Multivariable public key encryption system, method and device and storage medium
By introducing a multivariate public key encryption system into the financial system, using the public key composed of multiple quadratic polynomials generated by bilinear mapping, the problem of traditional encryption solutions being insufficient in the number of variables and information hiding capabilities is solved, and higher security and flexibility is achieved, and it is suitable for data encryption needs in financial systems and other fields.
Patent Information
- Application Number
- CN202510454641.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-06-24
AI Technical Summary
When facing the development of quantum computing technology, traditional public key cryptography systems face potential security threats, especially in information protection and data encryption in the financial field. The existing encryption solutions have limitations on the number of variables and lack information hiding capabilities.
A multivariate public key encryption system is proposed. The first device end uses the public key to encrypt the plaintext data to be encrypted, obtains the ciphertext data, and sends it to the second device end, and decrypts it after receiving it. The public key is obtained through bilinear mapping and consists of multiple quadratic polynomials, which avoids the limitation of the number of variables being squared, increasing the flexibility of calculation and universality of the encryption scheme.
The promotion of existing encryption solutions has been achieved, the universality and security of encryption solutions has been improved, and the bilinear mapping operation method has provided higher security and flexibility, adapting to the data encryption needs in the fields of financial systems and other fields.
Smart Images

Figure CN120200823A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of data processing, and in particular, to a multivariate public key encryption system, method, apparatus, and storage medium. Background Art
[0002] With the rapid development of quantum computing technology, the traditional public key cryptosystem faces potential security threats. For example, in the financial field, cryptographic technology is widely used in key links such as information protection, transaction verification, and data encryption, and is an important technical support for ensuring business continuity and data security. To address potential future security challenges, exploring post-quantum cryptography (PQC) algorithms suitable for banking information systems has important practical significance.
[0003] In PQC algorithms, the multivariate public key cryptosystem has become a strong candidate for deploying encryption schemes in financial systems due to its low computational complexity and high implementation efficiency. Currently, there is a SimpleMatrix encryption scheme designed based on a square matrix structure. However, this scheme has limitations on the number of variables, requiring the number of variables to be a perfect square, and there are certain deficiencies in the information hiding ability of the matrix operation method used. Summary of the Invention
[0004] In view of this, the present disclosure provides a multivariate public key encryption system, method, apparatus, and storage medium.
[0005] According to one aspect of the present disclosure, a multivariate public key encryption system is provided. The system includes a first device end and a second device end.
[0006] The first device end is configured to:
[0007] Encrypt the plaintext data to be encrypted using the public key to obtain ciphertext data. The public key is obtained using a bilinear mapping and consists of multiple quadratic polynomials.
[0008] Send the ciphertext data to the second device end.
[0009] The second device end is configured to:
[0010] Receive the ciphertext data sent by the first device end and perform a target operation on the ciphertext data.
[0011] In a possible implementation, encrypting the plaintext data to be encrypted using the public key to obtain ciphertext data includes:
[0012] Taking each data bit in the plaintext data to be encrypted as a variable and substituting them into multiple quadratic polynomials respectively to obtain ciphertext data.
[0013] Among them, the number of quadratic polynomials is M, the length of the plaintext data to be encrypted is N, each quadratic polynomial consists of N variables, M = 2N, and M and N are positive integers respectively.
[0014] In a possible implementation, the public key is issued by the second device, and the second device is also used for:
[0015] Perform a first linear mapping on N first variables to obtain N second variables;
[0016] Perform a central mapping based on the N second variables to obtain M quadratic polynomials;
[0017] Perform a second linear mapping on the M quadratic polynomials to obtain a new M quadratic polynomials as the public key.
[0018] In a possible implementation, performing a central mapping based on the N second variables to obtain M quadratic polynomials includes:
[0019] Take the N second variables as the first vector, and respectively construct a second vector and a third vector based on the first vector. Each component in the second vector and the third vector is a random linear combination of the N second variables;
[0020] Perform a target bilinear mapping based on the first vector and the second vector to obtain a first polynomial combination;
[0021] Perform a target bilinear mapping based on the first vector and the third vector to obtain a second polynomial combination; the first polynomial combination and the second polynomial combination each include N quadratic polynomials, and the target bilinear mapping satisfies the reversibility condition;
[0022] Obtain M quadratic polynomials based on the first polynomial combination and the second polynomial combination.
[0023] In a possible implementation, performing a target operation on the ciphertext data includes:
[0024] Decrypt the ciphertext data using the private key. The private key includes the mapping method of the first linear mapping, the mapping method of the second linear mapping, the coefficients of the second vector, and the coefficients of the third vector.
[0025] In a possible implementation, decrypting the ciphertext data using the private key includes:
[0026] Based on the mapping method of the second linear mapping, perform the inverse mapping of the second linear mapping on the ciphertext data to obtain the M quadratic polynomials after the inverse mapping;
[0027] Divide the M quadratic polynomials after the inverse mapping into a third polynomial combination and a fourth polynomial combination;
[0028] The fourth vector is obtained by solving based on the third polynomial combination and the fourth polynomial combination, and the fourth vector includes N variables;
[0029] Based on the mapping method of the first linear mapping, the inverse mapping of the first linear mapping is performed on the fourth vector to obtain the plaintext data.
[0030] According to another aspect of the present disclosure, a multivariate public key encryption method is provided. This method is used for the first device side, and the method includes:
[0031] Using the public key to encrypt the plaintext data to be encrypted to obtain ciphertext data, the public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials;
[0032] Sending the ciphertext data to the second device side, and the ciphertext data is used for the second device side to perform the target operation.
