Encryption, trap door generation and mode detection methods and devices

CN120035957APending Publication Date: 2025-05-23ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380072465.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-17
Filing Date
2023-10-09
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art is difficult to detect patterns effectively in encrypted data streams, especially since existing solutions are complex or can detect patterns of fixed size only.

Method used

By generating trap gates associated with the mode, the key parameterization in the public key encryption system is used to realize the detection of any size mode in the encrypted data stream. The method includes selecting integers s and r, calculating the trap gate element T, and determining the existence of the pattern by detecting a specific value in the password.

Benefits of technology

It is implemented to detect the existence of patterns in the encrypted data stream without decrypting the data stream, and the method is low in complexity and does not rely on the knowledge of encrypted plaintext data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120035957A_ABST
    Figure CN120035957A_ABST
Patent Text Reader

Abstract

The encryption method is implemented in a system defining a public key (pk) to obtain a password (C) by encrypting data (m) comprising a base character m [i], the public key (pk) comprising:-an element gc, i, for any integer i between 1 and an integer u, the element gc, i being in the form of g (ac, i), where ac, i is an integer between 0 and an integer p-1, g is a generator of group G; -an element hk for any integer k between 1 and integer t, the element hk having the form of g (1 / bk), where bk is an integer between 0 and p-1; -a generator g; description of group G; and-a description of a function H having values in a finite set, said method comprising the steps of:-selecting (C22) an integer a between 0 and p-1; calculating (C24) a value Ek = H (hk (a)) for any integer k between 1 and integer t; calculating (C26), for any integer i between 1 and an integer u, a value Ci equal to ga [i], ia, obtaining (C28) a password (C) consisting of elements {Ek, Ci}.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of telecommunications.

[0002] More particularly, the present invention relates to encryption systems known as "searchable" encryption systems, that is, systems for detecting the presence of patterns in an encrypted data stream. Background Art

[0003] Nowadays, it is observed that most (about 90%) of the data flows exchanged on telecommunication networks are encrypted. This is the case, for example, of HTTPS requests or DNS requests.

[0004] This encryption prevents surveillance of these data streams, for example for the detection of attacks (malware, denial of service, etc.) or content filtering (parental controls, etc.).

[0005] A solution for monitoring encrypted data exchanged between service providers is described in the document (Lin-Shung Huang, Alex Rice, Erling Ellingsen and Collin Jackson, Analyzing forged SSL certificates, 2014 IEEE Symposium on Security and Privacy, pp. 83-97. IEEE Computer Society Press, May 2014), which consists in using a proxy server that impersonates the service provider, obtains the encryption key, decrypts the characters, analyzes them in plain text, re-encrypts them, and sends them to the user. This solution is not satisfactory because it reveals the data to the proxy server.

[0006] Another family of encryption solutions to which the present invention belongs is known as “searchable encryption.” Searchable encryption makes it possible to detect whether a data stream contains a cipher of a pattern, provided that certain information, usually called a “trapdoor” and previously associated with the pattern, is preserved.

[0007] The following three papers propose such solutions:

[0008] [1]Justine Sherry, Chang Lan, Raluca Ada Popa and Sylvia Ratnasamy.BlindBox: Deep Packet Inspection over Encrypted Traffic.InProceedings of the 2015 ACM Conference on Special Interest Group on DataCommunication,SIGCOMM′15;

[0009] [2] Nicolas Desmoulins, Pierre-Alain Fouque, Cristina Onete and Olivier Sanders. Pattern matching on encrypted streams. In Thomas Peyrin and Steven Galbraith, editors, ASIACRYPT 2018; and

[0010] [3] Elie Bouscatié, Guilhem Castagnos and Olivier Sanders. Public KeyEncryption with Flexible Pattern Matching. ASIACRYPT 2021.

[0011] The solution based on symmetric cryptography described in [1] only allows the detection of patterns of fixed size. It is therefore very limited and not particularly suitable for detecting malware whose size can vary greatly. The solutions described in [2] and [3] are quite complex, especially because they require the use of pairing-friendly elliptic curves.

