Method and System for Compression Encryption

By reusing encryption parameters and incorporating a blackout signature scheme, the method addresses the resilience issues of current encryption methods against quantum computer attacks, achieving substantial efficiency gains in data transmission.

JP7691998B2Active Publication Date: 2025-06-12PEE Q SHIELD LT D
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2022558211
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-04-08
Filing Date
2021-04-06
Publication Date
2025-06-12
Estimated Expiration
2041-04-06

AI Technical Summary

Technical Problem

Current encryption methods are not resilient to attacks based on quantum computers, and new methods under development lack maturity and depth, particularly in terms of size and communication requirements.

Method used

A method that reduces the size of encryption updates and encrypted messages by reusing parameters in both pre-quantum and post-quantum encryption schemes, combined with a blackout or erasure signature scheme, to achieve efficiency gains in data transmission.

Benefits of technology

This approach results in a significant reduction in data transmitted during encrypted message transmission, leading to improved efficiency and performance, especially when transmitting multiple encryption methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691998000004
    Figure 0007691998000004
  • Figure 0007691998000005
    Figure 0007691998000005
  • Figure 0007691998000006
    Figure 0007691998000006
Patent Text Reader

Abstract

Disclosed herein are methods and systems for transmitting multiple ciphertexts to multiple users. The systems and methods described herein provide for performing encryption updates involving multiple encryption keys and multi-ciphertexts to multiple recipient nodes. Methods and systems for organizing a database are also disclosed herein.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Background

[0001] With the imminent arrival of practical large-scale quantum computing, several security issues are associated, among which the particularly important one is that the currently used encryption methods are not resilient to attacks based on quantum computers. Therefore, new encryption methods are under development, but they tend to lack the maturity and depth of more established methods, including the size of the methods and communication requirements.

Summary of the Invention

Means for Solving the Problems

[0002] Summary

[0002] In one aspect, the present disclosure provides a method for reducing the size of encryption updates and other encrypted messages generated using both pre-quantum and post-quantum encryption schemes. By reusing at least some of the parameters used in the encryption process, one copy of those parameters can be sent along with the encryption to reduce the amount of data transmitted. Since one copy can be used instead of one copy per message, a large efficiency gain can be achieved. This reuse also enables the use of a more preferred organizational hierarchy and can improve performance when transmitting multiple encryption methods compared to non-reuse schemes. Combining the reuse of parameters with a blackout or erasure signature scheme can lead to a large reduction on the server side of the data transmitted during the transmission of encrypted messages, resulting in an efficiency gain.

[0003]

[0003] In another aspect, the present disclosure provides a method for transmitting a ciphertext including a plurality of encrypted portions to a plurality of users, the method including: (a) providing a common set of system parameters for the plurality of users; (b) generating a plurality of encrypted portions by encrypting plaintext using parameters unique to each user of the plurality of users; (c) generating a ciphertext including a portion derived from the common set of system parameters and the plurality of encrypted portions; and (d) transmitting the ciphertext to the plurality of users, the ciphertext being decodable at least in part using parameters unique to each user of the plurality of users.

[0004]

[0004] In some embodiments, the encrypted portions are encrypted using a lattice-based encryption method. In some embodiments, the encrypted portions are encrypted using an isogeny-based encryption method. In some embodiments, the common set of system parameters is generated using a seed and a pseudorandom number generator. In some embodiments, at least some of the parameters unique to each user of the plurality of users are generated using a seed and a pseudorandom number generator. In some embodiments, the common set of system parameters or the parameters unique to each user of the plurality of users includes a non-square matrix.

[0005]

[0005] In another aspect, the present disclosure provides a method for transmitting a ciphertext to a plurality of users, the method including: (a) generating a system parameter set, the parameter set including parameters independent of the public keys of the users among the plurality of users; (b) generating a fixed component based at least in part on the system parameter set; (c) generating a plurality of variable components by encrypting plaintext using each public key of the plurality of users; and (d) transmitting a ciphertext including the fixed component and the variable components to the plurality of users, the ciphertext being decodable at least in part using the fixed component.

[0006]

[0006] In some embodiments, the encryption is based on an encryption method selected from the group consisting of the Lindner-Peikert scheme, the supersingular isogeny Diffie-Hellman protocol, and the isogeny-based public key encryption method.

[0007]

[0007] In another aspect, the present disclosure provides a method of compiling a database, the method comprising: (a) structuring a plurality of recipients in a tree structure of item number m, where "m" is at least 2; and (b) sending compressed ciphertext updates to less than all of the plurality of recipients.

[0008]

[0008] In some embodiments, the number of terms m is at least about 8. In some embodiments, the number of terms m is from about 8 to about 16. In some embodiments, the number of bytes used for transmission is less than or equal to about 1 / 2 of the number of bytes for transmitting to each of multiple recipients. In some embodiments, the compressed ciphertext update is encrypted using a lattice-based encryption method. In some embodiments, the compressed ciphertext update is encrypted using an encryption method based on isomorphisms. In some embodiments, transmitting includes transmitting the same message to each node of a tree structure. In some embodiments, the same message includes update information of the encryption key of the user of the database. In another aspect, the present disclosure provides a method for performing an encrypted update including a plurality of encryption keys and multi-ciphertexts on multiple recipient nodes, the method including: (a) receiving the encrypted update; (b) generating a reduced encrypted update by removing one or more of the plurality of encryption keys and one or more ciphertexts of the multi-ciphertext; (c) transmitting the reduced encrypted update to a recipient node among the multiple recipient nodes; and (d) repeating (b) to (c) for one or more other nodes among the multiple nodes. In some embodiments, each node receives a reduced encrypted update including one encryption key of the plurality of encryption keys and one ciphertext of the multi-ciphertext. In some embodiments, each node of the multiple nodes receives a reduced encrypted update including a different encryption key of the plurality of encryption keys and a different ciphertext of the multi-ciphertext from each other node among the multiple nodes. In some embodiments, the recipient node has child nodes. In some embodiments, the child nodes can access the decryption key of each recipient node in the path of the child node. In some embodiments, (d) is performed substantially simultaneously with each node of the multiple nodes. In some embodiments, the method further includes reducing the number of bytes transmitted to the multiple nodes to less than or equal to about 1 / n, where n is the number of nodes among the multiple nodes. In some embodiments, one or more ciphertexts are encrypted using a lattice-based encryption method.In some embodiments, one or more ciphertexts are encrypted using an encryption method based on a homogeneous mapping. In some embodiments, the encryption update is signed using a blacked-out signature. In some embodiments, the blacked-out signature facilitates removing one or more of a plurality of encryption keys and a plurality of multi-ciphertexts.

[0009]

[0009] Another aspect of the present disclosure provides a non-transitory computer-readable medium including machine-executable code that, when executed by one or more computer processors, implements any of the above methods or the methods elsewhere in this specification.

[0010]

[0010] Another aspect of the present disclosure provides a system including one or more computer processors and a computer memory coupled thereto. The computer memory includes machine-executable code that, when executed by one or more computer processors, implements any of the above methods or the methods elsewhere in this specification.

[0011]

[0011] Additional aspects and advantages of the present disclosure will become readily apparent to those skilled in the art from the following detailed description, which illustrates merely exemplary embodiments of the present disclosure. As will be recognized, the present disclosure is capable of other different embodiments, and some of the details thereof are capable of various obvious modifications all without departing from the present disclosure. Accordingly, the drawings and description are to be regarded as illustrative in nature and not as restrictive.

[0012] Incorporation by reference

[0012] All published publications, patents, and patent applications cited herein are hereby incorporated by reference into this specification to the same extent as if each individual published publication, patent, or patent application were specifically and individually indicated to be incorporated by reference. To the extent that the incorporated published publications and patents or patent applications conflict with the disclosure contained herein, this specification supersedes and / or is intended to take precedence over any such conflicting material.

[0013] Brief Description of the Drawings

[0013] The novel features of the present invention are particularly described in the appended claims. A better understanding of the features and advantages of the present invention can be obtained by referring to the following detailed description of exemplary embodiments in which the principles of the present invention are utilized and the accompanying drawings (likewise "Figure" and "FIG." in this specification).

Brief Description of the Drawings

[0014]

Figure 1

[0014] It is a flowchart of an example process for sending multiple ciphertexts to multiple users.

Figure 2

[0015] It is a flowchart of an example process for sending multiple ciphertexts to multiple users.

