Cryptosystem, encryption device, decryption device, and key generation device

By using the Richelot homologous sequence of the Abelian surfaces A0 and As as the key in the SETA encryption method, the problem of excessively long decryption time in the SETA encryption method is solved, and the decryption time is significantly shortened.

CN116194977BActive Publication Date: 2026-03-17MITSUBISHI ELECTRIC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080105252.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-23
Publication Date
2026-03-17
Estimated Expiration
2040-09-23

AI Technical Summary

Technical Problem

In the SETA encryption method, the decryption process takes a lot of time, and existing technologies are unable to effectively reduce the decryption time.

Method used

The Richelot homologous sequence, with Abelian surface A0 as the starting point and Abelian surface As as the ending point, is used as the secret key, and Abelian surface As is set as the public key. Encryption and decryption are performed using the Richelot homologous sequence.

Benefits of technology

By shortening the length of the prime number p in the SETA encryption method to 1/3, the time required for decryption is significantly reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116194977B_ABST
    Figure CN116194977B_ABST
Patent Text Reader

Abstract

The cryptographic system (1) performs a cryptographic process in which a Richelot homology sequence which starts from an Abelian surface A0 and ends at an Abelian surface A s is set as a secret key, and the Abelian surface A s is set as a public key. The encryption device (20) generates a Richelot homology sequence which moves the Abelian surface A s as the public key by encoding a plaintext m, and calculates the Abelian surface A m as a ciphertext. The decryption device (30) calculates a Richelot homology sequence which starts from the Abelian surface A m as the public key and ends at the Abelian surface A s as the ciphertext, based on the Richelot homology sequence as the secret key. The decryption device (30) decrypts the ciphertext by moving the Abelian surface A m as the ciphertext by the Richelot homology sequence as the secret key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to homologous cryptography. Background Technology

[0002] There are homologous cryptosystems such as SIDH (Supersingular Isogeny Diffie-Hellman key exchange) and SIKE (Supersingular Isogeny Key Encapsulation).

[0003] In homologous cryptography such as SIDH and SIKE, security cannot be based on the difficulty of the underlying homologous problem. Instead, it needs to be based on the difficulty of a SIDH-type homologous problem that requires providing auxiliary information from the points of the elliptic curve to the attacker (interpreter). Therefore, in SIDH-type homologous cryptography, the desired approach is to construct a method that bases security on the difficulty of the underlying homologous problem without any auxiliary information.

[0004] Non-patent document 1 describes a SIDH-type same-origin cipher, namely SETA encryption, which makes security based on the difficulty of the same-origin problem without auxiliary information.

[0005] Existing technical documents

[0006] Non-patent literature

[0007] Non-patent literature 1: CDS Guilhem, P. Kutas, C. Petit, J. Silva, SETA: Supersingular Encryption from Torsion Attacks.

[0008] Non-patent literature 2: C. Petit, Faster Algorithms for Isogeny Problems using Torsion Point Images. Summary of the Invention

[0009] The problem that the invention aims to solve

[0010] In the SETA encryption method, the decryption algorithm uses the cipher decryption method described in Non-Patent Document 2. Therefore, decryption takes a very long time.

[0011] The purpose of this invention is to reduce the time spent on decryption in the SETA encryption method.

[0012] Methods for solving problems

[0013] The cryptographic system of this invention will start from the Abelian surface A0 and proceed from the Abelian surface A s Richelot isogeny sequences ending with a Richelot terminus. Set as the secret key, and set the Abel surface A s Cryptographic processing using public keys, wherein the cryptographic system comprises: an encryption device that generates a Richelot homologous sequence by encoding plaintext m. The movement of the Abel surface A as the public key s And calculating the Abelian surface A m The Abel surface A m The method is configured as ciphertext; and a decryption device is configured based on the Richelot homologous sequence as a secret key. Calculate the Abel surface A as the public key. s Starting from point A and taking the Abel surface A as the ciphertext, m Richelot isogeny with the endpoint being Richelot homology.

