Encryption device, decryption device, encryption method, decryption method, and computer-readable recording medium

By updating the values of b and r bits, the integrity corruption problem caused by b bit value conflict in Tweakable block encryption authentication encryption is solved, and high-security authentication encryption is achieved, reducing the frequency of key updates.

CN115039374BActive Publication Date: 2025-07-18MITSUBISHI ELECTRIC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080094939.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-02-06
Publication Date
2025-07-18
Estimated Expiration
2040-02-06

AI Technical Summary

Technical Problem

The authenticated encryption of existing Tweakable block encryption conflicts on the decryption function Dec side of the decryption function leads to integrity damage, and the key updates are frequent and the cost is high.

Method used

By updating the encryption function E of the value S1 of the b bit and updating the value of the r bit, the ciphertext and authentication characters of the b+r bit are generated to ensure that the value of the b+r bit is updated during decryption.

Benefits of technology

The bit security of b+r bits is realized, reducing the frequency of key updates, and improving security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115039374B_ABST
    Figure CN115039374B_ABST
Patent Text Reader

Abstract

The dividing unit (22) divides the plaintext M into b-bit values starting from the beginning and generates b-bit values M1, ..., M m‑1 and a value M of 1 bit or more and b bits or less m The S1 calculation unit (241) sets the b-bit value H1 to the value M0, and for each integer i where i=1, ..., m, sets the value M0 in ascending order. i‑1 As the input of encryption function E, the value S1(i) is calculated according to the value S1(i) and the value M i Calculated value C i The S2 calculation unit (242) sets the r-bit value H2 to the value S2(0), and calculates the value S2(i) from the value S1(i) and the value S2(i-1) for each integer i of i=1,...,m in ascending order. The ciphertext generation unit (243) generates the ciphertext based on the value C associated with each integer i of i=1,...,m. i Generate ciphertext C. The authenticator generation unit (25) generates an authenticator T of b+r bits using the value S1(m) and the value S2(m).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authenticated encryption algorithm using block encryption. Background Art

[0002] An authenticated encryption algorithm is an encryption algorithm that realizes a concealment function and a tampering detection function. When using an authenticated encryption algorithm, it is possible to communicate after concealing a message between the two, and the receiver can confirm whether the sent message has been tampered with.

[0003] The authenticated encryption algorithm has two algorithms: an encryption function Enc and a decryption function Dec.

[0004] The encryption function Enc is a function that takes as input a secret key K, a random number N, public data A, and a plaintext M and outputs a ciphertext C and an authentication tag T for tampering detection. In addition, the random number N uses a different value each time encryption is performed, and the same value is not used as long as the secret key K is not changed.

[0005] The decryption function Dec takes as input a secret key K, a random number N, public data A, a ciphertext C, and an authentication tag T' for tampering detection, and outputs a plaintext M when the input values have not been tampered with, and outputs a value indicating forgery when they have been tampered with. Hereafter, the value indicating forgery is represented as ⊥.

[0006] Let the sender Alice and the receiver Bob communicate using an authenticated encryption algorithm. The secret key K is shared in advance by the sender Alice and the receiver Bob.

[0007] The sender Alice takes as input a secret key K, a random number N, public data A, and a plaintext M, and calculates a ciphertext C and an authentication tag T for tampering detection using the encryption function Enc. Then, the sender Alice sends the random number N, the public data A, the ciphertext C, and the authentication tag T for tampering detection to the receiver Bob.

[0008] The receiver Bob sets the secret key K, the random number N, the public data A, the ciphertext C, and the authentication tag T for tampering detection as the input to the decryption function Dec. The decryption function Dec outputs a plaintext M when the random number N, the public data A, the ciphertext C, and the authentication tag T for tampering detection have not been tampered with.

[0009] In addition, the public data A is a value that can be made public. The public data A may also be absent. Furthermore, the sender Alice uses a different value as the random number N each time encryption is performed, and does not use the same value.

[0010] Regarding the security of authenticated encryption, there are the concealment and integrity defined in Non-Patent Document 1.

[0011] Secrecy defines the security that the plaintext cannot be leaked from the ciphertext. In the security game related to secrecy, the attacker accesses either the encryption function Enc of the authenticated encryption method or the Oracle that outputs random numbers, and identifies which one has been accessed. The probability that the attacker correctly identifies is called the identification probability. The lower the identification probability, the higher the security of secrecy.

[0012] Integrity defines the security that the public data or ciphertext cannot be tampered with. In the security game related to integrity, the attacker accesses the encryption function Enc and the decryption function Dec of the authenticated encryption method, and inputs forged public data, ciphertext, and authentication tags to the decryption function Dec with the goal of passing the tampering check. The probability of passing this tampering check is called the forgery probability. The lower the forgery probability, the higher the security of integrity.

[0013] As a structural method of authenticated encryption algorithms, there is a method using Tweakable block ciphers.

[0014] Tweakable block ciphers consist of an encryption function E and a decryption function D. The encryption function E is a function that takes as input a key K, a Tweak value TW, and a b-bit plaintext block M and outputs a b-bit ciphertext block C. It is written as C = E(K, TW, M). The decryption function D of Tweakable block ciphers is a function that takes as input a key K, a Tweak value TW, and a b-bit ciphertext block C and outputs a b-bit plaintext block M. It is written as M = D(K, TW, C).

[0015] The size b of the plaintext block M and the ciphertext block C is called the block size. When the key K and the Tweak value TW are fixed, the encryption function E and the decryption function D of Tweakable block ciphers become b-bit permutation functions. Generally, a secret value is used as the key K, and a publicly available value is used as the Tweak value TW. Let the set of Tweak values be TWset and the set of keys be Kset. That is, the Tweak value TW is selected from TWset, and the key K is selected from Kset.

[0016] Specific algorithms for Tweakable block ciphers are described in Non-Patent Documents 2 and 3.

[0017] Examples of the specific values of TWset, Kset, and the block size b of Tweakable block ciphers are described in Non-Patent Document 2. SKINNY-128-384 described in Non-Patent Document 2 is a Tweakable block cipher with a block size of 128 bits and the total length of the Tweak value and the key length being 384 bits. Therefore, when the length of the Tweak value is set to 256 bits, the block size b = 128, Kset = {0, 1} 128 , TWset = {0, 1}256 。

[0018] When constructing authenticated encryption using Tweakable block cipher, the encryption function Enc is composed of the encryption function E of Tweakable block cipher, and the decryption function Dec is composed of the encryption function E or the decryption function D of Tweakable block cipher.

[0019] When designing authenticated encryption using Tweakable block cipher, when proving the security of authenticated encryption, as defined in Non-Patent Document 4, Tweakable block cipher is replaced with Tweakable random permutation.

[0020] As the authenticated encryption with the highest security among the previously proposed authenticated encryptions using Tweakable block cipher, there are ΘCB described in Non-Patent Document 4, PFB described in Non-Patent Document 5, and Romulus described in Non-Patent Document 6.

