Method for deciphering an encrypted secret and associated devices
A decryption method using cyclic rotation operations on sparse polynomials addresses side-channel vulnerabilities in post-quantum cryptographic algorithms, ensuring security and performance efficiency.
Patent Information
- Application Number
- FR2023012929
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-11-23
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2043-11-23
AI Technical Summary
Existing post-quantum cryptographic algorithms are vulnerable to side-channel attacks, leading to performance degradation due to cumbersome security measures.
A decryption method using a moderate-density quasi-cyclic parity-checking code with sparse polynomials, employing cyclic rotation operations on shared private keys and random integers to protect against side-channel attacks while maintaining performance.
The method provides robust resistance to side-channel attacks with minimal computational overhead, preserving implementation time and interoperability with existing post-quantum algorithms.
Smart Images

Figure 00000014_0000 
Figure 00000015_0000
Abstract
Description
Title of the invention: Method for deciphering an encrypted secret and associated devices
[0001] The present invention relates to a method for decrypting a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate-density quasi-cyclic parity-checking code. The invention also relates to an associated encryption device, receiver, and communication system.
[0002] In preparation for the advent of quantum computers, many cryptographic mechanisms called "post-quantum" are being developed.
[0003] A post-quantum cryptographic mechanism is an algorithm constructed as being more algorithmically robust to the use of a quantum computer compared to a so-called classical algorithm.
[0004] This is particularly the case for the bit-reversal key encapsulation mechanism.
[0005] Such a mechanism is more often referred to as the BIKE algorithm.
[0006] The abbreviation BIKE refers to the corresponding English name "Bit Flipping Key Encapsulation".
[0007] However, an attacker can also gain access to physical quantities of the physical system implementing such a cryptographic algorithm. Computation time, the amount of thermal radiation, the amount of electromagnetic radiation, and power consumption are examples of such physical quantities.
[0008] Through this access, the attacker can recover secret information exchanged by using the cryptographic mechanism even if the algorithm is not broken in the algorithmic sense of the term.
[0009] Such an attack is called a side channel attack or SCA attack, the abbreviation SCA then referring to the corresponding English term "Side Channel Attack".
[0010] It is therefore desirable to make post-quantum algorithms insensitive to side-channel attacks.
[0011] To this end, it is possible to apply an approach consisting of decomposing the calculation performed by the post-quantum algorithm into elementary operations. The elementary operations here are additions, multiplications, and the logical operations "AND", "OR" and "EXCLUSIVE OR" (more often referred to by their corresponding English names of "AND", "OR" and "XOR" operations).
[0012] Then, the elementary operations are protected by masking techniques. A masked multiplication, a masked sum, and a masked comparison are examples of masking techniques.
[0013] To ensure good security, such an approach is implemented for each elementary operation, which makes the approach cumbersome and has a significant impact on the performance of the algorithm's implementation. Typically, the implementation time is 15 to 30 times longer with the use of such an approach.
[0014] There is therefore a need for a method of decrypting a secret encrypted by a post-quantum cryptographic algorithm that is robust to side-channel attacks with better implementation time.
[0015] To this end, the description describes a method for decrypting a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate-density quasi-cyclic parity-checking code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between a sender and a receiver, the decryption method being implemented by the receiver and comprising:
[0016] - the reception of a polynomial syndrome derived from secrecy,
[0017] - the generation of random integers,
[0018] - the application of a first operation on the first sparse polynomial of the key private, to obtain a first modified hollow polynomial,
[0019] - the application of a second operation on the second hollow polynomial forming the private key, to obtain a second modified hollow polynomial forming, with the first modified hollow polynomial, a modified private key,
[0020] - the application of a third operation on the syndrome polynomial to obtain a modified polynomial syndrome to be deciphered
[0021] - the search for modified error polynomials such as the linear combination of Error polynomials modified by the modified private key yield the modified syndrome polynomial to be decrypted, and
[0022] - the deduction of the shared secret by applying a fourth operation on the first modified error polynomial and a fifth operation on the second modified error polynomial,
[0023] the five operations depending on the generated random integers and preserving the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of non-null coefficients of the polynomial.
[0024] According to particular embodiments, the decryption method has one or more of the following characteristics, taken individually or in all technically possible combinations:
[0025] - each of the five operations is the same function parameterized by at least one integer, at least one integer parameterizing the function depending on at least one generated random integer.
