Encryption system, encryption method and encryption program
The ciphertext conversion system securely transforms symmetric ciphertexts to public-key ciphertexts using exclusive OR operations, addressing security risks and reducing key generation costs.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-13
- Publication Date
- 2026-04-02
AI Technical Summary
Existing methods for converting a ciphertext of a symmetric encryption scheme into a public-key encryption scheme require decryption of the symmetric ciphertext, leading to potential security risks due to plaintext exposure.
A ciphertext conversion system that employs a conversion device to encrypt a symmetric ciphertext using a public-key encryption scheme without decryption, utilizing a conversion unit that calculates a converted public-key ciphertext and a corresponding key through exclusive OR operations with symmetric encryption values and auxiliary information.
The system enables secure conversion of symmetric ciphertexts to public-key ciphertexts without decryption, reducing the need for conversion keys and key generation calls, thereby enhancing security and efficiency.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The present disclosure relates to a ciphertext conversion system, a ciphertext conversion method, and a ciphertext conversion program. State of the art
[0002] A proxy re-encryption (PRE) system is a system that delegates the authority to decrypt a ciphertext to another person without decrypting the ciphertext itself. Non-patent literature 1 discloses a PRE method in an arbitrary attribute-based encryption scheme (attribute-based PRE, ABPRE). Using the technique described in non-patent literature 1, proxy encryption can be implemented between attribute-based encryption schemes that differ from one another. Non-patent literature 2 describes a technique for changing a key without decrypting the ciphertext of a symmetric encryption.
[0003] Patent literature 1 describes a ciphertext conversion system comprising a conversion key generation device. The conversion key generation device includes a conversion target setting unit and a conversion key generation unit. The conversion target setting unit generates an attribute-based encryption key and an attribute-based ciphertext, which is encrypted from the attribute-based encryption key according to an attribute-based encryption scheme.The conversion key generation unit generates a conversion key that transforms a first common-key ciphertext into a second common-key ciphertext. This second ciphertext conforms to a first common-key cryptographic scheme but differs from the first. It does this based on initial cryptographic common-key information used in generating the first common-key ciphertext by encrypting a plaintext with a first secret key according to a first common-key cryptographic scheme. The conversion key generation unit then generates a third common-key ciphertext according to a second common-key cryptographic scheme by encrypting a second secret key, used to decrypt the second common-key ciphertext, with the attribute-based encryption key.Patent literature 2 to 4 describes further cryptographic techniques known from the prior art. Reference list: Non-patented literature Non-Patent Literature 1: Z. Yu, MH Au, R. Yang, J. Lai, Q. Xu, “Achieving Flexibility for ABE with Outsourcing via Proxy Re-Encryption,” ASIACCS' 18, June 2018 Non-Patent Literature 2: A. Syalim, T. Nishide, and K. Sakurai, “Realizing Proxy Re-encryption in the Symmetric World,” Communications in Computer and Information Science 251, November 2011 Patent literature Patent literature 1: DE 11 2021 007 337 T5 Patent literature 2: DE 692 30 429 T2 Patent literature 3: DE 600 24 941 T2 Patent literature 4: JP 2008 - 172 736 A Summary of the invention: Technical problem
[0004] A typical proxy re-encryption method, such as the one disclosed in non-patent literature 1, is a technique that transforms a ciphertext of one public-key encryption scheme into another. The technique disclosed in non-patent literature 2 is a technique that transforms a ciphertext of a symmetric encryption scheme into a ciphertext of the symmetric encryption scheme. That is, to transform a ciphertext of a symmetric encryption scheme into a ciphertext of a public-key encryption scheme, it is necessary, using existing techniques, to first decrypt the ciphertext of the symmetric encryption scheme and then to encrypt a decrypted plaintext using the public-key encryption scheme.One problem with existing methods is therefore that plaintext is revealed when the ciphertext of the symmetric encryption scheme is converted into the ciphertext of the public-key encryption scheme, resulting in low security.
