Computing unit, terminal device, network, calculation method and program
The arithmetic unit addresses the issue of identical ciphertexts by converting and adjusting key lengths and initialization values in stream ciphers, ensuring distinct ciphertexts for different bit length keys.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2026-04-01
AI Technical Summary
In the transition from 128-bit to 256-bit encryption, there is a challenge in distinguishing between keys of different bit lengths, leading to identical ciphertexts when expanding or compressing keys, which is undesirable.
An arithmetic unit that converts keys to a predetermined bit length by expanding or shortening, and adjusts constants or initial values in the stream cipher initialization process based on the bit length of the assigned key, using methods like AEGIS-256 and Rocca-S.
Ensures generation of different ciphertexts even when keys are obtained by expanding or compressing bit lengths, maintaining encryption integrity.
Smart Images

Figure 2026056421000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an arithmetic unit, a terminal device, a network, an arithmetic method, and a program.
Background Art
[0002] Conventional 3GPP (registered trademark) specifications are formulated on the premise of assigning a 128-bit key to a 128-bit cipher. For example, Non-Patent Document 1 defines the specific specifications of such a technology. Also, Non-Patent Documents 2 and 3 define the specific encryption specifications.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Non-Patent Document 2
Non-Patent Document 3
Summary of the Invention
[0004] Currently, discussions are underway to introduce 256-bit encryption. If 256-bit encryption is introduced, 256-bit keys and 128-bit keys will coexist. For example, a 128-bit key may be assigned to a 256-bit encryption. In order to use a 128-bit key with 256-bit encryption, the 128-bit key must be expanded to a 256-bit key. In this case, the key assigned as 256 bits and the 256-bit key obtained by expanding the 128-bit key will be indistinguishable from each other. Also, a 256-bit key may be assigned to a 128-bit encryption. In order to use a 256-bit key with 128-bit encryption, the 256-bit key must be compressed to a 128-bit key. In this case, the key assigned as 128 bits and the 128-bit key obtained by compressing the 256-bit key will be indistinguishable from each other.
[0005] In other words, there was a problem in that if the bit sequence of an assigned key and the bit sequence of a key obtained by expanding or shrinking the assigned key were identical, they could not be distinguished. Therefore, when encryption was performed using these keys, identical ciphertexts would be obtained. However, these keys originally had different bit sequences, and it is desirable that they produce different ciphertexts.
[0006] The present invention has been made in consideration of these circumstances, and its purpose is to provide a computing device, terminal device, network, and computing method that, even when performing encryption processing using a key obtained by expanding or contracting the bit length of the key, can generate different ciphertexts or decrypt ciphertexts if the bit sequences of the assigned keys are different. [Means for solving the problem]
[0007] (1) One aspect of the present invention is an arithmetic unit comprising at least a processor and memory, wherein when the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the arithmetic unit converts the assigned common key to a key of a predetermined bit length by expanding or shortening the bit length of the assigned common key, and performs encryption or decryption processing of a stream cipher, wherein at least one of the constants or initial values used for initializing the stream cipher differs depending on the bit length of the assigned common key. (2) In addition, in the arithmetic unit of (1) described above, the number of initializations of the stream cipher is made different from the number of initializations defined by the encryption method used in the encryption or decryption process of the stream cipher, thereby making the initial value used for initializing the stream cipher different according to the bit length of the assigned common key. (3) In addition, in one aspect of the present invention, in the computing device described in (1) or (2) above, the encryption method used for the encryption or decryption of the stream cipher is AEGIS-256. (4) In addition, in the arithmetic unit of (3) described above, at least one bit of the constant S2 or S3 among the 128-bit blocks S0 to S5 is different in the stream cipher initialization step according to the bit length of the common key that was assigned. (5) In addition, in one aspect of the present invention, in the computing device described in (1) or (2) above, the encryption method used for the encryption or decryption of the stream cipher is Rocca-S. (6) In addition, in the arithmetic unit of (5) described above, the value of at least one of the constants S[2] or S[1] among S[0] to S[6] which indicate the state of Rocca-S is different in the stream cipher initialization process according to the bit length of the common key that has been assigned. (7) In another aspect of the present invention, in the arithmetic unit of (5) described above, the value of S[6] among S[0] to S[6] which indicate the state of Rocca-S is different in the initialization process of the stream cipher according to the bit length of the common key that was assigned. (8) Another aspect of the present invention is a terminal device equipped with the arithmetic unit described in any