[0026] - at least one integer parameterizing the function is specific to each operation.
[0027] - at least two integers parameterizing the function are linear combinations of two random integers generated.
[0028] - each of the operations associates to a polynomial P(X), the modified polynomial P(X)*XT modulo XT+1 -1, the polynomial and the modified polynomial having a degree less than or equal to d, r and d being integers.
[0029] - the cryptographic mechanism is a key encapsulation algorithm bit flip.
[0030] - during the generation step, only three integers are generated
[0031] The description also describes a device for decrypting a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate-density quasi-cyclic parity-checking code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between a sender and a receiver, of which the decryption device is a part, the receiver being suitable for receiving a syndrome polynomial derived from the secret, the decryption device being suitable for:
[0032] - generate random integers,
[0033] - apply a first operation to the first sparse polynomial of the private key, to obtain a first modified hollow polynomial,
[0034] - apply a second operation on the second hollow polynomial forming the key private, to obtain a second modified hollow polynomial which, together with the first modified hollow polynomial, forms a modified private key,
[0035] - apply a third operation on the polynomial syndrome to obtain a modified polynomial syndrome to be deciphered
[0036] - search for modified error polynomials such as the linear combination of Error polynomials modified by the modified private key yield the modified syndrome polynomial to be decrypted, and
[0037] - deduce shared secret by applying a fourth operation to the first modified error polynomial and a fifth operation on the second modified error polynomial,
[0038] the five operations depending on the generated random integers and preserving the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of non-null coefficients of the polynomial.
[0039] The description also proposes a receiver suitable for receiving a syndrome polynomial derived from a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate density quasi-cyclic parity checking corrector code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between a sender and the receiver, the receiver comprising a decryption device.
[0040] The description also proposes a communication system comprising:
[0041] - a transmitter capable of encrypting a secret by means of a cryptographic mechanism asymmetric key encapsulation based on moderate-density quasi-cyclic parity-checking code, the cryptographic mechanism using a private key formed by two sparse polynomials and having been shared between the sender and a receiver, the sender being specific to sending a syndrome polynomial derived from the secret, and
[0042] - a receptor as previously described.
[0043] In this description, the expression "specific to" means interchangeably "suitable for", "adapted to" or "configured for".
[0044] Some features and advantages of the invention will become apparent from the following description, given solely by way of non-limiting example, and made with reference to the accompanying drawings, in which:
[0045] - [Fig. 1], [Fig. 1] is a schematic representation of a system of communication, and
[0046] - [Fig.2], [Fig.2] is a flowchart of an example of an implementation of a method of decrypting a secret encrypted by an asymmetric cryptographic mechanism of key encapsulation based on a moderate density quasi-cyclic parity checking correcting code.
[0047] A communication system 10 is schematically represented in [Fig.1].
[0048] The communication system 10 comprises a transmitter 12 and a receiver 14.
[0049] The communication system 10 aims to ensure communication between the transmitter 12 and receiver 14, for example satellite communication.
[0050] The transmitter 12 includes a transmitting antenna 16 and an encryption device 18.
[0051] The transmitting antenna 16 is suitable for transmitting information to other antennas.
[0052] The encryption device 18 is suitable for encrypting messages by implementing a cryptographic mechanism.
[0053] The cryptographic mechanism is an asymmetric cryptographic key encapsulation algorithm.
[0054] Such a cryptographic mechanism is often referred to as KEM, this abbreviation referring to the corresponding English term "Key Encapsulation Mechanism".
[0055] In the present example, the cryptographic mechanism is a post-quantum algorithm, that is to say, it is constructed as being more robust to the use of a quantum computer compared to a so-called classical algorithm.
[0056] More specifically, the cryptographic mechanism is a moderate-density quasi-cyclic parity-checking code-correcting algorithm.
[0057] Such a correction code is more often referred to as the QC-MDPC correction code. The abbreviation QC-MDPC refers to the corresponding English name "Quasi-Cyclic Moderate Density Parity Check".
[0058] According to the example described, the cryptographic mechanism is a key encapsulation algorithm using a bit-reversal decoding algorithm (BIKE algorithm as previously stated).
[0059] The encryption device 18 uses a private key formed by two sparse polynomials denoted hl and h2.
[0060] Each of the hollow polynomials hl and h2 is a polynomial on GF(2).
