Computing unit, terminal device, network, calculation method and program
By padding and encrypting the common key to match the input key length, the computing device addresses the need for expanding 128-bit keys to 256-bit ciphers, ensuring secure communication in systems with mixed cipher lengths.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2026-03-19
AI Technical Summary
The introduction of 256-bit ciphers necessitates the expansion of 128-bit keys to match the bit length of 256-bit ciphers, as both will coexist, requiring a method to generate keys equal in size to the cipher algorithm.
A computing device performs padding and encryption steps to expand the bit length of a common key to match the input key used in the cryptographic algorithm, using a time-dependent variable plaintext and methods like AES or stream ciphers, until the concatenated ciphertext matches the input key length.
This approach allows for generating keys equal in size to the cryptographic algorithm, ensuring secure communication by expanding the bit length of the common key.
Smart Images

Figure 2026049951000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an arithmetic device, a terminal device, a network, an arithmetic method, and a program.
Background Art
[0002] Conventional 3GPP (registered trademark) specifications are formulated on the premise of allocating a 128-bit key to a 128-bit cipher. For example, Non-Patent Document 1 defines the specific specifications of such a technology.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Here, currently, discussions are underway for introducing 256-bit ciphers. When 256-bit ciphers are introduced, it is assumed that 128-bit ciphers and 256-bit ciphers will coexist. In such a case, there is a need for using a 128-bit key with a 256-bit cipher. That is, there is a need to expand the bit length of a given key and generate a key equal to the size of the key used in the cipher algorithm.
[0005] The present invention has been made in consideration of such circumstances, and an object thereof is to provide an arithmetic device, a terminal device, a network, an arithmetic method, and a program capable of expanding the bit length of a given key and generating a key equal to the size of the key used in the cipher algorithm.
Means for Solving the Problems
[0006] (1) One aspect of the present invention is a computer having at least a processor and memory, which is a computing device that causes a computer to perform the following steps: a padding step, when the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, to pad the bit length of the common key to be the same as the bit length of the input key; an encryption step, when the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, to pad the bit length of the common key to be the same as the bit length of the input key; an encryption step, when the bit length of the ciphertext generated by the encryption step is shorter than the bit length of the input key, to repeat the encryption step again until the bit length of the concatenated generated ciphertext is the same as or longer than the bit length of the input key, thereby generating a key having the same bit length as the input key. (2) In addition, in one aspect of the present invention, in the computing device of (1) described above, the predetermined plaintext used in the encryption process is different from one another depending on the number of iterations performed by the key generation process. (3) In another aspect of the present invention, in the computing device of (1) or (2) described above, the predetermined plaintext used in the encryption process is a time-dependent variable agreed in advance between the terminal device and the network. (4) In addition, in one aspect of the present invention, in the arithmetic device described in any of (1) to (3) above, the bit length of a predetermined plaintext used in the encryption step is the same as the value obtained by dividing the bit length of the input key by a natural number n of 1 or more, and the key generation step generates a key having the same bit length as the bit length of the input key by repeating the encryption step n times. (5) In addition, in one aspect of the present invention, in the computing device described in any of (1) to (4) above, the encryption step generates a ciphertext using the AES (Advanced Encryption Standard) method or a stream cipher method. (6) In addition, in one aspect of the present invention, in the arithmetic unit described in any of (1) to (4) above, the bit length of the common key is 128 bits and the bit length of the input key is 256 bits. (7) Another aspect of the present invention is a terminal device equipped with the arithmetic unit described in any of (1) to (6) above. (8) Another aspect of the present invention is a network comprising the computing device described in any of (1) to (6) above. (9) In another aspect of the present invention, in the network described in (8) above, the computing device is provided in at least one of the next generation Node B (gNodeB or gNB) or the AMF (Access and Mobility Management Function). (10) Another aspect of the present invention is a calculation method comprising: a padding step in which, if the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, padding is performed to make the bit length of the common key the bit length of the input key; an encryption step in which a ciphertext is generated by performing a predetermined plaintext encryption process agreed upon between the terminal device and the network using the key generated in the padding step; and a key generation step in which, if the bit length of the ciphertext generated in the encryption step is shorter than the bit length of the input key, the encryption step is repeated until the bit length of the concatenated generated ciphertext is the same as or longer than the bit length of the input key, thereby generating a key having the same bit length as the input key. (11) Another aspect of the present invention is a program that causes a computer to execute: a padding step in which, if the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, padding is used to make the bit length of the common key the bit length of the input key; an encryption step in which a ciphertext is generated by performing a predetermined plaintext encryption process agreed upon between the terminal device and the network using the key generated in the padding step; and a key generation step in which, if the bit length of the ciphertext generated in the encryption step is shorter than the bit length of the input key, the encryption step is repeated until the bit length of the concatenated generated ciphertext is the same as or longer than the bit length of the input key, thereby generating a key having the same bit length as the input key. [Effects of the Invention]