of (1) to (7) above. (9) Another aspect of the present invention is a network comprising the computing device described in any of (1) to (7) above. (10) In another aspect of the present invention, in the network described in (9) above, the computing device is provided in at least one of the next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function). (11) Another aspect of the present invention is an arithmetic method to be performed by an arithmetic unit comprising at least a processor and memory, wherein if the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned common key is converted to a key of a predetermined bit length by expanding or shortening the bit length, and an encryption or decryption process of a stream cipher is performed, and at least one of the constants or initial values used for initializing the stream cipher differs depending on the bit length of the assigned common key. (12) Another aspect of the present invention is a program to be executed by an arithmetic unit comprising at least a processor and memory, wherein if the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the program converts the assigned common key to a key of a predetermined bit length by expanding or shortening the bit length of the common key, and performs encryption or decryption processing of a stream cipher, The program is such that, depending on the bit length of the assigned common key, at least one of the constants or initial values used to initialize the stream cipher differs. [Effects of the Invention]
[0008] According to the present invention, even when encryption processing is performed using a key obtained by expanding or contracting the bit length of the key, if the bit sequences of the assigned keys are different, it is possible to provide a computing device, terminal device, network, and computing method that can generate different ciphertexts or decrypt ciphertexts. [Brief explanation of the drawing]
[0009] [Figure 1] This figure shows a schematic architecture of a wireless system according to one embodiment. [Figure 2] This is a block diagram schematically representing the wireless system according to this embodiment. [Figure 3] This diagram illustrates the processing of the wireless system according to this embodiment when a 128-bit key is provided and when a 256-bit key is provided. [Figure 4] This is the first figure illustrating the initialization of blocks when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. [Figure 5] This is a second figure illustrating the initialization of blocks when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. [Figure 6] This figure shows an example of the correspondence between the number of bits in a key and a constant in the wireless system according to this embodiment. [Figure 7] This diagram illustrates the initialization of blocks when the Rocca-S encryption method is adopted in the wireless system according to this embodiment. [Figure 8] This is a block diagram showing an example of the internal configuration of the arithmetic unit according to this embodiment. [Modes for carrying out the invention]
[0010] [Embodiment] Preferred embodiments of an arithmetic unit, a terminal device, a network, an arithmetic method, and a program according to an aspect of the present invention will be described in detail below with reference to the accompanying drawings. Note that the aspects of the present invention are not limited to these embodiments, and also include those with various modifications or improvements. That is, the components described below include those that can be easily assumed by those skilled in the art and substantially the same components, and the components described below can be combined as appropriate. Also, various omissions, substitutions, or changes of the components can be made without departing from the gist of the present invention. Also, in the following drawings, in order to make each configuration easy to understand, the scale, number, etc. in each structure may be different from the scale, number, etc. in the actual structure.
[0011] In the following description, for convenience of explanation, terms and names defined in the IETF (Internet Engineering Task Force) and 3GPP (registered trademark) LTE (3rd Generation Partnership Project Long Term Evolution) standards may be used. However, this embodiment is not limited to such terms and names and is also applicable to systems based on other standards.
[0012] [Wireless System] FIG. 1 is a diagram showing a schematic architecture of a wireless system according to an embodiment. The wireless system 1 shown in the figure has, as a functional configuration, a control plane (C-Plane), which is a function for controlling communication, and a user plane (U-Plane), which is a function for realizing user communication. In the figure, for simplicity of explanation, a basic architecture used in the 5th Generation (5G) mobile communication system is shown, but the wireless system 1 to which this embodiment is applied is not limited to an example applied to 5G and is widely applicable to other systems.
[0013] In the following description, a component other than the UE (User Equipment) may be described as a network. The network includes an access stratum and a non-access stratum. The access stratum includes at least a base station, and the non-access stratum includes at least an AMF (Access and Mobility Management Function). As shown in the figure, the UE and the AMF cooperate with each other via the N1 interface. In the following description, the base station and the AMF may be described in a higher-level concept and simply referred to as the network.