[0033] In a possible implementation manner, using the public key to encrypt the plaintext data to be encrypted to obtain ciphertext data includes:
[0034] Taking each data bit in the plaintext data to be encrypted as a variable and substituting them into multiple quadratic polynomials respectively to obtain ciphertext data;
[0035] Wherein, the number of quadratic polynomials is M, the length of the plaintext data to be encrypted is N, each quadratic polynomial consists of N variables, M = 2N and M, N are positive integers respectively.
[0036] In a possible implementation manner, the public key is issued by the second device side, and the method further includes:
[0037] The second device side performs a first linear mapping on N first variables to obtain N second variables;
[0038] The second device side performs a central mapping based on the N second variables to obtain M quadratic polynomials;
[0039] The second device side performs a second linear mapping on the M quadratic polynomials to obtain new M quadratic polynomials as the public key.
[0040] In a possible implementation manner, the second device side performs a central mapping based on the N second variables to obtain M quadratic polynomials, including:
[0041] The second device side takes the N second variables as the first vector, and respectively constructs a second vector and a third vector based on the first vector. Each component in the second vector and the third vector is a random linear combination of the N second variables;
[0042] The second device side performs a target bilinear mapping based on the first vector and the second vector to obtain a first polynomial combination;
[0043] The second device performs a target bilinear mapping based on the first vector and the third vector to obtain a second polynomial combination; the first polynomial combination and the second polynomial combination each include N quadratic polynomials, and the target bilinear mapping satisfies the reversibility condition;
[0044] The second device obtains M quadratic polynomials based on the first polynomial combination and the second polynomial combination.
[0045] In a possible implementation, the operations performed by the second device include:
[0046] The second device decrypts the ciphertext data using a private key, which includes the mapping method of the first linear mapping, the mapping method of the second linear mapping, the coefficients of the second vector, and the coefficients of the third vector.
[0047] In a possible implementation, the second device decrypts the ciphertext data using the private key, including:
[0048] The second device performs an inverse mapping of the second linear mapping on the ciphertext data based on the mapping method of the second linear mapping to obtain M inverse-mapped quadratic polynomials;
[0049] The second device divides the M inverse-mapped quadratic polynomials into a third polynomial combination and a fourth polynomial combination;
[0050] The second device solves for a fourth vector based on the third polynomial combination and the fourth polynomial combination, and the fourth vector includes N variables;
[0051] The second device performs an inverse mapping of the first linear mapping on the fourth vector based on the mapping method of the first linear mapping to obtain the plaintext data.
[0052] According to another aspect of the present disclosure, a multi-variable public key encryption method is provided. This method is used for the second device, and the method includes:
[0053] Receiving ciphertext data sent by the first device, where the ciphertext data is obtained by the first device encrypting the plaintext data to be encrypted using a public key, and the public key is obtained by a bilinear mapping and consists of multiple quadratic polynomials;
[0054] Performing target operations on the ciphertext data.
[0055] In a possible implementation, the first device encrypts the plaintext data to be encrypted using the public key, including:
[0056] The first device substitutes each data bit in the plaintext data to be encrypted as a variable into multiple quadratic polynomials to obtain the ciphertext data;
[0057] Among them, the number of quadratic polynomials is M, the length of the plaintext data to be encrypted is N, each quadratic polynomial consists of N variables, M = 2N and M, N are positive integers respectively.
[0058] In a possible implementation, the public key is issued by the second device side, and the method further includes:
[0059] Perform a first linear mapping on N first variables to obtain N second variables;
[0060] Perform a central mapping based on the N second variables to obtain M quadratic polynomials;
[0061] Perform a second linear mapping on the M quadratic polynomials to obtain new M quadratic polynomials as the public key.
[0062] In a possible implementation, performing a central mapping based on the N second variables to obtain M quadratic polynomials includes:
[0063] Take the N second variables as the first vector, and respectively construct a second vector and a third vector based on the first vector. Each component in the second vector and the third vector is a random linear combination of the N second variables;
[0064] Perform a target bilinear mapping based on the first vector and the second vector to obtain a first polynomial combination;
[0065] Perform a target bilinear mapping based on the first vector and the third vector to obtain a second polynomial combination; The first polynomial combination and the second polynomial combination each include N quadratic polynomials, and the target bilinear mapping satisfies the reversibility condition;
[0066] Obtain M quadratic polynomials based on the first polynomial combination and the second polynomial combination.
[0067] In a possible implementation, performing a target operation on the ciphertext data includes:
[0068] Decrypt the ciphertext data using the private key. The private key includes the mapping method of the first linear mapping, the mapping method of the second linear mapping, the coefficients of the second vector, and the coefficients of the third vector.
[0069] In a possible implementation, decrypting the ciphertext data using the private key includes:
[0070] Based on the mapping method of the second linear mapping, perform the inverse mapping of the second linear mapping on the ciphertext data to obtain the M quadratic polynomials after the inverse mapping;
[0071] Divide the M quadratic polynomials after the inverse mapping into a third polynomial combination and a fourth polynomial combination;
[0072] The fourth vector is obtained by solving based on a third polynomial combination and a fourth polynomial combination, and the fourth vector includes N variables.
[0073] Based on the mapping method of the first linear mapping, the inverse mapping of the first linear mapping is performed on the fourth vector to obtain the plaintext data.
[0074] According to another aspect of the present disclosure, there is provided a multi-variable public key encryption device, including a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the steps of the above method.