[0007] According to the present invention, it is possible to provide a computing device, terminal device, network, computing method, and program that can expand the bit length of a given key and generate a key equal in size to the key used in the cryptographic algorithm. [Brief explanation of the drawing]
[0008] [Figure 1] This figure shows a schematic architecture of a wireless system according to one embodiment. [Figure 2] This is a block diagram schematically representing the wireless system according to this embodiment. [Figure 3] This diagram illustrates the processing of the wireless system according to this embodiment when a 128-bit key is provided and when a 256-bit key is provided. [Figure 4] This is a flowchart showing a series of steps in the calculation method according to this embodiment. [Figure 5] This block diagram shows an example of the internal configuration of a network or terminal device according to this embodiment. [Modes for carrying out the invention]
[0009] [Embodiment] The following describes in detail, with reference to the attached drawings, a preferred embodiment of the computing device, terminal device, network, computing method, and program according to aspects of the present invention. It should be noted that the embodiments of the present invention are not limited to these embodiments, and include various modifications and improvements. In other words, the components described below include those that are easily conceivable to those skilled in the art, and those that are substantially the same, and the components described below can be combined as appropriate. Furthermore, various omissions, substitutions, or modifications of components can be made without departing from the spirit of the present invention. Also, in the following drawings, the scale and number of components in each structure may differ from the scale and number of components in the actual structure in order to make each structure easier to understand.
[0010] In the following explanation, for the sake of clarity, terms and names defined in the 3GPP® LTE (3rd Generation Partnership Project Long Term Evolution) standard may be used. However, this embodiment is not limited by such terms and names and is applicable to systems based on other standards.
[0011] Figure 1 shows a schematic architecture of a wireless system according to one embodiment. The wireless system 1 shown in the figure has a control plane (C-Plane), which has functions for controlling communication, and a user plane (U-Plane), which has functions for realizing user communication. For the sake of simplicity, the figure shows a basic architecture used in 5th generation mobile communication systems (5G), but the wireless system 1 to which this embodiment is applied is not limited to an example applied to 5G, but can be broadly applied to other systems.
[0012] In the following explanation, components other than the UE (User Equipment) may be referred to as the network. The network includes the access layer and the non-access layer. The access layer includes at least a base station, and the non-access layer includes at least an AMF (Access and Mobility Management Function). As shown in the diagram, the UE and AMF communicate with each other via the N1 interface. In the following explanation, base stations and AMF may be referred to as higher-level concepts and simply as the network.
[0013] Figure 2 is a schematic block diagram of the wireless system according to this embodiment. The figure schematically represents a part of the configuration of the wireless system 1. The wireless system 1 has a network 30 and terminal devices 50. As an example, the figure shows one network and multiple terminal devices 50. Specifically, as an example of multiple terminal devices 50, terminal device 50-1, terminal device 50-2, ... and terminal device 50-m (where m is a natural number of 1 or more) are shown.
[0014] Network 30 communicates information with terminal equipment 50. Network 30 includes at least a base station. The base station may include the functions of an O-RU (Radio Unit), O-DU (Distributed Unit), and O-CU (Central Unit), for example, as defined in the O-RAN (Open-RAN) specification.
[0015] The base station may also be referred to as a next generation Node B (gNodeB or gNB), en-gNB, Next Generation-Radio Access Network (NG-RAN) node, eNB, low-power node, CU, DU, RU, gNB-DU, Remote Radio Head (RRH), Integrated Access and Backhaul / Backhauling (IAB) node, etc. The base station is not limited to one node and may be composed of a plurality of nodes (for example, a combination of lower nodes such as RUs and DUs and upper nodes such as CUs).
[0016] The terminal device 50 is used by a user. Specific examples of the terminal device 50 may include smartphones, tablet terminal devices, wearable devices, etc. Note that the terminal device 50 may also be referred to as a user device or UE, etc.
[0017] Here, both the network 30 and the terminal device 50 include an arithmetic device 10. The arithmetic device 10 includes at least a processor and a memory as a hardware configuration. The functions of the arithmetic device 10 may be realized by causing a computer to execute a program. The arithmetic device 10 performs operations for expanding or compressing the number of bits of a key used for encryption or decryption. The configurations of the arithmetic devices 10 included in the network 30 and the terminal device 50 may be the same or different. However, at least a part of the configurations of the arithmetic devices 10 included in the network 30 and the terminal device 50 is assumed to have the same configuration as each other.
