Information Processing Apparatus, Method, and Program
By integrating a white-box secure message authentication code with a block cipher and hash function, the solution addresses the lack of white-box secure AEAD, providing enhanced security in data communication systems against powerful attacks.
Patent Information
- Application Number
- JP2024515190
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-11
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-04-11
AI Technical Summary
Current cryptographic techniques lack white-box security for Authenticated Encryption with Associated Data (AEAD), which is crucial for ensuring both confidentiality and authenticity in data communication, especially when attackers can see the implementation details of the encryption software.
A white-box secure message authentication code is realized using a tag generation function MAC1, combined with a block cipher and a cryptographic hash function, to ensure authenticity, and then integrated with a white-box secure symmetric key cipher to create a secure AEAD.
This approach provides robust security against white-box attacks, ensuring both authenticity and confidentiality in data communication systems, even when attackers have access to the software implementation details.
Smart Images

Figure 0007700960000005 
Figure 0007700960000006 
Figure 0007700960000007
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing apparatus, method, and program.
Background Art
[0002] Generally, cryptographic techniques are designed to be secure against black-box attacks. A black-box attack is an attack in which an attacker can know input-output pairs with respect to an encryption function or a decryption function. On the other hand, an attack in which an attacker can see not only input-output pairs but also the content of software implementing an encryption function or a decryption function is called a white-box attack. Being secure against a black-box attack is also referred to as "black-box secure", and being (to some extent) secure against a white-box attack is also referred to as "white-box secure".
[0003] Cryptographic techniques are mainly techniques for obtaining confidentiality, but in recent years, techniques for obtaining not only confidentiality but also authenticity have become important. As a technique for obtaining authenticity, a message authentication code (MAC) is known. Also known is a technique called authenticated encryption or AEAD (Authenticated Encryption with Associated Data) that can obtain both confidentiality and authenticity at the same time (for example, Non-Patent Document 1, etc.). AEAD is often configured by combining a common key cipher such as CTR or CBC and a message authentication code.
Prior Art Documents
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, there has been no white-box secure AEAD so far. On the other hand, since many AEADs can be configured by combining a symmetric key cipher and a message authentication code, if a white-box secure message authentication code can be realized, a white-box secure AEAD can be configured by combining it with a white-box secure symmetric key cipher.
[0006] In view of the above points, the present disclosure provides a technique for realizing a white-box secure message authentication code.
Means for Solving the Problems
[0007] An information processing apparatus according to an aspect of the present disclosure uses a tag generation function MAC1 of a message authentication code that is secure against white-box attacks K (where K is the key) to verify the authenticity of data X with a tag T = MAC1 KIt has a tag generation unit configured to generate (X), and the tag generation function MAC1 K is an encryption function E of a block cipher that is secure against white-box attacks and has an input / output length of n bits K and a predetermined hash function H with an output length of m ≥ 2n bits, and predetermined functions f1, f2: {0, 1} m → {0, 1} n and f3: {0, 1} n × {0, 1} n → {0, 1} n and is configured using them.
Advantages of the Invention
[0008] A technique for realizing a white-box secure message authentication code is provided.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Modes for Carrying Out the Invention
[0010] Hereinafter, the first and second embodiments of the present invention will be described. In the first embodiment, a communication system 1 that constitutes a white-box secure message authentication code and enables data communication that satisfies authenticity using this message authentication code will be described. Further, in the second embodiment, an AEAD is configured from the message authentication code configured in the first embodiment, and a communication system 1 that enables data communication that satisfies confidentiality and authenticity using this AEAD will be described.
[0011] Note that the communication system 1 according to the first embodiment is applicable to various systems in which data communication that needs to ensure authenticity occurs. Similarly, the communication system 1 according to the second embodiment is applicable to various systems in which data communication that needs to ensure confidentiality and authenticity occurs.
[0012] [Preparation] Hereinafter, terms, techniques, etc. used in the first and second embodiments will be described.
[0013] [Confidentiality and Authenticity] Confidentiality and authenticity are important concepts in information security. Confidentiality refers to a state in which information about data to be protected cannot be obtained illegally by a malicious attacker. Technologies for obtaining confidentiality include symmetric-key cryptography and public-key cryptography. Authenticity refers to a state in which data to be protected has not been illegally altered by an attacker, or a state in which an attacker cannot fabricate data illegally. Technologies for obtaining authenticity include message authentication codes and digital signatures.
[0014] [Symmetric-Key Cryptography Technology] Symmetric-key cryptography is a type of cryptography in which users use a common secret key. For example, when a person encrypts data using symmetric-key cryptography and sends it to another person, the same secret key must be used for both encryption and decryption. Unlike public-key cryptography such as RSA cryptography, symmetric-key cryptography cannot disclose the key (or part of it). On the other hand, it has the advantage of not requiring the use of algebraic problems such as the prime factorization problem and being fast in processing. Many data protection technologies such as SSL / TLS are realized by skillfully combining the advantages of both public-key cryptography, which can disclose the key (or part of it), and fast symmetric-key cryptography. Both public-key cryptography and symmetric-key cryptography are indispensable as basic security technologies. The first and second embodiments described below relate to symmetric-key cryptography.
