Method for decrypting an encrypted secret and associated devices
The method addresses the vulnerability of post-quantum cryptographic mechanisms to side-channel attacks by employing a decryption technique that uses random integers and specific operations on sparse polynomials and syndrome polynomials, achieving robustness and efficient performance.
Patent Information
- Application Number
- FR2023012929
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-23
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2043-11-23
AI Technical Summary
Post-quantum cryptographic mechanisms, such as the BIKE algorithm, are vulnerable to side-channel attacks where an attacker can recover secret information by accessing physical quantities of the system implementing the algorithm.
A method for decrypting a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, which involves generating random integers and applying specific operations to the sparse polynomials and syndrome polynomial to form a modified private key and decipher the syndrome polynomial, thereby deducing the shared secret.
The method provides robustness against side-channel attacks while maintaining efficient implementation performance, preserving the decoding mechanism of the original BIKE algorithm, and ensuring low additional computational load.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for decrypting an encrypted secret and associated devices
[0001] The present invention relates to a method for decrypting a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code. The invention also relates to an associated encryption device, receiver and communication system.
[0002] As part of the preparation for the emergence of quantum computers, many so-called "post-quantum" cryptographic mechanisms are being developed.
[0003] A post-quantum cryptographic mechanism is an algorithm constructed to be more algorithmically robust to the use of a quantum computer compared to a so-called classical algorithm.
[0004] This is particularly the case with the bit-flipping key encapsulation mechanism.
[0005] Such a mechanism is more often referred to as the BIKE algorithm.
[0006] The abbreviation BIKE refers to the corresponding English name of “Bit Flipping Key Encapsulation”.
[0007] However, an attacker may also have access to physical quantities of the physical system implementing such a cryptographic algorithm. Examples of such physical quantities are computation time, the amount of thermal radiation, the amount of electromagnetic radiation and consumption.
[0008] Through this access, the attacker can recover secret information exchanged using the cryptographic mechanism even if the algorithm is not broken in the algorithmic sense of the term.
[0009] Such an attack is called a side channel attack or SCA attack, the abbreviation SCA then referring to the corresponding English term “Side Channel Attack”.
[0010] It is therefore desirable to make post-quantum algorithms insensitive to side-channel attacks.
[0011] To this end, it is possible to apply an approach consisting of breaking down the calculation performed by the post-quantum algorithm into elementary operations. The elementary operations here are additions, multiplications, logical operations “AND”, “OR” and “EXCLUSIVE OR” (more often referred to by the corresponding English names of operations “AND”, “OR” and “XOR”).
[0012] Then, elementary operations are protected by masking techniques. Masked multiplication, masked sum, and masked comparison are examples of masking techniques.
[0013] To ensure good security, such an approach is implemented for each elementary operation, which makes the approach tedious and very impactful on the implementation performance of the algorithm. Typically, the implementation time is 15 to 30 times longer with the use of such an approach.
[0014] There is therefore a need for a method of decrypting a secret encrypted by a post-quantum cryptographic algorithm which is robust to side channel attacks and has a better implementation time.
[0015] For this purpose, the description describes a method for decrypting a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between a transmitter and a receiver, the decryption method being implemented by the receiver and comprising:
[0016] - the reception of a syndrome polynomial deriving from the secret,
[0017] - the generation of random integers,
[0018] - applying a first operation to the first sparse polynomial of the key private, to obtain a first modified sparse polynomial,
[0019] - the application of a second operation on the second sparse polynomial forming the private key, to obtain a second modified sparse polynomial forming with the first modified sparse polynomial, a modified private key,
[0020] - applying a third operation on the syndrome polynomial to obtain a modified syndrome polynomial to decipher,
[0021] - the search for modified error polynomials such as the linear combination of the error polynomials modified by the modified private key gives the modified syndrome polynomial to decrypt, and
[0022] - the deduction of the shared secret by applying a fourth operation on the first modified error polynomial and a fifth operation on the second modified error polynomial,
[0023] the five operations depending on the generated random integers and retaining the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of unneeded coefficients of the polynomial.
[0024] According to particular embodiments, the decryption method has one or more of the following characteristics, taken in isolation or in all technically possible combinations:
[0025] - each of the five operations is the same function parameterized by at least one integer, at least one integer parameterizing the function depending on at least one generated random integer.
