Cipher system, encryption device, re-encryption key generation device, re-encryption device, and cipher program
8 claims: 3 independent, 5 dependent
- 12つの情報が互いに対応している場合に一方の情報が設定された暗号文を他方の情報が設定された復号鍵により復号可能な暗号方式における代理人再暗号機能を実現する暗号システムであり、 互いに対応する属性情報x,vのうちの一方が設定された暗号文cと、互いに対応する属性情報y,zのうちの一方が設定された暗号文c ~ とを含む暗号文ctを出力する暗号化装置と、 前記属性情報x,vのうちの他方が設定された復号鍵k * を取得し、取得した復号鍵k * を変換情報W 1 で変換した復号鍵k *rk と、前記属性情報y,zのうちの他方が設定された復号鍵k ~*rk と、互いに対応する属性情報x’,v’のうちの一方が設定されて前記変換情報W 1 が暗号化された暗号化変換情報ψ rk とを含む再暗号化鍵rkを出力する再暗号化鍵生成装置と、 互いに対応する追加情報Η,Θのうちの一方が前記暗号文ctに設定された暗号文c renc と、前記追加情報Η,Θのうちの他方が前記再暗号化鍵rkに設定された復号鍵k *renc とを含む再暗号文rctを出力する再暗号化装置とを備えることを特徴とする暗号システム。
- 2前記復号鍵k ~*rk は、前記属性情報y,zのうちの他方が設定された復号鍵k ~* を変換情報W ~ 1 で変換して生成され、 前記暗号化変換情報ψ rk は、前記属性情報x’,v’のうちの一方が設定されて前記変換情報W 1 及び前記変換情報W ~ 1 が暗号化されて生成されたことを特徴とする請求項1に記載の暗号システム。
- 3前記暗号文cは、基底Bにおけるベクトルであり、 前記復号鍵k * は、前記基底Bに対応する基底B * におけるベクトルであり、 前記暗号文c ~ は、前記基底Bを変換情報H^により変換した基底Hにおけるベクトルであり、 前記復号鍵k ~*rk は、前記基底B * を前記変換情報H^により変換した基底H * におけるベクトルであることを特徴とする請求項2に記載の暗号システム。
- 4前記暗号システムは、さらに、 前記属性情報x’,v’のうちの他方の属性情報が設定された復号鍵k * ’を取得し、取得した復号鍵k * ’を用いて前記再暗号文rctを復号する再暗号文復号装置を備えることを特徴とする請求項1から3までのいずれかに記載の暗号システム。
- 5前記暗号化装置は、数1に示す前記暗号文cと、数2に示す前記暗号文c ~ とを含む前記暗号文ctを出力し、 前記再暗号化鍵生成装置は、数3に示す前記復号鍵k * を取得し、数4に示す復号鍵k *rk と、数5に示す前記復号鍵k ~*rk と、前記暗号化変換情報ψ rk とを含む前記再暗号化鍵rkを出力し、 前記再暗号化装置は、数6に示す前記暗号文c renc と、数7に示す前記復号鍵k *renc とを含む前記再暗号文rctを出力することを特徴とする請求項3に記載の暗号システム。
- 6前記暗号化装置は、数8に示す前記暗号文cと、数9に示す前記暗号文c ~ とを含む前記暗号文ctを出力し、 前記再暗号化鍵生成装置は、数10に示す前記復号鍵k * を取得し、数11に示す復号鍵k *rk と、数12に示す前記復号鍵k ~*rk と、前記暗号化変換情報ψ rk とを含む前記再暗号化鍵rkを出力し、 前記再暗号化装置は、数13に示す前記暗号文c renc と、数14に示す前記復号鍵k *renc とを含む前記再暗号文rctを出力することを特徴とする請求項3に記載の暗号システム。
- 72つの情報が互いに対応している場合に一方の情報が設定された暗号文を他方の情報が設定された復号鍵により復号可能な暗号方式における代理人再暗号機能を実現する暗号システムにおける再暗号化鍵生成装置であり、 互いに対応する属性情報x,vのうちの一方が設定された復号鍵k * を取得し、取得した復号鍵k * を変換情報W 1 で変換した復号鍵k *rk と、互いに対応する属性情報y,zのうちの一方が設定された復号鍵k ~*rk と、互いに対応する属性情報x’,v’のうちの一方が設定されて前記変換情報W 1 が暗号化された暗号化変換情報ψ rk とを含む再暗号化鍵rkを出力する再暗号化鍵出力部を備えることを特徴とする再暗号化鍵生成装置。
- 82つの情報が互いに対応している場合に一方の情報が設定された暗号文を他方の情報が設定された復号鍵により復号可能な暗号方式における代理人再暗号機能を実現する暗号システムにおける再暗号化装置であり、 互いに対応する属性情報x,vのうちの一方が設定された暗号文cと、互いに対応する属性情報y,zのうちの一方が設定された暗号文c ~ とを含む暗号文ctを受信する暗号文受信部と、 前記属性情報x,vのうちの他方が設定された復号鍵k * を変換情報W 1 で変換した復号鍵k *rk と、前記属性情報y,zのうちの他方が設定された復号鍵k ~*rk と、互いに対応する属性情報x’,v’のうちの一方が設定されて前記変換情報W 1 が暗号化された暗号化変換情報ψ rk とを含む再暗号化鍵rkを受信する再暗号化鍵受信部と、 互いに対応する追加情報Η,Θのうちの一方が前記暗号文ctに設定された暗号文c renc と、前記追加情報Η,Θのうちの他方が前記再暗号化鍵rkに設定された復号鍵k *renc とを含む再暗号文rctを出力する再暗号分出力部とを備えることを特徴とする再暗号化装置。
Independent claims8
264 paragraphs, as filed
The present invention relates to a Functional Proxy Re-Encryption (FPRE) method in functional cryptography. In particular, the present invention relates to an FPR (Functional Conditional Proxy Re-Encryption, FCPRE) method in which conditions for re-encryption can be specified.
Proxy Re-Encryption (PRE) is a system that delegates the authority to decrypt a ciphertext to another person without decrypting the ciphertext. Non-Patent Document 1 describes a PRE (Identity-Based PRE, IBPRE) method in ID-based cryptography. Non-Patent Document 2 describes a PRE (Attribute-Based PRE, ABPRE) method in attribute-based cryptography. In the PRE method described in Non-Patent Document 2, only the attribute consisting of logical product and negation can be specified in the ciphertext.
Non-Patent Document 3 describes a conditional proxy re-encryption (CPRE) method that can specify conditions for re-encryption.
Patent Document 1 describes a functional encryption (FE) method. Non-Patent Document 4 describes the FPR method.
<p num="0005"><patcit num="1"><text>Japanese Unexamined Patent Publication No. 2012-133214</text></patcit></p>
<p num="0006"><nplcit num="1"><text>M.Green, and G. Ateniese, Identity-Based Proxy Re-encryption. In Applied Cryptography and Network Security. Volume 4521 of LNCS, pp 288-306, 2007.</text></nplcit><nplcit num="2"><text>Xiaohui Liang, Zhenfu Cao, Huang Lin, Jun Shao. Attribute based proxy re-encryption with delegating capabilities. ASIACCS 2009 pp.276-286.</text></nplcit><nplcit num="3"><text>J.Weng, Y.Yang Q.Tang, RHDeng, and F.Bao, Efficient Conditional Proxy Re-Encryption with Chosen-Ciphertext Security in ISC2009.</text></nplcit><nplcit num="4"><text>Yutaka kawai and Katuyuki Takashima, Fully-Anonymous Functional Proxy-Re-Encryption. Cryptology ePrint Archive: Report 2013/318</text></nplcit><nplcit num="5"><text>Okamoto, T Takashima, K .: Decentralized Attribute-Based Signatures.ePrint http://eprint.iacr.org/2011/701</text></nplcit><nplcit num="6"><text>Okamoto, T Takashima, K .: Fully Secure Unbounded Inner-Product and Attribute-Based Encryption.ePrint http://eprint.iacr.org/2012/671</text></nplcit><nplcit num="7"><text>Okamoto, T., Takashima, K .: Achieving Short Ciphertexts or Short Secret-Keys for Adaptively Secure General Inner-Product Encryption. CANS 2011, LNCS, vol. 7092, pp. 138-159 Springer Heidelberg (2011).</text></nplcit></p>
<p num="0007"> Since the CPRE method described in Non-Patent Document 3 is not a method in functional encryption, there are restrictions on the specification of the decryptor and the specification of the re-encryption conditions, and it is not possible to flexibly deal with it. The FPR method described in Non-Patent Document 4 can be re-encrypted for all ciphertexts that can be decrypted by the recipient by using a re-encryption key created by the recipient, and the recipient can re-encrypt. It was not possible to specify the ciphertext to be converted. An object of the present invention is to make it possible to flexibly specify the conditions of a ciphertext that can be re-encrypted when a re-encryption key is generated.</p>
<p num="0008"> The cryptosystem according to the present invention is It is a cryptographic system that realizes an agent re-encryption function in a cryptographic method in which a ciphertext in which one piece of information is set can be decrypted by a decryption key in which the other information is set when two pieces of information correspond to each other. A ciphertext c in which one of the attribute information x and v corresponding to each other is set, and a ciphertext c in which one of the attribute information y and z corresponding to each other is set.<sup>~</sup>An encryption device that outputs a ciphertext ct including and Decryption key k in which the other of the attribute information x and v is set<sup>*</sup>And the obtained decryption key k<sup>*</sup>Conversion information W<sub>1,t</sub>Decryption key converted in<sup>* rk</sup>And the decryption key k in which the other of the attribute information y and z is set.<sup>~ * rk</sup>And one of the attribute information x', v'corresponding to each other is set, and the conversion information W<sub>1,t</sub>Cryptographic conversion information ψ<sup>rk</sup>A re-encryption key generator that outputs a re-encryption key rk including and Ciphertext c in which one of the additional information Η and Θ corresponding to each other is set in the ciphertext ct.<sup>renc</sup>And the decryption key k in which the other of the additional information Η, Θ is set in the re-encryption key rk.<sup>* renc</sup>With a re-encryption device that outputs a re-ciphertext rct including It is characterized by having.</p>
<p num="0009"> In the encryption system according to the present invention, the encryption device sets not only the decryption condition of the ciphertext ct (the attribute information of one of the attribute information x and v) but also the condition that the ciphertext ct can be re-encrypted. (Attribute information of one of attribute information y and z) can be set to generate the ciphertext ct. Further, the re-encryption key generator not only decrypts the re-encryption statement rct (attribute information of one of the attribute information x', v'), but also re-encrypts the condition (attribute information y, z). The other attribute information of) can be set to generate the re-encryption key rk. In addition, there are no restrictions on the attribute information to be set, and decryption conditions and re-encryption conditions can be flexibly specified.</p>
<figref num="1">Explanatory diagram of the matrix M ^.</figref><figref num="2">Matrix M<sub>δ</sub>Explanatory drawing.</figref><figref num="3">s<sub>0</sub>Explanatory drawing.</figref><figref num="4">s<sup> T</sup>Explanatory drawing.</figref><figref num="5">Configuration diagram of the cryptographic processing system 10 that executes the CP-FCPRE method.</figref><figref num="6">The functional block diagram which shows the function of the key generator 100.</figref><figref num="7">The functional block diagram which shows the function of the encryption apparatus 200.</figref><figref num="8">The functional block diagram which shows the function of the decoding apparatus 300.</figref><figref num="9">The functional block diagram which shows the function of the re-encryption device 400.</figref><figref num="10">The functional block diagram which shows the function of the reciphertext decryption apparatus 500.</figref><figref num="11">A flowchart showing the processing of the Setup algorithm.</figref><figref num="12">A flowchart showing the processing of the KG algorithm.</figref><figref num="13">A flowchart showing the processing of the Enc algorithm.</figref><figref num="14">A flowchart showing the processing of the RKG algorithm.</figref><figref num="15">A flowchart showing the processing of the REnc algorithm.</figref><figref num="16">A flowchart showing the processing of the Dec1 algorithm.</figref><figref num="17">A flowchart showing the processing of the Dec2 algorithm.</figref><figref num="18">Configuration diagram of the cryptographic processing system 10 that executes the KP-FCPRE method.</figref><figref num="19">The functional block diagram which shows the function of the key generator 100.</figref><figref num="20">The functional block diagram which shows the function of the encryption apparatus 200.</figref><figref num="21">The functional block diagram which shows the function of the decoding apparatus 300.</figref><figref num="22">The functional block diagram which shows the function of the re-encryption device 400.</figref><figref num="23">The functional block diagram which shows the function of the reciphertext decryption apparatus 500.</figref><figref num="24">A flowchart showing the processing of the KG algorithm.</figref><figref num="25">A flowchart showing the processing of the Enc algorithm.</figref><figref num="26">A flowchart showing the processing of the RKG algorithm.</figref><figref num="27">A flowchart showing the processing of the REnc algorithm.</figref><figref num="28">A flowchart showing the processing of the Dec1 algorithm.</figref><figref num="29">A flowchart showing the processing of the Dec2 algorithm.</figref><figref num="30">The figure which shows an example of the hardware composition of the key generation apparatus 100, the encryption apparatus 200, the decryption apparatus 300, the re-encryption apparatus 400, and the re-encryption sentence decryption apparatus 500.</figref>
Hereinafter, embodiments of the invention will be described with reference to the drawings. In the following description, the processing device is CPU 911 or the like, which will be described later. The storage device is ROM 913, RAM 914, magnetic disk 920, etc., which will be described later. The communication device is a communication board 915 or the like, which will be described later. The input device is a keyboard 902, a communication board 915, etc., which will be described later. That is, the processing device, the storage device, the communication device, and the input device are hardware.
The notation in the following description will be described. When A is a random variable or distribution, the number 101 represents the random selection of A to y according to the distribution of A. That is, in the number 101, y is a random number.<maths num="101"><img id="000002" he="15" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> When A is a set, the number 102 represents the uniform selection of y from A. That is, in the number 102, y is a uniform random number.<maths num="102"><img id="000003" he="15" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> The number 103 indicates that y is a set defined by z, or y is a set to which z is assigned.<maths num="103"><img id="000004" he="12" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> When a is a constant, the number 104 represents that the machine (algorithm) A outputs a to the input x.<maths num="104"><img id="000005" he="29" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Number 105, that is, F<sub>q</sub>Indicates a finite field of order q.<maths num="105"><img id="000006" he="15" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Vector notation is finite field F<sub>q</sub>Represents the vector representation in. That is, the number 106.<maths num="106"><img id="000007" he="31" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> The number 107 is the two vectors x shown in the number 108.<sup>→</sup>And v<sup>→</sup>Represents the inner product shown in the number 109 with.<maths num="107"><img id="000008" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="108"><img id="000009" he="25" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="109"><img id="000010" he="18" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> X<sup>T</sup>Represents the transposed matrix of the matrix X. Basis B and Basis shown in number 110<sup>*</sup>On the other hand, the number is 111.<maths num="110"><img id="000011" he="22" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="111"><img id="000012" he="30" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> e<sup>→</sup><sub>j</sub>Indicates the normal basis vector shown in Equation 112.<maths num="112"><img id="000013" he="24" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, in the following description, if Vt, nt, wt, zt, nu, wu, zu is shown as subscript or superscript, this Vt, nt, wt, zt, nu, wu, zu is V.<sub>t</sub>, n<sub>t</sub>, w<sub>t</sub>, z<sub>t</sub>, n<sub>u</sub>, w<sub>u</sub>, z<sub>u</sub>Means. Similarly, if δi, j is superscripted, then this δi, j is δ.<sub>i, j</sub>Means. Further, when , which means a vector, is attached to a subscript or a superscript, this means that the subscript or the superscript is attached with a superscript. Also, when ~ is attached to a subscript or superscript, it means that this ~ is attached to the subscript or superscript.
Embodiment 1. In this embodiment, after explaining the basic concept for realizing the FCPRE method, the configuration of the FCPRE method according to this embodiment will be described. First, the FCPRE will be briefly described. Secondly, a space having a rich mathematical structure called a dual pairing vector space (DPVS), which is a space for realizing the FCPRE method, will be described. Third, the concept for realizing the FCPRE method will be explained. Here, the span program, the inner product and access structure of the attribute vectors, and the secret sharing method (secret sharing method) will be described. Fourth, the FCPRE method according to this embodiment will be described. In this embodiment, the ciphertext-policy is an FCPRE method (Ciphertext-Policy). The FCPRE, CP-FCPRE) method will be described. Therefore, first, the basic configuration of the CP-FCPRE method will be described. Next, the basic configuration of the encryption system 10 that realizes this CP-FCPRE method will be described. Next, the parts used to realize this CP-FCPRE method will be described. Then, the CP-FCPRE method and the encryption system 10 according to this embodiment will be described in detail.
<1.FCPRE> First, FPR will be described. FPRE is an agent re-encryption method that makes the relationship between the encryption key (ek), the decryption key (dk), and the re-encryption key (rk) more sophisticated and flexible.
FPRE has the following two features. First, the encryption key and the decryption key are set with the attribute information x and the attribute information v, respectively. Then, for the relation R, only when R (x, v) holds, the decryption key dk<sub>v</sub>Is the encryption key ek<sub>x</sub>The ciphertext encrypted with can be decrypted. Second, in addition to the attribute information x and attribute information v being set for the encryption key and decryption key, two attribute information (x', v) are set for the re-encryption key. There is. And only when R (x, v) holds, the re-encryption key rk<sub>(x', v)</sub>Is the encryption key ek<sub>x</sub>Decryption key dk for which R (x', v') holds for the ciphertext encrypted with<sub>v'</sub>Ciphertext that can be decrypted with, that is, the encryption key ek<sub>x'</sub>It can be changed to the ciphertext encrypted with.