Figure 3

[0016] It is a flowchart of an example process for performing an encryption update including multiple encryption keys and multiple multi-ciphertexts for multiple recipient nodes.

Figure 4A

[0017] An example of the Lindner-Peikert framework is shown.

Figure 4B

[0017] An example of the Lindner-Peikert framework is shown.

Figure 4C

[0017] An example of the Lindner-Peikert framework is shown.

Figure 4D

[0018] An example of pseudo-code of an implementation of ciphertext compression of a single message sent to one or more recipients is shown.

Figure 5A

[0019] An example of pseudo-code of an implementation of ciphertext compression of one or more messages sent to one or more recipients is shown.

Figure 5B

[0020] An example of pseudo-code of an implementation of the SIKE public-key encryption method is shown.

Figure 5C

[0020] An example of pseudo-code of an implementation of the SIKE public-key encryption method is shown.

Figure 5D

[0020] Shows a pseudocode example of an implementation form of the SIKE public key encryption method.

Figure 6A

[0021] Shows a pseudocode example of an implementation form of ciphertext compression in the SIKE public key encryption method for one message sent to one or more recipients.

Figure 6B

[0022] Shows a pseudocode example of an implementation form of ciphertext compression in the SIKE public key encryption method for one or more messages sent to one or more recipients.

Figure 7A

[0023] Shows plots of update sizes in multiple different situations using the Kyber512 key encapsulation mechanism.

Figure 7B

[0024] Shows plots of update sizes in multiple different situations using the FrodoKEM-640 key encapsulation mechanism.

Figure 7C

[0025] Shows plots of update sizes in multiple different situations using the SIKE / p434 key encapsulation mechanism.

Figure 8

[0026] Shows a table of efficiency improvement in using a ciphertext compression method and system using various encryption methods.

Figure 9

[0027] Shows an example of supersingular isogeny Diffie-Hellman key exchange (SIDH).

Figure 10A

[0028] Shows multiple protocols that can be used in conjunction with ciphertext compression.

Figure 10B

[0028] Shows multiple protocols that can be used in conjunction with ciphertext compression.

Figure 10C

[0028] Shows multiple protocols that can be used in conjunction with ciphertext compression.

Figure 10D

[0028] Shows multiple protocols that can be used in conjunction with ciphertext compression.

Figure 10E

[0028] Shows multiple protocols that can be used in conjunction with ciphertext compression.

Figure 11

[0029] Shows a computer system configured by a program or other means to implement the method provided in this specification.

Figure 12A

[0030] Shows a pseudocode example of one implementation of the commuting supersingular isogeny Diffie-Hellman (cSIDH) public-key encryption method.

Figure 12B

[0030] Shows a pseudocode example of one implementation of the commuting supersingular isogeny Diffie-Hellman (cSIDH) public-key encryption method.

Figure 12C

[0030] Shows a pseudocode example of one implementation of the commuting supersingular isogeny Diffie-Hellman (cSIDH) public-key encryption method.

Figure 12D

[0030] Shows a pseudocode example of one implementation of the commuting supersingular isogeny Diffie-Hellman (cSIDH) public-key encryption method.

Figure 12D

[0031] Shows a pseudocode example of one implementation of ciphertext compression of a single message sent to one or more recipients.

Embodiments for Carrying Out the Invention

[0015] Detailed Description

[0032] Various embodiments of the present invention are shown and described herein, but it will be apparent to those skilled in the art that such embodiments are provided merely as examples. Without departing from the present invention, many variations, modifications, and substitutions can be conceived by those skilled in the art. It should be understood that various alternative forms to the embodiments of the present invention described herein can be adopted.

[0016]

[0033] When the terms “at least,” “greater than,” or “above” precede the first numerical value in a series of two or more numerical values, the terms “at least,” “greater than,” or “above” always apply to each numerical value in that series of numerical values. For example, 1, 2, 3 or more is equivalent to 1 or more, 2 or more, or 3 or more.

[0017]

[0034] If the terms "not exceeding", "less than", or "below" precede the first numerical value in a series of two or more numerical values, the terms "not exceeding", "less than", or "below" shall always apply to each numerical value in the series. For example, 3, 2, or 1 below is equivalent to 3 below, 2 below, or 1 below.

[0018]

[0035] As used herein, the term "ciphertext" generally refers to encrypted text. Encryption can be encryption performed by an algorithm. The text can be numbers (e.g., binary representation), characters, words, etc., or any combination thereof. The ciphertext can be encrypted plaintext. The ciphertext can be an encrypted message. A multi-ciphertext can be one or more ciphertexts in the same package.

[0019]

[0036] As used herein, the term "public key" generally refers to an encryption key used for encryption. The public key does not have to be kept secret. The public key can be accessible by a user (e.g., a user sending a message), a service (e.g., software running on a suitably configured computer), or any other sender / receiver of an encrypted object. The public key can be used to encrypt plaintext into ciphertext. For example, a user, Alice, can use the public key of another user, Bob, to encrypt plaintext, and the ciphertext can be decrypted only by Bob.

[0020]

[0037] As used herein, the term "private key" generally refers to an encryption key used for decryption. The private key can be kept secret from a user (e.g., a user sending a message), a service (e.g., software running on a suitably configured computer), or any other sender / receiver of an encrypted object. The private key can be used to decrypt ciphertext into plaintext.

[0021]

[0038] As used herein, the term "encryption scheme" generally refers to methods of encryption and decryption. The encryption scheme can be a lattice-based scheme. Examples of encryption schemes can be public-key encryption, symmetric-key encryption (e.g., Advanced Encryption Standard (AES)), Round5, Saber, NewHope, Kyber, FrodoKEM, and supersingular isogeny key encapsulation. The encryption scheme can be a key encapsulation mechanism (KEM). The encryption scheme can be a code-based encryption scheme. Examples of code-based encryption schemes can be BIKE-3, ROLLO-3, HQC, RQC, etc. Other examples of lattice-based, code-based, or other encryption schemes can be found in the National Institutes for Standards and Testing (NIST) Post-Quantum Cryptography project files, such as the "Status Report on the First Round of the NIST Post-Quantum Cryptography Standardization Process" by Alagic et al. issued on January 31, 2019 (DOI: 10.6028 / NIST.IR.8240), which is hereby incorporated by reference in its entirety. The encryption scheme can be a public-key encryption scheme (PKE).

[0022]

[0039] Multi-ciphertexts can be used in implementing a ciphertext compression scheme. For example, using multi-ciphertexts to reduce the amount of data transmitted during key exchange can be ciphertext compression. Thus, these terms can be related throughout the present disclosure. A multi-ciphertext can include multiple ciphertexts.

[0023]

[0040] The present disclosure provides a method and system for sending a ciphertext including a plurality of encrypted parts to a plurality of users. The method of sending a ciphertext including a plurality of encrypted parts to a plurality of users may include providing a common set of system parameters for the plurality of users. The plurality of encrypted parts may be generated by encrypting a plaintext using parameters unique to each of the plurality of users. A ciphertext including parts derived from the common set of system parameters and the plurality of encrypted parts may be sent to the plurality of users. The plurality of ciphertexts may be at least partially decryptable using parameters unique to each of the plurality of users.

[0024]

[0041] Figure 1 shows a flowchart of a process 100 for sending a plurality of ciphertexts to a plurality of users. In operation 110, process 100 may include providing a common set of system parameters to a plurality of users. The plurality of ciphertexts can be at least about 2, 3, 4, 5, 6, 7, 8, 9, 10, 50, 100, 250, 500, 1,000, 5,000, 10,000, 50,000, 100,000, 500,000, 1,000,000 or more than 1,000,000 ciphertexts. The plurality of ciphertexts can be at most about 1,000,000, 500,000, 100,000, 50,000, 10,000, 5,000, 1,000, 500, 250, 100, 50, 10, 9, 8, 7, 6, 5, 4, 3, 2 or less than 2 ciphertexts. The number of users among the plurality of users can be greater than, equal to or less than the number of ciphertexts among the plurality of ciphertexts. For example, 500 ciphertexts can be generated to be sent to 1,000 users. The plurality of users can be, for example, server clients (e.g., client devices that receive updates from a server, intermediate servers that receive updates and communicate them to other clients), messaging recipients, website visitors, system receiving software updates, etc. Messaging recipients can be recipients of digital messages (e.g., emails, Short Message Service (SMS), Multimedia Messaging Service (MMS)). Systems that receive software updates can be server devices (e.g., computing clusters), end-user devices (e.g., laptop computers, desktop computers, smartphones, tablets), etc. For example, a central server can output updates received by a plurality of server nodes. In another example, a desktop computer can output peer-to-peer updates to another desktop computer. The ciphertexts can be encryption methods based on lattices, encryption methods based on isomorphisms (e.g., encryption methods based on super-special isomorphisms), encryption methods based on prime factorizations, other encryption methods described elsewhere in this specification, etc. The encryption method can be a post-quantum encryption method (e.g., a method that is more resilient to attacks by non-classical computers).The encryption method can be a pre-quantum encryption method (e.g., currently used encryption methods). The encryption method can operate at a chosen ciphertext attack (CCA) security level. The encryption method can operate at a chosen plaintext attack (CPA) security level.