[0021] Regarding the concealment property, the recognition probability for these methods is 0. Regarding the integrity property, with respect to the number of accesses q to the decryption function Dec of the authenticated encryption D , the forgery probability is q D / 2 b 。

[0022] These authenticated encryptions have a forgery probability less than 1 before q D becomes 2 b . Therefore, before q D becomes 2 b , the security of the authenticated encryption can be ensured. The bit security is the value obtained by applying log2 to q when the probability becomes 1. Therefore, the bit security of these authenticated encryptions is b bits (=log22 D ). b )

[0023] Prior Art Documents

[0024] Non-Patent Documents

[0025] Non-Patent Document 1: Tetsu Iwata, Keisuke Ohashi, and Kazuhiko Minematsu. Breaking and Repairing GCM Security Proofs. CRYPTO 2012, Proceedings. pages 31 - 49. Lecture Notes in Computer Science volume7417. Springer. 2012.

[0026] Non-Patent Document 2: Christof Beierle, Jeremy Jean, Stefan Kolbl, Gregor Leander, Amir Moradi, Thomas Peyrin, Yu Sasaki, Pascal Sasdrich, and Siang Meng Sim. The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS. CRYPTO 2016, Proceedings, Part II. pages 123-153. Lecture Notes in Computer Science volume 9815. Springer. 2016.

[0027] Non-Patent Document 3: Jeremy Jean, Ivica Nikolic, and Thomas Peyrin. Tweaks and Keys for Block Ciphers: The TWEAKEY Framework. ASIACRYPT 2014, Proceedings, Part II. pages 274-288. Lecture Notes in Computer Science volume 8874. Springer. 2014.

[0028] Non-Patent Document 4: Ted Krovetz and Phillip Rogaway. The Software Performance of Authenticated-Encryption Modes. FSE 2011. pages 306-327. Lecture Notes in Computer Science volume 6733. Springer. 2011.

[0029] Non-Patent Document 5: Yusuke Naito and Takeshi Sugawara. Lightweight Authenticated Encryption Mode of Operation for Tweakable Block Ciphers. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020 volume 1. pages 66-94.

[0030] Non-Patent Document 6: Tetsu Iwata, Mustafa Khairallah, Kazuhiko Minematsu, and Thomas Peyrin. Duel of the Titans: The Romulus and Remus Families of Lightweight AEAD Algorithms. IACR Cryptology ePrint Archive 2019 / 992. Summary of the Invention

[0031] Problems to be Solved by the Invention

[0032] Authenticated encryption using Tweakable block cipher described in any one of Non-Patent Documents 4 to 6 also has a structure in which a value of b bits is updated on the Dec side of the decryption function. However, by taking advantage of the collision of the values of b bits, the integrity of the authenticated encryption is compromised. A collision of the values of b bits means that the values of b bits are the same for two different inputs to the authenticated encryption.

[0033] The value of b bits is as shown in 2 b like that. Therefore, by performing the operation of the decryption function Dec twice, the integrity can be compromised. That is, the theoretical limit of the bit security of the structure of the prior art is b bits. b In authenticated encryption, in order to ensure security, the key of the authenticated encryption is updated before the recognition probability or the forgery probability becomes 1. On the other hand, key update takes labor time and cost. Therefore, an authenticated encryption with a long life of one key, that is, a low update frequency, is preferred. An authenticated encryption with a small recognition probability and forgery probability, that is, a high bit security, can further reduce the key update frequency.

[0034] An object of the present invention is to achieve authenticated encryption with high bit security.

[0035] Means for Solving the Problems

[0036] The encryption device of the present invention includes: an acquisition unit that acquires a plaintext M; a division unit that divides the plaintext M acquired by the acquisition unit from the beginning by every b bits to generate values M1,..., M of b bits

[0037] and a value M of 1 bit or more and b bits or less, where the b bits are the block size of the encryption function E of the block cipher; an S1 calculation unit that sets a value H1 of b bits as the value M0, and for each integer i from 1 to m in ascending order, sets the value M m-1 and 1 bit or more and b bits or less value M m of, where the b bits are the block size of the encryption function E of the block cipher; an S1 calculation unit that sets a value H1 of b bits as the value M0, and for each integer i from 1 to m in ascending order, sets the value M i-1Calculate the value S1(i) as the input to the encryption function E, and calculate the value C based on the value S1(i) and the value M i Calculate the value C i ; an S2 calculation unit that sets the r-bit value H2 as the value S2(0), and for each integer i = 1,..., m, in ascending order, calculates the value S2(i) based on the value S1(i) calculated by the S1 calculation unit and the value S2(i-1); a ciphertext generation unit that generates the ciphertext C based on the value C related to each integer i = 1,..., m i ; and an authentication tag generation unit that generates a b+r-bit authentication tag T using the value S1(m) and the value S2(m).

[0038] Advantages of the Invention

[0039] In the present invention, the b-bit value S1 is updated using the encryption function E, and the r-bit value is updated using the output of the encryption function E. Thus, a structure capable of updating a b+r-bit value during decryption can be achieved, and b+r-bit bit security can be realized. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 is a structural diagram of the encryption device 10 according to Embodiment 1.

[0041] Figure 2 is a structural diagram of the decryption device 30 according to Embodiment 1.

[0042] Figure 3 is a flowchart showing the overall operation of the encryption device 10 according to Embodiment 1.

[0043] Figure 4 is a flowchart showing the public data processing according to Embodiment 1.

[0044] Figure 5 is an explanatory diagram of the public data processing according to Embodiment 1.

[0045] Figure 6 is a flowchart showing the encryption process according to Embodiment 1.

[0046] Figure 7 is an explanatory diagram of the encryption process according to Embodiment 1.

[0047] Figure 8 is a flowchart showing the authentication tag generation process according to Embodiment 1.

[0048] Figure 9 is an explanatory diagram of the authentication tag generation process according to Embodiment 1.

[0049] Figure 10 is a flowchart showing the overall operation of the decryption device 30 according to Embodiment 1.

[0050] Figure 11 It is a flowchart showing the decryption process of Embodiment 1.

[0051] Figure 12 It is an explanatory diagram of the decryption process of Embodiment 1.

[0052] Figure 13 It is an explanatory diagram of the authenticator generation process of Modification 1.

[0053] Figure 14 It is a structural diagram of the encryption device 10 of Modification 2.

[0054] Figure 15 It is a structural diagram of the decryption device 30 of Modification 2. Detailed Embodiments

[0055] Embodiment 1

[0056] ***Explanation of Structure***

[0057] Refer to Figure 1 The structure of the encryption device 10 of Embodiment 1 will be described.

[0058] The encryption device 10 has hardware such as a processor 11, a memory 12, a storage 13, and a communication interface 14. The processor 11 is connected to the other hardware via signal lines and controls these other hardware.

[0059] The encryption device 10 has acquisition unit 21, division unit 22, public data processing unit 23, encryption unit 24, authenticator generation unit 25, and output unit 26 as functional structural elements. The public data processing unit 23 has an H1 calculation unit 231 and an H2 calculation unit 232. The encryption unit 24 has an S1 calculation unit 241, an S2 calculation unit 242, and a ciphertext generation unit 243. The functions of the respective functional structural elements of the encryption device 10 are implemented by software.