[0014] FIG. 2 is a block diagram schematically showing a radio system according to the present embodiment. The figure schematically shows a part of the configuration of the radio system 1. The radio system 1 includes a network 30 and a terminal device 50. In the figure, as an example, one network and a plurality of terminal devices 50 are described. Specifically, as an example of the plurality of terminal devices 50, the terminal device 50-1, the terminal device 50-2,..., and the terminal device 50-m (m is a natural number of 1 or more) are described.
[0015] The network 30 communicates with the terminal device 50. The network 30 includes at least a base station. The base station may include the functions of an O-RU (Radio Unit), an O-DU (Distributed Unit), and an O-CU (Central Unit), for example, as defined by the O-RAN (Open-RAN) specifications.
[0016] Base stations are sometimes also called next generation Node B (gNodeB or gNB), en-gNB, Next Generation-Radio Access Network (NG-RAN) node, eNB, low-power node, CU, DU, RU, gNB-DU, Remote Radio Head (RRH), Integrated Access and Backhaul / Backhauling (IAB) node, etc. A base station is not limited to a single node, but may consist of multiple nodes (for example, a combination of lower-level nodes such as RU or DU and higher-level nodes such as CU).
[0017] The terminal device 50 is used by the user. Specific examples of the terminal device 50 include smartphones, tablet devices, wearable devices, etc. The terminal device 50 may also be referred to as a user device or UE.
[0018] Here, both the network 30 and the terminal device 50 are equipped with an arithmetic unit 10. The arithmetic unit 10 has at least a processor and memory as its hardware configuration. The arithmetic unit 10 may also have its functions realized by having a computer execute a program. The arithmetic unit 10 performs calculations to expand or compress the number of bits of a key used for encryption or decryption. The configurations of the arithmetic units 10 provided by the network 30 and the terminal device 50 may be the same or different. However, at least a part of the configuration of the arithmetic units 10 provided by the network 30 and the terminal device 50 shall be the same.
[0019] Furthermore, the location of the arithmetic unit 10 within the network 30 is arbitrary. For example, the arithmetic unit 10 may be located in the gNodeB or the AMF. Alternatively, the arithmetic unit 10 may be located in at least one of the gNodeB or the AMF within the network 30.
[0020] Figure 3 illustrates the processing in the case where a 128-bit key and a 256-bit key are provided to the wireless system according to this embodiment. Here, the wireless system 1 may be provided with a 128-bit key or a 256-bit key. Whether to perform encrypted communication using a 128-bit key or a 256-bit key is decided at the start of communication. Specifically, the network 30 and the terminal device 50 negotiate at the start of communication to determine the algorithm to be used.
[0021] If the negotiation results in the use of 128 bits and a 128-bit key is provided, it is possible to encrypt communication between parties using the 128-bit key directly. However, if a 256-bit key is provided, it is necessary to first compress the 256-bit key to 128 bits and then use the compressed 128-bit key to encrypt communication between parties. Figures 3(A) and 3(B) show an example where the negotiation results in the use of 128 bits. Figures 3(C) and 3(D) show an example where the negotiation results in the use of 256 bits.
[0022] Figure 3(A) shows an example where, as a result of negotiation, it is decided to use 128 bits and a 128-bit key is provided. In this case, the network 30 and the terminal device 50 can communicate with each other using encrypted communication with a 128-bit key.
[0023] Figure 3(B) shows an example where, as a result of negotiation, it is decided to use 128 bits and a 256-bit key is provided. In this case, both the network 30 and the terminal device 50 are required to compress the 256-bit key to 128 bits. The network 30 and the terminal device 50 then use the compressed key to perform encrypted communication with each other.
[0024] Figure 3(C) shows an example where, as a result of negotiation, it is decided to use 256 bits and a 128-bit key is provided. In this case, both the network 30 and the terminal device 50 need to expand the 128-bit key to 256 bits. The network 30 and the terminal device 50 then use the expanded key to perform encrypted communication with each other.
[0025] Figure 3(D) shows an example where, as a result of negotiation, it is decided to use 256 bits and a 256-bit key is provided. In this case, the network 30 and the terminal device 50 can communicate with each other using the 256-bit key in an encrypted manner.