[0015] Hereinafter, unless otherwise specified, simply referring to "symmetric-key encryption" shall mean a narrow sense of symmetric-key encryption whose main purpose is to encrypt data of various lengths to maintain confidentiality. Examples of narrow-sense symmetric-key encryption include confidentiality modes such as the CTR mode and CBC mode, and stream ciphers such as KCipher-2. Although block ciphers such as AES (Advanced Encryption Standard), Camellia, SPACE (Reference 1), and SPNBox (Reference 2) can also be classified as narrow-sense symmetric-key encryption in principle, for the convenience of explanation in this specification, when referring to "(narrow-sense) symmetric-key encryption", block ciphers shall not be included.
[0016] In recent years, symmetric key cryptography that provides not only confidentiality but also authenticity when encrypting data has been widely used. Such cryptography is called authenticated encryption or AEAD. Representative examples of AEAD include GCM, CCM, SIV (Synthetic Initialization Vector) (Non-Patent Document 1), etc. AEAD is often composed of a symmetric key cryptography in a narrow sense and a message authentication code (MAC). Here, a message authentication code is a symmetric key cryptography technology whose purpose is to provide only authenticity without considering confidentiality. The first embodiment described below relates to a message authentication code, and the second embodiment relates to AEAD.
[0017] Hereinafter, the block cipher, symmetric key cryptography in a narrow sense, message authentication code, and AEAD will be described in more detail. Also, the cryptographic hash function will be described. In this specification, it is assumed that all data and function inputs and outputs are represented as bit strings.
[0018] · Block Cipher A block cipher is a cipher E that takes as inputs a key K of a fixed length (e.g., 256 bits) and a plaintext M of a fixed length (e.g., 128 bits), and outputs a ciphertext C of the same length as the plaintext. That C is the ciphertext corresponding to M and K is written as C = E K (M). E K is also called an encryption function. A block cipher is required to be decodable. That is, there exists a decryption function D K such that D K (E K (M)) = M holds for any plaintext M. Also, D K (E K (C)) = C holds for any ciphertext C. Representative examples of block ciphers include AES, Camellia, etc.
[0019] Here, note that even if there is a good block cipher that can securely encrypt short fixed-length data, it is not obvious how to securely encrypt arbitrary-length data (especially long data).
[0020] · Symmetric key cipher in the narrow sense In this specification, when referring to a symmetric key cipher in the narrow sense, it shall be a cipher E that takes as input a fixed-length key K, a fixed-length initial vector IV, and an arbitrary-length plaintext M, and outputs a ciphertext C. Here, in principle, IV is a value that changes each time the encryption process is performed. IV may be randomly selected for each encryption process. Also, there is a method that allows a single IV to be reused repeatedly. In a block cipher, M is of a fixed length (e.g., 128 bits), but in a symmetric key cipher in the narrow sense, M is of arbitrary length. For example, M may be 1 bit or 1 gigabyte, etc. Let C be the ciphertext corresponding to (K, IV, M), which is written as C = Enc K (IV, M). Enc K is also called an encryption function. Similar to a block cipher, a symmetric key cipher in the narrow sense is also decryptable. That is, there is a decryption function Dec K such that Dec K (IV, Enc K (IV, M)) = M holds for any plaintext M.
[0021] Symmetric key ciphers for encrypting arbitrary-length plaintexts are often created using block ciphers. Those with a structure such as a symmetric key cipher in the narrow sense, a message authentication code, or AEAD that utilize a block cipher are called block cipher usage modes or simply modes. In a mode, common key cipher techniques other than block ciphers may be used as necessary. In this specification, in particular, the mode for creating a symmetric key cipher in the narrow sense shall be called the confidentiality mode. Representative examples of the confidentiality mode include the CTR mode and the CBC mode, etc.
[0022] · Message Authentication Code (MAC) A message authentication code is a function (tag generation function) MAC K (M) that takes as input a fixed-length key K and an arbitrary-length message M and outputs a fixed-length output T called a tag, and
[0023] [Number] Verification function VER that outputs K (M, T). Here,
[0024] [Number] means that "T is a legitimate tag generated from M and K", and VER K (M, T) = ⊥ means that "T is an illegally generated tag". A secure message authentication code, roughly speaking, satisfies the properties that "only those who know the secret key K can calculate the legitimate value of T" and "the tag values corresponding to different messages are different", and can be used for detecting illegal modifications (i.e., obtaining authenticity).
