Polar coding based on data privacy protection
By employing a multi-cryptographic security mechanism based on polarization theory and using multiple cryptographic keys to encode data in polarity, the problem of complex and insecure encryption methods in 5G wireless systems is solved, achieving efficient data protection and enhanced security.
Patent Information
- Application Number
- CN202080093769.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-01-20
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2040-01-20
AI Technical Summary
Existing encryption algorithms are insufficient to effectively protect command and control signals from cyberattacks and unauthorized access in 5G wireless systems, especially in industrial scenarios such as smart factories, where traditional encryption methods are complex and lack sufficient security.
A multi-cryptographic security mechanism based on polarization theory is adopted, which uses two or more cryptographic keys to encode the data in polarity. The encryptor generates a cryptographic vector, and the decryptor uses these keys to decode, ensuring that the data can only be decrypted when all keys are correct.
It significantly improves data protection and security, prevents unauthorized recipients from decrypting data, avoids the complexity and potential vulnerabilities of traditional encryption methods, and provides firmware-level and dynamic-level security.
Smart Images

Figure CN115004559B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Example embodiments of the present disclosure generally relate to the field of cryptography, and in particular to devices, methods, apparatuses, and computer-readable storage media for data encryption and decryption. BACKGROUND
[0002] Data security is very important in the digital world. Especially when deploying a fifth generation (5G) wireless system for industrial scenarios such as smart factories, command and control (C&C) signals need proper encryption to be protected from cyber attacks and unauthorized access. Data transferred from a sender to a receiver can be protected by cryptographic encryption. Conventional encryption algorithms include Advanced Encryption Standard (AES), Data Encryption Standard (DES), and the like. SUMMARY
[0003] Generally, example embodiments of the present disclosure provide devices, methods, apparatuses, and computer-readable storage media for data encryption and decryption.
[0004] In a first aspect, a device is provided that includes at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the device to obtain a first cryptographic key and a second cryptographic key. The first cryptographic key includes a vector of cryptographic elements, and the second cryptographic key includes a set of indices corresponding to a subset matrix of a polar matrix. The device is then caused to generate a cryptographic vector by polar encoding a data vector based on the first cryptographic key and the second cryptographic key and the polar matrix. The device is further caused to combine the data vector and the cryptographic vector for use in encrypting the data vector.
[0005] In a second aspect, a device is provided that includes at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the device to obtain a first cryptographic key and a second cryptographic key. The first cryptographic key includes a vector of cryptographic elements, and the second cryptographic key includes a set of indices corresponding to a subset matrix of a polar matrix. The device is then caused to derive a combination of a data vector and a cryptographic vector by polar decoding an encrypted data vector based on the first and second cryptographic keys. The cryptographic vector is generated by polar encoding the data vector based on the first cryptographic key and the second cryptographic key and the polar matrix. The device is further caused to obtain the data vector from the combination of the data vector and the cryptographic vector.
[0006] In a third aspect, there is provided a method of data encryption. In the method, a first cryptographic key and a second cryptographic key are obtained. The first cryptographic key comprises a vector of cryptographic elements and the second cryptographic key comprises a set of indices corresponding to a subset matrix of a polarisation matrix. A cryptographic vector is generated by polar encoding a data vector based on the first cryptographic key and the second cryptographic key and the polarisation matrix. The data vector and the cryptographic vector are combined for use in encrypting the data vector.
[0007] In a fourth aspect, there is provided a method of data decryption. In the method, a first cryptographic key and a second cryptographic key are obtained. The first cryptographic key comprises a vector of cryptographic elements and the second cryptographic key comprises a set of indices corresponding to a subset matrix of a polarisation matrix. A combination of a data vector and a cryptographic vector is derived by polar decoding an encrypted data vector based on the first cryptographic key and the second cryptographic key. The cryptographic vector is generated by polar encoding a data vector based on the first cryptographic key and the second cryptographic key and the polarisation matrix. The data vector is obtained from the combination of the data vector and the cryptographic vector.
[0008] In a fifth aspect, there is provided an apparatus comprising means for performing the method according to the third or fourth aspect.
[0009] In a fourth aspect, there is provided a computer readable storage medium comprising program instructions stored thereon. The instructions, when executed by a processor of a device, cause the device to perform the method according to the third or fourth aspect.
[0010] It is to be understood that the Summary is not intended to identify key or essential features of example embodiments of the disclosure, nor is it intended to be used to limit the scope of the disclosure. Other features, details, and advantages of the disclosure will become readily apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0011] Some example embodiments will now be described with reference to the accompanying drawings, in which:
[0012] Figure 1 An example channel polarisation phenomenon is illustrated;
[0013] Figures 2(a), 2(b) and 2(c) illustrate example polar encoding structures with one, two and three polarisations respectively;
[0014] Figure 3 An example environment in which example embodiments of the disclosure can be implemented is illustrated;
[0015] Figure 4 A flow diagram of an example method of data encryption according to some example embodiments of the disclosure is illustrated;
[0016] Figure 5a flowchart illustrating an example data encryption method, in accordance with some other example embodiments of the present disclosure;
[0017] Figure 6 a flowchart illustrating an example data decryption method, in accordance with some example embodiments of the present disclosure;
[0018] Figure 7 a flowchart illustrating an example decryption process using a depth-first algorithm, in accordance with some example embodiments of the present disclosure; and
[0019] Figure 8 a simplified block diagram of a device suitable for implementing example embodiments of the present disclosure.
