Cryptographic system
Abstract
This record has no abstract on file.
Term
Projected expiry 12 May 2029.
- Priority
- Filed
- Granted
- Today
- Projected expiry
14 claims: 6 independent, 8 dependent
- 1複数の平文ワードを暗号化または復号化するための暗号化または復号化システムを作成する、コンピュータ実装された方法であって、 誤り位置関連付け手段によって、 各平文ワード(202)を、誤りベクトルの誤り位置(212)の各集合(207)に関連付ける段階(104,207)と、 前記複数の平文ワードの各々の平文ワードについて、 誤りベクトル関連付け手段によって、 前記平文ワード(202)の各値を、前記平文ワード(202)に関連付けられた誤り位置の前記集合(207)外の位置では同一の値を有する各誤りベクトルに関連付ける段階(106)と 前記平文ワードの各々の前記値それぞれについて、前記平文ワードが前記値をとるときに、前記平文ワードの暗号化された形が前記値に関連付けられた前記誤りベクトルに基づく暗号文ワードであるように 、構成手段によって、 システムを構成する段階と、を有することを特徴とする方法。
- 2シンドローム表現関連付け手段により、 前記複数の平文ワードの各々の平文ワードについて、前記平文ワード(202)の前記各値を、誤り訂正符号に従って、前記各誤りベクトルの各シンドローム(218)の各表現に関連付ける段階(108)をさらに有し、 前記システムを構成する段階が、前記平文ワードの各々の前記値それぞれについて、前記平文ワードが前記値をとるときに、前記平文ワードの前記暗号化された形が、前記値に関連付けられた前記誤りベクトルの前記各シンドロームの前記表現に基づく暗号文ワードであるように構成するものである、ことを特徴とする請求項1に記載の方法。
- 3平文ワードの前記各値に関連付けられた前記各表現が、前記平文ワードの前記各値が広がる線形空間の次元よりも大きい次元を有する線形空間に広がることを特徴とする請求項1に記載の方法。
- 4誤り位置の前記各集合が相互に分離されていることを特徴とする請求項1に記載の方法。
- 5前記各誤りベクトル値が、最大で1つの非ゼロの位置(212)を有することを特徴とする請求項1に記載の方法。
- 6平文ワードの前記各値に関連付けられた前記各誤りベクトル値が相互に一意性を有することを特徴とする請求項1に記載の方法。
- 7提供手段によって、 前記平文ワードの前記各値に関連付けられた前記各表現を指定する参照テーブルを提供する段階(108)をさらに有することを特徴とする請求項1に記載の方法。
- 8複数の平文ワードを暗号化するための暗号化システムを作成するシステムであって、 各平文ワード(202)を、誤りベクトルの誤り位置(212)の各集合(207)に関連付けるための手段と、 前記複数の平文ワードの各々の平文ワードについて、前記平文ワード(202)の各値を、前記平文ワード(202)に関連付けられた誤り位置の前記集合(207)外の位置では同一の値を有する各誤りベクトルに関連付けるための手段であって、前記平文ワードの各々の前記値それぞれについて、前記平文ワードが前記値をとるときに、前記平文ワードの暗号化された形が前記値に関連付けられた前記誤りベクトルに基づく暗号文ワードであるようにシステムを構成する手段とを具備することを特徴とするシステム。
- 9複数の平文ワード(302)を暗号化するためのシステムであって、 各平文ワード(302)に対応する複数の各参照テーブル(304)であり、平文ワードに対応する参照テーブルが、当該平文ワードの各値を、各誤りベクトルに基づいて各シンドロームの各表現に関連付けるように構成され、平文ワードの各値に関連付けられた前記各誤りベクトルが、当該平文ワードに関連付けられた誤り位置の集合外の位置では同一の値を有する、参照テーブル(304)と、 前記各平文ワード(302)の前記各値に関連付けられた前記表現を、暗号文ブロック(308)へと結合するための暗号文生成器(306)とを具備することを特徴とするシステム。
- 10前記暗号文生成器(306)が、XORにより表現を結合するためのXORユニットを具備することを特徴とする請求項9に記載のシステム。
- 11複数の平文ワード値を暗号化するコンピュータ実装される方法であって、 参照テーブル処理手段によって、 各平文ワード(302)に対応する複数の各参照テーブル(304)において、前記各平文ワード(302)の各値に関連付けられた各シンドロームの各表現(304)を調べる段階であって、平文ワードに対応する参照テーブルが、当該平文ワードの各値を、各誤りベクトルに基づいて、各シンドロームの各表現に関連付けるように構成され、かつ平文ワードの各値に関連付けられた前記各誤りベクトルが、前記平文ワードに関連付けられた誤り位置の集合外の位置では同一の値を有する、段階と、 結合手段によって、 前記各平文ワード(302)の前記各値に関連付けられた前記表現を、暗号文ブロック(308)へと結合する段階とを有することを特徴とする方法。
- 12暗号文ブロックを復号するためのシステムであって、 誤り訂正符号に従って、前記暗号文ブロックからシンドロームに対応する誤りベクトル(210)を復元するための復号器と、 各平文ワード(202)に関連付けられた(208)前記誤りベクトルの誤り位置(212)で前記誤りベクトルの少なくとも1つの値から前記各平文ワード(202)の値を調べるための参照テーブルとを具備することを特徴とするシステム。
- 13暗号文ブロックを復号するコンピュータ実装される方法であって、 復元手段によって、 誤り訂正符号に従って、前記暗号文ブロックからシンドロームに対応する誤りベクトル(210)を復元する段階と、 調査処理手段によって、 各平文ワード(202)に関連付けられた(208)前記誤りベクトルの誤り位置(212)で前記誤りベクトルの値から前記各平文ワード(202)の値を調べる段階とを有することを特徴とする方法。
- 14プロセッサに、請求項1、11、または13に記載の方法を実施させる機械読み取り可能な命令からなるコンピュータプログラム。
Independent claims14
67 paragraphs, as filed
The present invention relates to cryptography. The present invention also relates to a method of creating an encryption or decryption system. The present invention also relates to systems and methods for performing encryption and decryption.
Public-key cryptography (also called asymmetric cryptography) is a cipher that has two different keys, one for encryption and the other for decryption. The encryption key is public and anyone can use it, but the decryption key is kept secret. There are only a few known public key cryptosystems. Known public key cryptosystems include RSA, elliptic curves, McEliece, and HFE (Hidden Field Equations). Compared to symmetric cryptography, public key cryptography is relatively costly, for example, in terms of computational power, hardware cost, and / or computational time. For this reason, current public key cryptography is not useful for applications that use inexpensive and resource-limited devices such as sensors.
Niederreiter presented a variant of the McEliece cryptosystem based on linear error correction codes. In Niederreiter's cryptographic scheme, plaintext messages are interpreted as error vectors, and ciphertext messages are based on the error vector syndrome. Therefore, according to the particular error correction code used, the encryption will include the calculation of the error vector syndrome, and the decryption will include the calculation of the error vector from the syndrome. Due to the nature associated with the error correction code, the error vector can have only a limited number of ones. Therefore, a plaintext message that may have an arbitrary number of 1s is first transformed into an error vector that has a limited number of 1s. This conversion step can require a significant amount of computational time.
