Method and system for compression encryption
By reusing encryption parameters and employing sanitization schemes, the method enhances encryption efficiency and resilience against quantum computers, addressing inefficiencies in current encryption methods.
Patent Information
- Application Number
- JP2025091910
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2020-04-08
- Filing Date
- 2025-06-02
- Publication Date
- 2025-09-09
AI Technical Summary
Current encryption methods lack resilience against quantum computers and are inefficient in terms of size and communication requirements, necessitating the development of new encryption schemes that are both robust and efficient.
A method involving parameter reuse and sanitization or erasure signature schemes is employed to reduce the data sent during encrypted message transmission, utilizing a common set of system parameters and unique user parameters for efficient encryption and decryption processes.
This approach significantly reduces data transmission size and improves organizational hierarchy, leading to efficiency gains and enhanced performance in sending multiple encryption methods, particularly when combined with lattice-based and isogeny-based encryption schemes.
Smart Images

Figure 2025131667000001_ABST
Abstract
Description
[Background technology]
[0001] background
[0001] The imminent arrival of practical large-scale quantum computing brings with it several security challenges, not the least of which is the lack of resilience of currently used encryption methods to attacks based on quantum computers. Thus, while new encryption methods are being developed, they tend to lack the maturity and depth of more established methods, including their size and communication requirements. Summary of the Invention [Means for solving the problem]
[0002] overview
[0002] In one aspect, the present disclosure provides a method for reducing the size of encrypted updates and other encrypted messages generated using both pre-quantum and post-quantum encryption schemes. By reusing at least some of the parameters used in the encryption process, one copy of those parameters can be sent with the encryption, reducing the amount of data sent. Because one copy can be used instead of one per message, significant efficiency gains can be realized. This reuse also allows for a more favorable organizational hierarchy to be used, which can improve performance when sending multiple encryption methods when compared to non-reuse schemes. Combining parameter reuse with a sanitization or erasure signature scheme can lead to a significant reduction in the data sent at the server side during the transmission of encrypted messages, leading to efficiency gains.
[0003]
[0003] In another aspect, the present disclosure provides a method for transmitting a ciphertext including multiple encrypted portions to multiple users, the method including: (a) providing a common set of system parameters for the multiple users; (b) generating the multiple encrypted portions by encrypting plaintext using parameters unique to each of the multiple users; (c) generating a ciphertext including a portion derived from the common set of system parameters and the multiple encrypted portions; and (d) transmitting the ciphertext to the multiple users, wherein the ciphertext is at least partially decodable using parameters unique to each of the multiple users.
[0004] In some embodiments, the encrypted portion is encrypted using a lattice-based encryption scheme. In some embodiments, the encrypted portion is encrypted using an isogeny-based encryption scheme. In some embodiments, the common set of system parameters is generated using a seed and a pseudorandom number generator. In some embodiments, at least the parameters unique to each user of the multiple users are generated using a seed and a pseudorandom number generator. In some embodiments, the common set of system parameters or the parameters unique to each user of the multiple users comprises a non-square matrix.
[0005]
[0005] In another aspect, the present disclosure provides a method for transmitting a ciphertext to a plurality of users, the method including: (a) generating a system parameter set, the parameter set including parameters independent of public keys of users of the plurality of users; (b) generating a fixed component based at least in part on the system parameter set; (c) generating a plurality of variable components by encrypting a plaintext using each of the public keys of the plurality of users; and (d) transmitting the ciphertext including the fixed component and the variable component to the plurality of users, the ciphertext being decodable at least in part using the fixed component.
[0006] In some embodiments, the encryption is based on an encryption scheme selected from the group consisting of Lindner-Peickert scheme, hypersingular isogenous Diffie-Hellman protocol, and isogenous-based public key encryption schemes.
[0007]
[0007] In another aspect, the present disclosure provides a method for organizing a database, the method including (a) structuring a plurality of recipients in a tree structure with m terms, where "m" is at least 2, and (b) sending compressed ciphertext updates to less than all of the plurality of recipients.
[0008] In some embodiments, the number of terms m is at least about 8. In some embodiments, the number of terms m is between about 8 and about 16. In some embodiments, the number of bytes used for sending is about half or less the number of bytes for sending the update to each of the multiple recipients. In some embodiments, the condensed ciphertext update is encrypted using a lattice-based encryption scheme. In some embodiments, the condensed ciphertext update is encrypted using an isogeny-based encryption scheme. In some embodiments, sending includes sending the same message to each node of the tree structure. In some embodiments, the same message includes updates to the encryption keys of users of the database. In another aspect, the present disclosure provides a method for performing an encryption update including multiple encryption keys and multi-ciphertexts on multiple recipient nodes, the method including: (a) receiving the encryption update; (b) generating a reduced encryption update by removing one or more of the multiple encryption keys and one or more ciphertexts of the multi-ciphertexts; (c) transmitting the reduced encryption update to a recipient node of the multiple recipient nodes; and (d) repeating (b)-(c) for one or more other nodes of the multiple nodes. In some embodiments, each node receives the reduced encryption update including one encryption key of the multiple encryption keys and one ciphertext of the multi-ciphertexts. In some embodiments, each node of the multiple nodes receives the reduced encryption update including a different encryption key of the multiple encryption keys and a different ciphertext of the multi-ciphertexts from each other node of the multiple nodes. In some embodiments, the recipient node has child nodes. In some embodiments, the child nodes have access to the decryption keys of each recipient node in the child node's path. In some embodiments, (d) is performed substantially concurrently with each node of the multiple nodes. In some embodiments, the method further includes reducing the number of bytes sent to the plurality of nodes by a factor of about n or more, where n is the number of nodes in the plurality of nodes. In some embodiments, the one or more ciphertexts are encrypted using a lattice-based encryption scheme.In some embodiments, the one or more ciphertexts are encrypted using an isogeny-based encryption scheme. In some embodiments, the encrypted updates are signed using a black signature. In some embodiments, the black signature facilitates removing one or more of the multiple encryption keys and the multiple multi-ciphertexts.
[0009]
[0009] Another aspect of the present disclosure provides a non-transitory computer-readable medium containing machine-executable code that, when executed by one or more computer processors, performs any of the above methods or methods elsewhere in this specification.
[0010] Another aspect of the present disclosure provides a system including one or more computer processors and a computer memory coupled thereto, the computer memory including machine-executable code that, when executed by the one or more computer processors, performs any of the methods described above or elsewhere herein.
[0011]
[0011] Additional aspects and advantages of the present disclosure will become readily apparent to those skilled in the art from the following detailed description, in which merely exemplary embodiments of the present disclosure are shown and described. As will be recognized, the present disclosure is capable of other and different embodiments, and its several details are capable of modifications in various obvious respects, all without departing from the present disclosure. Accordingly, the drawings and description are to be regarded as illustrative in nature, and not as limiting.
[0012] Incorporation by Reference
[0012] All publications, patents, and patent applications cited herein are incorporated by reference to the same extent as if each individual publication, patent, or patent application was specifically and individually indicated to be incorporated by reference. To the extent that the publications and patents or patent applications incorporated by reference conflict with the disclosure contained herein, it is intended that the present specification supersede and / or take precedence over any such conflicting material.