[0020] Throughout the drawings, identical or similar reference numerals can designate identical or similar elements throughout the several views. DETAILED DESCRIPTION
[0021] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these example embodiments are described for illustrative purposes only and help the skilled person to understand and implement the present disclosure, and are not meant to limit the scope of the present disclosure in any way. The disclosure described herein can be implemented in various ways other than those described below.
[0022] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0023] As used herein, the term "encrypter" refers to any suitable device capable of encrypting data or a portion thereof. The term "decrypter" refers to any suitable device capable of decrypting encrypted data or a portion thereof. Examples of encrypters and decrypters include, but are not limited to, personal computers, laptop computers, tablet computers, personal digital assistants, blades, servers, smartphones, laptop embedded equipment (LEE), laptop mounted equipment (LME), customer premises equipment (CPE), sensors, metering devices, personal wearable devices, and / or vehicles capable of computing. In this document, the terms "encode" and "encrypt" can be used interchangeably, and the terms "decode" and "decrypt" can be used interchangeably.
[0024] As used herein, the term "circuitry" can refer to one or more or all of the following:
[0025] (a) hardware-only circuitry implementations (such as implementations in only analog and / or digital circuitry) and
[0026] (b) combinations of hardware circuits and software, such as (as applicable): (i) combinations of analog and / or digital hardware circuits with software / firmware, such as (as applicable) (ii) combinations of
[0027] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of microprocessor(s), that requires software (e.g., firmware) for operation, but it is not present when it is not needed for operation.
[0028] This definition of circuitry applies to all uses of this term in this application, including all uses in any claims. As a further example, as used in this application, the term circuitry also covers an implementation that is a hardware circuit or processor (or multiple processors) or a portion of hardware circuit or processor and its (or their) accompanying software and / or firmware. As an example and where applicable, the term circuitry thus covers an implementation in which the hardware circuit or processor (or multiple processors) is a baseband integrated circuit or processor integrated circuit for a mobile device or similar integrated circuit in a server, cellular base station, or other computing or base station device.
[0029] As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. The term "includes" and variations thereof are to be read to be equivalent to the term "comprising." The term "based on" is to be read as "based, at least in part, on." The term "one embodiment" and "an embodiment" are to be read as "at least one embodiment." The term "another embodiment" is to be read as "at least one other embodiment." Other definitions, explicit and implicit, can be included elsewhere below.
[0030] As used herein, the terms "first," "second," and the like, can be used herein to describe various elements, which are not necessarily described in a particular order. Such terms are used merely as labels to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element without departing from the scope of example embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0031] Polar codes have been standardized in 3GPP as the error control code for 5G wireless systems. Polar codes are designed based on the channel polarization theory.
[0032] Figure 1An example channel polarization phenomenon 100 is shown. In this example, after repetition and recursive polar coding, the channel is polarized where most of the samples of the channel have symmetric capacities represented by mutual information values "0" or "1". The mutual information value "1" indicates that the channel is 100% reliable while the mutual information value "0" indicates that the channel is 100% noisy. As Figure 1 shown in the middle, several samples have mutual information values between 0 and 1. If the number of samples reaches infinity, the channel polarization phenomenon can be ideal.
[0033] Figures 2(a), 2(b) and 2(c) show example polar coding structures 200, 205 and 210 with one, two and three polarizations, respectively. The module 215 (denoted by W) represents the channel, u i represents the input, and x i represents the output (i = 1, 2,..., N, where N is any suitable positive integer). If the input u i and the output x i are arranged in the form of vectors u and X, respectively, then Figures 2(a) to 2(c) The recursive polarization depicted in the middle can be generalized and expressed by equation (1) as follows:
[0034] X = uG (1)
[0035] where the polarization matrix G is the Kronecker n-th power of the 2 x 2 matrix and X is the polarized version of the input vector u, that is, the vector containing the encrypted data.
[0036] When the dimension of G exceeds the size of u, a sub-matrix of G is used instead, denoted by G AA . The element in the i-th row, j-th column of G AA is taken from the set A, that is, i e A, j e A. The set A represents the set of indices used to indicate the positions in a given sequence that carry the input data bits. The complement of A is denoted by , which indicates the indices of the rows and columns that are not selected for the sub-matrix G AA .
[0037] It is proposed to use the polarization theory for data encryption. For example, encryption and decryption can be implemented equivalently via the encoding and decoding processes of a polar code. However, conventional encryption methods rely on matrix transformations and are therefore complex. The proposed encryption and decryption complexity is on the order of O(N log N), where N is the length of the input binary data sequence and O(.) is the standard Landau notation.
[0038] The inventors found that the output X of equation (1) can be seen as two separate and independent parts as follows:
[0039] X = [u c] (2)
[0040] The second part c can accordingly be denoted as
[0041]
[0042] Thus, equation (1) is equivalent to equation (2) and equation (3).
[0043] Equation (3) has the following mathematical properties:
[0044] 1. The term G AA is always null, independent of the dimension of G and A. Thus, equation (3) can be rewritten as follows:
[0045]
[0046] 2. The vector v can be an arbitrary vector. In other words, the value of the vector v has no impact on the polarization phenomenon.
[0047] Example embodiments of the present disclosure propose a novel data encryption scheme based on the polarization theory. The scheme utilizes two or more cryptographic keys to polarize encode data to provide a multi-cryptographic security mechanism. Thus, decryption or decoding of the data requires that all of these keys are correct. If any one of the cryptographic keys is incorrect, then decryption will fail. As such, an unauthorized recipient lacking the correct key(s) cannot decrypt and read the original data.