[0012] The present invention proposes a searchable encryption system that overcomes the shortcomings / deficiencies of the prior art and / or provides improvements thereto. Summary of the invention

[0013] Therefore, and according to a first aspect, the invention relates to a method for generating a trapdoor in a cryptographic system, the trapdoor being associated with a pattern w comprising basic characters w[1], ... w[v] included in an alphabet supplemented by special characters that can replace any character of the alphabet, the system defining a key parameterized by integers n and t and comprising:

[0014] - an integer a for any character c of the alphabet and for any integer i between 1 and the integer n c,i ;as well as

[0015] - an integer b for any integer k between 1 and the integer t k ;

[0016] The method comprises the following steps:

[0017] - selecting an integer s comprised between 1 and an integer t; and

[0018] - Calculated value T = b s *(r 1 a w[1],1 +r 2 a w[2],2 +…+r v a w[v],v ), if w[i] is the special character, then r i =0, otherwise r i is equal to the integer r,

[0019] The trapdoor includes elements s, r and T.

[0020] Relatedly, the invention relates to a device for generating a trapdoor in a cryptographic system, the trapdoor being associated with a pattern w comprising basic characters w[1], ... w[v] included in an alphabet supplemented by special characters that can replace any character of the alphabet, the system defining a key parameterized by integers n and t and comprising:

[0021] - an integer a for any character c of the alphabet and for any integer i between 1 and the integer n c,i ;as well as

[0022] - an integer b for any integer k between 1 and the integer t k ;

[0023] The equipment includes:

[0024] - means for selecting an integer s comprised between 1 and an integer t; and

[0025] - used to calculate the value T = b s *(r 1 a w[1],1 +r 2 a w[2],2 +…+r v a w[v],v ) module, if w[i] is the special character, then r i =0, otherwise r i is equal to the integer r,

[0026] The trapdoor includes elements s, r and T.

[0027] The trapdoors thus generated make it possible to detect patterns of any size in the data stream through the detection process described later.

[0028] According to a second aspect, the invention relates to an encryption method implemented in an encryption system defining a public key, in order to obtain a password by encrypting data m comprising at least u basic characters m[i], the public key comprising:

[0029] - for any integer i between 1 and the integer u, the element g c,i , element g c,i With g^(a c,i ) in the form of c,i is an integer between 0 and an integer p-1, and g is a generator of a group G of order p;

[0030] - an element h for any integer k between 1 and the integer t k , element h k With g^(1 / b k ) in the form of k is an integer between 0 and p-1;

[0031] - generator g;

[0032] - a description of group G; and

[0033] - a description of a function H with a finite set of values,

[0034] The method comprises the following steps:

[0035] - select an integer a between 0 and p-1;

[0036] - For any integer k between 1 and t, calculate the value E k =H(h k ^(a));

[0037] - For any integer i between 1 and u, compute the value equal to g m[i],i ^a value C i ,

[0038] - obtain a password, the password is composed of the element {E k , C i}composition.

[0039] Relatedly, the invention relates to an encryption device implemented in an encryption system defining a public key, the device being configured to obtain a password (C) by encrypting data (m) comprising at least u basic characters m[i], the public key comprising:

[0040] - for any integer i between 1 and the integer u, the element g c,i , element gc,i With g^(a c,i ) in the form of c,i is an integer between 0 and an integer p-1, and g is a generator of a group G of order p;

[0041] - an element h for any integer k between 1 and the integer t k , element h k With g^(1 / b k ) in the form of k is an integer between 0 and p-1;

[0042] - a generator g of group G;

[0043] - a description of group G; and

[0044] - a description of a function H with a finite set of values,

[0045] The device comprises:

[0046] - a module for selecting an integer a between 0 and p-1;

[0047] - A first module for calculating the value E for any integer k between 1 and t k =H(h k ^(a)),

[0048] - A second module for calculating, for any integer i between 1 and u, a m[i],i ^a value C i ,as well as

[0049] A module for obtaining a password, the password being composed of an element {E k , C i}composition.

[0050] Pattern and data are strings belonging to an alphabet. Characters can be of any type. For example, characters can be encoded in 2 bits, 8 bits, etc. The string can be a DNA sequence.

[0051] Very advantageously, the encryption method is performed independently of the pattern to be detected. Thus, the device that encrypts the data stream does not take into account during encryption the patterns that may be sought in the stream, nor the size of these patterns.