[0005] The aim of the present disclosure is to convert a ciphertext encrypted with a symmetric encryption scheme into a ciphertext of a public-key encryption scheme without decryption. Solution to the problem
[0006] A ciphertext conversion system according to the present disclosure comprises a conversion device with a conversion unit to perform encryption of a public-key encryption scheme using a public key and a decryption release condition to generate a converted public-key ciphertext and a key corresponding to the converted public-key ciphertext, and calculated as at least one part of a converted ciphertext is an exclusive OR of a first ciphertext, a value calculated by performing encryption of a symmetric encryption scheme using a secondary secret key that is a random number and a second auxiliary piece of information, and a value calculated by performing encryption of the symmetric encryption scheme using the key corresponding to the converted public-key ciphertext and a third auxiliary piece of information, wherein the first ciphertext is an exclusive OR of a value calculated by performing encryption of the symmetric encryption scheme using a first auxiliary piece of information and a primary secret key that is a random number, a value,which is calculated by performing an encryption of the symmetric encryption scheme using the second auxiliary information and the secondary secret key, and a plaintext. Advantageous effects of the invention
[0007] According to the present disclosure, a first ciphertext, which is a ciphertext encrypted by a symmetric encryption scheme, is transformed using a value calculated by performing encryption of the symmetric encryption scheme using a secondary secret key and auxiliary information, and a second value calculated by performing encryption of the symmetric encryption scheme using a key corresponding to a transformed public-key ciphertext and auxiliary information. The key corresponding to the transformed public-key ciphertext is a key generated by encryption with a public-key encryption scheme.Therefore, according to the present disclosure, a ciphertext encrypted with the symmetric encryption scheme can be converted into a ciphertext of the public-key encryption scheme without decryption. Brief description of the drawings Fig. Figure 1 is an illustration showing an example of a configuration of a ciphertext conversion system 100 according to embodiment 1; Fig. Figure 2 is an illustration showing an example of a configuration of a symmetric secret key generating device 200 according to embodiment 1; Fig. Figure 3 is an illustration showing an example of a configuration of a common parameter generating device 300 according to embodiment 1; Fig. Figure 4 is an illustration showing an example of a configuration of a user secret key generation device 400 according to embodiment 1; Fig. Figure 5 is an illustration showing an example of a configuration of a ciphertext generation device 500 according to embodiment 1; Fig. Figure 6 is an illustration showing an example of a configuration of a conversion device 600 according to embodiment 1; Fig. Figure 1 is an illustration showing an example of a configuration of a decryption device 700 according to embodiment 1; Fig. Figure 8 is an illustration showing an example of a hardware configuration of each of the devices according to embodiment 1; Fig. Figure 9 is a flowchart illustrating the operation of the symmetric secret key generating device 200 according to embodiment 1; Fig. Figure 10 is a flowchart illustrating the operation of the common parameter generating device 300 according to embodiment 1; Fig. Figure 11 is a flowchart illustrating the operation of the user secret key generation device 400 according to embodiment 1; Fig. Figure 12 is a flowchart illustrating the operation of the ciphertext generation device 500 embodiment 1; Fig. Figure 13 is a flowchart illustrating the operation of the conversion device 600 according to embodiment 1; Fig. Figure 14 is a flowchart illustrating the operation of the decryption device 700 according to embodiment 1; and Fig. Figure 15 shows an example of a hardware configuration of each of the devices according to a variant of embodiment 1. Description of embodiments
[0008] In the description and drawings of the embodiments, identical and corresponding elements are designated by the same reference numeral. The description of elements designated by the same reference numeral may be omitted or simplified where appropriate. The arrows in the illustrations primarily indicate data or signal flows or processing flows. "Device" or "unit" may be interpreted as appropriately as "apparatus," "circuit," "equipment," "step," "method," "process," or "circuit." Design 1.*** Configuration Description ***
[0009] In this embodiment, a ciphertext conversion system 100 is disclosed. An overview of this embodiment is described below with reference to the drawings.
[0010] Fig. is a block diagram showing a configuration of the ciphertext conversion system 100 according to this embodiment. As in Fig. As shown in Figure 1, the ciphertext conversion system 100 comprises a plurality of symmetric secret key generation devices 200, a common parameter generation device 300, a plurality of user secret key generation devices 400, a ciphertext generation device 500, a conversion device 600 and a decryption device 700.
[0011] The devices comprising the Ciphertext Conversion System 100 can be installed in a local area network (LAN) or similar within the same company, instead of being connected to each other via the Internet 101 to enable communication. At least two of the devices comprising the Ciphertext Conversion System 100 can be configured as an integral unit, depending on requirements.
[0012] The Internet 101 is a communication channel that connects the multiple Symmetric Secret Key Generation Devices 200, the Common Parameter Generation Device 300, the Multiple User Secret Key Generation Devices 400, the Ciphertext Generation Device 500, the Conversion Device 600, and the Decryption Device 700 to enable communication. The Internet 101 is a specific example of a network. Other types of networks can also be used instead of the Internet 101.
[0013] The Symmetric Secret Key Generation Device 200, for example, is a personal computer (PC), also known as a secret key generation device for symmetric encryption. The Symmetric Secret Key Generation Device 200 is a computer that generates a master secret key sk1 and a secondary secret key sk2, transmits the generated master secret key sk1 to the user secret key generation device 400, and transmits the generated secondary secret key sk2 via the Internet 101 to the conversion device 600. The master secret key sk1 is also referred to as the master secret key for symmetric encryption. The secondary secret key sk2 is also referred to as the secondary secret key for symmetric encryption.