[0048] According to example embodiments of the present disclosure, a cryptographic key (referred to as a first cryptographic key) comprises a vector of cryptographic elements, and an additional cryptographic key (referred to as a second cryptographic key) comprises a set of indices, such as the set A or Corresponding to a subset matrix of the polarization matrix (such as G). In some example embodiments, the set of indices can indicate which of the cryptographic elements in the vector of cryptographic elements are to be used for encryption and / or decryption of the data vector. For example, the cryptographic elements having indices corresponding to respective indices of the set of indices are to be used.
[0049] If the vector of cryptographic elements or the set of indices is incorrect, then the following error cases will occur during decryption or decoding:
[0050] 1. One element is extracted from the vector of incorrect cryptographic elements and has an incorrect position indicated by the corresponding index from the incorrect set of indices.
[0051] 2. One element is extracted from the vector of incorrect cryptographic elements but has a correct position indicated by the corresponding index from the correct set of indices.
[0052] 3. An element is extracted from a vector of correct cipher elements but has an incorrect position indicated by a corresponding index from a set of incorrect indices.
[0053] In any of the above cases, successful decryption or decoding will not be possible. For example, if an incorrect cipher element is inserted or a cipher element is inserted at an incorrect position indicated by an index from a set of indices, the decoding or decryption will fail. As such, the multi-cipher security mechanism according to example embodiments of the present disclosure significantly improves data protection and security.
[0054] Figure 3 An example environment 300 in which example embodiments of the present disclosure can be implemented is shown.
[0055] The environment 300 includes an encrypter 310 and a decrypter 320. The encrypter 310 and the decrypter 320 can be implemented by any suitable device having data encryption and decryption functionality. The encrypter 310 can transmit data to the decrypter 320 in a wireless or wired manner. The data transmission can follow any suitable wireless and / or wired communication standard or protocol and employ any suitable wireless and / or wired communication technology.
[0056] In various example embodiments of the present disclosure, the data transmission from the encrypter 310 to the decrypter 320 uses the polar theory. Specifically, the encrypter 310 performs polar encoding on data using at least two cipher keys to generate ciphers for data encryption. The decrypter 320 thus uses these cipher keys for data decryption. A recipient without the correct cipher keys will not be able to decrypt the data.
[0057] Figure 4 A flowchart of an example method 400 of data encryption according to some example embodiments of the present disclosure is shown. The method 400 can be implemented by the encrypter 310 shown in Figure 3 For discussion purposes, the method 400 will be described with reference to the encrypter 310 shown in Figure 3 The method 400.
[0058] At block 405, the encrypter 310 obtains at least two cipher keys, referred to as a first cipher key and a second cipher key, respectively. The first cipher key includes a vector of cipher elements, and the second cipher key includes a set of indices corresponding to a subset matrix of a polar matrix such as G. In some example embodiments, the first cipher key can be implemented by an arbitrary vector v, and the second cipher key can be implemented by a set A or .
[0059] The cryptographic keys can be obtained by the encryptor 310 in any suitable manner. In some example embodiments, one or both of the cryptographic keys can be predefined or predetermined. For example, the cryptographic key(s) can be burned into the firmware of the encryptor 310 and the decryptor 320 by the manufacturer. The burned cryptographic key(s) can be unique for each individual encryptor and decryptor pair. This provides firmware-level data protection and security. Third party recipients cannot intercept and decode the encrypted information.
[0060] In some example embodiments, one or both of the cryptographic keys can be dynamically configured, e.g., by a system administrator. For example, the cryptographic key(s) can be physically included in a password book and configured by an authorized system administrator. The configured cryptographic key(s) can be changed from time to time to improve data security.
[0061] In some example embodiments, the two cryptographic keys can be configured differently to minimize the possibility of security breach. For example, one key can be burned into the firmware of the encryptor 310 and the decryptor 320 to provide a first level of security at the firmware level. The other cryptographic key can be included in a configured password book so that this cryptographic key can be changed periodically to provide another level of security.
[0062] In some example embodiments, the encryptor 310 can randomly select one or both of the cryptographic keys for data encryption to further improve data security. In this case, the encryptor 310 can indicate or transmit the selected cryptographic key(s) to the decryptor 320 via a secure means (a secure offline transmission channel or a secure online transmission channel) for data decryption.
[0063] After obtaining the cryptographic keys, at block 410, the encryptor 310 generates a cipher vector by polar encoding a data vector based on a polar matrix and at least a first cryptographic key and a second cryptographic key. Any suitable polar encoding algorithm can be applied herein. In the example embodiments implemented, Equation (4) can be used for polar encoding of the data vector u, and the cipher vector is generated as c. Equation (3) or any other polar encoding algorithm can also be used. In the example embodiments implemented, Equation (4) can be used for polar encoding of the data vector u, and the cipher vector is generated as c. Equation (3) or any other polar encoding algorithm can also be used.
[0064] In some example embodiments, the encryptor 310 can generate a subvector of the cipher elements from the vector of the cipher elements to further improve data privacy protection. The subvector of the cipher elements can be randomly selected by the encryptor 310.
[0065] Alternatively, a sub-vector of the cipher elements can be selected based on a set of indices as the second cipher key. For example, the set of indices can indicate which cipher elements in the vector of cipher elements are to be used for encryption and decryption. Thus, the indices of the cipher elements of the sub-vector correspond to the indices of the set of indices. In this case, inserting incorrect elements in the sub-vector or inserting elements with incorrect indices in the sub-vector will result in decryption failure. As such, data security can be significantly improved.
