Cipher system, encryption device, decryption device, and program

The cryptographic system addresses non-tight security and Ring-LWE incompatibility by using polynomial-size modulo-q LWE for threshold public-key cryptography, ensuring tight security and compatibility with Ring-LWE, enhancing efficiency and security in lattice cryptographies.

JP2025101353APending Publication Date: 2025-07-07KDDI CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
JP2023218151
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-25
Publication Date
2025-07-07

AI Technical Summary

Technical Problem

Conventional simulation-secure threshold public-key cryptography relies on the Known-Norm LWE assumption, leading to non-tight security and incompatibility with Ring-LWE, which is essential for efficient lattice cryptographies like fully homomorphic cryptography.

Method used

A cryptographic system that constructs threshold public key cryptography based on polynomial-size modulo-q LWE, using error and random number distributions to mask partial decryption results, ensuring security without requiring Known-Norm LWE.

Benefits of technology

Achieves simulation-secure threshold public-key cryptography with tighter security parameters, compatible with Ring-LWE, and efficient fully homomorphic cryptography, eliminating the need for non-standard assumptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025101353000001_ABST
    Figure 2025101353000001_ABST
Patent Text Reader

Abstract

To provide a cipher system that constitutes an efficient and simulation-safe threshold value public key encryption based on polynomial size law q and LWE problem.SOLUTION: A cipher system 100 comprises: a definition unit 11 for defining a key distribution and random number distribution and an error distribution for masking a partial ciphertext under a condition that satisfies exactness; a key generation unit 12 for generating an error according to the error distribution, together with a secret key and a public key; a setting unit 13 for distributing secretly distributed share to each party; an encryption unit 21 for encrypting a message using the public key and a first random number and further generating a ciphertext including a second random number; a partial decryption unit 31 for partially decrypting the ciphertext using the secret key share in each party and calculating a partial deciphertext in which a value derived by multiplying the error share to the second random number is added; and an overall decryption unit 32 for decrypting the message on the basis of the sum total of partial deciphertexts of effective share aggregates.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for constructing a threshold public key cryptosystem based on the Learning with Errors (LWE) problem.

Background Art

[0002] The simulation-based security of cryptographic protocols is a modern security proof technique / model that designs an ideal trustworthy function (ideal function) to be realized and shows that the actual cryptographic protocol is computationally indistinguishable from the input / output of the ideal function. It is a useful technique for showing general composability. In particular, since the security proof of secure multi-party computation (MPC) is often constructed based on simulation, simulation-based security is also important for using cryptographic protocols as components of MPC.

[0003] In contrast, classical game-based security is a security design that prioritizes the ease of constructing conventional security proofs. For example, in the game-based security of public key cryptography, it is shown that ciphertexts of 0 and ciphertexts of 1 are indistinguishable, while in simulation-based security, it is shown that there is no difference in the output of the attacker between the case where the attacker is given a ciphertext (= reality) and the case where the attacker is not given a ciphertext (= ideal function).

[0004] Also, the (t,N)-threshold public key cryptosystem (Threshold PKE: ThPKE) is a public key cryptosystem in which, out of all N participants having different secret key shares, t participants perform partial decryption and decryption is possible by bringing in the partial decryption texts. In Non-Patent Document 1, a simulation-secure threshold public key cryptosystem based on the polynomial-size modulo q LWE problem (Definition D.2 described later) was proposed.

Prior Art Documents

Non-Patent Documents

[0005]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

Non-Patent Document 4

Non-Patent Document 5

Non-Patent Document 6

Summary of the Invention

Problems to be Solved by the Invention

[0006] The conventional simulation-secure threshold public-key cryptography (Non-Patent Document 1) is more specifically based on the "Known-Norm LWE" assumption, which is a variant of the LWE assumption stating that even if the norm ∥e∥ of the error e is given to the attacker, it is computationally difficult. This is not based on LWE. Therefore, the conventional method has the following two problems due to this assumption.

[0007] Non-tight security: Known-Norm LWE has been shown to be computationally difficult by showing a reduction from LWE, but it has been reported that due to the loss in this reduction, a loss of bit security of about 10 bits occurs, for example.

[0008] Compatibility with Ring-LWE: Recent efficient lattice cryptographies are constructed based on Ring-LWE (Non-Patent Document 2), which is an extension of the LWE problem, and the same applies to fully homomorphic cryptography (e.g., Non-Patent Documents 3, 4). When attempting to construct ThPKE based on Ring-LWE using the method of Non-Patent Document 1, the "Known-Norm Ring-LWE" assumption that the norm ∥e∥ of the error e is known is required. However, unlike LWE, the reduction from Ring-LWE to Known-Norm Ring-LWE is not known, so Ring-LWE cannot be used as a security assumption in this method.