[0025] In this specification, only message authentication codes for which the verification function VER K is calculated as shown in Algorithm 1 in FIG. 1 are considered. That is, the verification function VER K takes the message M and the tag T as inputs, calculates T' ← MAC K (M) (line 1), and then, if T' = T, outputs a symbol indicating that T is a legitimate tag (lines 2 - 3), and if not, outputs a symbol indicating that T is an illegal tag (lines 4 - 5).
[0026] Similar to symmetric-key cryptography in the narrow sense, a message authentication code (its tag generation function) may also be realized using a block cipher (i.e., as a block cipher usage mode). Representative examples of message authentication codes in which the tag generation function is realized as a block cipher usage mode include CMAC and the like.
[0027] ·Authenticated Encryption with Associated Data (AEAD) The encryption function E of AEAD takes as input not only (K, IV, M) which a symmetric key cipher in the narrow sense takes, but also associated data A of arbitrary length. Also, this encryption function E outputs not only the ciphertext C but also a tag T. Let (T, C) be the tag and ciphertext corresponding to (K, IV, A, M), which is written as (T, C) = E K (IV, A, M). Similar to the symmetric key cipher in the narrow sense, there is a decryption function D K that exists, and D K (IV, A, E K (IV, A, M)) = M holds for any plaintext M.
[0028] The decryption function D of AEAD K has a function of detecting forgery, similar to the verification function of the message authentication code. That is, if the ciphertext C and the tag T are values generated illegally, D K outputs a symbol ⊥ indicating that the verification has failed (that is, D K (IV, A, (T, C)) = ⊥). When T and C are values calculated properly by the encryption function, as described above, the original message M is output.
[0029] A secure AEAD converts the message M into the ciphertext C to protect confidentiality and also protects against forgery to ensure authenticity. An attacker cannot know what the value of M is just by looking at C. On the other hand, confidentiality is not guaranteed for the associated data A. That is, roughly speaking, it is assumed that the value of A is not encrypted and is visible to the attacker. However, authenticity is guaranteed for A and it is protected against forgery. That is, if A is forged into another value A' in the middle, the decryption function fails the verification and D K (IV, A', (T, C)) = ⊥. Therefore, data for which authenticity needs to be guaranteed but confidentiality is not required (for example, the header of an IP packet, etc.) becomes A.
[0030] AEAD is often composed by combining a symmetric key cipher in the narrow sense and a message authentication code. Representative examples of such configurations include GCM, CCM, SIV (Non-Patent Document 1), etc. For example, the symmetric key cipher (Enc K',Dec K' ) and a message authentication code tag generation function MAC K are given. At this time, the encryption function E of SIV (K,K') is defined, for example, by Algorithm2 shown in FIG. 2. That is, the encryption function E of SIV (K,K') takes (IV, A, M) as input, T←MAC K (pad(IV, A, M)) and C←Enc K' (adj(T), M) are calculated (lines 1-2), and then (T, C) is output (line 3). The encryption function E configured in this way (K,K') is schematically represented as shown in FIG. 3. Here, pad is a function that takes a triple of bit strings (IV, A, M) as input and outputs a single bit string IV||A||M||len(M). Note that x||y represents the bit concatenation of two bit strings x and y, and len(M) is the bit length of M represented by some bit string. Also, adj takes the output T of MAC K as input, and when the length of T (hereinafter, this length is referred to as τ bits) is different from the length of the IV used in Enc K' or Dec K' (hereinafter, this length is referred to as ν bits. Note that this IV is different from the IV taken as input by SIV), it is a function that adjusts the length to ν bits by truncating some bits of T or adding extra bits to T. Specifically, when τ = ν, adj(T) outputs the input T as it is. On the other hand, when τ > ν, adj(T) outputs the lower ν bits of the input T. Also, when τ < ν, adj(T) outputs 0 ν-τ ||T. Here, 0 ν-τ is a (ν - τ)-bit bit string in which all bits are 0.
[0031] Also, the decryption function D of SIV (K,K') is defined, for example, by Algorithm3 shown in FIG. 4. That is, the decryption function D of SIV (K,K') takes (IV, A, T, C) as input, M←Dec K' (adj(T), C) and T'←MAC KAfter calculating (lines 1 - 2) (pad(IV,A,M)), if T = T', output M (lines 3 - 4); otherwise, output ⊥ (lines 5 - 6).
[0032] Note that in Algorithm 2 shown in Figure 2 and Algorithm 3 shown in Figure 4, different independent keys (K and K') are used for MAC, Enc, and Dec. However, it is also acceptable that K and K' are not independent (i.e., K = K').
[0033] In Algorithm 2 shown in Figure 2 and Algorithm 3 shown in Figure 4, for the sake of explanation, there are several places where the configuration of SIV is changed from the original paper (Non - Patent Document 1) that proposed it. First, in the original paper, IV is not taken as an input (considered as part of A), but in Algorithm 2 shown in Figure 2 and Algorithm 3 shown in Figure 4, IV is also taken as an input. Also, in the original paper, instead of combining MAC K with pad, a pseudo - random function that can take a pair of bit strings as input is used. adj is also introduced in Algorithm 2 shown in Figure 2 and Algorithm 3 for the sake of explanation. The essence of SIV is "input (IV and) A and M into a keyed function and use the output T as the substitute for the IV of Enc K' ", so the above - mentioned changes do not change its essence.