<p><nplcit num="1"><text>Henk CA van Tilborg (ed.), "Encyclopedia of Cryptography and Security", Springer 2005, ISBN 978-0-387-23473-1</text></nplcit></p>
<p> It would be beneficial to implement an improved method of creating an encryption or decryption system. To better address this problem, in the first aspect of the invention, one step of associating each plaintext word with each set of error positions in the error vector and at least one value of each plaintext word being one of the plaintext words. A method is presented that has a step associated with each error vector having the same value at a position outside the set of associated error positions.</p><p> These associations allow for efficient encryption or decryption. Each plaintext word is associated with each set of error positions, and the error vector associated with each possible value of the plaintext word has the same value outside the position in each set, so one or more position-related values. It is possible to determine the value of the position of the error vector simply by examining the plaintext word. In other words, it is not necessary to consider the value of this particular plaintext word in order to determine the value of the position of the error vector that is not related to that particular plaintext word. This reduces the complexity of the pretreatment stage. Moreover, in the decoder, the association can be used to more efficiently retrieve the plaintext word from the error vector. This aspect of the invention allows for efficient conversion from plaintext to quantities related to error vectors, that such conversion evaluates individual plaintext words, and individual of these. This is because it can be implemented by combining the error vectors obtained from the plaintext words of.</p><p> Each plaintext word can correspond to a series of words, for example, a series of words in a plaintext block. There may be a fixed or predetermined relationship between the continuous positions of the plaintext words in the plaintext block and each set of associated error positions. Each value of a plaintext word is each value that such a plaintext word can take, for example, a range of values that can be composed of bits of the plaintext word. The various values of the plaintext word are associated with the various error vectors by varying the value of the error vector at the position associated with each plaintext word. The position of the error vector outside the set of error positions can be held at a fixed value for all error vectors associated with the plaintext word. In principle, such fixed values can be different for different positions outside the set of erroneous positions. In an exemplary embodiment, the value of the error vector is zero outside the relevant set of error positions.</p><p> In embodiments, each value of a plaintext word is associated with each representation of each syndrome of each error vector according to an error correction code. This direct association between the plaintext word and the representation of the syndrome creates a very efficient cryptographic system, because it eliminates the need to calculate the error vector itself.</p><p> In embodiments, each representation associated with each value of a plaintext word extends into a linear space having at least as large a dimension as, or preferably larger than, the dimension of the linear space in which each value of the plaintext word extends. This makes it more difficult to attack the resulting cryptosystem in certain applications, such as white-box cryptography.</p><p> In the embodiment, the sets of error positions are separated from each other. Thus, in order to determine the value of the error vector position, it is only necessary to consider a single plaintext word. This makes it possible to provide an efficient encryption and / or decryption system.</p><p> The various associations that have been established can be provided to the cryptosystem by one or more reference tables, whereby the encryption performs multiple reference operations and combines the results of the reference operations. It is done by doing.