[0025]

[0042] The common set of system parameters may not depend on the public keys of users among multiple users. For example, the common set of system parameters can be common to each of multiple users. The common set of system parameters can be related to the type of encryption method used for generating ciphertexts. For example, in an encryption method based on a homomorphic mapping, the common set of system parameters can be a large integer. In another example, the common set of system parameters can be one or more matrices including numbers or polynomials. The common set of system parameters can provide a detailed description of an instance of the encryption method. For example, the common set of system parameters of a lattice-based encryption method can be different from the common set of parameters of a prime factorization-based encryption method. In another example, the system parameters can be an example of an encryption method used as a template. At least one parameter of the common set of system parameters can be generated using a seed and a pseudorandom number generator. For example, a message encrypted as a ciphertext can be converted into a numerical seed and supplied to a pseudorandom number generator to generate system parameters. The common set of system parameters can be compressed. The compression can be non-invertible compression or invertible compression. For example, the size of one or more parameters can be reduced by dropping lower bits. The common set of system parameters can be represented as A elsewhere in this specification.

[0026]

[0043] In another operation 120, process 100 may include generating a plurality of encrypted portions by encrypting plaintext using parameters unique to each of a plurality of users. The parameters unique to each of the plurality of users may include one or more public keys. For example, a user, Alice, can encrypt a message to another user, Bob, using Bob's public key, and the ciphertext sent from Alice to Bob includes the encrypted message. The public key may include one or more encryption keys, one or more verification keys, one or more identification numbers, etc., or any combination thereof. The ciphertext may include a fixed portion and a variable portion. The fixed portion may depend on a common set of system parameters. The fixed portion may be the same for each of the plurality of users. The fixed portion may be referred to as U elsewhere in this specification. The variable portion may depend on a common set of system parameters and parameters unique to each of the plurality of users (e.g., the public keys of each of the plurality of users). The variable portion may be referred to as V elsewhere in this specification. At least one parameter of the parameters unique to each of the plurality of users may be generated using a seed and a pseudo-random number generator. For example, a seed including a user's public key may be input into a pseudo-random number generator to generate parameters unique to the user. In another example, a seed may be input into a pseudo-random number generator to generate a user's public key. The common set of system parameters may include one or more non-square matrices. The parameters unique to each of the plurality of users may include one or more non-square matrices. The non-square matrix may include numbers, polynomials, other equations, etc. Encrypting may be encrypting by an encryption method described elsewhere in this specification. The parameters unique to each of the plurality of users may be referred to as public keys elsewhere in this specification.

[0027]

[0044] In another operation 130, process 100 may include generating a ciphertext that includes a portion derived from a common set of system parameters and a plurality of encrypted portions. In another operation 140, process 100 may include sending the ciphertext to a plurality of users. The plurality of ciphertexts may be decryptable using parameters unique to each of the plurality of users, at least in part. The plurality of ciphertexts may be combined into a single multi-ciphertext. For example, a single transmission may include the plurality of ciphertexts. The transmission may be via a communication protocol (e.g., Internet Protocol (IP), Transmission Control Protocol (TCP), Hypertext Transfer Protocol (HTTP), or a secure variant thereof such as HTTPS, etc.). The transmission may be in a manner as shown in any of FIGS. 10A-10E. The transmission may include sending the common set of system parameters and the plurality of ciphertexts to a distributor, and the distributor may send the common set of system parameters and one of the plurality of ciphertexts to each of the plurality of users.

[0028]

[0045] The common set of system parameters may be generated, at least in part, by a probability distribution. Using a probability distribution for parameter generation may impart additional security to the methods and systems described herein. The probability distribution may be such that the parameters generated using the probability distribution are in a finite ring R such that parameter ∈ R, where R = Z q or R = Z q / m can be satisfied, where Z q is the integer modulo q and m is a monic polynomial).

[0029]

[0046] The present disclosure provides a method and system for sending ciphertexts to multiple users. The method for sending ciphertexts to multiple users may include generating a system parameter set. The system parameter set may include parameters that do not depend on the public keys of the users among the multiple users. A fixed component may be generated at least partially based on the system parameter set. Multiple variable components may be generated by encrypting the plaintext using each public key of the multiple users. The encryption may be based on an encryption method selected from the group consisting of the Lindner-Peikert method, the supersingular isogeny Diffie-Hellman protocol, and a public key encryption method based on isogeny. The ciphertext including the fixed component and the variable components may be sent to the multiple users. The ciphertext may be decryptable using at least partially the fixed component. The ciphertext may be a multi-ciphertext.

[0030]

[0047] The present disclosure provides a method and system for compiling a database. The method for compiling a database may include structuring multiple recipients in a tree structure with the number of terms "m". The number of terms "m" may be at least 2. Compressed ciphertext updates may be sent to less than all of the multiple recipients.

[0031]

[0048] Figure 2 is a flowchart of an example process 200 for sending a plurality of ciphertexts to a plurality of users. In operation 210, process 200 may include structuring a plurality of recipients in a tree structure with an arity m. The arity can be the maximum number of child nodes that a node of the tree can have. For example, a tree with an arity of 4 can have a maximum of 4 child nodes per node. Examples can be seen in FIG. 10D showing a tree with an arity of 2 and FIG. 10E showing a tree with an arity of 4. The arity "m" can be at least about 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 50, 100, 250, 500, 1,000 or more than 1,000. The arity "m" can be at most about 1,000, 500, 250, 100, 50, 25, 24, 23, 22, 21, 20, 19, 18, 17, 16, 15, 14, 13, 12, 11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1 or less than 1. The arity "m" can be within a range defined by any two of the above points. For example, the tree can have an arity of 8 to 16. The plurality of recipients can be other nodes of the tree. Other nodes of the tree can have their own child nodes. For example, the plurality of recipients of an update from node 1 in FIG. 10E can be nodes including nodes 2, 3, and 4 and nodes 18, 19, and 20. Nodes of the tree structure can be configured to accommodate information used for encrypting that node or any child node of that node.

[0032]

[0049] In another operation 220, process 200 may include transmitting a compressed ciphertext update to less than all of the plurality of recipients. The transmission may be a transmission via a network. The network may be a public network (e.g., the Internet) or a private network (e.g., a local network). The compressed ciphertext update may be generated by the methods and systems described elsewhere in this specification. The compressed ciphertext update may be encrypted using a lattice-based encryption method, an encryption method based on a homogeneous mapping, etc. The number of bytes for transmitting the compressed ciphertext update may be at least about 1 / 1.1, 1 / 1.2, 1 / 1.3, 1 / 1.4, 1 / 1.5, 1 / 1.6, 1 / 1.7, 1 / 1.8, 1 / 1.9, 1 / 2, 1 / 2.5, 1 / 3, 1 / 3.5, 1 / 4, 1 / 4.5, 1 / 5, 1 / 5.5, 1 / 6, 1 / 6.5, 1 / 7, 1 / 7.5, 1 / 8, 1 / 8.5, 1 / 9, 1 / 9.5, 1 / 10, 1 / 11, 1 / 12, 1 / 13, 1 / 14, 1 / 15, 1 / 16, 1 / 17, 1 / 18, 1 / 19, 1 / 20, 1 / 21, 1 / 22, 1 / 23, 1 / 24, 1 / 25 or more less than the number of bytes for transmitting the update to each of the plurality of recipients. The number of bytes for transmitting the compressed ciphertext update may be at most about 1 / 25, 1 / 24, 1 / 23, 1 / 22, 1 / 21, 1 / 20, 1 / 19, 1 / 18, 1 / 17, 1 / 16, 1 / 15, 1 / 14, 1 / 13, 1 / 12, 1 / 11, 1 / 10, 1 / 9.5, 1 / 9, 1 / 8.5, 1 / 8, 1 / 7.5, 1 / 7, 1 / 6.5, 1 / 6, 1 / 5.5, 1 / 5, 1 / 4.5, 1 / 4, 1 / 3.5, 1 / 3, 1 / 2.5, 1 / 2, 1 / 1.9, 1 / 1.8, 1 / 1.7, 1 / 1.6, 1 / 1.5, 1 / 1.4, 1 / 1.3, 1 / 1.2, 1 / 1.1 or less than the number of bytes for transmitting the update to each of the plurality of recipients.