[0014] Invention Effects

[0015] In this invention, the Abelian surface A0 is taken as the starting point and the Abelian surface A is taken as the starting point. s Richelot homologous sequences ending with Set as the secret key, and set the Abel surface A s Let this be the public key. This allows the length of the prime number p in the SETA encryption method to be 1 / 3. As a result, the time spent decrypting in the SETA encryption method can be reduced. Attached Figure Description

[0016] Figure 1 This is a structural diagram of the cryptographic system 1 according to implementation method 1.

[0017] Figure 2 This is a structural diagram of the key generation device 10 according to Embodiment 1.

[0018] Figure 3 This is a structural diagram of the encryption device 20 in Implementation Method 1.

[0019] Figure 4 This is a structural diagram of the decryption device 30 in Embodiment 1.

[0020] Figure 5 The number of curves C0, ..., C in implementation method 1 is 2. κThe flowchart for the calculation process.

[0021] Figure 6 This is an illustration of the SETA encryption method.

[0022] Figure 7 This is an explanatory diagram of the number 2SETA cryptographic method of implementation method 1.

[0023] Figure 8 This is a flowchart illustrating the operation of the key generation device 10 according to Embodiment 1.

[0024] Figure 9 This is a flowchart illustrating the operation of the encryption device 20 in Embodiment 1.

[0025] Figure 10 This is a flowchart illustrating the operation of the decryption device 30 in Embodiment 1.

[0026] Figure 11 This is a structural diagram of the key generation device 10 in Modified Example 1.

[0027] Figure 12 This is a structural diagram of the encryption device 20 in Modified Example 1.

[0028] Figure 13 This is a structural diagram of the decryption device 30 in Modified Example 1. Detailed Implementation

[0029] Implementation Method 1

[0030] ***Structure Description***

[0031] Reference Figure 1 The structure of the cryptographic system 1 in Implementation 1 will be described.

[0032] The cryptographic system 1 has a key generation device 10, an encryption device 20, and a decryption device 30. The key generation device 10, the encryption device 20, and the decryption device 30 are connected via a communication path 40 such as a LAN (Local Area Network) and the Internet.

[0033] Reference Figure 2 The structure of the key generation device 10 in Embodiment 1 will be described.

[0034] The key generation device 10 is a computer.

[0035] The key generation device 10 has hardware such as a processor 11, memory 12, storage 13, and communication interface 14. The processor 11 is connected to other hardware via signal lines and controls these other hardware components.

[0036] As functional structural elements, the key generation device 10 includes an acquisition unit 111, a mapping calculation unit 112, and a key setting unit 113. The functions of each functional structural element of the key generation device 10 are implemented by software.

[0037] The memory 13 stores a program that implements the functions of each functional structural element of the key generation device 10. This program is read into the memory 12 by the processor 11 and executed by the processor 11. Thus, the functions of each functional structural element of the key generation device 10 are implemented.

[0038] Reference Figure 3 The structure of the encryption device 20 in Embodiment 1 will be described.

[0039] The encryption device 20 is a computer.

[0040] The encryption device 20 has hardware such as a processor 21, memory 22, storage 23, and communication interface 24. The processor 21 is connected to other hardware via signal lines and controls these other hardware components.

[0041] As functional structural elements, the encryption device 20 has an acquisition unit 211 and an encryption unit 212. The functions of each functional structural element of the encryption device 20 are implemented by software.

[0042] The memory 23 stores programs that implement the functions of each functional structural element of the encryption device 20. These programs are read into the memory 22 by the processor 21 and executed by the processor 21. Thus, the functions of each functional structural element of the encryption device 20 are implemented.

[0043] Reference Figure 4 The structure of the decryption device 30 in Embodiment 1 will be described.

[0044] The decryption device 30 is a computer.

[0045] The decryption device 30 has hardware such as a processor 31, memory 32, storage 33, and communication interface 34. The processor 31 is connected to other hardware via signal lines and controls these other hardware components.

[0046] As functional structural elements, the decryption device 30 has an acquisition unit 311 and a decryption unit 312. The functions of each functional structural element of the decryption device 30 are implemented by software.

[0047] The memory 33 stores programs that implement the functions of each functional structural element of the decryption device 30. These programs are read into the memory 32 by the processor 31 and executed by the processor 31. Thus, the functions of each functional structural element of the decryption device 30 are implemented.