[0009] An object of the present invention is to provide a cryptographic system that constructs a simulation-secure threshold public key cryptography based on a polynomial-size modulo-q LWE problem without requiring Known-Norm LWE.

Means for Solving the Problem

[0010] The cryptographic system according to the present invention includes a definition unit that defines, under conditions satisfying accuracy, a key distribution for generating a first error with respect to a public key in a threshold public key cryptography based on LWE, a random number distribution used in encryption, and an error distribution for masking a partial decryption result; a key generation unit that generates a second error according to the error distribution, together with the secret key of the threshold public key cryptography and the public key corresponding to the secret key; a setting unit that distributes shares obtained by secretly sharing the secret key and the second error to each party; an encryption unit that encrypts a message using the public key and a first random number according to the random number distribution, and further generates a ciphertext including a second random number according to the random number distribution; a partial decryption unit that, in each party, partially decrypts the ciphertext using the share of the secretly shared secret key, and calculates a partial decryption result by adding a value obtained by multiplying a share of the second error secretly shared with respect to the second random number; and an overall decryption unit that decrypts the message based on the sum of the partial decryption results of the valid share set.

[0011] The threshold public key cryptography may be a fully homomorphic cryptography.

[0012] The LWE may be Ring-LWE.

[0013] The encryption device according to the present invention provides a key distribution for generating a first error with respect to a public key in a threshold public key cryptography based on LWE, and an error distribution for masking a partial decryption text, together with a random number distribution used during encryption, under the condition that the accuracy is satisfied. Using the public key generated corresponding to the secret key of the threshold public key cryptography and a first random number according to the random number distribution, a message is encrypted, and an encryption unit that generates a ciphertext including a second random number according to the random number distribution is provided. In each party to which shares obtained by secretly distributing the secret key and a second error generated according to the error distribution are distributed, when the ciphertext is partially decrypted using the share of the secret key, a partial decryption text obtained by adding a value obtained by multiplying the share of the second error by the second random number is calculated.

[0014] The decryption device according to the present invention provides a key distribution for generating a first error with respect to a public key in a threshold public key cryptography based on LWE, and an error distribution for masking a partial decryption text, together with a random number distribution used during encryption, under the condition that the accuracy is satisfied. The secret key of the threshold public key cryptography and shares obtained by secretly distributing a second error generated according to the error distribution are distributed. When a message is encrypted using the public key generated corresponding to the secret key and a first random number according to the random number distribution, and a ciphertext including a second random number according to the random number distribution is provided, the ciphertext is partially decrypted using the share of the secret key, and a partial decryption text obtained by adding a value obtained by multiplying the share of the second error secretly distributed with respect to the second random number is calculated. A total decryption unit that decrypts the message based on the sum of the partial decryption texts of the valid share set is provided.

[0015] The encryption program according to the present invention is for causing a computer to function as the encryption device.

[0016] The decryption program according to the present invention is for causing a computer to function as the decryption device.

Advantages of the Invention

[0017] According to the present invention, a threshold public key cryptography that is simulation secure based on a polynomial-sized modulo-q LWE problem and does not require Known-Norm LWE can be constructed.

Brief Description of the Drawings

[0018]

Figure 1

Figure 2

Figure 3

Modes for Carrying Out the Invention

[0019] Hereinafter, an example of an embodiment of the present invention will be described. First, the notations, definitions, theorems, etc. used in this embodiment will be described in the following [A] to [D].

[0020] [A. Notation] In this embodiment, the following notations are used. log represents the logarithm with base 2. For N ∈ N (natural numbers), [N] = {1,..., N} is defined. When the set {x i} i∈S is given, the index set S is also given. Bold lowercase letters are mainly used for vectors, and bold uppercase letters are mainly used for matrices, but this is not the case when it is obvious that it is a vector or a matrix. For the vector x = (x1,..., x n ), the i-th component is denoted as x i or x[i]. For the modulo q ∈ Z (integers),

Number

[0021] [B. Related to Statistics] When random variables X1, X2 independently follow the same distribution χ, [Number] is written as. For distributions χ1, χ2, χ1 + χ2 represents the distribution {x1 + x2 | x1 ← χ1, x2 ← χ2, and x1 and x2 are independent}. U(X) denotes the uniform distribution on the set X. Also, [Number] represents sampling the variable X from U(S). The continuous normal distribution with mean 0 and standard deviation σ > 0 is denoted as N σ and is written as.

