining d simulated random numbers are the coefficients of the remaining terms are '0, thereby generating the random number polynomial r.
[0368] Next, the encryption unit 114c constructs the verification value polynomial ap in order to make the received verification value a applicable to the encryption algorithm E of the NTRU password, and makes the value of each bit of the N-bit bit string and verification when the verification value a is expressed in binary. The coefficients of each item of the value polynomial ap correspond, and the verification value a is transformed into the verification value polynomial apo. For example, suppose that the value of the lower b-th bit of the verification value a is the value of the coefficient of the terms X to b. Specifically, when the verification value a = 10010 (represented by bits), the verification value polynomial ap = X5+X2o is generated
[0369] Next, the encryption unit 114c uses the public key polynomial h as the key, and uses the random number polynomial r to execute the above-mentioned encryption algorithm E on the verification value polynomial ap, and generates the first encrypted text cl=E (ap, r, h). [0370] Next, the encryption unit 114c outputs the generated first encrypted text c1 to the first transmission unit 117c.
[0371] (4) Random number shielding section 116c
[0372] The random number masking unit 116c receives the random number s from the random number generating unit 112c, receives the verification value a from the first function unit 113c, and then generates the second encrypted text c2=s xor a, and encrypts the generated second The text c2 is output to the first sending unit 117co
[0373] Here, xor is an operator representing an "exclusive" operation.
[0374]Furthermore, the random number masking unit 116c may use a shared key encryption algorithm, addition operation, or multiplication operation instead of the "exclusive" operation.
[0375] (5) First transmission unit 117c
[0376] The first transmission unit 117c receives the first encrypted text c1 from the encryption unit 114c, receives the second encrypted text c2 from the random number masking unit 116c, and transmits the received first encrypted text c1 and the second encrypted text c2 via the Internet 130. Sent to the decryption device 120c. [0377] 2.2 Composition of decryption device 120c
[0378] As shown in FIG. 10, the decryption device 120c has the same configuration as the decryption device 120, instead of the first receiving unit 122, the decrypting unit 123, the second function unit 126, and the comparing unit 127, it includes a first receiving unit 122c, Decryption unit 123c, random number mask removal unit 125c, second function unit 126c, and comparison unit 127co
[0379] Here, the first reception unit 122c, the decryption unit 123c, the random number mask removal unit 125c, the second function unit 126c, and the comparison unit 127co will be described.
[0380] (1) First receiving unit 122c
[0381] The first receiving unit 122c receives the first encrypted text c1 and the second encrypted text c2 from the encryption device 110c via the Internet 130, outputs the received first encrypted text c1 to the decryption unit 123c, and outputs the received second encrypted text c2 Output to the random number mask removal unit 125co
[0382] (2) Decryption unit 123c
[0383] The decryption unit 123c receives the secret key polynomial f from the secret key input unit 121, and receives the first encrypted text c1 from the first receiving unit 122c. As shown below, the secret key polynomial f is used for the first encrypted text cl performs decryption and generates a decryption verification value a. Here, the decryption verification value a is a decrypted text based on the NTRU password.
[0384] The decryption unit 123c uses the secret key polynomial f as a key, executes the above-mentioned decryption algorithm D on the first encrypted text cl, and generates a decryption verification value polynomial ap,=D(cl, f). Here, the decryption verification value polynomial ap is a decrypted text of the NTRU cipher expressed by a polynomial. Therefore, the decryption unit 123c converts the decryption verification value polynomial ap' into the decryption verification value a', and sets the decryption verification value polynomial ap to the coefficients of each item It corresponds to the value of each bit of the decryption verification value a'of the N-bit bit string expressed in binary. For example, the coefficient of the b-th power term X~b of the decryption verification value polynomial ap' becomes the low-order bth of the decryption verification value a,
CN 1745537 Β
The value of the bit. Specifically, when the decryption verification value polynomial ap = X~5+X~2, it is converted into the decryption verification value a, = 10010 (expressed in bits).
[0385] Next, the decryption unit 123c outputs the generated decryption verification value a'to the random number mask removal unit 125c, and outputs the received first encrypted text c1 to the comparison unit 127c<sub>o</sub>
[0386] (3) Random number mask removal unit 125c
[0387] The random number mask removing unit 125c receives the second encrypted text c2 from the first receiving unit 122c, receives the decryption verification value a from the decryption unit 123c, and generates a decrypted random number s<sup>,</sup> = c2 xor a, and the generated random number s<sup>,</sup>Output to the second function part 126co
[0388]Furthermore, when the random number masking unit 116c does not use the exclusive operation, but uses a shared key encryption algorithm, addition operation, or multiplication operation, the random number masking unit 125c may also use the corresponding shared key encryption algorithm. Shared key decryption algorithm, subtraction operation or division operation.
[0389] (4) Second function part 126c
[0390] The second function unit 126c has the same function G algorithm as the function of the first function unit 113c.
[0391] The second function unit 126c receives the decrypted random number s'from the random number mask removal unit 125c, and generates a function value G(s,) of the received decrypted random number s'. Secondly, similar to the first function part 113c, the verification value a", the shared key K, and the random value u are generated based on the function value G(s,), and the generated verification value a", the shared key K, and the random value are generated. The value u is output to the comparison unit 127co
[0392] (5) Comparison unit 127c
[0393] As shown in FIG. 10, the comparison unit 127c is composed of a comparison operation unit 127s and an encryption unit 127t.
[0394] The encryption unit 127t receives the public key polynomial h from the secret key input unit 121, receives the verification value a" and the random value u from the second function unit 126c, and uses the received public key polynomial like the encryption unit 114c. h and a random value u, encrypt the verification value a", generate the first re-encrypted text cl, and output the generated first re-encrypted text cP to the comparison operation unit 127so
[0395] In addition, the comparison operation unit 127s receives the shared key K'from the second function unit 126c, receives the first encrypted text c1 from the decryption unit 123c, receives the first re-encrypted text c1 from the encryption unit 127t, and then receives Compare the received first encrypted text cl with the received first re-encrypted text cP, and when it is judged that the first encrypted text cl = the first re-encrypted text cP, output the received shared key K to the public key decryption unit 128 .
[0396] 2.3 Actions of the content distribution system 10c
[0397] Next, the overall operation of the content distribution system 10c according to Embodiment 2 will be described using the processing system diagram shown in FIG. 11.
[0398] The encryption device 110c receives the public key polynomial h of the decryption device 120c (step S101), generates a random number s (step S102), and calculates the function value G (s), and derives the verification value from the function value G (s) a. Shared key K and random value u (step S121). Next, the encryption device 110c uses the public key polynomial h and the random value u, and uses the NTRU password to encrypt the verification value a, generates the first encrypted text cl (step S105), and encrypts the random number s according to the verification value a, The second encrypted text c2 = s xor a is generated (step S122). Next, the encryption device 110c transmits the first encrypted text c1 and the second encrypted text c2 to the decryption device 120c via the Internet 130 (step S106).
[0399] That is, the encryption device 110c performs the following processing and sends the encrypted text C=(cl, c2) to the decryption device 120c.
[0400] (a) Generate a random number s.
[0401] (b) Generate G(s), and generate a, K, and u based on G(s).
[0402] (c) Use the public key polynomial h and the random value u to generate the first encrypted text cl of the verification value a.
[0403] (d) Generate c2 = s xor a.
[0404] Secondly, the encryption device 110c uses the derived shared key K to encrypt the plain text mi (1 W i W n) received from the content service device 140 using a public key cryptography method to generate an encrypted text Ci (1 W i W η), and sent to the decryption device 120c via the Internet 130 (step S108).
[0405] On the other hand, the decryption device 120c receives the secret key polynomial f and the public key polynomial h of the decryption device 120c (step S151), and receives the first encrypted text c1 and the second encrypted text c2 from the encryption device 110c via the Internet 130 (Step S106) The first encrypted text cl is decrypted using the secret key polynomial f to generate a decryption verification value a (Step S152). Secondly, according to the decryption verification value a, decrypt the second encrypted text c2, and generate the decrypted random number s<sup>,</sup> = c2xor a, (step S171). Next, the decryption device 120c decrypts the function value G of the random number s, (s0 derives the verification value a", the random value u, and the shared key K in step S172). Furthermore, the verification value a" is encrypted to generate the first Re-encrypt the text cl (step S155), if cl' = cl (step S156), output the shared key K'(step S157).
[0406] That is, the decryption device 120c performs the following processing and derives the shared key K'.
[0407] (a) Use the secret key polynomial f to decrypt the first encrypted text cl to generate a'.
[0408] (b) Generate s'=c2 xor a'.
[0409] (c) Generate G(s'), and generate a", u', and K'from G(s').
[0410] (d) Use the public key polynomial h and the random value u to generate the first re-encrypted text cl of a".
[0411] (e) Check whether cl'=cl holds, and if so, output the shared key K.
[0412] Here, if the correct secret key polynomial f corresponding to the public key polynomial h used in the encryption device 110c is used in the decryption device 120c, the first decrypted text C1 is correctly decrypted, and the decryption verification value a, = a, the decryption random number s'generated according to the second encrypted text c2 and a'= So Therefore, the verification value derived from G(s') a" = a, the shared key K, = K is established, and the random value u , = U. In this way, because a = a and u, = u are established, so cl, = cl is established, the decryption device 120c can derive the same shared key Ko as the encryption device 110c
[0413] Secondly, the decryption device 120c receives the public key encrypted text Ci (1 W i W η) from the encryption device 110c via the Internet 130, uses the derived shared key K Qi = Κ), and uses the public key cryptographic method to pair The received public key encrypted text Ci (1 W i W η) is decrypted to generate a decrypted text mi' (1 W i W η), and then the decrypted text mi' (1 W i W η) is output to the reproduction device 150.
[0414] Here, since the encryption key K used in generating the public key encrypted text is the same as the encryption key K'used in generating the decrypted text, the decryption device 120c can obtain the correct decrypted text mi' = mi(l W i Wn).
[0415] Furthermore, when a decryption error occurs, since the decrypted verification value a is different from the verification value a, the decrypted random number s obtained from the second encrypted text c2 is different from s. Therefore, the random value u derived from G(s,) and the shared key K are different from u and K, respectively. However, at this time, because a, and u are different from a and u, respectively, the first re-encrypted text cP and the first encrypted text cl are different, so the decryption device 120c does not output the shared key K\
[0416] 2.4 Effects of Embodiment 2
[0417] In the existing RSA-KEM algorithm, the element s that cannot be derived from the encrypted text C unless the secret key is known is input into the hash function G, and the shared key K is derived. However, if the NTRU cipher is used and the RSA-KEM algorithm as the key sealing mechanism is used to distribute the shared key, a decryption error may sometimes occur, so even if the secret key is used, the element s cannot be derived, so sometimes it may be derived. Incorrect shared key K,.