[0026] - at least one integer parameterizing the function is specific to each operation.
[0027] - at least two integers parameterizing the function are linear combinations of two randomly generated integers.
[0028] - each of the operations associates with a polynomial P(X), the modified polynomial P(X)*XT modulo XT+1 -1, the polynomial and the modified polynomial having a degree less than or equal to d, r and d being integers.
[0029] - the cryptographic mechanism is a key encapsulation algorithm bit flipping.
[0030] - during the generation step, only three integers are generated
[0031] The description also describes a device for decrypting a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between a transmitter and a receiver of which the decryption device is a part, the receiver being capable of receiving a syndrome polynomial deriving from the secret, the decryption device being capable of:
[0032] - generate random integers,
[0033] - apply a first operation on the first sparse polynomial of the private key, to obtain a first modified sparse polynomial,
[0034] - apply a second operation on the second sparse polynomial forming the key private, to obtain a second modified sparse polynomial forming with the first modified sparse polynomial, a modified private key,
[0035] - apply a third operation on the syndrome polynomial to obtain a modified syndrome polynomial to decipher,
[0036] - search for modified error polynomials such as the linear combination of the error polynomials modified by the modified private key gives the modified syndrome polynomial to decrypt, and
[0037] - deduce shared secret by applying a fourth operation on the first modified error polynomial and a fifth operation on the second modified error polynomial,
[0038] the five operations depending on the generated random integers and retaining the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of unneeded coefficients of the polynomial.
[0039] The description also proposes a receiver capable of receiving a syndrome polynomial deriving from a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between a transmitter and the receiver, the receiver comprising a decryption device.
[0040] The description also proposes a communication system comprising:
[0041] - a transmitter capable of encrypting a secret by a cryptographic mechanism asymmetric key encapsulation based on moderate-density quasi-cyclic parity-check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between the transmitter and a receiver, the transmitter being able to send a syndrome polynomial derived from the secret, and
[0042] - a receiver as previously described.
[0043] In the present description, the expression “suitable for” means indifferently “adapted for”, “adapted to” or “configured for”.
[0044] Characteristics and advantages of the invention will appear on reading the description which follows, given solely by way of non-limiting example, and made with reference to the appended drawings, in which:
[0045] - [Fig.l], [Fig.l] is a schematic representation of a system of communication, and
[0046] - [Fig.2], [Fig.2] is a flowchart of an example implementation of a method of decrypting a secret encrypted by an asymmetric cryptographic mechanism of key encapsulation based on a moderate-density quasi-cyclic parity check correcting code.
[0047] A communication system 10 is shown schematically in [Fig.l].
[0048] The communication system 10 comprises a transmitter 12 and a receiver 14.
[0049] The communication system 10 aims to ensure communication between the transmitter 12 and receiver 14, for example satellite communication.
[0050] The transmitter 12 comprises a transmission antenna 16 and an encryption device 18.
[0051] The transmitting antenna 16 is capable of transmitting information to other antennas.
[0052] The encryption device 18 is capable of encrypting messages by implementing a cryptographic mechanism.
[0053] The cryptographic mechanism is an asymmetric key encapsulation cryptographic algorithm.
[0054] Such a cryptographic mechanism is often referred to as KEM, this abbreviation referring to the corresponding English name of “Key Encapsulation Mechanism”.
[0055] In the present example, the cryptographic mechanism is a post-quantum algorithm, that is to say that it is constructed as being more robust to the use of a quantum computer compared to a so-called classical algorithm.
[0056] More specifically, the cryptographic mechanism is a moderate density quasi-cyclic parity check correcting code-based algorithm.
[0057] Such a correction code is more often referred to as a QC-MDPC correction code. The abbreviation QC-MDPC refers to the corresponding English term for “Quasi-Cyclic Moderate Density Parity Check”.
[0058] According to the example described, the cryptographic mechanism is a key encapsulation algorithm using a bit-flip decoding algorithm (BIKE algorithm as indicated previously).
[0059] The encryption device 18 uses a private key formed by two sparse polynomials denoted hl and h2.
[0060] Each of the sparse polynomials hl and h2 is a polynomial over GF(2).