[0022] (Definition B.1) The statistical distance between distributions χ1 and χ2 on the sample space Ω is [Number] is defined as. Here, f χ1 (x), f χ2 (x) are the probability density functions of χ1, χ2. This definition is naturally extended to continuous distributions.

[0023] (Definition B.2 Statistical indistinguishability) The fact that Δ(χ1, χ2) = negl(λ) holds is [Number] is denoted as.

[0024] (Definition B.3 Computational indistinguishability) For any probabilistic polynomial-time (PPT) algorithm A, we say that |Pr[A(χ1)=1] - Pr[A(χ2)=1]| = negl(λ) holds,

Number

[0025] (Definition B.4) The Min-entropy of a discrete distribution χ is defined as H ∞ (χ) = log min x∈Supp(x) 1 / Pr X←χ [X = x].

[0026] (Lemma B.5) Let q be a prime number, m, n ∈ N (natural numbers). For a random variable r over Z m q and

Number

Number

[0027] (Fact B.6) For m ≥ n log q + 2λ, r ~ U({0, 1} m ),

Number

[0028] (Proof)

Number

[0029] (Lemma B.7) When m ≥ n + ω(log n), with overwhelming probability, A ← U(Z m×n q ) is non-singular. That is, the linear combination of the rows of A spans Z n (see Non-Patent Document 6).

[0030] (Proof) Let p be the smallest prime factor of q. Then A is 1 / p m-n-1 is non - singular except for the following probabilities. Therefore, when m ≥ n+ω(log n), Pr[A is singular]=negl(n).

[0031] (Definition B.8) A distribution χ is Pr X←χ [X ≥ B]=negl(n) is said to be B - bounded when it is satisfied.

[0032] (Fact B.9) For any t > 0, X~N σ for [Number] holds. That is, N σ is σ·Ω(√n) - bounded.

[0033] (Proof) [Number]

[0034] [C. Linear Secret Sharing] Here, the configuration of the linear secret sharing used in the ThPKE of the present embodiment is shown (see Non - Patent Document 4).

[0035] (Definition C.1) The power set of a set S is [Number] is defined as

[0036] (Definition C.2 Monotone (Increasing) Access Structure) Let P = {P1,…,P N} be a set of parties. The system [Number] is said to be monotone if for any set B ⊆ C (⊆ P), if B ∈ A then C ∈ A holds. The monotone access structure on P is a monotone system

Number

[0037] (Definition C.3 Invalid / Valid Party Sets) For a set of parties P = {P1,..., P N} and an access structure A, a set S ∈ A is called a valid set, and a set S ∈ P(P)\A is called an invalid set. Also, the following sets are defined. Largest Invalid Participant Set:

Number

Number

[0038] (Definition C.4 Secret Sharing (SS:Secret Sharing) For a set of parties P = {P1,..., P N}, a secret space K, and an access structure A, a secret sharing scheme SS for them is a set of PPT algorithms SS = (SS.Share, SS.Combine) shown below.

[0039] SS.Share(k ∈ K, A) → (s1,..., s N ): Taking the secret k ∈ K and the access structure A as inputs, it outputs shares s1,..., s N for each party. SS.Combine({s i} i∈S ) → k: Taking the set of shares {s i} i∈S as input, it outputs the secret k ∈ K.

[0040] Also, SS needs to satisfy the following correctness and privacy. Correctness: For any S ∈ A, k ∈ K, (s1,..., s N) For SS.Share(k, A), SS.Combine({s i} i∈S ) = k holds. Privacy: For any

Number

Number

[0041] (Definition C.5 Binary Coefficient Linear Secret Sharing) Let the set of parties P = {P1,..., P N}, the class S of efficient access structures, and the secret space K = Z p (p is a prime number). At this time, a secret sharing scheme (Definition C.4) that satisfies the following properties is called a binary coefficient linear secret sharing (BinLSS) (see Non-Patent Document 4).

[0042] BinLSS.Share(k ∈ K, A) → (s1,..., s N ): There exists a matrix M ∈ Z l×N p called a share matrix, and each party P i is associated with a share index set T i ⊆ [l]. Sample random values

Number

[0043] BinLSS.Combine({s i} i∈S ): For any valid party set S ∈ A,

Number

Number

[0044] (Definition C.6 Valid / Invalid Share Set) Consider a BinLSS where the set of parties is P = {P1,..., P N}, and the share matrix is M ∈ Z l×N q . For an index set T ⊆ [l], T is said to be valid if Σ j∈T M[j] = (1, 0,..., 0), and invalid otherwise. Also, define the following sets. Largest Invalid Share Set:

Number

Number

[0045] Define the access structure used in threshold cryptography. (Definition C.7 Threshold Access Structure) Let P = {P1,..., P N} be the set of parties. An access structure A (t,N) is said to be a (t, N)-threshold access structure if for any set S ⊆ P, S ∈ A (t,N) means that |S| ≥ t holds.