[0418] However, in the content distribution system, encryption device, and decryption device of the second embodiment, the random number s is
The column function G(s) generates a verification value a and a random value u in addition to the shared key. The decryption device uses the random value u and the public key polynomial h to decrypt the verification value a, and then re-encrypts it to generate the first re-encryption. Text cl\As long as the first re-encrypted text cl and the first encrypted text c have different values, the shared key Κ will not be output. Therefore, when a decryption error occurs, it can prevent the difference between the encryption device and the decryption device from being derived Key.
[0419] In addition, the method of the present invention can use the same method as the verification method described in Non-Patent Document 3 to theoretically prove its safety.
[0420] 2.5 Modifications
[0421] The second embodiment described above is an example of carrying out the present invention, and the present invention is not limited to this embodiment, and various aspects can be implemented without departing from the spirit thereof. Of course, the same modification as in Embodiment 1 can be implemented, and the present invention also includes the following cases.
[0422] (1) The transformation from the verification value a to the verification value polynomial ap may also use other transformation methods. For example, it may be performed using a function in which the value of each bit of the bit string and the coefficient of each term of the polynomial correspond one-to-one. The conversion may be performed using a function value table stored in correspondence with the values of the respective bits of the bit string and the coefficients of the respective terms of the polynomial.
[0423] In addition, the transformation from the random value u to the random number polynomial r can also use other transformation methods. For example, as long as r is uniquely calculated from u, and the coefficients of the d power terms are set to 1, 1, d The coefficient of the power term is'-1', and the coefficient of other power terms is '0, then other transformation methods are also available. For example, a function corresponding to a random value u and a polynomial or a function value table can also be used. Transform.
[0424] (2) If the public key cipher used by the encryption unit 114c and the decryption unit 123c can be used in the encryption unit 114c to encrypt the verification value a using the public key and the random value u to generate the first encrypted text c1, The decryption unit 123c decrypts the first encrypted text cl using the secret key, and then generates a decryption verification value a equal to the verification value a. Therefore, the public key cipher used by the encryption unit 114c and the decryption unit 123c may be any cipher except the NTRU cipher, as long as it is a public key cipher using a random number.
[0425] For example, if an ElGamal cipher is used, h and f can be used as the public key and secret key of the ElGamal cipher, respectively. In the encryption unit 114c, a is encrypted using h and a random value u to generate cl. In the decryption unit 123c, cl is decrypted using f to regenerate a'.
[0426] (3) In addition to generating the random value u by the first function unit 113c and the second function unit 126c, as long as the same value can be obtained in the encryption device 110c and the decryption device 120c, other generation methods may be used.
[0427] For example, for an arbitrary function Func, u=Func (s) may be set, so that the encryption device 110c and the decryption device 120c can obtain the same value. That is, it can also
[0428] Generate G (s), and generate a and K based on G (s).
[0429] Generate Func (s) such that u = Func (s).
[0430] (4) In addition to being generated by the first function unit 113c and the second function unit 126c, the random value u is only required to obtain the same value in the encryption device 110c and the decryption device 120c, so the encryption device 110c also The random value u can be sent directly to the decryption device 120c.
[0431] That is, the encryption device 110c may send the encrypted text C and the random value u to the decryption device as follows
120b<sub>o</sub>In addition, the random value u can also be sent after encryption.
[0432] Generate G (s), and generate a and K based on G (s).
[0433] The random value u is sent from the encryption device 110c to the decryption device 120b through another channel.
[0434] (5) The random value u only needs to be the same value obtained by the encryption device 110c and the decryption device 120c, so
CN 1745537 Β
The first function unit 113c and the second function unit 126c may be used to generate partial information of a part of the random value u, and the remaining partial information of the random value u may be directly transmitted from the encryption device 110c to the decryption device 120c.
[0435] For example, as described below, the encryption device 110c may send the encrypted text C and the random value u2 to the decryption device
120c. In addition, the encryption device 110c may also encrypt the random value u2 before sending it.
[0436] Generate G (s), and generate a, K, and ul based on G (s).
[0437] Through another channel, the random value u2 is sent from the encryption device 110c to the decryption device 120b.
[0438] The encryption device 110c generates a random value u=ul xor u2.
[0439] (6) The decryption device 120c checks whether the first encrypted text c1 is the encrypted text of the verification value a" obtained by the second function unit 126c, and when c1 is the encrypted text of a", the shared key K is used to The public key encrypted text Ci is decrypted, but it is also possible to check whether the first encrypted text cl is an encrypted text of the decryption verification value a,.
[0440] (7) The decryption device 120c checks whether the first encrypted text c1 is the encrypted text of the verification value a" obtained by the second function unit 126c, and when c1 is the encrypted text of a", the shared key K is used to The public key encrypted text Ci is decrypted. However, as shown in step S156 of the processing system diagram of FIG. 12, the comparison unit 127c checks whether the value of a decrypted by the decryption unit 123c is equal to the value obtained by the second function unit 126c. The value of the generated a".
[0441] (8) In order to prevent a decryption error from deriving different keys between the encryption device 110c and the decryption device 120c, it is also possible to check whether the values of the first re-decrypted text C1 and the first encrypted text C1 are the same, Instead of outputting the shared key K', the encryption device 110c generates a hash function value for any more than one random number s, verification value a, random value u, or shared key K, and sends the generated hash function value To the decryption device 120c, the hash function value is verified by the decryption device 120c to determine whether to output the shared key K. In order to improve the security, the method disclosed in Patent Document 1 can also be used. That is, the modification (8) of Embodiment 1 may also be used.
3. Summary of Embodiment 1 and Embodiment 2
[0443] As explained above, the present invention is a shared key generating device that outputs shared key data and encrypted shared key data obtained by encrypting the above shared key data according to the public key data given in advance, including: A secret number data generation unit that generates secret number data; a shared key derivation unit that converts the secret number data into random number data and the shared key data according to predetermined processing; converts the secret number data into random number data and the shared key data based on the public key data and the random number data The above-mentioned secret number data is encrypted to generate a first encryption unit that encrypts the shared key data.
[0444] In addition, the present invention is a shared key generating device that outputs shared key data and encrypted shared key data obtained by encrypting the above shared key data according to the public key data given in advance, including: generating secret number data The secret number data generation part; the shared key derivation part that converts the secret number data into verification value data, random number data, and the shared key data according to a predetermined process; according to the public key data and the random number data, The first encryption part that generates the first encrypted preliminary data after the verification value data is encrypted; the second encryption part that generates the second encrypted preliminary data after the secret number data is encrypted based on the verification value data, and the encrypted shared key data is generated by the above-mentioned encrypted shared key data. The first encrypted preliminary data and the second encrypted preliminary data are composed.
[0445] Here, the second encryption unit may perform an exclusive operation of the secret number data and the verification value data before generating the second encrypted preliminary data.
[0446] Here, the second encryption unit may use the verification value data as an encryption key, and generate the second encryption preliminary data after encrypting the secret data using a public key encryption method.
[0447] Here, the second encryption unit may add the verification value data and the secret number data to regenerate the second encryption preliminary data.
CN 1745537 Β
[0448] Here, the second encryption unit may multiply the verification value data and the secret number data to generate the second encrypted preliminary data.
[0449] Here, the encrypted shared key data may be bit concatenation data of the first encrypted preliminary data and the second encrypted preliminary data.
[0450] Here, the first encryption unit may generate the encrypted shared key data after encryption using NTRU cryptography.
[0451] Here, the above-mentioned first encryption unit may generate the above-mentioned first encrypted preliminary data after being encrypted by the NTRU encryption method.
[0452] Here, the above-mentioned secret number data may be a random number generated randomly.
[0453] Here, as a predetermined process, the public key derivation unit may use a one-way hash function.
[0454] In addition, the present invention is a public key restoration device that decrypts encrypted public key data and outputs public key data based on pre-given secret key data and public key data, including: The first decryption unit that generates secret number data after decrypting the encrypted shared key data; converts the secret number data into random number data and the shared key derivation unit of the shared key data according to a predetermined process; The third encryption part that encrypts the secret number data and generates the re-encrypted shared key data by encrypting the key data and the random number data. When the encrypted shared key data and the re-encrypted shared key data are consistent, output the shared key data.
[0455] In addition, the present invention decrypts the encrypted shared key data composed of the first encrypted preliminary data and the second encrypted preliminary data based on the previously given secret key data and public key data, and then outputs the shared key data. A key restoration device, comprising: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; decrypts the second encrypted preliminary data based on the verification value data and then generates secret data The second decryption unit; a shared key derivation unit that converts the secret number data into verification value verification data, random number data, and the shared key data according to a predetermined process; converts the above public key data and the random number data into The third encryption unit that generates third encrypted preliminary data after the verification value verification data is encrypted, and outputs the shared key data when the first encrypted preliminary data and the third encrypted preliminary data match.
[0456] In addition, the present invention decrypts the encrypted shared key data composed of the first encrypted preliminary data and the second encrypted preliminary data based on the pre-given secret key data and public key data, and then outputs the shared key data. A key restoration device, comprising: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; decrypts the second encrypted preliminary data based on the verification value data and then generates secret data The second decryption unit; a shared key derivation unit that converts the secret number data into verification value verification data, random number data, and the shared key data according to a predetermined process; converts the above public key data and the random number data into The third encryption unit that generates third encrypted preliminary data after the verification value data is encrypted, and outputs the shared key data when the first encrypted preliminary data and the third encrypted preliminary data match.
[0457] Here, the second decryption unit may perform an exclusive operation of the second encrypted preliminary data and the verification value data before generating the secret number data.
[0458] Here, the second decryption unit may use the verification value data as an encryption key, and use a shared key encryption method to decrypt the second encrypted preliminary data to generate the secret number data.
[0459] Here, the second decryption unit may generate the secret number data after subtracting the verification value data from the second encrypted preliminary data.
[0460] Here, the second decryption unit may divide the second encrypted preliminary data by the verification value data.
Generate the above-mentioned secret number data.
[0461] Here, the first decryption unit may generate the shared key data after decryption using the NTRU cryptographic method.
[0462] Here, the first decryption unit may generate the verification value data after decryption using the NTRU encryption method.
[0463] Here, as a predetermined process, the shared key derivation unit may use a one-way hash function.
[0464] In addition, the present invention is an encryption device that generates encrypted text data in which plain text data is encrypted based on public key data given in advance, and includes: a secret number data generation unit that generates secret number data; A shared key derivation unit that converts the secret number data into random number data and shared key data; a first encryption unit that encrypts the secret number data based on the public key data and the random number data and then generates the first encrypted preliminary data A second encryption unit that generates second encrypted preliminary data after encrypting the plaintext data based on the shared key data, the encrypted text data being composed of the first encrypted preliminary data and the second encrypted preliminary data.