[0066] At block 415, the encrypter 310 combines the data vector and the generated cipher vector to encrypt the data vector. The data and cipher vectors can be combined in any suitable manner. For example, the encrypter 310 can concatenate the data and cipher vectors using Equation (2). As another example, the data and cipher vectors can be interleaved by the encrypter 310 according to a rule. Thus, the encrypter 310 can indicate or communicate the rule to the decrypter 320 for data decryption.
[0067] According to example embodiments of the present disclosure, the encrypter 310 employs at least two cipher keys during encryption of the data. In order to successfully decode the encrypted data, all the cipher keys are required by the receiving party. Any incorrectness of any key will result in decryption failure. The encrypted data can only be correctly decrypted when all the keys are correct.
[0068] Figure 5 A flowchart of an example process 500 according to some example embodiments of the present disclosure is shown. The process 500 can be an example implementation of the method 400 as shown in Figure 4 FIG. 4. For purposes of discussion, reference will be made to Figure 3 the process 500 will be described.
[0069] After the process 500 starts at block 505, at block 510, the encrypter 310 randomly selects a set A as the second cipher key and selects an arbitrary vector v as the first cipher key. At block 515, the encrypter 310 applies Equation (4) and the two cipher keys A and v to encode the data vector (expressed as vector u) and derive a cipher vector c, and then applies Equation (2) to concatenate u and c for constructing an encrypted data vector (expressed as vector X). At block 520, the encrypter 310 assigns each element of the concatenated u and c to X by the indices defined by A. At block 525, the encrypter 310 assigns each element of the concatenated u and c to X by the indices defined by the frozen set At block 520 and 525, the assignments can also be performed before the concatenation of u and c. Then, the method 500 ends at block 530.
[0070] On the receiving party side, the encrypted data is distorted by the communication medium and corrupted by noise. The decrypter 320 can use any suitable decoding method, existing or to be developed in the future, to decrypt the data.
[0071] Figure 6 A flowchart of an example method 600 of data decryption is shown in accordance with some example embodiments of the present disclosure. The method 600 can be implemented by the decrypter 320 shown in FIG. 3. Figure 3 For purposes of discussion, the method 600 will be described with reference to the decrypter 320 shown in FIG. 3. Figure 3 The method 600 will be described.
[0072] At block 605, the decrypter 320 obtains a first cryptographic key and a second cryptographic key. The first cryptographic key includes a vector of cryptographic elements, and the second cryptographic key includes a set of indices corresponding to a subset matrix of a polarizing matrix, such as G. The cryptographic key(s) can be obtained by the decrypter 320 in any suitable manner. For example, in example embodiments where one or both of the cryptographic keys can be predefined or predetermined, the decrypter 320 can know the cryptographic key(s) in advance. As another example, the cryptographic key(s) can be dynamically configured by a system administrator, for example. Alternatively or additionally, the cryptographic key(s) can be received from the encrypter 310.
[0073] At block 610, the decrypter 320 derives a combination of a data vector and a cryptographic vector by polar decoding the encrypted data vector based on the first cryptographic key and the second cryptographic key. The cryptographic vector is generated at the encrypter 310 by polar encoding the data vector based on the first cryptographic key and the second cryptographic key and the polarizing matrix. The combination of the data and cryptographic vectors can be implemented by concatenation of the data and cryptographic vectors, interleaving of the data and cryptographic vectors, and any other combination form.
[0074] At block 615, the decrypter 320 obtains the data vector from the combination of the data and cryptographic vectors. The recovery of the data vector can be implemented based on the combination form used by the encrypter 310. In example embodiments where the encrypter 310 interleaves the data and cryptographic vectors according to a particular rule, the decrypter 320 can receive the rule from the encrypter 310 and use the rule to derive the data vector from the interleaved data and cryptographic vectors.
[0075] As an example, the decrypter 320 can employ successive cancellation polar decoding during data decryption. An example process of successive cancellation polar decoding will be discussed below.
[0076] Suppose the scrambled and distorted version of the receiver X is denoted by y, and denote a vector y of length N = 2 n Suppose further that denote sub-vectors (a i ... a j ), where j < i are considered invalid, denoted by a i ......a j where only elements with even indices are selected, and denoted by a i ......a j where only elements with odd indices are selected. Furthermore, the decrypted version of u is denoted by
[0077] The decryption of y can be considered as a successive cancellation performed in a recursive manner to recover and The key part is to compute the likelihood ratio (LR). The LR is a conditional probability. Starting from the simplest case, as shown in Fig. 2(a), if the module 215 (denoted by W) is considered as a black box and the transition probabilities are used to define the relationship between the input and output of W, the conditional probability of the outputs y1, y2can be written as follows:
[0078] For y1,
[0079] For y2,
[0080] Figs. 2(b) and 2(c) illustrate scenarios where the polarization is applied repeatedly and recursively. These scenarios can be formulated by extending the equations (5) and (6) to any n > 0, N = 2 n , 1 < i < N, as follows,
[0081] For odd-indexed bits,
[0082]
[0083] For even-indexed bits,
[0084]
[0085] The decryption process is performed in a successive manner from the first bit to the last bit using the first cryptographic key and the second cryptographic key. For example, during the decryption of the ithbit, the decrypter 320 observes the received y and the previously decrypted information bits and generates an estimate The decrypter 320 can be considered as composed of N decision elements (DEs), each DE for one source element u i These DEs are activated in the order from 1 to N. If then the element u i is known. Thus, in the first cryptographic key is implemented by the vector v and the second cryptographic key is implemented by the set In an example embodiment, when the ith DE is activated, the ith DE searches the vector for index f such that Then, the ith DE simply sets and sends this result to all subsequent DEs. If i e A, the ith DE waits until it receives the previous decision Upon receipt, the ith DE computes the likelihood ratio (LR) as follows:
[0086]
[0087] The ith DE generates its decision as:
[0088]
[0089] The decision is then sent to all subsequent DEs. This is a single pass algorithm with no modification of estimates. The complexity of the algorithm is determined primarily by the complexity of computing the LR, which is O(N log N) in the standard Landau notation.