</p><p> Another aspect of the present invention provides a system for encrypting a plurality of plaintext words, wherein the system is a plurality of reference tables corresponding to each plaintext word, and the reference table corresponding to the plaintext word is a reference table. A reference table that is configured to associate each value of the plaintext word with each representation of each syndrome based on each error vector, and each error vector is zero outside the error position of the set associated with the plaintext word. And a ciphertext generator for combining the representation associated with each value of each plaintext word into a ciphertext block.</p><p> This system for encryption is relatively efficient because it converts plaintext into the appropriate ciphertext using the associations stored by the lookup table.</p><p> Other aspects of the invention are defined in the independent claims. Dependent claims define advantageous embodiments.</p><p> These and other aspects of the invention will be further clarified and described with reference to the drawings.</p>
<figref num="1">It is a figure which shows the processing step of the method of creating a cryptosystem.</figref><figref num="2">FIG. 5 shows some associations used to perform encryption and decryption.</figref><figref num="3">It is a figure which shows the system for encrypting data.</figref><figref num="4">It is a figure which shows the hardware architecture.</figref>
Hereinafter, embodiments based on the Niederreiter encryption scheme will be described. However, this is not intended to be limiting. A variant of Niederreiter's cryptographic scheme can also be used like any other cryptographic scheme. The part to be encrypted becomes efficient in terms of resources used and computational time. Further, the decoding can be performed by a relatively simple method.
Niederreiter presented a variant of the McEliece cryptosystem based on linear error correction codes. The idea behind Niederreiter's cryptographic scheme is to interpret plaintext messages as error vectors. The ciphertext is based on the syndrome associated with this error vector. More precisely, if e is an error vector corresponding to a plaintext message, then the encryption is a matrix H.<sup>*</sup>Matrix multiplication against H<sup>*</sup>It can be carried out by e. Where the matrix H<sup>*</sup>Is H<sup>*</sup>Given by = SHQ, in the equation S is a randomly selected reversible matrix, H is a parity check matrix for the linear code under consideration, and Q is a randomly selected ordinal matrix. .. Decoding involves reversing S and Q and performing an error-correcting code decoding process, i.e. deriving error e from its syndrome H. If the sign is t-error correction, this procedure only guarantees that it will work if the Hamming weight of the error vector e (ie, the number of 1s in e) is at most t. Therefore, the encryption scheme can be extended with a preprocessing step in which any plaintext message is mapped to an error vector with a Hamming weight of up to t. Niederreiter's encryption scheme does not specify this mapping. For example, when using product codes, it may be possible to use error vectors with errors greater than t. However, in such cases, it would be necessary to ensure that only error vectors that can be reconstructed based on that syndrome are used.
In Henk CA van Tilborg (eds.), "Encyclopedia of Cryptography and Security" (Non-Patent Document 1), in the section entitled "Niederreiter encryption scheme", the word of weight t and the interval
<maths num="1"><img file="JP5539331B2_D0001.tif" /></maths>
It is mentioned that there is a one-to-one correspondence with the length n having an integer in. Accurately calculating this correspondence is relatively costly (a quadratic expression of block length n). There is also an approximate solution with a cost proportional to the block length n.
FIG. 1 shows an embodiment of a process of creating an encryption system, that is, an encryption device. Such cryptographic systems can include hardware components, such as chips with electronic circuits capable of performing cryptographic processing. Cryptographic systems can also be implemented partially or completely in software. The process helps make the cryptographic device more efficient. In addition, the processes disclosed herein provide an efficient way to create cryptographic systems. The process is also described below with reference to FIG. FIG. 2 shows multiple plaintext words 206, error vectors 210, and multiple syndrome values 220, as well as an association between plaintext words and error vector positions (207), and an association between error vector values and syndromes (207). 214) is shown graphically.