[0013] BRIEF DESCRIPTION OF THE DRAWINGS The novel features of the invention are set forth with particularity in the appended claims. A better understanding of the features and advantages of the present invention will be obtained by reference to the following detailed description that sets forth illustrative embodiments, in which the principles of the invention are utilized, and the accompanying drawings (also referred to herein as "Figure" and "FIG."). [Brief explanation of the drawings]
[0014] [Figure 1] 1 is a flowchart of an example process for transmitting multiple ciphertexts to multiple users. [Figure 2]
[0015] 1 is a flowchart of an example process for transmitting multiple ciphertexts to multiple users. [Figure 3]
[0016] 10 is a flowchart of an example process for performing a cryptographic update involving multiple cryptographic keys and multiple multi-ciphertexts for multiple recipient nodes. [Figure 4A]
[0017] An example of the Lindner-Peikert framework is shown below. [Figure 4B]
[0017] An example of the Lindner-Peikert framework is given below. [Figure 4C]
[0017] An example of the Lindner-Peikert framework is given below. [Figure 4D]
[0018] 1 shows example pseudo-code for one implementation of ciphertext compression of a single message sent to one or more recipients. [Figure 5A]
[0019] 1 shows example pseudo-code for one implementation of ciphertext compression of one or more messages sent to one or more recipients. [Figure 5B]
[0020] 1 shows a pseudo-code example of one implementation of the SIKE public key encryption scheme. [Figure 5C]
[0020] A pseudo-code example of one implementation of the SIKE public key encryption scheme is shown below. [Figure 5D]
[0020] A pseudo-code example of one implementation of the SIKE public key encryption scheme is shown below. [Figure 6A]
[0021] 1 shows a pseudo-code example of one implementation of SIKE public key encryption ciphertext compression for a message sent to one or more recipients. [Figure 6B]
[0022] 1 shows a pseudo-code example of one implementation of SIKE public key encryption ciphertext compression of one or more messages sent to one or more recipients. [Figure 7A]
[0023] Plots of update sizes in several different scenarios using the Kyber512 key encapsulation mechanism. [Figure 7B]
[0024] 1 shows plots of update sizes in several different situations using the Frodo KEM-640 key encapsulation mechanism. [Figure 7C]
[0025] 1 shows plots of update sizes in several different situations using the SIKE / p434 key encapsulation mechanism. [Figure 8]
[0026] 1 shows a table of efficiency improvements using ciphertext compression methods and systems with various encryption schemes. [Figure 9]
[0027] An example of a supersingular homogeneous Diffie-Hellman key exchange (SIDH) is shown below. [Figure 10A]
[0028] 1 illustrates several protocols that can be used in conjunction with ciphertext compression. [Figure 10B]
[0028] Several protocols that can be used in conjunction with ciphertext compression are presented. [Figure 10C]
[0028] Several protocols that can be used in conjunction with ciphertext compression are presented. [Figure 10D]
[0028] Several protocols that can be used in conjunction with ciphertext compression are presented. [Figure 10E]
[0028] Several protocols that can be used in conjunction with ciphertext compression are presented. [Figure 11]
[0029] 1 illustrates a computer system programmed or otherwise configured to perform the methods provided herein. [Figure 12A]
[0030] 1 shows example pseudocode for one implementation of the commutative supersingular isogenous Diffie-Hellman key exchange (cSIDH) public key encryption scheme. [Figure 12B]
[0030] A pseudo-code example of one implementation of the commutative hypersingular isogenous Diffie-Hellman key exchange (cSIDH) public key encryption scheme is shown below. [Figure 12C]
[0030] A pseudo-code example of one implementation of the commutative hypersingular isogenous Diffie-Hellman key exchange (cSIDH) public key encryption scheme is shown below. [Figure 12D]
[0030] A pseudo-code example of one implementation of the commutative hypersingular isogenous Diffie-Hellman key exchange (cSIDH) public key encryption scheme is shown below. [Figure 12D]
[0031] 1 shows example pseudo-code for one implementation of ciphertext compression of a single message sent to one or more recipients. DETAILED DESCRIPTION OF THE INVENTION
[0015] Detailed Description
[0032] While various embodiments of the present invention have been shown and described herein, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Many variations, changes, and substitutions may occur to those skilled in the art without departing from the invention. It is understood that various alternatives to the embodiments of the invention described herein may be employed.
[0016]
[0033] Whenever the terms "at least," "greater than," or "greater than or equal to" precede the first number in a series of two or more numbers, the terms "at least," "greater than," or "greater than or equal to" apply to every number in the series. For example, 1, 2, 3 or more is equivalent to 1 or more, 2 or more, or 3 or more.
[0017]
[0034] Whenever the terms "not greater than," "less than," or "less than or equal to" precede the first number in a series of two or more numbers, the terms "not greater than," "less than," or "less than or equal to" apply to each number in the series. For example, 3, 2, or 1 or less is equivalent to 3 or less, 2 or less, or 1 or less.
[0018]
[0035] As used herein, the term "ciphertext" generally refers to encrypted text. Encryption can be encryption performed by an algorithm. Text can be numbers (e.g., binary representation), letters, words, etc., or any combination thereof. Ciphertext can be encrypted plaintext. Ciphertext can be an encrypted message. Multi-ciphertext can be one or more ciphertexts in the same package.
[0019]
[0036] As used herein, the term "public key" generally refers to a cryptographic key used for encryption. A public key does not have to be kept secret. A public key is accessible by a user (e.g., a user sending a message), a service (e.g., software running on a suitably configured computer), or any other sender / receiver of an encrypted object. A public key can be used to encrypt plaintext into ciphertext. For example, user Alice can encrypt plaintext using user Bob's public key, and the ciphertext can only be decrypted by Bob.
[0020]
[0037] As used herein, the term "private key" generally refers to a cryptographic key used for decryption. A private key may be kept secret from a user (e.g., a user sending a message), a service (e.g., software running on a suitably configured computer), or any other sender / receiver of an encrypted object. A private key may be used to decrypt ciphertext into plaintext.
[0021]
[0038] As used herein, the term "cryptography scheme" generally refers to a method of encryption and decryption. An encryption scheme may be a lattice-based scheme. Examples of encryption schemes may be public key encryption, symmetric key encryption (e.g., Advanced Encryption Standard (AES)), Round5, Saber, NewHope, Kyber, FrodoKEM, and hypersingular isogenous map key encapsulation. An encryption scheme may be a key encapsulation mechanism (KEM). An encryption scheme may be a code-based encryption scheme. Examples of code-based encryption schemes may be BIKE-3, ROLLO-3, HQC, RQC, etc. Other examples of lattice-based, code-based, or other encryption schemes can be found in the National Institutes for Standards and Testing (NIST) Post-Quantum Cryptography project files, such as "Status Report on the First Round of the NIST Post-Quantum Cryptography Standardization Process" by Alagic et al., published January 31, 2019 (DOI: 10.6028 / NIST.IR.8240), which is incorporated herein by reference in its entirety. The encryption scheme can be public key encryption (PKE).
[0022]
[0039] Multi-ciphertexts may be used in implementing ciphertext compression schemes. For example, using multi-ciphertexts to reduce the amount of data transmitted during a key exchange may be ciphertext compression. Accordingly, these terms may be relevant throughout this disclosure. Multi-ciphertexts may include multiple ciphertexts.
[0023]
[0040] The present disclosure provides a method and system for transmitting a ciphertext including multiple encrypted portions to multiple users. The method for transmitting a ciphertext including multiple encrypted portions to multiple users may include providing a common set of system parameters for the multiple users. The multiple encrypted portions may be generated by encrypting plaintext using parameters unique to each of the multiple users. The ciphertext including the multiple encrypted portions and portions derived from the common set of system parameters may be transmitted to the multiple users. The multiple ciphertext may be at least partially decodable using parameters unique to each of the multiple users.
[0024]
[0041] 1 shows a flowchart of an example process 100 for transmitting multiple ciphertexts to multiple users. At operation 110, process 100 may include providing a common set of system parameters to the multiple users. The multiple ciphertexts may be at least about 2, 3, 4, 5, 6, 7, 8, 9, 10, 50, 100, 250, 500, 1,000, 5,000, 10,000, 50,000, 100,000, 500,000, 1,000,000, or greater than 1,000,000 ciphertexts. The plurality of ciphertexts may be up to approximately 1,000,000, 500,000, 100,000, 50,000, 10,000, 5,000, 1,000, 500, 250, 100, 50, 10, 9, 8, 7, 6, 5, 4, 3, 2, or less than 2 ciphertexts. The number of users in the plurality of users may be greater than, equal to, or less than the number of ciphertexts in the plurality of ciphertexts. For example, 500 ciphertexts may be generated to be sent to 1,000 users. The plurality of users may be, for example, server clients (e.g., client devices receiving updates from a server, intermediate servers receiving updates and passing them on to other clients, etc.), messaging recipients, website visitors, systems receiving software updates, etc. Messaging recipients may be recipients of digital messages (e.g., email, short message service (SMS), multimedia messaging service (MMS)). The system receiving the software update may be a server device (e.g., a computing cluster), an end-user device (e.g., a laptop computer, a desktop computer, a smartphone, a tablet), etc. For example, a central server may output updates that are received by multiple server nodes. In another example, a desktop computer may output peer-to-peer updates to another desktop computer. The ciphertext may be a lattice-based encryption scheme, an isogeny-based encryption scheme (e.g., a supersingular isogeny-based encryption scheme), a prime factorization-based encryption scheme, another encryption scheme described elsewhere herein, etc. The encryption scheme may be a post-quantum encryption scheme (e.g., a scheme that is more robust to attacks by non-classical computers).The encryption scheme may be a pre-quantum encryption scheme (e.g., a currently employed encryption scheme). The encryption scheme may operate at a chosen ciphertext attack (CCA) security level. The encryption scheme may operate at a chosen plaintext attack (CPA) security level.