[0052] In one particular way of implementation, a device receiving an encrypted stream generates trapdoors associated with the patterns to be detected. It can perform the detection itself or delegate this task to another device with which it communicates with these trapdoors.

[0053] According to a third aspect, the invention relates to a method for detecting, in an encryption system, a pattern w in a password obtained by encryption of data, said pattern w comprising basic characters (w[1], ... w[v]) included in an alphabet supplemented by special characters that can replace any character of said alphabet, the method comprising the following steps:

[0054] - obtaining a trapdoor associated with said pattern;

[0055] - Calculate the element Q = C1^r1*...*Cv^rv, where if w[i] is the special character, then r i =0, otherwise r i = r;

[0056] - Calculate a value D equal to Q^(1 / T), where T is the element of the trapdoor;

[0057] - calculating a value H(D), where H is a function H having a finite set of values;

[0058] -If H(D) equals E s , then it is detected that the data includes the pattern w, where s is an integer included in the trapdoor.

[0059] Relatedly, the invention relates to a device for detecting, in an encryption system, a pattern w in a password obtained by encryption of data, said pattern comprising basic characters (w[1], ... w[v]) included in an alphabet supplemented by special characters that can replace any character of said alphabet, the device comprising:

[0060] - means for obtaining a trapdoor associated with said pattern;

[0061] - A first module for calculating the element Q = C1^r1*...*Cv^rv, where if w[i] is the special character, then r i =0, otherwise r i = r;

[0062] - a second module, for calculating a value D equal to Q^(1 / T), where T is an element of the trapdoor;

[0063] - a third module for calculating a value H(D), where H is a function H having values ​​in a finite set;

[0064] - A detection module, configured to if H(D) equals E s , then the detection data includes the pattern w, where s is an integer included in the trapdoor.

[0065] In one embodiment, the password is obtained by the encryption method described above, and the trapdoor is obtained by the trapdoor generation method described above.

[0066] Compared to the solutions described in previously introduced literature [2] and [3], which require the use of pairing-friendly elliptic curves, the method for detecting the presence of a pattern has a very low complexity.

[0067] Advantageously, the detection means does not require any knowledge about the plaintext data that has been encrypted. The pattern can be detected without decrypting the data stream.

[0068] Very advantageously, the pattern can be searched for at any position in the stream. According to the invention, the detection takes place on the w first characters of the password. In order to shift the position of the pattern to be detected, it is sufficient to start the pattern with an appropriate number of special characters.

[0069] The present invention also relates to a method for decrypting a password obtained by encrypting data comprising at least u basic characters, the password being generated according to the encryption method as described above, the decryption method comprising:

[0070] - obtaining a trapdoor associated with each of the different elementary data of the data stream, said trapdoor being generated according to the trapdoor generation method as described above,

[0071] - Detecting the presence of said trapdoor according to the pattern detection method as described above.

[0072] The present invention also relates to an encryption system, comprising:

[0073] - Trapdoor generation device,

[0074] - Encryption devices, and

[0075] - A device as described above for detecting the presence of a pattern in a password.

[0076] The present invention can be used, in particular, to detect malware by generating trapdoors associated with such malware.A list of patterns for malware detection is published at https: / / www.snort.org / .

[0077] The present invention can also be used to perform parental control by generating trapdoors corresponding to keywords to be filtered and by blocking streams including these keywords.

[0078] In a particular embodiment, the different steps of the trapdoor generation, encryption and detection method are determined by computer program instructions or implemented by a silicon chip comprising transistors adapted to form logic gates of a non-programmable wired logic.

[0079] Therefore, the invention also relates to a computer program on an information medium, capable of being implemented in a controller computer, the program comprising instructions suitable for implementing the steps of the method as described above.

[0080] The program may use any programming language, and be in the form of source code, object code, or an intermediate code between source code and object code, such as a partially compiled form, or any other desired form.