[0018] Note that the location where the arithmetic device 10 is provided in the network 30 is arbitrary. For example, the arithmetic device 10 may be provided in a gNodeB or an AMF. It can also be said that the arithmetic device 10 is provided in at least one of the gNodeB or the AMF in the network 30.
[0019] Figure 3 illustrates the processing in the case where a 128-bit key and a 256-bit key are provided to the wireless system according to this embodiment. Here, the wireless system 1 may be provided with a 128-bit key or a 256-bit key. Whether to use a 128-bit key or a 256-bit key for encrypted communication is decided at the start of communication. Specifically, the network 30 and the terminal device 50 negotiate at the start of communication to determine the algorithm to be used. If, as a result of the negotiation, it is decided to use a 256-bit key and a 256-bit key is provided, it is possible to perform encrypted communication with each other using the 256-bit key as is. However, if a 128-bit key is provided, it is necessary to first expand the 128-bit key to 256 bits and then perform encrypted communication with each other using the expanded 256-bit key.
[0020] Figure 3(A) shows an example where a 128-bit key is given. In this case, both the network 30 and the terminal device 50 need to expand the 128-bit key to 256 bits. The network 30 and the terminal device 50 then use the expanded key to perform encrypted communication with each other.
[0021] Figure 3(B) shows an example where a 256-bit key is provided. In this case, the network 30 and the terminal device 50 can communicate with each other using the 256-bit key in an encrypted manner.
[0022] [A specific example of how to enlarge a key] Figure 4 is a flowchart showing the sequence of operations of the calculation method according to this embodiment. A specific example of the key expansion method will be explained with reference to this figure. In the example described above, an example of expanding a 128-bit key to 256 bits was explained, but the number of bits in the key targeted by the key expansion method according to this embodiment is not limited to this example. In the following explanation, the number of bits in the key will be explained in a generalized manner.
[0023] As a premise, assume that a common key K1 is generated between the terminal device 50 and the network 30 as a key to be used for encryption. The common key K1 can also be described as a key assigned for use in communication between the terminal device 50 and the network 30. Furthermore, assume that algorithm E is selected as the encryption method to be used between the terminal device 50 and the network 30. The input key for algorithm E is described as input key K2. The input key K2 can also be described as a key used in a given algorithm E. The aforementioned arithmetic unit 10 generates input key K2 by expanding the common key K1. The terminal device 50 and the network 30, which communicate with each other, generate the same input key K2 by expanding the same common key K1.
[0024] (Step S11) First, the arithmetic unit 10 compares the bit lengths of the common key K1 and the input key K2. When the bit length of the common key K1 is |K1| and the bit length of the input key K2 is |K2|, if |K1| < |K2| (i.e., Step S11; YES), the arithmetic unit 10 generates the input key K2 from the common key K1, and proceeds to Step S12, continuing the subsequent processing. If |K1| < |K2| is not true (i.e., Step S11; NO), the arithmetic unit 10 does not need to perform key expansion processing and terminates the processing.
[0025] (Step S12) If the bit length of the common key K1 (e.g., 128 bits) is shorter than the bit length of the input key K2 (e.g., 256 bits), the arithmetic unit 10 pads the bit length of the common key K1 to match that of the input key K2. Any value can be used for padding, such as 0 or 1. The arithmetic unit 10 can also pad the common key K1 such that │K2│=pad(K1). This step may also be referred to as the padding step.
[0026] (Step S13) Next, the arithmetic unit 10 generates ciphertext Ci by performing cryptographic processing on plaintext m using the bit sequence pad(K1) generated in the padding process as a key. Plaintext m is a predetermined plaintext agreed upon in advance between the terminal device 50 and the network 30. Preferably, the bit length of plaintext m is the same as the bit length of the input key K2, or shorter than the bit length of the input key K2. The process performed in this step may also be described as the encryption process. In the encryption process, it can also be said that ciphertext Ci is generated based on the plaintext m and the key pad(K1). Here, i is the number of times the encryption process has been performed, and is a natural number greater than or equal to 1. For example, ciphertext C1 is obtained by the first encryption process, and ciphertext C2 is obtained by the second encryption process. Specifically, ciphertext C1 can be expressed as equation (1) below.