[0060] Programs for implementing the functions of the respective functional structural elements of the encryption device 10 are stored in the storage 13. This program is read into the memory 12 by the processor 11 and executed by the processor 11. Thus, the functions of the respective functional structural elements of the encryption device 10 are implemented.

[0061] Refer to Figure 2 The structure of the decryption device 30 of Embodiment 1 will be described.

[0062] The decryption device 30 has hardware such as a processor 31, a memory 32, a storage 33, and a communication interface 34. The processor 31 is connected to the other hardware via signal lines and controls these other hardware.

[0063] The decryption device 30 has an acquisition unit 41, a division unit 42, a public data processing unit 43, a decryption unit 44, an authentication symbol generation unit 45, and an output unit 46 as functional structural elements. The public data processing unit 43 has an H1 calculation unit 431 and an H2 calculation unit 432. The decryption unit 44 has an S1 calculation unit 441, an S2 calculation unit 442, and a plaintext generation unit 443. The functions of the respective functional structural elements of the decryption device 30 are implemented by software.

[0064] In the memory 33, there is stored a program for implementing the functions of the respective functional structural elements of the decryption device 30. This program is read into the memory 32 by the processor 31 and executed by the processor 31. Thereby, the functions of the respective functional structural elements of the decryption device 30 are implemented.

[0065] The processors 11 and 31 are ICs (Integrated Circuits) that perform processing. As a specific example, the processors 11 and 31 are CPUs (Central Processing Units), DSPs (Digital Signal Processors), or GPUs (Graphics Processing Units).

[0066] The memories 12 and 32 are storage devices that temporarily store data. As a specific example, the memories 12 and 32 are SRAMs (Static Random Access Memories) or DRAMs (Dynamic Random Access Memories).

[0067] The memories 13 and 33 are storage devices that store data. As a specific example, the memories 13 and 33 are HDDs (Hard Disk Drives). In addition, the memories 13 and 33 may also be removable storage media such as SD (Secure Digital) memory cards, CF (CompactFlash, registered trademark), NAND flash memories, floppy disks, optical discs, high-density discs, Blu-ray (registered trademark) discs, or DVDs (Digital Versatile Discs).

[0068] The communication interfaces 14 and 34 are interfaces for communicating with external devices. As a specific example, the communication interfaces 14 and 34 are ports of Ethernet (registered trademark), USB (Universal Serial Bus), or HDMI (registered trademark, High-Definition Multimedia Interface).

[0069] ***Description of the operation***

[0070] Refer to Figures 3 to 12 The operations of the encryption device 10 and the decryption device 30 in Embodiment 1 will be described.

[0071] The operation steps of the encryption device 10 in Embodiment 1 correspond to the encryption method in Embodiment 1. In addition, the program for implementing the operation of the encryption device 10 in Embodiment 1 corresponds to the encryption program in Embodiment 1.

[0072] The operation steps of the decryption device 30 in Embodiment 1 correspond to the decryption method in Embodiment 1. In addition, the program for implementing the operation of the decryption device 30 in Embodiment 1 corresponds to the decryption program in Embodiment 1.

[0073] **Definitions in the following description**

[0074] Let the set of values of the random number N be Nset.

[0075] Let the maximum number of blocks of the plaintext M, ciphertext C, and public data A be L. The number of blocks is the number of b-bit blocks that appear when the bit string of the plaintext M, ciphertext C, or public data A is divided every b bits. b bits is the block size in the Tweakable block cipher used by the encryption device 10 and the decryption device 20.

[0076] That is, when the maximum bit length of the plaintext M, ciphertext C, and public data A is L * L is L * / b or the smallest integer greater than or equal to it.

[0077] Let const be a fixed value, which is a value included in Nset. const can be any value in Nset. Let const1 be a fixed value of b bits and const2 be a fixed value of r bits. const1 can be any value of b bits and const2 can be any value of r bits. r is an integer greater than or equal to 1.

[0078] Let the exclusive OR operator for each bit be xor. For a bit string X, let the bit length of X be |X|.

[0079] Let pad be the following function: taking an input value with a bit length of b bits or less as input, bitwise combining the bits of the value following the input value to generate a b-bit value, and outputting the generated b-bit value.

[0080] For example, when a value X of b - 1 bits or less is input, the output pad(X) of pad is a value obtained by bit - combining 1 after the value X and then bit - combining a bit - string of 0s so that the bit - length becomes b. Further, for example, when a value Y of b bits is input, the output pad(Y) of pad is Y.

[0081] When i is an integer less than or equal to b, trunc[i] is a function that takes a b - bit value as input and outputs a predetermined i - bit value among the b bits of the input.

[0082] For example, trunc[i] is a function that outputs the most significant i bits among the b bits of the input. Further, for example, trunc[i] is a function that outputs the least significant i bits among the b bits of the input.

[0083] Let the set of Tweaks of the Tweakable block cipher used by the encryption device 10 and the decryption device 30 be TW = Nset×{1, 2,..., L}×{1, 2,..., 16}. 1, 2,..., L are different integer values. It suffices that 1, 2,..., L are different integer values, and they are not limited to the integer values of 1, 2,..., L. Similarly, 1, 2,..., 16 are different integer values. It suffices that 1, 2,..., 16 are different integer values, and they are not limited to the integer values of 1, 2,..., 16.

[0084] When TW is a t - bit space {0, 1} t Nset×{1, 2,..., L}×{1, 2,..., 16} only needs to be able to be assigned one - to - one to the t - bit space, and the method is arbitrary. For example, for an integer n, when Nset = {0, 1} n if the first n bits of the t bits are used as Nset, the next log2L bits are used as {1, 2,..., L}, and the last 4 bits are used as {1, 2,..., 16}, then the Tweak space can be realized. Here, the Tweak length t≥n + log2L+4.

[0085] Represent the Tweak value TW as (x, y, z). Here, x is a value selected from Nset. y is a value selected from {1, 2,..., L}. z is a value selected from {1, 2,..., 16}.

[0086] **Operation of the Encryption Device 10**

[0087] As a premise for the following description, assume that the encryption device 10 and the decryption device 30 share the key K.

[0088] Refer toFigure 3 The overall operation of the encryption device 10 according to Embodiment 1 will be described.

[0089] (Step S11: Acquisition process)

[0090] The acquisition unit 21 acquires the public data A and the plaintext M. Specifically, the acquisition unit 21 acquires the public data A and the plaintext M input by the user operating an input device connected via the communication interface 14.

[0091] Alternatively, the public data A may not be input. In this case, the acquisition unit 21 only acquires the plaintext M.

[0092] (Step S12: Segmentation process)

[0093] The segmentation unit 22 segments the public data A acquired in Step S11 from the beginning in units of every b bits, generating b-bit values A1,..., A a-1 and a value A that is 1 bit or more and b bits or less. a Therefore, when the values A1,..., A a are bit-combined, it becomes the public data A.