[0033]

[0050] Transmission may include sending the same message to each node of a tree structure. The message may include update information of a user's key in a database. For example, a user can send a key update to each node of a tree structure. In another example, a user can send a key update to each node at a specific level of a tree using a compressed ciphertext. The message can be a message as described elsewhere in this specification (e.g., a text message, a software update, an encryption key update). Transmission may include sending different messages to each node of a tree structure. For example, different encrypted messages can be sent from a user to each of a plurality of other users. Transmission may include sending several different messages to each node of a tree structure that is less than the number of nodes of the tree structure. For example, each node at a specific depth can receive the same message. In this example, a tree with an order of 4 and a depth of 2 can have one message sent to three nodes that are children of the same parent node and another message sent to a node that shares a parent with the parent, for a total of 6 updates sent. In this example, by sending 6 updates instead of 15 when sent without using a ciphertext compression method, the number of bytes for sending a compressed ciphertext update is 1 / (15 / 6)=1 / 2.5 of the number of bytes for sending an update to each of the recipients. In another example, a tree with an order of 4 and a depth of 2 where child nodes can access the decryption key in the path of the node can be updated by sending a multi-ciphertext to two nodes such as nodes 17 and 21 of FIG. 10E. In this example, the communication cost can be improved to 1 / (15 / 2)=1 / 7.5 compared to sending an update to each node of a plurality of nodes. Transmission may include sending d ciphertexts as a multi-ciphertext, where d = log m N, where m is the order of the tree and N is the number of recipient (e.g., user) nodes.

[0034]

[0051] The present disclosure provides a method and system for performing an encrypted update including a plurality of cryptographic keys and a plurality of multi-ciphertexts for a plurality of recipient nodes. A method for performing an encrypted update including a plurality of cryptographic keys and a plurality of multi-ciphertexts for a plurality of recipient nodes may include receiving the encrypted update. A reduced encrypted update may be generated by removing one or more of the plurality of cryptographic keys and one or more ciphertexts of the plurality of multi-ciphertexts. The reduced encrypted update may be transmitted to a recipient node of the plurality of recipient nodes. The operation may be repeated for one or more other nodes of the plurality of nodes.

[0035]

[0052] FIG. 3 is a flowchart of an example process 300 for performing an encrypted update including a plurality of cryptographic keys and a plurality of multi-ciphertexts for a plurality of recipient nodes. In operation 310, process 300 may include receiving the encrypted update. The encrypted update may include a plurality of cryptographic keys and / or a plurality of multi-ciphertexts. The encrypted update may include information such as half of a cryptographic key pair, an encrypted message, or any data that can be represented as a binary or hexadecimal string. The encrypted update may be received from one or more transmitting devices. The one or more transmitting devices may be computing devices (e.g., servers, mobile devices, computing devices, etc.). For example, a user's smartphone may be able to transmit the encrypted update. The encrypted update may be received by a suitably programmed computer (e.g., a server computer). For example, a user's laptop may be able to transmit a key update to a secure messaging server. The transmitting device may be of the same type as the plurality of recipient nodes. For example, the transmitting device may be a smartphone, and the recipient nodes may also be smartphones. The transmitting device may be of the same type as at least some of the plurality of recipient nodes. For example, the transmitting device may be a smartphone, and the recipient nodes may be other smartphones and server nodes.

[0036]

[0053] The encrypted update can be signed using a redacted signature. The redacted signature can be configured to allow operations on one or more data blocks during the encrypted update without compromising the signature or activating one or more data blocks. The operations can be rewriting, modification, deletion, addition, etc., or any combination thereof. For example, a multi-ciphertext containing a plurality of ciphertexts signed using a redacted signature can have the ciphertexts of the plurality of ciphertexts deleted while maintaining the signature. A user or a system that generates the encrypted update can indicate parts of the encrypted update that can be changed without affecting the signature, operations possible without affecting the signature, etc., or any combination thereof. For example, the system can indicate data blocks that can be deleted without affecting the signature. The ciphertext can be encrypted using a lattice-based encryption method. One or more ciphertexts can be ciphertexts encrypted as described elsewhere in this specification (e.g., generated using a lattice-based encryption method, generated using a homomorphism-based encryption method). The redacted signature can be forgery-proof, unmodifiable, or a combination thereof. The redacted signature can be private, transparent, accountable, or any combination thereof. The redacted signature can instead be a deletable signature. The redacted signature can be based on a Merkle tree.

[0037]

[0054] In another operation 320, process 300 may include generating a reduced encryption update by removing one or more of a plurality of cryptographic keys and one or more ciphertexts of a plurality of multi-ciphertexts. The removal may be performed without affecting the signature. The redacted signature may facilitate the removal of one or more of the plurality of cryptographic keys and one or more of the plurality of multi-ciphertexts. For example, an encryption update using a redacted signature can be changed without affecting the signature, while an encryption update not using a redacted signature cannot be changed without affecting the signature. The removal may be performed by a recipient of the encryption update. For example, a host server can remove blocks from an update received from a user. The removal may include removing one or more of the cryptographic keys and / or one or more ciphertexts of the multi-ciphertexts. One or more ciphertexts may be removed from an update to a recipient node that does not require the one or more ciphertexts. For example, in a multi-ciphertext including updates for nodes A, B, and C, the server can remove the updates for B and C from the reduced encryption update sent to A. The removal of one or more ciphertexts may reduce the update size sent to the recipient node. The number of bytes sent to a plurality of nodes can be reduced by at least about 1 / n compared to the number of bytes that could be used to send the update to each of the plurality of recipient nodes, where n is the number of nodes among the plurality of nodes. The number of bytes sent to a plurality of nodes can be reduced by at most about 1 / n compared to the number of bytes that could be used to send the update to each of the plurality of recipient nodes, where n is the number of nodes among the plurality of nodes. The number of bytes sent to a plurality of nodes can be reduced by at least about 1 / 1.1, 1 / 1.2, 1 / 1.3, 1 / 1.4, 1 / 1.5, 1 / 1.6, 1 / 1.7, 1 / 1.8, 1 / 1.9, 1 / 2, 1 / 2.5, 1 / 3, 1 / 3.5, 1 / 4, 1 / 4.5, 1 / 5, 1 / 5.5, 1 / 6, 1 / 6.5, 1 / 7, 1 / 7.5, 1 / 8, 1 / 8.5, 1 / 9, 1 / 9.5, 1 / 10, 1 / 11, 1 / 12, 1 / 13, 1 / 14, 1 / 15, 1 / 16, 1 / 17, 1 / 18, 1 / 19, 1 / 20, 1 / 21, 1 / 22, 1 / 23, 1 / 24, 1 / 25 or more compared to the number of bytes that could be used to send the update to each of the plurality of recipient nodes.The number of bytes sent to the plurality of nodes can be reduced to at most about 1 / 25, 1 / 24, 1 / 23, 1 / 22, 1 / 21, 1 / 20, 1 / 19, 1 / 18, 1 / 17, 1 / 16, 1 / 15, 1 / 14, 1 / 13, 1 / 12, 1 / 11, 1 / 10, 1 / 9.5, 1 / 9, 1 / 8.5, 1 / 8, 1 / 7.5, 1 / 7, 1 / 6.5, 1 / 6, 1 / 5.5, 1 / 5, 1 / 4.5, 1 / 4, 1 / 3.5, 1 / 3, 1 / 2.5, 1 / 2, 1 / 1.9, 1 / 1.8, 1 / 1.7, 1 / 1.6, 1 / 1.5, 1 / 1.4, 1 / 1.3, 1 / 1.2, 1 / 1.1 or less as compared to the number of bytes that can be used to send an update to each of the plurality of recipient nodes.