[0465] In addition, the present invention is a decryption device that decrypts the encrypted text data composed of the first encrypted preliminary data and the second encrypted preliminary data and outputs the decrypted text data based on the previously given secret key data and public key data, including : The first decryption unit that generates secret number data after decrypting the first encrypted preliminary data based on the secret key data; and derives the shared key that converts the secret number data into random number data and shared key data according to a predetermined process Section; According to the public key data and the random number data, the secret number data is encrypted to generate the third encryption part of the third encryption preliminary data, and also includes a decryption part, when the first encryption preliminary data and the third encryption preparation When the data matches, the second encrypted preliminary data is decrypted based on the shared key to generate the decrypted text data.
[0466] In addition, the present invention is an encryption device that generates encrypted text data in which plain text data is encrypted based on pre-given public key data, and encrypts text data based on pre-given secret key data and public key data. After the data is decrypted, it is a cryptographic system composed of a decryption device that outputs decrypted text data. The encryption device includes: a secret number data generating unit that generates secret number data; a shared key derivation unit that converts the secret number data into random number data and shared key data according to a predetermined process; and based on the public key data and the above The random number data encrypts the secret number data and then generates the first encryption part of the first encryption preliminary data; the second encryption part that generates the second encryption preliminary data after encrypting the plaintext data based on the shared key data, the encrypted text The data is composed of the first encrypted preliminary data, the second encrypted preliminary data, and the third encrypted preliminary data. The decryption device includes: a first decryption unit that generates secret number data after decrypting the first encrypted preliminary data based on the secret key data; and converts the secret number data into random number data and shared key data according to a predetermined process Shared key derivation unit; a third encryption unit that generates third encrypted preliminary data after encrypting the secret number data based on the public key data and the random number data, and also includes a decryption unit, when the first encrypted preliminary data and the above When the third encrypted preliminary data matches, the second After the encrypted preliminary data is decrypted, the above-mentioned decrypted text data is generated.
[0467] As described above, the present invention is proposed in view of the problems in the existing system. Therefore, in the cryptographic system, by constructing a new key sealing mechanism that can use NTRU cryptography, it is possible to prevent encryption and decryption. Different keys are derived between the devices, and encrypted communication from the sending device that uses the key derived by the key sealing mechanism to the receiving device can be reliably performed.
[0468] As described above, it is possible to provide a cryptographic system that cannot be implemented in the prior art, which has great value.
4. Embodiment 3
[0470] A content distribution system 10d (not shown) as another embodiment of the present invention will be described.
[0471] In addition, the content distribution system 10d is a system in which the content distribution system 10 is modified. Here, the content distribution system 10do will be described in detail focusing on the differences from the content distribution system 10d.
CN 1745537 Β
[0472] 4.1 Configuration of content distribution system 10d
[0473] The content distribution system 10d has the same configuration as the content distribution system 10, instead of the encryption device 110 and the decryption device 120, it includes the encryption device 110D and the decryption device 120do. The other components are the same as the content distribution system 10, so they are omitted. Description.
[0474] The content distribution system 10d is an encrypted communication system that performs encrypted communication after the key distribution of the key sealing mechanism using NTRU ciphers. The encryption device 110d and the decryption device 120D are connected via the Internet 130.
[0475] 4.2 Configuration of Encryption Device 110d
[0476] As shown in FIG. 13, the encryption device 110d consists of a public key input unit 111d, a random number generating unit 112d, a first function unit 113d, an encryption unit 114d, a second function unit 115d, a random number masking unit 116d, and a first The transmission unit 117d, the public key encryption unit 118, and the second transmission unit 119 are constituted.
[0477] The encryption device 110d is a computer system similar to the encryption device 110, and the encryption device 110d realizes its functions by operating a microprocessor in accordance with a computer program.
[0478] (1) Public key input unit 111d
[0479] The public key input unit 111d reads the public key polynomial h of the decryption device 120 from the memory card 160, and outputs the read public key polynomial h to the encryption unit 114d.
[0480] (2) Random number generator 112d
[0481] The random number generating unit 112d generates a random number s as a seed value used to generate the basis of the shared key K, and outputs the generated random number s to the first function unit 113 and the random number masking unit 116.
[0482] (3) First function part 113d
[0483] The first function unit 113d receives the random number s from the random number generation unit 112d, generates a function value G(s) of the received random number s, and generates a verification value a and a shared key K based on the function value G(s). Here, the function G is a hash function whose output length is 2k bits as a one-way function. The first function unit 113d uses the high-order k bits of the function value G(s) as the verification value a, and the low-order function value G(s) K bits are used as the shared key K.
[0484] Next, the first function unit 113d outputs the generated verification value a to the encryption unit 114d and the second function unit 115d, and the generated shared key K to the shared key encryption unit 118.
[0485] (4) Encryption unit 114d
[0486] The encryption unit 114d receives the public key polynomial h from the public key input unit 111d, receives the verification value a from the first function unit 113d, and uses the received public key polynomial h to generate the first verification value a as shown below. 1 Encrypted text clo Here, the first encrypted text cl generated is the encrypted text of the NTRU password.
[0487] The encryption unit 114d randomly generates a random number polynomial r. For the parameter d of the NTRU cipher, the coefficients of the d items of the random number polynomial r are T, and the coefficients of the remaining d items are the coefficients of the remaining items. It is ©. Secondly, in order that the verification value a can be applied to the encryption algorithm E of the NTRU cipher, the verification value polynomial ap is generated, and the value of each bit of the N-bit sequence when the verification value a is expressed in binary and the coefficients of each item of the verification value polynomial ap correspond. For example, suppose that the value of the low-order b-th place of the verification value a is the coefficient of the term Xb of the verification value polynomial ap, and thus the verification value a is transformed into the verification value polynomial ap. Specifically, when the verification value a = 10010 (expressed in bits), it is transformed into a verification value polynomial ap = X~5+X~2<sub>O</sub>Secondly, use the public key polynomial h, and use the random number polynomial r to execute the above encryption algorithm E on the verification value polynomial ap, and generate the first encrypted text cl = E (ap, r, h) as the encrypted text polynomial.
[0488] Next, the encryption unit 114d outputs the generated first encrypted text c1 to the second function unit 115d and the first transmission unit 117do
CN 1745537 Β
[0489] (5) Second function part 115d
[0490] The second function unit 115d receives the verification value a from the first function unit 113d, receives the first encrypted text c1 from the encryption unit 114d, and generates the verification value a and the function value H of the first encrypted text c1 as shown below (A, cl).
[0491] Here, the function H is a hash function, which is a kind of one-way function.
[0492] Since the first encrypted text c1 is an encrypted text of the NTRU cipher expressed by a polynomial, the second function unit 115d generates the first encrypted text bit string c1 so that the coefficients of the first encrypted text c1 are expressed in binary The value of each bit of the N-bit first encrypted text at the time of the bit column cl, corresponds to. For example, the coefficients of the terms X to b to the b power of the first encrypted text cl are taken as the low-order b-th value of the first encrypted text sequence cP. In this way, the first encrypted text cl is converted into the first encrypted text bit string cl\Specifically, when the first encrypted text cl = X~5+X~2, the first encrypted text bit string cP = 10010 ( Use bit performance).
[0493] Next, the second function unit 115d inputs the verification value a and the bit combination a||cl of the first ciphertext bit string cl to the hash function H, and generates a function value H(a, cl)=H(a | | cl,). Here,'| |'is an operator that represents bit-association.
[0494] Next, the second function unit 115d outputs the generated function value H(a, cl) to the random number mask unit 116d.
[0495] (6) Random number shielding section 116d
[0496] The random number masking unit 116d receives the random number s from the random number generating unit 112d, and the function value H(a, cl) from the second function unit 115d. Next, generate the second encrypted text c2 = s xorH (a, cl), and output the generated second encrypted text c2 to the first sending unit 117do
[0497]Furthermore, the random number masking unit 116d may use a shared key encryption algorithm, addition operation, or multiplication operation instead of the exclusive operation.
[0498] (7) First transmission unit 117d
[0499] The first sending unit 117d receives the first encrypted text c1 from the encryption unit 114d, receives the second encrypted text c2 from the random number masking unit 116d, and sends the received first encrypted text c1 and the second encrypted text c2 via the Internet 130 Go to decryption device 120d.
[0500] (8) Public key encryption unit 118 and second transmission unit 119
[0501] The public key encryption unit 118 and the second transmission unit 119 are respectively the same as the public key encryption unit 118 and the second transmission unit 119 included in the encryption device 110 except for the following points.
[0502] The common key encryption unit 118 receives the shared key K from the first function unit 113d.
[0503] 4.3 Composition of decryption device 120d
[0504] As shown in FIG. 14, the decryption device 120d includes a secret key input unit 121d, a first receiving unit 122d, a decryption unit 123d, a third function unit 124d, a random number mask removal unit 125d, a fourth function unit 126d, and a comparison The unit 127d, the public key decryption unit 128, and the second receiving unit 129 are constituted.
[0505] The decryption device 120d is the same computer system as the decryption device 120, and the decryption device 120d realizes its function by causing the microprocessor to operate in accordance with a computer program.
[0506] In addition, the public key decryption unit 128 and the second receiving unit 129 are the same as the public key decryption unit 128 and the second receiving unit 129 included in the decryption device 120, respectively, and their description is omitted here.
[0507] (1) Secret key input unit 121d
[0508] The secret key input unit 121d reads the secret key polynomial f of the decryption device 120d from the memory card 170, and outputs the read secret key polynomial f to the decryption unit 123do
[0509] (2) First receiving unit 122d
[0510] The first receiving unit 122d receives the first encrypted text c1 and the second encrypted text c2 from the encryption device 110d via the Internet 130, outputs the received first encrypted text c1 to the decryption unit 123d and the third function unit 124d, and receives 2nd encryption
The text c2 is output to the random number mask removal unit 125d<sub>o</sub>
[0511]Furthermore, when the random number masking unit 116d does not use the exclusive operation, but uses a shared key encryption algorithm, addition operation, or multiplication operation, the random number mask removal unit 125d can also use the corresponding shared key encryption algorithm. The shared key decryption algorithm, subtraction operation or division operation.
[0512] (3) Decryption unit 123d
[0513] The decryption unit 123d receives the secret key polynomial f from the secret key input unit 121d, and receives the first encrypted text C1 from the first receiving unit 122d. As shown below, the secret key polynomial f is used for the first encrypted text cl performs decryption and generates a decryption verification value a. Here, the decryption verification value a is a decrypted text based on the NTRU password.
[0514] The decryption unit 123d uses the secret key polynomial f to execute the above-mentioned decryption algorithm D on the first encrypted text cl to generate the decryption verification value polynomial ap'=D(cl, f). Next, the decryption verification value polynomial ap is used The decrypted text of the NTRU cipher expressed by a polynomial, therefore, the decryption unit 123d generates a decrypted verification value a, so that the coefficients of the decrypted verification value polynomial ap' are combined with the number of bits in the N-bit sequence when the decrypted verification value a is expressed in binary correspond. For example, the coefficient of the term X~b of the b-th power of the decryption verification value polynomial apis taken as the low-order b-th value of the decryption verification value a,. In this way, the decryption verification value polynomial ap is transformed into the decryption verification value a. Specifically, when the decryption verification value polynomial ap, = X~5+X~2, it is transformed into the decryption verification value a, = 10010 (expressed in bits).