[0048] Processors 11, 21, and 31 are ICs (Integrated Circuits) that perform processing. As specific examples, processors 11, 21, and 31 are CPUs (Central Processing Units), DSPs (Digital Signal Processors), and GPUs (Graphics Processing Units).

[0049] Memory modules 12, 22, and 32 are temporary storage devices for data. Specifically, memory modules 12, 22, and 32 are SRAM (Static Random Access Memory) and DRAM (Dynamic Random Access Memory).

[0050] Memory devices 13, 23, and 33 are storage devices for storing data. Specifically, memory devices 13, 23, and 33 are HDDs (Hard Disk Drives). Alternatively, memory devices 13, 23, and 33 can also be removable recording media such as SD (Secure Digital) memory cards, CF (Compact Flash) memory, NAND flash memory, floppy disks, optical discs, high-density disks, Blu-ray discs, and DVDs (Digital Versatile Disks).

[0051] Communication interfaces 14, 24, and 34 are interfaces used for communication with external devices. Specifically, communication interfaces 14, 24, and 34 are ports for Ethernet (registered trademark), USB (Universal Serial Bus), and HDMI (registered trademark, High-Definition Multimedia Interface).

[0052] exist Figure 2 In this diagram, only one processor 11 is shown. However, there can be multiple processors 11, and multiple processors 11 can cooperate to execute programs that perform various functions. Similarly, there can be multiple processors 21 and 31.

[0053] ***Instructions for Action***

[0054] Reference Figures 5-10 The operation of the cryptographic system 1 in Implementation 1 will be explained.

[0055] The operation steps of the cryptographic system 1 in Embodiment 1 are equivalent to the cryptographic method in Embodiment 1. Furthermore, the program that implements the operation of the cryptographic system 1 in Embodiment 1 is equivalent to the cryptographic program in Embodiment 1.

[0056] **Explanation of Concepts**

[0057] The basic concepts of the cryptographic method implemented by the cryptographic system 1 of Implementation Method 1 will be explained.

[0058] In Non-Patent Document 1, an elliptic curve is used. Cryptosystem 1 uses a type 2 curve instead of an elliptic curve.

[0059] The number of curves used in cryptosystem 1 is an algebraic curve as shown in mathematical formula 11. Here, the degree deg(f(X)) is 5 or 6.

[0060]

Mathematical Expression 11

[0061] C:Y2=f(X)

[0062] As shown in mathematical formula 12, starting from a certain number of 2 curve C0, the curve from the number of 2 curves to the endpoint C is... κ Up to this point, the Richelot homology curve is repeatedly shifted κ times, resulting in a total of 2 possible curves. Here, κ is an integer greater than 2.

[0063]

Mathematical Expression 12

[0064]

[0065] Given curves C0 and C with two possible values. κ In the case of these two number-2 curves, cryptosystem 1 will find (compute) a pair of number-2 curves C0 and C2. κ The Richelot-homogeneous columns ψ0, ψ1, ..., ψ used for interpolation κ-1 As a fundamental problem related to the security of cryptography, and considering the difficulty of this fundamental problem, the cipher system 1 constitutes the number of SETA ciphers 2 based on the difficulty of this fundamental problem.

[0066] Various number-2 curves use deg(G) j The three polynomials G with (X) ≤ 2 j (X) is represented as shown in mathematical formula 13. deg(G) j (X) is a polynomial G j The number of times (X) is used.

[0067]

Mathematical Expression 13

[0068]

[0069] Define a new set of three polynomials G as shown in mathematical expression 14.~ j (X).

[0070]

Mathematical Expression 14

[0071]

[0072]

[0073] Where, τ j It is [G] j+1 (X), G j+2 The coefficient of the highest order of (X)]. Therefore, G ~ j (X) is a polynomial of the highest degree with a coefficient of 1. Furthermore, G' j+1 (X) is G j+1 The differential of (X), G' j+2 (X) is G j+2 The differential of (X). Furthermore, the subscripts are assumed to represent the three polynomials G. j G is assigned as a sequence for processing, in the case of j=0. j+1 G(X) is G1(X) when j=1. j+1 G(X) is G2(X) when j = 2. j+1 (X) is G0(X). Similarly, G in the case of j=0 j+2 (X) is G2(X), j=1. j+2 (X) is G0(X), j=2. j+2 (X) is G1(X).

