EP1031204A2

Cryptographic system and method with fast decryption

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 16 September 2018, 8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

42 claims: 11 independent, 31 dependent

  1. 1
    Claims of equivalent WO 9934552 A2 CLAIMS 1. In a system for sending messages over a network between first and second computing units, a method comprising the following steps:(a) encrypting a message M into ciphertext C at the first computing unit, where the ciphertext C includes a value V and a value W, as follows: (1) a value V is a function of a number x, V = x e , where e is an integer and x is as follows: x = g R mod n, where: (i) n is a number n = p, p 2 where p, and p 2 are prime numbers with p ! = τ { q, + 1 and p 2 = r 2 c^ + 1, where τ and r 2 are random numbers, and qi and q 2 are prime numbers;(ii) R is a random number selected independent of the random numbers and r 2 ;and (iii) g is a number in the form of g = r 3 ( i "1)(p 2 "1)/q i q 2 mod n, where r 3 is a random number selected independent of the random numbers r l5 r 2 , and R;
  2. 2
    (2) a value W is a function of a value h(x) and the message M, the value h(x) being a result of a one-way function of the number x;(b) sending the ciphertext C from the first computing unit to the second computing unit;and (c) decrypting the ciphertext C at the second computing unit to reproduce the message M, where M is a function of the value W and the value h(x) and x is derived as x = V (1/e) mod q A mod n. 2. A method as recited in claim 1, wherein the encrypting step comprises the step of deriving the value W as W = h(x)ΘM.
  3. 12
    13. A method for decrypting ciphertext C to reproduce a message M, wherein:n is a number in the form n = pj p 2 , where p, and p 2 are prime numbers;Pi = r ι lι + 1 a d p 2 = r 2 q 2 + 1, where r, and r 2 are random numbers and q, and q 2 are prime numbers;g is a number in the form of g = r 3 (p ~1)(p 2 "1)/q ι q 2 mod n, where r 3 is a random number selected independent of the random numbers r, and r 2 ;x is a number in the form of x = g R mod n, where R is a random number selected independent of the random numbers r r 2 , and r 3 ;e is an integer;and V is a value in the form of V = x e ;the method comprising the following steps: recovering the number x from the value V, where x = V (1/e) mod q ^ mod n;transforming the number x according to a one-way function h to yield a value h(x);and decoding the ciphertext C according to a function of the value h(x) to recapture the message M.
  4. 17
    18. In a system for sending messages over a network between first and second computing units, a method comprising the following steps:(a) encrypting a message M into ciphertext C at the first computing unit, where the ciphertext C includes a value V and a value W, as follows: (1) a value V is a function of a number x, V = x e , where e is an integer selected from the first b odd primes, and x is as follows: x — g R mod n, where: (i) n is a number n = p, p 2 where p] and p 2 are prime numbers with p] = r, q, + 1 and p 2 = r 2 q 2 + 1, where q x and q 2 are prime numbers and r, and r 2 are random numbers that are not divisible by the first b odd primes;(ii) R is a random number selected independent of the random numbers r t and r 2 ;and (iii) g is a number in the form of g = r 3 (p ι "ιχp 2 "1)/q ι q 2 mod n, where r 3 is a random number selected independent of the random numbers r l5 r 2 , and R;(2) a value W is a function of a value h(x) and the message M, the value h(x) being a result of a one-way function of the number x;(b) sending the ciphertext C from the first computing unit to the second computing unit;and (c) decrypting the ciphertext C at the second computing unit to reproduce the message M, where M is a function of the value W and the value h(x) and x is derived as x = V (1/e) mod q q 2 mod n.
  5. 18
    19. In a Bellare-Rogaway cryptosystem that employs the RSA trapdoor permutation family, a method for improving decryption by replacing the RSA trapdoor permutation family with a family of trapdoor permutations based on exponentiation in subgroups of Z n * .
  6. 21
    22. A system for sending messages over a communications channel, comprising:an encoder to transform a message M into ciphertext C and transmit the ciphertext C over the communications channel, where the ciphertext C includes a value V and a value W, as follows: (1) a value V is a function of a number x, V = x e , where e is an integer and x is as follows: x = g R mod n, where: (i) n is a number n = p, p 2 where p, and p 2 are prime numbers with p, = r, q, + 1 and p 2 = r 2 q 2 + 1, where r, and r 2 are random numbers, and q, and q 2 are prime numbers;(ii) R is a random number selected independent of the random numbers T j and r 2 ;and (iii) g is a number in the form of g = r 3 (p i "1Xp 2 ~1)/q i q 2 mod n, where r 3 is a random number selected independent of the random numbers r,, r 2 , and R;(2) a value W is a function of a value h(x) and the message M, the value h(x) being a result of a one-way function of the number x;and a decoder coupled to receive the ciphertext C and the value V from the communications channel and to transform the ciphertext C back to the message M, where M is a function of the value W and the value h(x) and x is derived as x = v (1/e) mod q ι q mod n.
  7. 27