[0515] Next, the decryption unit 123d outputs the generated decryption verification value a'to the third function unit 124d and the comparison unit 127d.
[0516] (4) Third function part 124d
[0517] The third function unit 124d has an algorithm of the function H that is the same as the function of the second function unit 115d.
[0518] The third function unit 124d receives the first encrypted text c1 from the first receiving unit 122d, and receives the decryption verification value a'from the decryption unit 123d. Next, like the second function part 115d, the verification value a is generated, and the function value H (a,, cl) of the first encrypted text cl is generated, and the generated function value H (a,, cl) is output to the random number mask Remove part 125d<sub>o</sub>
[0519] (5) Random number mask removing unit 125d
[0520] The random number mask removing unit 125d receives the second encrypted text c2 from the first receiving unit 122d, receives the hash function value H(a', cl) from the third function unit 124d, and then generates a decrypted random number s'= c2 xor H(a', cl), output the generated decrypted random number s'to the fourth function part 126d<sub>o</sub>
[0521] (6) Fourth function part 126d
[0522] The fourth function unit 126d has the same function G algorithm as that of the first function unit 113d.
[0523] The fourth function unit 126d receives the decrypted random number s'from the random number mask removal unit 125d, and generates a hash function value G(s0o) of the decrypted random number s'. (S,) Generate the verification value a" and the shared key, and output the generated verification value a" and the shared key K to the comparison unit 127do
[0524] (7) Comparison unit 127d
[0525] The comparison unit 127d receives the decryption verification value a'from the decryption unit 123d, receives the verification value a" and the shared key K from the fourth function unit 126d, and then checks whether the decryption verification value a and the verification value a" are equal, If the decrypted verification value a is equal to the verification value a", the shared key K is output to the public key decryption unit 128.
[0526] (8) Public key decryption unit 128 and second receiving unit 129
[0527] The common key decryption unit 128 receives the shared key K'from the comparison unit 127d.
[0528] The public key decryption unit 128 is the same as the public key decryption unit 128 included in the decryption device 120 in other points, so the description is omitted here.
[0529] In addition, the second receiving unit 129 and the second receiving unit 129 included in the decryption device 120 are the same, so the explanation is omitted here.
Bright.
[0530] 4.4 Actions of the content distribution system 10d
[0531] The operation of the content distribution system 10d will be described using the flowchart shown in FIG. 15 and the processing system diagram shown in FIG. 16.
[0532] The public key input unit 111d receives the public key polynomial h of the decryption device 120 from the memory card 160, and outputs the public key polynomial h to the encryption unit 114d (step S201).
[0533] Next, the random number generating unit 112d generates a random number s, and then outputs the random number s to the first function unit 113d and the random number masking unit 116d (step S202).
[0534] Next, the first function unit 113d receives the random number s from the random number generation unit 112d, and generates a function value G(s) of the random number s (step S203). Next, the first function unit 113d generates a verification value a and a shared key K based on the function value G(s), then outputs the output verification value a to the encryption unit 114d and the second function unit 115d, and outputs the shared key K to the public Key encryption unit 118 (step S204) ο
[0535] Next, the encryption unit 114d receives the public key polynomial h from the public key input unit 111d, and receives the verification value a from the first function unit 113d. Next, the encryption unit 114d generates the first encrypted text cl of the verification value a using the public key polynomial h, and outputs the first encrypted text cl to the second function unit 115d and the first transmission unit 117d (step S205).
[0536] Next, the second function unit 115d receives the verification value a from the first function unit 113d, receives the first encrypted text cl from the encryption unit 114d, and generates the verification value a and the function value H (a, cl ), and output the function value H (a, cl) to the random number mask 116d (step S206) ο
[0537] Next, the random number masking unit 116d receives the random number s from the random number generating unit 112d, the function value H(a, cl) from the second function unit 115d, and the random number masking unit 116d generates the second encrypted text c2=s xor H(a, cl), and output the second encrypted text c2 to the first transmission unit 117d (step S207).
[0538] Next, the first transmission unit 117d receives the first encrypted text c1 from the encryption unit 114d, receives the second encrypted text c2 from the random number masking unit 116d, and sends the first encrypted text c1 and the second encrypted text c2 via the Internet 130. Go to the decryption device 120d (step S208).
[0539] Next, the public key encryption unit 118 receives a plurality of plain text mi (1 W i W n) from the content service device 140, receives the shared key K from the first function unit 113d, and uses the shared key K to pair the plain text mi (1 W i W η) executes the shared key encryption algorithm Sym, generates a shared key encrypted text Ci = Sym (mi, Κ) (1 W i W η), and encrypts the public key text Ci (l W i W n) is output to the second transmitting device 119 (step S209).
[0540] Next, the second sending unit 119 receives the public key encrypted text Ci (1 W i W n) from the public key encryption unit 118, sends it to the decryption device 120d via the Internet 130 (step S210), and ends the process.
[0541] On the other hand, the secret key input unit 121d receives the secret key polynomial f of the decryption device 120d from the memory card 170, and outputs the secret key polynomial f to the decryption unit 123 (step S251).
[0542] Next, the first receiving unit 122d receives the first encrypted text c1 and the second encrypted text c2 from the encryption device 110d via the Internet 130, outputs the first encrypted text c1 to the decryption unit 123d and the third function unit 124d, and receives The second encrypted text c2 is output to the random number mask removing unit 125d (step S208).
[0543] Next, the decryption unit 123d receives the secret key polynomial f from the secret key input unit 121, and receives the first encrypted text c1 from the first receiving unit 122d. Next, the secret key polynomial f is used to determine the first encrypted text c1. Decryption is performed, the decryption verification value a'is generated, and the decryption verification value a'is output to the third function unit 124d and the comparison unit 127d (step S252).
[0544] Next, the third function unit 124d receives the first encrypted text c1 from the first receiving unit 122d, and receives the first encrypted text c1 from the decryption unit 123d.
Receive the decryption verification value a, and then, like the second function part 115d, generate the verification value a, and the function value H(a<sup>,</sup>, Cl), and output the function value H(a,, cl) to the random number mask removing unit 125d (step S253).
[0545] Next, the random number mask removing unit 125d receives the second encrypted text c2 from the first receiving unit 122d, receives the hash function value H(a', cl) from the third function unit 124d, and next, generates a decrypted random number s '= c2 xor H(a', cl), and output the decrypted random number s'to the fourth function unit 126d (step S254).
[0546] Next, the fourth function unit 126d receives the decrypted random number s from the random number mask removal unit 125, and generates a hash function value G(s,) of the decrypted random number s, (step S255), and the first function unit Similarly, 113d generates the verification value a" and the shared key K'from the function value G(s,), and outputs the verification value a" and the shared key K'to the comparison unit 127d (step S256).
[0547] Next, the comparison unit 127d receives the decryption verification value a'from the decryption unit 123, receives the verification value a" and the shared key K from the fourth function unit 126d, and checks whether the decryption verification value a and the verification value a" are equal , If not (step S257), the processing ends.
[0548] If the decryption verification value a'and the verification value a" are equal (step S257), the comparison unit 127d outputs the shared key K'to the public key decryption unit 128 (step S258)
[0549] Next, the second receiving unit 129 receives the encrypted text Ci (1 W i W n) from the encryption device 110 via the Internet 130, and outputs it to the public key decryption unit 128 (step S210),
[0550] Next, the public key decryption unit 128 receives the shared key K'from the comparison unit 127d, receives the public key encrypted text Ci (1 W i W η) from the second receiving unit 129, and uses the shared key K to pair The public key encrypted text Ci (1 W i W η) executes the public key encryption algorithm Sym to generate the decrypted text mi' = Sym (Ci, K) (1 W i W η), and the decrypted text mi' (1 W i W η) Output to the outside (step S259), and then end the process.
[0551] 4.5 Operation Verification of Content Distribution System 10d
[0552] Next, the overall operation of the content distribution system 10d will be described.
[0553] The encryption device 110d receives the public key polynomial h of the decryption device 120d, generates a random number S, and derives the verification value a and the shared key K according to the function value G(s). Next, the encryption device 110d uses the public key polynomial h, and encrypts the verification value a with the NTRU password, generates the first encrypted text cl, and generates the function value H (a, cl) based on the verification value a and the first encrypted text cl, Generate the second encrypted text c2 = s xor (a, cl) according to the random number s and the function value H (a, cl). Next, the encryption device 110d sends the first encrypted text cl and the second encrypted text c2 to the decryption device 120do via the Internet 130. [0554] That is, the encryption device 110d performs the following processing and sends the encrypted text C=(cl, c2) to Decryption device 120d. [0555] Generate a random number s.
[0556] Generate G(s), and generate a and K according to G(s).
[0557] Use the public key polynomial h to generate the first encrypted text cl of the verification value a.
[0558] Generate c2=s xor H(a, cl).
[0559] Output the shared key K and the encrypted text C=(cl, c2).
[0560] Secondly, the encryption device 110d uses the derived shared key K to encrypt the plain text mi (1 W i W n) input from the content service device 140 using a public key cryptography method to generate an encrypted text Ci (1 W i W η), and sent to the decryption device 120do via the Internet 130
[0561] On the other hand, the decryption device 120d inputs the secret key polynomial f of the decryption device 120d, receives the first encrypted text C1 and the second encrypted text C2 from the encryption device 110d via the Internet 130, and uses the secret key polynomial f to compare the first encrypted text C1 and the second encrypted text C2. The encrypted text cl is decrypted, and a decryption verification value a is generated. According to the decryption verification value a, and the first encrypted text cl, the function value H(a,, cl) is generated, and the decryption random number s'= c2 xor(a) is generated according to the second encrypted text c2 and the function value H(a', cl) ', cl). Secondly,
The decryption device 120d derives the verification value a" and the shared key K according to the function value G(s,) of the decrypted random number s,. If the verification value a" = a, then outputs the shared key K, [0562] That is, The decryption device 120d performs the following processing and derives the shared key K'.
[0563] Use the secret key polynomial f to decrypt the first encrypted text cl to generate a.
[0564] Generate s'=c2 xor H(a', cl).
[0565] Generate G(s'), and generate a" and K'based on G(s').
[0566] Check if a"=a is established. If yes, output the shared key K,.
[0567] Here, if the correct secret key polynomial f corresponding to the public key polynomial h used in the encryption device 110d is used in the decryption device 120d, the first decrypted text c1 is correctly decrypted, and the decryption verification value a, = a, the decrypted random number s generated according to the second encrypted text c2 and H(a,, cl), = s. Therefore, the verification value a"=a derived from G(s,), the shared key K=Ko, and since a"=a holds, the decryption device 120d can derive the same shared key K as the encryption device 110d.
