System and method for secure communication based on network coding

By transforming calculations from GF(q^N) to GF(q^n) using an n×n multiplication table, the decoder addresses the computational inefficiency of MRD codes, enhancing error correction and security in communication networks.

JP7766880B2Active Publication Date: 2025-11-11NAT INST OF INFORMATION & COMM TECH +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022023960
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-18
Publication Date
2025-11-11
Estimated Expiration
2042-02-18

AI Technical Summary

Technical Problem

The use of MRD codes, including Gabidulin codes, in network coding requires significant computational resources, which is a bottleneck in efficient error correction and security in communication networks.

Method used

A decoder is introduced that utilizes a basis transformation to convert calculations from a finite field GF(q^N) to its subfield GF(q^n), reducing the computational load by employing an n×n multiplication table instead of an N×N table, particularly for shortened Gabidulin codes.

Benefits of technology

This approach significantly reduces the computational burden, enabling efficient error correction and security in communication networks by simplifying calculations and optimizing resource usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007766880000065
    Figure 0007766880000065
  • Figure 0007766880000066
    Figure 0007766880000066
  • Figure 0007766880000067
    Figure 0007766880000067
Patent Text Reader

Abstract

To reduce the amount of calculation when MRD codes are used.SOLUTION: A decoder 2 for decoding a signal encoded by MRD codes on a finite field GF(qN) includes a basis conversion unit 21 that converts the basis of the finite field GF(qN) into the basis of a subfield GF(qn) of the finite field GF(qN). Here, q is a power of a prime number, and n is a divisor of N. The decoding includes calculation using the basis of the finite field GF(qN) before conversion by the basis conversion unit, and calculation using the basis of the subfield GF(qn) after conversion by the basis conversion unit.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for communicating information while maintaining high confidentiality over a network where eavesdropping, errors, and falsification occur. [Background technology]

[0002] Advances in cloud services and high-speed mobile communications technology are driving a rapid increase in Internet traffic. While network facilities, including high-capacity optical fiber, are being strengthened, the number of devices and new services and applications are expected to continue to increase. Therefore, simply strengthening infrastructure at the current rate will not be enough, and communication methods themselves must be transformed into more efficient ones. Furthermore, with the amount of highly confidential information increasing, there is an increasing demand for information security. In addition to improving communication efficiency, there is also a need for mechanisms to prevent information leaks to third parties other than authorized users and unauthorized data tampering.

[0003] Network coding, which combines multiple pieces of information collected at a relay node, converts them into a different form (encodes them), and then transmits them, is a well-known method for efficiently performing multicast communication over a network. Network coding is beginning to be put into practical use as a new technology to support the rapid increase in communication traffic.

[0004] As a measure to correct errors that occur in a network, error correcting codes are generally used. Non-Patent Document 1 introduces MRD codes, proposing for the first time an encoding and decoding algorithm based on a rank criterion similar to conventional Reed-Solomon codes. The author's name is the origin of the Gabidulin code. Note that rank refers to the order of a matrix. Non-Patent Document 2 introduces a number of codes based on rank criteria, such as block codes and convolutional codes, and mainly describes Gabidulin codes. Non-Patent Document 3 describes error correction in random network coding. It proposes an encoding and decoding algorithm that can handle errors such as erasures and deviations that occur in a random network coding system using Gabidulin codes. Non-Patent Document 4 mainly describes MRD codes based on rank criteria, and proposes new encoding and decoding algorithms for Gabidulin codes. [Prior art documents] [Non-patent literature]

[0005] [Non-Patent Document 1] Gabidulin, EM: Theory of Codes with Maximum Rank Distance. Probl. Peredachi Inf. 21(1), 3-16 (1985) [Non-patent document 2] A. Wachter-Zeh: “Decoding of Block and Convolutional Codes in Rank Metric” Ph.D dissertation, Ulm University, Germany [Non-patent document 3] D. Silva, FR Kschischang, and R. K¨otter, “A rank-metric approach to error control in random network coding,” IEEE Trans. Inf. Theory, vol. 54, no. 9, pp. 3951-3967, 2008. [Non-patent document 4] D. Silva, “Error control for network coding,” Ph.D. dissertation, University of Toronto, Toronto, Canada, 2009 Summary of the Invention [Problem to be solved by the invention]

[0006] When MRD codes including Gabidulin codes are used, the amount of calculation required becomes a problem. An object of the present invention is to reduce the amount of calculation required when MRD codes are used. [Means for solving the problem]

[0007] To achieve the above object, a decoder according to one embodiment comprises: Consisting of a normal basis Finite field GF(q N ) , a decoder for decoding a signal encoded by an MRD code over the finite field GF(q N ) is defined as the basis of the finite field GF(q N ) subfield GF(q n ) before the transformation by the basis transformation unit. N ) and the subfield GF(q n ) basis. [Effects of the Invention]

[0008] According to the present invention, when the MRD code is used, the amount of calculation can be reduced. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is an explanatory diagram illustrating an example of a communication network configuration. [Figure 2] FIG. 10 is an explanatory diagram showing another example of a communication network configuration. [Figure 3] FIG. 1 is an explanatory diagram showing the encoding and decoding procedures when an error correction code is introduced into an LNC. [Figure 4] FIG. 1 is an explanatory diagram showing an example of a decoding procedure for Gabidulin codes. [Figure 5] FIG. 10 is an explanatory diagram showing another example of the decoding procedure of the Gabidulin code. [Figure 6] FIG. 2 is an explanatory diagram illustrating an example of a computer hardware configuration of a decoder. DETAILED DESCRIPTION OF THE INVENTION

[0010] The present invention will be described below based on the illustrated embodiments, but the present invention is not limited to the embodiments described below.