[0034] · Cryptographic hash function A cryptographic hash function (hereinafter simply referred to as a hash function) H takes an arbitrary - length data M as input and outputs a fixed - length (e.g., 256 - bit) bit string H(M). The specification of the hash function is basically publicly available, and it is a fixed function that anyone can calculate. In particular, the hash function does not take a key as input. A secure hash function is required to be resistant to pre - image attacks and collision attacks. Examples of secure and widely used hash functions include SHA - 2, SHA - 3, etc. Although the hash function does not take a key as input, it is conventionally classified into symmetric - key cryptography techniques.
[0035] <White-Box Cryptography> Generally, cryptographic techniques are designed to be secure against black-box attacks. A black-box attack is an attack in which an attacker can know input-output pairs with respect to an encryption function or a decryption function. For example, when the target of attack is a block cipher, the attacker is allowed to choose an arbitrary plaintext M and know the ciphertext C := E K (M) (alternatively, the attacker is allowed to know the plaintext M := D K (C) for an arbitrary ciphertext C.). After learning the ciphertexts corresponding to multiple plaintexts, the attacker aims to expose the secret key K or discover some bias in the ciphertexts that should originally appear completely random.
[0036] What is important here is that the attacker in a black-box attack cannot know how the cryptographic algorithm is implemented. All that is allowed for the attacker is to learn the input-output pairs of the encryption function E K or the decryption function D K .
[0037] On the other hand, an attack in which the attacker can see not only the input-output pairs of E K and D K , but also the content of the software (including information related to the secret key) implementing E K and D K is called a white-box attack. An example of a white-box attack is that malware sneaks into a PC using software implementing cryptographic techniques and sends the data of that software to the outside. Cryptographic techniques that can provide a certain level of security against white-box attacks are called white-box cryptographic techniques.
[0038] Of course, in an implementation where a short secret key of about several tens to several thousands of bits is simply embedded in software, no security can be guaranteed against white-box attacks. This is because if an attacker sees and copies the short secret key, all ciphertexts can be freely decrypted. Also, in a situation where an attacker can freely execute the software in which the cryptographic technology is implemented, no security can be ensured at all. For example, if an attacker can freely execute the software in which the decryption function is implemented at any time, any ciphertext can be freely decrypted by that attacker, and the original plaintext can be seen.
[0039] Therefore, when discussing security against white-box attacks, the following settings 1 and 2 are assumed.
[0040] 1. The secret key is expanded into very large data (e.g., several tens of gigabytes) by some method.
[0041] 2. There are certain restrictions on the attacker's capabilities. For example, there is an upper limit on the amount of data that can be transmitted externally among the data of the software implementation, or there is an upper limit on the time during which the contents of the software can be viewed.
[0042] As existing technologies that are white-box secure under the above settings, there are block ciphers such as SPACE (Reference 1) and SPNBox (Reference 2). Currently, no white-box attacks that can break the claimed security of these block ciphers are known.
[0043] It should be noted that white-box attacks are clearly more powerful than black-box attacks and give the attacker greater freedom. Therefore, white-box secure cryptographic technologies are black-box secure.
[0044] [First Embodiment] Hereinafter, the first embodiment will be described.
[0045] Since authenticity is an important property no less than confidentiality, when performing encryption using symmetric key cryptography technology, it has been the main trend in recent symmetric key cryptography designs to use AEAD to simultaneously ensure both confidentiality and authenticity. However, there has been no white-box secure AEAD until now. Existing AEADs such as GCM and CCM do not take into account white-box attacks. In particular, although GCM and CCM are block cipher usage modes, even if the block cipher used is white-box secure, GCM and CCM as AEADs are not necessarily white-box secure.
[0046] On the other hand, as described above, AEAD is often composed of a combination of a symmetric key cipher in the narrow sense and a message authentication code. Therefore, if a white-box secure message authentication code can be realized, a white-box secure AEAD can be constructed by combining this message authentication code with a white-box secure symmetric key cipher in the narrow sense.
[0047] Therefore, in the first embodiment, a communication system 1 that enables data communication satisfying authenticity with this message authentication code will be described after constructing a white-box secure message authentication code.
[0048] <Outline of the idea for constructing a white-box secure message authentication code> Message authentication codes and AEADs need to generate a short fixed-length tag T from an input of arbitrary length. In particular, when the input is very long, the long data must be compressed into short data by some method. Existing methods such as GCM and CCM (which do not take into account white-box attacks) perform compression in a method that depends on the secret key K. Since the compression process is not visible to a black-box attacker, GCM and CCM are secure against black-box attacks, but since the white-box attacker can see the content of the software, the compression process can also be seen. This fact that "the compression process can be seen" may lead to breaking the security of the message authentication code and AEAD.