The process can create a complete cryptographic system. However, it can also simply generate a set of parameters that can be used with existing parameterized cryptographic systems. Such parameters can contain cryptographic keys applied by the cryptographic system, or values derived from such keys, which are used to perform the processing steps of the cryptographic process. Used in cryptosystems.
In step 102, an error correction code is established. For example, such error correction codes, including known BCH codes, or linear codes such as known product codes, were originally developed to correct errors in data transmitted over the transmit channel. Error correction codes usually allow a vector, called a syndrome, to be derived from a received data block that may contain errors. There is usually a one-to-one relationship between the error that occurs and the syndrome. Known error correction schemes in the art can be applied to syndrome-based error detection. However, finding these errors based on the syndrome is not easy without knowledge of the parameters of the error correction code (eg, parity check matrix, etc.). Due to this property, it is possible to encrypt data in the form of error vector syndromes. The plaintext to error vector conversion can be parameterized and these parameters can form part of the cryptographic key.
In step 104, each plaintext word 202, 204 is associated with each set of error positions in the error vector. Each plaintext word is, for example, some words contained in a plaintext block to be encrypted. For example, a plaintext block contains a plurality of plaintext words 206. These plaintext words can be arranged consecutively. Each plaintext word 202, 204 in the plurality of plaintext words 206 can be associated with each set of error positions according to their position in the sequence. In FIG. 2, the plaintext word 202 is associated with a set of error positions 207, which is graphically indicated by a dashed arrow pointing to the position of the error vector 210 contained in that set. For example, the plaintext word 202 is associated with the position indicated by arrow 207. For example, arrow 208 points to position 212 of error vector 210. These positions can be randomly selected. However, it is preferred that the two plaintext words 202, 204 are not associated with the same error position 212. Therefore, it is preferable that the set of error positions is separated. This simplifies the encryption and / or decryption process.
In step 106, each value of the plaintext word, for example plaintext word 202, is associated with each error vector value. The position of each error vector value outside the set of error positions 207 associated with plaintext word 202 is zero. A one-to-one mapping between plaintext word values and error vector values is preferably established at this step by association. For example, the number of false positions contained in a set is at least one less than the number of possible values for plaintext word 202. In this case, one plaintext word value can be associated with an error value of zero, and the other plaintext word values are uniquely defined errors containing zeros at all positions except one position 212 in set 207. Can be mapped to vector values. Therefore, various plaintext word values are mapped to 1 at various positions contained in set 207. However, other configurations are possible. For example, it is possible to set it to 1 at a maximum of two positions contained in the set 207. For non-binary codes, the error position can take a value different from 0 and 1 depending on the plaintext word value.
In an alternative embodiment, in step 106, each error vector value outside the set of error positions 207 is not set to all zeros. For example, each error vector position outside the set of error positions 207 is assigned to a single value. Error vector positions outside the set 207 can get this value for all plaintext word values that a particular plaintext word can take. For example, all positions outside the set 207 are set to 1. Alternatively, some positions outside the set 207 can be set to 1 and other positions outside the set 207 can be set to 0.
Step 106 can be repeated for each of the plaintext words in the plurality of words. For each plaintext word 202, 204, each set 207 of error vector positions 212 is used. The association can be randomly selected to increase the security of the cipher. Alternatively, a given scheme can be used for the association.
This process now provides a mapping of the value of plaintext block 206 to the value of error vector 210. When processing a specific plaintext block containing multiple plaintext word values, the cryptosystem finds the error vector values associated with each plaintext word and simply uses these error vector values to represent the complete plaintext block. Can be added together to obtain one error vector value. Plaintext words are associated with various error vector positions, so adding error vectors does not lose any information. Instead of using addition, combine error vectors into a single error vector, with the constraint that the error vector values associated with each plaintext word can be restored from a single combined error vector. You can also use the method of. For binary error vectors, the addition should be modulo 2, which corresponds to an efficient XOR operation.
In step 108, the process can include associating each value of the plaintext word 202 with each syndrome 218 of each error vector according to the error correction code. More specifically, each value is associated with each representation of each syndrome. The error vector syndrome is derived from the sign used.
This step can include selecting a random linear reversible operator. This random linear operator can be applied to the syndrome to get a representation of the syndrome. Such a random linear reversible operator further improves cryptographic security. It is preferable to apply the same operator to all syndromes of all plaintext words. This allows the decryptor to apply the inverse operator to the received ciphertext in order to obtain the syndrome corresponding to the encrypted message.