[0011] First, the inventors of the present invention have conducted extensive research into linear network coding and Gabidulin codes, as will be described below. It should be noted that a shortened Gabidulin code according to an embodiment of the present invention, which will be described later, may be used together with linear network coding, or may be used independently of linear network coding.

[0012] [1 Linear Network Coding] Linear network coding (LNC), which has been a hot topic in recent years, is a method of linearly combining data received from multiple neighboring nodes and sending it to the neighboring node. It has attracted attention because it has superior features over conventional methods, such as improved data transmission speed.

[0013] In the communication network NW1 shown in Fig. 1, relay nodes s0 to s3 are connected to a source node s by links. Furthermore, relay nodes v0 to v3 are connected to each of the relay nodes s0 to s3 by links. In addition, terminal nodes t0 to t3 are connected to each of the relay nodes v0 to v3 by links.

[0014] The "[1]" shown above each of the relay nodes s0 to s3 means that the coefficient of the linear combination is "1." In other words, the relay node s0 transmits the packet x0 received from the source node s to the relay nodes v0 to v3. Similarly, the relay node s1 transmits the packet x1 received from the source node s to the relay nodes v0 to v3, the relay node s2 transmits the packet x2 received from the source node s to the relay nodes v0 to v3, and the relay node s3 transmits the packet x3 received from the source node s to the relay nodes v0 to v3.

[0015] Each of the relay nodes v0 to v3 receives packet x0 from relay node s0, packet x1 from relay node s1, packet x2 from relay node s2, and packet x3 from relay node s3.

[0016] Next, the relay node v0 calculates the element A of the linear network code matrix. 00 , A 01 , A 02 and A 03 and the received packets x0 to x3. That is, the relay node v0 performs the following calculation to obtain packet y0. y0=A 00 *x0+A 01 *x1+A 02 *x2+A 03 *x3 The relay node v0 transmits a packet y0 to each of the terminal nodes t0 to t3.

[0017] The relay nodes v1 to v3 also perform linear combination processing using the elements of the linear network code matrix and the received packets x0 to x3. 10 , A 11 , A 12 and A 13 The relay node v2 uses the linear network code matrix element A 20 , A 21 , A 22 and A 23The relay node v3 uses the linear network code matrix element A 30 , A 31 , A 32 and A 33 The relay nodes v1 to v3 obtain packets y1 to y3 by linear combination processing, respectively. The relay node v1 transmits packet y1 to each of the terminal nodes t0 to t3, the relay node v2 transmits packet y2 to each of the terminal nodes t0 to t3, and the relay node v3 transmits packet y3 to each of the terminal nodes t0 to t3.

[0018] [A 00 A 01 A 02 A 03 ] and [A 10 A 11 A 12 A 13 ] and [A 20 A 21 A 22 A 23 ] and [A 30 A 31 A 32 A 33 ] is the linear network code matrix in this example. The elements of the linear network code matrix are often generated so that the matrix is ​​a full-rank matrix, but generally they can be generated randomly.

[0019] Each of the terminal nodes t0 to t3 receives a packet y0 from the relay node v0, a packet y1 from the relay node v1, a packet y2 from the relay node v2, and a packet y3 from the relay node v3. Subsequently, each of the terminal nodes t0 to t3 calculates an inverse matrix A of the linear network coding matrix A. -1 and a vector consisting of received packets y0 to y3 to obtain the original messages x0 to x3.

[0020] In the communication network NW1, data to be transferred from the source node s is expressed as x=(x0x1x2x3). T The data received by terminal nodes t0 to t3 is expressed as y=(y0y1y2y3)T At each relay node, the transferred data is linearly combined and sent to the adjacent node, so the data received by the terminal node is as follows:

number

[0021] That is, x and y have the following relationship:

number

[0022] Using this equation, y=(y0y1y2y3) T From x=(x0x1x2x3) T LNC decoding is the calculation of the inverse matrix of the linear network code matrix A.

number

number

[0023] On the other hand, LNC has the problem of error propagation. For example, if an error e1 is injected into the link from relay node s1 to relay node v1, shown by the dashed line in Figure 2, the data passing through the link will be x1+e1. The packet received by the terminal node will be as follows:

number

number

[0024] As can be seen from the above equation, if an error is injected at just one point in the network, all decoded symbols will be affected by the error. This is called error propagation.