If the relation R is an equal sign, that is, if R (x, v) holds only when x = v, then the PRE method is IDPRE.
ABPRE is a more generalized PRE than IDPRE. In ABPRE, the attribute information set in the encryption key and the decryption key is a set of attribute information. For example, the attribute information set in the encryption key and decryption key is X: = (x), respectively.<sub>1</sub>, ..., x<sub>d</sub>) And V: = (v<sub>1</sub>, ..., v<sub>d</sub>) And. For the component of attribute information, the equal sign relationship for each component (for example, {x<sub>t</sub>= v<sub>t</sub>} t {1, ..., d}) is input to the access structure S. Then, R (X, V) is established only when the access structure S accepts the input. That is, the ciphertext encrypted with the encryption key can be decrypted with the decryption key. Non-Patent Document 2 proposes a PRE method of a ciphertext policy in which the access structure S is embedded in the ciphertext. The access structure at that time is a structure consisting only of logical product and negation.
Next, FCPRE will be described. FCPRE is an FPR that allows you to specify conditions for re-encryption. In FCPRE, attribute information x and attribute information v are set for the encryption key and decryption key, respectively, and two attribute information (x', v) are set for the re-encryption key. In addition, the attribute information z and the attribute information y are set in the ciphertext and the re-encryption key, respectively. Then, for the relation R, the encryption key ek is established only when R (x, v) is established and R (z, y) is established.<sub>x</sub>Decryption key dk for which R (x', v') holds for the ciphertext encrypted with<sub>v'</sub>Ciphertext that can be decrypted with, that is, the encryption key ek<sub>x'</sub>It can be changed to the ciphertext encrypted with.
There is a normal FE that does not have a ciphertext transfer function, that is, does not have a re-encryption key. In FE, the re-encryption key generation process and the re-encryption process do not exist, and the encryption key and the decryption key are set with the attribute information x and the attribute information v, respectively. Then, only when R (x, v) holds for the relation R, the decryption key dk<sub>v</sub>:= (dk, v) is the encryption key ek<sub>x</sub>The ciphertext encrypted with: = (ek, x) can be decrypted.
<2. Dual pairing vector space> First, a symmetric bilinear pairing group will be described. Symmetric bilinear pairing group (q, G, G<sup>T</sup>, g, e) are the prime number q, the cyclic additive group G of the order q, and the cyclic multiplication group G of the order q.<sup>T</sup>And g 0 G, and non-degenerate bilinear pairing that can be calculated in polynomial time (Nondegenerate Bilinear Pairing) e: G × G G<sub>T</sub>It is a pair with. Non-degenerate bilinear pairing is e (sg, tg) = e (g, g)<sup>st</sup>And e (g, g) 1. In the following explanation, G<sub>bpg</sub>, 1<sup>λ</sup>Parameter param of the bilinear pairing group with the security parameter λ as input<sub>G</sub>: = (q, G, G<sub>T</sub>The algorithm outputs the values of, g, e).
Next, the dual pairing vector space will be described. Dual pairing vector space (q, V, G)<sub>T</sub>, A, e) is a symmetric bilinear pairing group (param)<sub>G</sub>: = (q, G, G<sub>T</sub>, G, e)) can be constructed by the direct product. Dual pairing vector space (q, V, G)<sub>T</sub>, A, e) are prime numbers q and F shown in number 113<sub>q</sub>Above N-dimensional vector space V, cyclic group G of order q<sub>T</sub>, Standard basis of space V A: = (a<sub>1</sub>, ..., a<sub>N</sub>), And has the following operations (1) and (2). Where a<sub>i</sub>Is as shown in Equation 114.<maths num="113"><img id="000014" he="19" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="114"><img id="000015" he="19" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Operation (1): Non-degenerate bilinear pairing Pairing in space V is defined by the equation 115.<maths num="115"><img id="000016" he="54" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> It is a non-degenerate bilinear. That is, e (sx, ty) = e (x, y)<sup>st</sup>And for all y V, if e (x, y) = 1, then x = 0. Also, for all i and j, e (a)<sub>i</sub>, a<sub>j</sub>) = E (g, g)<sup>δi, j</sup>Is. Here, if i = j, then δ<sub>i, j</sub>If = 1 and i j, then δ<sub>i, j</sub>= 0. Also, e (g, g) 1 G<sub>T</sub>Is.
Calculation (2): Distortion mapping Linear transformation φ in space V shown in equation 116<sub>i, j</sub>Can do the number 117.<maths num="116"><img id="000017" he="25" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="117"><img id="000018" he="50" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Here, the linear transformation φ<sub>i, j</sub>Is called a distortion map.
In the following explanation, G<sub>dpvs</sub>, 1<sup>λ</sup>(λ natural number), N natural number, parameters of bilinear pairing group param<sub>G</sub>: = (q, G, G<sub>T</sub>The parameter param of the dual pairing vector space where the security parameter is λ and the N-dimensional space V is the input of the values of, g, e).<sub>V</sub>: = (q, V, G<sub>T</sub>The algorithm outputs the values of, A, e).
Here, a case where a dual pairing vector space is constructed by the above-mentioned symmetric bilinear pairing group will be described. It is also possible to construct a dual pairing vector space by asymmetric bilinear pairing groups. It is easy to apply the following description when a dual pairing vector space is constructed by asymmetric bilinear pairing groups.
<3. Concept for realizing FCPRE method> <No. 3-1. Span program> FIG. 1 is an explanatory diagram of the matrix M ^. {p<sub>1</sub>, ..., p<sub>n</sub>} Is a set of variables. M ^: = (M, ρ) is a labeled matrix. Where the matrix M is F<sub>q</sub>The above (L row x r column) matrix. In addition, ρ is a label attached to each row of the matrix M, and {p.<sub>1</sub>, ..., p<sub>n</sub>, ¬p<sub>1</sub>, ..., ¬p<sub>n</sub>} Is associated with any one literal. The label ρ attached to all lines of M<sub>i</sub>(i = 1, ..., L) is associated with any one literal. That is, ρ: {1, ..., L} {p<sub>1</sub>, ..., p<sub>n</sub>, ¬p<sub>1</sub>, ..., ¬p<sub>n</sub>}.
All input sequences δ {0,1}<sup>n</sup>On the other hand, the submatrix M of the matrix M<sub>δ</sub>Is defined. Matrix M<sub>δ</sub>Is a submatrix composed of rows of the matrix M in which the label ρ is associated with the value 1 by the input column δ. That is, the matrix M<sub>δ</sub>Is δ<sub>i</sub>P such that = 1<sub>i</sub>The row of the matrix M associated with and δ<sub>i</sub>¬p such as = 0<sub>i</sub>It is a submatrix consisting of rows of the matrix M associated with. Figure 2 shows the matrix M<sub>δ</sub>It is explanatory drawing of. In FIG. 2, n = 7, L = 6, r = 5. That is, the set of variables is {p<sub>1</sub>, ..., p<sub>7</sub>}, And the matrix M is a matrix of (6 rows × 5 columns). Further, in FIG. 2, the label ρ is ρ.<sub>1</sub>Is ¬p<sub>2</sub>To, ρ<sub>2</sub>Is p<sub>1</sub>To, ρ<sub>3</sub>Is p<sub>4</sub>To, ρ<sub>4</sub>Is ¬p<sub>5</sub>To, ρ<sub>5</sub>Is ¬p<sub>3</sub>To, ρ<sub>6</sub>Is p<sub>5</sub>It is assumed that they are associated with each other. Where the input sequence δ {0,1}<sup>7</sup>But δ<sub>1</sub>= 1, δ<sub>2</sub>= 0, δ<sub>3</sub>= 1, δ<sub>4</sub>= 0, δ<sub>5</sub>= 0, δ<sub>6</sub>= 1, δ<sub>7</sub>Suppose that = 1. In this case, the literal (p) surrounded by a broken line<sub>1</sub>, p<sub>3</sub>, p<sub>6</sub>, p<sub>7</sub>, ¬p<sub>2</sub>, ¬p<sub>4</sub>, ¬p<sub>5</sub>The submatrix consisting of the rows of the matrix M associated with) is the matrix M<sub>δ</sub>Is. That is, the first row of the matrix M (M)<sub>1</sub>), 2nd line (M<sub>2</sub>), 4th line (M<sub>4</sub>) Is the matrix M<sub>δ</sub>Is.
In other words, the map γ: {1, ..., L} {0,1} is [ρ (j) = p<sub>i</sub>] [δ<sub>i</sub>= 1] or [ρ (j) = ¬p<sub>i</sub>] [δ<sub>i</sub>When [= 0], it is assumed that γ (j) = 1, and in other cases, γ (j) = 0. In this case, M<sub>δ</sub>: = (M<sub>j</sub>)<sub>γ (j) = 1</sub>Is. Where M<sub>j</sub>Is the jth row of the matrix M. That is, in FIG. 2, the map γ (j) = 1 (j = 1,2,4) and the map γ (j) = 0 (j = 3,5,6). Therefore, (M<sub>j</sub>)<sub>γ (j) = 1</sub>Is M<sub>1</sub>, M<sub>2</sub>, M<sub>4</sub>And the matrix M<sub>δ</sub>Is. That is, the j-th row of the matrix M is the matrix M, depending on whether the value of the map γ (j) is 0 or 1.<sub>δ</sub>Whether or not it is included in is determined.
1<sup>→</sup> span <M<sub>δ</sub>The span program M ^ accepts the input string δ only if>, and rejects the input string δ otherwise. That is, the matrix M obtained from the matrix M ^ by the input sequence δ.<sub>δ</sub>Linear combination of 1<sup>→</sup>The span program M ^ accepts the input sequence δ only if In addition, 1<sup>→</sup>Is a row vector in which each element has a value of "1". For example, in the example of FIG. 2, the matrix M consisting of the first, second, and fourth rows of the matrix M<sub>δ</sub>Linear combination of each row of 1<sup>→</sup>The span program M ^ accepts the input sequence δ only if That is, α<sub>1</sub>(M<sub>1</sub>) + α<sub>2</sub>(M<sub>2</sub>) + α<sub>4</sub>(M<sub>4</sub>)=1<sup>→</sup>Α<sub>1</sub>, α<sub>2</sub>, α<sub>4</sub>If exists, the span program M ^ accepts the input sequence δ.
Here, a literal with a positive label ρ {p<sub>1</sub>, ..., p<sub>n</sub>A span program is called monotone if it is only associated with. On the other hand, the label ρ is literal {p<sub>1</sub>, ..., p<sub>n</sub>, ¬p<sub>1</sub>, ..., ¬p<sub>n</sub>When associated with }, the span program is called non-monotone. Here, the span program is non-monotone. Then, the access structure (non-monotone access structure) is configured by using the non-monotone span program. The access structure simply controls access to cryptography. That is, it controls whether or not the ciphertext can be decrypted. As will be described in detail later, since the span program is not monotone but non-monotone, the range of use of the FCPRE method configured by using the span program is expanded.
<3-2. Dot product of attribute information and access structure> Here, the above-mentioned mapping γ (j) is calculated using the inner product of the attribute information. That is, which row of the matrix M is the matrix M using the inner product of the attribute information.<sub>δ</sub>Decide whether to include it in.
U<sub>t</sub>(t = 1, ..., d and U<sub>t</sub>⊂{0,1}<sup>*</sup>) Is a sub-universe, which is a set of attributes. And U<sub>t</sub>Is the identification information (t) of the subset and the n-dimensional vector (v), respectively.<sup>→</sup>) And. That is, U<sub>t</sub>Is (t, v<sup>→</sup>). Where t {1, ..., d} and v<sup>→</sup> F<sub>q</sub><sup>n</sup>Is.
U<sub>t</sub>: = (t, v<sup>→</sup>) Is the variable p in the span program M ^: = (M, ρ). That is, p: = (t, v<sup>→</sup>). And the variable (p: = (t, v)<sup>→</sup>), (t, v'<sup>→</sup>Let the span program M ^: = (M, ρ) with), ...) be the access structure S. That is, the access structure S: = (M, ρ), and ρ: {1, ..., L} {(t, v)<sup>→</sup>), (t, v'<sup>→</sup>), ..., ¬ (t, v<sup>→</sup>), ¬ (t, v'<sup>→</sup>), ...}.
Next, let Γ be a set of attributes. That is, Γ: = {(t, x)<sup>→</sup><sub>t</sub>) | x<sup>→</sup><sub>t</sub> Fq<sup>n</sup>, 1 t d}. Given Γ in the access structure S, the map γ: {1, ..., L} {0,1} for the span program M ^: = (M, ρ) is defined as follows: .. For each integer i of i = 1, ..., L, [ρ (i) = (t, v<sup>→</sup><sub>i</sub>)] [(t, x)<sup>→</sup><sub>t</sub>) Γ] [v<sup>→</sup><sub>i</sub> X<sup>→</sup><sub>t</sub>= 0] or [ρ (i) = ¬ (t, v)<sup>→</sup><sub>i</sub>)] [(t, x)<sup>→</sup><sub>t</sub>) Γ] [v<sup>→</sup><sub>i</sub> X<sup>→</sup><sub>t</sub>When 0], γ (j) = 1, and in other cases, γ (j) = 0. That is, attribute information v<sup>→</sup>And x<sup>→</sup>The map γ is calculated based on the inner product of and. Then, as described above, which row of the matrix M is the matrix M by the mapping γ.<sub>δ</sub>It is decided whether to include it in. That is, attribute information v<sup>→</sup>And x<sup>→</sup>Which row of the matrix M is the matrix M by the inner product with<sub>δ</sub>It is decided whether to include it in 1<sup>→</sup> span <(M<sub>i</sub>)<sub>γ (i) = 1</sub>Access structure S: = (M, ρ) accepts Γ only if>.
<Third 3-3. Secret Sharing Method> The secret sharing method for access structure S: = (M, ρ) will be described. The secret sharing method is to disperse the secret information into meaningless distributed information. For example, the secret information s is distributed to 10 pieces, and 10 pieces of distributed information are generated. Here, each of the 10 distributed information does not have the information of the secret information s. Therefore, even if one piece of distributed information is obtained, no information can be obtained regarding the confidential information s. On the other hand, if you get all 10 distributed information, you can restore the secret information s. There is also a secret sharing method that can restore secret information s by obtaining only a part (for example, 8) without obtaining all 10 distributed information. In this way, the case where the secret information s can be restored with 8 out of 10 distributed information is called 8-out-of-10. In other words, the case where the secret information s can be restored with t out of n distributed information is called t-out-of-n. This t is called a threshold. Also, d<sub>1</sub>, ..., d<sub>10</sub>When 10 distribution information of<sub>1</sub>, ..., d<sub>8</sub>Confidential information s can be restored with up to 8 distributed information, but d<sub>3</sub>, ..., d<sub>10</sub>There is also a secret sharing method in which the secret information s cannot be restored with up to eight distributed information. That is, there is also a secret sharing method that controls not only the number of distributed information obtained but also whether or not the secret information s can be restored according to the combination of the distributed information.
Figure 3 shows s<sub>0</sub>It is explanatory drawing of. Figure 4 shows s<sup> T</sup>It is explanatory drawing of. Let the matrix M be a matrix of (L rows × r columns). f<sup> T</sup>Is the column vector shown in the number 118.<maths num="118"><img id="000019" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> S shown in number 119<sub>0</sub>Is the confidential information to be shared.<maths num="119"><img id="000020" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Also, s shown in number 120<sup> T</sup>S<sub>0</sub>Let it be a vector of L variance information.<maths num="120"><img id="000021" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> And distributed information s<sub>i</sub>Suppose that belongs to ρ (i).
If the access structure S: = (M, ρ) accepts Γ, that is, for γ: {1, ..., L} {0,1} 1<sup>→</sup> span <(M<sub>i</sub>)<sub>γ (i) = 1</sub>>, I {i {1, ..., L} | γ (i)-= 1} constant {α<sub>i</sub> F<sub>q</sub>| i I} exists. This is the example in Fig. 2, α<sub>1</sub>(M<sub>1</sub>) + α<sub>2</sub>(M<sub>2</sub>) + α<sub>4</sub>(M<sub>4</sub>)=1<sup>→</sup>Α<sub>1</sub>, α<sub>2</sub>, α<sub>4</sub>It is clear from the explanation that the span program M ^ accepts the input sequence δ when is present. That is, α<sub>1</sub>(M<sub>1</sub>) + α<sub>2</sub>(M<sub>2</sub>) + α<sub>4</sub>(M<sub>4</sub>)=1<sup>→</sup>Α<sub>1</sub>, α<sub>2</sub>, α<sub>4</sub>If the span program M ^ accepts the input sequence δ, then α<sub>1</sub>(M<sub>1</sub>) + α<sub>2</sub>(M<sub>2</sub>) + α<sub>4</sub>(M<sub>4</sub>)=1<sup>→</sup>Α<sub>1</sub>, α<sub>2</sub>, α<sub>4</sub>Exists. And the number 121.<maths num="121"><img id="000022" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> The constant {α<sub>i</sub>} Can be calculated in polynomial time in the size of the matrix M.