The encryption system uses associations to find the syndrome, rather than calculating and / or adding the error vector, adding the syndrome, getting the added syndrome, and adding a random reversible linear operator. It can be applied to the syndrome. This avoids the need to explicitly establish an error vector, thereby reducing the amount of storage space required to store the error vector. Cryptographic systems preferably (eg, after applying a linear reversible operator) have a direct association between the associated representation of the syndrome and the plaintext word. Thus, linear reversible operators do not need to be applied in cryptographic systems, thereby reducing computational complexity. In addition, the size of the key data is also reduced. Alternatively or in addition to adding the syndrome, other methods of binding the syndrome may also be contemplated.
For example, at step 110, the cryptosystem may include a lookup table that lists the representations of the syndrome associated with the various values of the plaintext word. For example, a separate reference table is provided for each plaintext word in the plaintext block.
Each representation associated with each value of the plaintext word preferably extends into a linear space having a dimension greater than the dimension of the linear space in which each value of the plaintext word extends. For example, if the association is stored in a separate reference table for each plaintext word, then when viewing such a reference table as a two-progress column with rows for each plaintext word value, the order of the matrix is the plaintext word. It is preferably larger than the bit size of. Each representation associated with each value of a plaintext word preferably extends to a linear space with a higher rank, such as a rank equal to or close to the dimension of the representation. Such a high rank can be achieved, for example, by experimental trials.
It is preferred that the sets of erroneous positions be separated from each other. Thus, the individual positions of the error vector are based on a single plaintext word, which makes the determination of the error vector and syndrome more efficient.
It is possible to reserve different error vector positions for different plaintext word values. In such cases, each error vector associated with each plaintext word value has at most one nonzero position 212. This makes the decoding system more efficient because the non-zero position of the error vector sufficiently determines the value of the plaintext word.
Each error vector value associated with each value of a plaintext word can be unique to each other. This allows the ciphertext to be decrypted without ambiguity.
FIG. 3 shows a system for encrypting a plurality of plaintext words 202. Such a system can be provided, for example, by the process described above. The system includes a plurality of reference tables 304 corresponding to each plaintext word, and the reference table corresponding to the plaintext word associates each value of the plaintext word with each representation of each syndrome based on each error vector value. The position of each error vector value outside the set of error positions associated with the plaintext word is zero. The system also includes a ciphertext generator 306 for combining expressions associated with multiple plaintext words into ciphertext block 308. The ciphertext generator 306 can be provided with an XOR unit for combining the representation 304 by XOR. Such a system will be described in more detail later. Other methods of combining are also possible, for example vector addition.
The method of encrypting multiple plaintext words involves examining each representation of each syndrome associated with each value of each plaintext word 302 in each of the plurality of reference tables 304 corresponding to each plaintext word 302. The corresponding reference table is configured to associate each value of its plaintext word with each representation of each syndrome based on each error vector value, and each error vector is a set of error positions associated with the plaintext word. It is zero outside. The method further comprises combining expressions associated with multiple plaintext words into ciphertext block 308.
The method of decrypting the ciphertext block 308 includes recovering the error vector corresponding to the syndrome from the ciphertext block according to a linear error correction code. The method further comprises examining each plaintext word value corresponding to each nonzero position of the error vector in the reference table. Such a relatively simple decoding system using a reference table is possible when the position of the error vector is directly linked to a single plaintext word.
In one embodiment, a reference table is provided for examining the value of each plaintext word 202 from at least one value of the error vector at the error position 212 of the (208) error vector associated with each plaintext word 202.
The system for decrypting the ciphertext block 308 includes a decoder for recovering the error vector corresponding to the syndrome from the ciphertext block according to the error correction code. The error correction code can be a linear error correction code. Such a decoder can be based on a known decoding algorithm, such as a decoding algorithm for a known BCH code. The system can further include a reference table for examining each plaintext word value corresponding to each nonzero bit position of the error vector.
In the following, another embodiment that maps plaintext to an error vector is disclosed. Further disclosed are embodiments in which this mapping is used to achieve efficient implementation of encryption. First, an embodiment of performing encryption is disclosed. The mapping is then disclosed in more detail. In the following, C is, for example, a fixed binary linear t-error correction code of length n, and H is an r × n parity check matrix for C, i.e. C is Hc. It consists of an n-bit word c with = 0.
FIG. 3 shows the encryption system described above. The following describes more selective details of the system for encryption. Encryption is t reference tables T<sub>0</sub>, T<sub>1</sub>, ..., T<sub>t-1</sub>Based on the aggregate of. The plaintext block P consisting of N = t · m bits is t word P of each m bit.<sub>0</sub>, P<sub>1</sub>, ..., P<sub>t-1</sub>It is divided into. For the value i of 0 i t-1, the word P<sub>i</sub>Is table T<sub>i</sub>In line r<sub>i</sub>And the ciphertext C has t rows r<sub>0</sub>, r<sub>1</sub>, ..., r<sub>t-1</sub>It is obtained by performing an exclusive OR operation on the.