[0061] GF(2) denotes a Galois field of order 2, that is to say a finite field comprising two elements. The notation ¢2 is sometimes used to refer to this body.
[0062] These polynomials hl and h2 are hollow polynomials modulo XT-1.
[0063] A sparse polynomial is a polynomial in which the majority of the coefficients are zero. As an order of magnitude, for a polynomial with approximately 10,000 coefficients, only about a hundred coefficients would be equal to 1.
[0064] T is an integer greater than 10000, so the polynomials constituting the private and public keys are of size greater than 10000 bits.
[0065] Preferably, the integer T is chosen to correspond to an AES security level.
[0066] The abbreviation AES here refers to the corresponding English name "Advanced Encryption Standard", often translated as "advanced encryption standard".
[0067] As a specific example, an integer T equal to 12323 bits will be chosen for an AES 128 security level, an integer T equal to 24659 bits for an AES 192 security level and an integer T equal to 40973 bits for an AES 256 security level.
[0068] Each sparse polynomial hl and h2 is thus a polynomial with coefficients on {0,1} and having a low weight.
[0069] The weight of a polynomial is the number of non-null coefficients of the polynomial. A weight is considered low when the weight is greater than or equal to 100 and less than or equal to 300.
[0070] The sender 12 shares the private key with the receiver 14.
[0071] The receiver 14 includes a receiving antenna 20 and a decryption device 22.
[0072] The receiving antenna 20 is suitable for receiving information from other antennas, and in particular from the transmitting antenna 16.
[0073] The decryption device 22 is an information processing unit formed for example of a memory and a processor associated with the memory.
[0074] The memory of the decryption device 22 is then capable of storing decryption software.
[0075] In an alternative not shown, the decryption device 22 is implemented in the form of a programmable logic component, such as an FPGA (Field Programmable Gate Array), or an integrated circuit, such as an ASIC (Application Specified Integrated Circuit).
[0076] When the decryption device 22 is implemented in the form of one or more software programs, i.e., in the form of a computer program, also called a computer program product, it is further capable of being stored on a computer-readable medium, not shown. The computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. By way of example, the readable medium is an optical disc, a magneto-optical disc, ROM, RAM, any type of non-volatile memory (e.g., FLASH or NVRAM), or a magnetic card. A computer program comprising software instructions is then stored on the readable medium.
[0077] The same remarks apply to the encryption device 18
[0078] The operation of the decryption device 22 is now described in reference to [Fig.2] is a flowchart illustrating an example of the implementation of a method for deciphering a secret.
[0079] It is assumed that a private key has been exchanged previously, so that the two hollow polynomials hl and h2 are known to both the encryption device 18 and the decryption device 22.
[0080] Furthermore, the transmitter 12 wishes to exchange a secret with the receiver 14.
[0081] According to the KEM BIKE specification, the encapsulation process consists of randomly generating an error pattern described by a first error polynomial e1 and a second error polynomial e2, from which a secret session key and a ciphertext sent to the receiver 14 are deduced. This operation described in the BIKE specification involves hash functions.
[0082] The two error polynomials el and e2 are polynomials on GF(2) modulo XT-1.
[0083] From the error polynomials e1 and e2 and the sparse polynomials hl and h2, the emitter 12. Calculate a syndrome polynomial S according to the following mathematical formula:
[0084] S = e * h 1+e2 * h2
[0085] The decryption process includes a reception step E30, a generation step E32, a first application step E34, a second application step E36, a third application step E38, a search step E40 and a deduction step E42.
[0086] During the reception step E30, the receptor 14 receives the syndrome S polynomial derived from the secret.
[0087] During the generation step E32, the decryption device 22 generates random integers.
[0088] According to the example described, the decryption device 22 draws three random integers rl, r2 and r3 from the interval [0, ..., Tl].
[0089] The draw is equiprobable here.
[0090] During the first application step E34, the decryption device 22 applies a first operation 01 on the first hollow polynomial hl.
[0091] The result of the first operation 01 is a first modified sparse polynomial hl'. This can be written mathematically as:
[0092] hl=Ol(hl)
[0093] In the example described, the first operation 01 is a "cyclic rotation" operation. Such an operation is written as:
[0094] P> > >r = P(X)^Xlmodulo XT-1]
[0095] Where: • P denotes a polynomial, • > > > illustrates the cyclic rotation operation, • r denotes an integer parameterizing the operation, • X is the variable on which the polynomial depends, and • * denotes multiplication.