[0075] According to another aspect of the present disclosure, there is provided a non-volatile computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0076] According to another aspect of the present disclosure, there is provided a computer program product, including a computer program, or a non-volatile computer-readable storage medium carrying the computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0077] According to an embodiment of the present disclosure, the first device end encrypts the plaintext data to be encrypted using a public key to obtain ciphertext data, and sends it to the second device end. The second device end receives the ciphertext data sent by the first device end and performs a target operation on the ciphertext data. Among them, the public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials, which can realize the promotion of the existing encryption scheme. By using the operation method of the bilinear mapping, the limitation of the number of variables being a perfect square in the prior art can be avoided, increasing the flexibility of calculation, making the selection of the number of variables more free, improving the universality of the encryption scheme, and providing higher security by keeping the rules of the bilinear mapping operation as a secret.
[0078] According to the following detailed description of exemplary embodiments with reference to the accompanying drawings, other features and aspects of the present disclosure will become clear. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] The accompanying drawings included in the specification and constituting a part of the specification show exemplary embodiments, features, and aspects of the present disclosure together with the specification, and are used to explain the principles of the present disclosure.
[0080] Figure 1 A schematic diagram showing an application scenario according to an embodiment of the present disclosure.
[0081] Figure 2 A structural diagram showing a multi-variable public key encryption system according to an embodiment of the present disclosure.
[0082] Figure 3A flowchart showing a multi-variable public key encryption method according to an embodiment of the present disclosure.
[0083] Figure 4 A flowchart showing a multi-variable public key encryption method according to an embodiment of the present disclosure.
[0084] Figure 5 A block diagram of an apparatus 1900 for multi-variable public key encryption shown according to an exemplary embodiment. Detailed implementation manners
[0085] Various exemplary embodiments, features, and aspects of the present disclosure will be described in detail below with reference to the accompanying drawings. The same reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings are not necessarily drawn to scale unless otherwise specified.
[0086] As used herein, the terms "comprising", "including", "having", or variations thereof are open-ended and include one or more stated features, wholes, elements, steps, components, or functions, but do not exclude the presence or addition of one or more other features, wholes, elements, steps, components, functions, or groups thereof.
[0087] When an element is referred to as being "connected", "coupled", "responsive" or variations thereof with respect to another element, it can be directly connected, coupled, or responsive to the other element, or intervening elements may be present.
[0088] Although the terms first, second, third, etc. may be used herein to describe various elements / operations, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another. Thus, without departing from the teachings of the inventive concept, a first element / operation in some embodiments may be referred to as a second element / operation in other embodiments.
[0089] The term "exemplary" used herein means "serving as an example, embodiment, or illustration". Any embodiment illustrated herein as "exemplary" should not be construed as being superior to or better than other embodiments.
[0090] In addition, for a better illustration of the present disclosure, numerous specific details are given in the following detailed implementation manners. Those skilled in the art should understand that the present disclosure can be implemented without some specific details. In some instances, methods, means, elements, and circuits well known to those skilled in the art are not described in detail so as to highlight the gist of the present disclosure.
[0091] With the rapid development of quantum computing technology, the traditional public-key cryptosystem faces potential security threats. For example, in the financial field, cryptography is widely used in key aspects such as information protection, transaction verification, and data encryption, and is an important technical support for ensuring business continuity and data security. To address potential future security challenges, exploring post-quantum cryptography (PQC) algorithms suitable for banking information systems has important practical significance.
[0092] In PQC algorithms, the multivariate public-key cryptosystem has become a strong candidate for deploying encryption schemes in financial systems due to its low computational complexity and high implementation efficiency. Currently, there is a SimpleMatrix encryption scheme designed based on a square matrix structure. However, this scheme has limitations on the number of variables, requiring the number of variables to be a perfect square, and the matrix operation method used has certain deficiencies in information hiding ability.
[0093] In view of this, the present disclosure proposes a multivariate public-key encryption system, method, device, and storage medium. The multivariate public-key encryption system according to the embodiments of the present disclosure encrypts the plaintext data to be encrypted using the public key by a first device end, obtains the ciphertext data, and sends it to a second device end. The second device end receives the ciphertext data sent by the first device end and performs a target operation on the ciphertext data. Among them, the public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials, which can realize the generalization of existing encryption schemes. The operation method of the bilinear mapping can avoid the limitation that the number of variables is a perfect square in the prior art, increasing the flexibility of calculation, making the selection of the number of variables more free, improving the universality of the encryption scheme, and providing higher security by keeping the rules of the bilinear mapping operation as a secret.
[0094] Figure 1 A schematic diagram showing an application scenario according to an embodiment of the present disclosure is as follows Figure 1 As shown, the multivariate public-key encryption system according to the embodiments of the present disclosure can be used in the financial field, for example, for encrypting privacy data in a banking information system. In this application scenario, the user terminal can encrypt the privacy data using the public key and send it to the bank server. The bank server decrypts it using the corresponding private key to restore the original privacy data, thereby realizing the confidentiality protection and trusted transmission of privacy data during the transmission process, and enhancing the overall security and controllability of the financial system.
[0095] It should be noted that the multivariate public-key encryption system according to the embodiments of the present disclosure can also be used in other scenarios outside the financial field. The embodiments of the present disclosure do not limit this, as long as there is a need to encrypt data, the multivariate public-key encryption system according to the embodiments of the present disclosure can be applied.
[0096] The multi-variable public key encryption system according to the embodiments of the present disclosure can be used in a terminal device or a server. The terminal device involved in the embodiments of the present disclosure can be any one or more of a mobile phone, a foldable electronic device, a tablet computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a cellular phone, a personal digital assistant (PDA), and a vehicle-mounted device. The embodiments of the present disclosure do not impose special restrictions on the specific type of the terminal device, and it can have wired or wireless communication functions.