[0074] Define a new type 2 curve C as shown in mathematical formula 15. ~ .

[0075]

Mathematical Expression 15

[0076]

[0077]

[0078] From curve C with 2 species to curve C with 2 species ~ The correspondence (mapping) is called Richellot homology. Richellot homology starting from curve C of type 2 is determined by the partitions of f(X) (G0(X), G1(X), G2(X). This corresponds to partitioning the zeros of f(X) into three pairs (a0, a1), (a2, a3), and (a4, a5). Furthermore, g will be discussed later.

[0079] **Explanation of the calculation method for the number of curve sequences (2)**

[0080] Cryptosystem 1 repeatedly performs Richelot homology calculations starting from curve C0 of type 2, to compute the series of curves C0, ..., C0 of type 2. κ However, based on three polynomials G... ~ j (X) When calculating Richellot coherence, it returns curve C with 2 possible forms. Therefore, after calculating Richellot coherence once, cryptosystem 1 rearranges the polynomials G. ~ j After changing the roots (zeros) of (X) to the new three polynomials, calculate the Richelot homology.

[0081] Reference Figure 5 For the number of curves C0, ..., C in implementation method 1 κ The calculation and processing will be explained.

[0082] Here, curve C has 2 species. i Defined as shown in mathematical formula 16.

[0083]

Mathematical Expression 16

[0084]

[0085] where

[0086]

[0087] In step S11, according to mathematical formula 14, three new polynomials (G) are generated based on the number of polynomials 2 and the curve C0. i、j (X)) j=0、1、2 Therefore, the number of curves C1 is calculated.

[0088] In step S12, as shown in mathematical expression 17, the three polynomials G are calculated. ~ 1、j Calculate Richelot homology τ 0、j It is [G] 0、j+1 (X), G 0、j+2 The highest order coefficient of (X)].

[0089]

Mathematical Expression 17

[0090]

[0091] Next, up to i = 1, ..., κ-1, for each integer i, the processing of steps S13 and S14 is performed in ascending order.

[0092] In step S13, f is performed. i The zero point of (X) (a) i ,m ) m=0,…,5 The rearrangement. Then, according to mathematical expression 14, generate three new polynomials (G). i、j (X)) j=0、1、2 Therefore, the number of varieties 2 curve C is calculated. i+1 .

[0093] In step S14, as shown in mathematical expression 18, the three polynomials G are calculated. ~ i+1、j Calculate Richelot homology τ i、j It is [G] i、j+1 (X), G i、j+2 The highest order coefficient of (X)].

[0094]

Mathematical Expression 18

[0095]

[0096] **SETA Encryption Method**

[0097] Reference Figure 6 The SETA encryption method described in Non-Patent Document 1 will be explained.

[0098] In the SETA encryption method, elliptic curves E0 and E2 are used. s E m The elliptic curve E0 is a public parameter. The elliptic curve E0 is a special curve with a simple egomorphic loop.

[0099] <Key Generation Processing>

[0100] First, generate a homologous sequence to serve as the secret key. Then, using homologous sequences Calculate the elliptic curve E by moving the elliptic curve E0 s Elliptic curve E s It is set as a public key.

[0101] <Encryption Processing>

[0102] First, the plaintext m is appropriately encoded to convert it into a homologous sequence. Then, using homologous sequences elliptic curve E as public key s Calculate the elliptic curve E m Elliptic curve E m It was set to be encrypted.

[0103] <Decryption Processing>

[0104] Able to use homologous sequences as secret keys The elliptic curve E0 is calculated using its self-similar ring. s The self-homogeneous ring is computed. Therefore, it is possible to use polynomial-time solutions to elliptic curve ET. s Starting from point E and using the elliptic curve E m The homology problem, with the endpoint being homology, can yield homology sequences. The inverse operation of encryption, i.e., decoding, is based on the same source sequence. Calculate the plaintext m.

[0105] Knowing the homologous sequence as the secret key Users can use homologous sequences Make the elliptic curve E s The calculation of the egomorphic ring returns to the calculation of the egomorphic ring of the elliptic curve E0, which is the key to decryption.