[0094] In addition, the segmentation unit 22 segments the plaintext M acquired in Step S11 from the beginning in units of every b bits, generating b-bit values M1,..., M m-1 and a value M that is 1 bit or more and b bits or less. m Therefore, when the values M1,..., M m are bit-combined, it becomes the plaintext M.

[0095] Alternatively, when the public data A is not acquired in Step S11, the segmentation unit 22 only generates the values M1,..., M m .

[0096] (Step S13: Public data process)

[0097] The public data processing unit 23 uses the values A1,..., A generated in Step S12 a to generate a value H1 and a value H2. The public data process will be described in detail later.

[0098] (Step S14: Encryption process)

[0099] The encryption unit 24 uses the values M1,..., M generated in Step S12 m and the values H1 and H2 generated in Step S13 to generate values S1(m) and S2(m) and the ciphertext C. The encryption process will be described in detail later.

[0100] (Step S15: Authenticator generation process)

[0101] The authenticator generation unit 25 generates an authenticator T for tampering detection using the value S1(m) and the value S2(m) generated in step S14. The authenticator generation process will be described in detail later.

[0102] (Step S16: Output process)

[0103] The output unit 26 outputs the ciphertext C generated in step S14 and the authenticator T generated in step S15. Specifically, the output unit 26 sends the ciphertext C and the authenticator T to the decryption device 30 via the communication interface 14.

[0104] Refer to Figure 4 and Figure 5 for the public data processing of Embodiment 1 ( Figure 3 step S13) for explanation.

[0105] (Step S131: Initial setting process)

[0106] The public data processing unit 23 sets the b-bit fixed value const1 as the value H1(0). In addition, the public data processing unit 23 sets the r-bit fixed value const2 as the value H2(0).

[0107] (Step S132: First calculation process)

[0108] The H1 calculation unit 231 and the H2 calculation unit 232 perform the following calculations (1) and (2) in ascending order for each integer i = 1,..., a-1.

[0109] (1) The H1 calculation unit 231 uses the key K, the Tweak value (const, i, 1), the calculated value A i and the value A' obtained by XORing the value H1(i-1) i as the input to the encryption function E of the Tweakable block cipher to calculate the value H1(i). That is, the H1 calculation unit 231 calculates H1(i) = E(K, (const, i, 1), A i xor H1(i-1)) for each integer i = 1,..., a-1 in ascending order.

[0110] (2) The H2 calculation unit 232 calculates the value H2(i) based on the value H1(i) calculated by the H1 calculation unit 231 and the value H2(i-1). Specifically, the H2 calculation unit 232 calculates the XOR of the value H2(i-1) and the r bits extracted from the value H1(i) using the function trunc[r] to generate the value H2(i). That is, the H2 calculation unit 232 calculates H2(i) = H2(i-1) xor trunc[r](H1(i)).

[0111] (Step S133: Second Calculation Process)

[0112] The H1 calculation unit 231 uses the function pad to generate a b-bit value pad(A a ) based on the value A. The H1 calculation unit 231 calculates the value A' which is the XOR of the key K, the Tweak value (const, a, 1), the calculated value pad(A a ), and the value H1(a - 1), and uses this as the input to the encryption function E of the Tweakable block cipher to calculate the value H1(a). The H1 calculation unit 231 sets the value H1(a) as the value H1. That is, the H1 calculation unit 231 calculates H1 = H1(a) = E(K, (const, a, 1), pad(A a ) xor H1(a - 1)). a a

[0113] Similar to step S132, the H2 calculation unit 232 calculates the XOR of the value H2(a - 1) and the r-bit value extracted from the value H1(a) using the function trunc[r], and generates the value H2(a). That is, the H2 calculation unit 232 calculates H2(a) = H2(a - 1) xor trunc[r](H1(a)).

[0114] In Figure 3 the case where the public data A is not obtained in step S11, instead of the processing shown in Figure 4 and Figure 5 , the public data processing unit 23 sets the fixed value const1 as the value H and the fixed value const2 as the value H2.

[0115] Refer to Figure 6 and Figure 7 for the encryption process of Embodiment 1 ( Figure 3 step S14).

[0116] (Step S141: Initial Setting Process)

[0117] The encryption unit 24 sets the b-bit value H1 generated in step S133 in Figure 4 as the value M0. In addition, the encryption unit 24 sets the r-bit value H2 generated in step S133 in Figure 4 as the value S2(0).

[0118] (Step S142: Variable Setting Process)

[0119] The encryption unit 24 sets the following value for the variable x according to the public data A.

[0120] In Figure 3 ​​In the case where the public data A is not obtained in step S11, the encryption unit 24 sets 2 for the variable x.

[0121] In Figure 3 the case where the public data A is obtained in step S11 of and |A| mod b = 0, the encryption unit 24 sets 7 for the variable x.

[0122] In Figure 3 the case where the public data A is obtained in step S11 of and |A| mod b ≠ 0, the encryption unit 24 sets 12 for the variable x.

[0123] (Step S143: First calculation process)

[0124] The S1 calculation unit 241 and the S2 calculation unit 242 perform the following processes (1) and (2) in ascending order for each integer i = 1,..., m - 1.

[0125] (1) The S1 calculation unit 241 uses the key K, the Tweak value (N, i, x), and the value M i-1 as inputs to the encryption function E to calculate the value S1(i), and calculates the value C i based on the value S1(i) and the value M i . Specifically, the S1 calculation unit 241 calculates the exclusive OR of the value S1(i) and the value M i to generate the value C i . That is, the S1 calculation unit 241 calculates S1(i) = E(K, (N, i, x), M i-1 ) and C i = S1(i) xor M i .

[0126] (2) The S2 calculation unit 242 calculates the value S2(i) based on the value S1(i) calculated by the S1 calculation unit 241 and the value S2(i - 1). Specifically, the S2 calculation unit 242 calculates the exclusive OR of the value S2(i - 1) and the r bits extracted from the value S1(i) using the function trunc[r] to calculate the value S2(i). That is, the S2 calculation unit 242 calculates S2(i) = S2(i - 1) xor trunc[r](S1(i)).

[0127] (Step S144: Second calculation process)

[0128] The S1 calculation unit 241 uses the key K, the Tweak value (N, m, x), and the value M m-1 as inputs to the encryption function E to calculate the value S1(m), and calculates the value C m based on the value S1(m) and the value M m . Specifically, the S1 calculation unit 241 calculates using the function trunc[|M m| The value M extracted from the value S1(m) m | and the exclusive OR of the value M m generate the value C m . That is, the S1 calculation unit 241 calculates S1(m) = E(K, (N, m, x), M m-1 ) and C m = trunc[|M m |](S1(m)) xor M m .

[0129] Similar to step S143, the S2 calculation unit 242 calculates the value S2(m - 1) and the exclusive OR of the r bits extracted from the value S1(m) using the function trunc[r], and calculates the value S2(m). That is, the S2 calculation unit 242 calculates S2(m) = S2(m - 1) xor trunc[r](S1(m)).