[0097] The server involved in the embodiments of the present disclosure can be located locally or in the cloud, and can be a physical device or a virtual device, such as a virtual machine, a container, etc., and has a wireless communication function. Among them, the wireless communication function can be set in the chip (system) or other components or assemblies of the server. The wireless communication function can be implemented, for example, through mobile communication technologies such as 2G / 3G / 4G / 5G, as well as Wi-Fi, Bluetooth, frequency modulation (FM), data radio, satellite communication, etc. Communication can also be carried out through a wired connection to achieve interaction with other devices.
[0098] Figure 2 The structural diagram of the multi-variable public key encryption system according to the embodiments of the present disclosure is shown. As Figure 2 shown, the multi-variable public key encryption system can include a first device end 201 and a second device end 202. The first device end 201 and the second device end 202 can be the above-mentioned terminal device or server.
[0099] The first device end 201 can be used for:
[0100] encrypting the plaintext data to be encrypted by using the public key to obtain ciphertext data.
[0101] Among them, the plaintext data to be encrypted can be data with confidentiality requirements. For example, it can be privacy or sensitive data such as user identity information, transaction-related data (including transaction amount, transaction instruction, transaction content, etc.), digital signature data, etc. For example, the first device end 201 can be a customer terminal. By encrypting the plaintext data to be encrypted and then transmitting it, the data security during the transmission process can be guaranteed.
[0102] The public key can be issued by the second device end 202. For example, the second device end 202 can be a bank server end. The public key can be pre-generated by the second device end 202, and the first device end 201 can obtain the public key issued by the second device end 202 to encrypt the plaintext data to be encrypted.
[0103] Among them, the public key can be composed of multiple quadratic polynomials. The number of quadratic polynomials can be M, in the form of (g1(x1, x2, …, x N ), g2(x1, x2, …, x N ), …, g M (x1, x2, …, x N ))), where g1 to g M can respectively represent M quadratic polynomials within a specified finite field K, and x1 to x N can respectively represent the variables in the quadratic polynomials. The number of quadratic polynomials can be controlled by the number of variables. Each quadratic polynomial can be composed of N variables, such that M = 2N and M and N are respectively positive integers. The specific form of the quadratic polynomial can be set as needed.
[0104] In the process of encrypting the plaintext data to be encrypted using the public key at the first device end 201 to obtain the ciphertext data, it is possible to:
[0105] Take each data bit in the plaintext data to be encrypted as a variable and substitute them into multiple quadratic polynomials respectively to obtain the ciphertext data.
[0106] Among them, the length of the plaintext data to be encrypted can be N, and the plaintext data to be encrypted can be expressed as (x1, x2, …, x N ) ∈ K N , where, for a positive integer s, K s is defined as an s-dimensional K-linear space (then K N can represent an N-dimensional K-linear space). Thus, the plaintext data to be encrypted (x1, x2, …, x N ) can be respectively substituted into the above quadratic polynomials g1 to g M to obtain the ciphertext data. The ciphertext data can be expressed as (y1, y2, …, y M ) ∈ K M , and K M can represent an M-dimensional K-linear space.
[0107] In a possible implementation, the plaintext data to be encrypted can be binary data. Each binary data bit in the binary data can be taken as a variable and substituted into the multiple quadratic polynomials corresponding to the above public key to obtain the ciphertext data. For example, if the plaintext data to be encrypted is 11010, then N is 5. The value of each binary data bit can be respectively taken as the value of the above variables x1 to x N and substituted into the above quadratic polynomials g1 to g M , where let x1 = 1, x2 = 1, x3 = 0, x4 = 1, x5 = 0 to obtain the ciphertext data.
[0108] The public key can be obtained by using bilinear mapping to expand the usage scenarios and parameter selection methods of the encryption method. The following further introduces the process of generating the public key.
[0109] The second device 202 can be used for:
[0110] Perform a first linear mapping on N first variables to obtain N second variables;
[0111] Perform a central mapping based on the N second variables to obtain M quadratic polynomials;
[0112] Perform a second linear mapping on the M quadratic polynomials to obtain M new quadratic polynomials as the public key.
[0113] Among them, the first variables can be expressed as the above (x1, x2, …, x N ), where x1 to x N are variables, that is, the N variables in the public key. The first linear mapping can be expressed as L1: K N → K N , and the second variables can be expressed as L1(x1, x2, …, x N ). The first linear mapping can be used to map the first variables to another set of variables in K N , so as to disrupt the structure of the first variables and enhance the security and anti-attack ability of the encryption function. The first linear mapping can be an arbitrary form of invertible linear transformation mapping.
[0114] The above M quadratic polynomials can be expressed as F(L1(x1, x2, …, x N ). Among them, F can represent the central mapping. In the process of performing a central mapping based on the N second variables to obtain M quadratic polynomials, it is possible to:
[0115] Regard the N second variables as the first vector, and respectively construct the second vector and the third vector based on the first vector;
[0116] Perform a target bilinear mapping based on the first vector and the second vector to obtain the first polynomial combination;
[0117] Perform a target bilinear mapping based on the first vector and the third vector to obtain the second polynomial combination;
[0118] Obtain M quadratic polynomials based on the first polynomial combination and the second polynomial combination.
[0119] Among them, the first vector can be expressed as A = (a1, a2, …, a N ), the second vector can be expressed as B = (b1, b2, …, b N ), and the third vector can be expressed as C = (c1, c2, …, cN )。The components in the second vector and the third vector can be random linear combinations of N second variables, that is, b i and c i can be randomly selected linear combinations of a1, a2, …, a N . For example, in the process of generating random linear combinations, a random number generator can be used for B and C respectively to randomly generate different weight sizes for different a1, a2, …, a N . By multiplying a1, a2, …, a N by the corresponding weights respectively, a set of linear combinations can be obtained as B or C.