[0106] **Number of Types 2: SETA Password Method**

[0107] Reference Figures 7-10 The number of SETA cryptographic methods implemented by the cryptographic system 1 of Implementation Method 1 will be described.

[0108] like Figure 7 As shown, the elliptic curves E0 and E in the SETA encryption method are... s E m Replace them respectively with curves C0 and C with 2 types. s C m homologous sequences Replace them with Richelot homologous sequences respectively This enables the implementation of a 2-SETA cryptographic method.

[0109] Reference Figure 8 The operation of the key generation device 10 in Embodiment 1 will be explained.

[0110] The operation steps of the key generation apparatus 10 in Embodiment 1 are equivalent to the key generation method in Embodiment 1. Furthermore, the program that implements the operation of the key generation apparatus 10 in Embodiment 1 is equivalent to the key generation program in Embodiment 1.

[0111] (Step S111: Obtain processing)

[0112] The number of curves C0 obtained from section 111 as a public parameter is obtained.

[0113] The number of curves C0 is obtained by writing the number 2 to memory 12.

[0114] (Step S112: Mapping calculation processing)

[0115] Mapping calculation unit 112 calculates the Richelot homology of curve C0 obtained in step S111. The number of 2-curves C1 is calculated. Furthermore, the mapping calculation unit 112 uses integers κ greater than 2 to rearrange the number of 2-curves C1 in ascending order for each integer i = 1, ..., κ-1. i Zeros, calculating Richelot homology And calculate the number of types 2 curve C i+1 .

[0116] Specifically, the mapping calculation unit 112 performs the reference Figure 5 The number of curves described is 2, C0, ..., C10. κ The calculation process involves calculating the number of 2-curve sequences C0, ..., C10. κ Homologous sequences to Richelot

[0117] The mapping calculation unit 112 sets the number of curves C0, ..., C2 to 2. κ Homologous sequences to Richelot Write 12 to memory.

[0118] (Step S113: Key setting process)

[0119] The key setting unit 113 will use the number of curves C calculated in step S112 to... κ As the number of species 2, curve C s The key is set as a public key. Furthermore, the key setting unit 113 will use the Richelot homology sequence calculated in step S112. Set as the secret key. That is, starting from curve C0 with a number of species 2 and following curve C with a number of species 2. s Richelot homologous sequences ending with It is set as a secret key.

[0120] The key setting unit 113 sends the public key to the encryption device 20 and the decryption device 30 via the communication interface 14. Furthermore, the key setting unit 113 secretly sends the secret key to the decryption device 30 via the communication interface 14. Secret transmission, for example, means transmitting the key after encryption using existing encryption methods.

[0121] The secret key is a Richellot homologous sequence. This is essentially about the number of curves C0, ..., C2. κ In the calculation and processing step S13, how to rearrange the roots using the permutation method σ0, ..., σ κ-1 Corresponding to the secret key.

[0122] Reference Figure 9The operation of the encryption device 20 in Embodiment 1 will be explained.

[0123] The operation steps of the encryption device 20 in Embodiment 1 are equivalent to the encryption method in Embodiment 1. Furthermore, the program that implements the operation of the encryption device 20 in Embodiment 1 is equivalent to the encryption program in Embodiment 1.

[0124] (Step S211: Obtain processing)

[0125] The acquisition unit 211 acquires the number of public keys generated by the key generation device 10, curve C. s Furthermore, the acquisition unit 211 acquires the plaintext m. The plaintext m is input by the user of the encryption device 20.

[0126] Obtain part 211 and the number of varieties 2 curve C s Write plaintext m into memory 22.

[0127] (Step S212: Encryption Processing)

[0128] Encryption unit 212 encodes the plaintext m obtained in step S211, converting plaintext m into a Richelot homologous sequence. Encryption unit 212 uses Richelot homologous sequences Move the curve C, which is the number of types of public keys obtained in step S211, to the curve C. s And calculate the number of types 2 curve C m Then, encryption unit 212 will use curve C with two possible values. m Set as encrypted.

[0129] The encryption unit 212 sends the ciphertext to the decryption device 30 via the communication interface 24.