[0061] GF(2) denotes a Galois field of order 2, that is to say a finite field comprising two elements. The notation ¢2 is sometimes used to designate this body.
[0062] These polynomials hl and h2 are sparse polynomials modulo XT-1.
[0063] A sparse polynomial is a polynomial in which the majority of coefficients are null. As an order of magnitude, for a polynomial of the order of 10,000 coefficients, only a hundred coefficients would be equal to 1.
[0064] T is an integer greater than 10000, so that the polynomials constituting the private and public keys are larger than 10000 bits.
[0065] Preferably, the integer T is chosen to correspond to an AES security level.
[0066] The abbreviation AES here refers to the corresponding English name of “Advanced Encryption Standard” often translated as “advanced encryption standard”.
[0067] As a specific example, an integer T equal to 12323 bits will be chosen for an AES 128 security level, an integer T equal to 24659 bits for an AES 192 security level and an integer T equal to 40973 bits for an AES 256 security level.
[0068] Each sparse polynomial hl and h2 is thus a polynomial with coefficients on {0,1} and having a low weight.
[0069] The weight of a polynomial is the number of unneeded coefficients of the polynomial. A weight is considered low when the weight is greater than or equal to 100 and less than or equal to 300.
[0070] Transmitter 12 shares the private key with receiver 14.
[0071] The receiver 14 comprises a receiving antenna 20 and a decryption device 22.
[0072] The receiving antenna 20 is capable of receiving information from other antennas, and in particular from the transmitting antenna 16.
[0073] The decryption device 22 is an information processing unit formed for example of a memory and a processor associated with the memory.
[0074] The memory of the decryption device 22 is then capable of storing decryption software.
[0075] In a variant not shown, the decryption device 22 is each produced in the form of a programmable logic component, such as an FPGA (Field Programmable Gate Array), or an integrated circuit, such as an ASIC (Application Specific Integrated Circuit).
[0076] When the decryption device 22 is produced in the form of one or more software programs, that is to say in the form of a computer program, also called a computer program product, it is furthermore capable of being recorded on a medium, not shown, readable by a computer. The computer-readable medium is for example a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. By way of example, the readable medium is an optical disk, a magneto-optical disk, a ROM memory, a RAM memory, any type of non-volatile memory (for example FLASH or NVRAM) or a magnetic card. A computer program comprising software instructions is then stored on the readable medium.
[0077] The same remarks apply for the encryption device 18
[0078] The operation of the decryption device 22 is now described in reference to [Fig.2] is a flowchart illustrating an example of implementation of a method for decrypting a secret.
[0079] It is assumed that a private key has been exchanged previously, so that the two sparse polynomials hl and h2 are known to both the encryption device 18 and the decryption device 22.
[0080] Furthermore, the transmitter 12 wishes to exchange a secret with the receiver 14.
[0081] According to the KEM BIKE specification, the encapsulation process consists of randomly generating an error pattern described by a first error polynomial el and a second error polynomial e2, from which a secret session key and an encrypted message sent to the receiver 14 are deduced. This operation described in the BIKE specification involves hash functions.
[0082] The two error polynomials el and e2 are polynomials over GF(2) modulo XT-1.
[0083] From the error polynomials el and e2 and the sparse polynomials hl and h2, the transmitter 12 calculates a syndrome polynomial S according to the following mathematical formula:
[0084] S = e \*h 1+e2*h2
[0085] The decryption method comprises a reception step E30, a generation step E32, a first application step E34, a second application step E36, a third application step E38, a search step E40 and a deduction step E42.
[0086] During the reception step E30, the receiver 14 receives the syndrome polynomial S derived from the secret.
[0087] During the generation step E32, the decryption device 22 generates random integers.
[0088] According to the example described, the decryption device 22 draws three random integers rl, r2 and r3 in the interval [0, ..., Tl].
[0089] The draw is equiprobable here.
[0090] During the first application step E34, the decryption device 22 applies a first operation 01 on the first sparse polynomial hl.
[0091] The result of the first operation 01 is a first modified sparse polynomial hl'. This is written mathematically as:
[0092] hl=Ol(hl)
[0093] In the example described, the first operation 01 is a “cyclic rotation” operation. Such a writing operation:
[0094] P> > >r = P(X)^Xlmodulo XT-1]
[0095] Where: • P denotes a polynomial, • > > > illustrates the cyclic rotation operation, • r denotes an integer parameterizing the operation, • X the variable on which the polynomial depends, and • * denotes multiplication.