[0014] For example, the Common Parameter Generation Device 300 is a PC that generates common parameters used in the Ciphertext Conversion System 100 and transmits information specifying the generated common parameters to the plurality of User Secret Key Generation Devices 400 and the Conversion Device 600 via the Internet 101. The common parameters include a general secret key msk and a public key pk. The information containing the common parameters can be sent directly to each device by mail or similar means instead of being transmitted via the Internet 101. The terms "data" and "information" can essentially have the same meaning.
[0015] For example, the User Secret Generation Device 400 is a PC. The User Secret Generation Device 400 receives the Master Secret Key sk1 from the Symmetric Secret Generation Device 200, receives the General Secret Key msk from the Common Parameter Generation Device 300, and accepts as input information specifying an attribute parameter Γ. The User Secret Generation Device 400 is a computer that generates a User Secret Key sku based on the received General Secret Key msk and Master Secret Key sk1, as well as the attribute parameter Γ, and transmits the generated User Secret Key sku to the Decryption Device 700.
[0016] The ciphertext generator 500 is a device that functions as a data encryption device, such as a PC, and is also referred to as a symmetric key ciphertext generator. The ciphertext generator 500 receives the primary secret key sk1 and the secondary secret key sk2 from the symmetric key generator 200 and also accepts as input information specifying a plaintext M. The ciphertext generator 500 is a computer that generates a symmetric key ciphertext Csk using the received primary secret key sk1 and secondary secret key sk2 and the plaintext M, and transmits the generated symmetric key ciphertext Csk to the conversion device 600.
[0017] The conversion device 600 is, as a specific example, a PC. The conversion device 600 receives the secondary secret key sk2 from the symmetric secret key generation device 200, receives the public key pk from the common parameter generation device 300, receives the ciphertext of the symmetric key Csk from the ciphertext generation device 500, and accepts as input information specifying a decryption release condition L. The conversion device 600 is a computer that generates a converted symmetric key ciphertext Csk' and a converted public key ciphertext Cpk using the received data and the decryption release condition L, and transmits the generated converted symmetric key ciphertext Csk' and the converted public key ciphertext Cpk to the decryption device 700.
[0018] Decryption Device 700 is, as a specific example, a PC. Decryption Device 700 is a computer that receives the converted symmetric key ciphertext Csk' and the converted public key ciphertext Cpk from Conversion Device 600, also receives the user secret key sku from User Secret Key Generation Device 400, decrypts a ciphertext based on the received data, and outputs a decryption result.
[0019] Fig. Figure 2 is a block diagram showing an example configuration of the Symmetric Secret Key Generating Device 200. As shown in Fig. As shown in Figure 2, the symmetric secret key generation device 200 comprises an input unit 201, a symmetric key encryption generation device 202, and a transmission unit 203. Although not shown, the symmetric secret key generation device 200 includes a recording medium for storing data used in each symmetric secret key generation device 200.
[0020] The input unit 201 accepts the input of information specifying a key bit length k to be used in the ciphertext conversion system 100.
[0021] The symmetric key encryption device 202 generates the primary secret key sk1 and the secondary secret key sk2. The primary secret key sk1 and the secondary secret key sk2 are random numbers and are used as the basis for operations in the ciphertext conversion system 100. Although not shown, the symmetric key encryption device 202 may include a random number generation function or similar to generate the primary secret key sk1 and the secondary secret key sk2.
[0022] The transmission unit 203 transmits the master secret key sk1, generated by the symmetric key encryption device 202, to the user secret key generation device 400 and the ciphertext generation device 500. The transmission unit 203 transmits the secondary secret key sk2, generated by the symmetric key encryption device 202, to the ciphertext generation device 500 and the conversion device 600.
[0023] Fig. Figure 3 is a block diagram showing an example configuration of the Common Parameter Generating Device 300. As shown in Fig. As shown in Figure 3, the common parameter generating unit 300 comprises an input unit 301, a common parameter generating device 302, and a transmission unit 303. Although not shown, the common parameter generating unit 300 includes a recording medium for storing data used in each unit of the common parameter generating unit 300.
[0024] The input unit 301 accepts the input of information specifying the key bit length k to be used in the ciphertext conversion system 100.
[0025] The Common Parameter Generator 302 generates the public key pk and the general secret key msk. The public key pk and the general secret key msk are used as the basis for operations in the Ciphertext Transformation System 100. Although not shown, the Common Parameter Generator 302 may include a random number generator or similar function to generate the public key pk and the general secret key msk.
[0026] The transmission unit 303 transmits the public key pk generated by the common parameter generation unit 302 to the conversion device 600. The transmission unit 303 transmits the master secret key msk generated by the common parameter generation unit 302 to each of the multiple user secret key generation devices 400.