    28. An encoder for a cryptographic system, where:n is a number in the form n = p, p 2 , where p, and p 2 are prime numbers;p, = r, q x + 1 and p 2 = r 2 q 2 + 1, where r, and r 2 are random numbers and q, and q 2 are prime numbers;and g is a number in the form of g = r 3 (p 1Xp 2 "1) q i q 2 mod n, where r 3 is a random number selected independent of the random numbers r, and r 2 ;the encoder comprising: means for computing a number x = g R mod n, where R is a random number selected independent of the random numbers r r 2 , and r 3 ;means for transforming the number x according to a one-way function h to yield a value h(x);and means for encoding a message M according to a function of the value h(x).
  8. 30
    31. A decoder for a cryptographic system, where:n is a number in the form n = p, p 2 , where p, and p 2 are prime numbers;p 1 = rj q α + 1 and p 2 = r 2 q 2 + 1, where r, and r 2 are random numbers and q, and q 2 are prime numbers;g is a number in the form of g = r 3 (p i "1Xp 2 "1)/q i q 2 mod n, where r 3 is a random number selected independent of the random numbers τ x and r 2 ;x is a number in the form of x = g R mod n, where R is a random number selected independent of the random numbers r 1} r 2 , and r 3 ;e is an integer;V is a value in the form of V = x e ;and W is a value derived from a function of a message M and a value h(x), where h(x) is a result of a one-way function h;the decoder comprising: means for receiving the values V and W;means for recovering the number x from the value V, where x = V (1/e) mod q ι q 2 mod n;means for transforming the number x according to a one-way function h to yield the value h(x);and means for decoding the value W according to a function of the value h(x) to recapture the message M.
  9. 33
    34. A system for sending messages over a communications channel, comprising:an encoder to transform a message M into ciphertext C and transmit the ciphertext C over the communications channel, where the ciphertext C includes a value V and a value W, as follows: (1) a value V is a function of a number x, V = x e , where e is an integer selected from the first b odd primes, and x is as follows: x = g R mod n, where: (i) n is a number n = τp λ p 2 where p] and p 2 are prime numbers with p, = r, q, + 1 and p 2 = r 2 q 2 + 1 , where q, and c^ are prime numbers and r, and r 2 are random numbers that are not divisible by the first b odd primes;(ii) R is a random number selected independent of the random numbers r, and r 2 ;and (iii) g is a number in the form of g = r 3 (p "1Xp 2 "1)/q i q 2 mod n, where r 3 is a random number selected independent of the random numbers r l5 r 2 , and R;(2) a value W is a function of a value h(x) and the message M, the value h(x) being a result of a one-way function of the number x;a decoder coupled to receive the ciphertext C and the value V from the communications channel and to transform the ciphertext C back to the message M, where M is a function of the value W and the value h(x) and x is derived as x = V (1 e) mod q ' q 2 mod n.
  10. 34
    35. A Bellare-Rogaway cryptosystem that employs the RSA trapdoor permutation family, characterized by replacing the RSA trapdoor permutation family with a family of trapdoor permutations based on exponentiation in subgroups of Z n *.
  11. 35
    36. A computer-readable medium having computer-executable instructions for directing a computer to encrypt a message M to a ciphertext C, where:n is a number in the form n = p, p 2 , where p, and p 2 are prime numbers;Pi = r ι Qi + 1 an d V2 = r 2 h + 1) where r, and r 2 are random numbers and q x and qj are prime numbers;and g is a number in the form of g = r 3 (p ιχ, Y 1)/q ι q 2 mod n, where r 3 is a random number selected independent of the random numbers r, and r 2 ;the computer-readable medium comprising: computer-executable instructions to direct a computer to compute a number x = g R mod n, where R is a random number selected independent of the random numbers r l5 r 2 , and r 3 ;computer-executable instructions to direct a computer to transform the number x according to a one-way function h to yield a value h(x);and computer-executable instructions to direct a computer to encode a message M according to a function of the value h(x).
  12. 39
    40. A computer-readable medium having computer-executable instructions for directing a computer to decrypt ciphertext C to recover a message M, where:n is a number in the form n = p x p 2 , where p, and p 2 are prime numbers;Pi = r ι Qi + 1 an d P2 = r 2 ° + I * where and r 2 are random numbers and q ! and c^ are prime numbers;g is a number in the form of g = r 3 (p ' "1)(p 2 "1)/q ι q 2 mod n, where r 3 is a random number selected independent of the random numbers r and r 2 ;x is a number in the form of x = g R mod n, where R is a random number selected independent of the random numbers r,, r 2 , and r 3 ;e is an integer;and V is a value in the form of V = x e ;the computer-readable medium comprising: computer-executable instructions to direct a computer to recover the number x from the value V, where x = V (1/e) mod q q 2 mod n;computer-executable instructions to direct a computer to transform the number x according to a one-way function h to yield h(x);and computer-executable instructions to direct a computer to decode the ciphertext C according to a function of h(x) to recapture the message M.