[0081] The present invention also relates to computer-readable information media and includes instructions of a computer program as described above. The information medium can be any entity or device capable of storing a program. For example, the medium can include a storage device, such as a non-volatile memory of a ROM, flash memory type or even a magnetic recording device, such as a hard disk. On the other hand, the information medium can be a transmissible medium such as an electrical signal or an optical signal, which can be transmitted via an electrical or optical cable, by radio or by other means. The program according to the present invention can especially be downloaded onto an Internet type network. Alternatively, the information medium can be an integrated circuit in which the program is contained, which is suitable for executing the method in question or for use in the execution of the method in question. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] Other features and advantages of the invention will emerge from the description given below, with reference to the accompanying drawings which illustrate exemplary embodiments of the invention but are not limited thereto. In the drawings:

[0083] [ Figure 1 ] Figure 1 represents an encryption system that can be encrypted according to a specific embodiment;

[0084] [ Figure 2 ] Figure 2 represents the main steps of a key generation method according to a specific embodiment;

[0085] [ Figure 3 ] Figure 3 represents the main steps of an encryption method according to a specific embodiment;

[0086] [ Figure 4 ] Figure 4 shows the main steps of a trapdoor generation method according to a specific embodiment;

[0087] [ Figure 5 ] Figure 5 represents the main steps of a method for detecting the presence of a pattern according to a particular embodiment;

[0088] [ Figure 6 ] Figure 6 represents an encryption device according to a specific embodiment;

[0089] [ Figure 7 ] Figure 7 represents a trapdoor generation device according to a specific embodiment;

[0090] [ Figure 8 ] Figure 8 A device for detecting the presence of a pattern according to a specific embodiment is shown. DETAILED DESCRIPTION

[0091] It should be noted that the usual cryptographic notation is used here, where:

[0092] - "x_i" means "x subscript i", i.e. "xi";

[0093] - "g^x" means "g to the power of x", i.e. "gx",

[0094] - When a number of index factors intervene, the product is indicated by an asterisk "*". Notations without the asterisk are also possible: "2n" stands for "2*n".

[0095] -When many index factors are involved, addition is usually represented by the symbol "+".

[0096] Figure 1 A searchable encryption system SYS according to the invention is represented. This system SYS makes it possible to detect the presence of a pattern w in a stream C of encrypted data.

[0097] In the figure, an encryption device DC encrypts plaintext data to generate an encrypted data stream C and sends the encrypted stream C to a decryption device RX, which is configured to decrypt the encrypted stream and recover the plaintext data stream.

[0098] The encryption system SYS is based on a public key cryptosystem. To this end, it relies on a secret key sk and an associated public key pk. It is assumed that the key generation device KG is arranged to generate a key pair sk, pk according to known methods.

[0099] The trapdoor generation device DG is configured to generate, for a given pattern w, a trapdoor T(w) associated with the pattern. The trapdoor generation device DG is represented as being independent, but may for example be integrated into the decryption device RX.

[0100] The trapdoor T(w) is intended to be used by the detection device DD to detect the presence of a pattern w in the encrypted stream.The trapdoor generation device DG is configured to send the trapdoor(s) it has generated to the detection device DD.

[0101] The cryptographic system SYS therefore comprises a trapdoor generating device DG, an encryption device DC and a detection device DD.

[0102] In the embodiment described here, the cryptographic system SYS uses a group G of order p. This group can be any group, but in the rest of the description it can in particular be a set of points of an elliptic curve, or a multiplicative subgroup of a finite field.

[0103] The data is then processed into a string of characters belonging to the alphabet S.

[0104] Figure 2 Figure 1 shows the main steps K10 to K28 that can be implemented by the key generation device KG according to a particular embodiment. The key is parameterized by integers n and t.

[0105] The key generation method comprises a first step K10 of selecting the parameters of the system, these parameters comprising:

[0106] n: the maximum number of characters that can be encrypted by the encryption method;

[0107] t: integer;

[0108] p: prime number;

[0109] G: a group of order p;

[0110] G: Elements of G that are not neutral elements are called generators;

[0111] H: A function H that takes as input any bit string and has values ​​in a finite set D. In practice, any cryptographic hash function such as SHA-256 or SHA-3, for example, may be used.

[0112] During a step K20 , the key generation method generates a key pair {pk, sk} comprising a secret key sk and an associated public key pk.

