EP1528705B1

Use of isogenies for design of cryptosystems

Abstract

Techniques are disclosed to provide public-key encryption systems. More particularly, isogenies of Abelian varieties (e.g., elliptic curves in one-dimensional cases) are utilized to provide public-key encryption systems. For example, the isogenies permit the use of multiple curves instead of a single curve to provide more secure encryption. The techniques may be applied to digital signatures and/or identity based encryption (IBE) solutions. Furthermore, the isogenies may be used in other applications such as blind signatures, hierarchical systems, and the like. Additionally, solutions are disclosed for generating the isogenies.In one implementation, the techniques include publishing a public key corresponding to an isogeny. An encrypted message is decrypted with a decryption key that corresponds to the isogeny (e.g., its dual isogeny).

EP1528705B1, drawing sheet 1
Sheet 1 of 25

Term

Term ended

Expired 10 August 2024, 2.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

32 claims: 32 independent, 0 dependent

  1. 1
    A method comprising:publishing (104) a public key defined by an isogeny (φ) that maps a plurality of points from a first Abelian variety (E 1 ) onto a second Abelian variety (E 2 );and decrypting (108) an encrypted message using a decryption key defined by isogeny.
  2. 2
    A method as recited by claim 1, wherein the first and second Abelian varieties are elliptic curves.
  3. 3
    A method as recited by one of claims 1 or 2, wherein the decryption key is a dual isogeny (φ̂) of the isogeny.
  4. 4
    A method as recited by one of claims 1 to 3, wherein the isogeny is generated using a technique selected from a group comprising complex multiplication generation, modular generation, linearly independent generation, and combinations thereof.
  5. 5
    A method as recited by one of claims 1 to 4, wherein the second Abelian variety is one of a plurality of Abelian varieties, and the isogeny is one of a family of isogenies, each isogeny mapping a plurality of points from the first Abelian variety onto one of the plurality of Abelian varieties, and the public key and the decryption key are defined by all isogenies of the family.
  6. 6
    A method as recited by one of claims 1 to 5, wherein the decryption is performed by bilinear pairing.
  7. 7
    A method as recited by claim 6, wherein the bilinear pairing is a pairing selected from a group comprising Well pairing, Tate pairing, and square pairing.
  8. 8
    A method as recited by one of claims 1 to 7, wherein the method signs the message.
  9. 9
    A method as recited by one of claims 1 to 8, wherein the method provides identity based encryption.
  10. 10
    A method as recited by one of claims 1 to 9, further comprising:generating (102) the isogeny (φ) that maps a plurality of points from the first Abelian variety (E 1 ) onto a second Abelian variety (E 2 );and encrypting (106) the message using an encryption key defined by the isogeny.
  11. 11
    A method as recited by claim 10, wherein at least one of the encryption key or the decryption key is a private key, the private key being a dual isogeny (φ̂) of the isogeny.
  12. 12
    A method as recited by one of claims 1 to 11, further comprising composing a plurality of modular isogenies to provide the isogeny without revealing any intermediate curves.
  13. 13
    A method as recited by one of claims 1 to 12, further comprising using the output of a trace map to shorten the representation of points on an Abelian variety.
  14. 14
    A method as recited by claim 13, further comprising using the output of a trace map down to a base field to shorten the representation of points on the Abelian variety mapped by the isogeny.
  15. 15
    A system comprising:a first processor;a first system memory coupled to the first processor, the first system memory being adapted to store a public key defined by an isogeny (φ) that maps a plurality of points from a first Abelian variety (E 1 ) onto a second Abelian variety (E 2 ) a second processor;a second system memory coupled to the second processor, the second system memory being adapted to store an encrypted message and a decryption key defined by the isogeny, the second processor being adapted to decrypt the encrypted message with the decryption key wherein the first processor is adapted to gerenate the encrypted message by using an encryption key defined by the isogeny.
  16. 16
    A system as recited by claim 15, wherein the first and second Abelian varieties are elliptic curves.
  17. 17
    A system as recited by one of claims 15 or 16, wherein at least one of the encryption key or the decryption key is a private key, the private key being a dual isogeny (φ̂) of the isogeny.
  18. 18
    A system as recited by one of claims 15 to 17, wherein the second Abelian variety is one of a plurality of Abelian varieties, and the isogeny is one of a family of isogenies, each isogeny mapping a plurality of points from the first Abelian variety onto one of the plurality of Abelian varieties, and the public key and the decryption key are defined by all isogenies of the family.
  19. 19
    A system as recited by one of claims 15 to 18, wherein the second processor is adapted to perform the decryption by bilinear pairing.
  20. 20
    A system as recited by claim 19, wherein the bilinear pairing is one of a group comprising Weil pairing, Tate pairing, and square pairing.
  21. 21
    One or more computer-readable media having instructions stored thereon that, when executed, direct a machine to perform method steps comprising:publishing a public key defined by an isogeny (φ) that maps a plurality of points from a first Abelian variety (E 1 ) onto a second Abelian variety (E 2 );and decrypting an encrypted message using a decryption key defined by the isogeny.
  22. 22
    One or more computer readable media as recited by claim 21, wherein the first and second Abelian varieties are elliptic curves.
  23. 23
    One or more computer-readable media as recited by one of claims 21 or 22, wherein the decryption key is a private key, the private key being a dual isogeny (φ̂) of the isogeny.
  24. 24
    One or more computer-readable media as recited by one of claims 21 to 23, wherein the isogeny is generated using a technique selected from a group comprising complex multiplication generation, modular generation, linearly independent generation, and combinations thereof.
  25. 25
    One or more computer-readable media as recited by one of claims 21 to 24, wherein the second Abelian variety is one of a plurality of Abelian varieties, and the isogeny is one of a family of isogenies, each isogeny mapping a plurality of points from the first Abelian variety onto one of the plurality of Abelian varieties, and the public key and the decryption key are defined by all isogenies of the family.
  26. 26
    One or more computer-readable media as recited by one of claims 21 to 25, wherein the decrypting is performed by bilinear pairing.
  27. 27
    One or more computer-readable media as recited by claim 26, wherein the bilinear pairing is a pairing selected from a group comprising Weil pairing, Tate pairing, and square pairing.
  28. 28
    One or more computer-readable media as recited by one of claims 21 to 27, wherein the method steps further comprise composing a plurality of modular isogenies to provide the isogeny without revealing any intermediate curves.
  29. 29
    One or more computer-readable media as recited by one of claims 21 to 28, wherein the method steps further comprise using the output of a trace map to shorten the representation of points on an Abelian variety.
  30. 30
    One or more computer-readable media as recited by claim 29, wherein the method steps further comprise using the output of a trace map down to a base field to shorten the representation of points on the Abelian variety mapped by the isogeny.
  31. 31
    One or more computer-readable media as recited by one of claims 21 to 30, wherein the method steps sign the message.
  32. 32
    One or more computer-readable media as recited by one of claims 21 to 31, wherein the method steps provide identity based encryption.
Independent claims32