[0120] The first polynomial combination can be expressed as E1 = T(A, B), and the second polynomial combination can be expressed as E2 = T(A, C), where T can represent the target bilinear mapping, T: K N ×K N →K N . The target bilinear mapping satisfies the invertibility condition, which can be expressed as:
[0121] T satisfies that for any non - zero p, q ∈ K N , there exist p -1 and q -1 belonging to K N such that T(T(r, q), q -1 ) = r and T(p -1 , T(p, r)) = r hold for any r ∈ K N . Through this invertibility condition, it can be ensured that the ciphertext data in the embodiments of the present disclosure can be decrypted.
[0122] In a possible implementation, the target bilinear mapping T can be constructed based on the companion matrix of an irreducible polynomial of degree N. Among them, the irreducible polynomial of degree N can be expressed as R(d) = d N +h N-1 d N -1 +…+h1d 1 +h0. Denote the companion matrix of R(d) as CM (used to describe the linear recurrence relation of R(d)). Let the element in the j - th row and k - th column of T i be the element in the i - th row and k - th column of CM j-1 , then T(p, q) = (T1(p, q), …, T N (p, q)) can be obtained as the target bilinear mapping that meets the requirements.
[0123] Therefore, the above-mentioned first polynomial combination E1 and second polynomial combination E2 may respectively include N quadratic polynomials, and the way to combine the first polynomial combination and the second polynomial may be to let f i and f i+N respectively represent the i-th elements of E1 and E2, so that M quadratic polynomials f1, f2, …, f M can be obtained as the M quadratic polynomials. Then, the central mapping can be expressed as:
[0124] F(a1, a2, …, a N ) = (f1(a1, a2, …, a N ), f2(a1, a2, …, a N ), …, f M (a1, a2, …, a N ))
[0125] The second linear mapping can be expressed as L2: K M → K M , and by performing the second linear mapping on the M quadratic polynomials, the new M quadratic polynomials obtained can be expressed as L2(F(L1(x1, x2, …, x N ))). The second linear mapping can be used to map F(L1(x1, x2, …, x N )) to another set of M quadratic polynomials in K M , so as to disrupt the structure of the original M quadratic polynomials, thereby enhancing the security and anti-attack ability of the encryption function. The second linear mapping can be an arbitrary form of invertible linear transformation mapping
[0126] Finally, the public key can be expressed as: G(x1, x2, …, x N ) =
[0127] L2(F(L1(x1, x2, …, x N ))) = g1(x1, x2, …, x N ), g2(x1, x2, …, x N ), …, g M (x1, x2, …, x N )
[0128] The ciphertext data can be expressed as (y1, y2, …, y M ) = G(x1, x2, …, x N )
[0129] In the embodiments of the present disclosure, through the design of the central mapping, the central mapping is obtained based on a bilinear mapping that satisfies the reversibility condition, enabling operations to be performed using elements in a linear space. Compared with the existing method of performing operations using matrix elements, the selection of the number of variables can be made more freely, improving the universality of the encryption scheme. Through the design of the first linear mapping and the second linear mapping, the central mapping can be protected from being easily cracked, thereby further enhancing the security and anti-attack ability of the encryption function.
[0130] The first device 201 can send the ciphertext data to the second device 202.
[0131] The second device 202 is configured to:
[0132] Receive the ciphertext data sent by the first device 201 and perform a target operation on the ciphertext data.
[0133] According to the embodiments of the present disclosure, the first device encrypts the plaintext data to be encrypted using the public key to obtain ciphertext data and sends it to the second device. The second device receives the ciphertext data sent by the first device and performs a target operation on the ciphertext data. The public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials, which can realize the generalization of the existing encryption scheme. The operation method of the bilinear mapping can avoid the limitation that the number of variables in the prior art is a square number, increasing the flexibility of calculation, making the selection of the number of variables more free, improving the universality of the encryption scheme, and providing higher security by keeping the rules of the bilinear mapping operation as a secret.
[0134] The target operation may include storing, forwarding, etc. the ciphertext data without decrypting it, or may also include decrypting the ciphertext data to obtain the plaintext data, and then performing operations such as verifying, analyzing, calculating, or business processing on the plaintext data. The embodiments of the present disclosure do not limit this.
[0135] In a possible implementation manner, the second device 202 performing the target operation on the ciphertext data includes:
[0136] Decrypting the ciphertext data using the private key.
[0137] The private key can be a non-public and non-disclosable key, which can be kept only by the decrypting party, i.e., the second device 202. The ciphertext data can be decrypted using the private key to recover the plaintext data.
[0138] Wherein, the private key may include the mapping method of the first linear mapping L1, the mapping method of the second linear mapping L2, the coefficients of the second vector, and the coefficients of the third vector.
[0139] The coefficients of the second vector are the above b1 to b in BN The coefficients of each polynomial element, and the coefficients of the third vector, namely c1 to c in the above C N The coefficients of each polynomial element.
[0140] In the process of decrypting ciphertext data using the private key, it is possible to:
[0141] Based on the mapping method of the second linear mapping, perform the inverse mapping of the second linear mapping on the ciphertext data to obtain M quadratic polynomials after the inverse mapping;
[0142] Divide the M quadratic polynomials after the inverse mapping into a third polynomial combination and a fourth polynomial combination;
[0143] Solve to obtain a fourth vector based on the third polynomial combination and the fourth polynomial combination;
[0144] Based on the mapping method of the first linear mapping, perform the inverse mapping of the first linear mapping on the fourth vector to obtain the plaintext data.