[0027]
number
[0028] Here, it is preferable that the bit length of the predetermined plaintext m used in the encryption process is the same as the value obtained by dividing the bit length of the input key K2 (e.g., 128 bits) by a natural number n greater than or equal to 1 (e.g., 128 bits or 64 bits). By doing so, the process of extracting the leading bit of the bit sequence in step S15, which will be explained later, can be omitted. By increasing n (shortening the bit length of the plaintext m), the number of encryption steps can be increased, which can result in stronger encryption, but it can also increase the processing load.
[0029] Furthermore, the plaintext m used for encryption only needs to be agreed upon in advance between the terminal device 50 and the network 30, and may be different each time in the repeated encryption process. In other words, the plaintext m may differ from one another depending on the number of iterations (i mentioned above). Also, different plaintext m may be used depending on the time. Plaintext m can also be said to be a variable that depends on time.
[0030] Furthermore, known technologies can be applied as examples of specific encryption processes performed during the encryption process. Specific examples of encryption processes include the AES (Advanced Encryption Standard) method or stream ciphers. A more specific example of a stream cipher is Snow-3G (with ZUC as an option).
[0031] (Step S14) Here, the bit length of the ciphertext generated by the encryption process differs depending on the bit length of the plaintext m. The encryption process is carried out, for example, until the number of bits in the bit sequence obtained by concatenating the ciphertext Ci is equal to or greater than the bit length of the input key K2. This process may be described as the key generation process. If the number of bits in the bit sequence obtained by concatenating the ciphertext Ci is less than the bit length of the input key K2 (i.e., Step S14; NO), the process returns to Step S13 and the encryption process is repeated. If the number of bits in the bit sequence obtained by concatenating the ciphertext Ci is equal to or greater than the bit length of the input key K2 (i.e., Step S14; YES), the process proceeds to Step S15.
[0032] Here, if the number of bits in the bit sequence obtained by concatenating the ciphertext Ci is the same as the bit length of the input key K2, step S15 can be skipped and the input key K2 can be obtained as shown in equation (2) below. However, if the number of bits in the bit sequence obtained by concatenating the ciphertext Ci is not the same as the bit length of the input key K2, and is greater than the bit length of the input key K2, the bit length of the input key K2 can be obtained by performing step S15 below.
[0033]
number
[0034] (Step S15) In this step, the arithmetic unit 10 obtains the input key K2 by extracting an arbitrary bit sequence from the bit sequence obtained by concatenating the ciphertext Ci. The arithmetic unit 10 may, for example, obtain the input key K2 by taking the leading bit from the bit sequence obtained by concatenating the ciphertext Ci. The input key K2 obtained by taking the leading bit can be represented by the following equation (3).
[0035]
number
[0036] Figure 5 is a block diagram showing an example of the internal configuration of a network or terminal device according to this embodiment. At least some of the functions of the network 30 or terminal device 50 can be realized using a computer. As shown in the figure, the computer is composed of a central processing unit (processor) 901, RAM 902, input / output ports 903, input / output devices 904 and 905, etc., and a bus 906. The computer itself can be realized using existing technology. The central processing unit 901 executes instructions contained in programs read from RAM 902, etc. The central processing unit 901 writes data to RAM 902, reads data from RAM 902, and performs arithmetic and logical operations according to each instruction. RAM 902 stores data and programs. Each element contained in RAM 902 has an address and can be accessed using that address. RAM stands for "Random Access Memory". Input / output ports 903 are ports for the central processing unit 901 to exchange data with external input / output devices, etc. Input / output devices 904 and 905 are input / output devices. Input / output devices 904 and 905 exchange data with the central processing unit 901 via input / output ports 903. Bus 906 is a common communication channel used within the computer. For example, the central processing unit 901 reads and writes data to RAM 902 via bus 906. Also, for example, the central processing unit 901 accesses input / output ports via bus 906. Furthermore, all or part of each functional unit of the network 30 or terminal device 50 may be implemented using hardware such as ASICs, PLDs, or FPGAs. Furthermore, all or part of each functional unit may be implemented by a combination of software and hardware.
[0037] [Summary of Embodiments] According to the embodiments described above, the arithmetic unit 10 causes a computer, which includes at least a processor and memory, to perform a padding step, an encryption step, and a key generation step. In the padding step, if the bit length of the common key K1 assigned for use in communication between the terminal device 50 and the network 30 is shorter than the bit length of the input key K2 used in a predetermined algorithm E, padding is performed to make the bit length of the common key K1 the bit length of the input key K2. In the encryption step, a ciphertext Ci is generated by performing encryption processing on a predetermined plaintext m agreed upon between the terminal device 50 and the network 30 using the key generated in the padding step. In the key generation step, if the bit length of the ciphertext generated in the encryption step is shorter than the bit length of the input key K2, the encryption step is repeated and the processing is performed again until the bit length of the concatenated generated ciphertext is the same as or longer than the bit length of the input key K2, thereby generating a key with the same bit length as the input key K2. By adopting this configuration, the bit length of a given key can be expanded, and a key equal in size to the key used in the cryptographic algorithm can be generated.