[0096] In the case of the first operation 01, the integer parameterizing the operation is (r3-rl) modulo T, so that the first operation 01 is written with the previous notations:
[0097] O\(h\) =hï> > > {(r3-rV)moduloT)
[0098] During the second application step E36, the decryption device 22 applies a second operation 02 on the second sparse polynomial h2.
[0099] The result of the second operation 02 is a second modified sparse polynomial h2'. This is written mathematically as:
[0100] h2=O2(h2)
[0101] The second operation 02 is also a “cyclic rotation” operation, the integer parameterizing the operation being different since it is (r3 + r2) modulo T. The second operation 02 is written as follows with the previous notations:
[0102] O2(h2) = h2> > > ((r3 + r2)modulo T)
[0103] The set of the first modified sparse polynomial hl' and the second modified sparse polynomial h2' forms a modified private key.
[0104] During the third application step E38, the decryption device 22 applies a third operation 03 on the syndrome polynomial S.
[0105] The result of the third operation 03 is a modified syndrome polynomial S'. This is written mathematically as:
[0106] S' = O3(S)
[0107] The third operation 03 is also a “cyclic rotation” operation, the integer parameterizing the operation being different since it is r3. The third operation 03 is written as follows with the previous notations:
[0108] O3(S)=S>>>r3
[0109] The modified syndrome polynomial S' obtained at the end of the third application step E38 is the polynomial to be deciphered.
[0110] For this, during the search step E40, the decryption device 22 searches for a first modified error polynomial el' and a second modified polynomial e2' verifying a condition dependent on the modified syndrome polynomial S'.
[0111] According to the example described, the condition is that the linear combination of the modified error polynomials el' and e2' by the modified private key gives the modified syndrome polynomial S'. This corresponds to the following equation:
[0112] eï*hl+e2*h2 = S'
[0113] The decryption device 22 by solving this equation obtains the first modified error polynomial el' and the second modified polynomial e2'.
[0114] During the deduction step E42, the decryption device 22 deduces the shared secret.
[0115] For this, the decryption device 22 applies a fourth operation 04 on the first modified error polynomial el'.
[0116] The result of this fourth operation 04 is the first error polynomial el, which is written mathematically:
[0117] ¢1 = 04(^)
[0118] The fourth operation 04 is also a “cyclic rotation” operation, the integer parameterizing the operation being different since it is ri. The fourth operation 04 is written as follows with the previous notations:
[0119] 04(^1) = el'> > >rl
[0120] The decryption device 22 also applies a fifth operation 05 on the second modified error polynomial e2'.
[0121] The result of this fifth operation 05 is the second error polynomial e2, which is written mathematically:
[0122] e2 = O5(e2)
[0123] The fifth operation 05 is also a “cyclic rotation” operation, the integer parameterizing the operation being different since it is r2. The fifth operation 05 is written as follows with the previous notations:
[0124] O5(e2) =e2> > >r2
[0125] The decryption device 22 thus recovers the initial error pattern, giving it access to the secret shared between the transmitter 12 and the receiver 14.
[0126] The method implemented by the decryption device 22 randomly changes the representation of the long vectors at the input and output of the decoding algorithm by modifying five operations.
[0127] The decryption method thus constitutes a countermeasure to auxiliary channel attacks implemented on a post-quantum key exchange algorithm (here a BIKE type algorithm).
[0128] The method also allows to keep the same decoding mechanism as in the original BIKE algorithm.
[0129] As a result, the described method preserves performance and interoperability with other implementations of the BIKE algorithm.
[0130] Furthermore, the method does not involve modifying the physical implementation of the BIKE algorithm, the additional computational load being low.
[0131] The method can be implemented for any security level of the BIKE algorithm.
[0132] The method provides the best compromise between good implementation performance and a good level of security.
[0133] In this case, the good level of security corresponds to good resistance to attacks by auxiliary channels.
[0134] Other embodiments are conceivable.
[0135] In particular, the method may use different operations.