[0130] (Step S145: Third calculation process)

[0131] The S1 calculation unit 241 uses the function pad to generate a b-bit value pad(C m ) according to the value C calculated in step S144. The S1 calculation unit 241 calculates the exclusive OR of the value S1(m) calculated in step S144 and the value pad(C m ) and updates the value S1(m). That is, the S1 calculation unit 241 calculates S1(m) = S1(m) xor pad(C m ). m )

[0132] (Step S146: Ciphertext generation process)

[0133] The ciphertext generation unit 243 performs bit combination on the values C for each integer i = 1,..., m and generates the ciphertext C. That is, the ciphertext generation unit 243 calculates C = C1||C2||…C i . In addition, || represents bit combination. m .

[0134] Refer to Figure 8 and Figure 9 to describe the authenticator generation process of Embodiment 1( Figure 3 step S15).

[0135] (Step S151: Variable setting process)

[0136] The authenticator generation unit 25 sets the following values for the variable y and the variable z according to the public data A and the plaintext M.

[0137] In Figure 3In the case where public data A is not obtained in step S11 and |M| mod b = 0, the authentication symbol generation unit 25 sets 3 for the variable y and 4 for the variable z.

[0138] In Figure 3 the case where public data A is not obtained in step S11 and |M| mod b ≠ 0, the authentication symbol generation unit 25 sets 5 for the variable y and 6 for the variable z.

[0139] In Figure 3 the case where public data A is obtained in step S11 and |A| mod b = 0 and |M| mod b = 0, the authentication symbol generation unit 25 sets 8 for the variable y and 9 for the variable z.

[0140] In Figure 3 the case where public data A is obtained in step S11 and |A| mod b = 0 and |M| mod b ≠ 0, the authentication symbol generation unit 25 sets 10 for the variable y and 11 for the variable z.

[0141] In Figure 3 the case where public data A is obtained in step S11 and |A| mod b ≠ 0 and |M| mod b = 0, the authentication symbol generation unit 25 sets 13 for the variable y and 14 for the variable z.

[0142] In Figure 3 the case where public data A is obtained in step S11 and |A| mod b ≠ 0 and |M| mod b ≠ 0, the authentication symbol generation unit 25 sets 15 for the variable y and 16 for the variable z.

[0143] (Step S152: First calculation process)

[0144] The authentication symbol generation unit 25 uses the key K, the Tweak value (N, m, y), and the value S1(m) updated in Figure 6 step S145 as the input of the encryption function E to calculate the value S1(m + 1). That is, the authentication symbol generation unit 25 calculates S1(m + 1) = E(K, (N, m, y), S1(m)).

[0145] The authentication symbol generation unit 25 calculates the value S2(m + 1) based on the value S1(m + 1) and the value S2(m). Specifically, it calculates the exclusive OR of the value S2(m) and the r bits extracted from the value S1(m + 1) using the function trunc[r] to calculate the value S2(m + 1). That is, the authentication symbol generation unit 25 calculates S2(m + 1) = S2(m) xor trunc[r](S1(m + 1)).

[0146] (Step S153: Second calculation process)

[0147] The authenticator generation unit 25 calculates S1(m + 2) by using the key K, the Tweak value (N, m, z), and the value S1(m + 1) calculated in step S152 as the input to the encryption function E. That is, the authenticator generation unit 25 calculates S1(m + 2) = E(K, (N, m, z), S1(m + 1)).

[0148] (Step S154: Third calculation process)

[0149] The authenticator generation unit 25 performs bit combination on the value S1(m + 2) calculated in step S153 and the value S2(m + 1) calculated in step S152 to generate an (b + r)-bit authenticator T. That is, the authenticator generation unit 25 calculates T = S1(m + 2) || S2(m + 1).

[0150] Refer to Figure 10 The overall operation of the decryption device 30 according to Embodiment 1 will be described.

[0151] (Step S21: Acquisition process)

[0152] The acquisition unit 41 acquires the public data A, the ciphertext C, and the authenticator T'.

[0153] Specifically, the acquisition unit 41 acquires the public data A input by the user operation via the input device connected to the communication interface 34. In addition, the acquisition unit 41 acquires the ciphertext C transmitted in step S16 of Figure 3 and acquires the authenticator T transmitted in step S16 of Figure 3 as the authenticator T'.

[0154] In addition, the public data A may not be input. In this case, the acquisition unit 41 only acquires the ciphertext C and the authenticator T. In addition, when the public data A is not input in step S11 of Figure 3 , the public data A is not input in step S21 either. On the other hand, when the public data A is input in step S11 of Figure 3 , the public data A is also input in step S21.

[0155] (Step S22: Division process)

[0156] The division unit 42 divides the public data A acquired in step S21 from the beginning by every b bits to generate b-bit values A1,..., A a-1 and a value A that is 1 bit or more and b bits or less a . Therefore, when the values A1,..., A a are combined by bits, it becomes the public data A.

[0157] In addition, the splitting unit 42 splits the ciphertext C obtained in step S21 starting from the beginning by every b bits, generating b-bit values C1, ..., C m-1 and values C of 1 bit or more and b bits or less. m Therefore, when combining the bits of the values C1, ..., C m , it becomes the ciphertext C.

[0158] In addition, when the public data A is not obtained in step S21, the splitting unit 42 only generates the values C1, ..., C m .

[0159] (Step S23: Public data processing)

[0160] Similar to Figure 3 step S13, the public data processing unit 43 uses the values A1, ..., A generated in step S22 a to generate the value H1 and the value H2. That is, the public data processing unit 43 generates the value H1 and the value H2 by referring to Figure 4 and Figure 5 the methods described.

[0161] (Step S24: Decryption processing)

[0162] The decryption unit 44 uses the values C1, ..., C generated in step S22 m and the values H1 and H2 generated in step S23 to generate the values S1(m) and S2(m) and the plaintext M. The decryption processing will be described in detail later.

[0163] (Step S25: Authenticator generation processing)

[0164] Similar to Figure 3 step S15, the authenticator generation unit 45 uses the values S1(m) and S2(m) generated in step S24 to generate the authenticator T for tampering detection. That is, the authenticator generation unit 45 generates the authenticator T by referring to Figure 8 and Figure 9 the methods described.

[0165] (Step S26: Tampering determination processing)

[0166] The authenticator generation unit 25 determines whether the authenticator T generated in step S25 and the authenticator T' obtained in step S21 are the same.

[0167] When they are the same, the authenticator generation unit 25 determines that there is no tampering and proceeds to step S27. On the other hand, when they are not the same, the authenticator generation unit 25 determines that there is tampering and proceeds to step S28.

[0168] (Step S27: First Output Process)

[0169] The output unit 26 outputs the plaintext M generated in step S24. Specifically, the output unit 26 sends the plaintext M to the user's terminal or the like via the communication interface 14.