[0113] During a step K22, for any character c of the alphabet S and for any integer i between 1 and n, the key generation method selects an integer a between 0 and p-1 c,i , and calculate g c,i =g^(a c,i ).

[0114] During a step K24, for any integer k between 1 and t, the method selects an integer b between 0 and p-1 k , and calculate h k =g^(1 / b k ).

[0115] During a step K26, the method defines the public key pk of the cryptographic system as the set consisting of:

[0116] -Element g c,i 、h k and g;

[0117] - a description of group G; and

[0118] - Description of the function H.

[0119] Note that pk = {g c,i ,h k ,g,G,H}.

[0120] During a step K28, the method defines the key sk of the cryptographic system as the set consisting of:

[0121] - integer a c,i and b k ;

[0122] - or any information that would allow them to be found.

[0123] Note that sk = {a c,i ,b k ,g,G,H}

[0124] As is known, it is assumed that the public key pk is known to all devices of the system SYS, in particular to the encryption device DC. The secret key sk is known to the trapdoor generation device DT and the decryption device RX.

[0125] Figure 3 Represents the main steps C22 to C28 of the encryption method according to a particular embodiment.

[0126] The encryption method makes it possible to encrypt any string m = m[1], m[2], ..., m[u], where the size u of the string is less than or equal to the maximum size n of data that can be encrypted and decrypted by the system SYS. The character m[i] is an element of the alphabet S, whatever i is.

[0127] The encryption method uses the public key pk={g c,i ,h k ,g,G,H} to encrypt data.

[0128] During a step C22 , the encryption method selects an integer a between 0 and p−1.

[0129] During a step C24, the encryption method calculates E=H(h k ^(a)). Recall here that the function H takes as input any bit string and has values ​​in a finite set D.

[0130] During a step C26, the encryption method calculates C for any integer i between 1 and u. i =g m[i],i ^a.

[0131] During a step C28, the cryptographic method obtains a k and C i The password C is composed of. Note that C = {E k ,C i}. Note that the password consists of t+u elements, where:

[0132] -t: an integer selected as part of the system parameters; and

[0133] -u: The size of the data to be encrypted.

[0134] In the embodiment described here, the encryption method is implemented by an encryption device DC, and the encryption device DC transmits the cryptogram C to the decryption device RX.

[0135] Figure 4 The main steps T22 to T26 of the trapdoor generation method according to a specific embodiment are shown.

[0136] The trapdoor generation method makes it possible to generate trapdoors for any patterns w = w[1], w[2], ..., w[v] and w[i], where the size v of the pattern is less than or equal to the maximum size n of data that can be encrypted and decrypted by the system SYS, regardless of whether i is an element of the alphabet S or the special character "*".

[0137] This method uses the secret key sk = {a c,i ,b k ,g,G,H}.

[0138] During a step T22 , the trapdoor generation method selects an integer s between 1 and t.

[0139] During step T24, the trapdoor generation method selects an integer r between 1 and p-1 and calculates T=b s *(r 1 a w[1],1 +r 2 a w[2],2 +…+r v a w[v],v ),in:

[0140] - If w[i] is the special character "*", then r i = 0, and

[0141] - Otherwise r i =r.

[0142] In one particular embodiment, r=1 for all trapdoors.

[0143] During step T26, the generation method obtains a trapdoor T(w) for pattern w, where T(w) = {s, r, T}. Note that r does not need to be secret.

[0144] In the embodiment described here, the trapdoor generation method is implemented by the decryption device RX.

[0145] In the embodiment described here, the decryption device RX sends a trapdoor T(w) to the device DD for detecting the presence of a pattern.

[0146] Figure 5 Represents the main steps D22 to D32 of a method for detecting the presence of a pattern according to a particular embodiment.

[0147] The method for detecting the presence of a pattern allows testing whether the pattern w=w[1], w[2], ..., w[v] corresponds to a pattern that has been encrypted to generate a password C={E k ,C i}, v elements of the plaintext data m, k is included between 1 and t, and i is included between 1 and u.

[0148] This method uses:

[0149] - Alphabet S;

[0150] - integer t

[0151] -The size of the plaintext string before encryption u

[0152] - length v of pattern w

[0153] - Password C = {E k ,C i};

[0154] - a trapdoor T(w) = {s, r, T} associated with the pattern w; and

[0155] -Function H.