[0038] Furthermore, the above-described embodiment makes it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation," by, for example, "expanding the bit length of a given key and generating a key equal in size to the key used in the cryptographic algorithm."
[0039] Although embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments, and design modifications and the like are also included within the scope of the gist of the present invention.
[0040] Alternatively, computer programs for realizing the functions of each of the above-mentioned devices may be recorded on a computer-readable recording medium, and the programs recorded on this recording medium may be loaded into a computer system and executed. Note that the term "computer system" here may include hardware such as an operating system and peripheral devices. Furthermore, "computer-readable recording media" refers to writable non-volatile memory such as flexible disks, magneto-optical disks, ROMs, and flash memory, portable media such as DVDs (Digital Versatile Discs), and storage devices such as hard disks built into computer systems.
[0041] Furthermore, "computer-readable recording media" also includes volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. In addition, the above program may be transmitted from the computer system that stores the program in a storage device, etc., to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" for transmitting the program refers to a medium that has the function of transmitting information, such as a network such as the Internet or a communication line such as a telephone line. Furthermore, the above program may be for the purpose of realizing a part of the above-mentioned functions. Moreover, it may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system. [Explanation of Symbols]
[0042] 1... Wireless system, 10... Processing unit, 30... Network, 50... Terminal device, K1... Common key, E... Algorithm, K2... Input key, m... Plaintext
Claims
1. A computer equipped with at least a processor and memory, If the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, a padding step is performed to make the bit length of the common key the bit length of the input key, An encryption step to generate ciphertext by performing a predetermined plaintext encryption process agreed upon between the terminal device and the network using the key generated by the padding step, If the bit length of the ciphertext generated by the encryption process is shorter than the bit length of the input key, the encryption process is repeated until the bit length of the concatenated generated ciphertext is the same as or longer than the bit length of the input key, and a key generation process is performed to generate a key having the same bit length as the input key. A computing device that performs the execution.
2. The predetermined plaintext used in the encryption process is different from one another depending on the number of iterations performed in the key generation process. The computing device according to claim 1.
3. The predetermined plaintext used in the encryption process is a time-dependent variable agreed upon in advance between the terminal device and the network. The computing device according to claim 1.
4. The bit length of the predetermined plaintext used in the encryption process is the same as the bit length of the input key divided by a natural number n of 1 or more. The key generation step generates a key having the same bit length as the input key by repeating the encryption step n times. The computing device according to claim 1.
5. The encryption step generates ciphertext using the AES (Advanced Encryption Standard) method or a stream cipher method. The computing device according to claim 1.
6. The bit length of the aforementioned common key is 128 bits, and the bit length of the aforementioned input key is 256 bits. The computing device according to claim 1.
7. A terminal device comprising the arithmetic unit according to any one of claims 1 to 6.
8. A network comprising the computing device described in any one of claims 1 to 6.
9. The aforementioned computing device is provided in at least one of the next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function), The network according to claim 8.
10. If the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, a padding step is performed to make the bit length of the common key the bit length of the input key, An encryption step to generate ciphertext by performing a predetermined plaintext encryption process agreed upon between the terminal device and the network using the key generated by the padding step, If the bit length of the ciphertext generated by the encryption process is shorter than the bit length of the input key, the encryption process is repeated until the bit length of the concatenated generated ciphertext is the same as or longer than the bit length of the input key, and a key generation process is performed to generate a key having the same bit length as the input key. A method of calculation.
11. On the computer, If the bit length of a common key assigned for use in communication between a terminal device and a network is shorter than the bit length of an input key used in a predetermined algorithm, a padding step is performed to make the bit length of the common key the bit length of the input key, An encryption step in which a ciphertext is generated by performing a predetermined plaintext encryption process agreed upon between the terminal device and the network using the key generated in the padding step, If the bit length of the ciphertext generated by the encryption step is shorter than the bit length of the input key, the encryption step is repeated until the bit length of the concatenated generated ciphertext is equal to or longer than the bit length of the input key, and a key generation step is performed to generate a key having the same bit length as the input key. A program that executes the command.