[0130] Reference Figure 10 The operation of the decryption device 30 in Embodiment 1 will be explained.

[0131] The operation steps of the decryption device 30 in Embodiment 1 are equivalent to the decryption method in Embodiment 1. Furthermore, the program that implements the operation of the decryption device 30 in Embodiment 1 is equivalent to the decryption program in Embodiment 1.

[0132] (Step S311: Obtain processing)

[0133] The acquisition unit 311 acquires the public parameters, as well as the public key and secret key generated by the key generation device 10. Furthermore, the acquisition unit 311 acquires the ciphertext generated by the encryption device 20.

[0134] The acquisition unit 311 writes the public parameters, public key, secret key, and ciphertext into memory 32.

[0135] (Step S312: Decryption)

[0136] The decryption unit 312 uses the Richelot homologous sequence obtained in step S311 as the secret key. And the number-2 curve C0, which is a public parameter, are used to calculate the number-2 curve C obtained in step S311, which is the public key. s Starting from the curve C, which is the number of ciphertexts obtained in step S311, the curve represents the number of ciphertexts. m Richelot homology with endpoint Then, the decryption section 312 is homologous to Richelot. Decoding is performed, and the plaintext m' = m is calculated. Here, decoding is the inverse operation of encoding performed in step S212.

[0137] The decryption unit 312 outputs plaintext m' via communication interface 14.

[0138] ***Effects of Implementation Method 1***

[0139] As described above, in the cryptographic system 1 of Embodiment 1, the elliptic curves E0 and E in the SETA encryption method are... s E m Replace them respectively with curves C0 and C with 2 types. s C m homologous sequences Replace them with Richelot homologous sequences respectively This enables the implementation of a 2-SETA cryptographic method.

[0140] In the SETA encryption method with two possible values, the value of the prime number p used in the SETA encryption method can be reduced to 1 / 3. As a result, the time spent on decryption can be reduced.

[0141] ***Other Structures***

[0142] <Variation Example 1>

[0143] In Implementation 1, the use of two types of curves C0 and C1 is explained. s C m However, it is still possible to use the number of curves C0 and C2 in the cryptographic system 1 of implementation method 1. s C m Rewritten as Abelian surfaces A0, A s A m That is, the elliptic curves E0 and E in the SETA encryption method are... s E m Replace them respectively with Abelian surfaces A0 and A s A m homologous sequences Replace with homologous sequences respectively This allows for a cryptographic method that achieves the same effect as the 2SETA cryptographic method.

[0144] In the case of using a number-two curve as in Embodiment 1, the preferred number-two curve is the number-two curve corresponding to the portion of the Abelian surface that is not decomposed into the direct product of elliptic curves E0 and is adjacent to the portion that is decomposed into the direct product of elliptic curves E0.

[0145] Furthermore, when not using a type 2 curve, it is preferable to use the part decomposed into the direct product of elliptic curves.

[0146] Furthermore, E0 / F is used in the direct product of elliptic curves decomposed from an Abelian surface when the elliptic curve E0 is a prime number p divided by 4 with a remainder of 3. p y 2 =x 3 E0 / F when +x or a prime number p is divided by 4 and the remainder is 1 p y 2 =x 3 +c, where c is a constant. Additionally, F p It takes the prime number p as the body of the law.

[0147] <Variation Example 2>

[0148] In Implementation Example 1, each functional structural element is implemented in software. However, as a variation 2, each functional structural element can also be implemented in hardware. Regarding this variation 2, the differences from Implementation Example 1 will be explained.

[0149] Reference Figure 11 The structure of the key generation device 10 in Modified Example 2 will be described.

[0150] When the various functional structural elements are implemented in hardware, the key generation device 10 replaces the processor 11, memory 12, and storage device 13 with electronic circuitry 15. Electronic circuitry 15 is a dedicated circuit that implements the functions of each functional structural element, memory 12, and storage device 13.

[0151] Reference Figure 12 The structure of the encryption device 20 in Modified Example 2 will be described.

[0152] When the various functional structural elements are implemented in hardware, the encryption device 20 replaces the processor 21, memory 22, and storage device 23 with electronic circuit 25. Electronic circuit 25 is a dedicated circuit that implements the functions of each functional structural element, memory 22, and storage device 23.