[0156] In the embodiment described herein, the detection method includes the following steps D22 to D32.

[0157] During step D22, the detection method calculates the element Q=C using the formula 1 ^r 1 *…*C v ^r v :

[0158] - If w[i] is the special character "*", then r i = 0, and

[0159] - Otherwise r i =r.

[0160] During a step D24 , the detection method calculates the element D=Q̂(1 / T).

[0161] During a step D26 , the detection method calculates H(D).

[0162] During step D28, the detection method compares H(D) with E s For comparison, E s is the first element of the trapdoor T(w), E s is an element of rank s of the cipher C.

[0163] If H(D)=E s , the detection method determines or detects (step D30) that the data m encrypted with C include the pattern w. Otherwise, the detection method determines (step D32) that the data m encrypted with C do not include the pattern w. This detection is performed without decrypting the cipher C.

[0164] A proof of the effectiveness of the encryption proposed above is provided below.

[0165] If there is a pattern w=w[1],…,w[v] in the data m=m[1],…,m[u], then for any i between 1 and v, w[i]=m[i], so that w[i] is different from the special character “*”.

[0166] Let J denote the set of such i's.

[0167] Then, the element Q calculated in step D22 is exactly C for i belonging to J i The product of ^r.

[0168] Due to C i =g m[i],i ^a=g^(a*a m[i],i )=g^(a*a w[i],i ), the product is exactly g^(a*r*A), where for i belongs to J, A is a w[i],i The sum.

[0169] So Q^(1 / T) simplifies the sum and gives exactly g^(a / b s ). Computing the image with this final value of H, we land exactly on E s superior.

[0170] If, on the other hand, the pattern differs from the encrypted character sequence even at a single position, then it can be proven to fall back to E. s The probability of this happening is at most 1 / p, which is negligible in practice. In practice, p can be chosen to be, for example, close to 2 256 .

[0171] The present invention also relates to a method for decrypting a password obtained by encrypting data comprising at least u basic characters, the password being generated according to the encryption method as described above, the decryption method comprising:

[0172] - obtaining a trapdoor associated with each of the different elementary data of the data stream, said trapdoor being generated according to the method for generating a trapdoor as described above,

[0173] - Detecting the presence of the trapdoor according to the method for detecting a pattern as described above.

[0174] Now about Figure 6 A device DG for generating a trapdoor in an encryption system according to an exemplary embodiment is described. The device DG is a computer device, such as a computer.

[0175] The trapdoor generation DG device includes:

[0176] - a processing unit or processor 601 , or CPU (Central Processing Unit), intended to load instructions into a memory in order to execute them, in order to perform operations;

[0177] - A collection of memories, including a volatile memory 602, or a RAM (Random Access Memory) for executing code instructions, storing variables, etc., and a storage memory 603 of the EEPROM (Electrically Erasable Programmable Read Only Memory) type. In particular, the storage memory 603 is arranged to store a trapdoor generation software module, which includes code instructions for implementing the steps of the trapdoor generation method as described above. The storage memory 603 is also arranged to store a secret key sk of the encryption system in a secure area.

[0178] The trapdoor generation device DG also includes:

[0179] - a module MT22 for selecting an integer s comprised between 1 and t;

[0180] - used to calculate the value T = b s *(r 1 a w[1],1 +r 2 a w[2],2 +…+r v a w[v],v ) module MT24, if w[i] is the special character, then r i =0, otherwise r i is equal to the integer r, and

[0181] - A module RES for recovering a trapdoor comprising the elements s, r and T.

[0182] Now combine Figure 7A cryptographic device DC according to an exemplary embodiment is described. The cryptographic device DC is a computer equipment, such as a computer.

[0183] It includes:

[0184] - a processing unit or processor 701 or CPU, intended to load instructions into a memory in order to execute them, in order to perform operations;

[0185] - A collection of memories, including a volatile memory 702, or a RAM for executing code instructions, storing variables, etc., and a storage memory 703 of the EEPROM type. In particular, the storage memory 703 is arranged to store an encryption software module comprising code instructions for implementing the steps of the encryption method as described above. The memory 703 is also arranged to store a public key pk of the encryption system.