[0170] (Step S28: Second Output Process)

[0171] The output unit 26 outputs the forged value ⊥.

[0172] Refer to Figure 11 and Figure 12 for the decryption process of Embodiment 1 ( Figure 10 step S24).

[0173] The processing of steps S241 to S242 is the same as the processing of Figure 6 steps S141 to S142. In addition, the processing of step S245 is the same as the processing of Figure 6 step S145.

[0174] (Step S243: First Calculation Process)

[0175] The S1 calculation unit 441 and the S2 calculation unit 442 perform the following processes (1) and (2) in ascending order for each integer i from i = 1,..., m - 1.

[0176] (1) Similar to Figure 6 step S143, the S1 calculation unit 441 uses the key K, the Tweak value (N, i, x), and the value M i-1 as the input of the encryption function E to calculate the value S1(i). In addition, the S1 calculation unit 441 calculates the value M i based on the value S1(i) and the value C i . Specifically, the S1 calculation unit 441 calculates the exclusive OR of the value S1(i) and the value C i to generate the value M i . That is, the S1 calculation unit 241 calculates S1(i) = E(K, (N, i, x), M i-1 ) and M i = S1(i) xor C i .

[0177] (2) Similar to Figure 6Similarly to step S143, the S2 calculation unit 442 calculates the value S2(i) based on the value S1(i) calculated by the S1 calculation unit 441 and the value S2(i - 1). Specifically, the S2 calculation unit 442 calculates the exclusive OR of the value S2(i - 1) and the r bits extracted from the value S1(i) using the function trunc[r] to calculate the value S2(i). That is, the S2 calculation unit 442 calculates S2(i) = S2(i - 1) xor trunc[r](S1(i)).

[0178] (Step S244: Second calculation process)

[0179] Similar to Figure 6 step S144, the S1 calculation unit 441 uses the key K, the Tweak value (N, m, x), and the value M m-1 as inputs to the encryption function E to calculate the value S1(m). In addition, the S1 calculation unit 441 calculates the value M m based on the value S1(m) and the value C m . Specifically, the S1 calculation unit 441 calculates the exclusive OR of the |C m |-bit value extracted from the value S1(m) using the function trunc[|C m |] and the value C m to generate the value M m . That is, the S1 calculation unit 441 calculates S1(m) = E(K, (N, m, x), M m-1 ) and M m = trunc[|C m |](S1(m)) xor C m .

[0180] Similar to Figure 6 step S144, the S2 calculation unit 442 calculates the exclusive OR of the value S2(m - 1) and the r bits extracted from the value S1(m) using the function trunc[r] to calculate the value S2(m). That is, the S2 calculation unit 442 calculates S2(m) = S2(m - 1) xor trunc[r](S1(m)).

[0181] (Step S246: Plaintext generation process)

[0182] The plaintext generation unit 443 performs bit combination on the values M i related to each integer i from i = 1,..., m to generate the plaintext M. That is, the plaintext generation unit 443 calculates M = M1||M2||…M m .

[0183] ***Effects of Embodiment 1***

[0184] As described above, the encryption device 10 of Embodiment 1 updates the b-bit value S1 using the encryption function E, and updates the r-bit value using the output of the encryption function E. As a result, the decryption device 30 is configured to update the b+r-bit value during decryption. As a result, b+r-bit security can be achieved.

[0185] ***Other structures***

[0186] <Modification Example 1>

[0187] In Embodiment 1, only the value S1(m+2) is calculated in step S153 of Figure 8 . However, the value S2(m+2) may also be calculated based on the value S1(m+2). Specifically, as Figure 13 shows, the authenticator generation unit 25 calculates the exclusive OR of the value S2(m+1) and the r bits extracted from the value S1(m+2) using the function trunc[r], and calculates the value S2(m+2). That is, the authenticator generation unit 25 calculates S2(m+2) = S2(m+1) xor trunc[r](S1(m+2)).

[0188] In this case, in step S154 of Figure 8 , the authenticator generation unit 25 performs bitwise combination of the value S1(m+2) and the value S2(m+2) to generate the authenticator T. That is, the authenticator generation unit 25 calculates T = S1(m+2) || S2(m+2).

[0189] <Modification Example 2>

[0190] In Embodiment 1, each functional structural element is implemented by software. However, as Modification Example 2, each functional structural element may also be implemented by hardware. Regarding this Modification Example 2, the differences from Embodiment 1 will be described.

[0191] Refer to Figure 14 to describe the structure of the encryption device 10 of Modification Example 2.

[0192] When each functional structural element is implemented by hardware, the encryption device 10 has an electronic circuit 15 instead of the processor 11, the memory 12, and the storage 13. The electronic circuit 15 is a dedicated circuit that implements the functions of each functional structural element, the memory 12, and the storage 13.

[0193] Refer to Figure 15 to describe the structure of the decryption device 30 of Modification Example 2.

[0194] In the case where each functional structural element is implemented by hardware, the decryption device 30 has an electronic circuit 35 instead of the processor 31, the memory 32, and the storage 33. The electronic circuit 35 is a dedicated circuit that implements the functions of each functional structural element, the memory 32, and the storage 33.

[0195] As the electronic circuits 15, 35, a single circuit, a composite circuit, a programmed processor, a parallel-programmed processor, a logic IC, a GA (Gate Array), an ASIC (Application Specific Integrated Circuit), and an FPGA (Field-Programmable Gate Array) are assumed.

[0196] Each functional structural element can be implemented by one electronic circuit 15, 35, or multiple electronic circuits 15, 35 can be dispersed to implement each functional structural element.

[0197] <Modification Example 3>

[0198] As Modification Example 3, it is also possible that some of the functional structural elements are implemented by hardware and the other functional structural elements are implemented by software.

[0199] The processors 11, 31, the memories 12, 32, the storages 13, 33, and the electronic circuits 15, 35 are referred to as processing circuits. That is, the functions of each functional structural element are implemented by the processing circuits.

[0200] Reference Numeral Explanation

[0201] 10: Encryption device; 11: Processor; 12: Memory; 13: Storage; 14: Communication interface; 15: Electronic circuit; 21: Acquisition unit; 22: Division unit; 23: Public data processing unit; 231: H1 calculation unit; 232: H2 calculation unit; 24: Encryption unit; 241: S1 calculation unit; 242: S2 calculation unit; 243: Ciphertext generation unit; 25: Authentication symbol generation unit; 26: Output unit; 30: Decryption device; 31: Processor; 32: Memory; 33: Storage; 34: Communication interface; 35: Electronic circuit; 41: Acquisition unit; 42: Division unit; 43: Public data processing unit; 431: H1 calculation unit; 432: H2 calculation unit; 44: Decryption unit; 441: S1 calculation unit; 442: S2 calculation unit; 443: Plaintext generation unit; 45: Authentication symbol generation unit; 46: Output unit.