[0096] In the case of the first operation 01, the integer parameterizing the operation is (r3-rl) modulo T, so that the first operation 01 can be written with the previous notations:
[0097] O\(h\) =hï> > > {(r3-rV)moduloT)
[0098] During the second application step E36, the decryption device 22 applies a second operation 02 on the second hollow polynomial h2.
[0099] The result of the second operation 02 is a second modified sparse polynomial h2'. This can be written mathematically as:
[0100] h2=O2(h2)
[0101] The second operation 02 is also a "cyclic rotation" operation, the integer parameterizing the operation being different since it is (r3 + r2) modulo T. The second operation 02 is written as follows with the previous notation:
[0102] O2(h2) = h2> > > ((r3 + r2)modulo T)
[0103] The set of the first modified hollow polynomial hl' and the second modified hollow polynomial h2' forms a modified private key.
[0104] During the third application step E38, the decryption device 22 applies a third operation 03 on the syndrome polynomial S.
[0105] The result of the third operation 03 is a modified syndrome polynomial S'. This can be written mathematically as:
[0106] S' = O3(S)
[0107] The third operation 03 is also a "cyclic rotation" operation, the integer parameterizing the operation being different since it is r3. The third operation 03 is written as follows with the previous notation:
[0108] O3(S)=S>>>r3
[0109] The modified syndrome polynomial S' obtained at the end of the third application step E38 is the polynomial to be deciphered.
[0110] For this purpose, during the search step E40, the decryption device 22 searches for a first modified error polynomial el' and a second modified polynomial e2' satisfying a condition depending on the modified syndrome polynomial S'.
[0111] According to the example described, the condition is that the linear combination of the modified error polynomials el' and e2' by the modified private key gives the modified syndrome polynomial S'. This corresponds to the following equation:
[0112] eï*hl+e2*h2 = S'
[0113] The decryption device 22, by solving this equation, obtains the first modified error polynomial el' and the second modified polynomial e2'.
[0114] During the deduction step E42, the decryption device 22 deduces the shared secret.
[0115] For this purpose, the decryption device 22 applies a fourth operation 04 on the first modified error polynomial el'.
[0116] The result of this fourth operation 04 is the first error polynomial el, which can be written mathematically as:
[0117] ¢1 = 04(^)
[0118] The fourth operation 04 is also a "cyclic rotation" operation, the integer parameterizing the operation being different since it is ri. The fourth operation 04 is written as follows using the previous notation:
[0119] 04(^1) = el'> > >rl
[0120] The decryption device 22 also applies a fifth operation 05 on the second modified error polynomial e2'.
[0121] The result of this fifth operation 05 is the second error polynomial e2, which can be written mathematically as:
[0122] e2 = O5(e2)
[0123] The fifth operation 05 is also a "cyclic rotation" operation, the integer parameterizing the operation being different since it is r2. The fifth operation 05 is written as follows with the previous notation:
[0124] O5(e2) =e2> > >r2
[0125] The decryption device 22 thus recovers the initial error pattern, giving it access to the secret shared between the sender 12 and the receiver 14.
[0126] The process implemented by the decryption device 22 randomly changes the representation of the long input and output vectors of the decoding algorithm by modifying five operations.
[0127] The decryption process thus constitutes a countermeasure to side-channel attacks implemented on a post-quantum key exchange algorithm (here a BIKE-type algorithm).
[0128] The process also allows the same decoding mechanism to be retained as in the original BIKE algorithm.
[0129] It follows that the described process preserves performance and interoperability with other implementations of the BIKE algorithm.
[0130] Moreover, the process does not involve modifying the physical implementation of the BIKE algorithm, the additional computational load being low.
[0131] The method can be implemented for any security level of the BIKE algorithm.
[0132] The process provides the best compromise between good implementation performance and a good level of safety.
[0133] In this case, the right level of security corresponds to good resistance to side-channel attacks.
[0134] Other embodiments are conceivable.
[0135] In particular, the process can use different operations.
[0136] More specifically, each operation depends on at least one generated random integer and retains the weight of the polynomial on which the operation is applied.
[0137] Preferably, as is the case here, each of the five operations is the same function parameterized by at least one randomly generated integer. Cyclic rotation is just one particular example of a function that can be used here.