[0027] Fig. Figure 4 is a block diagram showing an example configuration of the User Secret Key Generation Device 400. As shown in Fig. As shown in Figure 4, the User Secret Key Generation Device 400 comprises an input unit 401, a key receiving unit 402, a key generation unit 403, and a transmission unit 404. Although not shown, the User Secret Key Generation Device 400 includes a recording medium for storing data used in each unit of the User Secret Key Generation Device 400.
[0028] The input unit 401 accepts input of information specifying the attribute parameter Γ.
[0029] The key receiving unit 402 receives the general secret key msk and the main secret key sk1.
[0030] The key generation unit 403 generates the user secret key sku = (sk Γ, sk1). Although not shown, the key generation unit 403 may contain a random number generation function or similar to generate the user secret key sku.
[0031] The transmission unit 404 transmits the user secret key sku generated by the key generation unit 403 to the decryption device 700.
[0032] Fig. Figure 5 is a block diagram showing an example configuration of the ciphertext generation device 500. As shown in Fig. As shown in Figure 5, the ciphertext generation device 500 comprises an input unit 501, a key receiving unit 502, an encryption unit 503, and a transmission unit 504. Although not shown, the ciphertext generation device 500 includes a recording medium for storing data used in each unit of the ciphertext generation device 500.
[0033] The input unit 501 accepts the input of information specifying the plaintext M.
[0034] The key receiving unit 502 receives the main secret key sk1 and the secondary secret key sk2.
[0035] The 503 encryption unit generates the symmetric ciphertext Csk. Although not shown, the 503 encryption unit may contain a random number generation function or similar to generate the symmetric key ciphertext Csk.
[0036] The transmission unit 504 transmits the symmetric key ciphertext Csk to the conversion device 600.
[0037] Fig. Figure 6 is a block diagram showing an example of a configuration of the conversion device 600.
[0038] As in Fig. As shown in Figure 6, the conversion device 600 comprises a key receiving unit 601, an input unit 602, a ciphertext receiving unit 603, a conversion unit 604, and a transmission unit 605. Although not shown, the conversion device 600 includes a recording medium for storing data used in each unit of the conversion device 600.
[0039] The key receiving unit 601 receives the public key pk and the secondary secret key sk2.
[0040] The input unit 602 accepts input of information indicating the decryption release condition L from an external source.
[0041] The ciphertext receiver 603 receives the symmetric key ciphertext Csk.
[0042] First, the conversion unit 604 generates the converted public-key ciphertext Cpk using the decryption release condition L and the public key pk. At this point, the conversion unit 604 performs encryption of a public-key cipher scheme using the public key pk and the decryption release condition L to generate a converted public-key ciphertext P and a key K corresponding to the converted public-key ciphertext P.
[0043] Next, the transformation unit 604 transforms the symmetric ciphertext Csk using the secondary secret key sk2 to generate the transformed symmetric-key ciphertext Csk'. At this point, the transformation unit 604 computes, as at least a part of the transformed symmetric-key ciphertext Csk', an exclusive OR of a first ciphertext, a value calculated by encrypting a secondary secret key using the secondary secret key sk2 and secondary auxiliary information, and a value calculated by encrypting the symmetric cipher scheme using the key K, which corresponds to the transformed public-key ciphertext P, and secondary auxiliary information.The first ciphertext is an exclusive OR of a value calculated by performing encryption using the symmetric encryption scheme with the first auxiliary piece of information and the primary secret key sk1, a value calculated by performing encryption using the symmetric encryption scheme with the second auxiliary piece of information and the secondary secret key sk2, and the plaintext M. The transformed symmetric key ciphertext Csk' can be composed of at least one part of the transformed symmetric key ciphertext Csk', the first auxiliary piece of information, and the third auxiliary piece of information. The public-key encryption scheme, for example, is a functional encryption scheme or an attribute-based encryption scheme where an access scope can be defined.
[0044] The transmission unit 605 transmits the converted public-key ciphertext Cpk and the converted symmetric-key ciphertext Csk' to the decryption device 700.
[0045] Fig. Figure 7 is a block diagram showing an example of a configuration of the Decryption Device 700.
[0046] The decryption device 700 comprises a ciphertext receiving unit 701, a key receiving unit 702, a decryption unit 703 and a result output unit 704.
[0047] The ciphertext receiver 701 receives the converted public-key ciphertext Cpk and the converted symmetric-key ciphertext Csk'.
[0048] The key receiving unit 702 receives the user secret key sku.
[0049] The decryption unit 703 performs a decryption procedure to decrypt the plaintext M.
[0050] In particular, the decryption unit 703 first performs the decryption of the attribute-based encryption scheme using the user secret key sk. Γ according to the decryption release condition L and the converted public-key ciphertext Cpk, in order to decrypt the key K according to the converted public-key ciphertext Cpk.