The following discloses a process that allows the plaintext to error vector mapping to be established in the Niederreiter cryptographic scheme so that the above cryptosystems can be obtained using reference tables.
In the encryption system of Figure 3, t words P, each with m bits.<sub>0</sub>, P<sub>1</sub>, ..., P<sub>t-1</sub>In the case of a plaintext block P consisting of N = t · m bits divided into, the length n = t · 2<sup>m</sup>An error vector of -1 is used. Let V = {0,1, ..., n} be the set of error vector positions (or components) 1, ..., n and the value 0.
First, V, each size 2<sup>m</sup>T separated sets V<sub>0</sub>, V<sub>1</sub>, ..., V<sub>t-1</sub>You can choose to divide into. For example, the division is randomly selected for added security.
Second, for i = 0, ..., t-1, v<sub>i</sub>From the mbit word to V<sub>i</sub>Make a map to. Mapping v<sub>i</sub>Can also be randomly selected for safety reasons. Thus, the plaintext word P<sub>i</sub>Is the number v<sub>i</sub>(P<sub>i</sub>) V<sub>i</sub>Corresponds to. This number v<sub>i</sub>(P<sub>i</sub>) Is used as the position of the error vector or as a component.
This makes it possible to define the error vector e (P) as an n-bit vector with positions or components represented by 1 to n, in which case all positions are in position v.<sub>i</sub>(P<sub>i</sub>), However, it is set to 0 except for i = 0, ..., t-1. The latter position is set to 1. v<sub>i</sub>(P<sub>i</sub>If) is equal to 0, do not add the nonzero component to the error vector. Thus, e (P) has a Hamming weight t or t-1. Hamming weight is some v<sub>i</sub>(P<sub>i</sub>) Is equal to 0, then t-1.
The error vector e (P) can be encrypted according to the Niederreiter scheme in a manner known in the art by applying SHQ to the error vector e (P), where Q is a binary ordinal matrix. And S is a reversible matrix. But the random division V<sub>0</sub>, V<sub>1</sub>, ..., V<sub>t-1</sub>And random mapping v<sub>i</sub>Because of, the binary ordinal matrix Q can be excluded, or the partitioning and mapping can be modified to absorb Q. Therefore, e (P) is encrypted by applying the matrix SH to the error vector e (P), thereby calculating SHe (P), where S is a randomly selected linear matrix.
Returning to the encryption system in Figure 3, i = 0, ..., t-1, and any m-bit value x (where the value x is P).<sub>i</sub>Reference table T for (representing possible values of)<sub>i</sub>The entry for (x) is v<sub>i</sub>Filled with SH columns indexed by (x). In other words, SH v<sub>i</sub>The (x) th column is T<sub>i</sub>Used as the value of (x). v<sub>i</sub>T for (x) = 0<sub>i</sub>The value of (x) is set to 0. Using these values for the reference table in Figure 3, the encryption system can generate the desired ciphertext. The encryption system thus obtained is very efficient because its main operations are table reference and XOR operation. The mapping of any plaintext to an error vector in this embodiment is based on a random division of n + 1 positions into t sets and a random numbering of positions inside each of these sets. There is.
In the following, specific embodiments will be disclosed. This particular embodiment uses a particular number, such as for block size, but these particular numbers are not limited. For plaintext, a 128-bit block size and an 8-bit word size are used. Encryption uses a 128/8 = 16 lookup table, so one lookup table is used for each word. These numbers are merely exemplary, and block ciphers can be defined for other numbers as well. The block size of ciphertext is larger than 128 bits for plaintext, that is, 192 bits. Therefore, public key cryptography is subject to a 50% size overhead. For the variables used in the description with respect to FIG. 3, the above numbers are specified by the plaintext block length M = 128, the plaintext word size m = 8, and the number of plaintext words t = 16 in the plaintext block.
The codeword length n, which corresponds to the length of the error vector, is 16.2.<sup>8</sup>-1=2<sup>12</sup>-1, but it is an 8-bit plaintext word with an error vector of 2<sup>8</sup>2 of the error vector except for one 8-bit plaintext word that is converted to position -1<sup>8</sup>This is because it is converted to the position of.