[0026] Here, if the 128-bit key given in Figure 3(A) and the 128-bit key compressed from 256 bits in Figure 3(B) are identical, then despite the given keys being different, the encryption process will produce the same ciphertext for both. Similarly, if the 256-bit key given in Figure 3(D) and the 256-bit key expanded from 128 bits in Figure 3(C) are identical, then despite the given keys being different, the encryption process will produce the same ciphertext for both.
[0027] Thus, it is undesirable for the same ciphertext to be produced from two different sets of bit sequences. In other words, it is desirable that a given 128-bit key and a 128-bit key compressed based on a given 256-bit key be treated as different keys, and that different ciphertexts be generated from them. Similarly, it is desirable that a given 256-bit key and a 256-bit key expanded based on a given 128-bit key be treated as different keys, and that different ciphertexts be generated from them.
[0028] If we want to distinguish between key lengths, we need to provide information about the key length using a separate input parameter, distinct from the key itself. However, in the current specification, there is no input parameter to define the bit length of the key.
[0029] The following describes a method for performing encryption processing using a key obtained by expanding or contracting the bit length of the key, in which the bit length of the key before expansion or contraction is reflected in the encryption processing, and for generating different ciphertexts when the given keys are different. In this embodiment, the encryption or decryption processing of a stream cipher is assumed, but any encryption method can be used. Below, as examples of encryption methods, an example using AEGIS-256 and an example using Rocca-S will be described.
[0030] [AEGIS-256] Figure 4 is the first diagram illustrating the initialization of blocks when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. In AEGIS-256, 128-bit blocks are initialized as shown in the figure. The figure shows 128-bit blocks S0 to S5 from top to bottom. As shown in the figure, S2 is const1 and S3 is const0. That is, S2 and S3 are defined as constants.
[0031] Figure 5 is a second diagram illustrating the initialization of a block when the AEGIS-256 encryption scheme is adopted in the wireless system according to this embodiment. In AEGIS-256, a constant (const) is defined as a value formed by concatenating S3=const0 and S2=const1. S3=const0 can also be said to be the upper 16 bytes of const, and S2=const1 can be said to be the lower 16 bytes of const.
[0032] In this embodiment, for example, when a key smaller than 256 bits (e.g., a 128-bit key) is given and the given key is expanded for use with AEGIS-256, the key length is used as an input parameter and reflected in the value of const. For example, since the first byte of const is 00, this first byte is set to a value corresponding to the key length.
[0033] Furthermore, the input parameter for determining the key length is not limited to the example of using the first byte; any bit from the bits defined as constants may be used. That is, in each of the 128-bit blocks S0 to S5, at least one bit of the constant S2 or S3 may differ depending on the bit length of the assigned key during the initialization process of the stream cipher.
[0034] Figure 6 shows an example of the correspondence between the number of bits in a key and a constant in the wireless system according to this embodiment. In the figure, the number of bits in the assigned key is shown in the left column, and the value of the first byte of the const is shown in the right column, showing the correspondence between them. As shown in the figure, the value of the first byte can be defined as 01 when using a 192-bit key, 02 when using a 128-bit key, and 03 when using an 80-bit key.
[0035] Note that the illustrated example is just one example, and the value of the first byte of const can be any other value. For example, the value of const can be the number of bits in the key itself. For example, it is possible to define it as C0 for a 192-bit key, 80 for a 128-bit key, and 50 for an 80-bit key.
[0036] Furthermore, this example is not limited to cases where only a part of a block defined as a constant, such as the first byte of a const variable, is modified. It is also possible to prepare different initial values depending on the length of the bit sequence of the key being used.
[0037] [Rocca-S] Figure 7 illustrates the initialization of a block when the Rocca-S encryption method is adopted in the wireless system according to this embodiment. In the Rocca-S initialization process, first, N, K0, and K1 are loaded into S[0] to S[6] as shown in the figure. Here, S[2] is defined as the constant Z0, and S[4] is defined as the constant Z1. At least a portion of Z0 and Z1 may differ depending on the bit length of the assigned key, as explained with reference to Figure 6. In other words, among S[0] to S[6] which indicate the state of Rocca-S, at least one of the constants S[2] or S[1] differs in the stream cipher initialization process depending on the bit length of the assigned common key.