[0038]

[0055] In another operation 330, process 300 may include sending the reduced encryption update to recipient nodes of the plurality of recipient nodes. The recipient nodes may decrypt the encryption update. The recipient nodes may receive one encryption key and one ciphertext. One or more of the multi-ciphertexts need not be sent to all of the plurality of nodes. For example, in a system having three nodes, an update having three ciphertexts in the multi-ciphertext can be split into three single-ciphertext updates. In this example, each node can receive one particular ciphertext out of the three, and thus not all of the ciphertexts of the multi-ciphertext are sent to all of the plurality of nodes. The reduced ciphertext can be sent via a public network (e.g., the Internet), a private network (e.g., a virtual private network (VPN), a local network), etc. The reduced ciphertext may still include a valid signature.

[0039]

[0056] In another operation 340, process 300 may include repeating operations 320-330 for one or more other nodes among the plurality of nodes. Operation 340 may be executed substantially simultaneously for each node of the plurality of nodes. Operation 340 may provide key updates across the server. Each node may receive a reduced encryption update that includes one of the plurality of encryption keys and one of the multi-ciphertexts. For example, the server may reduce the plurality of encryption keys and multi-ciphertexts to a single encryption key and a single ciphertext and transmit them to the nodes. Each node of the plurality of nodes may receive a reduced encryption update from each other node of the plurality of nodes that includes a different encryption key among the plurality of encryption keys and a different ciphertext among the multi-ciphertexts. For example, in the case of an encryption update (U,V 1 ,V 2 ), node 1 may receive (U,V 1 ), and node 2 may receive (U,V 2 ). The receiving node may have one or more child nodes. The child nodes may be child nodes of a tree structure. The child nodes may thus have one or more additional child nodes. For example, nodes 5, 6, 7, and 8 in FIG. 10E may be child nodes of node 18. The child nodes may have access to one or more parameters stored in the receiving node. The child nodes may be able to access the decryption keys of each receiving node in the path of the child nodes.

[0040]

[0057] Figures 4A - 4C show an example of the Lindner - Peikert (LP) framework. Further details of the Lindner - Peikert framework can be found in "Better key sizes (and attacks) for LWE - based encryption" by Richard Lindner and Chris Peikert; In Aggelos Kiayias, editor, CT - RSA 2011, volume 6558 of LNCS, pages 319 - 339. Springer, Heidelberg, February 2011, which is hereby incorporated by reference in its entirety. The LP framework can be used as a framework for interpreting several encryption schemes. The LP framework can provide a convenient framework for explaining the ciphertext compression method herein. Figure 4A shows an example of the function keygen() that can be used for generating the encryption key ek and the decryption key dk. D * The function can be a probability distribution function as described elsewhere in this specification. In introducing randomness using the probability distribution, the LP framework can be more resilient against attacks based on quantum computers. Using the probability distribution, a plurality of parameters A, S, and E can be generated and combined to form the parameter B. Although shown here as a square matrix, the parameter A can be non - square. The scheme can remain functional by adapting the dimensions of the other matrices (e.g., S, E). In Figure 4B, the message msg can be encrypted using the parameters generated in the equation of Figure 4A. The encrypted message can be represented by V, while one or more system parameters not related to the public key can be represented by U. The ciphertext can include both U and V. For example, several system parameters can be concatenated with the encoded message to form a single ciphertext. Figure 4C shows the decryption process of the ciphertext generated in Figure 4B.

[0041]

[0058] To improve the LP framework, several changes can be made to the LP framework. One change can be to enable a more compact representation of the elements in FIGS. 4A - 4C (e.g., A, S, E, B, R, E’, E’’, U, and V) by representing one or more of the elements as a seed through which one or more elements can be recompiled through a generator. The generator can be a pseudo - random number generator. For example, A can be represented as a seed that, when input into a random number generator, generates the complete matrix A. The seed can be another element. For example, the public key ek can be used as the seed for element A. In another example, the plaintext message msg can be used as the seed for element S. Compression can be applied to one or more of the elements. Compression can be irreversible or reversible. For example, irreversible compression can be applied to elements B, U, and V by dropping the lower bits. The application of compression can reduce the size of the elements and thus the size of any update involving the elements.

[0042]

[0059] FIG. 4D shows an example of pseudocode for an implementation of ciphertext compression of a single message sent to one or more recipients. By adopting a common A element for each user k, the number of A elements can be reduced to 1 / k. This reuse of the A element can be equivalent to generating A from a seed. By reusing A, the same R and E’ can be used for each of the k users. By applying these two changes to the decoding process in FIG. 4B, a new process for generating multi - ciphertexts can follow. The multi - ciphertext can encrypt the same message msg to k separate users simultaneously. The multi - ciphertext (U, V i ) can be decoded by each user i of the k users using the same decoding algorithm as in FIG. 4C. By reusing the system parameter U for each of the k users, the total communication cost of the multi - ciphertext can be |U| + |V|, where |x| can be the byte size of x. Conversely, the total communication cost of sending k ciphertexts can be k·(|U| + |V|). When there are many users k, the use of multi - ciphertexts can reduce the total communication cost by about

Number

[0043]

[0060] In one example, the process of FIG. 4D can start by providing one or more system parameters A, one or more encryption keys ek for each user i of k users i =B i and a common message msg. The example process of FIG. 4D can start by generating parameters R and E' from a distribution function. The parameters R, E', and A (e.g., system parameters reusable for each user) can be combined such that U ← RA + E'. The parameter U can include information usable by each of a plurality of users (e.g., information independent of the users' public keys). For each user i of k users, the parameter E i '' can be generated from another distribution function, and V i ← RB i + E i '' + Encode(msg) can be used. This can generate iV i which can then be concatenated with the parameter U such that mctxt := (U, V 0 ,..., V k-1 ), where mctxt can be a multi - ciphertext. The multi - ciphertext can have a size equal to the size of U plus k times the size of V.

[0044]

[0061] FIG. 5A shows a pseudo - code example of one implementation of ciphertext compression for one or more messages sent to one or more recipients. The example of FIG. 5A can be a multi - message analog of the example of FIG. 4D. In FIG. 5A, the single message msg of FIG. 4D can be replaced with a different message msg i for each user i of k users. The process can be similar in other respects and can follow a similar trend as described elsewhere in this specification. The difference is that each message msg iSince they can have different sizes, |V| may not be constant.

[0045]

[0062] FIGS. 5B-5D show pseudo-code examples of one implementation of the Supersingular Isogeny Key Encapsulation (SIKE) public-key encryption scheme. FIGS. 5B-5D may differ from FIGS. 4A-4C in that they may be based on the SIKE scheme described in the Supersingular Isogeny Key Encapsulation specification by David Jao et al. issued on March 31, 2019 by the National Institute of Standards and Technology and incorporated herein by reference as part of the SIKE submission package. In FIG. 5B, to generate a secret (or decryption key) S, a random member of the key space K A may be selected. Then, using the isogeny algorithm isogen, an isogeny of S can be computed to generate P, i.e., the public (or encryption) key. In FIG. 5C, s B can be generated from the key space K B From the isogeny of s B computed by the isogeny algorithm isogen, a parameter U (e.g., a parameter that does not depend on the user's public key) can be generated, while another isogeny algorithm, isoex, can generate a shared key j from the encryption key P and s B The process of generating the shared key j can be seen in more detail in FIG. 9. The function H can map the shared key j to a bit string and then act on it using the exclusive OR operator on the message msg to return V. The ciphertext can be generated by concatenating U and V as shown in the equation ctxt := (U, V). The decryption process can be found in FIG. 5D, and the same isogeny algorithm isoex can generate the same shared key j using the parameter U and the decryption key S, and thus use it to decrypt the message msg from V.

[0046]

[0063] Figure 6A shows a pseudo-code example of an implementation of ciphertext compression in the SIKE public-key encryption scheme for one or more messages sent to one or more recipients. The code in Figure 6A may be a SIKE analogue of the example in Figure 4D. The difference may be that Figure 6A shows an implementation of ciphertext compression in an encryption scheme based on a homogeneous mapping as described in Figures 5B - 5D. The difference in the process between Figure 5C and Figure 6A may be that several users k each receive the message msg. The parameter U may be user-independent (e.g., not dependent on any parameter related to a specific user). Thus, U may be reused for each user i of the k users. The parameter V may not be user-independent (e.g., dependent on a parameter related to a specific user), and thus each user may have a different V i and follow a process similar to Figure 5C, but instead have a plurality of encryption keys P i to generate a multi-ciphertext mctxt := (U, V 0 ,..., V k-1 ). Each user i of the k users may decrypt the ciphertext (U, V i ) of the multi-ciphertext using the process of Figure 5D. By having one parameter for all users, the size of the multi-ciphertext can be reduced by a factor of k·|U|, and thus the efficiency of the computing device on which the algorithm is executed can be improved.