The error vector can contain one error for each of t = 16 words, so as is known in the art, a length of 2 that can correct 16 errors.<sup>12</sup>Error correction code of -1, eg length 2<sup>12</sup>The BCH code of -1 is used. It is known in the art that this BCH code parity check matrix can have 192 rows. That is, the syndrome contains 192 bits. Therefore, 128-bit plaintext is mapped to a 192-bit syndrome, which is the basis of the ciphertext.
The secret part of the code is 2<sup>8</sup>×2<sup>4</sup>From 2<sup>12</sup>It can contain a randomly selected 12-bit S-box U that defines the bijective function to. v<sub>i</sub>The value of (x) is given by the number from {0,1, ..., n} represented by the binary value U (x, i), and also V<sub>i</sub>Is the number v for every byte x<sub>i</sub>Includes (x). We noticed that U absorbs the ordinal matrix Q in Niederreiter's cryptographic scheme. By not limiting U to be an ordinal matrix, the embodiment can gain security.
The secret part of the cipher further contains a randomly selected 192 × 192 bit reversible matrix S.
The secret part of the cipher is further given by 16-error correction BCH code 192 × (2)<sup>12</sup>-1) Bit parity check matrix H can be included. For example, an abbreviated BCH code can be used.
Expansion function E has 1 at position x and 0 at other positions when x> 0 for a 12-bit input x 2<sup>12</sup>Returns a -1 bit output vector and a zero vector if x = 0 2<sup>12</sup>From
<maths num="2"><img file="JP5539331B2_D0002.tif" /></maths>
Let it be a function of. The public part of the cipher is in table T<sub>0</sub>, T<sub>1</sub>, ..., T<sub>15</sub>Can contain a collection of, in which case T<sub>i</sub>Defines the following 8-bit to 192-bit functions.
<maths num="3"><img file="JP5539331B2_D0003.tif" /></maths>
Plaintext block P = (P<sub>0</sub>, P<sub>1</sub>, ..., P<sub>15</sub>) Ciphertext block C
<maths num="4"><img file="JP5539331B2_D0004.tif" /></maths>
Obtained by
This encryption is publicly available information (reference table T).<sub>i</sub>) Can be used. Therefore, using this embodiment, it is only necessary to make the reference table available to the encryption device. There is no need to reveal the matrix SHQ.
Decryption can only be done if the confidential information is known. It works as follows. First, S<sup>-1</sup>Is applied. This is the value
<maths num="5"><img file="JP5539331B2_D0005.tif" /></maths>
give.
Value by BCH decoding
<maths num="6"><img file="JP5539331B2_D0006.tif" /></maths>
Is derived. This value is P<sub>i</sub>One of is U (P<sub>i</sub>Includes 15 or 16 1s, depending on whether i) = 0 is satisfied. U for each position of this value, including 1<sup>-1</sup>Is applied. From this, plaintext P<sub>0</sub>, P<sub>1</sub>, ..., P<sub>15</sub>Can be derived.
The techniques disclosed herein are advantageous because they can be applied in systems where public key cryptography is desirable, but in the case of computationally intensive solutions such as RSA due to resource constraints, for example. , Not very suitable.
FIG. 4 shows an exemplary hardware architecture suitable for implementing the systems and methods described herein, at least in part, in software. The software can be stored in memory 406, and software instructions are executed by processor 402. An input 404 and a display 412 can be used to initiate several processes and also provide the possibility of user interaction. Key data, reference table values, plaintext, and / or ciphertext can be communicated, for example, through communication ports 408 and / or removable medium 410. Communication port 408 can provide, for example, a connection to a local area network, the Internet, or a television network. Such connections can be wired or wireless. The removable medium can include a CD or DVD reader and / or a writer. Sensor 414 may be provided to acquire the sensed data. The sensor 414 can include, for example, a digital fingerprint sensor or an iris scanner. Alternatively, the sensor 414 can also include a medical scanning device such as an X-ray sensor or an ultrasonic scanner. If the encryption system described herein is implemented in software stored in memory 406, the system may receive multiple reference tables, for example, via communication port 408 or removable medium 410. it can. The system can encrypt data obtained via sensor 414, communication port 408, or removable medium 410. The encrypted data can be stored locally in memory 406 or exported via communication port 408 or removable medium 410. It is also possible to implement methods for software-generated cryptographic systems using hardware architectures. For example, software stored in memory 406 may have multiple reference tables as described above. Generate. Such reference tables can be hard-coded into the encryption system or sent over communication port 408 to a pre-programmed encryption system that can receive such reference tables. You can also.