[0025]
[0042] The common set of system parameters may be independent of the public keys of users among the multiple users. For example, the common set of system parameters may be common to each user among the multiple users. The common set of system parameters may be related to the type of encryption scheme used to generate the ciphertext. For example, in an isogeny-based encryption method, the common set of system parameters may be large integers. In another example, the common set of system parameters may be one or more matrices including numbers or polynomials. The common set of system parameters may provide a detailed description of an instance of an encryption scheme. For example, the common set of system parameters for a lattice-based encryption scheme may be different from the common set of parameters for an encryption scheme based on prime factorization. In another example, the system parameters may be an instance of an encryption scheme used as a template. At least one parameter of the common set of system parameters may be generated using a seed and a pseudorandom number generator. For example, a message to be encrypted as the ciphertext may be converted into a numeric seed and fed to a pseudorandom number generator to generate the system parameters. The common set of system parameters may be compressed. The compression may be lossy or lossless. For example, the size of one or more parameters may be reduced by dropping less significant bits. The common set of system parameters may be denoted as A elsewhere in this specification.
[0026]
[0043] In another operation 120, the process 100 may include generating multiple encrypted portions by encrypting the plaintext using parameters unique to each of the multiple users. The parameters unique to each of the multiple users may include one or more public keys. For example, user Alice can encrypt a message to user Bob using Bob's public key, and the ciphertext sent from Alice to Bob includes the encrypted message. The public key may include one or more encryption keys, one or more verification keys, one or more identification numbers, etc., or any combination thereof. The ciphertext may include a fixed portion and a variable portion. The fixed portion may depend on a common set of system parameters. The fixed portion may be the same for each of the multiple users. The fixed portion may be referred to elsewhere herein as U. The variable portion may depend on the common set of system parameters and parameters unique to each of the multiple users (e.g., the public key of each of the multiple users). The variable portion may be referred to elsewhere herein as V. At least one of the parameters unique to each of the multiple users may be generated using a seed and a pseudorandom number generator. For example, a seed including the user's public key may be input into a pseudorandom number generator to generate the user's unique parameter. In another example, the seed may be input into a pseudorandom number generator to generate the user's public key. The common set of system parameters may include one or more non-square matrices. The parameters unique to each of the multiple users may include one or more non-square matrices. The non-square matrices may include numbers, polynomials, other equations, etc. Encrypting may be by an encryption scheme described elsewhere herein. The parameters unique to each of the multiple users may be referred to as a public key elsewhere herein.
[0027]
[0044] In another operation 130, the process 100 may include generating a ciphertext including a portion derived from a common set of system parameters and multiple encrypted portions. In another operation 140, the process 100 may include transmitting the ciphertext to multiple users. The multiple ciphertexts may be decodable, at least in part, using parameters unique to each of the multiple users. The multiple ciphertexts may be combined into a single multi-ciphertext. For example, a single transmission may include multiple ciphertexts. The transmission may be via a communications protocol (e.g., Internet Protocol (IP), Transmission Control Protocol (TCP), Hypertext Transfer Protocol (HTTP) or its secure variant (HTTPS), etc.). The transmission may be in a manner such as shown in any of FIGS. 10A-10E. The transmission may include transmitting the common set of system parameters and the multiple ciphertexts to a distributor, and the distributor may transmit the common set of system parameters and one of the multiple ciphertexts to each of the multiple users.
[0028]
[0045] The common set of system parameters may be generated, at least in part, by a probability distribution. Using a probability distribution to generate the parameters may provide additional security to the methods and systems described herein. The probability distribution may be a finite ring R (where R is a function of R = Z) such that the parameters generated using the probability distribution are parameters ∈ R. q or R=Z q / m, wherein Z q is an integer modulo q, and m is a monic polynomial).
[0029]
[0046] The present disclosure provides a method and system for transmitting a ciphertext to multiple users. The method for transmitting a ciphertext to multiple users may include generating a system parameter set. The system parameter set may include parameters independent of the public keys of users among the multiple users. A fixed component may be generated at least in part based on the system parameter set. Multiple variable components may be generated by encrypting a plaintext using each of the multiple users' public keys. The encryption may be based on an encryption scheme selected from the group consisting of Lindner-Peickert scheme, a supersingular isogenous Diffie-Hellman protocol, and an isogenous-based public key encryption scheme. The ciphertext including the fixed component and the variable component may be transmitted to the multiple users. The ciphertext may be decodable at least in part using the fixed component. The ciphertext may be a multi-ciphertext.
[0030]
[0047] The present disclosure provides methods and systems for organizing a database. The method for organizing a database may include structuring a plurality of recipients in a tree structure with "m" terms. The number of terms "m" may be at least 2. Compressed ciphertext updates may be sent to less than all of the plurality of recipients.
[0031]
[0048] FIG. 2 is a flowchart of an example process 200 for transmitting multiple ciphertexts to multiple users. At operation 210, process 200 may include structuring multiple recipients in a tree structure of m terms. The m terms may be the maximum number of child nodes that a node in the tree can have. For example, a four-term tree has a maximum of four child nodes per node. Examples may be seen in FIG. 10D, which shows a two-term tree, and FIG. 10E, which shows a four-term tree. The m terms may be at least about 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 50, 100, 250, 500, 1,000, or more than 1,000. The number of terms "m" can be up to about 1,000, 500, 250, 100, 50, 25, 24, 23, 22, 21, 20, 19, 18, 17, 16, 15, 14, 13, 12, 11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, or less than 1. The number of terms "m" can be within the range defined by any two points above. For example, the tree can be 8 to 16 terms. Multiple recipients can be other nodes in the tree. Other nodes in the tree can have their own child nodes. For example, multiple recipients of updates from node 1 in FIG. 10E can include nodes 2, 3, and 4, as well as nodes 18, 19, and 20. A node in the tree structure can be configured to contain information used to encrypt that node or any of its child nodes.
[0032]
[0049] In another operation 220, process 200 may include transmitting the condensed ciphertext update to less than all of a plurality of recipients. The transmission may be over a network. The network may be a public network (e.g., the Internet) or a private network (e.g., a local network). The condensed ciphertext update may be generated by methods and systems described elsewhere herein. The condensed ciphertext update may be encrypted using a lattice-based encryption scheme, an isogeny-based encryption scheme, or the like. The number of bytes for transmitting the compressed ciphertext update may be at least about 1 / 1.1, 1 / 1.2, 1 / 1.3, 1 / 1.4, 1 / 1.5, 1 / 1.6, 1 / 1.7, 1 / 1.8, 1 / 1.9, 1 / 2, 1 / 2.5, 1 / 3, 1 / 3.5, 1 / 4, 1 / 4.5, 1 / 5, 1 / 5.5, 1 / 6, 1 / 6.5, 1 / 7, 1 / 7.5, 1 / 8, 1 / 8.5, 1 / 9, 1 / 9.5, 1 / 10, 1 / 11, 1 / 12, 1 / 13, 1 / 14, 1 / 15, 1 / 16, 1 / 17, 1 / 18, 1 / 19, 1 / 20, 1 / 21, 1 / 22, 1 / 23, 1 / 24, 1 / 25 or more less than the number of bytes for transmitting the update to each of the multiple recipients. The number of bytes for sending a compressed ciphertext update may be up to about 1 / 25, 1 / 24, 1 / 23, 1 / 22, 1 / 21, 1 / 20, 1 / 19, 1 / 18, 1 / 17, 1 / 16, 1 / 15, 1 / 14, 1 / 13, 1 / 12, 1 / 11, 1 / 10, 1 / 9.5, 1 / 9, 1 / 8.5, 1 / 8, 1 / 7.5, 1 / 7, 1 / 6.5, 1 / 6, 1 / 5.5, 1 / 5, 1 / 4.5, 1 / 4, 1 / 3.5, 1 / 3, 1 / 2.5, 1 / 2, 1 / 1.9, 1 / 1.8, 1 / 1.7, 1 / 1.6, 1 / 1.5, 1 / 1.4, 1 / 1.3, 1 / 1.2, 1 / 1.1 or less than the number of bytes for sending an update to each of the multiple recipients.