[0153] Reference Figure 13The structure of the decryption device 30 in Modified Example 2 will be described.

[0154] When all functional structural elements are implemented in hardware, the decryption device 30 replaces the processor 31, memory 32, and storage device 33 with electronic circuitry 35. Electronic circuitry 35 is a dedicated circuit that implements the functions of each functional structural element, memory 32, and storage device 33.

[0155] As electronic circuits 15, 25, and 35, consider single circuits, composite circuits, programmable processors, parallel programmable processors, logic ICs, GAs (Gate Arrays), ASICs (Application Specific Integrated Circuits), and FPGAs (Field-Programmable Gate Arrays).

[0156] Each functional structural element can be realized using a single electronic circuit 15, 25, or 35, or multiple electronic circuits 15, 25, or 35 can be used to realize each functional structural element separately.

[0157] <Variation Example 3>

[0158] As a variation of Example 3, some of the functional structural elements can be implemented in hardware, while other functional structural elements can be implemented in software.

[0159] Processors 11, 21, 31, memory 12, 22, 32, storage 13, 23, 33, and electronic circuits 15, 25, 35 are referred to as processing circuits. That is, the functions of each functional structural element are realized through processing circuits.

[0160] The embodiments and modifications of the present invention have been described above. Several embodiments and modifications may also be implemented in combination. Furthermore, any one or a portion of any of the embodiments and modifications may be implemented. In addition, the present invention is not limited to the above embodiments and modifications, and various changes can be made as needed.

[0161] Label Explanation

[0162] 1: Cryptographic system; 10: Key generation device; 11: Processor; 12: Memory; 13: Storage device; 14: Communication interface; 15: Electronic circuit; 111: Acquisition unit; 112: Mapping calculation unit; 113: Key setting unit; 20: Encryption device; 21: Processor; 22: Memory; 23: Storage device; 24: Communication interface; 25: Electronic circuit; 211: Acquisition unit; 212: Encryption unit; 30: Decryption device; 31: Processor; 32: Memory; 33: Storage device; 34: Communication interface; 35: Electronic circuit; 311: Acquisition unit; 312: Decryption unit.

Claims

1. A cryptosystem which performs a Richelot homology φ s with an Abelian variety A0 as a starting point and an Abelian variety A s as a terminal point, sets the Abelian variety A s as a secret key, and sets the Abelian variety A The cryptographic system has: An encryption device generates a Richelot homology sequence φ by encoding a plaintext m m Moving the abel surface A as a public key s While calculating the abel surface A m , the abel surface A m Is set to ciphertext; and a decryption device which, from said Richelot homology φ s , calculates the Richelot homology φ s , starting from said Abelian surface A m as public key, and ending at said Abelian surface A m as said ciphertext, The cryptographic system also has a key generation device that calculates a Richelot homology φ0 of the Abelian surface A0 to calculate an Abelian surface A1, uses an integer κ of 2 or more, reorders the zero points of the Abelian surface A i in ascending order with respect to each integer i of i = 1,..., κ - 1, calculates a Richelot homology φ i to calculate an Abelian surface A i+1 , sets the Abelian surface A κ as an Abelian surface A s , sets a public key, and sets a group of the Richelot homologies φ i with respect to each integer i of i = 0,..., κ - 1, that is, a Richelot homology sequence φ s as a secret key.

2. The cryptographic system according to claim 1, wherein The cryptographic system uses a genus-2 curve corresponding to the Abelian surface A0 as the Abelian surface A0.

3. The cryptographic system according to claim 2, wherein The genus-2 curve corresponds to a portion adjacent to a portion decomposed into a direct product of the elliptic curve E0 in the portion of the Abelian surface A0 that is not decomposed into a direct product of the elliptic curve E0.

4. The cryptographic system according to claim 1, wherein The cryptographic system uses a portion decomposed into a direct product of the elliptic curve E0 in the Abelian surface A0 as the Abelian surface A0.

5. The cryptographic system according to claim 3, wherein The elliptic curve E0 is E0 / F when the prime p leaves a remainder of 3 when divided by 4 p : y 2 = x 3 + x or E0 / F when the prime p leaves a remainder of 1 when divided by 4 p : y 2 = x 3 + c, where c is a constant, the F p is a field with the prime p as modulus.