[0051] Next, the decryption unit 703 calculates as plaintext M an exclusive OR of at least one part of the converted symmetric key ciphertext Csk', a value calculated by performing the encryption of the symmetric encryption scheme using the decrypted key K corresponding to the converted public key ciphertext Cpk and the third auxiliary information, and a value calculated by performing the encryption of the symmetric encryption scheme using the main secret key sk1 and the first auxiliary information.
[0052] The output unit 704 outputs the plaintext M decrypted by the decryption unit 703.
[0053] Fig. Figure 8 is an illustration showing an example of the hardware resources of each of the devices according to this embodiment. As shown in Fig. As shown in Figure 8, each of the devices is a general computer containing a processor 11 (CPU - central processing unit).
[0054] As a concrete example, the processor 11 is a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The processor 11 is connected via a bus 12 to hardware devices such as a read-only memory (ROM) 13, a random access memory (RAM) 14, a communication board 15, a display 31 (display device), a keyboard 32, a mouse 33, a drive 34, and a magnetic disk device 20, and controls these hardware devices. The drive 34 is a device that reads from and writes to a storage medium such as a flexible disk drive (FD), a compact disc (CD), and a digital versatile disc (DVD).
[0055] The ROM 13, the RAM 14, the magnetic disk device 20 and the drive 34 are examples of a storage device.
[0056] The keyboard 32, the mouse 33 and the communication board 15 are examples of an input device.
[0057] The display 31 and the communication board 15 are examples of an output device.
[0058] The communication board 15 is connected to a communication network such as a LAN, the Internet or a telephone line, either wired or wirelessly.
[0059] The magnetic disk device 20 stores an operating system (OS) 21, programs 22 and files 23.
[0060] The programs 22 comprise programs that perform functions which, in this embodiment, are referred to as a "unit". The programs are read and executed by the processor 11. That is, the programs cause a computer to function as each "unit" and cause the computer to execute a procedure or method of each "unit".
[0061] The files 23 contain various data (inputs, outputs, determination results, processing results, etc.) that are used in each “unit” described in this embodiment.
[0062] Processes of this embodiment, which are described by means of flowcharts or similar, are carried out using hardware such as the processor 11, the storage device, the input device and the output device.
[0063] What is referred to as a "unit" can be implemented through firmware, software, hardware, or a combination of these elements.
[0064] Any program described in this specification can be recorded on a computer-readable, non-volatile recording medium. The non-volatile recording medium is, as a concrete example, an optical disk or flash memory. Any program described in this specification can be provided as a program product. *** Description of Operating Mode ***
[0065] A method for operating each of the devices that constitute the Ciphertext Conversion System 100 corresponds to a Ciphertext Conversion Method. The Ciphertext Conversion Method is also a generic term for methods that are executed in each of the devices. A program that implements the operation of each of the devices that constitute the Ciphertext Conversion System 100 corresponds to a Ciphertext Conversion Program. The Ciphertext Conversion Program is also a generic term for programs that are executed in each of the devices.
[0066] Before describing the functionality of the Ciphertext Conversion System 100, the basic cryptographic techniques and the notation used in this embodiment will be explained below.
[0067] Attribute-based encryption is an encryption that can only be decrypted by a user who has a user secret key generated with a set of attributes Γ that satisfy a decryption condition defined by the decryption release condition L.
[0068] Method 1: Method that receives the setup ABESETUP, a key length, etc. as input and outputs a general secret key msk and a public key pk.
[0069] Method 2: Method that takes as input the generation of the secret user key ABEKEYGEN, the general secret key msk and the set of attributes Γ and generates a user secret key sk Γ generated, which corresponds to the set of attributes Γ.
[0070] Method 3: Method which receives as input the encryption ABEENC, the public key pk and the decryption release condition L and generates a key K for symmetric encryption and a ciphertext P corresponding to the key K.
[0071] Method 4: Method that takes as input the decryption ABEDEC, the user secret key sk Γ receives the ciphertext P and outputs the key K encrypted as ciphertext P if the set of attributes Γ matches the condition L used for decryption when generating the ciphertext P.
[0072] In common-key encryption, a plaintext M is encrypted with a secret symmetric key sk, and a ciphertext is decrypted with the same secret symmetric key sk. The secret key for symmetric encryption sk is a random value, and the encryption function SKEENC takes the secret key for symmetric encryption sk and the plaintext M as input and outputs the ciphertext. Decryption function SKEDEC takes the secret symmetric key sk and the ciphertext as input and outputs the plaintext M.