[0046] In the following Theorem C.8, it is shown that BinLSS (Definition C.5) corresponds to any threshold access structure. Therefore, a ThPKE can be constructed by constructing a PKE whose access structure for decryption follows BinLSS. (Theorem C.8) For any A (t,N) (Definition C.7), an efficient BinLSS exists (see Non-Patent Document 4).

[0047] Shows a configuration example of BinLSS. (Example C.9) BinLSS for the (N,N)-threshold access structure can be configured as follows.

[0048] SS.Share(k ∈ Z p ) → (s1,…,s N ): Let l = N, and define the share matrix as follows.

Number

Number

Number

[0049] SS.Combine({s i} i∈S ): The set of valid parties is S = {P1,…,P N}, and the set of valid shares is T = [N]. For the input {s i} i∈[N] , restore the secret by calculating it as follows.

Number

[0050] In the above, only the secret sharing of the scalar value k ∈ Z p was shown, but in this embodiment, the secret vector s ∈ Z n q is always secretly shared. This can be realized as follows. That is, for each element of the vector s, shares are generated by secret sharing using different random numbers, and the share vectors s1, …, s l ∈Z n q are obtained. At this time, the secret vector s can be reconstructed as a linear combination of s1, …, s l using the same index set for each element. Also, privacy (Definition C.4) holds.

[0051] [D.Reused-A LWE] In Non-Patent Document 1, for the security proof of ThPKE, the Reused-A-LWE problem, which is a variant of the LWE problem (see Non-Patent Document 7), was introduced, but it was limited to the case where the error distribution is a continuous normal distribution. Here, the error distribution of the Reused-A-LWE problem is generalized to an arbitrary distribution (Definition D.9), and furthermore, a reduction from LWE with an arbitrary error distribution to Reused-A-LWE is shown (Theorem D.10). Also, it is shown that this reduction has a smaller loss of error parameters than the reduction in Non-Patent Document 1 (Corollary D.11).

[0052] (Definition D.1 LWE Distribution) Let n ∈ N (natural number) be the security parameter, m = poly(n) be the number of samples, q = q(n) ≥ 2 be an integer, and χ be a distribution with mean 0 on X q ∈ {Z q , R q}. The LWE distribution for a fixed

Number

Number

[0053] (Definition D.2) Decision-LWE s (m, n, q, χ) is U(Z m×n q × X n q ) and LWE sThe problem of distinguishing (m,n,q,χ).

[0054] (Definition D.3) Search-LWE s (m,n,q,χ) is the problem of finding s from a sample (A,b) ← LWE s (m,n,q,χ).

[0055] (Fact D.4) Search-LWE s If there exists a PPT algorithm A that solves (m,n,q,χ), then Decision-LWE s There exists a PPT algorithm A' that solves (m,n,q,χ).

[0056] (Proof) Let (A,b) be a sample drawn from LWE s (m,n,q,χ) or U(Z m×n q ×Z n q ). The algorithm A'(A,b) can be constructed as follows using algorithm A. That is,

Number

Number

[0057] We can also define the (semi) - order between probability distributions as follows. (Definition D.5) For probability distributions χ1 and χ2 with mean 0, (including the distribution χ null : Pr[(X ← χ null ) = 0] = 1), there exists a distribution χ δ such that

Number

[0058] (Example D.6) For any 0 < σ1 < σ2, N σ1 ≤ N σ2 holds. (Proof) Let e1 ← N σ1 and add e δ ← N σ2-σ1 to it, then e1 + e δ ~ N σ2 holds.

[0059] (Lemma D.7) When Decision-LWE s (m, n, q, χ1) is computationally difficult, for any χ2 ≥ χ1, Decision-LWE s (m, n, q, χ2) is also computationally difficult.

[0060] (Proof) Since χ2 ≥ χ1, there exists some χ δ such that [Number theory] holds. Let (A, b) ← LWE s (m, n, q, χ1), sample e’ ← χ m δ and set b’ := b + e’, then [Number theory] follows. If Decision-LWE s (m, n, q, χ2) were computable, then by the above transformation, Decision-LWE s (m, n, q, χ1) would also be computable, contradicting the assumption. Thus, the claim is obtained by contradiction.