[0568] Secondly, the decryption device 120d uses the derived shared key K'(=K) to receive the public key encrypted text Ci (1 W i W n) from the encryption device 110d via the Internet 130, and uses a public cryptographic method to receive The public key encrypted text Ci (1 W i W η) is decrypted to generate a decrypted text mi (1 W i W η), which is then output to the reproduction device 150.
[0569] Here, since the encryption key K used in generating the public key encrypted text is the same as the encryption key K used in generating the decrypted text, the decryption device 120d can correctly obtain the decrypted text mi'=mi(l W i Wn).
[0570] 4.6 Effects of Embodiment 3
[0571] In the existing PSEC-KEM algorithm, a*p and a*w are used as the input of the hash function Η, and if a secret key is not used, it is difficult to calculate a*w from a*p. Hellman problem, to finally derive the shared key K. At this time, if the secret key is not known, the shared key Ko cannot be derived. Therefore, other public key ciphers that do not use Diffie-Hellman problems, such as NTRU ciphers, are not compatible with Diffie. -Hellman problem a*p, a*w are equivalent passwords, so there is a problem that the PSEC-KEM algorithm cannot be used.
[0572] However, in the content distribution system, encryption device, and decryption device of the present invention, since the input of the hash function H is used as the verification value a and the encrypted text cl, the PSEC-KEM algorithm can be used, and NTRU can be used. Password or other public key password.
[0573] Furthermore, in NTRU ciphers, even if a public key is used to encrypt a plain text to generate an encrypted text, and a regular secret key is used to decrypt the encrypted text to generate a decrypted text, the decrypted text and the original plain text will also occur Different cases (for example, refer to Non-Patent Document 2). If such a decryption error occurs, the decryption device will get the wrong decryption verification value a'. However, since the verification value a" obtained from G(s,) is not equal to a, the shared key K is not output. , Even if a decryption error occurs, it can prevent the encryption device and the decryption device from sharing the wrong key.
[0574] In addition, in the decryption device, since the process of generating the re-encrypted text is not performed, the amount of calculation can be reduced compared with the prior art.
[0575] Thus, the NTRU password can be used to form a key sealing mechanism, and the NTRU password can be used for key distribution between the encryption device and the decryption device.
[0576] In addition, the method of the present invention can use the same method as the verification method described in Non-Patent Document 3 to theoretically prove its safety.
[0577] 4.7 Modifications
[0578] The above-described embodiment is an example of implementing the present invention, and the present invention is not limited to this embodiment.
CN 1745537 Β
Various forms can be implemented within the scope deviating from the spirit. The present invention also includes the following cases.
[0579] (1) The parameter of the NTRU password used is not limited to N=167, and the parameter N can also take other values.
[0580] (2) The bit sequence and polynomial conversion methods performed by the encryption unit 114d, the second function unit 115d, the decryption unit 123d, and the third function unit 124d are not limited to this method, and other conversion methods may be used.
[0581] For example, a function or a table of function values in which a bit string and a polynomial are in one-to-one correspondence can be used for conversion.
[0582] In addition, for example, the conversion method described in Modification Example (1) of Embodiment 2 may be used for conversion.
[0583] (3) If the public key encryption method used by the encryption unit 114d and the decryption unit 123d can be used in the encryption unit 114d to encrypt the verification value a using the public key, the first encrypted text c1 is generated in the decryption unit. In 123d, use the secret key to decrypt the first encrypted text cl, and then generate a decryption verification value a equal to the verification value a.
[0584] Therefore, the public key cipher used by the encryption unit 114d and the decryption unit 123d may use any public key cipher in addition to the NTRU cipher.
[0585] For example, if an RSA cipher is used, h and f can be used as the public key and the secret key of the RSA cipher, respectively. In the encryption unit 114d, a is encrypted using h to generate cl, and in the decryption unit 123d, f is used. Decrypt cl and generate a.
[0586] In addition, for example, if an ElGamal cipher is used, h and f can be used as the public key and secret key of the ElGamal cipher, respectively. In the encryption unit 114d, a random number r is generated, and h and r are used to encrypt a to generate cl. In the decryption unit 123d, cl is decrypted using f to regenerate a'.
[0587] In addition, since the RSA cipher and the ElGamal cipher are described in detail in Non-Patent Document 1, their description is omitted here.
[0588] (4) The first function unit 113d uses the high-order k bits of the function value G(s) as the verification value a, as long as the verification value a and the shared key K are derived from the function value G(s). Other methods can be used.
[0589] (5) As long as the second function unit 115d derives the function value H(a, cl) from the verification value a and the first encrypted text cl, other generation methods may be used.
[0590] For example, for any two-term operation #, a#cl may be input to the function H to derive the function value. Furthermore, in the NTRU encryption, since the first encrypted text cl is a polynomial, it is also possible to transform the first encrypted text cl' from the first encrypted text cl, and input a#cl' into the function Η to derive the function value .
[0591] (6) Furthermore, as long as the second function unit 115d uses the verification value a to derive the function value, other methods may be adopted.
[0592] For example, the second function unit 115d may output H(a), or may directly output the verification value a as it is. That is, in the encryption device 110d, the second encrypted text c2 can be used as
[0593] · c2 = s xor H (a) or
[0594] · c2 = s xor a derived.
[0595] At this time, the third function unit 124d of the decryption device 120d outputs
[0596] · H(a<sup>,</sup>)or
[0597] · a'ο
(7) If the random number masking unit 116d can derive the second cipher text c2 from the random number s and the function value H(a, cl), the random number mask removing unit 125d can derive the second cipher text c2 and the function value H (a, cl) To derive the random number s, other methods can also be used.
[0599] For example, the random number masking unit 116d may use the second encrypted text c2 as
[0600] .c2 = s+H(a, c 1) or
CN 1745537 Β
[0601] · c2 = s · H(a, cl) derived.
5. Embodiment 4
[0603] A content distribution system 10e (not shown) as yet another embodiment of the present invention will be described.
[0604] The content distribution system 10e is a system that is modified on the basis of the content distribution system 10d shown in Embodiment 3. The difference from the content distribution system 10d is that the encryption device divides by the function value G(s). In addition to the verification value a and the shared key K, a random value u is also generated; the verification value a is encrypted with the random value u to generate the first encrypted text cl. The method of determining when the decryption device outputs the shared key K is also different from the content distribution device 10d.
[0605] Here, the content distribution system 10θ will be described in detail centering on the differences from the content distribution system 10d.
[0606] 5.1 Configuration of content distribution system 10e
[0607] The content distribution system 10e has the same configuration as the content distribution system 10d, and instead of the encryption device 110d and the decryption device 120d, it includes an encryption device 110e and a decryption device 120e. Since the other configuration is the same as the content distribution system 10D, the description thereof is omitted.
[0608] The content distribution system 10e is a system that uses NTRU for key distribution. The encryption device 110e and the decryption device 120e are connected via the Internet 130.
[0609] 5.2 Configuration of Encryption Device 110e
[0610] As shown in FIG. 17, the encryption device 110e consists of a public key input unit 111d, a random number generation unit 112d, a first function unit 113e, an encryption unit 114e, a second function unit 115d, a random number masking unit 116d, and a first The transmission unit 117d, the public key encryption unit 118, and the second transmission unit 119 are constituted.
[0611] The public key input unit 111d, the random number generating unit 112d, the second function unit 115d, the random number masking unit 116d, the first transmission unit 117d, the public key encryption unit 118, and the second transmission unit 119 constitute encryption The components of the device 110 are the same, so the description is omitted. Here, only the configuration and operation of the first function unit 113e and the encryption unit 114e that are different from the components of the encryption device 110d will be described.
[0612] (1) First function part 113e
[0613] The first function unit 113e receives the random number s from the random number generation unit 112d, and generates a function value G(s) of the received random number s. Next, as shown below, the verification value a, the shared key K, and the random value u are generated based on the generated function value G(s).
[0614] Here, the function G is a hash function with an output length of 3k bits, and the first function unit 113e uses the upper k bits of the function value G(s) as the verification value a, and the middle k bits of the function value G(s) Bits are used as the shared key K, and the low-order k bits of the function value G(s) are used as the random value u.
[0615] Next, the first function unit 113e outputs the generated verification value a to the encryption unit 114e and the second function unit 115d, outputs the generated shared key K to the public key encryption unit 118, and outputs the generated random value u Output to the encryption unit 114e.
[0616] (2) Encryption unit 114e
[0617] The encryption unit 114e receives the public key polynomial h from the public key input unit 111d, and receives the verification value a and the random value u from the first function unit 113e. Next, as shown below, the first encrypted text cl of the verification value a is generated using the public key polynomial h and the random value u . Here, the first encrypted text cl is an encrypted text of the NTRU password. The random value u is a blind value and is used to make the verification value a which is the object of encryption unknown.
[0618] The encryption unit 114e generates a random number polynomial r uniquely obtained from a random number u. For the parameter d of the NTRU encryption, the coefficients of the d terms of the random number polynomial r are '1', and the remaining d terms are each The coefficient is'-1, and the coefficients of the remaining terms are '0'.
[0619] Specifically, the random value U is set as the initial value (random number seed) of the simulated random number series, and 2d non-repeated ones are selected from {0, 1,...N-ι} The coefficient of the power term represented by the first d simulated random numbers is '1', and the coefficient of the power term represented by the remaining d simulated random numbers is the coefficient of the remaining terms. 0,, from this to generate a random number polynomial r.
[0620] Next, the encryption unit 114e, like the encryption unit 114d, uses the random number polynomial r to generate the first encrypted text cl=E (ap, r, h).
[0621] Next, the encryption unit 114e outputs the generated first encrypted text c1 to the second function unit 115d and the first transmission unit.
117do
[0622] 5.3 Composition of the decryption device 120e
[0623] As shown in FIG. 18, the decryption device 120e consists of a secret key input unit 121e, a decryption unit 123e, a third function unit 124d, a random number mask removal unit 125d, a fourth function unit 126e, a comparison unit 127e, and a public key. The decryption unit 128 and the second receiving unit 129 are constituted.
[0624] Here, since the third function unit 124d, the random number mask removal unit 125d, the common key decryption unit 128, and the second receiving unit 129 and the decryption device 120d include the same constituent elements, the description is omitted, and the description is the same as that of the decryption device. The configuration and operation of the secret key input unit 121e, the decryption unit 123e, the fourth function unit 126e, and the comparison unit 127e having different constituent elements included in 120d.