[0073] In this embodiment of symmetric encryption, a counter-mode encryption method using a block cipher is employed. In counter-mode, encryption is performed using the SENC encryption function of the symmetric encryption scheme and the auxiliary information auxC, as specified in [Formula 1], and decryption is performed using the SENC encryption function and the auxiliary information auxC, as specified in [Formula 2]. Note that the + operator represents an exclusive OR operation. The auxiliary information is a counter value. C=SENC(sk,auxC)+M M=SENC(sk,auxC)+C
[0074] Fig. Figure 9 shows an example of how to generate a secret key. Based on Fig. Section 9 describes the process of generating a secret key. (Step S201: Information input step)
[0075] The input unit 201 accepts as input information specifying the key bit length k. (Step S202: Step to generate the secret key)
[0076] The symmetric key encryption generating device 202 for symmetric encryption generates two k-bit random numbers and designates one of the generated random numbers as the master secret key sk1 and the other of the generated random numbers as the secondary secret key sk2. (Step S203: Transfer step)
[0077] The transmission unit 203 transmits the main secret key sk1 and the secondary secret key sk2 to each device as needed.
[0078] Fig. Figure 10 shows an example of a parameter generation method. Based on Fig. Section 10 describes the parameter generation process. (Step S301: Information input step)
[0079] The input unit 301 receives as input information specifying the key bit length k. (Step S302: Key generation step)
[0080] The Common Parameter Generating Device 302 performs the setup of attribute-based encryption to generate the master secret key msk and the public key pk. (Step S303: Transfer step)
[0081] The transmission unit 303 transmits the generated general secret key msk and the public key pk to each device as needed.
[0082] Fig. Figure 11 shows an example of generating a user secret key. Fig. Section 11 describes the procedure for generating the user secret key. (Step S401: Attribute Input Step)
[0083] The input unit 401 receives information specifying the attribute parameter Γ. (Step S402: Key input step)
[0084] The key receiving unit 402 receives the general secret key msk and the main secret key sk1. (Step S403: Step to generate the user secret key)
[0085] The key generation unit 403 performs the user key generation ABEKEYGEN of attribute-based encryption using the attribute parameter Γ and the master secret key msk to generate the user secret key skΓ. (Step S404: Transfer step)
[0086] The transmission unit 404 transmits the user secret key sku = (sk Γ , sk1) including the generated user secret key sk Γ to any device, as needed.
[0087] Fig. Figure 12 shows an example of how to generate a ciphertext. Based on Fig. Section 12 describes the process of generating ciphertext. (Step S501: Key Receipt Step)
[0088] The key receiving unit 502 receives the main secret key sk1 and the secondary secret key sk2. (Step S502: Plain text input step)
[0089] The input unit 501 receives information about the plaintext M. (Step S503: Encryption step)
[0090] The encryption device 503 encrypts the plaintext M as specified in [Formula 3]. At this point, the encryption device 503 generates auxiliary information auxC1 and auxiliary information auxC2, each as data of a suitable bit length. The encryption device 503 sets up the ciphertext with symmetric key Csk (C, auxC1, auxC2). Auxiliary information auxC1 is also called the first auxiliary information. Auxiliary information auxC2 is also called the second auxiliary information. C is the first ciphertext and is a ciphertext of the symmetric encryption scheme. SENC(sk1, auxC1) is a value calculated by encryption using the first auxiliary information and the master key sk1 with the symmetric encryption scheme.SENC (sk2, auxC2) is a value calculated by encrypting using the symmetric encryption method with the second auxiliary information and the secondary secret key sk2, a random number. C=SENC(sk1,auxC1)+SENC(sk2,auxC2)+M (Step S504: Transfer step)
[0091] The transmission unit 504 transmits the ciphertext with symmetric key Csk (= (C, auxC1, auxC2)) to each device as required.
[0092] Fig. Figure 13 shows an example of a conversion procedure. Based on Fig. Section 13 describes the conversion process. (Step S601: Key Receipt Step)
[0093] The key receiving unit 601 receives the public key pk and the secondary secret key sk2. (Step 602: Input step)
[0094] The input unit 602 accepts as input information that specifies the decryption release condition L. (Step 603: Step to generate the conversion target)
[0095] The conversion unit 604 performs the ABEENC attribute-based encryption using the public key pk and the decryption release condition L, as specified in [Formula 4]. Note that P is a converted public-key ciphertext, and K is a key corresponding to the converted public-key ciphertext and generated by decrypting P. (K,P)=ABEENC(pk,L) (Step 604: Conversion step for encryption with a shared key)
[0096] The ciphertext receiver 603 receives the symmetric key ciphertext Csk (= (C, auxC1, auxC2)).