[0033]
[0050] The sending may include sending the same message to each node in the tree structure. The message may include a key update for a user in the database. For example, a user may send a key update to each node in the tree structure. In another example, a user may send a key update to each node at a particular level in the tree using a compressed ciphertext. The message may be a message as described elsewhere herein (e.g., a text message, a software update, an encryption key update). The sending may include sending a different message to each node in the tree structure. For example, a different encrypted message may be sent from a user to each of multiple other users. The sending may include sending several different messages to each node in the tree structure that is less than the number of nodes in the tree structure. For example, each node at a particular depth may receive the same message. In this example, a tree with an order of four and a depth of two may have one message sent to three nodes that are children of the same parent node and another message sent to nodes that share a parent with the parent node, for a total of six updates sent. In this example, by sending six updates instead of the 15 sent without using the ciphertext compression scheme, the number of bytes to send a compressed ciphertext update is 1 / (15 / 6) = 1 / 2.5 of the number of bytes to send the update to each of the recipients. In another example, a tree of 4 terms and depth 2, where child nodes have access to the decryption key in the node's path, can be updated by sending a multi-ciphertext to two nodes, such as nodes 17 and 21 in FIG. 10E. In this example, the communication cost can be improved by 1 / (15 / 2) = 1 / 7.5 compared to sending an update to each node of multiple nodes. The transmission can include sending d ciphertexts in a multi-ciphertext, where d = log m N, where m is the number of terms in the tree and N is the number of recipient (eg, user) nodes.
[0034]
[0051] The present disclosure provides methods and systems for performing a cryptographic update including multiple encryption keys and multiple multi-ciphertexts for multiple recipient nodes. A method for performing a cryptographic update including multiple encryption keys and multiple multi-ciphertexts for multiple recipient nodes may include receiving a cryptographic update. A reduced cryptographic update may be generated by removing one or more of the multiple encryption keys and one or more ciphertexts of the multiple multi-ciphertexts. The reduced cryptographic update may be transmitted to a recipient node of the multiple recipient nodes. Operations may be repeated for one or more other nodes of the multiple nodes.
[0035]
[0052] FIG. 3 is a flowchart of an example process 300 for performing encryption updates including multiple encryption keys and multiple multi-ciphertexts on multiple recipient nodes. At operation 310, process 300 may include receiving an encryption update. The encryption update may include multiple encryption keys and / or multiple multi-ciphertexts. The encryption update may include information such as half of an encryption key pair, an encrypted message, or any data representable as a binary or hexadecimal string. The encryption update may be received from one or more sending devices. The one or more sending devices may be computing devices (e.g., servers, mobile devices, computing devices, etc.). For example, a user's smartphone may send the encryption update. The encryption update may be received by an appropriately programmed computer (e.g., a server computer). For example, a user's laptop may send the encryption key update to a secure messaging server. The sending device may be of the same type as the multiple recipient nodes. For example, the sending device may be a smartphone, which may also be a recipient node. The sending device may be of the same type as at least some of the multiple recipient nodes. For example, the sending device may be a smartphone, and the recipient nodes may be other smartphones and server nodes.
[0036]
[0053] The encrypted update may be signed using a redactable signature. The redactable signature may be configured to allow operations on one or more data blocks in the encrypted update without compromising the signature or invalidating one or more data blocks. The operations may be rewrite, modify, delete, add, etc., or any combination thereof. For example, a multi-ciphertext including multiple ciphertexts signed with a redactable signature may allow a ciphertext of the multiple ciphertexts to be deleted while preserving the signature. A user or a system generating the encrypted update may indicate portions of the encrypted update that can be changed without affecting the signature, operations that can be performed without affecting the signature, etc., or any combination thereof. For example, the system may indicate data blocks that can be deleted without affecting the signature. The ciphertext may be encrypted using a lattice-based encryption scheme. One or more ciphertexts may be ciphertexts encrypted as described elsewhere herein (e.g., generated using a lattice-based encryption scheme, generated using an isogeny-based encryption scheme). The redactable signature may be unforgeable, unalterable, or a combination thereof. The redactable signature may be private, transparent, accountable, or any combination thereof. A redactable signature may alternatively be a removable signature. A redactable signature may be based on a Merkle tree.
[0037]
[0054] In another operation 320, the process 300 may include generating a reduced encrypted update by removing one or more of the multiple encryption keys and one or more ciphertexts of the multiple multi-ciphertexts. The removal may be performed without affecting the signature. A sanitized signature may facilitate the removal of one or more of the multiple encryption keys and one or more of the multiple multi-ciphertexts. For example, an encrypted update using a sanitized signature can be modified without affecting the signature, while an encrypted update without a sanitized signature cannot be modified without affecting the signature. The removal may be performed by the recipient of the encrypted update. For example, a host server may remove blocks from an update received from a user. The removal may include removing one or more of the encryption keys and / or one or more ciphertexts of a multi-ciphertext. One or more ciphertexts may be removed from an update to a recipient node that does not need the one or more ciphertexts. For example, in a multi-ciphertext including updates for nodes A, B, and C, the server may remove updates for B and C from the reduced encrypted update sent to A. The removal of one or more ciphertexts may reduce the update size sent to the recipient node. The number of bytes sent to the plurality of nodes may be reduced by at least about 1 / n compared to the number of bytes that could be used to send updates to each of the plurality of recipient nodes, where n is the number of nodes in the plurality of nodes. The number of bytes sent to the plurality of nodes may be reduced by at most about 1 / n compared to the number of bytes that could be used to send updates to each of the plurality of recipient nodes, where n is the number of nodes in the plurality of nodes. The number of bytes sent to the plurality of nodes may be reduced by at least about 1 / 1.1, 1 / 1.2, 1 / 1.3, 1 / 1.4, 1 / 1.5, 1 / 1.6, 1 / 1.7, 1 / 1.8, 1 / 1.9, 1 / 2, 1 / 2.5, 1 / 3, 1 / 3.5, 1 / 4, 1 / 4.5, 1 / 5, 1 / 5.5, 1 / 6, 1 / 6.5, 1 / 7, 1 / 7.5, 1 / 8, 1 / 8.5, 1 / 9, 1 / 9.5, 1 / 10, 1 / 11, 1 / 12, 1 / 13, 1 / 14, 1 / 15, 1 / 16, 1 / 17, 1 / 18, 1 / 19, 1 / 20, 1 / 21, 1 / 22, 1 / 23, 1 / 24, 1 / 25 or more compared to the number of bytes that may be used to send updates to each of the plurality of recipient nodes.The number of bytes sent to the plurality of nodes may be reduced by up to about 1 / 25, 1 / 24, 1 / 23, 1 / 22, 1 / 21, 1 / 20, 1 / 19, 1 / 18, 1 / 17, 1 / 16, 1 / 15, 1 / 14, 1 / 13, 1 / 12, 1 / 11, 1 / 10, 1 / 9.5, 1 / 9, 1 / 8.5, 1 / 8, 1 / 7.5, 1 / 7, 1 / 6.5, 1 / 6, 1 / 5.5, 1 / 5, 1 / 4.5, 1 / 4, 1 / 3.5, 1 / 3, 1 / 2.5, 1 / 2, 1 / 1.9, 1 / 1.8, 1 / 1.7, 1 / 1.6, 1 / 1.5, 1 / 1.4, 1 / 1.3, 1 / 1.2, 1 / 1.1 or less compared to the number of bytes that may be used to send updates to each of the plurality of recipient nodes.
[0038]
[0055] In another operation 330, the process 300 may include transmitting the reduced encrypted update to a recipient node of a plurality of recipient nodes. The recipient node may decrypt the encrypted update. The recipient node may receive one encryption key and one ciphertext. One or more ciphertexts of the multi-ciphertext need not be transmitted to all of the plurality of nodes. For example, in a system with three nodes, an update having three ciphertexts in the multi-ciphertext can be split into three single ciphertext updates. In this example, each node may receive one particular ciphertext out of the three, and thus not all ciphertexts of the multi-ciphertext are transmitted to all of the plurality of nodes. The reduced ciphertext may be transmitted over a public network (e.g., the Internet), a private network (e.g., a virtual private network (VPN), a local network), etc. The reduced ciphertext may still include a valid signature.