In the FCPRE method according to the following embodiment, as described above, the access structure is configured by applying the inner product predicate and the secret sharing method to the span program. Therefore, access control can be freely designed by designing the matrix M in the span program and the attribute information x and the attribute information v (predicate information) in the inner product predicate. In other words, access control can be designed with a very high degree of freedom. The design of the matrix M corresponds to the condition design such as the threshold value of the secret sharing method. For example, the attribute-based encryption method described above corresponds to a case where the design of the inner product predicate is limited to a certain condition in the access structure in the FCPRE method according to the following embodiment. That is, compared to the access structure in the FCPRE method according to the following embodiment, the access structure in the attribute-based encryption method accesses the attribute information x and the attribute information v (predicate information) in the inner product predicate because there is no design freedom. The degree of freedom in control design is low. Specifically, the attribute-based encryption method uses attribute information {x.<sup>→</sup><sub>t</sub>}<sub>t {1, ..., d}</sub>And {v<sup>→</sup><sub>t</sub>}<sub>t {1, ..., d}</sub>And, a two-dimensional vector for the equal sign relationship, eg x<sup>→</sup><sub>t</sub>: = (1, x<sub>t</sub>) And v<sup>→</sup><sub>t</sub>: = (v<sub>t</sub>, -1) and so on. Further, the PRE in the inner product predicate encryption method corresponds to the case where the design of the matrix M in the span program is limited to a certain condition in the access structure in the FCPRE method according to the following embodiment. That is, compared to the access structure in the FCPRE method according to the following embodiment, the access structure in the inner product predicate encryption method has a lower degree of freedom in designing access control because there is no degree of freedom in designing the matrix M in the span program. Specifically, the inner product predicate encryption method is a case where the secret sharing method is limited to 1-out-of-1 (or d-out-of-d).
In particular, the access structure in the FCPRE method according to the following embodiment constitutes a non-monotone access structure using a non-monotone span program. Therefore, the degree of freedom in designing access control is increased. Specifically, since the non-monotone span program includes a negative literal (¬p), a negative condition can be set. For example, suppose that the first company has four departments, A department, B department, C department, and D department. Here, suppose that access control is performed so that only users belonging to departments other than the B department of the first company can be accessed (decryptable). In this case, if the negative condition cannot be set, it is necessary to set the condition that "belongs to any of the A, C, and D departments of the first company." On the other hand, if the negative condition can be set, the condition "being an employee of the first company and belonging to a department other than the B department" can be set. In other words, by being able to set negative conditions, it is possible to set natural conditions. Although the number of departments is small here, it can be seen that it is very effective when the number of departments is large.
<4. Basic configuration of FC PRE method> <No. 4-1. Basic configuration of CP-FC PRE method> The configuration of the CP-FCPRE method will be briefly described. Note that CP (ciphertext policy) means that the policy is embedded in the ciphertext, that is, the access structure is embedded.
The CP-FCPRE method has seven algorithms: Setup, KG, Enc, RKG, REnc, Dec1 and Dec2. (Setup) The Setup algorithm has a security parameter λ and an attribute format n<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>; w<sub>1</sub>, ..., w<sub>d</sub>; z<sub>1</sub>, ..., z<sub>d</sub>) Is an input, and it is a probabilistic algorithm that outputs the public parameter pk and the master key sk. (KG) The KG algorithm is an attribute set Γ: = {(t, x)<sup>→</sup><sub>t</sub>) | x<sup>→</sup><sub>t</sub> F<sub>q</sub><sup>nt</sup>, 1 t d}, the public parameter pk, and the master key sk as inputs, the decryption key sk<sub>Γ</sub>Is a probabilistic algorithm that outputs. (Enc) The Enc algorithm has message m and access structure S = (M, ρ), S<sup>~</sup>= (M<sup>~</sup>, ρ<sup>~</sup>) And the public parameter pk as input, ciphertext ct<sub>S</sub>Is a probabilistic algorithm that outputs. (RKG) RKG algorithm is the decryption key sk<sub>Γ</sub>And the access structure S': = (M', ρ') and the attribute set Γ<sup>~</sup>And the public parameter pk as input, the re-encryption key rk<sub>Γ, S'</sub>Is a probabilistic algorithm that outputs. (REnc) The REnc algorithm is a ciphertext ct<sub>S</sub>And the re-encryption key rk<sub>Γ, S'</sub>And the public parameter pk as input, the reciphertext rct<sub>S'</sub>Is a probabilistic algorithm that outputs. (Dec1) Dec1 algorithm re-ciphertext rct<sub>S'</sub>And the decryption key sk<sub>Γ'</sub>And the public parameter pk are input, and the message m or the identification information is output. (Dec2) Dec2 algorithm is ciphertext ct<sub>S</sub>And the decryption key sk<sub>Γ</sub>And the public parameter pk are input, and the message m or the identification information is output.
<No. 4-2. Cryptographic system 10> A cryptographic system 10 that executes a CP-FCPRE algorithm will be described. FIG. 5 is a configuration diagram of the encryption system 10 that executes the CP-FCPRE method. The encryption system 10 includes a key generation device 100, an encryption device 200, a decryption device 300 (re-encryption key generation device), a re-encryption device 400, and a re-encryption text decryption device 500.
The key generator 100 has a security parameter λ and an attribute format n.<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>; w<sub>1</sub>, ..., w<sub>d</sub>; z<sub>1</sub>, ..., z<sub>d</sub>) And is input to execute the Setup algorithm to generate the public parameter pk and the master key sk. Then, the key generator 100 discloses the public parameter pk. Further, the key generator 100 executes the KG algorithm with the attribute set Γ as an input to execute the decryption key sk.<sub>Γ</sub>Is generated and secretly transmitted to the decoding device 300. Further, the key generator 100 executes the KG algorithm with the attribute set Γ'as an input to execute the decryption key sk.<sub>Γ'</sub>Is generated and secretly transmitted to the re-ciphertext decryption device 500.
The encryption device 200 includes the message m and the access structures S, S.<sup>~</sup>And the ciphertext ct by executing the Enc algorithm with the public parameter pk as input.<sub>S</sub>To generate. The encryption device 200 has a ciphertext ct.<sub>S</sub>To the re-encryptor 400.
The decryption device 300 is a decryption key sk<sub>Γ</sub>And the access structure S'and the attribute set Γ<sup>~</sup>And the public parameter pk as input to execute the RKG algorithm and re-encryption key rk<sub>Γ, S'</sub>To generate. The decryption device 300 is a re-encryption key rk<sub>Γ, S'</sub>Is secretly sent to the re-encryptor 400. In addition, the decryption device 300 has a public parameter pk and a decryption key sk.<sub>Γ</sub>And the ciphertext ct<sub>S</sub>The Dec2 algorithm is executed with and as input, and the message m or identification information is output.
The re-encryption device 400 is a re-encryption key rk.<sub>Γ, S'</sub>And the ciphertext ct<sub>S</sub>And the public parameter pk, execute the REnc algorithm, and re-ciphertext rct<sub>S'</sub>To generate. The re-encryption device 400 is a re-encryption statement rct.<sub>S'</sub>To the re-ciphertext decryption device 500.
The reciphertext decryption device 500 has a decryption key sk<sub>Γ'</sub>And the reciphertext rct<sub>S'</sub>And the public parameter pk are input, the Dec1 algorithm is executed, and the message m or the identification information is output.
<Parts 4-3. Parts used to realize the CP-FCPRE method> In order to realize the CP-FCPRE method, functional cryptography (CP-FE) of ciphertext policy and one-time signature are used. Since all of them are known techniques, the methods used in the following description will be briefly described here. An example of the CP-FE method is described in Patent Document 1.
CP-FE method is Setup<sub>CP-FE</sub>,KG<sub>CP-FE</sub>, Enc<sub>CP-FE</sub>, Dec<sub>CP-FE</sub>It has four algorithms. (Setup<sub>CP-FE</sub>) Setup<sub>CP-FE</sub>The algorithm has a security parameter λ and an attribute format n<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>) And as input, public parameter pk<sup>CP-FE</sup>And the master key sk<sup>CP-FE</sup>It is a probabilistic algorithm that outputs and. (KG<sub>CP-FE</sub>) KG<sub>CP-FE</sub>The algorithm is an attribute set Γ: = {(t, x)<sup>→</sup><sub>t</sub>) | x<sup>→</sup><sub>t</sub> F<sub>q</sub><sup>nt</sup>, 1 t d} and the public parameter pk<sup>CP-FE</sup>And the master key sk<sup>CP-FE</sup>As input, decryption key sk<sub>Γ</sub><sup>CP-FE</sup>Is a probabilistic algorithm that outputs. (Enc<sub>CP-FE</sub>) Enc<sub>CP-FE</sub>The algorithm is message m, access structure S = (M, ρ), and public parameter pk.<sup>CP-FE</sup>It is a probabilistic algorithm that outputs the ciphertext ψ with and as input. (Dec<sub>CP-FE</sub>) Dec Dec<sub>CP-FE</sub>The algorithm is the ciphertext ψ and the decryption key sk.<sub>Γ</sub><sup>CP-FE</sup>And the public parameter pk<sup>CP-FE</sup>It is an algorithm that outputs message m or identification information with and as input.
The one-time signature method has three algorithms, SigKG, Sig, and Ver. (SigKG) The SigKG algorithm is a probabilistic algorithm that inputs the security parameter λ and outputs the signature key sigk and the verification key verk. (Sig) The Sig algorithm is a probabilistic algorithm that outputs the signature S by inputting the signature key sigk and the message m. (Ver) The Ver algorithm takes the verification key verk, the message m, and the signature S as inputs, and outputs 1 if the signature S is valid for the verification key verk and the message m, and outputs 0 if the signature S is not valid. It is an algorithm.
<4-4. Details of CP-FCPRE method and encryption processing system 10> Based on FIGS. 6 to 17, the CP-FCPRE method and the functions and operations of the cryptographic processing system 10 that executes the CP-FCPRE method will be described. FIG. 6 is a functional block diagram showing the functions of the key generator 100. FIG. 7 is a functional block diagram showing the functions of the encryption device 200. FIG. 8 is a functional block diagram showing the functions of the decoding device 300. FIG. 9 is a functional block diagram showing the functions of the re-encryption device 400. FIG. 10 is a functional block diagram showing the functions of the reciphertext decryption device 500. 11 and 12 are flowcharts showing the operation of the key generator 100. Note that FIG. 11 is a flowchart showing the processing of the Setup algorithm, and FIG. 12 is a flowchart showing the processing of the KG algorithm. FIG. 13 is a flowchart showing the operation of the encryption device 200, and is a flowchart showing the processing of the Enc algorithm. FIG. 14 is a flowchart showing the operation of the decoding device 300, and is a flowchart showing the processing of the RKG algorithm. FIG. 15 is a flowchart showing the operation of the re-encryption device 400, and is a flowchart showing the processing of the REnc algorithm. FIG. 16 is a flowchart showing the operation of the re-ciphertext decryption device 500, and is a flowchart showing the processing of the Dec1 algorithm. FIG. 17 is a flowchart showing the operation of the decoding device 300, and is a flowchart showing the processing of the Dec2 algorithm.
The functions and operations of the key generator 100 will be described. As shown in FIG. 6, the key generation device 100 includes a master key generation unit 110, a master key storage unit 120, an information input unit 130, a decryption key generation unit 140, and a key transmission unit 150 (key output unit). Further, the decryption key generation unit 140 includes a CP-FE key generation unit 141, a random number generation unit 142, and a decryption key k.<sup>*</sup>A generation unit 143 is provided.
First, the processing of the Setup algorithm will be described with reference to FIG. (S101: Orthonormal Basis Generation Step) The master key generator 110 calculates the number 122-1 and the number 122-2 by the processing device, and the parameter param<sub>n </sub>And base B<sub>0</sub>And base B<sup>*</sup><sub>0</sub>And base B<sub>t</sub>And base B<sup>*</sup><sub>t</sub>And the basis H<sub>t</sub>And H<sup>*</sup><sub>t</sub>And generate.<maths num="122-1"><img id="000023" he="154" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="122-2"><img id="000024" he="99" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
That is, the master key generation unit 110 executes the following processing. (1) The master key generator 110 uses the input device to set the security parameter λ (1).<sup>λ</sup>) And the attribute format n<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>; w<sub>1</sub>, ..., w<sub>d</sub>; z<sub>1</sub>, ..., z<sub>d</sub>) And enter. Where d is an integer greater than or equal to 1, and for each integer t of t = 1, ..., d, n<sub>t</sub>Is an integer greater than or equal to 1 and w<sub>t</sub>, z<sub>t</sub>Is an integer greater than or equal to 0.
(2) The master key generator 110 uses the processing device to input the security parameter λ input in (1) as input to the algorithm G.<sub>bpg</sub>Execute the parameter param of the bilinear pairing group<sub>G</sub>: = (q, G, G<sub>T</sub>, g, e) generate values.
(3) The master key generator 110 is N<sub>0</sub>Set to 9 and N for each integer t of t = 1, ..., d<sub>t</sub>To n<sub>t</sub>+ w<sub>t</sub>+ z<sub>t</sub>Set +1. Further, the master key generation unit 110 generates a random number ψ. The master key generator 110 is e (G, G).<sup>ψ</sup>G<sub>T</sub>Set to.
Subsequently, the master key generation unit 110 executes the following processes (4) to (10) for each integer t of t = 0, ..., D. (4) The master key generator 110 uses the security parameter λ input in (1) and the N set in (3).<sub>t</sub>And the param generated in (2)<sub>G</sub>: = (q, G, G<sub>T</sub>Algorithm G with the values of, g, e) as inputs<sub>dpvs</sub>To execute the parameter param of the dual pairing vector space<sub>Vt</sub>: = (q, V<sub>t</sub>, G<sub>T</sub>, A<sub>t</sub>Generate the value of, e).
(5) The master key generator 110 is the N set in (3).<sub>t</sub>And F<sub>q</sub>Linear transformation X with and as input<sub>t</sub>: = (χ<sub>t, i, j</sub>)<sub>i, j</sub>Is randomly generated. GL is an abbreviation for General Linear. That is, GL is a general linear group, a set of square matrices with a non-zero determinant, and a group for multiplication. Also, (χ<sub>t, i, j</sub>)<sub>i, j</sub>Is the matrix χ<sub>t, i, j</sub>It means a matrix related to the subscripts i and j. Here, (χ<sub>t, i, j</sub>)<sub>i, j</sub>Then i, j = 1, ..., N<sub>t</sub>Is.
(6) The master key generator 110 uses a random number ψ and a linear transformation X.<sub>t</sub>Based on (ν<sub>t, i, j</sub>)<sub>i, j</sub>: = ψ (X<sub>t</sub><sup>T</sup>)<sup>-1</sup>To generate. In addition, (ν<sub>t, i, j</sub>)<sub>i, j</sub>Also (χ)<sub>t, i, j</sub>)<sub>i, j</sub>Similar to the matrix ν<sub>t, i, j</sub>It means a matrix related to the subscripts i and j. Here, (ν<sub>t, i, j</sub>)<sub>i, j</sub>Then i, j = 1, ..., N<sub>t</sub>Is.
(7) The master key generator 110 uses the linear transformation X generated in (5).<sub>t</sub>Based on, the standard basis A generated in (4)<sub>t</sub>From base B<sub>t</sub>To generate. The master key generator 110 generated in (6) (ν)<sub>t, i, j</sub>)<sub>i, j</sub>Based on, the standard basis A generated in (4)<sub>t</sub>From base B<sup>*</sup><sub>t</sub>To generate.
(8) The master key generator 110 is the N set in (3), as in (5).<sub>t</sub>And F<sub>q</sub>With and as input, linear transformation X'<sub>t</sub>: = (χ'<sub>t, i, j</sub>)<sub>i, j</sub>Is randomly generated.
(9) The master key generator 110 uses the random number ψ and the linear transformation X'as in (6).<sub>t</sub>Based on (ν'<sub>t, i, j</sub>)<sub>i, j</sub>: = ψ (X'<sub>t</sub><sup>T</sup>)<sup>-1</sup>To generate.
(10) The master key generator 110 uses the linear transformation X'generated in (8).<sub>t</sub>Based on, the basis A generated in (4)<sub>t</sub>From base H<sub>t</sub>To generate. The master key generator 110 generated in (9) (ν'<sub>t, i, j</sub>)<sub>i, j</sub>Based on, the basis A generated in (4)<sub>t</sub>From base H<sup>*</sup><sub>t</sub>To generate.
(11) The master key generator 110 is a param<sub>n </sub>{Param generated in (4)<sub>Vt</sub>}<sub>t = 0, ..., d</sub>And g<sub>T</sub>And set.
(S102: CP-FE master key generation step) The master key generator 110 calculates the number 123 by the processing device, and the public parameter pk of the functional cipher.<sup>CP-FE</sup>And the master key sk<sup>CP-FE</sup>And generate.<maths num="123"><img id="000025" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S103: Public parameter generation step) The master key generation unit 110 is based on the base B by the processing device.<sub>0</sub>Partial basis B ^<sub>0</sub>And base B<sub>t</sub>Partial basis B ^<sub>t</sub>And the basis H<sub>t</sub>Partial basis H ^<sub>u</sub>And base B<sup>*</sup><sub>0</sub>Partial basis B ^<sup>*</sup><sub>0</sub>And base B<sup>*</sup><sub>t</sub>Partial basis B ^<sup>*</sup><sub>t</sub>And the basis H<sup>*</sup><sub>t</sub>Partial basis H ^<sup>*</sup><sub>u</sub>And are generated as shown in the number 124.<maths num="124"><img id="000026" he="70" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> The master key generator 110 has a public parameter pk<sup>CP-FE</sup>And the security parameters λ and param<sub>n </sub>And partial basis B ^<sub>0</sub>, B ^<sub>t</sub>, H ^<sub>u</sub>, B ^<sup>*</sup><sub>0</sub>, B ^<sup>*</sup><sub>t</sub>, H ^<sup>*</sup><sub>u</sub>Together with, the public parameter pk.