[0061] (Lemma D.8) When Decision-LWE s (m, n, q, χ) is computationally difficult, for any m ≥ n + ω(log n), the probability [Number theory] is overwhelming.

[0062] (Proof) [Number theory] Let \(P = 1 - P'\). Then, it suffices to show \(P'=\text{negl}(n)\). We will prove this by contradiction. Assume that \(P'\) is non - negligible. We will show the existence of a PPT algorithm that solves Search - LWE with probability \(P'-\text{negl}(n)\) as follows. s for (A, b = As + e) ~ LWE (A, b = As + e) ~ LWE s Let \((m,n,q,\chi)\). With probability \(P'\), [Number theory] and calculate the following \(b'\) at this time.

[0063] X q =R q When, [Number theory] calculate. Here, [Number theory] holds. X q =Z q When, [Number theory] means \(e = 0\), so simply define \(b':=b = As\).

[0064] From Lemma B.7, with probability \(1-\text{negl}(n)\), there exists some \(A'\in\mathbb{Z}\) n×m q such that \(A'A = I\) n (\(n\times n\) identity matrix) holds. Find this \(A'\) and output \(A'b'=s\). Furthermore, from Fact D.4, using the above algorithm, a PPT algorithm that solves Decision - LWE s (m,n,q,\chi) (with non - negligible advantage) can be constructed. Therefore, since it contradicts the assumption, by reductio ad absurdum, we obtain P’ = negl(n).

[0065] (Definition D.9 Generalization of Reused-A LWE) Let n, m, q ∈ N, and let χ1 and χ2 be distributions over X q ∈ {Z q , R q}}. The Reused-A LWE distribution ReusedA-LWE

Number

number

Number

Number

[0066] (Theorem D.10) When both Decision-LWE(n, m, q, χ1) and Decision-LWE(n, m, q, χ2) are computationally difficult, Decision-ReusedA-LWE(n, m, q, χ1, χ2) is also computationally difficult.

[0067] (Proof) For simplicity of notation, let X1 := LWE(n, m, q, χ1), X2 := LWE(n, m, q, χ1), X3 := ReusedA-LWE(n, m, q, χ1, χ2), and let Adv i (i ∈ {1, 2, 3}) denote the advantage of algorithm A for the Decision problem of each X Xi A . Defining the hybrid distribution

Number

Number

[0068] Theorem D.10 means that when the Decision-LWE problems corresponding to (A, b1) and (A, b2) are both computationally difficult, it is computationally difficult to obtain information other than the error difference e2 - e1 from (A, b1, b2). Also, Theorem D.10 subsumes the claim for Decision-LWE in Non-Patent Document 1, and can be further improved as follows.

[0069] (Corollary D.11) Let 0 < σ1, σ2, σ min := min(σ1, σ2). If Decision-LWE(n, m, q, N σmin ) is difficult, then Decision-ReusedA-LWE(n, m, q, N σ1 , N σ2 ) is also difficult.

[0070] (Proof) From Definition D.5, N σmin ≤ N σ1 , N σ2 , so the claim is obtained from Lemma D.7 and Theorem D.10.

[0071] In this way, in Theorem D.10, the reduction from LWE with an arbitrary error distribution to Reused-A LWE was shown. Furthermore, in Corollary D.11, it was shown that this reduction has a smaller parameter loss than before. Note that in Non-Patent Document 1, the computational hardness assumption of Decision-LWE(n, m, q, N b =(σ -2 1 + σ -2 2) -1 / 2 ) was required, but σb ​

Number

[0072] [Configuration of This Embodiment] Next, the configuration of the threshold public key cryptography of this embodiment will be described in detail. In this embodiment, in the threshold public key cryptography based on LWE, a new error η for masking the partial decryption text is provided, and not only the secret key s but also η is secretly shared and distributed to each party. When each party generates a partial decryption text, by adopting a configuration in which an error generated using the share of η is added, information leakage regarding the error e of the LWE sample, which has been a conventional problem, is prevented.

[0073] FIG. 1 is a diagram showing the functional configuration of the encryption system 100 in this embodiment. The encryption method implemented in the encryption system 100 is a threshold public key cryptography based on LWE, and includes a management device 10 that generates parameters and key information, an encryption device 20 that generates a ciphertext of a message using the public key, and a plurality of parties (decryption devices 30) that have shares of the secret key and can perform partial decryption of the ciphertext. In this embodiment, the encryption system 100 is configured to include three types of information processing devices, but this is not limiting. Each function included in the encryption method may be aggregated into a smaller number of devices or may be distributed.