[0039]
[0056] In another operation 340, process 300 may include repeating operations 320-330 for one or more other nodes of the plurality of nodes. Operation 340 may be performed substantially simultaneously for each node of the plurality of nodes. Operation 340 may provide encryption key updates to the entire server. Each node may receive a reduced encryption update including one encryption key of the plurality of encryption keys and one ciphertext of the multi-ciphertext. For example, the server may reduce the plurality of encryption keys and the multi-ciphertext to a single encryption key and a single ciphertext and transmit it to the node. Each node of the plurality of nodes may receive a reduced encryption update from each other node of the plurality of nodes including a different encryption key of the plurality of encryption keys and a different ciphertext of the multi-ciphertext. For example, for an encryption update (U, V1, V2), node 1 may receive (U, V1), and node 2 may receive (U, V2). A recipient node may have one or more child nodes. The child nodes may be child nodes in a tree structure. A child node may therefore have one or more additional child nodes. For example, nodes 5, 6, 7, and 8 in Figure 10E may be child nodes of node 18. A child node may have access to one or more parameters stored in the recipient node. A child node may have access to the decryption key of each recipient node in the child node's path.
[0040]
[0057] 4A-4C show an example of the Lindner-Peikert (LP) framework. Further details of the Lindner-Peikert framework can be found in "Better key sizes (and attacks) for LWE-based encryption" by Richard Lindner and Chris Peikert; in Aggelos Kiayias, editor, CT-RSA 2011, volume 6558 of LNCS, pages 319-339. Springer, Heidelberg, February 2011, which is incorporated by reference in its entirety. The LP framework can be used as a framework for interpreting several encryption schemes. The LP framework may provide a convenient framework for describing the ciphertext compression method herein. FIG. 4A shows an example function keygen() that can be used to generate the encryption key ek and the decryption key dk. * The function may be a probability distribution function as described elsewhere herein. By using a probability distribution to introduce randomness, the LP framework may be more robust against quantum computer-based attacks. A probability distribution may be used to generate multiple parameters A, S, and E, which may be combined to form parameter B. While shown here as a square matrix, parameter A may be non-square. The scheme may remain functional by adapting the dimensions of the other matrices (e.g., S, E). In FIG. 4B, a message msg may be encrypted using the parameters generated in the equation of FIG. 4A. The encrypted message may be represented by V, while one or more system parameters not related to the public key may be represented by U. The ciphertext may include both U and V. For example, several system parameters may be concatenated along with the encoded message into a single ciphertext. FIG. 4C illustrates the decryption process for the ciphertext generated in FIG. 4B.
[0041]
[0058] Several modifications may be made to the LP framework to improve it. One modification may allow for a more compact representation of the elements of FIGS. 4A-4C (e.g., A, S, E, B, R, E′, E″, U, and V) by representing one or more of the elements as a seed that can be passed through a generator to recombine one or more elements. The generator may be a pseudorandom number generator. For example, A may be represented as a seed that, when input to a random number generator, generates the complete matrix A. The seed may be another element. For example, a public key ek may be used as the seed for element A. In another example, a plaintext message msg may be used as the seed for element S. Compression may be applied to one or more of the elements. Compression may be lossy or lossless. For example, lossy compression may be applied to elements B, U, and V by dropping low-order bits. Applying compression may reduce the size of the elements and therefore the size of any updates involving the elements.
[0042]
[0059] FIG. 4D shows an example of pseudocode for one implementation of ciphertext compression for a single message sent to one or more recipients. By adopting a common A element for each user k, the number of A elements can be reduced by a factor of k. This reuse of A elements can be equivalent to generating A from a seed. By reusing A, the same R and E' can be used for each of the k users. By applying these two changes to the decryption process of FIG. 4B, a new process for generating multi-ciphertexts can follow. Multi-ciphertexts can simultaneously encrypt the same message msg to k distinct users. Multi-ciphertexts (U, V) can be used to decrypt the same message msg to k distinct users. i ) can be decrypted by each user i of the k users using the same decryption algorithm as in Figure 4C. By reusing the system parameter U for each of the k users, the total communication cost of multi-ciphertext can be |U| + |V|, where |x| can be the byte size of x. Conversely, the total communication cost of sending k ciphertexts can be k (|U| + |V|). With many users k, the use of multi-ciphertext reduces the total communication cost to approximately
number
[0043]
[0060] In one example, the process of FIG. 4D includes providing one or more system parameters A, one or more encryption keys e k to each user i of k users, i =B i and a common message msg. The example process of FIG. 4D may begin by generating parameters R and E' from a distribution function. Parameters R, E', and A (e.g., system parameters reusable for each user) may be combined such that U←RA+E'. Parameter U may include information usable by each user of multiple users (e.g., information independent of the user's public key). For each user i of the k users, parameter E i '' can be generated from another distribution function, V i ←RB i +E i ''+Encode(msg) can be used. i which can then generate mctxt:=(U,V0,...,V k-1 ), where mctxt may be a multi-ciphertext. The multi-ciphertext may have a size equal to the size of U plus k times the size of V.
[0044]
[0061] 5A shows a pseudo-code example of one implementation of ciphertext compression with one or more messages sent to one or more recipients. The example of FIG. 5A can be a multi-message analog of the example of FIG. 4D. In FIG. 5A, the single message msg of FIG. 4D is a different message msg for each user i of k users. i The process may be similar in other respects and may follow similar trends as described elsewhere herein. The difference is that each message msg iThe problem is that |V| may not be constant because |V| may have different sizes.
[0045]
[0062] 5B-5D show example pseudocode for one implementation of the Supersingular Isogeny Key Encapsulation (SIKE) public key encryption scheme. Figures 5B-5D may differ from Figures 4A-4C in that they may be based on the SIKE scheme described in the Supersingular Isogeny Key Encapsulation specification by David Jao et al., published March 31, 2019, by the National Institute of Standards and Technology as part of the SIKE submission package (incorporated herein by reference). In Figure 5B, a key space K is used to generate a secret (or decryption key) S. A A random member of S may then be selected. The isogen algorithm isogen may then be used to compute an isogeny of S to generate P, the public (or cryptographic) key. B into the key space K B From there, the isogen algorithm is calculated as s B While the isogeny of s can generate parameters U (e.g., parameters that are independent of the user's public key), another isogeny algorithm, isoex, generates parameters U from the cryptographic key P and s B A shared key j can be generated from U, and the process of generating the shared key j can be seen in more detail in Figure 9. A function H can map the shared key j to a bit string, which can then be operated on using the exclusive OR operator on the message msg to return V. The ciphertext can be generated by concatenating U and V as shown in the equation ctxt:=(U,V). The decryption process can be found in Figure 5D, where the same isogenous mapping algorithm isoex can utilize parameters U and decryption key S to generate the same shared key j, which can then be used to decrypt the message msg from V.
[0046]
[0063] FIG. 6A shows a pseudo-code example of one implementation of ciphertext compression in a SIKE public key encryption scheme for a message sent to one or more recipients. The code in FIG. 6A may be a SIKE analog of the example in FIG. 4D. The difference may be that FIG. 6A shows one implementation of ciphertext compression in an isogeny-based encryption scheme as described in FIGS. 5B-5D. The process difference between FIG. 5C and FIG. 6A may be that several users k each receive the message msg. The parameter U may be user-independent (e.g., not dependent on any parameters associated with a particular user). Thus, U may be reused for each user i of the k users. The parameter V may not be user-independent (e.g., dependent on parameters associated with a particular user), thus each user may receive a different V. i 5C, but instead have multiple encryption keys P i and multi-ciphertext mctxt:=(U,V0,...,V k-1 ) can be generated. Each user i of the k users can generate the multi-ciphertext ciphertext (U,V i ) can be decrypted. By having one parameter for all users, the size of the multi-ciphertext can be reduced by a factor of k |U|, thus improving the efficiency of the computing device on which the algorithm is running.
[0047]
[0064] 6B shows a pseudo-code example of one implementation of ciphertext compression in SIKE public key encryption of one or more messages sent to one or more recipients. The example of FIG. 6B can be a multi-messaging analog of the example of FIG. 6A. In FIG. 6B, the single message msg of FIG. 6A is compressed into a different message msg for each user i of k users. i Each user i can use the multi-ciphertext (U, V0,..., V k-1 ) ciphertext (U,V i ) may be decryptable. The security of the example of FIG. 6B may be at a higher level than the security of the example of FIG. 5A.