(S104: Master key generation step) The master key generator 110 is the master key sk<sup>CP-FE</sup>And the basis vector b<sup>*</sup><sub>0,1</sub>And the basis H shown in equation 125<sup>*</sup><sub>u</sub>Let the master key sk be a part of the basis vector of.<maths num="125"><img id="000027" he="16" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S105: Master key memory step) The master key storage unit 120 stores the public parameter pk generated in (S103) in the storage device. Further, the master key storage unit 120 stores the master key sk generated in (S104) in the storage device.
That is, in (S101) to (S104), the key generator 100 executes the Setup algorithm shown in the equations 126-1 and 126-2 to generate the public parameter pk and the master key sk. Then, in (S105), the key generation device 100 stores the generated public parameter pk and the master key sk in the storage device. The public parameter is made public via a network, for example, and is made available to the encryption device 200, the decryption device 300, the re-encryption device 400, and the re-encryption text decryption device 500.<maths num="126-1"><img id="000028" he="208" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="126-2"><img id="000029" he="123" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Next, the processing of the KG algorithm will be described with reference to FIG. (S201: Information input step) The information input unit 130 uses an input device to set the attribute set Γ: = {(t, x).<sup>→</sup><sub>t</sub>: = (x<sub>t, 1</sub>, ..., x<sub>t, nt</sub> F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>})) | Enter 1 t d}. Note that t may not be all integers of 1 or more and less than or equal to d, but may be at least some integers of 1 or more and less than or equal to d. The attribute set Γ is, for example, the decryption key sk.<sub>Γ</sub>Attribute information of the user of is set.
(S202: CP-FE decryption key generation step) The CP-FE key generator 141 calculates the number 127 by the processing device and sks the decryption key for functional encryption.<sub>Γ</sub><sup>CP-FE</sup>To generate.<maths num="127"><img id="000030" he="19" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S203: Random number generation step) The random number generation unit 142 generates a random number as shown in the number 128 by the processing device.<maths num="128"><img id="000031" he="52" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S204: Decryption key k<sup>*</sup>Generation step) Decryption key k<sup>*</sup>The generation unit 143 uses a processing device to obtain a decryption key k.<sup>*</sup><sub>0</sub>Is generated as shown in the number 129.<maths num="129"><img id="000032" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Basis B and Basis shown in Equation 110<sup>*</sup>The number is 111 for and. Therefore, the number 129 is the basis B<sup>*</sup><sub>0</sub>Basis vector b<sup>*</sup><sub>0,1</sub>1 is set as the coefficient of, and the basis vector b<sup>*</sup><sub>0,2</sub>Δ is set as the coefficient of, and the basis vector b<sup>*</sup><sub>0,3</sub>, ..., b<sup>*</sup><sub>0,6</sub>0 is set as the coefficient of, and the basis vector b<sup>*</sup><sub>0,7</sub>, b<sup>*</sup><sub>0,8</sub>As a coefficient of φ<sub>0,1</sub>, φ<sub>0,2</sub>Is set and the basis vector b<sup>*</sup><sub>0,9</sub>It means that 0 is set as the coefficient of.
Also, the decryption key k<sup>*</sup>The generation unit 143 uses the processing device to perform the decryption key k for each integer t included in the attribute set Γ.<sup>*</sup><sub>t</sub>Is generated as shown in the number 130.<maths num="130"><img id="000033" he="24" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> The number 130 is the basis B<sup>*</sup><sub>t</sub>Basis vector b<sup>*</sup><sub>t, 1</sub>, ..., b<sup>*</sup><sub>t, nt</sub>As a coefficient of δx<sub>t, 1</sub>, ..., δx<sub>t, nt</sub>Is set and the basis vector b<sup>*</sup><sub>t, nt + 1</sub>, ..., b<sup>*</sup><sub>t, nt + wt</sub>0 is set as the coefficient of, and the basis vector b<sup>*</sup><sub>t, nt + wt + 1</sub>, ..., b<sup>*</sup><sub>t, nt + wt + zt</sub>As a coefficient of φ<sub>t, 1</sub>, ..., φ<sub>t, zt</sub>Is set and the basis vector b<sup>*</sup><sub>t, nt + wt + zt + 1</sub>It means that 0 is set as the coefficient of.
Also, the decryption key k<sup>*</sup>The generation unit 143 has u = 1, ..., d and i = 1, ..., n depending on the processing device.<sub>u</sub>Decryption key k for each integer u, i<sup>~*</sup><sub>u, i</sub>Is generated as shown in the number 131.<maths num="131"><img id="000034" he="24" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S205: Key transmission step) The key transmitter 150 has an attribute set Γ and a functional encryption decryption key sk.<sub>Γ</sub><sup>CP-FE</sup>And the decryption key k<sup>*</sup><sub>0</sub>, k<sup>*</sup><sub>t</sub>, k<sup>~*</sup><sub>u, i</sub>Decryption key sk with and as an element<sub>Γ</sub>Is secretly transmitted to the decoding device 300 via the network, for example, by a communication device. Of course, the decryption key sk<sub>Γ</sub>May be transmitted to the decoding device 300 by other methods.
That is, in (S201) to (S204), the key generator 100 executes the KG algorithm shown in Equation 132 to execute the decryption key sk.<sub>Γ</sub>To generate. Then, in (S205), the key generator 100 sets the decryption key sk.<sub>Γ</sub>Is transmitted to the decoding device 300.<maths num="132"><img id="000035" he="129" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The key generator 100 has a decryption key sk in (S201).<sub>Γ'</sub>Attribute set Γ': = {(t, x') in which the attribute information of the user of<sup>→</sup><sub>t</sub>: = (x'<sub>t, 1</sub>, ..., x'<sub>t, nt</sub> F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>})) | Enter 1 t d} to execute the KG algorithm and decrypt key sk<sub>Γ'</sub>To generate. Then, the key generator 100 has a decryption key sk.<sub>Γ'</sub>: = (Γ', sk<sub>Γ'</sub><sup>CP-FE</sup>, k'<sup>*</sup><sub>0</sub>, {k'<sup>*</sup><sub>t</sub>}<sub>(t, x t) Γ</sub>, {k'<sup>~*</sup><sub>t, i</sub>}<sub>u = 1, ..., d; i = 1, ..., nu</sub>) Is sent to the re-ciphertext decryption device 500.
The functions and operations of the encryption device 200 will be described. As shown in FIG. 7, the encryption device 200 includes a public parameter receiving unit 210, an information input unit 220, a signature processing unit 230, an encryption unit 240, and a ciphertext transmitting unit 250 (ciphertext output unit). Further, the encryption unit 240 includes an f vector generation unit 241, an s vector generation unit 242, a random number generation unit 243, and a ciphertext c generation unit 244.
The processing of the Enc algorithm will be described with reference to FIG. (S301: Public parameter reception step) The public parameter receiving unit 210 receives, for example, the public parameter pk generated by the key generation device 100 via the network by the communication device.
(S302: Information input step) The information input unit 220 has an access structure S: = (M, ρ), S depending on the input device.<sup>~</sup>: = (M<sup>~</sup>, ρ<sup>~</sup>) Is entered. Access structures S, S<sup>~</sup>Is set according to the conditions of the system to be realized. Also, the ρ of the access structure S is, for example, the ciphertext ct.<sub>S</sub>Attribute information of the user who can decrypt is set. Also, Access Structure S<sup>~</sup>Ρ<sup>~</sup>For example, information for setting reencryptable conditions is set. Where ρ (i) = (t, v<sup>→</sup><sub>i</sub>: = (v<sub>i, 1</sub>, ..., v<sub>i, nt</sub>) F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>}) (v<sub>i, nt</sub> 0). Also, ρ<sup>~</sup>(i) = (u, z<sup>→</sup><sub>i</sub>: = (z<sub>i, 1</sub>, ..., z<sub>i, nu</sub>) F<sub>q</sub><sup>nu</sup>\{0<sup>→</sup>}) (z)<sub>i, nu</sub> 0). Note that M is a matrix of L rows and r columns, and M<sup>~</sup>Is L<sup>~</sup>Line r<sup>~</sup>It is a matrix of columns. Further, the information input unit 220 inputs the message m to be transmitted to the decoding device 300 by the input device.
(S303: Signature key generation step) The signature processing unit 230 calculates the number 133 by the processing device to generate a signature key sigk for one-time signature and a verification key verk.<maths num="133"><img id="000036" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S304: f vector generation step) The f vector generation unit 241 uses a processing device to generate a vector f.<sup>→</sup>, f<sup>~→</sup>Is randomly generated as shown in the number 134.<maths num="134"><img id="000037" he="25" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S305: s vector generation step) The s vector generation unit 242 uses the processing device to generate the vector s.<sup> T</sup>, s<sup>~ T</sup>Is generated as shown in Equation 135.<maths num="135"><img id="000038" he="25" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Further, the s vector generation unit 242 has a value s depending on the processing device.<sub>0</sub>, s<sup>~</sup><sub>0</sub>Is generated as shown in the number 136.<maths num="136"><img id="000039" he="25" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S306: Random number generation step) The random number generation unit 243 generates a random number as shown in the number 137 by the processing device.<maths num="137"><img id="000040" he="45" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S307: Ciphertext c generation step) The ciphertext c generation unit 244 uses the processing device to generate the ciphertext c.<sub>0</sub>Is generated as shown in the number 138.<maths num="138"><img id="000041" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 244 uses the processing device to perform the ciphertext c for each integer i of i = 1, ..., L.<sub>i</sub>Is generated as shown in the number 139.<maths num="139"><img id="000042" he="67" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 244 uses the processing device to perform the ciphertext c.<sub>T</sub>Is generated as shown in the number 140.<maths num="140"><img id="000043" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 244 uses the processing device to perform the ciphertext c.<sup>~</sup><sub>0</sub>Is generated as shown in the number 141.<maths num="141"><img id="000044" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 244 has j = 1, ..., L depending on the processing device.<sup>~</sup>For each integer j in, the ciphertext c<sup>~</sup><sub>j</sub>Is generated as shown in the number 142.<maths num="142"><img id="000045" he="69" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 244 uses the processing device to perform the ciphertext c.<sup>~</sup><sub>T</sub>Is generated as shown in the number 143.<maths num="143"><img id="000046" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S308: Signature generation step) The signature processing unit 230 calculates the number 144 by the processing device and ct the ciphertext.<sub>S</sub>Generate a signature Sig for element C of.<maths num="144"><img id="000047" he="20" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S309: Ciphertext transmission step) The ciphertext transmitter 250 has access structures S, S.<sup>~</sup>And the ciphertext c<sub>0</sub>, c<sub>1</sub>, ..., c<sub>L</sub>, c<sub>T</sub>, c<sup>~</sup><sub>0</sub>, c<sup>~</sup><sub>1</sub>, ..., c<sup>~</sup><sub>L ~</sub>, c<sup>~</sup><sub>T</sub>And the ciphertext ct with the verification key verk and the signature Sig as elements<sub>S</sub>Is transmitted to the decoding device 300 via the network, for example, by a communication device. Of course, the ciphertext ct<sub>S</sub>May be transmitted to the decoding device 300 by other methods.
That is, in (S301) to (S308), the encryption device 200 executes the Enc algorithm shown in the numbers 145-1 and 145-2, and the ciphertext ct<sub>S</sub>To generate. Then, in (S309), the encryption device 200 generated the ciphertext ct.<sub>S</sub>Is transmitted to the decoding device 300.<maths num="145-1"><img id="000048" he="125" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="145-2"><img id="000049" he="212" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The functions and operations of the decoding device 300 will be described. As shown in FIG. 8, the decryption device 300 includes a decryption key receiving unit 310, an information input unit 320, a re-encryption key generation unit 330, a re-encryption key transmission unit 340 (re-encryption key output unit), and a ciphertext reception unit. It includes a unit 350, a verification unit 360, a complement coefficient calculation unit 370, a pairing calculation unit 380, and a message calculation unit 390. Further, the re-encryption key generation unit 330 includes a random number generation unit 331 and conversion information W.<sub>1</sub>Generator 332, conversion information W<sub>1</sub>Encryption unit 333, decryption key k<sup>* rk</sup>It includes a generation unit 334 and a conversion unit 335. Further, the verification unit 360 includes a span program calculation unit 361 and a signature verification unit 362.
Here, the processing of the RKG algorithm will be described based on FIG. The Dec2 algorithm will be described later.
(S401: Decryption key reception step) The decryption key receiving unit 310 is, for example, a decryption key sk transmitted from the key generation device 100 via a network by a communication device.<sub>Γ</sub>To receive. Further, the decryption key receiving unit 310 receives the public parameter pk generated by the key generation device 100.
(S402: Information input step) The information input unit 320 inputs the access structure S': = (M', ρ') by the input device. The access structure S'is set according to the conditions of the system to be realized. Also, the ρ'of the access structure S'is, for example, the reciphertext rct.<sub>S'</sub>Attribute information of the user who can decrypt is set. Where ρ'(i) = (t, v<sup>→’</sup><sub>i</sub>: = (v'<sub>i, 1</sub>, ..., v'<sub>i, nt</sub>) F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>}) (v'<sub>i, nt</sub> 0). In addition, the information input unit 130 uses an input device to set the attribute set Γ.<sup>~</sup>: = {(u, y<sup>→</sup><sub>u</sub>: = (y<sub>u,1</sub>, ..., y<sub>u, nu</sub> F<sub>q</sub><sup>nu</sup>\{0<sup>→</sup>})) | Enter 1 u d}. Note that u may not be all integers of 1 or more and d or less, but may be at least some integers of 1 or more and d or less. Also, the attribute set Γ<sup>~</sup>For example, attribute information indicating a condition for re-encryption is set.
(S403: Random number generation step) The random number generation unit 331 generates a random number by the processing device as shown in the number 146.<maths num="146"><img id="000050" he="49" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S404: Conversion information W<sub>1</sub>Generation step) Conversion information W<sub>1</sub>The generation unit 332 uses the processing device to convert information W.<sub>1,0</sub>, W<sub>1,t</sub>, W<sup>~</sup><sub>1, u</sub>Is generated as shown in the number 147.<maths num="147"><img id="000051" he="40" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S405: Conversion information W<sub>1</sub>Encryption step) Conversion information W<sub>1</sub>The encryption unit 333 calculates the number 148 by the processing device and converts the conversion information W.<sub>1,0</sub>, W<sub>1,t</sub>, W<sup>~</sup><sub>1, u</sub>Is encrypted by functional encryption, and the encryption conversion information ct<sup>rk</sup><sub>S'</sub>(ψ<sup>rk</sup>) Is generated. Conversion information W<sub>1,0</sub>, W<sub>1,t</sub>, W<sup>~</sup><sub>1, u</sub>Is encrypted by functional cryptography with access structure S'as input, so the reciphertext rct<sub>S'</sub>The attribute information of the user who can decrypt is set and encrypted.<maths num="148"><img id="000052" he="30" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S406: Decryption key k<sup>* rk</sup>Generation step) Decryption key k<sup>* rk</sup>The generation unit 334 has a decryption key k depending on the processing device.<sup>* rk</sup><sub>0</sub>, k<sup>* rk</sup><sub>0, ran</sub>Is generated as shown in the number 149.<maths num="149"><img id="000053" he="27" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* rk</sup>The generator 334 uses the processing device to perform the decryption key k for each integer t included in the attribute set Γ.<sup>* rk</sup><sub>t</sub>, k<sup>* rk</sup><sub>t, ran</sub>Is generated as shown in the number 150.<maths num="150"><img id="000054" he="27" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* rk</sup>The generation unit 334 is an attribute set Γ depending on the processing device.<sup>~</sup>For each integer u contained in, the decryption key k<sup>~ * rk</sup><sub>u</sub>Is generated as shown in the number 151.<maths num="151"><img id="000055" he="44" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S407: Conversion step) The conversion unit 335 calculates the number 152 by the processing device and calculates the basis D.<sup>^*</sup><sub>0</sub>, D<sup>^*</sup><sub>t</sub>, U<sup>^*</sup><sub>u</sub>To generate.<maths num="152"><img id="000056" he="38" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S408: Key transmission step) The re-encryption key transmitter 340 has an attribute set of Γ and Γ.<sup>~</sup>And access structure S'and decryption key k<sup>* rk</sup><sub>0</sub>, k<sup>* rk</sup><sub>0, ran</sub>, k<sup>* rk</sup><sub>t</sub>, k<sup>* rk</sup><sub>t, ran</sub>, k<sup>~ * rk</sup><sub>u</sub>And encryption conversion information ct<sup>rk</sup><sub>S'</sub>And base D<sup>^*</sup><sub>0</sub>, D<sup>^*</sup><sub>t</sub>, U<sup>^*</sup><sub>u</sub>Re-encryption key rk with<sub>Γ, S'</sub>Is secretly transmitted to the re-encryption device 400 via the network, for example, by a communication device. Of course, the re-encryption key rk<sub>Γ, S'</sub>May be transmitted to the re-encrypting device 400 by other methods.
