EP2149221A2

Method of authentication of an entity by a verifying entity

Abstract

Method of authentication of an entity by a verifying entity, said entities sharing a pair of secret keys X and Y. According to the invention, said secret keys X and Y are binary matrices n ´ m (n,m >l), said method comprising steps repeated r times (r = l) consisting: - for the entity (1) to be authenticated and the verifying entity (2), in exchanging binary vectors a and b of n bits respectively drawn randomly by the verifying entity (2) and the entity (1) to be authenticated, and, for the entity (1) to be authenticated, in randomly drawing a binary noise vector c of m bits, each of said m bits being equal to 1 with a probability ? of less than 1/2, and in calculating and transmitting to the verifying entity (2) a response vector z of m bits equal toz = aX + bY +c, - for the verifying entity, in calculating the Hamming weight (220') of an error vector e = z + aX + bY, then, for the verifying entity, in accepting (240') the authentication if the Hamming weight of the r error vectors e satisfy a comparison relation (230') with a parameter (T) dependent on the probability ?. Application to cryptographic protocols for authenticating electronic chips at very low cost.

Term

1.7 yearsto projected expiry

Projected expiry 21 May 2028, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

11 claims: 4 independent, 7 dependent

  1. 1
    Claims of equivalent WO 2008149031 A2 1. A method of authenticating an entity (1) with a checking entity (2), said entities sharing a pair of secret keys X and Y, characterized in that said secret keys X and Y are binary matrices nxm (n, m> l), said method comprising repeated steps r times (r ≥ 1) consisting of:for the entity (1) to be authenticated and the verifier entity (2), exchanging bit vectors a and b of n bits respectively randomly selected by the verifier entity (2) and the entity (1) to be authenticated, and, for the entity (1) to authenticate, to draw a binary noise vector c of m bits, each of said m bits being equal to 1 with a probability η less than 1/2, and calculating and transmitting to the auditing entity (2) a response vector z of m bits equal to z = aX @ bY @ c, - for the auditing entity (2), to calculate the Hamming weight of an error vector e = z ® aX ® bY, then, for the auditing entity (2), to accept the authentication if the Hamming weights of the r error vectors e satisfy a relation of comparison to a parameter {T, t) function of the probability η.
  2. 6
    Method according to one of claims 4 or 5, wherein t is (η + ε) m where ε is a margin less than 1/2.
  3. 7
    The method of any one of claims 1 to 6, wherein said X and Y matrices are Toeplitz matrices.
  4. 8
    Entity intended to be authenticated by a checking entity (2), said entities sharing a pair of secret keys X and Y, characterized in that said entity (1) to be authenticated comprises means (10) for storing secret keys X and Y constituted by bit matrices nxm (n, m> 1), means (12) of communication with the checking entity (2), and means (11) of calculation able to perform r times (r> 1) the steps consisting of:drawing lots and transmitting to the checking entity (2) a binary vector b of n bits, to be received from the checking entity (2), a binary vector with n bits, to draw a binary vector at random a noise c of m bits, each of said m bits being equal to 1 with a probability η less than 1/2, and calculating and transmitting to the checking entity (2) a response vector z of m bits equal to z = aX ® bY θ c.
  5. 10
    Audit entity sharing a pair of secret keys X and Y with an entity (1) to be authenticated, characterized in that said checking entity (2) comprises means (20) for storing secret keys X and Y constituted by binary matrices nxm (n, m> l), means (22) for communication with the entity (1) to be authenticated, and means (21) for calculating able to carry out r times (r> 1) the steps of:to receive from the entity (1) to authenticate a binary vector b of n bits, to draw lots and to transmit to the entity (1) to authenticate a binary vector a of n bits, to receive from the entity (1) to authenticate a response vector z of m bits, to calculate the Hamming weight of an error vector e = z ® aX ® bY, and accepting authentication if the Hamming weights of the error vectors e satisfy a comparison relation to a parameter (T, t) function of a predetermined probability η.