[0145] The above method for performing the inverse mapping of the second linear mapping can be implemented based on related technologies, and this disclosure places no restrictions thereon. Through the inverse mapping of the second linear mapping, (y1, y2,..., y M ) can be restored to the variable data before the second linear mapping. The M quadratic polynomials after the inverse mapping can be expressed as (z1, z2,..., z M ) = L2 -1 (y1, y2,..., y M ).
[0146] Among them, the first N quadratic polynomials in (z1, z2,..., z M ) can be used as the third polynomial combination, and the last N quadratic polynomials in (z1, z2,..., z M ) can be used as the fourth polynomial combination. Then, the third polynomial combination can be expressed as E3 = (z1, z2,..., z N ), and the fourth polynomial combination can be expressed as E4 = (z N+1 , z N+2 ,..., z M ). The fourth vector includes N variables and can be expressed as (w1, w2,..., w N ), and each element in the above (z1, z2,..., z M ) can be regarded as a quadratic polynomial about the variables (w1, w2,..., w N ).
[0147] The process of solving to obtain the fourth vector based on the third polynomial combination and the fourth polynomial combination can be understood as performing operations on (z1, z2,..., z M)The process of performing the inverse mapping of the above central mapping F. In the process of solving for the fourth vector based on the third polynomial combination and the fourth polynomial combination, the following several possible cases can be considered for solving:
[0148] In the case where E3≠0, it can be solved based on T(T(B, E3 -1 ), E4) = C, where the elements b i and c i in B and C can be regarded as quadratic polynomials about the same N variables. Since the coefficients of each quadratic polynomial in B and C have been given by the private key, this equation gives N linear equations about N variables, and thus N variables can be solved as (w1, w2,..., w N ).
[0149] In the case where E4≠0, it can be solved based on T(T(C, E4 -1 ), E2) = B. Similarly, since the coefficients of each quadratic polynomial in B and C have been given by the private key, this equation also gives N linear equations about N variables, and thus N variables can be solved as (w1, w2,..., w N ).
[0150] In the case where E3 = 0 and E4 = 0, if A≠0, it can be solved by simultaneously solving T(A -1 , E3) = B and T(A -1 , E4) = C. Among them, the elements a1~a N in A can be regarded as N variables different from B and C. Thus, by simultaneously solving these two sets of equations, M = 2N linear equations about M variables can be given, and N variables can be solved as (w1, w2,..., w N ) by elimination.
[0151] Finally, if A = 0, at this time E3 = 0 and E4 = 0, then the solution (w1, w2,..., w N ) = 0. This situation rarely occurs in the actual decryption process, which means that the obtained original plaintext data is empty. At this time, the second device 202 can send an error prompt or an exception response to the first device 201 to prompt that the plaintext data is invalid or there is an exception.
[0152] The method of performing the inverse mapping of the first linear mapping can also be implemented based on related technologies. The present disclosure does not limit this. Through the inverse mapping of the first linear mapping, (w1, w2,..., w N ) can be restored to the variable data before the first linear mapping. The plaintext data obtained after the inverse mapping can be expressed as (x1, x2,..., x N ) = L1 -1(w1, w2, …, w N ).
[0153] Thus, the decryption of the ciphertext data can be realized, and thus, the second device 202 can perform subsequent operations such as verification, analysis, calculation, or business processing on the plaintext data.
[0154] Figure 3 The flowchart of the multi-variable public key encryption method according to an embodiment of the present disclosure is shown. This method can be used for the first device 201, such as Figure 3 shown, the method includes:
[0155] Step S301, encrypt the plaintext data to be encrypted using the public key to obtain ciphertext data;
[0156] Among them, the public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials.
[0157] Step S302, send the ciphertext data to the second device 202.
[0158] Among them, the ciphertext data is used for the second device 202 to perform the target operation.
[0159] In a possible implementation manner, step S301 includes:
[0160] Regarding each data bit in the plaintext data to be encrypted as a variable, and substituting them into multiple quadratic polynomials respectively to obtain ciphertext data;
[0161] Among them, the number of quadratic polynomials is M, the length of the plaintext data to be encrypted is N, each quadratic polynomial consists of N variables, M = 2N and M, N are positive integers respectively.
[0162] In a possible implementation manner, the public key is issued by the second device 202, and the method further includes:
[0163] The second device 202 performs a first linear mapping on N first variables to obtain N second variables;
[0164] The second device 202 performs a central mapping based on the N second variables to obtain M quadratic polynomials;
[0165] The second device 202 performs a second linear mapping on the M quadratic polynomials to obtain new M quadratic polynomials as the public key.
[0166] In a possible implementation manner, the second device 202 performs a central mapping based on the N second variables to obtain M quadratic polynomials, including:
[0167] The second device 202 uses the N second variables as the first vector, and respectively constructs a second vector and a third vector based on the first vector. Each component in the second vector and the third vector is a random linear combination of the N second variables;
[0168] The second device 202 performs a target bilinear mapping based on the first vector and the second vector to obtain a first polynomial combination;
[0169] The second device 202 performs a target bilinear mapping based on the first vector and the third vector to obtain a second polynomial combination; The first polynomial combination and the second polynomial combination each include N quadratic polynomials, and the target bilinear mapping satisfies the reversibility condition;
[0170] The second device 202 obtains M quadratic polynomials based on the first polynomial combination and the second polynomial combination.
[0171] In a possible implementation, the operations performed by the second device 202 include:
[0172] The second device 202 decrypts the ciphertext data using a private key, and the private key includes the mapping method of the first linear mapping, the mapping method of the second linear mapping, the coefficients of the second vector, and the coefficients of the third vector.