[0625] (1) Secret key input unit 121e
[0626] The secret key input unit 121e receives the secret key polynomial f and the public key polynomial h of the decryption device 120e from the memory card 170, outputs the secret key polynomial f to the decryption unit 123e, and outputs the public key polynomial h to Comparison part 127e<sub>o</sub>
[0627] (2) Decryption unit 123e
[0628] The decryption unit 123e receives the secret key polynomial f from the secret key input unit 121e, receives the first encrypted text c1 from the first receiving unit 122d, and then uses the secret key polynomial f to decrypt the first encrypted text c1 , Generate the decryption verification value a, and output the generated decryption verification value a to the third function unit 124d, and output the received first encrypted text clo to the comparison unit 127e
[0629] (3) Fourth function part 126e
[0630] The fourth function unit 126e has the same function G algorithm as that of the first function unit 113e.
[0631] The fourth function unit 126e receives the decrypted random number s from the random number mask removal unit 125d, and generates a hash function value G(s,) of the received decrypted random number s. Secondly, similar to the first function part 113e, the verification value a", the shared key K, and the random value u are generated based on the function value G(s,), and the generated verification value a", the shared key K, and the random value are generated. The value u is output to the comparison unit 127e<sub>o</sub>
[0632] (4) Comparison unit 127e
[0633] As shown in FIG. 18, the comparison unit 127e is composed of a comparison operation unit 127p and an encryption unit 127q.
[0634] The encryption unit 127q receives the public key polynomial h from the secret key input unit 121e, and receives the verification value a" and the random value u from the fourth function unit 126e. Next, like the encryption unit 114d, it uses the received public key The key polynomial h and the random value ", the received verification value a" are encrypted, the first re-encrypted text c is generated, and the generated first re-encrypted text cl' is output to the comparison operation unit 127p<sub>o</sub>
[0635] The comparison operation unit 127p receives the first encrypted text c1 from the decryption unit 123b, and receives the first re-encrypted text c1 from the encryption unit 127q. Next, it compares the received first encrypted text c1 and the first re-encrypted text cP to determine Whether cP = clo
CN 1745537 Β
If cl, = cl, output the received shared key K to the public key decryption unit 128, if not cl, = cl, then output the received shared key
[0636] 5.4 Operation verification of content distribution system 10e
[0637] Next, the overall operation of the content distribution system 10e will be described using the processing system diagram shown in FIG. 19.
[0638] The encryption device 110e receives the public key polynomial h of the decryption device 120e (step S201), generates a random number s (step S202), generates a function value G(s) (step S203), and derives it from the function value G(s) Verify the value a, the shared key K, and the random value u (step S204). Next, the encryption device 110e uses the public key polynomial h and the random value u, and encrypts the verification value a with the NTRU password, generates the first encrypted text cl (step S205), and generates a function based on the verification value a and the first encrypted text cl Value H(a, cl) (step S206), and generate a second encrypted text c2=sxor H(a, cl) based on the random number s and the function value H(a, cl) (step S207). Next, the encryption device 110b sends the first encrypted text c1 and the second encrypted text c2 to the decryption device 120e via the Internet 130 (step S208).
[0639] That is, the encryption device 110e performs the following processes (a) to @), and sends the encrypted text C=(cl, c2) to the decryption device 120e.
[0640] (a) Generate a random number s.
[0641] (b) Generate G(s), and generate a, K, and u based on G(s).
[0642] (c) Use the public key polynomial h and the random value u to generate the first encrypted text cl of the verification value a.
[0643] (d) Generate c2 = s xor H(a, cl) a.
[0644] Secondly, the encryption device 110e uses the derived shared key K to encrypt the plain text mi (1 W i Wn) input from the content service device 140 with a public key cipher to generate an encrypted text Ci (1 W i W n) (Step S209), and send it to the decryption device 120e via the Internet 130 (Step S210).
[0645] On the other hand, the decryption device 120e receives the secret key polynomial f and the public key polynomial h of the decryption device 120e (step S251, step 251e), and receives the first encrypted text c1 and the second encrypted text c1 and the second encrypted text c1 from the encryption device 110e via the Internet 130. The encrypted text c2 (step S208), the first encrypted text cl is decrypted using the secret key polynomial f, and a decryption verification value a'is generated (step S252). Next, a function is generated based on the decryption verification value a'and the first encrypted text cl Value H(a', cl) (step S253), generate a decrypted random number s'= c2 xor H(a', cl) according to the second encrypted text c2 and the function value H (a', cl) (step S254) o Next, the decryption device 120e decrypts the function value G(s') of the random number s'(step S255), and derives the verification value a", the random value u, and the shared key K according to the generated function value G(s,), ( Step S256e). Next, the verification value a" is encrypted to generate the first re-encrypted text cl, (step S261), if cl,=cl (step S257), then the shared key K'is output (step S258).
[0646] That is, the decryption device 120e performs the following processes (a) to (e), and derives the shared key K'.
[0647] (a) Use the secret key polynomial f to decrypt the first encrypted text cl to generate a.
[0648] (b) Generate s'=c2 xor H(a', cl).
[0649] (c) Generate G(s'), and generate a", u', K'according to G(s').
[0650] (d) Use the public key polynomial h and the random value u to generate the first re-encrypted text cl of a".
[0651] (e) Check whether cl'=cl is established, and if so, output the shared key K'.
[0652] Here, if the correct secret key polynomial f corresponding to the public key polynomial h used in the encryption device 110e is used in the decryption device 120e, the first decrypted text c1 is correctly decrypted, and the decryption verification value a, = a, the decryption random number s generated according to the second encrypted text c2 and H (a,, cl), = s. Therefore, the verification value a" derived from G(s,) = a, the shared key K, = K is established, and the random value u, = Uo. Thus, since a = a and u, = u is established, so cl, = cl
CN 1745537 Β
If established, the decryption device 120e can derive the same shared key K as the encryption device 110e.
[0653] Next, the decryption device 120e receives the public key encrypted text Ci(1 W i W n) from the encryption device 110e via the Internet 130 (step S210), and uses the public key cipher to encrypt the received public key Ci(1 W i W η) is decrypted to generate a decrypted text mi' (1 W i Wn) (step S259), and then the decrypted text mi' (1 W i W η) is output to the reproduction device 150.
[0654] Here, since the encryption key K used when the public key encrypted text is generated is the same as the encryption key K'used when the decrypted text is generated, the decryption device 120e can correctly obtain mi' = mi (1 W i W η).
[0655] 5.5 Effects of the content distribution system 10e
[0656] In the existing PSEC-KEM algorithm, a*p and a*w are used as the input of the hash function H, and it is difficult to calculate the Diffie- a*w from a*p without using a secret key. Hellman problem, to finally derive the shared key K, at this time, if the secret key is not known, the shared key K cannot be derived. Therefore, other public key ciphers that do not use the Diffie-Hellman problem, including the NTRU cipher, do not have ciphers equivalent to a*p and a*w in the Diffie-Hellman problem. Therefore, there is a problem that the PSEC-KEM algorithm cannot be used.
[0657] However, in the content distribution system, encryption device, and decryption device of the present invention, since the input of the hash function H is used as the verification value a and the encrypted text cl, it is possible to use NTRU encryption or Other public key passwords.
[0658] Furthermore, if a decryption error occurs, the decryption device obtains the wrong decryption verification value. However, since cl is not equal to cl, the shared key K is not output. Therefore, even if a decryption error occurs, it is possible to prevent the encryption device and the decryption device from sharing the wrong key.
[0659] Thus, the NTRU password can be used to form a key sealing mechanism, and the NTRU password can be used for key distribution between the encryption device and the decryption device.
[0660] In addition, the method of the present invention can use the same method as the verification method described in Non-Patent Document 3 to theoretically prove its safety.
[0661] 5.6 Modifications
[0662] The above-described embodiment is an example of implementing the present invention, and the present invention is not limited to this embodiment, and various modes can be implemented without departing from the spirit thereof. Of course, the same modification as in Embodiment 3 can be implemented, and the present invention also includes the following cases.
(1) The transformation from the random value u to the random number polynomial r performed in the encryption unit 114e is not limited to this method. If r is uniquely obtained from u, other transformation methods can also be used. For example, The random value u is transformed with the function or function value table corresponding to the polynomial.
[0664] In addition, for example, the conversion method described in the modification (1) of the second embodiment may be used for conversion.
[0665] (2) If the public key cipher used by the encryption unit 114e and the decryption unit 123e can be used in the encryption unit 114e to encrypt the verification value a using the public key and the random value u to generate the first encrypted text c1, In the decryption unit 123e, the first encrypted text cl is decrypted using the secret key, and then the decryption verification value a equal to the verification value a is generated again. Therefore, the public key ciphers used by the encryption unit 114e and the decryption unit 123e can be used as long as they are public key ciphers using random numbers other than the NTRU cipher.
[0666] For example, if the ElGamal cipher is used, h and f can be respectively used as the public key and secret key of the ElGamal cipher. In the encryption unit 114e, a is encrypted using h and a random value u to generate cl, and then it is decrypted. In Part 123e, make
CN 1745537 Β
Use f to decrypt cl and then generate a'.
[0667] (3) In addition to generating the random value u by the first function unit 113e and the fourth function unit 126e, as long as the same value can be obtained in the encryption device 110e and the decryption device 120e, other generation methods may be used.
[0668] For example, for an arbitrary function Func, u=Func (s) may be used in the encryption device 110e and the decryption device
The same value can be obtained in 120e. That is, G(s) is generated, and a and K are generated based on G(s).
[0669] Generate Func (s) such that u = Func (s).
[0670] (4) Furthermore, in addition to being generated by the first function unit 113e and the fourth function unit 126e, the random value u only needs to obtain the same value in the encryption device 110e and the decryption device 120e, so the encryption device 110e can also send a random value Uo directly to the decryption device 120e
[0671] That is, the encrypted text C and the random value u may be sent to the decryption device 120e as follows.
[0672] Generate G (s), and generate a and K based on G (s).
[0673] Through another channel, the random value u is sent from the encryption device 110e to the decryption device 120e.
[0674] In addition, the encryption device 110e may also encrypt the random value u before sending it.
[0675] (5) Furthermore, since the random value u only needs to be able to obtain the same value from the encryption device 110e and the decryption device 120e, it is also possible to use the first function unit 113e and the fourth function unit 126e to generate a part of the random value u. The partial information of the structure, the remaining partial information of the random value u is directly sent from the encryption device 110e to the decryption device 120e.
[0676] For example, as described below, the encrypted text C and the random value u2 may also be sent to the decryption device 120e.
[0677] Generate G(s), and generate a, K, and ul according to G(s)<sub>o</sub>
[0678] Through another channel, the random value u2 is sent from the encryption device 110e to the decryption device 120e.
[0679] Use u = ul xor u2 to generate a random value u.
[0680] In addition, the encryption device 110e may also encrypt the random value u2 before sending it.
[0681] (6) The decryption device 120e verifies whether the first encrypted text cl is the encrypted text of the verification value a" obtained by the fourth function unit 126e, and when cl is the encrypted text of a", the shared key K is used to The public key encrypted text Ci is decrypted, but it can also be performed using the same verification method as the decryption device 120d of the third embodiment.