[0074] FIG. 2 is a diagram showing Algorithm 1 for realizing the threshold public key cryptography in this embodiment.

[0075] The control unit of the management device 10 functions as a definition unit 11, a key generation unit 12, and a setting unit 13 by executing software stored in the storage unit.

[0076] The definition unit 11 defines, by executing Params() of Algorithm 1, a key distribution (χ pk ) for generating a first error (e) with respect to the public key in the threshold public key cryptography based on LWE, a random number distribution (χ enc ) used during encryption, and an error distribution (χ err ) for masking the partial decryption text under the conditions satisfying the accuracy described later.

[0077] The key generation unit 12 generates, by executing KeyGen() of Algorithm 1, a second error (η) according to the error distribution, together with the secret key of the threshold public key cryptography and the public key corresponding to the secret key.

[0078] The setting unit 13 distributes, by executing Setup() of Algorithm 1, the shares obtained by secretly sharing the secret key and the second error to each party respectively.

[0079] The control unit of the encryption device 20 functions as the encryption unit 21 by executing software (encryption program) stored in the storage unit.

[0080] The encryption unit 21 encrypts the message μ using the public key and a first random number (r) according to the random number distribution by executing Enc() of Algorithm 1, and further generates a ciphertext ct including a second random number (r mask ) according to the random number distribution.

[0081] The control unit of the decryption device 30 functions as the partial decryption unit 31 and the overall decryption unit 32 by executing software (decryption program) stored in the storage unit.

[0082] The partial decryption unit 31 partially decrypts the ciphertext using the share of the secretly shared secret key at each party by executing PartDec() of Algorithm 1, and adds a value (r T mask η j ) obtained by multiplying the share of the second error secretly shared with respect to the second random number to obtain a partial decryption text (pdi ) is calculated.

[0083] The overall decoding unit 32 decodes the message based on the sum of the partial decoded texts of the valid share set by executing FinDec() of Algorithm 1.

[0084] Here, the correctness of ThPKE is defined, and it is shown that the method of this embodiment satisfies the correctness and its conditions.

[0085] (Definition 1 Correctness) Algorithm 1 is such that for an overwhelming proportion of (pk, sk, err) generated by KeyGen(), for any valid set S ∈ A, with overwhelming probability FinDec({pd i} i∈S ) = μ holds, then ThPKE is said to be correct.

[0086] (Theorem 2) For an overwhelming proportion of (pk := (A, As + e), sk := s, err := η) generated by KeyGen(),

Number

[0087] (Proof) In FinDec of Algorithm 1,

Number

Number

Number

[0088] As can be seen from the fact that η does not depend on N, χ sim also does not depend on N. Therefore, since the law q can be set independently of N, the ciphertext becomes more compact than before. For example, a specific parameter design can be performed as shown below.

[0089] (Example 3) m ≧ n, χ pk , χ err is B-bounded (Definition B.8), χ enc := N σenc When doing so,

Equation

[0090] (Proof) From the definition, with overwhelming probability, ∥e∥, ∥η∥ < B√m holds,

Equation

Equation

[0091] Next, the security of the method in this embodiment is defined, and it is shown that the proposed method satisfies Simulation Security (SS) and its conditions. Figure 3 is a diagram showing Algorithm 2, which is an experiment for defining the security of the method in this embodiment.

[0092] (Definition 4 SS: Simulation Security) For λ, A, there exists a PPT algorithm Sim, and for any stateful PPT algorithm A := (A1, A2, A3), the Expt of Algorithm 2 A,Real (1 λ ) and Expt A,Ideal (1 λWhen the output of () is computationally indistinguishable, the ThPKE scheme satisfies SS. Note that the attacker can repeat the lines 4 and later of Algorithm 2 for an arbitrary Poly(λ) times.

[0093] (Theorem 5) Let m ≥ n log q + 2λ, and χ = χ pk , χ err , χ enc If all Decision-LWE(n, m, q, χ) are hard, Algorithm 1 satisfies SS (Definition 4). In particular, if χ = χ pk = χ err = χ enc then the hardness assumption of Decision-LWE(n, m, q, χ) alone is sufficient.

[0094] (Proof) For any PPT algorithm A, there exists a Sim such that

Number

Number

[0095] Regarding Equation (4), it is obvious from the privacy (Definition C.4) of BinLSS (Definition C.5). Also, in Theorem C.8, it is shown that a BinLSS that satisfies accuracy and privacy can be constructed for any threshold access structure (Definition C.7). Therefore, it suffices to prove (3). Below, we show how to construct a Sim that satisfies (3).