That is, in (S401) to (S407), the decryption device 300 executes the RKG algorithm shown in the numbers 153-1 and 1532 to execute the re-encryption key rk.<sub>Γ, S'</sub>To generate. Then, in (S408), the decryption device 300 generated the re-encryption key rk.<sub>Γ, S'</sub>To the re-encryptor 400.<maths num="153-1"><img id="000057" he="153" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="153-2"><img id="000058" he="170" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The functions and operations of the re-encryption device 400 will be described. As shown in FIG. 9, the re-encryption device 400 includes a public parameter receiver 410, a ciphertext receiver 420, a re-encryption key receiver 430, a verification unit 440, an encryption unit 450, and a re-encryption text transmitter 460 ( It has a re-encrypted text output unit). Further, the verification unit 440 includes a span program calculation unit 441 and a signature verification unit 442. Further, the encryption unit 450 includes a random number generation unit 451 and an f vector generation unit 452, an s vector generation unit 453, and conversion information W.<sub>2</sub>Generator 454, conversion information W<sub>2</sub>Encryption unit 455, ciphertext c<sup>renc</sup>Generator 456, decryption key k<sup>* renc</sup>A generator 457 is provided.
The processing of the REnc algorithm will be described with reference to FIG. (S501: Public parameter reception step) The public parameter receiving unit 410 receives, for example, the public parameter pk generated by the key generation device 100 via the network by the communication device.
(S502: Ciphertext reception step) The ciphertext receiving unit 420 is, for example, a ciphertext ct transmitted by the encryption device 200 via a network by a communication device.<sub>S</sub>To receive.
(S503: Re-encryption key reception step) The re-encryption key receiver 430 is, for example, a re-encryption key rk transmitted from the decryption device 300 via a network by a communication device.<sub>Γ, S'</sub>To receive.
(S504: Span program calculation step) The span program calculation unit 441 uses the processing device to perform the ciphertext ct.<sub>S</sub>The access structure S contained in is the re-encryption key rk<sub>Γ, S'</sub>While determining whether or not to accept the Γ contained in, the ciphertext ct<sub>S</sub>Access structure S included in<sup>~</sup>But the re-encryption key rk<sub>Γ, S'</sub>Γ contained in<sup>~</sup>Is determined whether or not to accept. Whether the access structure S accepts Γ and whether the access structure S accepts Γ<sup>~</sup>Is Γ<sup>~</sup>The method of determining whether or not to accept the above is as described in "3. Concept for realizing FCPRE" in the first embodiment. In the span program calculation unit 441, the access structure S accepts Γ and the access structure S<sup>~</sup>Is Γ<sup>~</sup>Is accepted (accepted in S504), the process proceeds to (S505). On the other hand, the access structure S rejects Γ, or the access structure S<sup>~</sup>Is Γ<sup>~</sup>(Rejected by S504), the process ends.
(S505: Signature verification step) The signature verification unit 442 determines whether or not the result of calculating the number 154 is 1 by the processing device. If the result is 1 (valid in S505), the signature verification unit 442 proceeds to process (S506). On the other hand, when the result is 0 (injustice in S505), the signature verification unit 442 ends the process.<maths num="154"><img id="000059" he="39" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S506: Random number generation step) The random number generation unit 451 generates a random number as shown in the number 155 by the processing device.<maths num="155"><img id="000060" he="75" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S507: f vector generation step) The f vector generator 452 is a vector f depending on the processing device.<sup>→’</sup>, f<sup>~→’</sup>Is randomly generated as shown in the number 156.<maths num="156"><img id="000061" he="29" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S508: s vector generation step) The s vector generation unit 453 uses the processing device to generate the vector s.<sup>'T</sup>, s<sup>~ 'T</sup>Is generated as shown in the number 157.<maths num="157"><img id="000062" he="27" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Further, the s vector generation unit 453 has a value s depending on the processing device.<sub>0</sub><sup>’</sup>, s<sup>~</sup><sub>0</sub><sup>’</sup>Is generated as shown in the number 158.<maths num="158"><img id="000063" he="27" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S509: Conversion information W<sub>2</sub>Generation step) Conversion information W<sub>2</sub>The generation unit 454 uses the processing device to convert information W.<sub>2</sub>Is generated as shown in the number 159.<maths num="159"><img id="000064" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S510: Conversion information W<sub>2</sub>Encryption step) Conversion information W<sub>2</sub>The encryption unit 455 calculates the number 160 by the processing device and converts the conversion information W.<sub>2</sub>Is encrypted by functional encryption, and the encryption conversion information ct<sup>renc</sup><sub>S'</sub>(ψ<sup>renc</sup>) Is generated. Conversion information W<sub>2</sub>Is encrypted by functional cryptography with access structure S'as input, so the reciphertext rct<sub>S'</sub>The attribute information of the user who can decrypt is set and encrypted.<maths num="160"><img id="000065" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S511: Ciphertext c<sup>renc</sup>Generation step) Ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to generate the ciphertext c.<sup>~ renc</sup><sub>0</sub>Is generated as shown in the number 161.<maths num="161"><img id="000066" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to generate the ciphertext c for each integer i of i = 1, ..., L.<sup>renc</sup><sub>i</sub>Is generated as shown in the number 162.<maths num="162"><img id="000067" he="65" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to generate the ciphertext c.<sup>~ renc</sup><sub>T</sub>Is generated as shown in the number 163.<maths num="163"><img id="000068" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the ciphertext c<sup>renc</sup>The generator 456 may have j = 1, ..., L depending on the processing device.<sup>~</sup>For each integer i in, the ciphertext c<sup>~ renc</sup><sub>j</sub>Is generated as shown in the number 164.<maths num="164"><img id="000069" he="68" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S512: decryption key k<sup>* renc</sup>Generation step) Decryption key k<sup>* renc</sup>The generation unit 457 uses a processing device to obtain a decryption key k.<sup>* renc</sup><sub>0</sub>Is generated as shown in the number 165.<maths num="165"><img id="000070" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* renc</sup>The generation unit 457 uses the processing device to perform the decryption key k for each integer t included in the attribute set Γ.<sup>* renc</sup><sub>t</sub>Is generated as shown in the number 166.<maths num="166"><img id="000071" he="25" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* renc</sup>The generation unit 457 is an attribute set Γ depending on the processing device.<sup>~</sup>For each integer u contained in, the decryption key k<sup>~ * renc</sup><sub>u</sub>Is generated as shown in the number 167.<maths num="167"><img id="000072" he="25" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S513: Re-ciphertext transmission step) The reciphertext transmitter 460 has an access structure S', S, S.<sup>~</sup>And the attribute set Γ, Γ<sup>~</sup>And the decryption key k<sup>* renc</sup><sub>0</sub>, k<sup>* renc</sup><sub>t</sub>, k<sup>~ * renc</sup><sub>u</sub>And the ciphertext c<sup>~ renc</sup><sub>0</sub>, c<sup>renc</sup><sub>i</sub>, c<sup>~ renc</sup><sub>T</sub>, c<sup>~ renc</sup><sub>j</sub>And encryption conversion information ct<sup>rk</sup><sub>S'</sub>And encryption conversion information ct<sup>renc</sup><sub>S'</sub>Re-ciphertext rct with and as an element<sub>S'</sub>Is secretly transmitted to the reciphertext decryption device 500 via the network, for example, by a communication device. Of course, the reciphertext rct<sub>S'</sub>May be transmitted to the re-ciphertext decryption device 500 by other methods.
That is, in (S501) to (S512), the re-encryption device 400 executes the REnc algorithm shown in the numbers 168-1, the number 168-2, and the number 168-3, and the re-encryption statement rct.<sub>S'</sub>To generate. Then, in (S513), the re-encryption device 400 generated the re-encryption statement rct.<sub>S'</sub>To the re-ciphertext decryption device 500.<maths num="168-1"><img id="000073" he="193" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="168-2"><img id="000074" he="159" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="168-3"><img id="000075" he="101" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The functions and operations of the re-ciphertext decryption device 500 will be described. As shown in FIG. 10, the re-ciphertext decryption device 500 includes a decryption key receiving unit 510, a ciphertext receiving unit 520, a span program calculation unit 530, a complement coefficient calculation unit 540, a conversion information generation unit 550, a conversion unit 560, and a pair. It has a ring calculation unit 570 and a message calculation unit 580. The pairing calculation unit 570 and the message calculation unit 580 are collectively referred to as a decoding unit.
The processing of the Dec1 algorithm will be described with reference to FIG. (S601: Decryption key reception step) The decryption key receiving unit 510 is, for example, a decryption key sk transmitted from the key generation device 100 via a network by a communication device.<sub>Γ'</sub>To receive. Further, the decryption key receiving unit 310 receives the public parameter pk generated by the key generation device 100.
(S602: Ciphertext reception step) The ciphertext receiving unit 520 uses, for example, the re-encryption text rct transmitted by the re-encryption device 400 via the network by the communication device.<sub>S'</sub>To receive.
(S603: Span program calculation step) The span program calculation unit 530 re-encrypts the ciphertext rct by the processing device.<sub>S'</sub>The access structure S'contained in is the decryption key sk<sub>Γ'</sub>While determining whether to accept Γ'contained in, the reciphertext rct<sub>S'</sub>Access structure S included in<sup>~</sup>But the reciphertext rct<sub>S'</sub>Γ contained in<sup>~</sup>Is determined whether or not to accept. Whether or not access structure S'accepts Γ', and access structure S<sup>~</sup>Is Γ<sup>~</sup>The method of determining whether or not to accept the above is as described in "3. Concept for realizing FCPRE" in the first embodiment. In the span program calculation unit 530, the access structure S'accepts Γ'and the access structure S'<sup>~</sup>Is Γ<sup>~</sup>Is accepted (accepted in S603), the process proceeds to (S604). On the other hand, access structure S'rejects Γ', or access structure S<sup>~</sup>Is Γ<sup>~</sup>(Rejected by S603), the process ends.
(S604: Complementary coefficient calculation step) The complement coefficient calculation unit 540 has I, J, which is the number 169, and a constant (complement coefficient) {α, depending on the processing device.<sub>i</sub>}<sub>i I</sub>, {α<sup>~</sup><sub>j</sub>}<sub>j J</sub>And calculate.<maths num="169"><img id="000076" he="76" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S605: Conversion information generation step) The conversion information generation unit 550 uses the processing device to convert the conversion information W.<sub>1,0</sub>, W<sub>1,t</sub>, W<sup>~</sup><sub>1, u</sub>, W<sub>2</sub>Is generated as shown in the number 170.<maths num="170"><img id="000077" he="43" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S606: Conversion step) The conversion unit 560 uses the processing device to perform the decryption key k, as shown in Equation 171.<sup>*</sup><sub>0</sub>, k<sup>*</sup><sub>t</sub>, k<sup>~*</sup><sub>u</sub>And the ciphertext c<sup>~</sup><sub>0</sub>To generate.<maths num="171"><img id="000078" he="45" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S607: Pairing calculation step) The pairing calculation unit 570 calculates the number 172 by the processing device, and the session key K<sup>~</sup>To generate.<maths num="172"><img id="000079" he="75" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S608: Message calculation step) The message calculation unit 580 has m'= c depending on the processing device.<sup>~ renc</sup><sub>T</sub>/ K<sup>~</sup>To generate the message m'(= m).
That is, in (S601) to (S608), the re-ciphertext decryption device 500 executes the Dec1 algorithm shown in the numbers 173-1 and 173-2 to generate the message m'(= m).<maths num="173-1"><img id="000080" he="159" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="173-2"><img id="000081" he="139" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The processing of the Dec2 algorithm will be described with reference to FIG. (S701: Decryption key reception step) The decryption key receiving unit 310 is, for example, a decryption key sk transmitted from the key generation device 100 via a network by a communication device.<sub>Γ</sub>To receive. Further, the decryption key receiving unit 310 receives the public parameter pk generated by the key generation device 100.
(S702: Ciphertext reception step) The ciphertext receiving unit 350 is, for example, a ciphertext ct transmitted by the re-encrypting device 400 via a network by a communication device.<sub>S</sub>To receive.
(S703: Span program calculation step) The span program calculation unit 361 uses the processing device to perform the ciphertext ct.<sub>S</sub>The access structure S included in is the decryption key sk<sub>Γ</sub>Determine whether or not to accept the Γ contained in. The method for determining whether or not the access structure S accepts Γ is as described in 3. Concept for realizing FCPRE in the first embodiment. When the access structure S accepts Γ (accepted by S703), the span program calculation unit 361 proceeds to process (S704). On the other hand, if the access structure S rejects Γ (rejected by S703), the process ends.
(S704: Signature verification step) The signature verification unit 362 determines whether or not the result of calculating the number 174 is 1 by the processing device. If the result is 1 (valid in S704), the signature verification unit 362 proceeds to process (S705). On the other hand, when the result is 0 (injustice in S704), the signature verification unit 362 ends the process.<maths num="174"><img id="000082" he="37" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S705: Complementary coefficient calculation step) The complement coefficient calculation unit 370 has I, which is the number 175, and a constant (complement coefficient) {α, depending on the processing device.<sub>i</sub>}<sub>i I</sub>And calculate.<maths num="175"><img id="000083" he="47" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S706: Pairing calculation step) The pairing calculation unit 380 calculates the number 176 by the processing device to generate the session key K.<maths num="176"><img id="000084" he="37" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S707: Message calculation step) The message calculation unit 390 uses m'= c depending on the processing device.<sub>T</sub>Calculate / K to generate message m'(= m).
That is, from (S701) to (S707), the decoding device 300 executes the Dec2 algorithm shown in Equation 177 to generate the message m'(= m).<maths num="177"><img id="000085" he="155" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
As described above, the encryption system according to the first embodiment can realize the CP-FCPRE method. Therefore, one re-encryption key can transfer ciphertext to various types of user sets. Furthermore, it becomes possible to specify a condition for specifying a ciphertext to be re-encrypted.
In the above description, the decryption device 300 also serves as the re-encryption key generator, and the decryption device 300 executes not only the Dec2 algorithm but also the RKG algorithm. However, the decryption device 300 and the re-encryption key generation device may be separate devices. In this case, the decryption device 300 executes the Dec2 algorithm, and the re-encryption key generator executes the RKG algorithm. Therefore, in this case, the decryption device 300 has the functional configuration required to execute the Dec2 algorithm, and the re-encryption key generator has the functional configuration required to execute the RKG algorithm.
Also, in the above explanation, N<sub>t</sub>To n<sub>t</sub>+ w<sub>t</sub>+ z<sub>t</sub>I set +1. But N<sub>t</sub>To n<sub>t</sub>+ w<sub>t</sub>+ z<sub>t</sub>+ β<sub>t</sub>May be set. Here, β<sub>t</sub>Is an integer greater than or equal to 0. Also, in the above explanation, N<sub>0</sub>Was set to 9. But N<sub>0</sub>1 + 1 + 2 + w<sub>0</sub>+ z<sub>0</sub>+ β<sub>0</sub>May be set. Where w<sub>0</sub>, z<sub>0</sub>, β<sub>0</sub>Is an integer greater than or equal to 0.
Further, in the above description, the ciphertext c generated by S511<sup>~ renc</sup><sub>0</sub>Π'(verk, 1) is the additional information Η, and the decryption key k generated by S512<sup>* renc</sup><sub>0</sub>Σ (-1, verk) is the additional information Θ. Additional information Η, Θ are supported and canceled by the pairing operation performed on S607.
Embodiment 2. In the first embodiment, the CP-FCPRE method has been described. In the second embodiment, the FCPRE method (Key-Policy FCPRE, KP-FCPRE) method of the key policy will be described.
First, the basic configuration of the KP-FCPRE method will be described. Next, the basic configuration of the encryption processing system 10 that realizes this KP-FCPRE method will be described. Next, the parts used to realize this KP-FCPRE method will be described. Then, the KP-FCPRE method and the encryption processing system 10 according to this embodiment will be described in detail.
The configuration of the KP-FCPRE method will be briefly explained. Note that KP (key policy) means that the policy is embedded in the key, that is, the access structure is embedded.
<No. 1-1. Basic configuration of KP-FCPRE method> The KP-FCPRE method has seven algorithms: Setup, KG, Enc, RKG, REnc, Dec1 and Dec2. (Setup) The Setup algorithm has a security parameter λ and an attribute format n<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>; w<sub>1</sub>, ..., w<sub>d</sub>; z<sub>1</sub>, ..., z<sub>d</sub>) Is an input, and it is a probabilistic algorithm that outputs the public parameter pk and the master key sk. (KG) The KG algorithm takes the access structure S = (M, ρ), the public parameter pk, and the master key sk as inputs, and the decryption key sk.<sub>S</sub>Is a probabilistic algorithm that outputs. (Enc) The Enc algorithm has a message m and an attribute set Γ: = {(t, x).<sup>→</sup><sub>t</sub>) | x<sup>→</sup><sub>t</sub> F<sub>q</sub><sup>nt</sup>, 1 t d}, Γ<sup>~</sup>: = {(u, y<sup>→</sup><sub>u</sub>) | y<sup>→</sup><sub>u</sub> F<sub>q</sub><sup>nu</sup>, 1 y d} and the public parameter pk as input, ciphertext ct<sub>Γ</sub>Is a probabilistic algorithm that outputs. (RKG) RKG algorithm is the decryption key sk<sub>S</sub>And the attribute set Γ': = {(t, x'<sup>→</sup><sub>t</sub>) | x'<sup>→</sup><sub>t</sub> F<sub>q</sub><sup>nt</sup>, 1 t d} and access structure S<sup>~</sup>= (M<sup>~</sup>, ρ<sup>~</sup>) And the public parameter pk, the re-encryption key rk<sub>S, Γ'</sub>Is a probabilistic algorithm that outputs. (REnc) The REnc algorithm is a ciphertext ct<sub>Γ</sub>And the re-encryption key rk<sub>S, Γ'</sub>And the public parameter pk as input, the reciphertext rct<sub>Γ'</sub>Is a probabilistic algorithm that outputs. (Dec1) Dec1 algorithm re-ciphertext rct<sub>Γ'</sub>And the decryption key sk<sub>S'</sub>And the public parameter pk are input, and the message m or the identification information is output. (Dec2) Dec2 algorithm is ciphertext ct<sub>Γ</sub>And the decryption key sk<sub>S</sub>And the public parameter pk are input, and the message m or the identification information is output.