It will be appreciated that the present invention also extends to computer programs, in particular computer programs on or in a carrier adapted to carry out the present invention. The program may be any form of code intermediate between the source code and the object code, such as source code, object code, partially compiled form, or any form suitable for use in implementing the methods according to the invention. It can be in another form. It will also be appreciated that such programs can have many different architectural designs. For example, the program code that realizes the functions of the method or system according to the present invention can be subdivided into one or more subroutines. Many different methods for distributing functionality within these subroutines will be apparent to those of skill in the art. Subroutines can be stored together in one executable file to form a self-contained program. Such executable files can include computer executable instructions, such as processor instructions, and / or interpreter instructions (eg, Java® interpreter instructions). Alternatively, one or more or all subroutines can be stored in at least one external library file and linked statically or dynamically, such as at runtime. The main program contains at least one call to at least one subroutine. In addition, subroutines can include function calls to each other. Embodiments of a computer program product include computer executable instructions corresponding to each of at least one processing step of the method described above. These instructions can be subdivided into subroutines and / or stored in one or more files that can be statically or dynamically linked. Other embodiments relating to computer program products include at least one means of the system and / or product described above. Includes corresponding computer executable instructions. These instructions can be subdivided into subroutines and / or stored in one or more files that can be statically or dynamically linked.
The carrier of the computer program can be any entity or device that can carry the program. For example, the carrier can include a ROM, such as a CD ROM or semiconductor ROM, or a magnetic recording medium, such as a storage medium such as a floppy (registered trademark) disk or hard disk. Further, the carrier can be a transmittable carrier, such as an electrical or optical signal that can be transported electrically or via an optical cable, or can be transported wirelessly or by other means. When the program is carried out with such a signal, the carrier may consist of such a cable or other device or means. Alternatively, the carrier can be an integrated circuit with a built-in program, and the integrated circuit is adapted to carry out or be used to carry out the relevant method.
The embodiments described above are exemplary of the present invention and are not intended to be limiting, and many alternative embodiments will be made by those skilled in the art without departing from the appended claims. Note that you can design. In the claims, any reference symbol placed between parentheses should not be construed as limiting the scope of the claims. The use of the verb "comprise" and its conjugations does not preclude the existence of elements or steps other than those stated in the claims. The article "one (a or an)" that precedes an element does not preclude the existence of more than one such element. The present invention can be realized by hardware with several distinct elements and by a well-programmed computer. In the device claim, which enumerates several means, some of these means can be implemented by the same element of hardware. The mere fact that a particular measure is described in different dependent terms does not indicate that a combination of these measures cannot be used to make good use of it.
202,204 Plaintext word 206 Multiple plaintext words (plaintext block) 207 Association to a set of error positions 208 Association to error position 210 Error vector 212 Error vector error position (non-zero position) 214,215 Association to syndrome 216,218 Syndrome 220 Multiple Syndrome 302 plaintext word 304 reference table, representation 306 ciphertext generator 308 ciphertext block 402 processor 404 input 406 memory 408 communication port 410 removable medium 412 display 414 sensor
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP06138820A | Cites | Japan |
| JP03192383A | Cites | Japan |
| JP03085923A | Cites | Japan |
| JP2006189607A | Cites | Japan |
| US20060072743A1 | Cites | United States of America |
| US20050117745A1 | Cites | United States of America |
13 members in 7 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 08156522 | European Patent Office (EPO) | A | |
| 08156522 | European Patent Office (EPO) | A | |
| 081565228 | European Patent Office (EPO) | – | |
| 2009051944 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 2009051944 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 200808156522 | – | – | – |
| 2009051944 | – | – | – |
| EP20080156522 | – | – | – |
| WO2009IB51944 | – | – | – |
Members13
| Document | Office | Kind | |
|---|---|---|---|
| CA2736910A1 | Canada | A1 | |
| WO2009141756A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009141756A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20110014211A | Republic of Korea | A | |
| EP2294752A2 | European Patent Office (EPO) | A2 | |
| US2011091033A1 | United States of America | A1 | |
| JP2011521292A | Japan | A | |
| CN102187617A | China | A | |
| US8724802B2 | United States of America | B2 | |
| JP5539331B2This record | Japan | B2 | |
| CN102187617B | China | B | |
| KR101582806B1 | Republic of Korea | B1 | |
| CA2736910C | Canada | C |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313111S111 | S111 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5539331
- Publication, DOCDB
- 5539331
- Publication, EPODOC
- JP5539331B
- Application
- 2011510070
- Application, DOCDB
- 2011510070
- Application, EPODOC
- JP20110510070
Titles2
- Japanese
- 暗号システム
- English
- Cryptographic system
Classification
- CPC, 4
- H04L9/304
- H04L9/30
- H04L2209/12
- G09C1/00
- IPC, 1
- G09C1 00