[0047]

[0064] Figure 6B shows a pseudo-code example of an implementation of ciphertext compression in the SIKE public-key encryption scheme for one or more messages sent to one or more recipients. The example in Figure 6B may be a multi-messaging analogue of the example in Figure 6A. In Figure 6B, the single message msg in Figure 6A may be replaced by a different message msg i for each user i of the k users. Each user i may be able to decrypt the ciphertext (U, V 0 ,..., V k-1 ) of the multi-ciphertext (U, V i ). The security of the example in Figure 6B may be at a higher level than the security of the example in Figure 5A.

[0048]

[0065] Figures 12A - 12C show a pseudo - code example of an implementation of the Commutative Supersingular Isogeny Diffie - Hellman (cSIDH) public - key encryption scheme. Further details regarding the cSIDH scheme can be found in "CSIDH: An Efficient Post - Quantum Commutative Group Action" by Wouter Castryck, Tanja Lange, Chloe Martindale, Lorenz Panny, and Joost Renes, editors Thomas Peyrin and Steven D. Galbraith, Advances in Cryptology - ASIACRYPT 2018, pages 395 - 427. Springer International Publishing, 2018, which is hereby incorporated by reference in its entirety. The algorithm can be based on the El Gamal scheme. Briefly, the cSIDH scheme may be commutative while the SIDH scheme (where SIKE can be one implementation) may not be, in which respect it may differ from the SIDH scheme. Commutativity can be invariant with respect to the order in which one or more operations are performed. For example, integer multiplication is commutative as shown by (2 * 3) * 4 = 2 * (3 * 4). Non - commutative operations can be non - commutative. The cSIDH scheme can be based on a prime number p. The prime number can be a large prime number (e.g., a prime number with a value greater than 1,000,000). The size of the prime number (e.g., bit - length) can define the security of the cSIDH scheme. The prime number can be of the form p = 4·l 1 ·1 2 ...l r -1, where l i is a small distinct odd prime number. The prime number p can define a set S p which contains all elements A for which the elliptic - curve equation y 2 = x 3 + A·x 2 + x has exactly p solutions in the finite field F pcan be selected to be a subset of. Another group G can arise from the ideal class group of , , [Number], , , , , which can be denoted as Cl(O). The elements of the group can be called ideals and represented by "α". Thus, the commutative group action can be defined as Cl(O)×A→A, where A is the set of all coefficients A∈F [Number] and can be denoted as Cl(O). The elements of the group can be called ideals and represented by "α". Thus, the commutative group action can be defined as Cl(O)×A→A, where A is the set of all coefficients A∈F p and can be. This can mean that the elements of the group Cl(O) can act on the elliptic curve via an endomorphism. This can enable secret conversion from one curve to another, similar to the case of SIDH. Such an operation can be denoted as [α]E in this specification, including FIGS. 12A to 12D.

[0049]

[0066] In the setup phase, one or more parties (e.g., Alice and Bob) for key exchange agree on a large prime number p and a finite field F p and an initial elliptic curve E 0 : y 2 =x 3 +x as described above. In the key generation phase, such as shown in FIG. 12A, the first party (e.g., Alice) can sample an n-tuple of integers in the range [-B,B]=M, i.e., integers sampled separately. The integers can represent ideal classes [Number] where l i can be distinct prime ideals. The public key can be the coefficients A∈F 0 of the elliptic curve [α]E 2 : y 3 =x 2 +A·x p +x.

[0050]

[0067] Figure 12B shows a pseudo-code example of an encoding algorithm that can use the parameters generated in Figure 12A. The algorithm Keygen can be the algorithm of Figure 12A. The algorithm Keygen can generate additional parameter U that does not depend on the user's encryption key, is user-independent, or both. [a] and E in Figure 12A A Parameters [b] and E can be generated in the same way as A above. Parameter E R can be a secret shared among one or more parties. Parameter E R can be generated as follows: [a][b]E 0 =[b][a]E 0 =E R . E R can be in the form of y 2 =x 3 +R·x 2 +x, which can be the same for all parties (e.g., Alice and Bob) due to the commutativity of Cl(O). An exclusive OR operation applied to the hash of the message and the shared secret E R can be used to generate V. By concatenating parameter U and the encrypted message V, a ciphertext ctxt := (U, V) can be generated. The ciphertext can be decrypted as shown in Figure 12C. Parameter E U can be generated in the same way as parameter E A .

[0051]

[0068] Figure 12D shows a pseudo-code example of one implementation of ciphertext compression for a single message sent to one or more recipients. The elements of Figure 12D can be the same as the elements of Figure 12B. Instead of a single recipient, the algorithm of Figure 12D can be configured to send the same message msg to multiple users k. For each user i of the multiple users k, A i can generate a different E from the encryption key Ai . The encryption method can continue as in Figure 12B for each of the i users, and thus kV iAn encrypted message can be generated. In the same way as the methods discussed elsewhere in this specification, the encrypted message can be concatenated with a parameter U that is user-independent to generate a multi-ciphertext. The multi-ciphertext can be signed using a smudge signature as described elsewhere in this specification. The use of the multi-ciphertext scheme can improve the performance of a computer by reducing the operations associated with the group action calculations performed in key generation and key exchange operations. The group action operations can be the most computationally costly part of the algorithm, and the multi-ciphertext scheme can perform key generation once and reduce the computational cost of the algorithm by half. The multi-message multi-ciphertext scheme using the cSIDH scheme can be more secure than those based on the SIDH or lattice-based schemes. The multi-message multi-ciphertext scheme using the cSIDH scheme can be indistinguishable under chosen-plaintext attack (IND-CPA) secure.

[0052]

[0069] FIG. 12D can also be implemented in a multi-message manner. Instead of a single message msg for each i-th user of a plurality of users k, a plurality of messages msg can be provided in operation 6. i In this multi-message multi-ciphertext, each V i can contain a different message.

[0053]

[0070] Although various encryption schemes have been described herein, the methods and systems for generating and using the multi-ciphertexts described herein are not limited to a particular encryption scheme. The methods and systems described herein can be resilient against chosen-plaintext attack (CPA). For example, an attacker having the ability to send multiple plaintexts to be encrypted and receive the encrypted ciphertexts cannot identify the secret key. The methods and systems described herein can be made resilient against chosen-ciphertext attack (CCA) by the application of one or more general transformations. The transformations can be adapted to handle multiple recipients at once. The adapted transformations can be resilient against decryption failure. The adapted transformations can have a security proof in the quantum random oracle model (QROM).

[0054] Computer system

[0071] The present disclosure provides a computer system programmed to implement the methods of the present disclosure. FIG. 11 shows a computer system 1101 programmed or otherwise configured to implement the methods described elsewhere in this specification. The computer system 1101 can coordinate various aspects of the present disclosure, such as, for example, the generation of multi-ciphertexts, the distribution of messages / updates containing multi-ciphertexts, etc. The computer system 1101 can be a user's electronic device or a computer system located remotely from the electronic device. The electronic device can be a mobile electronic device. The computer system 1101 can be a non-classical computer system (e.g., a quantum computer system).

[0055]

[0072] Computer system 1101 includes a central processing unit (CPU, also referred to herein as "processor" and "computer processor") 1105, which can be a single-core or multi-core processor or multiple processors for parallel processing. The computer system 1101 also includes a memory or memory location 1110 (e.g., random access memory, read-only memory, flash memory), an electronic storage unit 1115 (e.g., hard disk), a communication interface 1120 (e.g., network adapter) for communicating with one or more other systems, and peripheral devices 1125 such as cache, other memory, data storage, and / or an electronic display adapter. The memory 1110, storage unit 1115, interface 1120, and peripheral devices 1125 communicate with the CPU 1105 through a communication bus (solid line) such as a motherboard. The storage unit 1115 can be a data storage unit (or data repository) for storing data. The computer system 1101 can be operably coupled to a computer network ("network") 1130 using the communication interface 1120. The network 1130 can be the Internet, the Internet and / or an extranet, or an intranet and / or an extranet that communicates with the Internet. In some cases, the network 1130 is a telecommunications network and / or a data network. The network 1130 can include one or more computer servers, thereby enabling distributed computing such as cloud computing. The network 1130 can optionally implement a peer-to-peer network using the computer system 1101, allowing devices coupled to the computer system 1101 to act as clients or servers.