[0048]
[0065] 12A-12C show example pseudocode for one implementation of the commutative supersingular isogenous Diffie-Hellman (cSIDH) public key encryption scheme. Further details regarding the cSIDH scheme can be found in "CSIDH: An Efficient Post-Quantum Commutative Group Action," by Wouter Castryck, Tanja Lange, Chloe Martindale, Lorenz Panny, and Joost Renes, edited by Thomas Peyrin and Steven D. Galbraith, Advances in Cryptology - ASIACRYPT 2018, pages 395-427. Springer International Publishing, 2018, which is incorporated by reference in its entirety. The algorithm may be based on the EI Gamal scheme. Briefly, the cSIDH scheme may differ from the SIDH scheme in that the cSIDH scheme may be commutative, while the SIDH schemes (of which SIKE may be one implementation) may not. Commutativity may be invariant to the order in which one or more operations are performed. For example, integer multiplication is (2 * 3) * 4=2 * (3 * 4) is commutative. Operations that are not commutative may be non-commutative. The cSIDH scheme may be based on a prime number p. The prime number may be a large prime number (e.g., a prime number with a value greater than 1,000,000). The size of the prime number (e.g., bit length) may define the security of the cSIDH scheme. The prime number is p=4·l1·12...l r -1, wherein l i A prime number p is a small distinct odd prime number in the set S p which can be expressed as the elliptic curve equation y 2 =x 3 +A·x 2 +x is a finite field F such that it contains all elements A that have exactly p solutions. p Another group G may be chosen to be a subset of
number
[0049]
[0066] In the setup phase, one or more parties to the key exchange (e.g., Alice and Bob) select a large prime number p and a finite field F as described above. p and the starting elliptic curve E0:y over the integers B 2 =x 3 In the key generation phase, such as shown in Figure 12A, a first party (e.g., Alice) may sample the range [-B, B] = M, i.e., an n-tuple of separately sampled integers. The integers are in the ideal class
number
[0050]
[0067] Figure 12B shows a pseudo-code example of an encoding algorithm that may use the parameters generated in Figure 12A. The algorithm Keygen may be the algorithm of Figure 12A. The algorithm Keygen may generate an additional parameter U that is independent of the user's encryption key, or that is user-independent, or both. AIn the same way, the parameters [b] and E A The parameter E R The parameter E can be a secret shared between one or more parties. R can be generated by: [a][b]E0=[b][a]E0=E R .E R is y 2 =x 3 +R·x 2 +x, which may be the same for all parties (e.g., Alice and Bob) due to the commutativity of Cl(O). R An exclusive OR operation applied to the hash of may be used to generate V. The concatenation of the parameter U and the encrypted message V may generate the ciphertext ctxt:=(U,V). The ciphertext may be decrypted as shown in Figure 12C. The parameter E U is the parameter E A can be generated in the same way.
[0051]
[0068] 12D shows example pseudocode for one implementation of ciphertext compression of a single message sent to one or more recipients. The elements of FIG. 12D may be the same as those of FIG. 12B. Instead of a single recipient, the algorithm of FIG. 12D may be configured to send the same message msg to multiple users k. For each user i of the multiple users k, A i E that differs from the encryption key Ai The encryption scheme can continue as in FIG. 12B for each of the i users, thus generating kV iThe encrypted message may be concatenated with a user-independent parameter U to generate a multi-ciphertext, in the same manner as discussed elsewhere herein. The multi-ciphertext may be signed using a redactable signature, as described elsewhere herein. The use of a multi-ciphertext scheme may improve computational performance by reducing the operations associated with class group operation calculations performed in the key generation and key exchange operations. The class group operation may be the most computationally expensive part of the algorithm, and a multi-ciphertext scheme may perform key generation once, halving the computational cost of the algorithm. A multi-message multi-ciphertext scheme using a cSIDH scheme may be more secure than one based on SIDH or a lattice-based scheme. A multi-message multi-ciphertext scheme using a cSIDH scheme may be ciphertext indistinguishable (IND-CPA) secure.
[0052]
[0069] 12D can also be implemented in a multi-message manner. Instead of a single message msg for each of the i users k, multiple messages msg can be sent in operation 6. i In this multi-message multi-ciphertext, each V i can contain different messages.
[0053]
[0070] Although described herein with respect to various encryption schemes, the methods and systems for generating and using multi-ciphertexts described herein are not limited to any particular encryption scheme. The methods and systems described herein may be robust against chosen-plaintext attacks (CPA). For example, an attacker with the ability to send multiple plaintexts to be encrypted and receive the encrypted ciphertexts cannot determine the private key. The methods and systems described herein may be made robust against chosen-ciphertext attacks (CCA) by applying one or more general transformations. The transformations may be adapted to handle multiple recipients at once. The adapted transformations may be robust against decryption failures. The adapted transformations may have security proofs in the quantum random oracle model (QROM).
[0054] Computer Systems
[0071] The present disclosure provides computer systems programmed to implement the methods of the present disclosure. FIG. 11 shows a computer system 1101 programmed or otherwise configured to implement methods described elsewhere herein. The computer system 1101 can coordinate various aspects of the present disclosure, such as, for example, generating multiple ciphertexts, distributing messages / updates containing multiple ciphertexts, etc. The computer system 1101 can be a user's electronic device or a computer system located remotely from the electronic device. The electronic device can be a mobile electronic device. The computer system 1101 can be a non-classical computer system (e.g., a quantum computer system).
[0055]
[0072] The computer system 1101 includes a central processing unit (CPU, also referred to herein as "processor" and "computer processor") 1105, which may be a single-core or multi-core processor or multiple processors for parallel processing. The computer system 1101 also includes memory or memory locations 1110 (e.g., random access memory, read-only memory, flash memory), an electronic storage unit 1115 (e.g., hard disk), a communication interface 1120 (e.g., network adapter) for communicating with one or more other systems, and peripheral devices 1125, such as cache, other memory, data storage, and / or electronic display adapters. The memory 1110, storage unit 1115, interface 1120, and peripheral devices 1125 communicate with the CPU 1105 through a communication bus (solid lines) such as a motherboard. The storage unit 1115 may be a data storage unit (or data repository) for storing data. Computer system 1101 can be operably coupled to a computer network (“network”) 1130 using communication interface 1120. Network 1130 can be the Internet, an Internet and / or extranet, or an intranet and / or extranet in communication with the Internet. In some cases, network 1130 is a telecommunications network and / or a data network. Network 1130 can include one or more computer servers, thereby enabling distributed computing such as cloud computing. Network 1130 can optionally implement a peer-to-peer network using computer system 1101, allowing devices coupled to computer system 1101 to act as clients or servers.
[0056]
[0073] The CPU 1105 may execute a series of machine-readable instructions, which may be implemented in a program or software. The instructions may be stored in a memory location, such as the memory 1110. The instructions may be directed to the CPU 1105, which may subsequently program or otherwise configure the CPU 1105 to perform the methods of the present disclosure. Examples of operations performed by the CPU 1105 may include fetch, decode, execute, and writeback.
[0057]
[0074] The CPU 1105 may be part of a circuit, such as an integrated circuit. One or more other components of the system 1101 may be included in the circuit. In some cases, the circuit is an application specific integrated circuit (ASIC).
[0058]
[0075] The storage unit 1115 may store files such as drivers, libraries, and saved programs. The storage unit 1115 may store user data, such as user preferences and user programs. Optionally, the computer system 1101 may include one or more additional data storage units external to the computer system 1101, such as located on a remote server that communicates with the computer system 1101 through an intranet or the Internet.
[0059]
[0076] Computer system 1101 can communicate with one or more remote computer systems through network 1130. For example, computer system 1101 can communicate with a user's remote computer system. Examples of remote computer systems include a personal computer (e.g., a portable PC), a slate or tablet PC (e.g., an Apple® iPad, a Samsung® Galaxy Tab), a telephone, a smartphone (e.g., an Apple® iPhone, an Android-enabled device, a Blackberry®), or a personal digital assistant. A user can access computer system 1101 through network 1130.
[0060]
[0077] Methods as described herein may be implemented by machine (e.g., computer processor) executable code stored in electronic storage locations of computer system 1101, such as memory 1110 or electronic storage unit 1115. Machine-executable or machine-readable code may be provided in the form of software. In use, the code may be executed by processor 1105. In some cases, the code may be retrieved from storage unit 1115 and stored in memory 1110 for easy access by processor 1105. In some circumstances, electronic storage unit 1115 may be omitted, and machine-executable instructions may be stored in memory 1110.