[0049] Therefore, consider performing most of the compression in the message authentication code (and AEAD tag generation) using a cryptographic hash function H that does not depend on the secret key K. Since hash functions are originally designed on the premise that they "compress a long bit string into a short bit string" and "the compression process is visible to attackers", it can be expected that a tag generation function that performs compression using the cryptographic hash function H is secure against white-box attacks.
[0050] On the other hand, to ensure authenticity, the value of the tag T must depend on the secret key. Since the hash function does not take the secret key as input, security cannot be guaranteed by H alone. Therefore, the aim is to ensure authenticity by calling a (white-box secure) block cipher multiple times after compressing with the hash function.
[0051] <Example configuration of a white-box secure message authentication code> · Notation E K is the encryption function of a block cipher with an input / output length of n bits, and H is a cryptographic hash function with an output length of m ≥ 2n bits. Also, let (Enc K' , Dec K' ) be a symmetric key cipher. In addition, let f1, f2: {0, 1} m → {0, 1} n and f3: {0, 1} n × {0, 1} n → {0, 1} n be functions determined by either of the following setting example 1 or setting example 2.
[0052] ≪Setting example 1 of f1~f3≫ f1 outputs the upper n bits of an m-bit input x.
[0053] f2 first extracts the upper 2n bits from an m-bit input x and sets this as d. It then outputs the lower n bits of d. Note that if m = 2n, f2 simply outputs the lower n bits of the input, and it should be noted that x = f1(x) || f2(x) holds.
[0054] f3: When an input \((x, y)\in\{0, 1\}\) n \(\times\{0, 1\}\) n is given, the exclusive OR of \(x\) and \(y\), that is
[0055]
Math
[0056] ≪Examples of settings for f1~f3 2≫ f1: Among the \(m\)-bit input \(x\), first set the upper \(n\) bits as \(d1\). Among these \(d1\), further set the lower \((n - 2)\) bits as \(d1'\), and output \(01||d1'\).
[0057] f2: Among the \(m\)-bit input \(x\), first take out the upper \(2n\) bits and set this as \(d\). Among these \(d\), further set the lower \((n - 2)\) bits as \(d2'\), and output \(10||d2'\).
[0058] f3: When an input \((x, y)\in\{0, 1\}\) n \(\times\{0, 1\}\) n is given, set the lower \((n - 2)\) bits of the exclusive OR of \(x\) and \(y\) as \(s3\), and output \(11||s3\).
[0059] · Tag generation function of a white-box secure message authentication code Under the above notations and settings, based on the above ideas, consider a tag generation function that takes an arbitrary-length data \(X\) as input and calculates and outputs a tag \(T = MAC1\) K (X) as shown in Algorithm 4 of Figure 5. That is, taking an arbitrary-length data \(X\) as input, after calculating \(h\leftarrow H(X)\) (first line), calculate \(s1\leftarrow E\) K (f1(h)) and \(s2\leftarrow E\) K (f2(h)) (second line), and then calculate and output \(T\leftarrow E\) K (f3(s1, s2)) (lines 3 - 4) of the tag generation function MAC1 K is considered. At this time, if the hash function \(H\) is secure and \(E\) K is white-box secure, then MAC1K It can also be expected to be white-box secure. The tag generation function MAC1 configured in this way K is schematically represented as shown in FIG. 6.
[0060] In addition, when using the second setting example of f1 to f3, the input of the encryption function E of the block cipher called three times K does not overlap. Therefore, an improvement in security can be expected compared to the first setting example of f1 to f3.
[0061] · Verification function of white-box secure message authentication code In Algorithm 1 shown in FIG. 1, by changing the input "message M and tag T" to "data X and tag T", and changing "T'←MAC K (M)" in the first line to "T'←MAC1 K (X)", a verification function of a white-box secure message authentication code (this is represented as VER1 K (X,T).) can be configured.
[0062] <Configuration example of communication system 1> A configuration example of the communication system 1 according to the first embodiment is shown in FIG. 7. As shown in FIG. 7, in the communication system 1 according to the first embodiment, a communication terminal 10 which is a transmitting-side terminal and a communication terminal 20 which is a receiving-side terminal are communicably connected via a communication network 30 such as the Internet. Note that examples of the communication terminal 10 and the communication terminal 20 include various communicable information processing devices such as a PC, a smartphone, a tablet terminal, a wearable device, an in-vehicle device, and an electric appliance.
[0063] The communication terminal 10 includes an authentication unit 101 and a transmission unit 102. The authentication unit 101 and the transmission unit 102 are realized, for example, by processing executed by one or more programs installed in the communication terminal 10 by a processor such as a CPU (Central Processing Unit).