Claims

1. An encryption device, the encryption device having: An acquisition unit that acquires a plaintext M; A splitting unit that splits the plaintext M obtained by the obtaining unit into b-bit values M1,..., M starting from the beginning every b bits, and generates values M that are 1 bit or more and b bits or less, where m-1 and values M that are 1 bit or more and b bits or less m , where The b bits are the block size of the encryption function E of block encryption; An S1 calculation unit that sets a b-bit value H1 as a value M0, and for each integer i from i = 1, ..., m, in ascending order, sets the value M i-1 as an input to the encryption function E to calculate a value S1(i), and calculates a value C based on the value S1(i) and the value M i ; i ; An S2 calculation unit that sets an r-bit value H2 as the value S2(0), and for each integer i = 1,..., m, in ascending order, calculates the value S2(i) according to the value S1(i) calculated by the S1 calculation unit and the value S2(i - 1); A ciphertext generation unit that generates a ciphertext C based on a value C related to each integer i of i = 1, ..., m i Generate the ciphertext C; And An authentication tag generation unit that generates a b + r-bit authentication tag T using the value S1(m) and the value S2(m).

2. The encryption device according to claim 1, wherein The S2 calculation unit calculates the exclusive OR of r bits in the value S1(i) and the value S2(i - 1) to generate the value S2(i).

3. The encryption device according to claim 1, wherein The S1 calculation unit calculates the exclusive OR of the value S1(i) and the value M for each integer i = 1,..., m, and generates the value C i i ,​ The ciphertext generation unit performs bit combination on the value C related to each integer i where i = 1,..., m to generate the ciphertext C. i ​ 4. The encryption device according to claim 2, wherein The S1 calculation unit calculates the exclusive OR of the value S1(i) and the value M for each integer i = 1,..., m, and generates the value C i i ,​ The ciphertext generation unit performs bit combination on the value C related to each integer i where i = 1,..., m i to generate the ciphertext C.

5. The encryption device according to any one of claims 1 to 4, wherein The authentication tag generation unit, for each integer i = m + 1, m + 2, in ascending order, calculates the value S1(i) with the value S1(i - 1) as the input to the encryption function E, and for at least the integer i including m + 1 in i = m + 1, m + 2, calculates the exclusive OR of r bits in the value S1(i) and the value S2(i - 1) to calculate the value S2(i), and performs bit combination on the value S1(m + 2) and the value S2(m + 1) or the value S2(m + 2) to generate the authentication tag T.

6. The encryption device according to any one of claims 1 to 4, wherein The acquisition unit acquires public data A, The splitting unit splits the public data A starting from the beginning by every b bits to generate b-bit values A1,..., A a-1 and values A that are more than 1 bit and less than or equal to b bits a , The encryption device further has: An H1 calculation unit that sets a fixed value const1 of b bits to a value H1(0), and for each integer i = 1,..., a, in ascending order, calculates a value A i and a value A' obtained by exclusive-OR of the sum value H1(i - 1) i as an input to the encryption function E to calculate a value H1(i), and sets the value H1(a) as the value H1; and An H2 calculation unit that sets an r-bit fixed value const2 as the value H2(0), and for each integer i = 1,..., a, in ascending order, calculates the value H2(i) according to the value H1(i) calculated by the H1 calculation unit and the value H2(i - 1), and sets the value H2(a) as the value H2.

7. The encryption device according to claim 5, wherein The acquisition unit acquires public data A, The splitting unit splits the public data A starting from the beginning by every b bits to generate b-bit values A1,..., A a-1 and values A that are more than 1 bit and less than or equal to b bits a , The encryption device further has: An H1 calculation unit that sets a fixed value const1 of b bits to a value H1(0), and for each integer i from i = 1,..., a, in ascending order, calculates a value A i and a value A' obtained by exclusive-ORing the sum value H1(i - 1) i as an input to the encryption function E to calculate a value H1(i), and sets the value H1(a) as the value H1; and An H2 calculation unit that sets an r-bit fixed value const2 as the value H2(0), and for each integer i = 1,..., a, in ascending order, calculates the value H2(i) according to the value H1(i) calculated by the H1 calculation unit and the value H2(i - 1), and sets the value H2(a) as the value H2.

8. The encryption device according to any one of claims 1 to 4, 7, wherein The block encryption is Tweakable block encryption, The S1 calculation unit, for each integer i = 1,..., m, calculates the value S1(i) with different Tweak values as the input to the encryption function E.

9. The encryption device according to claim 5, wherein The block encryption is Tweakable block encryption, The S1 calculation unit, for each integer i = 1,..., m, calculates the value S1(i) with different Tweak values as the input to the encryption function E.

10. The encryption device according to claim 6, wherein, the block encryption is Tweakable block encryption, for each integer i = 1,..., m, the S1 calculation unit calculates the value S1(i) by using different Tweak values as inputs of the encryption function E respectively.

11. A decryption device, comprising: an acquisition unit configured to acquire a ciphertext C and an authentication symbol T'; A splitting unit that splits the ciphertext C obtained by the obtaining unit into b-bit values C1,..., C starting from the beginning every b bits, and generates values C that are 1 bit or more and b bits or less. m-1 m , where the b bits are the block size of the encryption function E of the block encryption; ​ An S1 calculation unit that sets a b-bit value H1 as a value M0, and for each integer i from i = 1,..., m, in ascending order, sets the value M i-1 as an input to the encryption function E to calculate a value S1(i), and calculates the value M i based on the value S1(i) and the value C i ; an S2 calculation unit configured to set an r-bit value H2 as the value S2(0), and for each integer i = 1,..., m, calculate the value S2(i) in ascending order according to the value S1(i) calculated by the S1 calculation unit and the value S2(i - 1); A plaintext generation unit that generates a plaintext M based on values M associated with each integer i from i = 1,..., m i Generate the plaintext M; and an authentication symbol generation unit configured to generate a b + r-bit authentication symbol T by using the value S1(m) and the value S2(m), and determine whether the authentication symbol T is consistent with the authentication symbol T'.

12. The decryption device according to claim 11, wherein, the S2 calculation unit calculates the exclusive OR of r bits in the value S1(i) and the value S2(i - 1) to generate the value S2(i).

13. The decryption device according to claim 11, wherein, The S1 calculation unit calculates the exclusive OR of the value S1(i) and the value C for each integer i = 1,..., m, and generates the value M i i ,​ The plaintext generation unit performs bit combination on the value M related to each integer i of i = 1,..., m to generate the plaintext M. i ​ 14. The decryption device according to claim 12, wherein, The S1 calculation unit calculates the exclusive OR of the value S1(i) and the value C for each integer i = 1,..., m, and generates the value M i i ,​ The plaintext generation unit performs bit combination on the value M related to each integer i of i = 1,..., m i to generate the plaintext M.

15. The decryption device according to any one of claims 11 to 14, wherein, for each integer i = m + 1, m + 2, the authentication symbol generation unit calculates the value S1(i) by using the value S1(i - 1) as an input of the encryption function E in ascending order, and for at least one integer i including m + 1 among i = m + 1, m + 2, calculates the exclusive OR of r bits in the value S1(i) and the value S2(i - 1) to calculate the value S2(i), and performs bit combination on the value S1(m + 2) and the value S2(m + 1) or the value S2(m + 2) to generate the authentication symbol T.