[0061]
[0078] The code may be pre-compiled and configured for use with a machine having a processor adapted to execute the code, or may be compiled during run-time. The code may be selected so that the code can be executed pre-compiled or compiled.
[0062]
[0079] Aspects of the systems and methods provided herein, such as computer system 1101, can be implemented with programming. Various aspects of the present technology can be considered “products” or “articles of manufacture,” typically in the form of machine (or processor) executable code and / or associated data carried or embodied in a type of machine-readable medium. The machine-executable code can be stored in an electronic storage unit, such as memory (e.g., read-only memory, random-access memory, flash memory) or a hard disk. “Storage” type media can include any or all of a computer’s tangible memory, such as various semiconductor memories, tape drives, disk drives, etc., that can provide non-transitory storage for software programming from time to time, a processor, etc., or associated modules. All or portions of the software may sometimes be communicated over the Internet or various other telecommunications networks. Such communications may, for example, enable software to be loaded from one computer or processor to another, e.g., from a management server or host computer to an application server computer platform. Accordingly, other types of media that may carry software elements include optical, light wave, radio wave, and electromagnetic waves, such as those used across physical interfaces between local devices, through wired and light-to-ground warfare networks, and via various air links. Physical elements that carry such waves, such as wired or wireless links, optical links, etc., may also be considered media that carry software. As used herein, except when limited to non-transitory tangible "storage" media, terms such as computer or machine "readable medium" refer to any medium that participates in providing instructions to a processor for execution.
[0063]
[0080] Thus, a machine-readable medium such as a computer-executable code may take many forms, including, but not limited to, a tangible storage medium, a carrier wave medium, or a physical transmission medium. Non-volatile storage media include optical or magnetic disks, such as any storage device in any computer, such as may be used to implement the databases, etc., shown in the figures. Volatile storage media include dynamic memory, such as the main memory of such a computer platform. Tangible transmission media include coaxial cables, copper wire, and fiber optics, including the wires that comprise a bus within a computer system. Carrier wave transmission media may take the form of electric or electromagnetic signals, or acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Thus, common forms of computer readable media include, for example, floppy disks, flexible disks, hard disks, magnetic tape, any other magnetic media, CD-ROMs, DVDs or DVD-ROMs, any other optical media, punched card paper tape, any other physical storage media with a pattern of holes, RAM, ROM, PROMs and EPROMs, Flash EPROMs, any other memory chips or cartridges, carrier waves transporting data or instructions, cables or links transporting such carrier waves, or any other medium from which a computer can read programming code and / or data. Many of these forms of computer readable media may be involved in carrying one or more sequences of one or more instructions to a processor for execution.
[0064]
[0081] The computer system 1101 may include or be in communication with an electronic display 1135 that includes a user interface (UI) 1140, for example, to provide a programming interface. Examples of UIs include, but are not limited to, graphical user interfaces (GUIs) and web-based user interfaces.
[0065]
[0082] The methods and systems of the present disclosure may be implemented as one or more algorithms. The algorithms may be implemented in software when executed by the central processing unit 1105. The algorithms may, for example, implement one or more encryption algorithms such as those described herein. [Example]
[0066] example
[0083] The following examples are illustrative of the specific systems and methods described herein and are not intended to be limiting.
[0067] Example 1 - Real-world improvements in update size
[0084] Figures 7A-7C show example plots of update size vs. group size for various key encryption mechanisms. The examples shown in Figures 7A-7C illustrate improvements in computer system functionality that can be achieved through implementation of the methods and systems described elsewhere herein. For each group size shown in Figures 7A-7C, the number of tree terms was selected to minimize the update size. Figure 7A shows plots of update size in several different scenarios using the Kyber512 key encryption mechanism. The first row, Sender Key (c), shows update size as a function of group size for a sender-key scheme with compression applied, which can also be thought of as a compressed tree-KEM scheme, where a number of terms equal to the group size, and therefore a depth of 1, was used in process 200 of Figure 2. An example of a sender-key scheme can be found in Figure 10C, where a single node sends updates to each receiving node. The second row, Tree-KEM, traces the efficiency of an uncompressed scheme, such as that shown in Figure 10D. Although the initial cost of updates using the tree-KEM scheme is higher than the compressed sender-key scheme, group size increases efficiency, so the gain from using the tree-KEM scheme may be significant. Further improvements can be achieved by applying a compressed tree-KEM (e.g., tree-KEM(c)) scheme, as shown in line 3. The compressed tree-KEM scheme may be one implementation of process 200 of FIG. 2, in which ciphertext compression is used in the update process. The compressed tree-KEM scheme exhibits improved performance from the standard tree-KEM scheme for all group sizes greater than 2, and also exhibits significant improvement from the compressed sender-key scheme as group sizes increase beyond 64. Thus, the ciphertext-aware compressed tree-KEM scheme can improve update size, and therefore the performance of systems using updates, for all group sizes, with the larger the group, the greater the improvement provided.
[0068]
[0085] Similarly, Figures 7B and 7C show the improvement achieved by using a ciphertext compression scheme with an additional key encapsulation mechanism (KEM), demonstrating the generality of the improvement. Figure 7B is a plot for FrodoKEM640KEM, while Figure 7C shows update size vs. group size for SIKE / p434KEM. Callouts 770, 780, and 790 in Figure 7C are provided for clarity in the figure legend. In each figure, the performance of the compressed tree-KEM scheme is always better than the uncompressed tree-KEM scheme and better than the compressed sender-key scheme at larger group sizes. The location of the differences between the compressed sender-key and compressed tree-KEM schemes may depend on the system parameters, ciphertext, and multi-ciphertext relative sizes of each scheme. For example, FrodoKEM640 may have a relatively larger system parameter byte size compared to the ciphertext byte size than SIKE / p434, and therefore requires a larger group size to see the difference between compressed sender-key and compressed tree-KEM.
[0069]
[0086] FIG. 8 shows the possible asymptotic gain factors for several different KEM schemes when a multi-ciphertext scheme is used. The |U| value can be a system parameter (e.g., a parameter that is independent of the user's public key). The |U| value can correspond to the size of the parameter U in FIGS. 4A-4D and 5A-5D. Using a multi-ciphertext scheme can reduce the number of times these parameters are transmitted and therefore the amount of data that can be transmitted. The |V| value can be the size of a parameter that is dependent on the user's public key (e.g., the encrypted message, various other keys). Combining the |U| size and the |V| size produces a |ctxt| column, which indicates the size of the complete classical ciphertext. By reusing the |U| parameter instead of appending an additional |V| parameter, the size of a two-recipient multi-ciphertext can be |U| + 2|V|, while the size of a two-recipient classical ciphertext can be 2|U| + 2|V|. By calculating |ctxt| / |V|, an asymptotic gain factor can be determined, which may indicate the maximum efficiency factor that can be obtained by implementing the multi-ciphertext methods and systems as described elsewhere herein. As can be seen in Figure 8, the methods described herein can impart real efficiency gains to computer systems by reducing the communication bandwidth requirements for transmitting encryption key updates. Furthermore, Figure 8 can indicate the broad applicability of the multi-ciphertext method to a variety of different encryption schemes.
[0070] Example 2 - Database structure and interaction with ciphertext compression
[0087] 10A-10E show examples of protocols that can be used in conjunction with ciphertext compression. FIG. 10A is an example of a broadcast use case. In a broadcast use case, user A can output information to one or more recipients, six recipients in this example. If the information is confidential, A may need to perform some form of encryption on the information. Output may be via a network (e.g., the Internet), a broadcast medium (e.g., light waves, radio waves), etc. FIG. 10B shows a server-assisted messaging scheme. User A has a message addressed to one or more other users that A sends to server S. Because one or more users may not be online when user A sends the message, the message may be sent to server S, which is always online. In this example, the amount of data being transmitted can grow rapidly based on the number of intended recipients of the message. Using multiple ciphertexts can reduce the load leaving server S. In the six-recipient example, if user A sends a 1MB message containing 0.5 megabytes (MB) of user-independent system parameters and a 0.5MB encrypted message that is not user-independent, a standard ciphertext system would have A send 6MB of information to the server (6 users x 1MB per message), and the server would then send six 6MB messages (because any changes to a user's message could corrupt the signature). With a multi-ciphertext scheme, user A would send a 3.5MB message to the server (0.5MB of system parameters and a 3MB encrypted message), and the server could update each recipient with the 6MB message, for a total communication savings of 2.5MB. Using redactable signatures in conjunction with the multi-ciphertext scheme, user A could send a 3.5MB message to the server, and the server could remove information not intended for each of the multiple users, thereby sending six 1MB messages, for a total communication savings of 32.5MB. As can be seen, the combination of multi-ciphertext and redactable signatures can result in a significant reduction in the bandwidth required to transmit a message.