[0096] S mal ⊂ {P1,..., P N} is the maximum non-participating set (Definition C.3), so the obtained ∪ i∈S_mal T iFrom the maximum invalid share set \(T_{mal}\subseteq\cup\) i∈S_mal T i (Definition C.6) is obtained. In the following, \(\{p_d\}\) i \} i∈S = \{p j \} j∈Ti \leftarrow PartDec(pk, ct, sk i , err i )\} i∈S of \(p\) j among them,

Number

[0097] Define \(T = T\) mal \cup\{j\}\). Since \(T\) mal is the maximum invalid share set, \(T\) becomes the minimum valid share set. Therefore, from the correctness of BinLSS (Definition C.4),

Number

Number

Number

[0098] Combining Eqs. (5) and (6), we can write as follows.

Number

[0099] From Lemma B.5,

Number

Number

Number

[0100] Also here, the attacker can obtain any l = poly(λ) ciphertexts for a fixed pk and get l of (a’, Real, Atk). However, in that case too,

Number

[0101] Furthermore, from Lemma D.8, in KeyGen, with overwhelming probability, at least one of e and η is 1 or more, so χ enc ≦ χ e , χ η (Definition D.5). Also, from the assumption, Decision-LWE(n, m, q, χ enc ) is computationally difficult. Therefore, from Lemma D.7, Decision-LWE(χ e ) and Decision-LWE(χ η) are both computationally difficult. Therefore, from Theorem D.10 and Equation (7),

Number

[0102] And, from the definition of (6), p j = Real - r T mask η mal so,

Number

Number

Number

[0103] In line 3 of Algorithm 2, the (stateful) attacker A and Sim are given χ simThis is because, in fact, A can observe the variable that follows χ by taking the difference between Real in Equation (6) and Atk in Equation (5). sim This is because the variables that follow χ can be observed. In the prior art (Non-Patent Document 1), the configuration was such that ∥e∥ was obtained from the variance of this χ sim However, in the method of this embodiment, for example, when χ enc = N σ_enc then √(∥e∥ 2 + ∥η∥ 2 ) would be given to the attacker. However, as shown in Theorem 5, due to the (information-theoretic) security of BinLSS, an attacker who only has invalid shares cannot obtain any information about η, and thus cannot obtain any information about ∥e∥ from χ sim Therefore, in the method of this embodiment, security can be proven without the need for Known-Norm LWE or Known-Norm Ring-LWE.

[0104] In the conventional method, since the norm ∥e∥ of the error of the LWE sample As + e, which is the public key, is leaked to the attacker, it was necessary to go through the non-standard assumption of Known-Norm LWE. On the other hand, according to the configuration of the cryptographic system 100 of this embodiment, the configuration can be improved to only leak the value of √(∥e∥ 2 + ∥η∥ 2 ) to the attacker. Furthermore, from the security (Privacy, Definition C.4) of linear secret sharing (BinLSS, Definition C.5), the attacker cannot obtain any information about η unless a valid share set that enables decryption is given. For this reason, the value of ∥e∥ cannot be obtained from √(∥e∥ 2 + ∥η∥ 2 ). Therefore, the configuration of this embodiment can prove security directly from the standard LWE assumption without the need for the non-standard assumption of Known-Norm LWE.

[0105] As a result, the cryptographic system 100 does not incur the loss of bit security that existed in the conventional method via Known-Norm LWE. That is, when compared with the same bit security, it can be configured with smaller parameters, making it more efficient.

[0106] Also, the cryptographic system 100 may have a configuration in which LWE is replaced with Ring-LWE. The specific configuration is self-evidently derived by replacing LWE with Ring-LWE in this embodiment. In the conventional method, although a configuration based on Known-Norm Ring-LWE, which is a non-standard assumption, has been shown, the reduction from Ring-LWE to Known-Norm Ring-LWE is not known. That is, according to this embodiment, it has become possible to construct a simulation-secure threshold public-key cryptography based on the polynomial-size modulus q Ring-LWE problem.

[0107] Here, in the parameter design of LWE, according to Lemma D.7, when the security bit λ of Decision-LWEs(m,n,q,χ1) is known, for any χ2≧χ1, the security bit of Decision-LWEs(m,n,q,χ2) is at least λ. That is, by outputting λ, it becomes possible to design the security of LWE with high generality.