[0682] That is, as shown in the processing system of FIG. 20, the decryption unit 123d and the comparison unit 127d may be used in the same manner as the decryption device 120d, and the verification may be performed as follows.
[0683] (a) The first encrypted text c1 is encrypted using the secret key polynomial f, and a'is regenerated (step S252).
[0684] (b) Generate s'=c2 xor H(a', cl) (step S254).
[0685] (c) G(s') is generated (step S255), and a", K', and u'are generated based on G (s') (step S256e).
[0686] (d) It is checked whether a"=a is established (step S257), and if it is established, the shared key K'is output (step S258)
[0687] In addition, it is also possible to check whether the first encrypted text c1 is an encrypted text of the decryption verification value a'.
7. Summary of Embodiment 3 and Embodiment 4
[0689] As explained above, the present invention is a shared key generating device that outputs shared key data and encrypted shared key data obtained by encrypting the above shared key data according to the pre-given shared key data, including: A secret number data generating unit that generates secret number data; a shared key derivation unit that converts the secret number data into verification value data and the shared key data according to a predetermined process; encrypts the verification value data based on the public key data Then, the first encryption unit that generates the first encrypted preliminary data; the verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; encrypts the secret number data based on the conversion verification value data to generate the second A second encryption unit that encrypts preliminary data, wherein the encrypted shared key data is composed of the first encrypted preliminary data and the second encrypted preliminary data.
[0690] In addition, the present invention is a shared key generating device that outputs shared key data and encrypted shared key data obtained by encrypting the above shared key data according to the public key data given in advance, including: generating secret number data A secret number data generation unit; a shared key derivation unit that converts the secret number data and the first encrypted preliminary data into verification value data and the shared key data according to a predetermined process; verifies the above based on the public key data The first encryption unit that generates the first encrypted preliminary data after the value data is encrypted; the verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; the secret number data is encrypted based on the conversion verification value data A second encryption unit that generates second encrypted preliminary data, wherein the encrypted shared key data is composed of the first encrypted preliminary data and the second encrypted preliminary data.
[0691] In addition, the present invention is a shared key generating device that outputs shared key data and encrypted shared key data obtained by encrypting the above shared key data according to the public key data given in advance, including: generating secret number data The secret number data generation part; the shared key derivation part that converts the secret number data into verification value data, random number data, and the shared key data according to a predetermined process; according to the public key data and the random number data, The first encryption unit that generates the first encrypted preliminary data after the verification value data is encrypted; the verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; the secret number data is converted based on the conversion verification value data A second encryption unit that generates second encrypted preliminary data after encryption, and the encrypted shared key data is composed of the first encrypted preliminary data and the second encrypted preliminary data.
[0692] In addition, the present invention is a shared key generating device that outputs shared key data and encrypted shared key data obtained by encrypting the above shared key data according to the public key data given in advance, including: generating secret number data The secret number data generation part; the shared key derivation part that converts the secret number data into verification value data, random number data, and the shared key data according to a predetermined process; according to the public key data and the random number data, A first encryption unit that generates first encrypted preliminary data after the verification value data is encrypted; a verification value conversion unit that converts the verification value data and the first encrypted preliminary data into converted verification value data according to a predetermined process; verifies according to the conversion The value data encrypts the secret number data to generate a second encryption unit that generates second encrypted preliminary data, and the encrypted shared key data is composed of the first encrypted preliminary data and the second encrypted preliminary data.
[0693] Here, the above-mentioned secret number data may be a random number generated at random.
[0694] Here, as a predetermined process, the shared key derivation unit may use a one-way hash function.
[0695] Here, the first encryption unit may generate the first encrypted preliminary data after encryption using the NTRU encryption method.
[0696] Here, as the predetermined processing, the verification value conversion unit may use a one-way hash function.
[0697] Here, the second encryption unit may perform an exclusive operation of the secret number data and the verification value data to generate the second encrypted preliminary data.
[0698] Here, the second encryption unit may use the converted verification value data as an encryption key, and generate the second encrypted preliminary data by encrypting the secret data using a public key encryption method.
[0699] Here, the second encryption unit may add the converted verification value data and the secret number data to generate the second encrypted preliminary data.
[0700] Here, the second encryption unit may generate the second encrypted preliminary data after multiplying the verification value data and the secret number data.
[0701] Here, the encrypted shared key data may be bit concatenation data of the first encrypted preliminary data and the second encrypted preliminary data.
CN 1745537 Β
[0702] In addition, the present invention is a shared key recovery device that decrypts encrypted shared key data composed of first encrypted preliminary data and second encrypted preliminary data based on predetermined secret key data, and then outputs the shared key data, It includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; a verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; The second decryption unit that generates the secret number data after decrypting the above-mentioned second encrypted preliminary data by transforming the verification value data converts the above-mentioned secret number data into the shared key derivation unit of the above-mentioned shared key data according to a predetermined process, and uses it as the above-mentioned verification value When the data is consistent with the verification value verification data, the shared key data is output.
[0703] In addition, the present invention is a shared key recovery device that decrypts encrypted shared key data composed of first encrypted preliminary data and second encrypted preliminary data based on predetermined secret key data, and then outputs the shared key data, Comprising: a first decryption unit that decrypts the first encrypted preliminary data and regenerates verification value data based on the secret key data; and verifies that the verification value data and the first encrypted preliminary data are converted into converted verification value data according to a predetermined process Value conversion unit; according to the conversion verification value data, the second decryption unit that generates secret data after decrypting the second encrypted preliminary data; and derives the shared key that converts the secret number data into the shared key data according to a predetermined process Section, when the verification value data is consistent with the verification value verification data, the shared key data is output.
[0704] In addition, the present invention is a shared key recovery device that decrypts encrypted shared key data composed of first encrypted preliminary data and second encrypted preliminary data based on predetermined secret key data, and then outputs the shared key data, It includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; a verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; The second decryption unit that generates secret number data after decrypting the above-mentioned second encrypted preliminary data by transforming the verification value data; converts the above-mentioned secret number data into verification value verification data, random number data, and sharing of the above-mentioned shared key data according to a predetermined process The key derivation unit outputs the shared key data when the verification value data and the verification value verification data match.
[0705] In addition, the present invention is a shared key restoration device that decrypts encrypted shared key data composed of first encrypted preliminary data and second encrypted preliminary data based on predetermined secret key data, and then outputs the shared key data, It includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; a verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; The second decryption unit that transforms the verification value data decrypts the second encrypted preliminary data and generates the secret number data; converts the secret number data into the verification value verification data, the random number data, and the sharing of the shared key data according to a predetermined process The key derivation unit outputs the shared key data when the verification value data and the verification value verification data match.
[0706] In addition, the present invention decrypts the encrypted shared key data composed of the first encrypted preliminary data and the second encrypted preliminary data based on the previously given secret key data and public key data, and then outputs the shared key data. The key restoration device includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; and converts the verification value data and the first encrypted preliminary data into A verification value conversion unit that converts verification value data; a second decryption unit that generates secret data after decrypting the second encrypted preliminary data based on the conversion verification value data; converts the secret data into verification value verification data according to a predetermined process , The random number data and the shared key derivation part of the shared key data, encrypt the verification value verification data based on the public key data and the random number data, and then generate the third encryption part of the third encryption preliminary data, when the said first 1 When the encrypted preliminary data matches the third encrypted preliminary data, the shared key data is output.
[0707] In addition, the present invention decrypts the encrypted shared key data composed of the first encrypted preliminary data and the second encrypted preliminary data based on the previously given secret key data and public key data, and then outputs the shared key data. Key
CN 1745537 Β
The restoration device includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; and a verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process ; According to the conversion verification value data, the second decryption unit that generates the secret number data after decrypting the second encrypted preliminary data; in accordance with a predetermined process, transforms the secret number data into verification value verification data, random number data, and the shared key The data shared key derivation unit encrypts the verification value data based on the public key data and the random number data, and then generates the third encryption unit for generating third encryption preparation data. When the first encryption preparation data and the third encryption preparation data are When the data is consistent, the above shared key data is output.
[0708] In addition, the present invention decrypts the encrypted shared key data composed of the first encrypted preliminary data and the second encrypted preliminary data based on the previously given secret key data and public key data, and then outputs the shared key data. The key restoration device includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; and converts the verification value data and the first encrypted preliminary data into A verification value conversion unit that converts verification value data; a second decryption unit that decrypts the second encrypted preliminary data based on the conversion verification value data to generate secret data; converts the secret data into verification value verification data according to a predetermined process , The random number data and the shared key derivation part of the shared key data, encrypt the verification value verification data based on the public key data and the random number data, and then generate the third encryption part of the third encryption preliminary data, when the said first 1 When the encrypted preliminary data matches the third encrypted preliminary data, the shared key data is output.
[0709] In addition, the present invention decrypts the encrypted shared key data composed of the first encrypted preliminary data and the second encrypted preliminary data based on the previously given secret key data and public key data, and then outputs the shared key data. The key restoration device includes: a first decryption unit that decrypts the first encrypted preliminary data based on the secret key data and then generates verification value data; and converts the verification value data and the first encrypted preliminary data into A verification value conversion unit that converts verification value data; a second decryption unit that decrypts the second encrypted preliminary data based on the conversion verification value data to generate secret data, and converts the secret data into verification value verification data according to a predetermined process , The random number data and the shared key derivation part of the shared key data; the third encryption part that generates the third encryption preliminary data after encrypting the verification value data based on the public key data and the random number data, when the first When the encrypted preliminary data matches the third encrypted preliminary data, the shared key data is output.
[0710] Here, as a predetermined process, the shared key derivation unit may use a one-way hash function.
[0711] Here, the above-mentioned first decryption unit may generate verification value data after decryption using the NTRU encryption method.
[0712] Here, as the predetermined processing, the verification value conversion unit may use a one-way hash function.
[0713] Here, as a predetermined process, the verification value conversion unit may directly use the verification value data as the conversion verification value data as it is.
[0714] Here, the second decryption unit may perform an exclusive operation of the second encrypted preliminary data and the verification value data before generating the secret number data.
[0715] Here, the second decryption unit may use the converted verification value data as an encryption key, and generate the secret number data after decrypting the second encrypted preliminary data using a shared key encryption method.
[0716] Here, the second decryption unit may subtract the conversion verification value data from the second encrypted preliminary data to generate the secret number data.
[0717] Here, the second decryption unit may divide the second encrypted preliminary data by the converted verification value data to generate the secret number data.
[0718] In addition, the present invention generates an encrypted text in which the plain text data is encrypted based on the public key data given in advance.