[0056]

[0073] CPU 1105 can execute a series of machine-readable instructions that can be implemented by a program or software. The instructions can be stored in a memory location such as memory 1110. The instructions can be directed to CPU 1105 and subsequently configure CPU 1105 in a program or other way to implement the method of the present disclosure. Examples of operations executed by CPU 1105 can include fetch, decode, execute, and write-back.

[0057]

[0074] CPU 1105 can be a part of a circuit such as an integrated circuit. One or more other components of system 1101 can be included in the circuit. Optionally, the circuit is an application-specific integrated circuit (ASIC).

[0058]

[0075] Storage unit 1115 can store files such as drivers, libraries, and stored programs. Storage unit 1115 can store user data, such as user preferences and user programs. Optionally, computer system 1101 can include one or more additional data storage units external to computer system 1101, such as being located on a remote server that communicates with computer system 1101 through an intranet or the Internet.

[0059]

[0076] Computer system 1101 can communicate with one or more remote computer systems through network 1130. For example, computer system 1101 can communicate with a user's remote computer system. Examples of remote computer systems include personal computers (e.g., portable PCs), slates or tablet PCs (e.g., Apple® iPad, Samsung® Galaxy Tab), phones, smartphones (e.g., Apple® iPhone, Android-compatible devices, Blackberry®), or personal digital assistants. The user can access computer system 1101 through network 1130.

[0060]

[0077] A method as described herein can be implemented, for example, by machine (e.g., computer processor) executable code stored in an electronic memory location of a computer system 1101, such as memory 1110 or electronic storage unit 1115. The machine executable or machine readable code can be provided in the form of software. In use, the code can be executed by processor 1105. Optionally, the code can be retrieved from storage unit 1115 and stored in memory 1110 to facilitate access by processor 1105. Depending on the situation, the electronic storage unit 1115 can be excluded and the machine executable instructions can be stored in memory 1110.

[0061]

[0078] The code can be configured to be pre-compiled and used in conjunction with a machine having a processor adapted to execute the code, or can be compiled during run-time. The code can be selected to be pre-compiled or left compiled so that it can be executed.

[0062]

[0079] Aspects of the systems and methods provided herein, such as computer system 1101 etc., can be implemented in programming. Various aspects of the present technology can typically be considered as a "product" or "manufactured article" in the form of machine (or processor) executable code and / or associated data carried or implemented on a type of machine-readable medium. The machine executable code can be stored in an electronic memory unit such as a memory (e.g., read-only memory, random access memory, flash memory) or a hard disk. A "storage" type medium can include any or all of various semiconductor memories, tape drives, disk drivers, etc., which are tangible memories of a computer that can provide non-transitory storage for software programming, processors, etc., or related modules. All or part of the software can sometimes communicate through the Internet or various other electrical communication networks. Such communication can, for example, enable software to be loaded from one computer or processor to another computer or processor, such as from an administrative server or host computer to an application server's computer platform. Thus, another type of medium that can carry software elements includes optical, light wave, radio, and electromagnetic waves such as those used across physical interfaces between local devices, through wired and optical terrestrial networks, and via various air links. Physical elements that carry such waves, such as wired or wireless links, optical links, etc., can also be regarded as media for carrying software. As used herein, unless limited to non-transitory tangible "memory" media, terms such as computer or machine "readable media" refer to any medium involved in providing instructions to a processor for execution.

[0063]

[0080] Thus, a machine-readable medium such as computer-executable code can take many forms including, but not limited to, a tangible storage medium, a carrier wave medium, or a physical transmission medium. Non-volatile storage media include, for example, optical disks or magnetic disks of any storage device in any computer, such as those that can be used in the implementation of a database shown in the drawings. Volatile storage media include dynamic memories such as the main memory of such a computer platform. Tangible transmission media include coaxial cables, copper wire, and fiber optics, including the wires that make up a bus within a computer system. Carrier wave transmission media can take the form of electrical signals or electromagnetic signals such as those generated during wireless (RF) and infrared (IR) data communications, or in the form of sound waves or light waves. Thus, common forms of computer-readable media include, for example, floppy disks, flexible disks, hard disks, magnetic tape, any other magnetic medium, CD-ROM, DVD or DVD-ROM, any other optical medium, punch cards, paper tape, any other physical storage medium with patterns of holes, RAM, ROM, PROM, and EPROM, flash EPROM, any other memory chip or cartridge, carrier waves that transport data or instructions, cables or links that transport such carrier waves, or any other medium that a computer can read programming code and / or data from. Many of these forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to a processor for execution.

[0064]

[0081] The computer system 1101 can include, or be in communication with, for example, an electronic display 1135 that includes a user interface (UI) 1140 to provide a programming interface. Examples of UIs include, but are not limited to, graphical user interfaces (GUIs) and web-based user interfaces.

[0065]

[0082] The methods and systems of the present disclosure can be implemented as one or more algorithms. When the algorithms are executed by the central processing unit 1105, they can be implemented by software. The algorithms can implement, for example, one or more encryption algorithms as described herein.

Example

[0066] Example

[0083] The following examples are illustrative of specific systems and methods described herein and are not intended to be limiting.

[0067] Example 1 - Real-World Improvement in Update Size

[0084] Figures 7A - 7C show examples of update size vs group size plots for various key - encryption mechanisms. The examples shown in Figures 7A - 7C illustrate the improvement of the functionality of a computer system that can be achieved through the implementation of the methods and systems described elsewhere in this specification. For each group size shown in Figures 7A - 7C, the number of tree terms was selected to minimize the update size. Figure 7A shows a plot of update sizes in a plurality of different situations using the Kyber512 key - encryption mechanism. The first row, the sender key (c), shows the update size as a function of the group size of the sender - key scheme with compression applied, with the number of terms equal to the group size, and thus a depth of 1, which can also be considered as a compressed - tree KEM scheme used in process 200 of Figure 2. An example of the sender - key scheme can be found in Figure 10C where a single node sends the update to each receiving node. The second row, the tree KEM, traces the efficiency of an uncompressed scheme such as that shown in Figure 10D. The initial cost of an update using the tree KEM scheme is higher than that of the compressed - sender - key scheme, but the group size may provide a significant gain in using the tree KEM scheme for efficiency improvement. As shown in the third row, further improvement can be achieved by the application of the compressed - tree KEM (e.g., tree KEM(c)) scheme. The compressed - tree KEM scheme can be an implementation of process 200 of Figure 2 where ciphertext compression is used in the update process. The compressed - tree KEM scheme shows improved performance over the standard tree KEM scheme for all group sizes greater than 2, and also shows a significant improvement over the compressed - sender - key as the group size grows larger than 64. Thus, the ciphertext - corresponding compressed - tree KEM scheme can improve the update size, and thus the performance of the system using the update, for all group sizes, and the improvement provided increases as the group gets larger.

[0068]

[0085] Similarly, FIGS. 7B and 7C show the improvements represented by using the ciphertext compression scheme in an additional key encapsulation mechanism (KEM), demonstrating the universality of the improvements. FIG. 7B is a plot for the case of FrodoKEM640 KEM, while FIG. 7C shows the updated size vs. group size for the case of SIKE / p434 KEM. Callouts 770, 780, and 790 in FIG. 7C are presented to clarify the legend of the figure. In each figure, the performance of the compressed tree KEM scheme is always better than that of the uncompressed tree KEM scheme and better than that of the compressed sender key scheme for larger group sizes. The location of the difference between the compressed sender key scheme and the compressed tree KEM scheme may depend on the relative sizes of the system parameters, ciphertext, and multi-ciphertext of each scheme. For example, FrodoKEM640 can have a relatively large system parameter byte size compared to the byte size of the ciphertext, and thus takes a larger group size to see the difference between the compressed sender key and the compressed tree KEM.