[0064] The authentication unit 101 generates a tag T for the message X = M to be transmitted using the tag generation function MAC1K (X) is generated by (X). The transmitting unit 102 transmits (X, T) to the communication terminal 20. As a result, the communication terminal 10 obtains the tag T = MAC1 for the message X to be transmitted. K (X) can be generated by the authentication unit 101 and then (X, T) can be transmitted to the communication terminal 20 by the transmitting unit 102.
[0065] The communication terminal 20 includes a receiving unit 201 and a verification unit 202. The receiving unit 201 and the verification unit 202 are realized, for example, by the processing executed by one or more programs installed in the communication terminal 20 on a processor such as a CPU.
[0066] The receiving unit 201 receives (X, T) from the communication terminal 10. The verification unit 202 verifies the received (X, T) with VER1 K (X, T). As a result, the communication terminal 20 can receive (X, T) from the communication terminal 10 by the receiving unit 201 and verify the authenticity of the (X, T) by the verification unit 202.
[0067] <Modification Example> Hereinafter, a modification example of the algorithm of the tag generation function MAC1 K (shown as Algorithm4 in FIG. 5) will be described.
[0068] ·Modification Example 1-1 Change the "h←H(X)" in the first line of Algorithm4 shown in FIG. 5 to "h←H(E K (0 n )||X)". By additionally combining the value E K (0 n ) that depends on the secret key, an improvement in security can be expected.
[0069] ·Modification Example 1-2 Change the "T←E K (f3(s1, s2))" in the third line of Algorithm4 shown in FIG. 5 to
[0070]
Equation
[0071] ·Variants 1-3 Combine Variant 1-1 and Variant 1-2. That is, change "h←H(X)" on the first line of Algorithm 4 shown in FIG. 5 to "h←H(E K (0 n )||X)", and change "T←E K (f3(s1, s2))" on the third line to "T←(exclusive logical sum of s1 and s2)". An improvement in processing efficiency can be expected without significantly sacrificing security.
[0072] [Second Embodiment] Hereinafter, the second embodiment will be described. In the second embodiment, an AEAD is configured from the message authentication code configured in the first embodiment, and a communication system 1 that enables data communication satisfying confidentiality and authenticity by this AEAD will be described.
[0073] [Configuration Example of White-Box Secure AEAD]< In addition to the secure hash function H and the encryption function E of the white-box secure block cipher K and, if there is a narrow sense common key cipher (Enc K' , Dec K' ) that is white-box secure, by constructing SIV from MAC1 K described in the first embodiment and (Enc K' , Dec K' ), a white-box secure AEAD can be constructed.
[0074] That is, (Enc K' , Dec K' ) is a white-box secure narrow sense common key cipher. At this time, change "T←MAC K (pad(IV, A, M))" on the first line of Algorithm 2 shown in FIG. 2 to "T←MAC1 KAs "pad(IV,A,M))", the encryption function E of SIV (K,K') is configured. Also, in the second line of Algorithm3 shown in FIG. 4, "T'←MAC K (pad(IV,A,M))" is changed to "T'←MAC1 K (pad(IV,A,M))" to configure the decryption function D of SIV (K,K') . This enables the realization of data communication that guarantees both authenticity and confidentiality against a very powerful attack such as a white-box attack.
[0075] Note that there are configurations other than SIV for obtaining AEAD from a message authentication code and a narrow-sense symmetric-key cipher. However, since SIV satisfies a very strong security definition called DAE (deterministic authenticated-encryption), it is preferable to use SIV to ensure security against a powerful white-box attack.
[0076] <Configuration example of communication system 1> A configuration example of the communication system 1 according to the second embodiment is shown in FIG. 8. As shown in FIG. 8, in the communication system 1 according to the second embodiment, a communication terminal 10, which is a transmitting-side terminal, and a communication terminal 20, which is a receiving-side terminal, are communicably connected via a communication network 30 such as the Internet. Note that examples of the communication terminal 10 and the communication terminal 20 include various communicable information processing devices such as a PC, a smartphone, a tablet terminal, a wearable device, an in-vehicle device, and an electrical appliance.
[0077] The communication terminal 10 includes an encryption unit 103 and a transmission unit 102. The encryption unit 103 and the transmission unit 102 are realized, for example, by processing executed by an arithmetic device such as a CPU for one or more programs installed in the communication terminal 10.
[0078] The encryption unit 103 encrypts the ciphertext C of the message X = M to be transmitted and the tag T for the message X using the above-described white-box secure AEAD encryption function E (K,K')Generated by (IV, A, M). The encryption unit 103 includes the authentication unit 101. When generating the tag T for the message X, this authentication unit 101 generates the tag T by MAC1 K (for example, the first line of Algorithm 2 shown in FIG. 2). The transmission unit 102 transmits (T, C) to the communication terminal 20. As a result, the communication terminal 10 can generate the ciphertext C of the message X to be transmitted and the tag T for the message X by the encryption unit 103, and then transmit (T, C) to the communication terminal 20 by the transmission unit 102.