<No. 1-2. Cryptographic processing system 10> The cryptographic processing system 10 that executes the KP-FCPRE algorithm will be described. FIG. 18 is a configuration diagram of a cryptographic processing system 10 that executes the KP-FCPRE method. Similar to the encryption processing system 10 shown in FIG. 5, the encryption processing system 10 includes a key generation device 100, an encryption device 200, a decryption device 300 (re-encryption key generation device), a re-encryption device 400, and a re-encryption text decryption. It is equipped with a device 500.
The key generator 100 has a security parameter λ and an attribute format n.<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>; w<sub>1</sub>, ..., w<sub>d</sub>; z<sub>1</sub>, ..., z<sub>d</sub>) And is input to execute the Setup algorithm to generate the public parameter pk and the master key sk. Then, the key generator 100 discloses the public parameter pk. In addition, the key generator 100 executes the KG algorithm with the access structure S as an input to execute the decryption key sk.<sub>S</sub>Is generated and secretly transmitted to the decoding device 300. In addition, the key generator 100 executes the KG algorithm with the access structure S'as an input to execute the decryption key sk.<sub>S'</sub>Is generated and secretly transmitted to the re-ciphertext decryption device 500.
The encryption device 200 includes a message m and an attribute set Γ, Γ.<sup>~</sup>And the ciphertext ct by executing the Enc algorithm with the public parameter pk as input.<sub>Γ</sub>To generate. The encryption device 200 has a ciphertext ct.<sub>Γ</sub>To the re-encryptor 400.
The decryption device 300 has a public parameter pk and a decryption key sk.<sub>S</sub>And the attribute set Γ'and the access structure S<sup>~</sup>Execute the RKG algorithm with and as input, and re-encrypt key rk<sub>S, Γ'</sub>To generate. The decryption device 300 is a re-encryption key rk<sub>S, Γ'</sub>Is secretly sent to the re-encryptor 400. In addition, the decryption device 300 has a public parameter pk and a decryption key sk.<sub>S</sub>And the ciphertext ct<sub>Γ</sub>The Dec2 algorithm is executed with and as input, and the message m or identification information is output.
The re-encryption device 400 has a public parameter pk and a re-encryption key rk.<sub>S, Γ'</sub>And the ciphertext ct<sub>Γ</sub>With and as input, execute the REnc algorithm and re-ciphertext rct<sub>Γ'</sub>To generate. The re-encryption device 400 is a re-encryption statement rct.<sub>Γ'</sub>To the re-ciphertext decryption device 500.
The reciphertext decryption device 500 has a public parameter pk and a decryption key sk.<sub>S'</sub>And the reciphertext rct<sub>Γ'</sub>With the input of, the Dec1 algorithm is executed and the message m or identification information is output.
<Parts 1-3. Parts used to realize the KP-FCPRE method> In order to realize the KP-FCPRE method, functional cryptography (KP-FE) of the key policy and one-time signature are used. Since all of them are known techniques, the methods used in the following description will be briefly described here. An example of the KP-FE method is described in Patent Document 1. Further, since the one-time signature is as described in the first embodiment, the description thereof is omitted here.
KP-FE method is Setup<sub>KP-FE</sub>,KG<sub>KP-FE</sub>, Enc<sub>KP-FE</sub>, Dec<sub>KP-FE</sub>It has four algorithms. (Setup<sub>KP-FE</sub>) Setup<sub>KP-FE</sub>The algorithm has a security parameter λ and an attribute format n<sup>→</sup>: = (d; n<sub>1</sub>, ..., n<sub>d</sub>) And as input, public parameter pk<sup>KP-FE</sup>And the master key sk<sup>KP-FE</sup>It is a probabilistic algorithm that outputs and. (KG<sub>KP-FE</sub>) KG<sub>KP-FE</sub>The algorithm is access structure S = (M, ρ) and public parameter pk<sup>KP-FE</sup>And the master key sk<sup>KP-FE</sup>As input, decryption key sk<sub>S</sub><sup>KP-FE</sup>Is a probabilistic algorithm that outputs. (Enc<sub>KP-FE</sub>) Enc<sub>KP-FE</sub>The algorithm is the message m and the attribute set Γ: = {(t, x)<sup>→</sup><sub>t</sub>) | x<sup>→</sup><sub>t</sub> F<sub>q</sub><sup>nt</sup>, 1 t d} and the public parameter pk<sup>KP-FE</sup>It is a probabilistic algorithm that outputs the ciphertext ψ with and as input. (Dec<sub>KP-FE</sub>) Dec Dec<sub>KP-FE</sub>The algorithm is the ciphertext ψ and the decryption key sk.<sub>S</sub><sup>KP-FE</sup>And the public parameter pk<sup>KP-FE</sup>It is an algorithm that outputs message m or identification information with and as input.
<No. 1-4. Details of KP-FCPRE method and encryption processing system 10> Based on FIGS. 19 to 29, the functions and operations of the KP-FCPRE method and the encryption processing system 10 that executes the KP-FCPRE method will be described. FIG. 19 is a functional block diagram showing the functions of the key generator 100. FIG. 20 is a functional block diagram showing the functions of the encryption device 200. FIG. 21 is a functional block diagram showing the functions of the decoding device 300. FIG. 22 is a functional block diagram showing the functions of the re-encryption device 400. FIG. 23 is a functional block diagram showing the functions of the reciphertext decryption device 500. FIG. 24 is a flowchart showing the operation of the key generator 100, and is a flowchart showing the processing of the KG algorithm. FIG. 25 is a flowchart showing the operation of the encryption device 200, and is a flowchart showing the processing of the Enc algorithm. FIG. 26 is a flowchart showing the operation of the decoding device 300, and is a flowchart showing the processing of the RKG algorithm. FIG. 27 is a flowchart showing the operation of the re-encryption device 400, and is a flowchart showing the processing of the REnc algorithm. FIG. 28 is a flowchart showing the operation of the re-ciphertext decryption device 500, and is a flowchart showing the processing of the Dec1 algorithm. FIG. 29 is a flowchart showing the operation of the decoding device 300, and is a flowchart showing the processing of the Dec2 algorithm.
The functions and operations of the key generator 100 will be described. As shown in FIG. 19, the key generation device 100 includes a master key generation unit 110, a master key storage unit 120, an information input unit 130, a decryption key generation unit 140, and a key transmission unit 150 (key output unit). Further, the decryption key generation unit 140 includes a random number generation unit 142 and a decryption key k.<sup>*</sup>It includes a generation unit 143, a KP-FE key generation unit 144, an f vector generation unit 145, and an s vector generation unit 146.
Since the processing of the Setup algorithm is the same as the processing of the Setup algorithm described in the first embodiment, the description thereof will be omitted. However, in S102 in the first embodiment, the public parameter pk in CP-FE<sup>CP-FE</sup>And the master key sk<sup>CP-FE</sup>However, in the second embodiment, the public parameter pk in KP-FE is generated.<sup>KP-FE</sup>And the master key sk<sup>KP-FE</sup>And generate.
That is, the key generator 100 executes the Setup algorithm shown in the equations 178-1 and 178-2 to generate the public parameter pk and the master key sk.<maths num="178-1"><img id="000086" he="200" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="178-2"><img id="000087" he="121" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The processing of the KG algorithm will be described with reference to FIG. 24. (S801: Information input step) The information input unit 130 inputs the access structure S: = (M, ρ) by the input device. The matrix M of the access structure S is set according to the conditions of the system to be realized. Also, the ρ of the access structure S is, for example, the decryption key sk.<sub>S</sub>Attribute information of the user of is set. Where ρ (i) = (t, v<sup>→</sup><sub>i</sub>: = (v<sub>i.1</sub>, ..., v<sub>i.nt</sub>) F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>}) (v<sub>i, nt</sub> 0).
(S802: KP-FE decryption key generation step) The KP-FE key generator 144 calculates the number 179 by the processing device to generate a functional cipher.<maths num="179"><img id="000088" he="17" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S803: f vector generation step) The f vector generation unit 145 uses a processing device to generate a vector f.<sup>→</sup>Is randomly generated as shown in the number 180.<maths num="180"><img id="000089" he="18" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S804: s vector generation step) The s vector generation unit 146 uses the processing device to generate the vector s.<sup> T</sup>: = (s<sub>1</sub>, ..., s<sub>L</sub>)<sup>T</sup>Is generated as shown in the number 181.<maths num="181"><img id="000090" he="18" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths> Further, the s vector generation unit 146 has a value s depending on the processing device.<sub>0</sub>Is generated as shown in Equation 182.<maths num="182"><img id="000091" he="16" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S805: Random number generation step) The random number generation unit 142 generates a random number by the processing device as shown in the number 183.<maths num="183"><img id="000092" he="40" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S806: decryption key k<sup>*</sup>Generation step) Decryption key k<sup>*</sup>The generation unit 143 uses a processing device to obtain a decryption key k.<sup>*</sup><sub>0</sub>Is generated as shown in the number 184.<maths num="184"><img id="000093" he="15" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>*</sup>The generation unit 143 uses the processing device to perform the decryption key k for each integer i of i = 1, ..., L.<sup>*</sup><sub>i</sub>Is generated as shown in the number 185.<maths num="185"><img id="000094" he="65" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S807: Key transmission step) The key transmitter 150 has an access structure S and a decryption key sk.<sub>S</sub><sup>KP-FE</sup>And the decryption key k<sup>*</sup><sub>0</sub>, k<sup>*</sup><sub>i</sub>Decryption key sk with and as an element<sub>S</sub>Is secretly transmitted to the decoding device 300 via the network, for example, by a communication device. Of course, the decryption key sk<sub>S</sub>May be transmitted to the decoding device 300 by other methods.
That is, in (S801) to (S806), the key generator 100 executes the KG algorithm shown in Equation 186 to execute the decryption key sk.<sub>S</sub>To generate. Then, in (S807), the key generator 100 generates the decryption key sk.<sub>S</sub>Is transmitted to the decoding device 300.<maths num="186"><img id="000095" he="185" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The key generator 100 has a decryption key sk in (S801).<sub>S'</sub>Enter the access structure S': = (M', ρ') in which the attribute information of the user of is set, execute the KG algorithm, and decrypt the key sk.<sub>S'</sub>To generate. And decryption key sk<sub>S'</sub>: = (S', sk<sub>S</sub><sup>KP-FE</sup>, k'<sup>*</sup><sub>0</sub>, k'<sup>*</sup><sub>i</sub>) Is sent to the re-ciphertext decryption device 500. Where ρ'(i) = (t, v<sup>→’</sup><sub>i</sub>: = (v'<sub>i.1</sub>, ..., v'<sub>i.nt</sub>) F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>}) (v'<sub>i, nt</sub> 0).
The functions and operations of the encryption device 200 will be described. As shown in FIG. 20, the encryption device 200 includes a public parameter receiving unit 210, an information input unit 220, a signature processing unit 230, an encryption unit 240, and a ciphertext transmitting unit 250 (ciphertext output unit). Further, the encryption unit 240 includes a random number generation unit 243 and a ciphertext c generation unit 244.
The processing of the Enc algorithm will be described with reference to FIG. 25. (S901: Public parameter reception step) The public parameter receiving unit 210 receives, for example, the public parameter pk generated by the key generation device 100 via the network by the communication device.
(S902: Information input step) The information input unit 220 has an attribute set Γ: = {(t, x) depending on the input device.<sup>→</sup><sub>t</sub>: = (x<sub>t.1</sub>, ..., x<sub>t.nt</sub> Fq<sup>nt</sup>)) | 1 t d}, Γ<sup>~</sup>: = {(u, y<sup>→</sup><sub>u</sub>) | y<sup>→</sup><sub>u</sub> F<sub>q</sub><sup>nu</sup>, 1 y d}. Note that t and u may not be all integers of 1 or more and d or less, but may be at least some integers of 1 or more and d or less. Further, in the attribute set Γ, for example, the attribute information of the user that can be decoded is set. Also, the attribute set Γ<sup>~</sup>For example, information for setting reencryptable conditions is set. Further, the information input unit 220 inputs the message m to be transmitted to the decoding device 300 by the input device.
(S903: Signature key generation step) The signature processing unit 230 calculates the number 187 by the processing device to generate a signature key sigk for one-time signature and a verification key verk.<maths num="187"><img id="000096" he="16" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S904: Random number generation step) The random number generation unit 243 generates a random number by the processing device as shown in the number 188.<maths num="188"><img id="000097" he="39" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S905: Ciphertext c generation step) The ciphertext c generation unit 234 uses the processing device to generate the ciphertext c.<sub>0</sub>Is generated as shown in the number 189.<maths num="189"><img id="000098" he="16" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 234 uses the processing device to obtain the ciphertext c for each integer t included in the attribute information Γ.<sub>t</sub>Is generated as shown in the number 190.<maths num="190"><img id="000099" he="22" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 234 uses the processing device to perform the ciphertext c.<sub>T</sub>Is generated as shown in the number 191.<maths num="191"><img id="000100" he="15" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 234 uses the processing device to perform the ciphertext c.<sup>~</sup><sub>0</sub>Is generated as shown in the number 192.<maths num="192"><img id="000101" he="19" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 234 uses the processing device to perform the ciphertext c.<sup>~</sup><sub>u</sub>Is generated as shown in the number 193.<maths num="193"><img id="000102" he="23" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition, the ciphertext c generation unit 234 uses the processing device to perform the ciphertext c.<sup>~</sup><sub>T</sub>Is generated as shown in the number 194.<maths num="194"><img id="000103" he="17" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S906: Signature generation step) The signature processing unit 230 calculates the number 195 by the processing device and ct the ciphertext.<sub>Γ</sub>Generate a signature Sig for element C of.<maths num="195"><img id="000104" he="26" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S907: Ciphertext transmission step) The ciphertext transmitter 250 has an attribute set of Γ and Γ.<sup>~</sup>And the ciphertext c<sub>0</sub>, c<sub>t</sub>, c<sub>T</sub>, c<sup>~</sup><sub>u</sub>And the ciphertext ct with the verification key verk and the signature Sig as elements<sub>Γ</sub>Is transmitted to the decoding device 300 via the network, for example, by a communication device. Of course, the ciphertext ct<sub>Γ</sub>May be transmitted to the decoding device 300 by other methods.
That is, in (S901) to (S906), the encryption device 200 executes the Enc algorithm shown in the equation 196 to execute the ciphertext ct.<sub>Γ</sub>To generate. Then, in (S907), the encryption device 200 generated the ciphertext ct.<sub>Γ</sub>Is transmitted to the decoding device 300.<maths num="196"><img id="000105" he="196" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The functions and operations of the decoding device 300 will be described. As shown in FIG. 21, the decryption device 300 includes a decryption key receiving unit 310, an information input unit 320, a re-encryption key generation unit 330, a re-encryption key transmission unit 340 (re-encryption key output unit), and a ciphertext reception unit. It includes a unit 350, a verification unit 360, a complement coefficient calculation unit 370, a pairing calculation unit 380, and a message calculation unit 390. Further, the re-encryption key generation unit 330 includes a random number generation unit 331 and conversion information W.<sub>1</sub>Generator 332, conversion information W<sub>1</sub>Encryption unit 333, decryption key k<sup>* rk</sup>It includes a generation unit 334, a conversion unit 335, an f vector generation unit 336, and an s vector generation unit 337. Further, the verification unit 360 includes a span program calculation unit 361 and a signature verification unit 362.
Here, the processing of the RKG algorithm will be described based on FIG. 26. The Dec2 algorithm will be described later.
(S1001: Decryption key reception step) The decryption key receiving unit 310 is, for example, a decryption key sk transmitted from the key generation device 100 via a network by a communication device.<sub>S</sub>To receive. Further, the decryption key receiving unit 310 receives the public parameter pk generated by the key generation device 100.
(S1002: Information input step) The information input unit 320 uses an input device to set the attribute set Γ': = {(t, x').<sup>→</sup><sub>t</sub>: = (x'<sub>t.1</sub>, ..., x'<sub>t.nt</sub> F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>})) | Enter 1 t d}. Note that t may not be all integers of 1 or more and less than or equal to d, but may be at least some integers of 1 or more and less than or equal to d. Also, the attribute set Γ'is, for example, the reciphertext rct.<sub>Γ'</sub>Attribute information of the user who can decrypt is set. In addition, the information input unit 320 uses an input device to access the access structure S.<sup>~</sup>: = (M<sup>~</sup>, ρ<sup>~</sup>) Is entered. Access structure S<sup>~</sup>Matrix M<sup>~</sup>Is set according to the conditions of the system to be realized. Also, Access Structure S<sup>~</sup>Ρ<sup>~</sup>For example, attribute information indicating a condition for re-encryption is set. Where ρ (i) = (t, v<sup>→</sup><sub>i</sub>: = (v<sub>i.1</sub>, ..., v<sub>i.nt</sub>) F<sub>q</sub><sup>nt</sup>\{0<sup>→</sup>}) (v<sub>i, nt</sub> 0).