[0173] In a possible implementation, the second device 202 decrypts the ciphertext data using a private key, including:
[0174] The second device 202 performs an inverse mapping of the second linear mapping on the ciphertext data based on the mapping method of the second linear mapping to obtain M inverse-mapped quadratic polynomials;
[0175] The second device 202 divides the M inverse-mapped quadratic polynomials into a third polynomial combination and a fourth polynomial combination;
[0176] The second device 202 solves for a fourth vector based on the third polynomial combination and the fourth polynomial combination. The fourth vector includes N variables;
[0177] The second device 202 performs an inverse mapping of the first linear mapping on the fourth vector based on the mapping method of the first linear mapping to obtain the plaintext data.
[0178] According to an embodiment of the present disclosure, the first device encrypts the plaintext data to be encrypted using a public key to obtain ciphertext data, and sends the ciphertext data to the second device, so that the ciphertext data can be used by the second device to perform a target operation. Among them, the public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials, which can realize the generalization of the existing encryption scheme. Through the operation method of the bilinear mapping, the limitation of the number of variables being a square number in the prior art can be avoided, increasing the flexibility of calculation, making the selection of the number of variables more free, improving the universality of the encryption scheme, and by keeping the rules of the bilinear mapping operation as a secret, higher security can be provided.
[0179] Figure 4 The flowchart showing the multi-variable public key encryption method according to an embodiment of the present disclosure. This method is used for the second device 202, as Figure 4 shown, the method includes:
[0180] Step S401, receiving the ciphertext data sent by the first device 201;
[0181] The ciphertext data is obtained after the first device 201 encrypts the plaintext data to be encrypted using a public key. The public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials;
[0182] Step S402, performing a target operation on the ciphertext data.
[0183] In a possible implementation manner, the first device 201 encrypts the plaintext data to be encrypted using a public key, including:
[0184] The first device 201 takes each data bit in the plaintext data to be encrypted as a variable, and substitutes them into multiple quadratic polynomials respectively to obtain ciphertext data;
[0185] Among them, the number of quadratic polynomials is M, the length of the plaintext data to be encrypted is N, each quadratic polynomial consists of N variables, M = 2N and M, N are positive integers respectively.
[0186] In a possible implementation manner, the public key is issued by the second device 202, and the method further includes:
[0187] Performing a first linear mapping on N first variables to obtain N second variables;
[0188] Performing a central mapping based on the N second variables to obtain M quadratic polynomials;
[0189] Performing a second linear mapping on the M quadratic polynomials to obtain new M quadratic polynomials as the public key.
[0190] In a possible implementation manner, performing a central mapping based on the N second variables to obtain M quadratic polynomials, including:
[0191] Take N second variables as the first vector, and respectively construct a second vector and a third vector based on the first vector. Each component in the second vector and the third vector is a random linear combination of the N second variables;
[0192] Perform a target bilinear mapping based on the first vector and the second vector to obtain a first polynomial combination;
[0193] Perform a target bilinear mapping based on the first vector and the third vector to obtain a second polynomial combination; The first polynomial combination and the second polynomial combination each include N quadratic polynomials, and the target bilinear mapping satisfies the reversibility condition;
[0194] Obtain M quadratic polynomials based on the first polynomial combination and the second polynomial combination.
[0195] In a possible implementation manner, step S402 includes:
[0196] Use the private key to decrypt the ciphertext data. The private key includes the mapping method of the first linear mapping, the mapping method of the second linear mapping, the coefficients of the second vector, and the coefficients of the third vector.
[0197] In a possible implementation manner, using the private key to decrypt the ciphertext data includes:
[0198] Based on the mapping method of the second linear mapping, perform the inverse mapping of the second linear mapping on the ciphertext data to obtain the M quadratic polynomials after the inverse mapping;
[0199] Divide the M quadratic polynomials after the inverse mapping into a third polynomial combination and a fourth polynomial combination;
[0200] Solve to obtain a fourth vector based on the third polynomial combination and the fourth polynomial combination. The fourth vector includes N variables;
[0201] Based on the mapping method of the first linear mapping, perform the inverse mapping of the first linear mapping on the fourth vector to obtain the plaintext data.
[0202] According to the embodiments of the present disclosure, the second device receives the ciphertext data sent by the first device and performs a target operation on the ciphertext data. The ciphertext data is obtained by the first device encrypting the plaintext data to be encrypted using the public key. The public key is obtained by using a bilinear mapping and consists of multiple quadratic polynomials. It can realize the generalization of the existing encryption scheme. The operation method of the bilinear mapping can avoid the limitation of the number of variables being a square number in the prior art, increase the flexibility of calculation, and also make the selection of the number of variables more free, improving the universality of the encryption scheme. Moreover, by keeping the rules of the bilinear mapping operation as a secret, higher security can be provided.
[0203] In some embodiments, the functions or modules included in the apparatus provided by the embodiments of the present disclosure can be used to execute the methods described in the above method embodiments. The specific implementation can refer to the description of the above method embodiments. For the sake of brevity, it will not be repeated here.
[0204] The embodiments of the present disclosure further provide a multi-variable public key encryption apparatus, including a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the steps of the above method.
[0205] The embodiments of the present disclosure further provide a non-volatile computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented.
[0206] The embodiments of the present disclosure further provide a computer program product, including a computer program, or a non-volatile computer-readable storage medium carrying the computer program. When the computer program is executed by a processor, the steps of the above method are implemented.
[0207] Figure 5 is a block diagram of an apparatus 1900 for multi-variable public key encryption shown according to an exemplary embodiment. For example, the apparatus 1900 can be provided as a server or a terminal device. Referring to Figure 5 , the apparatus 1900 includes a processing component 1922, which further includes one or more processors, and memory resources represented by a memory 1932 for storing instructions executable by the processing component 1922, such as application programs. The application programs stored in the memory 1932 can include one or more modules each corresponding to a set of instructions. In addition, the processing component 1922 is configured to execute instructions to perform the above method.