16. The decryption device according to any one of claims 11 to 14, wherein, the acquisition unit acquires public data A, The splitting unit splits the public data A starting from the beginning by every b bits, generating b-bit values A1,..., A a-1 and values A of more than 1 bit and no more than b bits a , the decryption device further comprises: An H1 calculation unit that sets a fixed value const1 of b bits to the value H1(0), and for each integer i from i = 1,..., a, in ascending order, calculates the value A i and the value A' obtained by XORing the sum value H1(i - 1) i as the input of the encryption function E to calculate the value H1(i), and sets the value H1(a) as the value H1; and an H2 calculation unit configured to set an r-bit fixed value const2 as the value H2(0), and for each integer i = 1,..., a, calculate the value H2(i) in ascending order according to the value H1(i) calculated by the H1 calculation unit and the value H2(i - 1), and set the value H2(a) as the value H2.

17. The decryption device according to claim 15, wherein, the acquisition unit acquires public data A, The dividing unit divides the public data A starting from the beginning by every b bits to generate b-bit values A1,..., A a-1 and values A that are more than 1 bit and less than or equal to b bits a , the decryption device further comprises: An H1 calculation unit, which sets a fixed value const1 of b bits as the value H1(0), and for each integer i from i = 1,..., a, in ascending order, calculates the value A i and the value A' obtained by the exclusive OR of the sum value H1(i - 1) i as the input of the encryption function E to calculate the value H1(i), and sets the value H1(a) as the value H1; and an H2 calculation unit configured to set an r-bit fixed value const2 as the value H2(0), and for each integer i = 1,..., a, calculate the value H2(i) in ascending order according to the value H1(i) calculated by the H1 calculation unit and the value H2(i - 1), and set the value H2(a) as the value H2.

18. The decryption device according to any one of claims 11 to 14, 17, wherein, the block encryption is Tweakable block encryption, The S1 calculation unit calculates the value S1(i) by using different Tweak values as inputs to the encryption function E for each integer i = 1,..., m.

19. The decryption device according to claim 15, wherein the block encryption is Tweakable block encryption, the S1 calculation unit calculates the value S1(i) by using different Tweak values as inputs to the encryption function E for each integer i = 1,..., m.

20. The decryption device according to claim 16, wherein the block encryption is Tweakable block encryption, the S1 calculation unit calculates the value S1(i) by using different Tweak values as inputs to the encryption function E for each integer i = 1,..., m.

21. An encryption method, wherein an acquisition unit acquires a plaintext M, The splitting unit splits the plaintext M starting from the beginning into values of b bits each, generating b-bit values M1,..., M m-1 and values M of more than 1 bit and up to b bits m , where the b bits are the block size of the encryption function E of the block cipher The S1 calculation unit sets the b-bit value H1 as the value M0, and for each integer i = 1,..., m in ascending order, sets the value M i-1 as an input to the encryption function E to calculate the value S1(i), and calculates the value C i based on the value S1(i) and the value M i , the S2 calculation unit sets an r-bit value H2 as the value S2(0), and for each integer i = 1,..., m in ascending order, calculates the value S2(i) based on the value S1(i) and the value S2(i - 1), The ciphertext generation unit generates a ciphertext C based on the value C related to each integer i = 1,..., m i ​ an authentication symbol generation unit generates a b + r-bit authentication symbol T by using the value S1(m) and the value S2(m).

22. A decryption method, wherein an acquisition unit acquires a ciphertext C and an authentication symbol T', The splitting unit splits the ciphertext C from the beginning by every b bits to generate b-bit values C1,..., C m-1 and values C that are more than 1 bit and less than or equal to b bits, m where the b bits are the block size of the encryption function E of block encryption. The S1 calculation unit sets the b-bit value H1 as the value M0, and for each integer i = 1, ..., m, in ascending order, the value M i-1 is used as an input to the encryption function E to calculate the value S1(i), and based on the value S1(i) and the value C i calculate the value M i , the S2 calculation unit sets an r-bit value H2 as the value S2(0), and for each integer i = 1,..., m in ascending order, calculates the value S2(i) based on the value S1(i) and the value S2(i - 1), The plaintext generation unit generates a plaintext M based on values M related to each integer i where i = 1,..., m i and generates the plaintext M. an authentication symbol generation unit generates a b + r-bit authentication symbol T by using the value S1(m) and the value S2(m), and determines whether the authentication symbol T and the authentication symbol T' are identical.

23. A computer-readable recording medium storing an encryption program, which causes a computer to function as an encryption device that performs the following processes: an acquisition process of acquiring a plaintext M; Segmentation process: The plaintext M obtained through the acquisition process is segmented starting from the beginning by every b bits to generate b-bit values M1,..., M m-1 and values M of more than 1 bit and less than or equal to b bits m , where the b bits are the block size of the encryption function E of the block encryption; S1 calculation process: Set the b-bit value H1 to the value M0. For each integer i from 1 to m in ascending order, use the value M i-1 as the input to the encryption function E to calculate the value S1(i). Based on the value S1(i) and the value M i calculate the value C i ; an S2 calculation process of setting an r-bit value H2 as the value S2(0), and for each integer i = 1,..., m in ascending order, calculating the value S2(i) based on the value S1(i) calculated by the S1 calculation process and the value S2(i - 1); Ciphertext generation process, generating ciphertext C based on values C related to each integer i where i = 1,..., m i Generate ciphertext C; and an authentication symbol generation process of generating a b + r-bit authentication symbol T by using the value S1(m) and the value S2(m).

24. A computer-readable recording medium storing a decryption program, which causes a computer to function as a decryption device that performs the following processes: an acquisition process of acquiring a ciphertext C and an authentication symbol T'; Segmentation process: segment the ciphertext C obtained through the said acquisition process from the beginning by every b bits to generate b-bit values C1,..., C m-1 and values C that are more than 1 bit and less than or equal to b bits m , where the b bits are the block size of the encryption function E of the block encryption; S1 calculation process, set the b-bit value H1 to the value M0, for each integer i = 1,..., m, in ascending order, set the value M i-1 as the input of the encryption function E to calculate the value S1(i), according to the value S1(i) and the value C i calculate the value M i ; an S2 calculation process of setting an r-bit value H2 as the value S2(0), and for each integer i = 1,..., m in ascending order, calculating the value S2(i) based on the value S1(i) calculated by the S1 calculation process and the value S2(i - 1); Plaintext generation process, generating plaintext M according to values M related to each integer i from i = 1,..., m i Generate plaintext M; and an authentication symbol generation process of generating a b + r-bit authentication symbol T by using the value S1(m) and the value S2(m), and determining whether the authentication symbol T and the authentication symbol T' are identical.

Citation Information

Patent Citations

  • Certification device and recording medium

    JP2000286836A

  • Method and apparatus for facilitating efficient authenticated encryption

    US20060285684A1