(S1003: Random number generation step) The random number generation unit 331 generates a random number by the processing device as shown in the number 197.<maths num="197"><img id="000106" he="37" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1004: f vector generation step) The f vector generator 336 is a vector f depending on the processing device.<sup>~→</sup>Is randomly generated as shown in the number 198.<maths num="198"><img id="000107" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1005: s vector generation step) The s vector generator 337 is a vector s depending on the processing device.<sup>~ T</sup>Is generated as shown in the number 199.<maths num="199"><img id="000108" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Further, the s vector generation unit 337 has a value s depending on the processing device.<sup>~</sup><sub>0</sub>Is generated as shown in the number 200.<maths num="200"><img id="000109" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1006: Conversion information W<sub>1</sub>Generation step) Conversion information W<sub>1</sub>The generation unit 332 uses the processing device to convert information W.<sub>1,0</sub>, W<sub>1, i</sub>, W<sup>~</sup><sub>1,j</sub>Is generated as shown in the number 201.<maths num="201"><img id="000110" he="42" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1007: Conversion information W<sub>1</sub>Encryption step) Conversion information W<sub>1</sub>The encryption unit 333 calculates the number 202 by the processing device and converts the conversion information W.<sub>1,0</sub>, W<sub>1, i</sub>, W<sup>~</sup><sub>1,j</sub>Is encrypted by functional encryption, and the encryption conversion information ct<sup>rk</sup><sub>Γ'</sub>(ψ<sup>rk</sup>) Is generated. Conversion information W<sub>1,0</sub>, W<sub>1, i</sub>, W<sup>~</sup><sub>1,j</sub>Is encrypted by functional encryption with the attribute information Γ'as input, so the reciphertext rct<sub>Γ'</sub>The attribute information of the user who can decrypt is set and encrypted.<maths num="202"><img id="000111" he="31" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1008: decryption key k<sup>* rk</sup>Generation step) Decryption key k<sup>* rk</sup>The generation unit 334 has a decryption key k depending on the processing device.<sup>* rk</sup><sub>0</sub>Is generated as shown in the number 203.<maths num="203"><img id="000112" he="15" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* rk</sup>The generation unit 334 uses the processing device to perform the decryption key k for each integer i of i = 1, ..., L.<sup>* rk</sup><sub>i</sub>Is generated as shown in the number 204.<maths num="204"><img id="000113" he="15" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* rk</sup>The generation unit 334 has j = 1, ..., L depending on the processing device.<sup>~</sup>For each integer j in, the decryption key k<sup>~ * rk</sup><sub>j</sub>Is generated as shown in the number 205.<maths num="205"><img id="000114" he="71" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1009: Conversion step) The conversion unit 335 calculates the number 206 by the processing device and calculates the basis D.<sup>^*</sup><sub>0</sub>, D<sup>^*</sup><sub>i</sub>, U<sup>^*</sup><sub>j</sub>To generate.<maths num="206"><img id="000115" he="55" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1010: Key transmission step) The re-encryption key transmitter 340 is an access structure S, S.<sup>~</sup>And the attribute set Γ'and the decryption key k<sup>* rk</sup><sub>0</sub>, k<sup>* rk</sup><sub>i</sub>, k<sup>~ * rk</sup><sub>j</sub>And encryption conversion information ct<sup>rk</sup><sub>Γ'</sub>And base D<sup>^*</sup><sub>0</sub>, D<sup>^*</sup><sub>i</sub>, U<sup>^*</sup><sub>j</sub>Re-encryption key rk with<sub>S, Γ'</sub>Is secretly transmitted to the re-encryption device 400 via the network, for example, by a communication device. Of course, the re-encryption key rk<sub>S, Γ'</sub>May be transmitted to the re-encrypting device 400 by other methods.
That is, in (S1001) to (S1009), the decryption device 300 executes the RKG algorithm shown in the equations 207-1 and 207-2 to execute the re-encryption key rk.<sub>S, Γ'</sub>To generate. Then, in (S1010), the decryption device 300 generated the re-encryption key rk.<sub>S, Γ'</sub>To the re-encryptor 400.<maths num="207-1"><img id="000116" he="126" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="207-2"><img id="000117" he="190" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The functions and operations of the re-encryption device 400 will be described. As shown in FIG. 22, the re-encryption device 400 includes a public parameter receiver 410, a ciphertext receiver 420, a re-encryption key receiver 430, a verification unit 440, an encryption unit 450, and a re-encryption text transmitter 460 ( It is equipped with a re-encrypted text output unit). Further, the verification unit 440 includes a span program calculation unit 441 and a signature verification unit 442. Further, the encryption unit 450 includes a random number generation unit 451 and an f vector generation unit 452, an s vector generation unit 453, and conversion information W.<sub>2</sub>Generator 454, conversion information W<sub>2</sub>Encryption unit 455, ciphertext c<sup>renc</sup>Generator 456, decryption key k<sup>* renc</sup>A generator 457 is provided.
The processing of the REnc algorithm will be described with reference to FIG. 27. (S1101: Public parameter reception step) The public parameter receiving unit 410 receives, for example, the public parameter pk generated by the key generation device 100 via the network by the communication device.
(S1102: Ciphertext reception step) The ciphertext receiving unit 420 is, for example, a ciphertext ct transmitted by the encryption device 200 via a network by a communication device.<sub>Γ</sub>To receive.
(S1103: Re-encryption key reception step) The re-encryption key receiver 430 is, for example, a re-encryption key rk transmitted from the decryption device 300 via a network by a communication device.<sub>S, Γ'</sub>To receive.
(S1104: Span program calculation step) The span program calculation unit 441 re-encrypts the key rk by the processing device.<sub>S, Γ'</sub>The access structure S contained in is the ciphertext ct<sub>Γ</sub>While determining whether to accept the Γ contained in, the re-encryption key rk<sub>S, Γ'</sub>Access structure S included in<sup>~</sup>But the ciphertext ct<sub>Γ</sub>Γ contained in<sup>~</sup>Is determined whether or not to accept. Whether the access structure S accepts Γ and whether the access structure S accepts Γ<sup>~</sup>Is Γ<sup>~</sup>The method of determining whether or not to accept the above is as described in "3. Concept for realizing FCPRE" in the first embodiment. In the span program calculation unit 441, the access structure S accepts Γ and the access structure S<sup>~</sup>Is Γ<sup>~</sup>Is accepted (accepted in S1104), the process proceeds to (S1105). On the other hand, the access structure S rejects Γ, or the access structure S<sup>~</sup>Is Γ<sup>~</sup>(Rejected by S1104), the process ends.
(S1105: Signature verification step) The signature verification unit 442 determines whether or not the result of calculating the number 208 is 1 by the processing device. If the result is 1 (valid in S1105), the signature verification unit 442 proceeds to process (S1106). On the other hand, when the result is 0 (injustice in S1105), the signature verification unit 442 ends the process.<maths num="208"><img id="000118" he="41" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1106: Random number generation step) The random number generation unit 451 generates a random number by the processing device as shown in the number 209.<maths num="209"><img id="000119" he="49" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1107: f vector generation step) The f vector generator 452 is a vector f depending on the processing device.<sup>→’</sup>, f<sup>~→’</sup>Is randomly generated as shown in Equation 210.<maths num="210"><img id="000120" he="30" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1108: s vector generation step) The s vector generation unit 453 uses the processing device to generate the vector s.<sup>'T</sup>, s<sup>~ 'T</sup>Is generated as shown in Equation 211.<maths num="211"><img id="000121" he="26" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Further, the s vector generation unit 453 has a value s depending on the processing device.<sub>0</sub><sup>’</sup> , s<sup>~</sup><sub>0</sub><sup>’</sup>Is generated as shown in Equation 212.<maths num="212"><img id="000122" he="26" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1109: Conversion information W<sub>2</sub>Generation step) Conversion information W<sub>2</sub>The generation unit 454 uses the processing device to convert information W.<sub>2,0</sub>, W<sub>2,t</sub>, W<sub>2, u</sub>Is generated as shown in the number 213.<maths num="213"><img id="000123" he="39" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1110: Conversion information W<sub>2</sub>Encryption step) Conversion information W<sub>2</sub>The encryption unit 455 calculates the number 214 by the processing device, and the conversion information W<sub>2,0</sub>, W<sub>2,t</sub>, W<sub>2, u</sub>Is encrypted by functional encryption, and the encryption conversion information ct<sup>renc</sup><sub>S'</sub> (ψ<sup>renc</sup>) Is generated. Conversion information W<sub>2,0</sub>, W<sub>2,t</sub>, W<sub>2, u</sub>Is encrypted by functional encryption with the attribute information Γ'as input, so the reciphertext rct<sub>Γ'</sub>The attribute information of the user who can decrypt is set and encrypted.<maths num="214"><img id="000124" he="30" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1111: Ciphertext c<sup>renc</sup>Generation step) Ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to generate the ciphertext c.<sup>renc</sup><sub>0</sub>Is generated as shown in the number 215.<maths num="215"><img id="000125" he="18" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to generate the ciphertext c for each integer t included in the attribute information Γ.<sup>renc</sup><sub>t</sub>Is generated as shown in the number 216.<maths num="216"><img id="000126" he="18" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to generate the ciphertext c.<sup>renc</sup><sub>T</sub>Is generated as shown in the number 217.<maths num="217"><img id="000127" he="18" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the ciphertext c<sup>renc</sup>The generation unit 456 uses the processing device to determine the attribute information Γ.<sup>~</sup>For each integer u contained in, the ciphertext c<sup>renc</sup><sub>u</sub>Is generated as shown in the number 218.<maths num="218"><img id="000128" he="18" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1112: Decryption key k<sup>* renc</sup>Generation step) Decryption key k<sup>* renc</sup>The generation unit 457 uses a processing device to obtain a decryption key k.<sup>* renc</sup><sub>0</sub>Is generated as shown in the number 219.<maths num="219"><img id="000129" he="16" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* renc</sup>The generation unit 457 uses the processing device to perform the decryption key k for each integer i of i = 1, ..., L.<sup>* renc</sup><sub>i</sub>Is generated as shown in the number 220.<maths num="220"><img id="000130" he="71" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Also, the decryption key k<sup>* renc</sup>The generator 457 has j = 1, ..., L depending on the processing device.<sup>~</sup>For each integer j in, the decryption key k<sup>~ * renc</sup><sub>j</sub>Is generated as shown in the number 221.<maths num="221"><img id="000131" he="71" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1113: Re-ciphertext transmission step) The reciphertext transmission unit 460 uses the attribute set Γ', Γ, Γ.<sup>~</sup>And access structure S, S<sup>~</sup>And the decryption key k<sup>* renc</sup><sub>0</sub>, k<sup>* renc</sup><sub>i</sub>, k<sup>~ * renc</sup><sub>j</sub>And the ciphertext c<sup>renc</sup><sub>0</sub>, c<sup>renc</sup><sub>t</sub>, c<sup>renc</sup><sub>T</sub>, c<sup>~ renc</sup><sub>u</sub>And encryption conversion information ct<sup>rk</sup><sub>Γ'</sub>And ct<sup>renc</sup><sub>Γ'</sub>Re-ciphertext rct with and as an element<sub>Γ'</sub>Is secretly transmitted to the reciphertext decryption device 500 via the network, for example, by a communication device. Of course, the reciphertext rct<sub>Γ'</sub>May be transmitted to the re-ciphertext decryption device 500 by other methods.
That is, in (S1101) to (S1112), the re-encryption device 400 executes the REnc algorithm shown in the numbers 222-1, 222-2, and 222-3, and re-encrypts the CT.<sub>Γ'</sub>To generate. Then, in (S1113), the re-encryption device 400 generated the re-encryption sentence CT.<sub>Γ'</sub>To the re-ciphertext decryption device 500.<maths num="222-1"><img id="000132" he="195" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="222-2"><img id="000133" he="155" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="222-3"><img id="000134" he="111" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The functions and operations of the re-ciphertext decryption device 500 will be described. As shown in FIG. 23, the re-ciphertext decryption device 500 includes a decryption key receiving unit 510, a ciphertext receiving unit 520, a span program calculation unit 530, a complement coefficient calculation unit 540, a conversion information generation unit 550, a conversion unit 560, and a pair. It has a ring calculation unit 570 and a message calculation unit 580. The pairing calculation unit 570 and the message calculation unit 580 are collectively referred to as a decoding unit.
The processing of the Dec1 algorithm will be described with reference to FIG. 28. (S1201: Decryption key reception step) The decryption key receiving unit 510 is, for example, a decryption key sk transmitted from the key generation device 100 via a network by a communication device.<sub>S'</sub>To receive. Further, the decryption key receiving unit 310 receives the public parameter pk generated by the key generation device 100.
(S1202: Ciphertext reception step) The ciphertext receiving unit 520 uses, for example, the re-encryption text rct transmitted by the re-encryption device 400 via the network by the communication device.<sub>Γ'</sub>To receive.
(S1203: Span program calculation step) The span program calculation unit 530 uses the processing device to perform the decryption key sk.<sub>S'</sub>The access structure S'contained in is the reciphertext rct<sub>Γ'</sub>Accepts Γ'contained in, and re-ciphertext rct<sub>Γ'</sub>Access structure S included in<sup>~</sup>But the reciphertext rct<sub>Γ'</sub>Γ contained in<sup>~</sup>Judge whether or not to accept. Whether or not access structure S'accepts Γ', and access structure S<sup>~</sup>Is Γ<sup>~</sup>The method of determining whether or not to accept the above is as described in "3. Concept for realizing FCPRE" in the first embodiment. In the span program calculation unit 530, the access structure S'accepts Γ'and the access structure S'<sup>~</sup>Is Γ<sup>~</sup>Is accepted (accepted by S1203), the process proceeds to (S1204). On the other hand, access structure S'rejects Γ', or access structure S<sup>~</sup>Is Γ<sup>~</sup>(Rejected by S1203), the process ends.
(S1204: Complementary coefficient calculation step) The complement coefficient calculation unit 540 has I, J, which is the number 223, and a constant (complement coefficient) {α, depending on the processing device.<sub>i</sub>}<sub>i I</sub>, {α<sup>~</sup><sub>j</sub>}<sub>j J</sub>And calculate.<maths num="223"><img id="000135" he="78" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1205: Conversion information generation step) The conversion information generation unit 550 uses the processing device to convert the conversion information W.<sub>1,0</sub>, W<sub>1,t</sub>, W<sup>~</sup><sub>1, u</sub>, W<sub>2,0</sub>, W<sub>2,t</sub>, W<sup>~</sup><sub>2, u</sub>Is generated as shown in the number 224.<maths num="224"><img id="000136" he="54" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1206: Conversion step) The conversion unit 560 uses the processing device to perform the decryption key k, as shown in Equation 225.<sup>*</sup><sub>0</sub>, k<sup>*</sup><sub>i</sub>, k<sup>~*</sup><sub>j</sub>And the ciphertext c<sub>0</sub>, c<sub>t</sub>, c<sup>~</sup><sub>u</sub>To generate.<maths num="225"><img id="000137" he="67" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1207: Pairing calculation step) The pairing calculation unit 570 calculates the number 226 by the processing device, and the session key K<sup>~</sup>To generate.<maths num="226"><img id="000138" he="80" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1208: Message calculation step) The message calculation unit 580 has m'= c depending on the processing device.<sup>~ renc</sup><sub>T</sub>/ K<sup>~</sup>To generate the message m'(= m).
That is, in (S1201) to (S1208), the reciphertext decryption device 500 executes the Dec1 algorithm shown in the equations 227-1 and 227-2 to generate the message m'(= m).<maths num="227-1"><img id="000139" he="172" wi="159" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths><maths num="227-2"><img id="000140" he="168" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The processing of the Dec2 algorithm will be described with reference to FIG. 29. (S1301: Decryption key reception step) The decryption key receiving unit 310 is, for example, a decryption key sk transmitted from the key generation device 100 via a network by a communication device.<sub>S</sub>To receive. Further, the decryption key receiving unit 310 receives the public parameter pk generated by the key generation device 100.
(S1302: Ciphertext reception step) The ciphertext receiving unit 350 is, for example, a ciphertext ct transmitted by the re-encrypting device 400 via a network by a communication device.<sub>Γ</sub>To receive.
(S1303: Span program calculation step) The span program calculation unit 361 uses the processing device to perform the decryption key sk.<sub>S</sub>The access structure S contained in is the ciphertext ct<sub>Γ</sub>Determine whether or not to accept the Γ contained in. The method for determining whether or not the access structure S accepts Γ is as described in 3. Concept for realizing FCPRE in the first embodiment. When the access structure S accepts Γ (accepted by S1303), the span program calculation unit 361 proceeds to process (S1304). On the other hand, if the access structure S rejects Γ (rejected by S1303), the process ends.
(S1304: Signature verification step) The signature verification unit 362 determines whether or not the result of calculating the number 228 is 1 by the processing device. If the result is 1 (valid in S1304), the signature verification unit 362 proceeds to process (S1305). On the other hand, when the result is 0 (injustice in S1304), the signature verification unit 362 ends the process.<maths num="228"><img id="000141" he="41" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1305: Complementary coefficient calculation step) The complement coefficient calculation unit 370 has an I, which is the number 229, and a constant (complement coefficient) {α, depending on the processing device.<sub>i</sub>}<sub>i I</sub>And calculate.<maths num="229"><img id="000142" he="48" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1306: Pairing calculation step) The pairing calculation unit 380 calculates the number 230 by the processing device and generates the session key K.<maths num="230"><img id="000143" he="40" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
(S1307: Message calculation step) The message calculation unit 390 uses m'= c depending on the processing device.<sup>enc</sup><sub>d + 1</sub>Calculate / K to generate message m'(= m).