[0090] The simple computation using recursive formulas (7) and (8) is given as follows:
[0091] For odd index bits,
[0092]
[0093] For even index bits,
[0094]
[0095] The computation of the LR of length N is reduced to the computation of two LR of length N / 2. This recursion can continue down to block length 1, at which point the LR takes the form which can be computed directly.
[0096] All operations and features at the encrypter 310 as described above with reference to Figures 3 to 5 apply equally to the decrypter 320 and have similar effects. Details will be omitted for brevity.
[0097] Figure 7 An example decryption process 700 using a depth-first algorithm is shown in accordance with some example embodiments of the present disclosure. As shown, each node 705-K (K = 1, 2, …, 32) represents a DE of the decrypter 320, and the number K indicates the order of the DE to be activated.
[0098] According to example embodiments of the present disclosure, the decrypter 320 can correctly decrypt the data only when it knows both or more cryptographic keys. For example, in an example embodiment where the first cryptographic key is a set of cryptographic elements and the second cryptographic key is a set of indices to indicate which cryptographic elements in the set of cryptographic elements are to be used for data encryption, the decrypter 320 needs to know the correct indices of the correct cryptographic elements used for data encryption.
[0099] The decryption process is performed in a sequential manner, which means that the decision of the current bit value depends on the decoding result of the previous bit. Furthermore, the term "sequential" also means that each bit is processed in a sequential order. Once a certain bit is accessed, it will never be accessed again (revisited). In other words, the decryption procedure is sequential, which means that it is a single-pass process. Once a bit is decrypted (even if the result is wrong), there is no chance to look back. Therefore, if a decision error occurs, it cannot be corrected. These properties are mathematically shown in equations (5)-(12). As a result, only when both cryptographic keys are legitimate, the correct decryption can be achieved. Otherwise, even a single decision error occurs, the whole data will be corrupted because the wrongly decrypted bits cannot be corrected. Even a single bit error will inevitably lead to a disastrous decoding / decryption result.
[0100] For the brute-force search attack, an active attacker will usually keep checking all possible keys in the key space until he or she successfully finds the expected (correct) key. With the proposed scheme, assuming the original binary data to be transmitted has a length of The length of the encrypted binary data prepared for transmission is The encryption overhead can be formulated as For example, bits, p = 1 / 3. The set The dimension of the set 341 Furthermore, during decryption, each element from the set has to be inserted into the correct position. This 341-bit length overhead can be scattered and located at any combination of possible positions among the 1024 bits, i.e., Therefore, the total number of attempts in the worst case should be at least This number is astronomical, and therefore the attack is infeasible.
[0101] By carefully designing the whole system mechanism, the message-replay attack and the chosen-plaintext attack can be easily circumvented. For example, using different information sets A for the initial transmission and the first retransmission, the message-replay attack can be circumvented.
[0102] Figure 8is a simplified block diagram of a device 800 suitable for implementing example embodiments of the present disclosure. The device 800 can be implemented by or include the encrypter 310, or be implemented by or include the decrypter 320.
[0103] As shown, the device 800 includes a processor 810 and a memory 820 coupled to the processor 810. The memory 820 stores at least a program 830, assuming the program includes executable instructions, which when executed by the associated processor 810, enable the device 800 to operate in accordance with the example embodiments of the present disclosure, as discussed herein. Figures 3 to 7 The example embodiments herein can be implemented by computer software executable by the processor 810 of the device 800, or by hardware, or by a combination of software and hardware. The processor 810 can be configured to implement various example embodiments of the present disclosure.
[0104] The memory 820 can be of any type suitable to the local technical network and can use any suitable data storage technology, as non-limiting examples such as non-transitory computer-readable storage media, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. While only one memory 820 is illustrated in the device 800, there can be several physically separate memory modules in the device 800. The processor 810 can be of any type suitable to the local technical network, and can include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multi-core processor architectures, as non-limiting examples. The device 800 can have multiple processors such as special integrated circuit chips that are time-slaved to a clock that is synchronized with a master processor.
[0105] When the device 800 acts as or includes the encrypter 310, the processor 810 can implement the methods 400 and 500 as described above with reference to Figures 3 to 5 When the device 800 acts as or includes the decrypter 320, the processor 810 can implement the method 600 as described above with reference to Figures 6 to 7 All operations and features described above with reference to Figures 3 to 7 have similar effects for the device 700. Details will be omitted for brevity.
[0106] In general, the various example embodiments of the present disclosure can be implemented in hardware or special-purpose circuits, software, logic or any combination thereof. Some aspects can be implemented in hardware, while other aspects can be implemented in
[0107] The present disclosure also provides at least one computer program product tangibly embodied on a non-transitory computer readable storage medium. The computer program product includes computer executable instructions, such as those included in program modules, executed by devices on a target real or virtual processor to perform the methods 400, 500, and 600 described above with reference to Figures 3 to 7 Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules can be combined or split between program modules as desired in various example embodiments. Machine executable instructions for program modules can be executed within a local or distributed device. In a distributed device, program modules can be located in local and remote memory storage devices.