[0071]
[0088] 10C and 10E can be viewed as different tree structures equivalent to multi-ciphertext and redactable signatures. FIG. 10C is an example of a sender-key scheme in which a user updating a cryptographic key sends the update to each other user in a group. This structure is an N-ary tree, where N is the number of members in the group. This can be contrasted with the tree in FIG. 10D, which instead has the same number of recipient nodes but is instead arranged as a 2-ary tree. When a user sends a message such as a cryptographic key update in a sender-key scheme, the user sends N-1 messages, seven messages in the example of FIG. 10C. In the tree in FIG. 10D, each node knows the decryption keys of the nodes in its path (e.g., the path to node 1 is node 1010). Because each node knows the decryption keys in its path, a user updating a key must update all nodes in the user's path, which requires sending updates to the nodes in the common path. In the example of Figure 10D, for node 1, the path is node 1010 and the common path is node 1020. This leads to the transmission of d public keys and d ciphertexts, where d = log2N. Thus, the tree structure is such that the communication cost is log m It is more scalable than the sender key structure because it scales as N to N-1.
[0072]
[0089] Figure 10E is an example of a larger tree structure with term 4, made possible by using a multi-ciphertext scheme. Similar to the tree in Figure 10D, each node knows the decryption keys of the nodes in its path, so when User 1 sends an update, it knows d decryption keys, where d = log4N (=2 in this example), and (m-1) * d (where m is the number of users, in this example (m-1) *The first node sends m-1 multi-ciphertexts (where d=6). The number of multi-ciphertexts sent may be one per level. A multi-ciphertext may include (m-1) ciphertexts to update (m-1) other nodes per level. In the example of FIG. 10D, the first multi-ciphertext update from node 1 may include ciphertexts for nodes 2, 3, and 4, and the second multi-ciphertext update may include ciphertexts for nodes 18, 19, and 20. Multi-ciphertexts may also be signed with a redacted signature, which allows the multi-ciphertext to be modified before being sent to each recipient node. For example, the multi-ciphertext update to nodes 2, 3, and 4 may be modified to include the relevant updates rather than just the updates to the other two nodes.
[0073]
[0090] While preferred embodiments of the present invention have been shown and described herein, it will be obvious to those skilled in the art that such embodiments are provided by way of example only. The present invention is not intended to be limited by the specific examples provided herein. While the present invention has been described with reference to the above specification, the descriptions and illustrations of the embodiments herein are not intended to be construed in a limiting sense. Numerous variations, changes, and substitutions will occur to those skilled in the art without departing from the invention. Furthermore, it is to be understood that all aspects of the present invention are not limited to the specific illustrations, configurations, or relative proportions set forth herein, which depend upon a variety of conditions and variables. It is to be understood that various alternatives to the embodiments of the invention described herein may be employed in practicing the invention. It is therefore contemplated that the present invention shall encompass any and all such alternative modifications, variations, or equivalents. The following claims define the scope of the invention, and methods and structures within these claims and their equivalents are intended to be covered thereby.
Claims
1. 1. A method for transmitting a ciphertext containing multiple encrypted portions to multiple users, comprising: (a) providing a common set of system parameters for the plurality of users; (b) generating the plurality of encrypted portions by encrypting plaintext using a parameter unique to each user of the plurality of users; (c) generating the ciphertext including a portion derived from the common set of system parameters and the plurality of encrypted portions; (d) transmitting the ciphertext to the plurality of users, the ciphertext being at least partially decodable using the parameters unique to each user of the plurality of users; A method comprising:
2. The method of claim 1 , wherein the encrypted portion is encrypted using a lattice-based encryption scheme.
3. The method of claim 1 , wherein the encrypted portion is encrypted using an isogeny-based encryption scheme.
4. The method of any one of claims 1 to 3, wherein the common set of system parameters is generated using a seed and a pseudo-random number generator.
5. The method of any one of claims 1 to 4, wherein at least one of the parameters unique to each user of the plurality of users is generated using a seed and a pseudo-random number generator.
6. The method of any one of claims 1 to 5, wherein the common set of system parameters or the parameters unique to each user of the plurality of users comprises a non-square matrix.
7. 1. A method for transmitting ciphertext to multiple users, comprising: (a) generating a system parameter set, the parameter set including parameters independent of public keys of users of the plurality of users; (b) generating a fixed component based at least in part on the set of system parameters; (c) generating a plurality of variant components by encrypting a plaintext using each public key of the plurality of users; (d) transmitting the ciphertext to the plurality of users, the ciphertext including the fixed component and the variable component, the ciphertext being at least partially decodable using the fixed component; A method comprising:
8. 8. The method of claim 7, wherein the encryption is based on an encryption scheme selected from the group consisting of Lindner-Peickert, a hypersingular isogenous Diffie-Hellman protocol, and an isogenous-based public key encryption scheme.
9. 1. A method for organizing a database, comprising: (a) structuring a plurality of recipients in a tree structure of m terms, where "m" is at least 2; (b) transmitting the compressed ciphertext update to less than all of the plurality of recipients; A method comprising:
10. The method of claim 9 , wherein the number of terms m is at least about eight.
11. 10. The method of claim 9, wherein the number of terms m is from about 8 to about 16.
12. 10. The method of claim 9, wherein the number of bytes used for said sending is less than or equal to about half the number of bytes for sending an update to each of said plurality of recipients.
13. The method of any one of claims 9 to 12, wherein the compressed ciphertext updates are encrypted using a lattice-based encryption scheme.
14. The method of any one of claims 9 to 12, wherein the compressed ciphertext update is encrypted using an isogeny-based encryption scheme.
15. The method of any one of claims 9 to 14, wherein said sending comprises sending the same message to each node of said tree structure.
16. 16. The method of claim 15, wherein the same message includes updates to encryption keys of users of the database.
17. 1. A method for performing cryptographic updates involving multiple cryptographic keys and multi-ciphertexts for multiple recipient nodes, comprising: (a) receiving the encryption update; (b) generating a reduced encrypted update by removing one or more of the plurality of encryption keys and one or more ciphertexts of the multi-ciphertext; (c) transmitting the reduced encryption update to a recipient node of the plurality of recipient nodes; (d) repeating (b)-(c) for one or more other nodes of the plurality of nodes; A method comprising:
18. 20. The method of claim 17, wherein each node receives a reduced encryption update that includes one encryption key of the plurality of encryption keys and one ciphertext of the multi-ciphertext.
19. 20. The method of claim 18, wherein each node of the plurality of nodes receives a reduced encryption update including a different encryption key of the plurality of encryption keys and a different ciphertext of the multi-ciphertext from a respective other node of the plurality of nodes.
20. The method of any one of claims 17 to 19, wherein the recipient node has child nodes.
21. 21. The method of claim 20, wherein the child node has access to a decryption key for each recipient node in the child node's path.
22. The method of any one of claims 17 to 21, wherein (d) is performed substantially simultaneously for each node of the plurality of nodes.
23. 23. The method of any one of claims 17 to 22, further comprising reducing the number of bytes sent to the plurality of nodes by a factor of about n or less, where n is the number of nodes in the plurality of nodes.
24. The method of any one of claims 17 to 23, wherein the one or more ciphertexts are encrypted using a lattice-based encryption scheme.
25. The method of any one of claims 17 to 24, wherein the one or more ciphertexts are encrypted using an encryption scheme based on isogeny.
26. The method of any one of claims 17 to 25, wherein the encrypted update is signed with a black-out signature.
27. 27. The method of claim 26, wherein the redacted signature facilitates the removal of the one or more of the plurality of cryptographic keys and the plurality of multi-ciphertexts.
28. 28. A system comprising one or more computer processors and a computer memory coupled thereto, the computer memory comprising machine executable code which, when executed by the one or more computer processors, performs a method according to any one of claims 1 to 27.
Citation Information
Patent Citations
Cryptogram generating device, cryptogram communication system, and group parameter generating device
WO2008087734A1