[0097] The conversion unit 604 generates the auxiliary information auxC', performs the calculation specified in [Formula 5] using C, the secondary key sk2, the auxiliary information auxC2, the key K, and the generated auxiliary information auxC' to calculate C', and sets the converted ciphertext with symmetric key Csk' to (C', auxC1, auxC'). Note that the right-hand side of [Formula 5] can be converted as specified in [Formula 6]. The auxiliary information auxC' is the third auxiliary information. SENC(sk2, auxC2) is a value calculated by encrypting the symmetric cipher scheme using the secondary key sk2 and the second auxiliary information. SENC (K, auxC') is a value calculated by encrypting the symmetric encryption scheme using the key K, which corresponds to the converted public-key ciphertext, and the third auxiliary information.C' is at least a part of the converted symmetric key ciphertext Csk'. C'=C+SENC(sk2,auxC2)+SENC(K,auxC') C+SENC(sk2,auxC2)+SENC(K,auxC')=SENC(sk1,auxC1)+SENC(K,auxC')+M (Step 605: Transfer step)
[0098] The transmission unit 605 sets the converted public-key ciphertext Cpk to P and transmits the converted public-key ciphertext Cpk and the converted symmetric key ciphertext Csk' to each device as required.
[0099] Fig. Figure 14 shows an example of a decryption process. Based on Fig. The decryption process is described in section 14. (Step S701: Step of ciphertext reception)
[0100] The ciphertext receiver 701 receives the transformed public-key ciphertext Cpk (= P) and the transformed symmetric key ciphertext Csk'. (Step S702: Key input step)
[0101] The key receiving unit 702 receives the secret user key sku (= (sk Γ , sk1)). (Step 703: Step of the decryption process)
[0102] The decryption unit 703 performs the calculation specified in [Formula 7] as the decryption procedure of attribute-based encryption. The key K corresponds to the transformed public-key ciphertext Cpk. SENC(K, auxC') is a value calculated by encryption using the symmetric encryption scheme with the key K and the third auxiliary piece of information. SENC(sk1, auxC1) is a value calculated by encryption using the symmetric encryption scheme with the secret master key sk1 and the first auxiliary piece of information. K=ABEDEC(sk,P)M=C'+SENC(K,auxC')+SENC(sk1,auxC1) (Step 704: Output step)
[0103] The result output unit 704 outputs data indicating the plaintext M obtained through the decryption process. *** Description of the effects of embodiment 1 ***
[0104] As described above, according to this embodiment, a ciphertext of the symmetric encryption scheme can be converted into a ciphertext of the symmetric encryption scheme without being decrypted.
[0105] Furthermore, in this embodiment, it is not necessary to generate a conversion key for each ciphertext to convert a ciphertext of the symmetric encryption scheme into a ciphertext of the public-key encryption scheme. Therefore, according to this embodiment, the cost of generating a conversion key can be reduced, and the number of calls to a secret key for generating a conversion key can also be reduced, thus improving security. *** Other configurations ***<Variante 1>
[0106] Fig. Figure 15 shows an example of a hardware configuration for each of the devices according to this variant.
[0107] Each of the devices contains a processing circuit 18 in place of the processor 11, in place of the processor 11 and the ROM 13, in place of the processor 11 and the RAM 14, or in place of the processor 11, the ROM 13 and the RAM 14.
[0108] The processing circuit 18 is a piece of hardware that implements at least some of the units contained in each of the devices.
[0109] The processing circuit 18 can be dedicated hardware or a processor that executes the programs stored in RAM 14.
[0110] If the processing circuit 18 is dedicated hardware, a specific example of the processing circuit 18 is a single circuit, a composite circuit, a programmed processor, a parallel-programmed processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a combination thereof.
[0111] Each of the devices can contain a plurality of processing circuits as an alternative to processing circuit 18. The plurality of processing circuits share the role of processing circuit 18.
[0112] In each of the devices, some functions can be implemented through special hardware and the remaining functions through software or firmware.
[0113] In a specific example, the processing circuit 18 is implemented by hardware, software, firmware or a combination thereof.
[0114] The processor 11, the ROM 13, the RAM 14, and the processing circuit 18 are collectively referred to as the "processing circuit." This means that the functions of the functional components of the individual devices are implemented by the processing circuits. *** Further examples of implementation ***
[0115] Exemplary embodiment 1 has been described, and parts of this embodiment can be implemented in combination. Alternatively, this embodiment can be partially implemented. Alternatively, this embodiment can be modified in various ways as required and can be implemented wholly or partially in any combination.