[0108] Program code used to implement examples of the present disclosure can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, causes the machine to perform the described functions / operations described in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0109] In the context of the present disclosure, computer program code or related data can be carried by any suitable carrier to enable devices, apparatuses, or processors to perform various processes and operations as described above. Examples of carriers include signals, computer readable media.
[0110] The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0111] Moreover, while operations are depicted in a particular order, this should not be understood as requiring such an order, or that all illustrated operations be performed, to achieve desirable results. In certain scenarios, parallel processing and / or overlapping processing can be advantageous. Likewise, while several specific implementation details are contained in the above discussion, these should not be construed as limiting the scope of the disclosure but merely as describing techniques that can be specific to particular embodiments. Certain features described in the context of separate embodiments can also be implemented together in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented separately or in any suitable subcombination.
[0112] While the disclosure has been described in terms of specific embodiments thereof, it should be apparent that the scope of the disclosure is not limited to the specific embodiments described and / or illustrated. Rather, the scope of the disclosure is to be understood as encompassing any embodiments with features that are within the scope of the claims now or hereafter attached to the disclosure.
[0113] Various example embodiments of these techniques have been described. In addition to or in lieu of the foregoing, the following embodiments are described. Features described in any of the following examples can be used with any other example described herein.
[0114] In some aspects, an apparatus comprising: at least one processor; at least one memory including computer program code; the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to: obtain a first cryptographic key comprising a vector of cryptographic elements and a second cryptographic key comprising a set of indices corresponding to a subset matrix of a polarizing matrix; generate a vector cryptogram by polar encoding a data vector based on the first cryptographic key and the second cryptographic key and the polarizing matrix; combine the data vector and the vector cryptogram for encrypting the data vector.
[0115] In some example embodiments, the device is caused to combine the data vector and the cipher vector by concatenating the data vector and the cipher vector.
[0116] In some example embodiments, the device is caused to generate the cipher vector by generating, based on the set of indices, a sub-vector of cipher elements from the vector of cipher elements, the cipher elements of the sub-vector having indices corresponding to the indices of the set of indices in the vector of cipher elements; and performing polar encoding on the data using the polarizing matrix, the set of indices, and the sub-vector of cipher elements to generate the cipher vector.
[0117] In some example embodiments, at least one of the first cipher key and the second cipher key is dynamically configured or randomly selected.
[0118] In some example embodiments, a device comprises at least one processor; at least one memory including computer program code; the at least one memory and the computer program code are configured to, with the at least one processor, cause the device to obtain a first cipher key comprising a vector of cipher elements and a second cipher key comprising a set of indices corresponding to a subset matrix of a polarizing matrix; derive a combination of a data vector and a cipher vector by polar decoding encrypted data based on the first cipher key and the second cipher key, the cipher vector being generated by polar encoding the data vector based on the first cipher key and the second cipher key and the polarizing matrix; and obtain the data vector from the combination of the data vector and the cipher vector.
[0119] In some example embodiments, the combination of the data vector and the cipher vector comprises a concatenation of the data vector and the cipher vector.
[0120] In some example embodiments, the device is caused to derive the combination of the data vector and the cipher vector by generating, based on the set of indices, a sub-vector of cipher elements from the vector of cipher elements, the cipher elements of the sub-vector having indices corresponding to the indices of the set of indices in the vector of cipher elements; and performing polar decoding on the encrypted data using the set of indices and the sub-vector of cipher elements to derive the combination of the data vector and the cipher vector.
[0121] In some aspects, a method of data encryption comprises obtaining a first cipher key comprising a vector of cipher elements and a second cipher key comprising a set of indices corresponding to a subset matrix of a polarizing matrix; generating a cipher vector by polar encoding a data vector based on the first cipher key and the second cipher key; and combining the data vector and the cipher vector for encrypting the data vector.
[0122] In some example embodiments, combining the data vector and the cipher vector includes concatenating the data vector and the cipher vector.
[0123] In some example embodiments, generating the cipher vector includes generating a subvector of cipher elements from the vector of cipher elements based on the set of indices, the cipher elements of the subvector having indices corresponding to the indices of the set of indices in the vector of cipher elements; and performing polar encoding on the data vector using the polar matrix, the set of indices, and the subvector of cipher elements to generate the cipher vector.
[0124] In some example embodiments, at least one of the first cipher key and the second cipher key is dynamically configured or randomly selected.
[0125] In some aspects, a method of data decryption includes obtaining a first cipher key and a second cipher key, the first cipher key including a vector of cipher elements and the second cipher key including a set of indices corresponding to a subset matrix of a polar matrix; deriving a combination of a data vector and a cipher vector by polar decoding encrypted data based on the first cipher key and the second cipher key, the cipher vector generated by polar encoding the data vector based on the first cipher key and the second cipher key and the polar matrix; and obtaining the data vector from the combination of the data vector and the cipher vector.
[0126] In some example embodiments, the combination of the data vector and the cipher vector includes a concatenation of the data vector and the cipher vector.
[0127] In some example embodiments, deriving the combination of the data vector and the cipher vector includes generating a subvector of cipher elements from the vector of cipher elements based on the set of indices, the cipher elements of the subvector having indices corresponding to the indices of the set of indices in the vector of cipher elements; and performing polar decoding on the encrypted data using the set of indices and the subvector of cipher elements to derive the combination of the data vector and the cipher vector.
[0128] In some aspects, an apparatus for data decryption includes means for obtaining a first cipher key and a second cipher key, the first cipher key including a vector of cipher elements and the second cipher key including a set of indices corresponding to a subset matrix of a polar matrix; means for generating a cipher vector by polar encoding a data vector based on the first cipher key and the second cipher key and the polar matrix; and means for concatenating the data vector and the cipher vector for encrypting the data vector.