[0038] In addition to the example of changing at least one of the values of S[2]=Z0 or S[4]=Z1, the value of S[6]=0 may be set to be different depending on the bit length. For example, when using a 192-bit key, S[6] may be initialized to C000···0, when using a 128-bit key, to S[6]=8000···0, and when using an 80-bit key, to S[6]=5000···0. In other words, of the S[0] to S[6] values that indicate the state of Rocca-S, at least the value of S[6] will be different depending on the bit length of the shared key assigned during the initialization process of the stream cipher.
[0039] [Method based on the number of initialization rounds] Furthermore, with reference to Figures 4 to 7, an example has been described in which the constants used to initialize the stream cipher are varied according to the bit length of the assigned symmetric key. However, this embodiment is not limited to varying the constants, and the initial values may be varied by other methods. For example, the number of initialization rounds can be changed according to the bit length of the assigned symmetric key.
[0040] Specifically, in AEGIS-256, the number of initialization rounds is defined as R=16. For example, the number of initialization rounds may be R+a rounds depending on the bit length of the assigned common key. More specifically, the value of a is a natural number greater than or equal to 1, and a=0 may be used when using a 256-bit key, a=1 when using a 192-bit key, a=2 when using a 128-bit key, and a=3 when using an 80-bit key. Similarly, in Rocca-S, the number of initialization rounds is also defined as R=16. In Rocca-S, as in AEGIS-256, the number of initialization rounds may be R+a rounds depending on the bit length of the assigned common key.
[0041] In other words, by making the number of initializations of the stream cipher different from the number of initializations defined by the encryption scheme used in the encryption or decryption process of the stream cipher, the initial value used to initialize the stream cipher may be made different depending on the bit length of the assigned common key.
[0042] It could be argued that varying the number of initialization rounds according to the bit length (specifically, performing +a rounds) would increase the initialization time, but this difference is negligible and can be ignored.
[0043] [Internal structure] Figure 8 is a block diagram showing an example of the internal configuration of the arithmetic unit according to this embodiment. The arithmetic unit 10 is provided in at least one of the terminal device 50 or the network 30. If the bit length of the common key assigned for use in communication between the terminal device 50 and the network 30 differs from the bit length of the input key used in a predetermined algorithm, the arithmetic unit 10 converts the assigned common key to a key of the predetermined bit length by expanding or shortening the bit length, and then performs encryption or decryption processing of the stream cipher.
[0044] At least some of the functions of the arithmetic unit 10 can be realized using a computer as shown in the figure. This computer consists of a central processing unit (processor) 901, RAM 902, input / output ports 903, input / output devices 904 and 905, etc., and a bus 906. The computer itself can be realized using existing technology. The central processing unit 901 executes instructions contained in programs read from RAM 902, etc. The central processing unit 901 writes data to RAM 902, reads data from RAM 902, and performs arithmetic and logical operations according to each instruction. RAM 902 stores data and programs. Each element contained in RAM 902 has an address and can be accessed using that address. RAM stands for "Random Access Memory". Input / output ports 903 are ports for the central processing unit 901 to exchange data with external input / output devices, etc. Input / output devices 904 and 905 are input / output devices. Input / output devices 904 and 905 exchange data with the central processing unit 901 via input / output ports 903. Bus 906 is a common communication channel used within the computer. For example, the central processing unit 901 reads and writes data to RAM 902 via bus 906. Also, for example, the central processing unit 901 accesses input / output ports via bus 906. Furthermore, all or part of each functional unit of the network 30 or terminal device 50 may be implemented using hardware such as ASICs, PLDs, or FPGAs. Furthermore, all or part of each functional unit may be implemented by a combination of software and hardware.
[0045] [Summary of Embodiments] According to the embodiments described above, the arithmetic unit 10 comprises at least a processor and memory. When the bit length of a common key assigned for communication between the terminal device 50 and the network 30 differs from the bit length of an input key used in a predetermined algorithm, the arithmetic unit 10 converts the assigned common key to a key of a predetermined bit length by expanding or shortening its bit length, and then performs encryption or decryption processing of the stream cipher. The arithmetic unit 10 changes at least one of the constants or initial values used for initializing the stream cipher depending on the bit length of the assigned common key. By adopting such a configuration, when performing encryption processing using a key obtained by expanding or shortening the bit length of the key, the bit length of the key before expansion or shortening can be reflected in the encryption processing.