[0116] The embodiment described above is a substantially preferred example and is not intended to limit the present disclosure or its applications and scope. The methods described in the flowcharts or similar documents may be modified as needed. Reference symbol list
[0117] 11: Processor; 12: Bus; 13: ROM; 14: RAM; 15: Communication board; 18: Processing circuit; 20: Magnetic disk device; 21: Operating system; 22: Programs; 23: Files; 31: Display; 32: Keyboard; 33: Mouse; 34: Drive; 100: Ciphertext conversion system; 101: Internet; 200: Symmetric secret key generation device; 201: Input device; 202: Symmetric key encryption device; 203: Transmission device; 300: Common parameter generation device; 301: Input device; 302: Common parameter generation device; 303: Transmission device; 400: User secret key generation device; 401: Input device; 402: Key receiving unit; 403: Key generating unit; 404: Transmitting unit; 500: Ciphertext generating unit; 501: Input unit; 502: Key receiving unit; 503: Encryption unit; 504: Transmitting unit; 600: Conversion unit; 601: Key receiving unit; 602: Input unit;603: Ciphertext receiver; 604: Conversion unit; 605: Transmission unit; 700: Decryption unit; 701: Ciphertext receiver; 702: Key receiver; 703: Decryption unit; 704: Result output unit; auxC1, auxC2, auxC': Auxiliary information; Csk: Symmetric key ciphertext; Csk': Converted symmetric key ciphertext; Cpk: Converted public key ciphertext; L: Decryption condition; M: Plaintext; msk: General key; pk: Public key; sk1: Primary key; sk2: Secondary key; sku: User key; skΓ: User key.
Claims
[1] Ciphertext conversion system (100), comprising: a conversion device (600) with a conversion unit (604) to perform a public-key encryption procedure using a public key and a decryption release condition to generate a converted public-key ciphertext and a key corresponding to the converted public-key ciphertext, and a calculation, as at least one part of a converted symmetric-key ciphertext, an exclusive OR of a first ciphertext, a value calculated by performing an encryption of a symmetric encryption procedure using a secondary secret key that is a random number and second auxiliary information, and a value calculated by performing an encryption of the symmetric encryption procedure using the key corresponding to the converted public-key ciphertext and third auxiliary information, wherein the first ciphertext is an exclusive OR of a value calculated by performing an encryption of the symmetric encryption procedure using a first auxiliary information and a primary secret key that is a random number, a value,which is calculated by performing an encryption of the main secret key using the second auxiliary information and the secondary secret key, and a plaintext. [2] Ciphertext conversion system (100) according to claim 1, wherein the converted symmetric key ciphertext is composed of at least one part of the converted symmetric key ciphertext, the first auxiliary information and the third auxiliary information. [3] Ciphertext conversion system (100) according to claim 1 or 2, wherein the public-key encryption method is an attribute-based encryption method. [4] Ciphertext conversion system (100) according to claim 3, wherein the ciphertext conversion system (100) further performs a decryption of the attribute-based encryption scheme using a user secret key that satisfies the decryption release condition and the converted public-key ciphertext in order to decrypt the key that corresponds to the converted public-key ciphertext, and calculated, in plaintext, an exclusive OR of at least one part of the converted symmetric key ciphertext, a value calculated by performing the encryption of the symmetric encryption procedure using the decrypted key corresponding to the converted public key ciphertext and the third auxiliary information, and a value calculated by performing the encryption of the symmetric encryption procedure using the master secret key and the first auxiliary information. [5] Ciphertext conversion methods, including Performing a public-key encryption procedure using a public key and a decryption release condition to generate a transformed public-key ciphertext and a key corresponding to the transformed public-key ciphertext, and Compute, as at least one part of a converted symmetric-key ciphertext, an exclusive OR of a first ciphertext, a value calculated by performing an encryption of a symmetric encryption procedure using a secondary secret key that is a random number and second auxiliary information, and a value calculated by performing an encryption of the symmetric encryption procedure using the key corresponding to the converted public-key ciphertext and third auxiliary information, wherein the first ciphertext is an exclusive OR of a value calculated by performing an encryption of the symmetric encryption procedure using a first auxiliary information and a primary secret key that is a random number, a value,which is calculated by performing an encryption of the main secret key using the second auxiliary information and the secondary secret key, and of a plaintext, by a computer. [6] Ciphertext conversion program that causes a conversion device (600), which is a computer, to execute: a conversion procedure to perform an encryption of a public-key encryption procedure using a public key and a decryption release condition to generate a converted public-key ciphertext and a key corresponding to the converted public-key ciphertext, and a calculation, as at least a part of a converted symmetric key ciphertext, an exclusive OR of a first ciphertext, a value calculated by performing an encryption of a symmetric encryption procedure using a secondary secret key that is a random number, and second auxiliary information, and a value calculated by performing an encryption of the symmetric encryption procedure using the key corresponding to the converted public key ciphertext and third auxiliary information, wherein the first ciphertext is an exclusive OR of a value calculated by performing an encryption of the symmetric encryption procedure using a first auxiliary information and a primary secret key that is a random number, a value,which is calculated by performing an encryption of the main secret key using the second auxiliary information and the secondary secret key, and a plaintext.
Citation Information
Patent Citations
Ciphertext conversion system, conversion key generation method and conversion key generation program
DE112021007337T5
encryption method and device, decryption method and device
DE60024941T2
backup / recovery of the environment of a secret transmission facility and duplication in a public key cryptosystem
DE69230429T2
Ciphertext decryption right transfer system
JP2008172736A
JP002008172736A