The data encryption device includes: a secret number data generating unit that generates secret number data; a shared key derivation unit that converts the above secret number data into verification value data and shared key data according to a predetermined process; and based on the public key data The first encryption unit that generates the first encrypted preliminary data after encrypting the verification value data; the verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; and converts the secret data based on the conversion verification value data. A second encryption unit that generates second encrypted preliminary data after data encryption; a third encryption unit that generates third encrypted preliminary data after encrypting the plaintext data based on the shared key data, and the encrypted text data is composed of the first encrypted preliminary data , The above-mentioned second encrypted preliminary data and the above-mentioned third encrypted preliminary data are constituted.
[0719] In addition, the present invention is a decryption device that decrypts encrypted text data composed of the first encrypted preliminary data, the second encrypted preliminary data, and the third encrypted preliminary data based on the secret key data given in advance, and then outputs the decrypted text data, It includes: a first decryption unit that generates verification value data after decrypting the first encrypted preliminary data based on the secret key data; a verification value conversion unit that converts the verification value data into verification value data according to a predetermined process; A second decryption unit that converts the verification value data to decrypt the second encrypted preliminary data to generate secret data; and a shared key derivation unit that converts the secret data into verification value verification data and shared key data according to a predetermined process , It further includes a decryption unit, when the verification value data is consistent with the verification value verification data, the third encrypted preliminary data is decrypted according to the shared key to generate the decrypted text data.
[0720] In addition, the present invention is an encryption device that generates encrypted text data encrypted with plain text data based on the public key data given in advance, and decrypts the encrypted text data according to the given secret key data and outputs the decrypted data. A cryptographic system composed of a decryption device for text data. The encryption device includes: a secret number data generation unit that generates secret number data; a shared key derivation unit that converts the secret number data into verification value data and shared key data according to a predetermined process; The first encryption unit that generates the first encrypted preliminary data after the verification value data is encrypted; the verification value conversion unit that converts the verification value data into the verification value data according to a predetermined process; encrypts the secret number data based on the conversion verification value data A second encryption unit that generates second encrypted preliminary data; a third encryption unit that generates third encrypted preliminary data after encrypting the plaintext data based on the shared key data, and the encrypted text data is composed of the first encrypted preliminary data, the The second encrypted preliminary data is composed of the third encrypted preliminary data. The decryption device includes: a first decryption unit that generates the verification value data after decrypting the first encrypted preliminary data based on the secret key data; and converts the verification value data into a verification value of the converted verification value data according to a predetermined process Transformation department; A second decryption unit that generates the secret number data after decrypting the second encrypted preliminary data based on the conversion verification value data; and transforms the secret number data into a shared secret of verification value verification data and shared key data in accordance with a predetermined process The key derivation unit further includes a decryption unit that, when the verification value data and the verification value verification data match, decrypt the third encrypted preliminary data based on the shared key data to generate the decrypted text data.
[0721] As explained above, the present invention is proposed in view of the problems of the existing system. Therefore, in the cryptographic system, by forming a key sealing mechanism that can use the NTRU password, the NTRU password can be used in the encryption device and Key distribution between decryption devices.
[0722] As described above, it is possible to provide a cryptographic system that cannot be implemented in the prior art, which has great value.
[0723] 8. Other Modifications
[0724] Although the present invention has been described based on the above-mentioned embodiments, the present invention is not limited to the above-mentioned embodiments, and the following cases are also included in the present invention.
[0725] (1) The encryption device may not send each encrypted text to the decryption device via the Internet, but may write each encrypted text to a recording medium such as a DVD, and the decryption device may read each encrypted text from the recording medium.
[0726] (2) In addition to the method described in Non-Patent Document 2, the NTRU cipher used in the present invention may also be
EESS (Efficient Embedded Security Standard: Effective Embedded Security Standard) NTRU password. Regarding the NTRU password of the EESS method, there are in EESS [Consortium for Efficient Embedded Security, EfficientEmbedded Security Standards#]: Implementation Aspects of NTRUEncrypt and NTRU Sign, Version 2. 0, (available at http:/ceesstandards. org, May2003) The detailed description is therefore omitted here, and will be briefly described below.
[0727] In the NTRU cipher of the EESS method, the random number polynomial r is a polynomial with d coefficients of 1 and (Nd) coefficients of 0, or a polynomial calculated by using a plurality of such polynomials. Therefore, in the above embodiment, when generating the random number polynomial r, if such a polynomial is generated, the EESS method password can be used instead of the NTRU password, and the same effect can be obtained.
[0728] (3) The content distribution system may also be configured as shown below.
[0729] The content distribution system is composed of a content service device, an encryption device, a transmission device, a reception device, a decryption device, a reproduction device, and a monitor.
[0730] The encryption device and the decryption device correspond to the encryption device 110 and the decryption device 120 of the content distribution system 10. [0731] The content server device and the encryption device are connected via a dedicated line, and the content server device sends the content such as a movie composed of images and sounds to the encryption device via the dedicated line. The encryption device and the sending device are connected via a dedicated line. The encryption device transmits each encrypted text to the transmitting device, and the transmitting device multiplexes each encrypted text, modulates the encrypted text, and transmits it on the digital broadcast wave.
[0732] The receiving device is connected to the decrypting device, and the decrypting device is connected to the reproducing device. The receiving device receives the digital broadcast wave, extracts each encrypted text from the received digital broadcast wave, and transmits each extracted encrypted text to the decryption device ο The decryption device receives each encrypted text, and uses the received encrypted text to generate reproduced content, and the generated The reproduced content is output to the reproduction device. The reproduction device is connected to a monitor with a built-in speaker. The reproducing device receives the reproduced content, generates an image signal and a sound signal from the received reproduced content, and the monitor displays the image and outputs the sound.
[0733] (4) The content server device and the encryption device may be formed as an integrated device. In addition, the decryption device and the reproduction device may also be constituted by an integrated device.
[0734] (5) In each of the above embodiments, the memory card 160 prestores the public key polynomial, the memory card 170 prestores the secret key polynomial f and the public key polynomial h, and the encryption device 110 and the decryption device 120 respectively store the secret key polynomial f and the public key polynomial h. The card 160 and the memory card 170 obtain the public key polynomial and the secret key polynomial, but are not limited to this.
[0735] The encryption device 110 may store the public key polynomial in advance, and the decryption device 120 may store the public key polynomial and the secret key polynomial in advance.
[0736] In addition, the key management device may also generate a secret key polynomial and a public key polynomial, send the secret key polynomial and the public key polynomial secretly and securely to the decryption device 120, and send the generated public key polynomial to the decryption device 120. Send to the encryption device 110.
[0737] (6) The content distributed by the content distribution system is not limited to content such as movies composed of images and sounds. It can also be a database generated by moving images, still images, sounds, music, documents, novels, and DB software, spreadsheet data generated by table calculation software, computer programs, or other computer data.
[0738] In addition, the above-mentioned content may not be the above-mentioned work, but may be key information used for encryption, decryption, digital signature, signature verification, and the like.
[0739] For example, as shown in each of the above-mentioned embodiments, the encryption device and the decryption device may share a shared key, and
The secret device uses the shared key to encrypt the content key and then generates the encrypted content key, uses the content key to encrypt the content and generates the encrypted content, and sends the generated encrypted content key and the generated encrypted content to the decryption device. The decryption device receives the encrypted content key and the encrypted content, uses the shared key to decrypt the encrypted content key to generate a content key, and uses the generated content key to decrypt the encrypted content to generate content.
[0740] (7) The present invention may be the method shown above. It may be a computer program that implements these methods by a computer, or it may be a digital signal composed of the above-mentioned computer program.
[0741] In addition, the present invention may be to record the above-mentioned computer program or the above-mentioned digital signal on a computer-readable recording medium, for example, a floppy disk, a hard disk, a CD-ROM, a MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray disc), semiconductor memory and other technologies. In addition, it may be the above-mentioned computer program or the above-mentioned digital signal recorded on these recording media. [0742] In addition, the present invention may also be a technology for transmitting the above-mentioned computer program or the above-mentioned digital signal via an electric communication line, a wireless or wired communication line, a network typified by the Internet, digital broadcasting, and the like.
[0743] In addition, the present invention may also be a computer system having a microprocessor and a memory, the memory stores a computer program, and the microprocessor operates in accordance with the computer program.
[0744] In addition, the present invention may also be implemented by another independent computer system by recording the above-mentioned program and the above-mentioned digital signal in the above-mentioned recording medium before transferring, or transferring the above-mentioned program or the above-mentioned digital signal via the above-mentioned network or the like. .
[0745] (8) The above-mentioned embodiment and the above-mentioned modification may be combined separately.
[0746] The content distribution system described above can continue to be used commercially and repeatedly in an industry in which digital works such as music, movies, and novels are supplied to users from content providers. In addition, the encryption device and decryption device that constitute the content distribution system can be manufactured and sold in the electrical industry such as manufacturing electrical products.
[0747] In particular, it is suitable for industries that provide digital products by storing digital works on recording media such as DVDs and then circulating them on the market, or circulating them via the Internet, or broadcasting.
21 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO9808323A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| CN1232588A | Cites | China | Search report |
| US5937066A | Cites | United States of America | Search report |
| US5907618A | Cites | United States of America | Search report |
| US5953420A | Cites | United States of America | Search report |
| JP特开2002252611A | Cites | Japan | Search report |
20 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 3510632002 | Japan | – | |
| 3510622002 | Japan | – | |
| 2002351063 | Japan | A | |
| 2002351062 | Japan | A | |
| 0315214 | Japan | W |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| WO2004051920A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2004051921A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003302544A1 | Australia | A1 | |
| AU2003302545A1 | Australia | A1 | |
| JP2004201292A | Japan | A | |
| JP2004201293A | Japan | A | |
| US2004165726A1 | United States of America | A1 | |
| US2004174997A1 | United States of America | A1 | |
| EP1475920A1 | European Patent Office (EPO) | A1 | |
| EP1475920A4 | European Patent Office (EPO) | A4 | |
| KR20050083566A | Republic of Korea | A | |
| EP1569378A1 | European Patent Office (EPO) | A1 | |
| KR20050087815A | Republic of Korea | A | |
| CN1692598A | China | A | |
| CN1745537A | China | A | |
| EP1569378A4 | European Patent Office (EPO) | A4 | |
| US7471792B2 | United States of America | B2 | |
| CN1745537BThis record | China | B | |
| JP4485175B2 | Japan | B2 | |
| KR101027199B1 | Republic of Korea | B1 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiry of patent termCX01 | CX01 | |
| Transfer of patent rightTR01 | TR01 | |
| Transfer of patent rightTR01 | TR01 | |
| Change in the name or title of a patent holderCP01 | CP01 | |
| Change of name, title or addressCP03 | CP03 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1745537
- Application
- 801094843
Titles2
- Chinese
- 密钥共享系统、共享密钥生成装置及共享密钥复原装置
- English
- Key sharing system, shared key generating device and shared key recovery device
Classification
- IPC, 2
- H04L9 08
- G09C1 00