[0136] More specifically, each operation depends on at least one generated random integer and retains the weight of the polynomial on which the operation is applied.
[0137] Preferably, as is the case here, each of the five operations is the same function parameterized by at least one randomly generated integer. Cyclic rotation is just one particular example of a function that can be used here.
[0138] In addition, at least one integer parameterizing the function being specific to each operation.
[0139] To improve security, at least two integers parameterizing the function are linear combinations of two generated random integers.
[0140] Furthermore, it is possible to implement the aforementioned steps in a different order or simultaneously, depending on the most favorable implementation in the specific case considered.
Claims
Claims
1. A method of decrypting a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and having been shared between a transmitter (12) and a receiver (14), the decryption method being implemented by the receiver (14) and comprising: - receiving a syndrome polynomial (S) derived from the secret, - generating random integers, - applying a first operation on the first sparse polynomial (hl) of the private key, to obtain a first modified sparse polynomial (hl'), - applying a second operation on the second sparse polynomial (h2) forming the private key, to obtain a second modified sparse polynomial (h2') forming with the first modified sparse polynomial (hl'), a modified private key (hl', h2'),- applying a third operation on the syndrome polynomial (S) to obtain a modified syndrome polynomial (S') to be deciphered, - searching for the modified error polynomials (el', e2') such that the linear combination of the modified error polynomials (el', e2') by the modified private key (hl', h2') gives the modified syndrome polynomial (S') to be deciphered, and - deducing the shared secret by applying a fourth operation on the first modified error polynomial (el') and a fifth operation on the second modified error polynomial (e2'), the five operations depending on the generated random integers and retaining the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of unnullified coefficients of the polynomial.,
2. A decryption method according to claim 1, wherein each of the five operations is the same function parameterized by at least one integer, at least one integer parameterizing the function depending on at least one generated random integer.
3. A decryption method according to claim 2, wherein at least one integer parameterizing the function is specific to each operation.
4. A decryption method according to claim 2 or 3, wherein at least two integers parameterizing the function are linear combinations of two generated random integers.
5. A decryption method according to any one of claims 1 to 4, wherein each of the operations associates with a polynomial P(X), the modified polynomial P(X)*XT modulo XT +1 -1, the polynomial and the modified polynomial having a degree less than or equal to d, r and d being integers.
6. A decryption method according to any one of claims 1 to 5, wherein the cryptographic mechanism is a bit-flipping key encapsulation algorithm.
7. A decryption method according to any one of claims 1 to 6, wherein, in the generating step, only three integers are generated.
8. A device (22) for decrypting a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and having been shared between a transmitter (12) and a receiver (14) of which the decryption device (22) is a part, the receiver (14) being capable of receiving a syndrome polynomial (S) derived from the secret, the decryption device (22) being capable of: - generating random integers, - applying a first operation on the first sparse polynomial (hl) of the private key, to obtain a first modified sparse polynomial (hl'), - applying a second operation on the second sparse polynomial (h2) forming the private key, to obtain a second modified sparse polynomial (h2') forming, with the first modified sparse polynomial (hl'), a private key modified (hl', h2'),- apply a third operation on the syndrome polynomial (S) to obtain a modified syndrome polynomial (S') to decipher, - search for modified error polynomials (el', e2') such as the linear combination of the modified error polynomials (el', e2'), by the modified private key (hl', h2') gives the modified syndrome polynomial (S') to be decrypted, and - deduce shared secret by applying a fourth operation on the first modified error polynomial (el') and a fifth operation on the second modified error polynomial (e2'), the five operations depending on the generated random integers and retaining the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of unnullified coefficients of the polynomial.
9. Receiver (14) suitable for receiving a syndrome polynomial (S) derived from a secret encrypted by an asymmetric cryptographic mechanism for key encapsulation based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and having been shared between a transmitter (12) and the receiver (14), the receiver (14) comprising a decryption device (22) according to claim 8
10. Communication system (10) comprising: - a transmitter (12) capable of encrypting a secret by an asymmetric cryptographic mechanism for encapsulating a key based on a moderate-density quasi-cyclic parity check correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and having been shared between the transmitter (12) and a receiver (14), the transmitter (12) being capable of sending a syndrome polynomial (S) derived from the secret, and - a receiver (14) according to claim 9.