[0069]

[0086] Figure 8 shows the asymptotic gain factors possible with multiple different KEM schemes when the multi-ciphertext scheme is used. The |U| value can be a system parameter (e.g., a parameter that does not depend on the user's public key). The |U| value can correspond to the size of parameter U in FIGS. 4A-4D and FIGS. 5A-5D. The use of the multi-ciphertext scheme can reduce the number of times these parameters are transferred and thus the amount of data that can be transferred. The |V| value can be the size of a parameter that depends on the user's public key (e.g., an encrypted message, various other keys). By combining the |U| size and the |V| size, the |ctxt| column can be generated, which represents the size of a completely classical ciphertext. By reusing the |U| parameter instead of attaching an additional |V| parameter, the size of the multi-ciphertext for two recipients can be |U| + 2|V|, while the classical ciphertext for two recipients can be 2|U| + 2|V|. By calculating |ctxt| / |V|, the asymptotic gain factor can be determined, which can represent the maximum efficiency factor that can be obtained by implementing a multi-ciphertext method and system as described elsewhere in this specification. As seen in FIG. 8, the method described herein can provide an actual efficiency gain to a computer system by reducing the communication bandwidth requirements for transmitting an encryption key update. Further, FIG. 8 can show the broad applicability of the multi-ciphertext scheme to a variety of different encryption schemes.

[0070] Example 2 - Interaction between Database Structure and Ciphertext Compression

[0087] FIGS. 10A to 10E show examples of a plurality of protocols that can be used in conjunction with ciphertext compression. FIG. 10A is an example of a broadcast usage case. In the broadcast usage case, user A can output information to one or more recipients, in this example, six recipients. If the information is confidential, it may be a requirement for A to apply some encryption to the information. The output can be via a network (e.g., the Internet), a broadcast medium (e.g., light waves, radio waves), etc. FIG. 10B shows a server-assisted messaging scheme. User A has a message addressed to one or more other users that A sends to server S. Since one or more users may not be online when user A sends the message, the message can always be sent to server S that is always online. In this example, the amount of data transmitted can grow rapidly based on the number of intended recipients of the message. Using multi-ciphertext can reduce the load going out of server S. In the example of six recipients, when user A sends a 1MB message including a 0.5 megabyte (MB) system parameter independent of the user and a 0.5MB encrypted message not independent of the user, the standard ciphertext system causes A to send 6MB of information to the server (6 users × 1MB per message), and then the server sends out six 6MB messages (any change to the user's message may damage the book name). In the case of the multi-ciphertext scheme, user A sends a 3.5MB message to the server (0.5MB of system parameter and 3MB of encrypted message), and the server can update each recipient with a 6MB message, and the total communication reduction is 2.5MB. When using a blackout signature in conjunction with the multi-ciphertext scheme, user A can send a 3.5MB message to the server, and the server can remove information not intended for each of the plurality of users, thereby sending six 1MB messages, and the total communication reduction is 32.5MB. As is clear, the combination of multi-ciphertext and blackout signature can result in a significant reduction in the bandwidth required for message transmission.

[0071]

[0088] Figures 10C through 10E can be viewed as different tree structures equivalent to multi-ciphertext and blacked-out signatures. Figure 10C is an example of a sender key scheme in which a user who updates a cryptographic key sends the update to each of the other users in the group. This structure is a tree of degree N, where N is the number of members in the group. This can be contrasted with the tree of Figure 10D, which instead has the same number of recipient nodes but is instead arranged in a tree of degree 2. When a user sends a message such as a cryptographic key update in the sender key scheme, the user sends N - 1 messages, 7 messages in the example of Figure 10C. In the tree of Figure 10D, each node can know the decryption key of the nodes in its path (for example, the path to node 1 is node 1010). Since each node can know the decryption key in its path of the node, the user who updates the key needs to update all the nodes in the user's path, which requires sending the update to the nodes in the common path. In the example of Figure 10D, for node 1, the path is node 1010 and the common path is node 1020. This leads to the transmission of d public keys and d ciphertexts, where d = log 2 N. Thus, the tree structure is more scalable than the sender key structure because the communication cost scales as log m N to N - 1.

[0072]

[0089] Figure 10E is an example of a larger-degree tree structure having degree 4 made possible by using the multi-ciphertext scheme. Similar to the tree of Figure 10D, each node knows the decryption key of the nodes in its path, so when user 1 sends an update, d = log 4 N ( = 2 in this example) decryption keys and (m - 1) * d (where m is the number of users, and in this example (m - 1) *Transmit (d = 6) multi-ciphertexts. The number of multi-ciphertexts transmitted can be 1 per level. A multi-ciphertext can include (m - 1) ciphertexts to update (m - 1) other nodes per level. In the example of FIG. 10D, the first multi-ciphertext update from node 1 can include ciphertexts to nodes 2, 3, and 4, and the second multi-ciphertext update can include ciphertexts to nodes 18, 19, and 20. The multi-ciphertext can also be named using scribbled names that allow the multi-ciphertext to be changed before being sent to each recipient node. For example, the multi-ciphertext update to nodes 2, 3, and 4 can be changed to include related updates rather than updates to the other two nodes.

[0073]

[0090] Preferred embodiments of the present invention have been shown and described herein, but it will be apparent to those skilled in the art that such embodiments are provided by way of example only. The present invention is not intended to be limited by the specific examples provided herein. Although the present invention has been described with reference to the above specification, the description and illustration of embodiments herein are not intended to be construed in a limiting sense. Many variations, modifications, and substitutions will occur to those skilled in the art without departing from the present invention. Furthermore, it is to be understood that all aspects of the present invention are not limited to the specific figures, configurations, or relative proportions described herein, which depend on various conditions and variables. It should be understood that various alternative forms of the embodiments of the present invention described herein may be adopted in practicing the present invention. Accordingly, the present invention is intended to embrace any such alternative variations, modifications, or equivalents. The following claims define the scope of the present invention, and the methods and structures within these claims and their equivalents are intended to be encompassed thereby.

Claims

1. A method for transmitting a ciphertext including a plurality of encrypted parts to a plurality of users, comprising: a computer (a) providing a common set of system parameters for the plurality of users; (b) generating the plurality of encrypted parts by encrypting a plaintext using either an encryption method based on a lattice and an encryption method based on a homomorphism, and a parameter unique to each user of the plurality of users; (c) generating the ciphertext including a part derived from the common set of system parameters and the plurality of encrypted parts; (d) transmitting the ciphertext to the plurality of users, wherein the ciphertext is at least partially decodable using the parameter unique to each user of the plurality of users. A method comprising the above.

2. The method according to claim 1, wherein the common set of system parameters is generated using a seed and a pseudo-random number generator.

3. The method according to claim 1 or 2, wherein at least one of the parameters unique to each user of the plurality of users is generated using a seed and a pseudo-random number generator.

4. The method according to any one of claims 1 to 3, wherein the common set of system parameters or the parameter unique to each user of the plurality of users includes a non-square matrix.

5. (a) generating a system parameter set including the common set of system parameters, the system parameter set including parameters independent of the public keys of the users among the plurality of users; (b) generating a fixed component, which is a part derived from the common set of system parameters, based at least in part on the system parameter set. Further comprising: generating the plurality of encrypted parts includes generating a plurality of variable components by encrypting the plaintext using each public key of the plurality of users; The method according to any one of claims 1 to 4, wherein the ciphertext is at least partially decodable using the fixed component.

6. The method according to claim 5, wherein the encryption is based on an encryption method selected from the group consisting of the Lindner-Peikert method, the supersingular isogeny Diffie-Hellman protocol, and a public key encryption method based on an isogeny.

7. further comprising compiling a database, wherein compiling the database comprises structuring a plurality of recipients in a tree structure having a number of terms m, where "m" is at least 2, the structuring comprising the method according to any one of claims 1 to 6, wherein transmitting the ciphertext to the plurality of users comprises transmitting the ciphertext to a number of recipients less than all of the plurality of recipients.

8. The method according to claim 7, wherein the number of terms m is 8 to 16.

9. The method according to claim 7 or 8, wherein the transmitting comprises transmitting the same message to each node of the tree structure.

10. The method according to claim 9, wherein the same message comprises update information of the encryption key of the user of the database.

11. A system comprising one or more computer processors and a computer memory coupled thereto, wherein the computer memory, when executed by the one or more computer processors, comprises machine-executable code for performing the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Cryptogram generating device, cryptogram communication system, and group parameter generating device

    WO2008087734A1