[0186] The encryption device DC also includes:

[0187] - a module MC22 for selecting an integer a between 0 and p-1;

[0188] a first module MC24 for calculating, for any integer k between 1 and the integer t, the value E k =H(h k ^(a));

[0189] - a second module MC26 for calculating, for any integer i between 1 and the integer u, a value equal to g m[i],i ^a value C i ,as well as

[0190] - module MC28, for obtaining a password, said password being composed of the element {E k , C i}composition.

[0191] Now about Figure 8 A device DD for detecting the presence of a pattern according to an exemplary embodiment is described. The device DD is computer equipment, such as a computer.

[0192] It includes:

[0193] - a processing unit or processor 801 or CPU, intended to load instructions into a memory in order to execute them and thus perform operations;

[0194] - A collection of memories, including a volatile memory 802, or a RAM for executing code instructions, storing variables, etc., and a storage memory of the EEPROM type 803. In particular, the storage memory 803 is arranged to store a software module for detecting a pattern in a stream, the software module comprising code instructions for implementing the steps of the pattern detection method as described above.

[0195] The device DD for detecting the presence of a pattern also comprises:

[0196] - a module MD20 for obtaining a trapdoor T(w) associated with said pattern;

[0197] - A first module MD22 for calculating the element Q=C 1 ^r 1 *…*C v ^r v , where if w[i] is the special character, then r i =0, otherwise r i = r;

[0198] - a second module MD24, used to calculate a value D equal to Q^(1 / T), where T is an element of the trapdoor;

[0199] - a third module MD26 for calculating a value H(D), where H is a function H having values ​​in a finite set;

[0200] - A detection module MD30, which is configured to detect if H(D) is equal to E s , then the detection data (m) includes the pattern (w), where s is an integer included in the trapdoor.

Claims

1. A method for generating a trapdoor (T(w)) in a cryptographic system, the trapdoor (T(w)) being associated with a pattern w, the pattern w comprising the basic characters w[1], ... w[v] included in an alphabet (S), the alphabet (S) being supplemented by special characters that can replace any character of the alphabet, the system defining a key (sk) parameterized by integers n and t and include: - an integer a for any character c of said alphabet (S) and for any integer i between 1 and the integer n c,i ; as well as - an integer b for any integer k between 1 and the integer t k ; The method comprises the following steps: - selecting (T22) an integer s comprised between 1 and an integer t; as well as - Calculate (T24) value T = b s *(r 1 a w[1],1 +r 2 a w[2],2 +…+r v a w[v],v ), if w[i] is the special character, then r i =0, otherwise r i is equal to the integer r, The trapdoor includes elements s, r and T.

2. The encryption method is implemented in an encryption system defining a public key (pk) to obtain a password (C) by encrypting data (m) comprising at least u basic characters m[i], wherein the public key pk include: - for any integer i between 1 and the integer u, the element g c,i , the element g c,i With g^(a c,i ) in the form of c,i is an integer between 0 and an integer p-1, and g is a generator of a group G of order p; - an element h for any integer k between 1 and the integer t k , the element h k With g^(1 / b k ) in the form of k is an integer between 0 and p-1; - generator g; - a description of said group G; as well as - a description of a function H with a finite set of values, The method comprises the following steps: - select an integer a between (C22) 0 and p-1; - For any integer k between 1 and t, calculate the (C24) value E k =H(h k ^(a)); - For any integer i between 1 and u, calculate (C26) equal to g m[i],i ^a value C i , - obtain (C28) a password (C) consisting of the elements {E k ,C i }composition.

3. A method for detecting, in an encryption system, a pattern (w) in a cipher (C) obtained by encrypting data (m), said pattern (w) comprising the basic characters (w[1], ... w[v]) included in an alphabet (S), said alphabet (S) being supplemented by special characters which can replace any character of said alphabet, said method The following steps are involved: - obtaining (D20) a trapdoor (T(w)) associated with said pattern; - Calculate (D22) element Q = C 1 ^r 1 *…*C v ^r v , where if w[i] is the special character, then r i =0, otherwise r i = r; - calculating (D24) a value D equal to Q^(1 / T), where T is an element of said trapdoor; - calculating (D26) a value H(D), where H is a function H having values ​​in a finite set; -If H(D) equals E s , then calculating (D30) data (m) including said pattern (w), wherein s is an integer included in said trapdoor.