[0208] The apparatus 1900 may further include a power supply component 1926 configured to perform power management of the apparatus 1900, a wired or wireless network interface 1950 configured to connect the apparatus 1900 to a network, and an input / output interface 1958 (I / O interface). The apparatus 1900 can operate based on an operating system stored in the memory 1932, such as Windows Server TM , MacOS X TM , Unix TM , Linux TM , FreeBSD TM or the like.
[0209] In an exemplary embodiment, a non-volatile computer-readable storage medium is also provided, such as a memory 1932 including computer program instructions, and the computer program instructions can be executed by a processing component 1922 of the device 1900 to complete the above method.
[0210] A computer-readable storage medium can be a tangible device that can hold and store programs / instructions used by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device, such as a punched card or raised structures in grooves storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage medium used herein is not construed as an instantaneous signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0211] The computer programs (or computer-readable program instructions) described herein can be downloaded from a computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include a copper transmission cable, an optical fiber transmission, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.
[0212] A computer program (or computer program instructions) for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or, alternatively, may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, by using the state information of the computer-readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer-readable program instructions to implement various aspects of the present disclosure.
[0213] Aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0214] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data processing apparatus, create a means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. The computer-readable program instructions can also be stored in a computer-readable storage medium, which instructions cause a computer, a programmable data processing apparatus, and / or other devices to operate in a particular manner, such that the computer-readable medium storing the instructions comprises a manufacture comprising instructions for implementing various aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0215] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other devices implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0216] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or by a combination of dedicated hardware and computer instructions.
[0217] The embodiments of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, the practical application, or improvements made to the technology in the market, or to enable other ordinary skilled persons in the art to understand the embodiments disclosed herein.
Claims
1. A multivariate public key encryption system, characterized in that: The system comprises a first device end and a second device end, The first device is used for: Encrypting the plaintext data to be encrypted using a public key to obtain ciphertext data, wherein the public key is obtained using a bilinear mapping and is composed of multiple quadratic polynomials; Sending the ciphertext data to the second device end; The second device is used for: Receive the ciphertext data sent by the first device end, and perform a target operation on the ciphertext data.
2. The system according to claim 1, characterized in that The step of encrypting the plaintext data to be encrypted using the public key to obtain ciphertext data includes: Substituting each data bit in the plaintext data to be encrypted as a variable into the multiple quadratic polynomials to obtain ciphertext data; The number of quadratic polynomials is M, the length of the plaintext data to be encrypted is N, each quadratic polynomial consists of N variables, M=2N, and M and N are positive integers respectively.
3. The system according to claim 1, characterized in that The public key is issued by the second device, and the second device is further used for: Perform a first linear mapping on the N first variables to obtain N second variables; Performing center mapping based on the N second variables to obtain M quadratic polynomials; Perform a second linear mapping on the M quadratic polynomials to obtain new M quadratic polynomials as the public keys.
4. The system according to claim 3, characterized in that The center mapping is performed based on the N second variables to obtain M quadratic polynomials, including: Taking the N second variables as first vectors, constructing second vectors and third vectors based on the first vectors, respectively, wherein each component in the second vector and the third vector is a random linear combination of the N second variables; Perform a target bilinear mapping based on the first vector and the second vector to obtain a first polynomial combination; Performing a target bilinear mapping based on the first vector and the third vector to obtain a second polynomial combination; the first polynomial combination and the second polynomial combination respectively include N quadratic polynomials, and the target bilinear mapping satisfies a reversibility condition; The M quadratic polynomials are obtained based on the first polynomial combination and the second polynomial combination.
5. The system according to claim 4, characterized in that The performing a target operation on the ciphertext data includes: The ciphertext data is decrypted using a private key, where the private key includes a mapping mode of the first linear mapping, a mapping mode of the second linear mapping, coefficients of the second vector, and coefficients of the third vector.
6. The system according to claim 5, characterized in that Decrypting the ciphertext data using a private key includes: Based on the mapping mode of the second linear mapping, inverse mapping of the second linear mapping is performed on the ciphertext data to obtain M quadratic polynomials after inverse mapping; Dividing the inverse mapped M quadratic polynomials into a third polynomial combination and a fourth polynomial combination; Solving the third polynomial combination and the fourth polynomial combination to obtain a fourth vector, wherein the fourth vector includes N variables; Based on the mapping mode of the first linear mapping, the inverse mapping of the first linear mapping is performed on the fourth vector to obtain plaintext data.
7. A multivariate public key encryption method, characterized in that: The method is used on a first device, and includes: Encrypting the plaintext data to be encrypted using a public key to obtain ciphertext data, wherein the public key is obtained using a bilinear mapping and is composed of multiple quadratic polynomials; The ciphertext data is sent to a second device end, and the ciphertext data is used by the second device end to perform a target operation.
8. A multivariate public key encryption method, characterized in that: The method is used on a second device, and includes: Receiving ciphertext data sent by the first device, where the ciphertext data is obtained by encrypting the plaintext data to be encrypted by the first device using a public key, where the public key is obtained using a bilinear mapping and is composed of a plurality of quadratic polynomials; A target operation is performed on the ciphertext data.
9. A multivariate public key encryption device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to claim 7 or claim 8.
10. A non-volatile computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to claim 7 or claim 8 are implemented.
11. A computer program product, comprising a computer program, or a non-volatile computer-readable storage medium carrying a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to claim 7 or claim 8 are implemented.