[0129] In some example embodiments, the means for combining the data vector and the cipher vector includes means for concatenating the data vector and the cipher vector.
[0130] In some example embodiments, the means for generating the cipher vector includes means for generating a subvector of cipher elements from the vector of cipher elements based on the set of indices, the cipher elements of the subvector having indices corresponding to the indices of the set of indices in the vector of cipher elements, and means for performing polar encoding on the data using the polar matrix, the set of indices, and the selected subset of cipher elements to generate the cipher vector.
[0131] In some example embodiments, at least one of the first cipher key and the second cipher key is dynamically configured or randomly selected.
[0132] In some aspects, an apparatus for data decryption includes means for obtaining a first cipher key and a second cipher key, the first cipher key including a vector of cipher elements and the second cipher key including a set of indices corresponding to a subset matrix of a polar matrix; means for deriving a combination of a data vector and a cipher vector by polar decoding an encrypted data vector based on the first cipher key and the second cipher key, the cipher vector being generated by polar encoding the data vector based on the first cipher key and the second cipher key and the polar matrix; and means for obtaining the data vector from the combination of the data vector and the cipher vector.
[0133] In some example embodiments, the combination of the data vector and the cipher vector includes a concatenation of the data vector and the cipher vector.
[0134] In some example embodiments, the means for deriving the combination of the data vector and the cipher vector includes means for generating a subvector of cipher elements from the vector of cipher elements based on the set of indices, the cipher elements of the subvector having indices corresponding to the indices of the set of indices in the vector of cipher elements, and means for performing polar decoding on the encrypted data using the set of indices and the subvector of cipher elements to derive the combination of the data vector and the cipher vector.
[0135] In some aspects, a computer-readable storage medium includes program instructions stored thereon that, when executed by a processor of a device, cause the device to perform a method according to some example embodiments of the present disclosure.
Claims
1. A device for data encryption, comprising: At least one processor; as well as At least one memory, including computer program code; The at least one memory and the computer program code are configured, together with the at least one processor, to cause the device to perform at least the following operations: Obtain a first cryptographic key and a second cryptographic key, wherein the first cryptographic key comprises a vector v of cryptographic elements, and the second cryptographic key comprises a subset matrix G. AA The corresponding set of first indices A, wherein the subset matrix includes elements of the polarization matrix G selected based on the first index; A cryptographic vector c is generated by polar encoding a data vector u based on multiple versions of the first and second cryptographic keys, wherein the multiple versions of the second cryptographic key include a first version, a second version, and a third version. The first version is based on the first index A, and the second version is based on the complementary set of a second index denoted as A̅ that is not in the first index, corresponding to the subset matrix G. AA̅ The third version is based on the indices of rows and columns not selected from the polarization matrix G. AA̅ Both the first index A and the second index A̅ correspond to the row and column indices selected from the polarization matrix G as index A and unselected as index A̅, wherein the cryptographic vector c is generated according to the following formula: ; as well as The data vector u and the password vector v are linked together for encrypting the data vector.
2. The device according to claim 1, wherein: Linking the data vector to the cryptographic vector for encrypting the data vector includes performing X=[uc], where X is the encryption of the data vector based on the cryptographic vector.
3. The device according to claim 2, wherein the cryptographic element vector v is an arbitrary vector.
4. The device of claim 1, wherein the polarization matrix has a dimension exceeding the size of the data vector, and the acquisition of the second cryptographic key is performed because the polarization matrix has a dimension exceeding the size of the data vector.
5. The device according to claim 4, wherein the polarization matrix is a 2x2 matrix raised to the power of Kronecker n.
6. An apparatus for data decryption, comprising: At least one processor; as well as At least one memory, including computer program code; The at least one memory and the computer program code are configured, together with the at least one processor, to cause the device to perform at least the following operations: Obtain a first cryptographic key and a second cryptographic key, wherein the first cryptographic key comprises a vector v of cryptographic elements, and the second cryptographic key comprises a subset matrix G of the polarization matrix G. AA The corresponding set of first indices A, wherein the subset matrix includes elements of the polarization matrix G selected based on the first index; A combination of data vector u and cryptographic vector c is obtained by polarity decoding of the encrypted data vector based on multiple versions of the first and second cryptographic keys. The multiple versions of the second cryptographic key include a first version, a second version, and a third version. The first version is based on the first index A, and the second version is based on the complementary set of a second index denoted as A̅ that is not in the first index, corresponding to the subset matrix G. AA̅ The third version is based on the indices of rows and columns not selected from the polarization matrix G. AA̅ Both the first index A and the second index A̅ correspond to the row and column indices selected as index A and unselected as index A̅ from the polarization matrix G. The cryptographic vector is generated by polar encoding the data vector according to the following formula: ;as well as The data vector is obtained from the combination of the data vector and the password vector.
7. The device of claim 6, wherein the combination of the data vector and the cryptographic vector comprises: The connection between the data vector and the password vector; Connecting the data vector to the cryptographic vector for encrypting the data vector includes performing X=[uc], where X is the encryption of the data vector based on the cryptographic vector.
8. The device according to claim 7, wherein the cryptographic element vector v is an arbitrary vector.
9. The device of claim 6, wherein the polarization matrix has a dimension exceeding the size of the data vector, and the acquisition of the second cryptographic key is performed because the polarization matrix has a dimension exceeding the size of the data vector.