4. A device (DG) for generating a trapdoor (T(w)) in a cryptographic system, said trapdoor (T(w)) being associated with a pattern (w), said pattern (w) comprising basic characters (w[1], ... w[v]) included in an alphabet (S), said alphabet (S) being supplemented by special characters that can replace any character of said alphabet, said system defining a secret key (sk) parameterized by integers n and t and include: - an integer a for any character c of the alphabet (S) and for any integer i between 1 and the integer n c,i ; as well as - an integer b for any integer k between 1 and the integer t k ; The device (DG) comprises: - a module (MT22) for selecting an integer s comprised between 1 and t; and - used to calculate the value T = b s *(r 1 a w[1],1 +r 2 a w[2],2 +…+r v a w[v],v ) module (MT24), if w[i] is the special character, then r i =0, otherwise r i is equal to the integer r, The trapdoor (T(w)) includes elements s, r and T.

5. A computer program for a device for generating a trapdoor in an encryption system, comprising program code instructions for controlling the execution of the steps of the trapdoor generation method according to claim 1 when the program is executed on the device.

6. An encryption device (DC) implemented in an encryption system defining a public key (pk), the device being configured to obtain a password (C) by encrypting data (m) comprising at least u basic characters m[i], the public key (pk) being include: - for any integer i between 1 and the integer u, the element g c,i , the element g c,i With g^(a c,i ) in the form of c,i is an integer between 0 and an integer p-1, and g is a generator of a group G of order p; - an element h for any integer k between 1 and the integer t k , the element h k With g^(1 / b k ) in the form of k is an integer between 0 and p-1; - a generator g of group G; - description of group G; as well as - a description of a function H with a finite set of values, The device comprises: - a module (MC22) for selecting an integer a between 0 and p-1; - A first module (MC 24) for calculating, for any integer k between 1 and t, the value E k =H(h k ^(a)); - A second module (MC26) for calculating, for any integer i between 1 and u, a value equal to g m[i],i ^a value C i ,as well as A module (MC 28) for obtaining a password, the password being composed of the element {E k ,C i }composition.

7. A program for an encryption device, comprising program code instructions for controlling the execution of the steps of the encryption method according to claim 2 when the program is executed on the device.

8. A device (DD) for detecting, in an encryption system, the presence of a pattern (w) in a cipher (C) obtained by encrypting data (m), said pattern (w) comprising the basic characters (w[1], ... w[v]) included in an alphabet (S), said alphabet (S) being supplemented by special characters which can replace any character of said alphabet, said device include: - a module (MD 20) for obtaining a trapdoor (T(w)) associated with said pattern; - The first module (MD22) is used to calculate the element Q = C 1 ^r 1 *…*C v ^r v , where if w[i] is the special character, then r i =0, otherwise r i = r; a second module (MD24) for calculating a value D equal to Q^(1 / T), where T is an element of the trapdoor; - a third module (MD26) for calculating a value H(D), where H is a function H having values ​​in a finite set; - A detection module (MD30) configured to detect if H(D) is equal to E s , then it is detected that the data (m) includes the pattern (w), where s is an integer included in the trapdoor.

9. A program for a device for detecting the presence of a pattern in a password, comprising program code instructions for controlling the execution of the steps of the method for detecting the presence of a pattern in a password according to claim 3, when the program is executed on said device.

10. A method for decrypting a password (C) obtained by encrypting data (m) comprising at least u basic characters m[i], the password being generated by the encryption method according to claim 2, the decryption method include: - obtaining a trapdoor associated with each of the different elementary data of the data stream, the trapdoor being generated according to the trapdoor generation method according to claim 1, - According to the pattern detection method according to claim 3, detecting the presence of the trapdoor.

11. An encryption system, include: - a trapdoor generating device (DG) according to claim 4, - an encryption device (DC) according to claim 6, and - Device (DD) for detecting the presence of a pattern in a password according to claim 8.