[0108] Also, according to Theorem D.10, when the security bits λ1,λ2 of Decision-LWE(n,m,q,χ1) and Decision-LWE(n,m,q,χ2) are known, the security bit of Decision-ReusedA-LWE(n,m,q,χ1,χ2) can output min(λ1,λ2), enabling a highly general and more tight security design than before.

[0109] Note that, by realizing, for example, a secure and efficient threshold public key cryptography, it becomes possible to contribute to Goal 9 of the United Nations Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation."

[0110] As described above, the embodiments of the present invention have been described, but the present invention is not limited to the above-described embodiments. Further, the effects described in the above-described embodiments are merely an enumeration of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.

[0111] In this embodiment, mainly the (t,N)-threshold access structure has been assumed and described, but it is not limited thereto. The class of access structures that can be realized by BinLSS is a broader class that includes the class of threshold access structures.

[0112] Also, Algorithm 1 shows ThPKE, and by replacing this PKE part with fully homomorphic encryption (FHE), BinLSS-Threshold FHE (including (t,N)-Threshold FHE) can be constructed. And by using BinLSS-Threshold FHE, a Universal Thresholdizer (Non-Patent Document 4) can be constructed, and by using this, threshold signatures, CCA-secure Threshold PKE, Distributed PRFs, functional encryption, etc. can be constructed.

[0113] The encryption method by the encryption system 100 is realized by software or a hardware circuit. When it is realized by software, the program constituting this software is installed in an information processing device (computer). Also, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded.

Explanation of Signs

[0114] 10 Management device 11 Definition section 12 Key generation section 13 Setting section 20 Encryption device 21 Encryption section 30 Decryption device 31 Partial decryption section 32 Overall decryption section 100 Encryption system

Claims

1. A defining unit that defines, together with a key distribution for generating a first error for a public key in a threshold public key cryptosystem based on Learning with Errors (LWE), a random number distribution used during encryption, and an error distribution for masking a partial decryption result under conditions that satisfy accuracy; A key generation unit that generates a second error according to the error distribution, together with a secret key of the threshold public key cryptosystem and the public key corresponding to the secret key; A setting unit that distributes shares obtained by secretly sharing the secret key and the second error to each party; An encryption unit that encrypts a message using the public key and a first random number according to the random number distribution, and generates a ciphertext that further includes a second random number according to the random number distribution; A partial decryption unit that, in each party, partially decrypts the ciphertext using the share of the secretly shared secret key, and calculates a partial decryption result obtained by adding a value obtained by multiplying the share of the second error secretly shared for the second random number; An overall decryption unit that decrypts the message based on the sum of the partial decryption results of the valid share set. An encryption system comprising the above.

2. The encryption system according to claim 1, wherein the threshold public key cryptosystem is a fully homomorphic cryptosystem.

3. The encryption system according to claim 1, wherein the LWE is Ring-LWE.

4. A key distribution for generating a first error for a public key in a threshold public key cryptosystem based on Learning with Errors (LWE), a random number distribution used during encryption, and an error distribution for masking a partial decryption result are provided under conditions that satisfy accuracy, An encryption unit that encrypts a message using the public key generated corresponding to the secret key of the threshold public key cryptosystem and a first random number according to the random number distribution, and generates a ciphertext that further includes a second random number according to the random number distribution; An encryption device that, in each party to which shares obtained by secretly sharing the secret key and a second error generated according to the error distribution are distributed, calculates a partial decryption result obtained by adding a value obtained by multiplying the share of the second error for the second random number when the ciphertext is partially decrypted using the share of the secret key.

5. A key distribution for generating a first error for a public key in a threshold public key cryptosystem based on Learning with Errors (LWE), and an error distribution for masking a partial decryption text are provided under conditions that satisfy accuracy, together with a random number distribution used during encryption. Shares obtained by secretly sharing a secret key of the threshold public key cryptosystem and a second error generated according to the error distribution are distributed. When a message is encrypted using the public key generated corresponding to the secret key and a first random number according to the random number distribution, and a ciphertext including a second random number according to the random number distribution is provided, a partial decryption unit that partially decrypts the ciphertext using the share of the secret key and calculates a partial decryption text obtained by adding a value obtained by multiplying a share of the second error secretly shared with respect to the second random number. A decryption device including: an overall decryption unit that decrypts the message based on a sum of the partial decryption texts of the valid share set.

6. An encryption program for causing a computer to function as the encryption device according to claim 4.

7. A decryption program for causing a computer to function as the decryption device according to claim 5.

Citation Information

Cited By

  • Cryptographic systems, adjustment devices, decryption devices, and programs

    JP2026144770A