[0079] The communication terminal 20 has a receiving unit 201 and a decryption unit 203. The receiving unit 201 and the decryption unit 203 are realized, for example, by the processing executed by one or more programs installed in the communication terminal 20 on an arithmetic device such as a CPU.
[0080] The receiving unit 201 receives (T, C) from the communication terminal 10. The decryption unit 203 verifies the tag T by the white-box secure AEAD decryption function D (K,K') (IV, A, T, C), and decrypts the ciphertext C if the verification is successful. The decryption unit 203 includes a verification unit 202. When verifying the tag T, this verification unit 202 generates the tag T' by MAC1 K and verifies whether this tag T' matches the tag T (for example, the second and third lines of Algorithm 4 shown in FIG. 4). As a result, the communication terminal 20 can receive (T, C) from the communication terminal 10 by the receiving unit 201, and perform the authenticity verification and decryption of (T, C) by the decryption unit 203.
[0081] <Modification Example> Hereinafter, a modification example of the algorithms of the white-box secure SIV encryption function E (K,K') and decryption function D (K,K') will be described. Note that the algorithm of the SIV encryption function E (K,K') is that the "T ← MAC K (pad(IV, A, M))" in the first line of Algorithm 2 shown in FIG. 2 is changed to "T ← MAC1 Kis set to "(pad(IV,A,M))". Also, the decryption function D of SIV (K,K') has an algorithm where the "T'←MAC" in the second line of Algorithm3 shown in FIG. 4 K "(pad(IV,A,M))" is changed to "T'←MAC1 K "(pad(IV,A,M))".
[0082] ·Modification Example 2-1 MAC1 realized by the algorithm of any one of Modification Examples 1-1 to 1-3 of the first embodiment is used. K
[0083] ·Modification Example 2-2 Let K' = K. As a result, the length of the secret key to be held can be reduced, and an improvement in processing efficiency can be expected.
[0084] ·Modification Example 2-3 Combine Modification Example 2-1 and Modification Example 2-2. That is, MAC1 realized by the algorithm of any one of Modification Examples 1-1 to 1-3 of the first embodiment K is used and K' = K is set.
[0085] [Hardware Configuration Example] The communication terminal 10 and the communication terminal 20 according to the first embodiment and the second embodiment can be realized by, for example, the hardware configuration of the computer 500 shown in FIG. 9. The computer 500 shown in FIG. 9 includes an input device 501, a display device 502, an external I / F 503, a communication I / F 504, a RAM (Random Access Memory) 505, a ROM (Read Only Memory) 506, an auxiliary storage device 507, and a processor 508. These pieces of hardware are communicably connected to each other via a bus 509.
[0086] The input device 501 is, for example, a keyboard, a mouse, a touch panel, physical buttons, or the like. The display device 502 is, for example, a display, a display panel, or the like. Note that the computer 500 may not have at least one of the input device 501 and the display device 502.
[0087] The external I / F 503 is an interface with an external device such as the recording medium 503a. The computer 500 can read from and write to the recording medium 503a via the external I / F 503. Examples of the recording medium 503a include a flexible disk, a CD (Compact Disc), a DVD (Digital Versatile Disk), an SD memory card (Secure Digital memory card), a USB (Universal Serial Bus) memory card, and the like.
[0088] The communication I / F 504 is an interface for connecting to a communication network. The RAM 505 is a volatile semiconductor memory (storage device) that temporarily holds programs and data. The ROM 506 is a non-volatile semiconductor memory (storage device) that can hold programs and data even when the power is turned off. The auxiliary storage device 507 is a storage device (storage device) such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a flash memory, for example. The processor 508 is an arithmetic device such as a CPU, for example.
[0089] The communication terminal 10 and the communication terminal 20 according to the first embodiment and the second embodiment can realize the various processes described above by having the hardware configuration of the computer 500 shown in FIG. 9. Note that the hardware configuration of the computer 500 shown in FIG. 9 is an example and is not limited thereto. For example, the computer 500 shown in FIG. 9 may have a plurality of auxiliary storage devices 507 and a plurality of processors 508, or may have various hardware other than the illustrated hardware.
[0090] The present invention is not limited to the specifically disclosed above embodiments, and various modifications, changes, combinations with known technologies, etc. are possible without departing from the scope of the claims.
[0091] [References] Reference 1: Andrey Bogdanov and Takanori Isobe. White - box cryptography revisited: Space - hard ciphers. In Indrajit Ray, Ninghui Li, and Christopher Kruegel, editors, Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA, October 12 - 16, 2015, pp. 1058 - 1069. ACM, 2015. Reference 2: Andrey Bogdanov, Takanori Isobe, and Elmar Tischhauser. Towards practical whitebox cryptography: Optimizing efficiency and space hardness. In Jung Hee Cheon and Tsuyoshi Takagi, editors, Advances in Cryptology - ASIACRYPT 2016 - 22nd International Conference on the Theory and Application of Cryptology and Information Security, Hanoi, Vietnam, December 4 - 8, 2016, Proceedings, Part I, Vol. 10031 of Lecture Notes in Computer Science, pp. 126 - 158, 2016.