10. The device of claim 9, wherein the polarization matrix is a 2x2 matrix raised to the power of Kronecker n.
11. A method for encrypting data, comprising: Obtain a first cryptographic key and a second cryptographic key, wherein the first cryptographic key comprises a vector v of cryptographic elements, and the second cryptographic key comprises a subset matrix G of the polarization matrix G. AA The corresponding set of first index A, the subset matrix includes elements of the polarization matrix selected based on the first index; A cryptographic vector c is generated by polar encoding a data vector u based on multiple versions of the first and second cryptographic keys. The multiple versions of the second cryptographic key include a first version, a second version, and a third version. The first version is based on a first index A, the second version is based on a complementary set of second indices denoted as A̅ that are not in the first index, and the third version is based on a subset matrix G. AA̅ The third version of both the first index A and the second index A̅ corresponds to the row and column indices selected from the polarization matrix G as index A and unselected as index A̅, wherein the cipher vector c is generated according to the following formula: ;as well as The data vector u and the password vector v are linked together for encrypting the data vector.
12. The method according to claim 11, wherein: Linking the data vector to the cryptographic vector for encrypting the data vector includes performing X=[uc], where X is the encryption of the data vector based on the cryptographic vector.
13. The method of claim 12, wherein the cryptographic element vector v is an arbitrary vector.
14. The method of claim 11, wherein the dimension of the polarization matrix exceeds the size of the data vector, and the acquisition of the second cryptographic key is performed because the dimension of the polarization matrix exceeds the size of the data vector.
15. The method of claim 14, wherein the polarization matrix is a Kronecker power of a 2×2 matrix.
16. A method for data decryption, comprising: Obtain a first cryptographic key and a second cryptographic key, wherein the first cryptographic key comprises a vector v of cryptographic elements, and the second cryptographic key comprises a subset matrix G of the polarization matrix G. AA The corresponding set of first index A, the subset matrix includes elements of the polarization matrix selected based on the first index; A combination of data vector u and cryptographic vector c is obtained by polar decoding of the encrypted data vector based on multiple versions of the first and second cryptographic keys. The multiple versions of the second cryptographic key include a first version, a second version, and a third version. The first version is based on the first index A, and the second version is based on the complementary set of a second index, denoted as A̅, that is not in the first index, corresponding to the subset matrix G. AA̅ The third version is based on the indices of rows and columns not selected from the polarization matrix G. AA̅ Both the first index A and the second index A̅ correspond to the row and column indices selected as index A and unselected as index A̅ from the polarization matrix G. The cryptographic vector is generated by polar encoding the data vector according to the following formula: ;as well as The data vector is obtained from the combination of the data vector and the password vector.
17. The method of claim 16, wherein the combination of the data vector and the cryptographic vector comprises: The connection between the data vector and the password vector, Connecting the data vector to the cryptographic vector for encrypting the data vector includes performing X=[uc], where X is the encryption of the data vector based on the cryptographic vector.
18. The method of claim 17, wherein the cryptographic element vector v is an arbitrary vector.
19. The method of claim 16, wherein the polarization matrix has a dimension exceeding the size of the data vector, and the acquisition of the second cryptographic key is performed because the polarization matrix has a dimension exceeding the size of the data vector.
20. The method of claim 19, wherein the polarization matrix is a 2x2 matrix raised to the power of Kronecker n.
21. A data encryption device, comprising: Components for obtaining a first cryptographic key and a second cryptographic key, wherein the first cryptographic key comprises a vector v of cryptographic elements, and the second cryptographic key comprises a subset matrix G of the polarization matrix G. AA The corresponding set of first index A, the subset matrix includes elements of the polarization matrix selected based on the first index; A component for generating a cryptographic vector c by polar encoding a data vector u based on multiple versions of a first cryptographic key and a second cryptographic key, wherein the multiple versions of the second cryptographic key include a first version, a second version, and a third version, the first version being based on a first index A, and the second version being based on a complementary set of second indices denoted as A̅ that are not in the first index, corresponding to a subset matrix G. AA̅ The third version is based on the indices of rows and columns not selected from the polarization matrix G. AA̅ Both the first index A and the second index A̅ correspond to the row and column indices selected from the polarization matrix G as index A and unselected as index A̅, wherein the cryptographic vector c is generated according to the following formula: ; as well as A component for connecting the data vector and the cryptographic vector for encrypting the data vector.
22. A data decryption apparatus, comprising: Components for obtaining a first cryptographic key and a second cryptographic key, wherein the first cryptographic key comprises a vector v of cryptographic elements, and the second cryptographic key comprises a subset matrix G of the polarization matrix G. AA The corresponding set of first index A, the subset matrix includes elements of the polarization matrix selected based on the first index; A component for deriving a combination of a data vector u and a cryptographic vector c by polar decoding an encrypted data vector based on multiple versions of a first cryptographic key and a second cryptographic key, wherein the multiple versions of the second cryptographic key include a first version, a second version, and a third version, the first version being based on a first index A, the second version being based on a complementary set of second indices denoted as A̅ that are not in the first index, and the third version being based on a subset matrix G. AA̅ The first index A and the second index A̅ correspond to the row and column indices selected as index A and unselected as index A̅ from the polarization matrix G. The cryptographic vector is generated by polar encoding the data vector according to the following formula: ;as well as A component for obtaining the data vector from the combination of the data vector and the password vector.
23. A computer-readable storage medium comprising program instructions stored thereon, which, when executed by a processor of a device, cause the device to perform the method according to any one of claims 11 to 15.
24. A computer-readable storage medium comprising program instructions stored thereon, which, when executed by a processor of a device, cause the device to perform the method according to any one of claims 16 to 20.