6. The cryptographic system according to claim 4, wherein The elliptic curve E0 is E0 / F when the prime p leaves a remainder of 3 when divided by 4 p : y 2 = x 3 + x or E0 / F when the prime p leaves a remainder of 1 when divided by 4 p : y 2 = x 3 + c, where c is a constant, the F p is a field with the prime p as modulus.

7. An encryption device in a cryptosystem which performs a Richelot homology φ which takes an abelian variety A0 as a starting point and an abelian variety A s as a terminal point, wherein the Richelot homology φ is defined by φ (x, y) = (x + y, y), and the abelian variety A s is set as a secret key, and the abelian variety A s is set as a public key, and the cryptosystem performs a cryptographic process in which, The Abelian surface A1is calculated by calculating the Richelot homology φ0of the Abelian surface A0, using an integer κ of 2 or more, and rearranging the zeros of the Abelian surface A i in ascending order with respect to each integer i = 1,..., κ - 1, calculating the Richelot homology φ i i = 0,..., κ - 1, and calculating the Abelian surface A i+1 i = 0,..., κ - 1, and calculating the Abelian surface A κ i = 0,..., κ - 1, and calculating the Abelian surface A s is set as a public key, and the group of the Richelot homologies φ i i = 0,..., κ - 1, that is, the Richelot homology sequence φ s is set as a secret key, wherein, The encryption device has an encryption section that generates a Richelot homology sequence φ by encoding the plaintext m m The mobile as a public key of the abel surface A s And calculate the abel surface A m , the abel surface A m Set as ciphertext.

8. A decryption device in a cryptographic system that performs a cryptographic process of Richelot homology φ s with an Abelian surface A0 as a starting point and an Abelian surface A s as an end point, with a secret key, and an Abelian surface A s as a public key, wherein The Abelian surface A1 is calculated by calculating the Richelot homology φ0 of the Abelian surface A0, using an integer κ of 2 or more, and rearranging the zeros of the Abelian surface A i in ascending order with respect to each integer i = 1,..., κ - 1, calculating the Richelot homology φ i i = 0,..., κ - 1, and calculating the Abelian surface A i+1 i = 0,..., κ - 1, and calculating the Abelian surface A κ i = 0,..., κ - 1, and calculating the Abelian surface A s is set as a public key, and a group of the Richelot homologies φ i i = 0,..., κ - 1, that is, a Richelot homology sequence φ s is set as a secret key, wherein the decryption device has: a ciphertext acquisition unit that acquires a ciphertext that is a Richelot congruent sequence φ generated by encoding a plaintext m m moving the abel surface A as a public key s the calculated abel surface A m ; and a decryption unit that decrypts the Richelot isogeny φ s , which is the Richelot isogeny φ s with the Abelian surface A m as a starting point and the Abelian surface A m as a terminal point 9. A key generation apparatus in a cryptographic system which performs a cryptographic process with a Richelot homology φ which takes an Abelian surface A0 as a starting point and an Abelian surface A s as a terminal point, wherein the Abelian surface A0 is set as a secret key, and the Abelian surface A s is set as a public key. s The key generation device has: ​ an acquisition unit that acquires an Abelian surface A0 as a public parameter; a mapping calculation section that calculates an Abelian surface A1 from a Richelot homology φ0 of the Abelian surface A0 acquired by the acquisition section, and that, using an integer κ of 2 or more, with respect to each integer i of i = 1,..., κ - 1, rearranges the zero points of the Abelian surface A i in ascending order to calculate the Richelot homology φ i to calculate the Abelian surface A i+1 ; and a key setting section that sets an Abelian surface A calculated by the mapping calculation section as a public key, and sets a Richelot isogeny sequence φ κ is set as a public key, and a Richelot isogeny sequence φ i of each integer i for i = 0,..., κ - 1 is set as a secret key.

Citation Information

Patent Citations

  • Elliptic curve isogeny based key agreement protocol

    CN110383754A

  • Encoding abelian variety-based ciphertext with metadata

    US20190132129A1