Explanation of Reference Signs
[0092] 1 Communication system 10 Communication terminal 20 Communication terminal 30 Communication network 101 Authentication unit 102 Transmission unit 103 Encryption unit 201 Reception unit 202 Verification unit 203 Decryption unit 500 Computer 501 Input device 502 Display device 503 External I / F 503a Recording medium 504 Communication I / F 505 RAM 506 ROM 507 Auxiliary storage device 508 Processor 509 Bus
Claims
1. Tag generation function MAC1 of message authentication code that is secure against white-box attacks K (where K is the key) is used to generate a tag T = MAC1 K (X) for verifying the authenticity of data X, and has a tag generation unit configured to generate The tag generation function MAC1 K is An encryption function E of a block cipher that is secure against white-box attacks and has an input / output length of n bits K a predetermined hash function H with an output length of m ≥ 2n bits, and predetermined functions f1, f2: {0, 1} m → {0, 1} n and f3: {0, 1} n × {0, 1} n → {0, 1} n An information processing apparatus configured using these components
2. The tag generation function MAC1 K is taking the data X as an input, h ← H(X) or h ← H(E K (0 n ) || X) (where || is bit concatenation), s 1 ←E K (f1(h)), s 2 ←E K (f2(h)), T ← E K (f3(s 1 , s 2 )) or T ← (s 1 and s 2 exclusive logical sum), and outputting the tag T thereby, the information processing apparatus according to claim 1.
3. the function f1 outputs the upper n bits of the m-bit input, the function f2 extracts the upper 2n bits of the m-bit input and then outputs the lower n bits of the upper 2n bits, The function f3 satisfies (x, y) ∈ {0, 1} n × {0, 1} n When the above is input, the information processing apparatus according to claim 2 outputs the exclusive OR of x and y.
4. After extracting the upper n bits from the m-bit input, the function f1 further extracts d representing the lower (n - 2) bits from the upper n bits, and outputs 01||d 1 and outputs 01||d 1 and outputs After extracting the upper 2n bits from the m-bit input, the function f2 further extracts d representing the lower (n - 2) bits from the upper 2n bits and outputs 10||d. 2 and further extracts d representing the lower (n - 2) bits from the upper 2n bits and outputs 10||d. 2 and outputs The function f3 is such that when (x, y) ∈ {0, 1} n × {0, 1} n is input, it extracts s which represents the lower (n - 2) bits of the exclusive OR of x and y 3 and outputs 11||s 3 The information processing apparatus according to claim 2
5. Encryption function E of an authenticated cipher that is secure against white-box attacks (K,K') wherein, using (where K' is a key), a ciphertext C of data M is generated, and an encryption unit is configured such that a tag generation unit generates a tag for verifying the authenticity of the ciphertext C as the tag T. The encryption function E (K,K') is The tag generation function MAC1 K and the encryption function Enc of a common key cipher that is secure against white box attacks K' The information processing apparatus according to any one of claims 1 to 3, which is configured using these.
6. The encryption function E (K,K') is taking an initial vector IV, associated data A, and the data M as inputs, The tag generation unit calculates a tag T ← MAC1 K (X) where X = IV || A || M || len(M) (where || is bit concatenation and len(M) is a bit string representing the length of M). C ← Enc K' calculate (adj(T), M) (where adj(T) is a predetermined function that adjusts the length of T to the length of the initialization vector of the common key cipher), and outputting the tag T and the ciphertext C, the information processing apparatus according to claim 5.
7. Tag generation function MAC1 of message authentication code secure against white box attacks K (where K is the key), the tag T = MAC1 for verifying the authenticity of the data X K (X) is generated, and the computer executes the tag generation procedure configured to generate The tag generation function MAC1 K is An encryption function E of a block cipher that is secure against white-box attacks and has an input / output length of n bits K a predetermined hash function H with an output length of m ≥ 2n bits, and predetermined functions f1, f2: {0, 1} m → {0, 1} n and f3: {0, 1} n × {0, 1} n → {0, 1} n A method configured using the above.
8. Tag generation function MAC1 of message authentication code that is secure against white box attacks K However, using K as the key, a tag T = MAC1 K (X) is generated to verify the authenticity of data X. The computer is made to execute the tag generation procedure configured as such. The tag generation function MAC1 K is Encryption function E of a block cipher that is secure against white-box attacks and has an input / output length of n bits K and a predetermined hash function H with an output length of m ≥ 2n bits, and predetermined functions f1, f2: {0, 1} m → {0, 1} n and f3: {0, 1} n × {0, 1} n → {0, 1} n A program configured using these.
Citation Information
Patent Citations
CMAC computation using white-box implementations with external encodings
US20180359081A1
Password authentication using white-box cryptography
US20200099525A1