[0138] In addition, at least one integer parameterizing the function being specific to each operation.
[0139] To improve security, at least two integers parameterizing the function are linear combinations of two generated random integers.
[0140] Furthermore, it is possible to implement the aforementioned steps in a different order or simultaneously, depending on the most favorable implementation in the specific case under consideration.
Claims
Demands
1. A method for decrypting a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate-density quasi-cyclic parity-checking code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) known to the receiver (14), the decryption method being implemented by the receiver (14) and comprising: - receiving a syndrome polynomial (S) derived from the secret, - generating random integers, - applying a first operation on the first sparse polynomial (hl) of the private key, to obtain a first modified sparse polynomial (hl'), - applying a second operation on the second sparse polynomial (h2) forming the private key, to obtain a second modified sparse polynomial (h2') which, together with the first modified sparse polynomial (hl'), forms a modified private key (hl', h2').- the application of a third operation on the syndrome polynomial (S) to obtain a modified syndrome polynomial (S') to be deciphered, - the search for modified error polynomials (el', e2') such that the linear combination of the modified error polynomials (el', e2') by the modified private key (hl', h2') gives the modified syndrome polynomial (S') to be deciphered, and - the deduction of the shared secret by applying a fourth operation on the first modified error polynomial (el') whose result is a first error polynomial (el) and a fifth operation on the second modified error polynomial (e2') whose result is a second error polynomial (e2), the five operations depending on the generated random integers and preserving the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of non-null coefficients of the polynomial.
2. A decryption method according to claim 1, wherein each of the five operations is the same function parameterized by at least one integer, at least one integer parameterizing the function depending on at least one generated random integer.
3. A decryption method according to claim 2, wherein at least one integer parameterizing the function is specific to each operation.
4. A decryption method according to claim 2 or 3, wherein at least two integers parameterizing the function are linear combinations of two generated random integers.
5. A decryption method according to any one of claims 1 to 4, wherein each of the operations associates to a polynomial P(X), the modified polynomial P(X)*Xr modulo XT +1 -1, the polynomial and the modified polynomial having a degree less than or equal to T, r and T being integers.
6. A decryption method according to any one of claims 1 to 5, wherein the cryptographic mechanism is a bit-reversal key encapsulation algorithm.
7. A decryption method according to any one of claims 1 to 6, wherein, during the generation step, only three integers are generated.
8. A decryption device (22) for a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate-density quasi-cyclic parity-checking code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and known to a receiver (14) of which the decryption device (22) is a part, the receiver (14) being suitable for receiving a syndrome polynomial (S) derived from the secret, the decryption device (22) being suitable for: - generating random integers, - applying a first operation on the first sparse polynomial (hl) of the private key, to obtain a first modified sparse polynomial (hl'), - applying a second operation on the second sparse polynomial (h2) forming the private key, to obtain a second modified sparse polynomial (h2') which, together with the first modified sparse polynomial (hl'), forms a modified private key (hl', h2').- apply a third operation on the syndrome polynomial (S) to obtain a modified syndrome polynomial (S') to be deciphered, - search for modified error polynomials (el', e2') such that the linear combination of the modified error polynomials (el', e2'), by the modified private key (hl', h2') gives the modified syndrome polynomial (S') to be deciphered, and - deduce shared secret by applying a fourth operation on the first modified error polynomial (e1') whose result is a first error polynomial (el) and a fifth operation on the second modified error polynomial (e2') whose result is a second error polynomial (e2), the five operations depending on the generated random integers and preserving the weight of the polynomial on which the operation is applied, the weight of a polynomial being the number of non-null coefficients of the polynomial.
9. A receiver (14) adapted to receive a syndrome polynomial (S) derived from a secret encrypted by an asymmetric cryptographic key encapsulation mechanism based on a moderate-density quasi-cyclic parity-checking code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and being known to the receiver (14), the receiver (14) comprising a decryption device (22) according to claim 8
10. Communication system (10) comprising: - a transmitter (12) suitable for encrypting a secret by means of an asymmetric cryptographic key encapsulation mechanism based on a moderate density quasi-cyclic parity checking correcting code, the cryptographic mechanism using a private key formed by two sparse polynomials (hl, h2) and being known to a receiver (14), the transmitter (12) being suitable for sending a syndrome polynomial (S) derived from the secret, and - a receiver (14) according to claim 9.