[0046] According to this embodiment, since the bit length of the key before expansion or reduction is reflected in the encryption process, if the bit lengths before expansion or reduction are different, even if the bit sequences of the keys obtained by expanding or reducing the bit length are the same, different ciphertexts can be obtained. In other words, according to this embodiment, even when performing encryption processing using a key obtained by expanding or reducing the bit length of the key, if the bit sequences of the assigned keys are different, different ciphertexts can be generated or the ciphertexts can be decrypted.
[0047] Furthermore, the above-described embodiment makes it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation," by, for example, "reflecting the bit length of the key before expansion or reduction in the encryption process when performing encryption using a key obtained by expanding or reducing the bit length of the key."
[0048] Although embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments, and design modifications and the like are also included within the scope of the gist of the present invention.
[0049] Alternatively, computer programs for realizing the functions of each of the above-mentioned devices may be recorded on a computer-readable recording medium, and the programs recorded on this recording medium may be loaded into a computer system and executed. Note that the term "computer system" here may include hardware such as an operating system and peripheral devices. Furthermore, "computer-readable recording media" refers to writable non-volatile memory such as flexible disks, magneto-optical disks, ROMs, and flash memory, portable media such as DVDs (Digital Versatile Discs), and storage devices such as hard disks built into computer systems.
[0050] Furthermore, "computer-readable recording media" also includes volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. In addition, the above program may be transmitted from the computer system that stores the program in a storage device, etc., to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" for transmitting the program refers to a medium that has the function of transmitting information, such as a network such as the Internet or a communication line such as a telephone line. Furthermore, the above program may be for the purpose of realizing a part of the above-mentioned functions. Moreover, it may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system. [Explanation of Symbols]
[0051] 1... Wireless system, 10... Computing unit, 30... Network, 50... Terminal device
Claims
1. Equipped with at least a processor and memory, A arithmetic unit that, when the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, converts the assigned common key to a key of a predetermined bit length by expanding or shortening the bit length of the common key, and then performs encryption or decryption processing of a stream cipher, Depending on the bit length of the assigned common key, at least one of the constants or initial values used to initialize the stream cipher differs. Computing device.
2. By making the number of initializations of the stream cipher different from the number of initializations defined by the encryption method used in the encryption or decryption process of the stream cipher, the initial value used for initializing the stream cipher is made different according to the bit length of the assigned common key. The computing device according to claim 1.
3. The encryption method used for the encryption or decryption of the aforementioned stream cipher is AEGIS-256. The computing device according to claim 1.
4. Of the 128-bit blocks S0 to S5, at least one of the constant bits of S2 or S3 differs in the stream cipher initialization process according to the bit length of the assigned common key. The computing device according to claim 3.
5. The encryption method used for the encryption or decryption of the stream cipher is Rocca-S. The computing device according to claim 1.
6. Among the S[0] to S[6] that indicate the state of Rocca-S, the value of at least one of the constants S[2] or S[1] differs in the initialization process of the stream cipher according to the bit length of the assigned common key. The arithmetic device according to claim 5.
7. Of the S[0] to S[6] values indicating the state of Rocca-S, the value of S[6] differs depending on the bit length of the shared key assigned during the initialization process of the stream cipher. The arithmetic device according to claim 5.
8. A terminal device comprising the computing device described in any one of claims 1 to 7.
9. A network comprising the computing device according to any one of claims 1 to 7.
10. The aforementioned computing device is provided in at least one of the next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function), The network according to claim 9.
11. A method of calculation performed by an arithmetic unit comprising at least a processor and memory, If the bit length of a shared key assigned for communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned shared key is converted to a key of the predetermined bit length by expanding or shortening its bit length, and then the encryption or decryption process of the stream cipher is performed. Depending on the bit length of the assigned common key, at least one of the constants or initial values used to initialize the stream cipher differs. Calculation method.
12. A program to be executed by a computing device that includes at least a processor and memory, If the bit length of a shared key assigned for communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned shared key is converted to a key of the predetermined bit length by expanding or shortening its bit length, and then the encryption or decryption process of the stream cipher is performed. Depending on the bit length of the assigned common key, at least one of the constants or initial values used to initialize the stream cipher differs. program.