That is, in (S1301) to (S1307), the decoding device 300 executes the Dec2 algorithm shown in Equation 231 to generate the message m'(= m).<maths num="231"><img id="000144" he="144" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
As described above, the encryption system according to the second embodiment can realize the KP-FCPRE method. Therefore, one re-encryption key can transfer ciphertext to various types of user sets. Furthermore, it becomes possible to specify a condition for specifying a ciphertext to be re-encrypted.
In the above description, the decryption device 300 also serves as the re-encryption key generator, and the decryption device 300 executes not only the Dec2 algorithm but also the RKG algorithm. However, the decryption device 300 and the re-encryption key generation device may be separate devices. In this case, the decryption device 300 executes the Dec2 algorithm, and the re-encryption key generator executes the RKG algorithm. Therefore, in this case, the decryption device 300 has the functional configuration required to execute the Dec2 algorithm, and the re-encryption key generator has the functional configuration required to execute the RKG algorithm.
Also, in the above explanation, N<sub>t</sub>To n<sub>t</sub>+ w<sub>t</sub>+ z<sub>t</sub>I set +1. But N<sub>t</sub>To n<sub>t</sub>+ w<sub>t</sub>+ z<sub>t</sub>+ β<sub>t</sub>May be set. Here, β<sub>t</sub>Is an integer greater than or equal to 0. Also, in the above explanation, N<sub>0</sub>Was set to 9. But N<sub>0</sub>1 + 1 + 2 + w<sub>0</sub>+ z<sub>0</sub>+ β<sub>0</sub>May be set. Where w<sub>0</sub>, z<sub>0</sub>, β<sub>0</sub>Is an integer greater than or equal to 0.
Further, in the above description, the ciphertext c generated in S1111<sup>~ renc</sup><sub>0</sub>Π'(verk, 1) is the additional information Η, and the decryption key k generated by S1112<sup>* renc</sup><sub>0</sub>Σ (-1, verk) is the additional information Θ. Additional information Η, Θ correspond and are canceled by the pairing operation performed on S1207. In addition, although there is a risk that the security may be slightly reduced, a value such as a random number may be included in the additional information instead of verk.
In the above embodiment, assuming a case where the message is encrypted by FE and sent to the destination, the re-encryption device 400 re-encrypts the ciphertext and changes the destination of the ciphertext. FE can realize not only the function of encrypting a message and sending it to a destination, but also a searchable encryption that makes it searchable without decrypting the ciphertext. When the searchable encryption is realized by FE, the set search keyword can be changed by the algorithm described in the above embodiment. In the above embodiment, a user who can decrypt the attribute information set in the ciphertext is specified. Then, by changing the attribute information, the destination of the ciphertext was changed. When the searchable encryption is realized by FE, a part of the attribute information set in the ciphertext specifies a searchable user, and a part of the remaining attribute information specifies a search keyword. Therefore, it is possible to change the set search keyword by changing the portion of the attribute information in which the search keyword is specified by using the algorithm described in the above embodiment.
Further, in the above embodiment, it is assumed that one key generation device 100 generates a decryption key. However, it is also possible to combine the algorithm of the above embodiment with the distributed multi-administrator method described in Non-Patent Document 5 so that a plurality of key generators 100 generate one decryption key. Is.
Further, in the above embodiment, when adding an attribute category (attribute format n).<sup>→</sup>(If you want to increase the value of d in), you had to reissue the public parameters. However, it is also possible to combine the algorithm of the above embodiment with the Unbounded method described in Non-Patent Document 6 so that attribute categories can be added without reissuing the published parameters.
Further, in the above embodiment, assuming that the length of the vector used for the inner product encryption is N, the size of the public parameter and the master private key is N.<sup>2</sup>N for the generation of decryption key and encryption processing given to the user in proportion to<sup>2</sup>It takes time proportional to. However, by combining the algorithm of the above embodiment with the method described in Non-Patent Document 7, the size of the public parameter and the master private key can be reduced, and the processing and encryption of the decryption key to be given to the user can be performed. It is also possible to shorten the processing time.
Further, in the above embodiment, it is assumed that the key or the ciphertext is transmitted to the destination device. However, instead of this, the key or ciphertext may be output to a storage medium such as a CD or DVD so that the destination device reads the storage medium.
Embodiment 3. In the above embodiment, a method of realizing cryptographic processing in the dual vector space has been described. In the third embodiment, a method of realizing cryptographic processing in a dual module will be described.
That is, in the above embodiment, the cryptographic processing is realized in the cyclic group of the prime number q. However, when the ring R is represented by the composite number M as in the number 232, the cryptographic processing described in the above embodiment can be applied to the module having the ring R as a coefficient.<maths num="232"><img id="000145" he="45" wi="158" file="JP6022073B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
F in the algorithm described in the above embodiment<sub>q</sub>By changing to R, cryptographic processing in a dual module can be realized.
In the above embodiment, from the viewpoint of proof of security, ρ (i) for each integer i of i = 1, ..., L is a set of affirmative forms for different identification information t ( t, v<sup>→</sup>) Or the negative set ¬ (t, v<sup>→</sup>) May be limited. In other words, ρ (i) = (t, v<sup>→</sup>) Or ρ (i) = ¬ (t, v<sup>→</sup>), Let the function ρ ~ be a mapping of {1, ..., L} {1, ... d} where ρ ~ (i) = t. In this case, ρ ~ may be limited to injective. Note that ρ (i) is ρ (i) of the above-mentioned access structure S: = (M, ρ (i)).
Next, the hardware configuration of the encryption system 10 (key generation device 100, encryption device 200, decryption device 300, re-encryption device 400, re-ciphertext decryption device 500) in the embodiment will be described. FIG. 30 is a diagram showing an example of the hardware configuration of the key generation device 100, the encryption device 200, the decryption device 300, the re-encryption device 400, and the re-encryption text decryption device 500. As shown in FIG. 30, the key generator 100, the encryption device 200, the decryption device 300, the re-encryption device 400, and the re-encryption message decryption device 500 are CPU911s (Central Processing Units) that execute programs. , Processing device, computing device, microprocessor, microcomputer, processor). CPU911 is ROM913, RAM914, LCD901 (Liquid Crystal) via bus 912. It is connected to Display), keyboard 902 (K / B), communication board 915, and magnetic disk device 920 to control these hardware devices. Instead of the magnetic disk device 920 (fixed disk device), a storage device such as an optical disk device or a memory card read / write device may be used. The magnetic disk device 920 is connected via a predetermined fixed disk interface.
ROM913 and magnetic disk device 920 are examples of non-volatile memory. RAM914 is an example of volatile memory. The ROM 913, RAM 914, and magnetic disk device 920 are examples of storage devices (memory). The keyboard 902 and the communication board 915 are examples of input devices. The communication board 915 is an example of a communication device. Further, the LCD901 is an example of a display device.
The operating system 921 (OS), the window system 922, the program group 923, and the file group 924 are stored in the magnetic disk device 920 or ROM 913. The programs of the program group 923 are executed by the CPU 911, the operating system 921, and the window system 922.
In the above description, the program group 923 includes "master key generation unit 110", "master key storage unit 120", "information input unit 130", "decryption key generation unit 140", "key transmission unit 150", and "publication". Parameter receiving unit 210 , Information input unit 220 , Signing processing unit 230 , Encryption unit 240 , Cryptographic text transmitting unit 250 , Decryption key receiving unit 310 , Information input unit 320 , "Re-encryption key generation unit 330", "Re-encryption key transmission unit 340", "Cryptography reception unit 350", "Verification unit 360", "Complementary coefficient calculation unit 370", "Pairing calculation unit 380", "Message calculation unit 390", "Public parameter reception unit 410", "Cryptography reception unit 420", "Re-encryption key reception unit 430", "Verification unit 440", "Encryption unit 450", "Re-encryption text" "Sender 460", "Decryption key receiver 510", "Cryptographic receiver 520", "Span program calculation unit 530", "Complementary coefficient calculation unit 540", "Conversion information generation unit 550", "Conversion unit 560" , "Pairing calculation unit 570", "Message calculation unit 580", and other software, programs, and other programs that execute the functions described above are stored. The program is read and executed by CPU911. In the file group 924, "public parameter pk", "master private key sk", and "decryption key sk" are described in the above description.<sub>S</sub>, sk<sub>Γ</sub>, "Ciphertext ct<sub>Γ</sub>, ct<sub>S</sub>, "Re-encryption key rk<sub>Γ, S'</sub>, rk<sub>S, Γ'</sub>, "Reciphertext rct<sub>S'</sub>, rct<sub>Γ'</sub>, "Access Structure S, S', S<sup>~</sup>, "Attribute set Γ, Γ', Γ<sup>~</sup>, "Message m" and other information, data, signal values, variable values and parameters are stored as each item of "file" and "database". The "file" and "database" are stored in a recording medium such as a disk or memory. Information, data, signal values, variable values, and parameters stored in a storage medium such as a disk or memory are read into the main memory or cache memory by the CPU 911 via a read / write circuit, and are extracted, searched, referenced, compared, and calculated. -Used for CPU 911 operations such as calculation, processing, output, printing, and display. Information, data, signal values, variable values, and parameters are temporarily stored in the main memory, cache memory, and buffer memory during the operation of CPU911 for extraction, search, reference, comparison, calculation, calculation, processing, output, printing, and display. Is remembered in.
Further, the arrow portion of the flowchart in the above description mainly indicates the input / output of data or signal, and the data or signal value is recorded in the memory of RAM914, other recording medium such as an optical disk, or an IC chip. In addition, data and signals are transmitted online by bus 912, signal lines, cables, other transmission media, and radio waves. Further, what is described as "~ part" in the above description may be "~ circuit", "~ device", "~ device", "~ means", "~ function", or "~ function". It may be "step", "~ procedure", or "~ processing". Further, what is described as "~ device" may be "~ circuit", "~ device", "~ means", "~ function", and also "~ step", "~ procedure", "~ step". ~ Processing "may be used. Further, what is described as "~ processing" may be "~ step". That is, what is described as "~ part" may be realized by the firmware stored in the ROM 913. Alternatively, it may be implemented only by software, only hardware such as elements, devices, boards, and wiring, or a combination of software and hardware, or a combination of firmware. The firmware and software are stored as a program in a recording medium such as ROM913. The program is read by CPU911 and executed by CPU911. That is, the program functions a computer or the like as the "~ part" described above. Alternatively, the computer or the like is made to execute the procedure or method of "~ part" described above.
100 key generator, 110 master key generator, 120 master key storage unit, 130 information input unit, 140 decryption key generator, 141 CP-FE key generator, 142 random number generator, 143 decryption key k<sup>*</sup>Generation unit, 144 KP-FE key generation unit, 145 f vector generation unit, 146 s vector generation unit, 150 key transmission unit, 200 encryption device, 210 public parameter receiver, 220 information input unit, 230 signature processing unit, 240 Encryption unit, 241 f vector generation unit, 242 s vector generation unit, 243 random number generation unit, 244 ciphertext c generation unit, 250 ciphertext transmission unit, 300 decryption device, 310 decryption key receiver, 320 information input unit, 330 Re-encryption key generator, 331 random number generator, 332 conversion information W<sub>1</sub>Generator, 333 Conversion information W<sub>1</sub>Encryption part, 334 Decryption key k<sup>* rk</sup>Generation unit, 335 conversion unit, 336 f vector generation unit, 337 s vector generation unit, 340 re-encryption key transmission unit, 350 ciphertext reception unit, 360 verification unit, 361 span program calculation unit, 362 signature verification unit, 370 completion Coefficient calculation unit, 380 pairing calculation unit, 390 message calculation unit, 400 re-encryption device, 410 public parameter reception unit, 420 ciphertext reception unit, 430 re-encryption key reception unit, 440 verification unit, 441 span program calculation unit , 442 Sign verification unit, 450 encryption unit, 451 random number generation unit, 452 f vector generation unit, 453 s vector generation unit, 454 conversion information W<sub>2</sub>Generator, 455 Conversion information W<sub>2</sub>Cryptographic unit, 456 Ciphertext c<sup>renc</sup>Generator, 457 Decryption key k<sup>* renc</sup>Generation unit, 460 re-ciphertext transmitter, 500 re-ciphertext decryption device, 510 decryption key receiver, 520 ciphertext receiver, 530 span program calculation unit, 540 complement coefficient calculation unit, 550 conversion information generation unit, 560 conversion unit , 570 Pairing calculator, 580 Message calculator.
188 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84 Sheet 85 Sheet 86 Sheet 87 Sheet 88 Sheet 89 Sheet 90 Sheet 91 Sheet 92 Sheet 93 Sheet 94 Sheet 95 Sheet 96 Sheet 97 Sheet 98 Sheet 99 Sheet 100 Sheet 101 Sheet 102 Sheet 103 Sheet 104 Sheet 105 Sheet 106 Sheet 107 Sheet 108 Sheet 109 Sheet 110 Sheet 111 Sheet 112 Sheet 113 Sheet 114 Sheet 115 Sheet 116 Sheet 117 Sheet 118 Sheet 119 Sheet 120 Sheet 121 Sheet 122 Sheet 123 Sheet 124 Sheet 125 Sheet 126 Sheet 127 Sheet 128 Sheet 129 Sheet 130 Sheet 131 Sheet 132 Sheet 133 Sheet 134 Sheet 135 Sheet 136 Sheet 137 Sheet 138 Sheet 139 Sheet 140 Sheet 141 Sheet 142 Sheet 143 Sheet 144 Sheet 145 Sheet 146 Sheet 147 Sheet 148 Sheet 149 Sheet 150 Sheet 151 Sheet 152 Sheet 153 Sheet 154 Sheet 155 Sheet 156 Sheet 157 Sheet 158 Sheet 159 Sheet 160 Sheet 161 Sheet 162 Sheet 163 Sheet 164 Sheet 165 Sheet 166 Sheet 167 Sheet 168 Sheet 169 Sheet 170 Sheet 171 Sheet 172 Sheet 173 Sheet 174 Sheet 175 Sheet 176 Sheet 177 Sheet 178 Sheet 179 Sheet 180 Sheet 181 Sheet 182 Sheet 183 Sheet 184 Sheet 185 Sheet 186 Sheet 187 Sheet 188
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2013105065A | Cites | Japan | Search report |
| JP2013105065A | Cites | Japan | Examiner |
| JPH11112491A | Cites | Japan | Examiner |
| JP11112491A | Cites | Japan | – |
| JP2013105065A | Cites | Japan | – |
| JPN7013004333; Jian WENG et al.: 'Conditional proxy re-encryption secure against chosen-ciphertext attack' Proceedings of the 4th International Symposium on Information, Computer, and Communications Security , 2009, pp. 322-332, ACM | Non-patent | – | Search report |
| JPN6013058811; Yutaka KAWAI et al.: 'Fully-Anonymous Functional Proxy-Re-Encryption' Cryptology ePrint Archive Report 2013/318,Ver. 20130602:132251, 20130602, International Association for Cryptologic Research | Non-patent | – | Examiner |
| JPN7013004333; Jian WENG et al.: 'Conditional proxy re-encryption secure against chosen-ciphertext attack' Proceedings of the 4th International Symposium on Information, Computer, and Communications Security , 2009, pp. 322-332, ACM | Non-patent | – | Examiner |
| Yutaka KAWAI et al.,Fully-Anonymous Functional Proxy-Re-Encryption,Cryptology ePrint Archive,International Association for Cryptologic Research,2013年 6月 2日,Report 2013/318,Ver. 20130602:132251,[2013年11月21日検索],インターネット,URL,http://eprint.iacr.org/2013/318/20130602:132251 | Non-patent | – | – |
| Jian WENG et al.,Conditional proxy re-encryption secure against chosen-ciphertext attack,Proceedings of the 4th International Symposium on Information, Computer, and Communications Security,ACM,2009年,pp. 322-332,URL,http://dl.acm.org/citation.cfm?id=1533100 | Non-patent | – | – |
10 members in 5 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2013077491 | Japan | W | |
| 2013077491 | Japan | W | |
| JP2013077491 | – | – | – |
| WO2013JP77491 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| WO2015052799A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN105637799A | China | A | |
| US2016234012A1 | United States of America | A1 | |
| EP3057262A1 | European Patent Office (EPO) | A1 | |
| JP6022073B2This record | Japan | B2 | |
| JPWO2015052799A1 | Japan | A1 | |
| EP3057262A4 | European Patent Office (EPO) | A4 | |
| US9979536B2 | United States of America | B2 | |
| CN105637799B | China | B | |
| EP3057262B1 | European Patent Office (EPO) | B1 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 6022073
- Publication, DOCDB
- 6022073
- Publication, EPODOC
- JP6022073B
- Application
- 2015541368
- Application, DOCDB
- 2015541368
- Application, EPODOC
- JP20150541368
Titles2
- Japanese
- 暗号システム、再暗号化鍵生成装置及び再暗号化装置
- English
- Cryptographic system, re-encryption key generator and re-encryption device
Classification
- CPC, 4
- H04L9/30
- H04L9/0618
- H04L2209/76
- H04L9/0861
- IPC, 2
- G09C1 00
- H04L9 08