[0025] Error propagation by LNC becomes fatal when error correcting codes are introduced. Generally, the encoding and decoding procedures when error correcting codes are introduced into LNC are shown in Figure 3. First, in step ST11, the source node s performs error correction coding on the user data. In step ST12, the node that transmits on each link of the communication network NW1 performs LNC encoding and then transmits. In step ST13, the node that has received the signal in each link of the communication network NW1 performs LNC decoding. In step ST14, the terminal nodes t0 to t3 perform error correction decoding.

[0026] Errors propagate before the error correction decoding (step ST14), resulting in many symbols being in error during decoding. Conventional error correction codes (ECC, error correction code) such as Reed-Solomon code and BCH code perform correction on a symbol-by-symbol basis. Therefore, they cannot handle situations where errors occur in many symbols, and LNC and conventional error correction codes are incompatible.

[0027] On the other hand, when we consider how errors propagate, we can see that they can be expressed as rank errors. If an error is injected into one link, it results in a rank error of 1, and if an error is injected into n links, it results in a maximum of n rank errors. A code that can correct rank errors is called a maximum rank distance code (MRD code). Gabidulin codes are a form of MRD code. The embodiments described below relate to a method for constructing Gabidulin codes suitable for LNC, and in particular to shortened Gabidulin codes.

[0028] [2 Gabidulin code] [2.1 Fundamentals of Gabidulin Code] To construct a network coding that is robust to noise (including not only errors but also tampering), we can introduce Gabidulin codes. To do this, we construct a set F that satisfies the following conditions:

[0029] Condition: "For any X∈F and a matrix E with rank t or less, there is a unique element of F whose rank distance from X+E is t or less."

[0030] However, the rank distance is defined as follows: For matrices a and b of the same size, the rank distance between a and b is defined as the rank difference between a and b.

number

[0031] If an element of F that satisfies the condition is transmitted as information, errors can be corrected if they occur on t or fewer links. Therefore, such a set F is called a rank error-correcting code (rank code). This was proposed by Ernst Mukhamedovich Gabidulin and is also called a Gabidulin code.

[0032] To satisfy the conditions of a Gabidulin code, the following equation must be satisfied for any a, b∈F (a≠b).

number

[0033] The Gabidulin code has the following characteristics: ·Finite field GF(q N ) and q=p s (p is a prime number). For example, if p=2, s=4, and N=7, then the finite field GF(16 7) It becomes the code above, and the original number becomes the code over an ultra-high order finite field of 260 million or more. Note that a finite field is also called a Galois Field. · The Frobenius q - power used in the construction of the rank code is defined as follows. [Number] · In calculations involving the Frobenius q - power, there are various advantages in calculation by expressing the elements of a finite field using a normal basis. · The encoding of the rank code is similar to the Reed - Solomon code, which is a typical error - correcting code. · The decoding of the rank code is similar to the Reed - Solomon code, but there are also many differences, such as the need to obtain the coefficients of a high - order polynomial containing the Frobenius q - power. Also, calculations of multiplication, reciprocal, and inverse matrix are required, and it is important to establish a calculation method over an ultra - high order finite field.

[0034] The Gabidulin code is denoted as Gab(n,k). Here, n (n≦N) is the code length, and k is the number of information symbols. The number of correctable rank errors in Gab(n,k) is [Number] This is the case. When n < N, the code is called a shortened Gabidulin code.

[0035] Next, the encoding of the Gabidulin code will be explained. The encoding method can be directly applied to the shortened Gabidulin code as well. Furthermore, the decoding of the Gabidulin code will also be explained. Note that the decoding method cannot be directly applied to the shortened Gabidulin code. That is, the following explanation of decoding is limited to the case of n = N.

[0036] [2.2 Encoding of Gabidulin Code] Encoding of Gabidulin codes can be implemented using the same method as general error-correcting codes such as Reed-Solomon codes: constructing a generator matrix and performing matrix operations. The generator matrix G of Gab(n,k) is given by the following equation:

number

number

[0037] For n=N, g0, ,g n-1 ∈GF(q N ) and h0,...,h n-1 ∈GF(q N ) is a finite field GF(q N ) is often used as a normal basis (constructed with the primitive root β). However, in the case of shortened Gabidulin codes, h0, ,h n-1 ∈GF(q N ) is a subfield GF(q n ) is taken as a normal basis (constructed with the primitive root α). Encoding is performed using a generator matrix G in GF(q N ) is performed by matrix operations on GF(q N ) is a k-symbol vector on the matrix G. Encoding is performed by multiplying the generator matrix G and the information data U to obtain the codeword x.

number

[0038] 2.3 Decoding Gabidulin Codes Next, we will explain the decoding of Gabidulin codes. As mentioned above, the explanation here is limited to the case where n=N. Decoding is the process of restoring the codeword x of the Gabidulin code from the received word x'. Assume that a τ-rank error e is added to the codeword (code length n) of the Gabidulin code.

number

[0039] The error vector e can be decomposed as follows:

number

[0040] a is a function of GF(q N ) is called the error span of the τ-rank error on Θ, and is one of the bases of the error space. Θ is called the error coefficient and corresponds to the error locator of the Reed-Solomon code. Decoding starts with syndrome calculation, then finds the error span a and error coefficient Θ, and estimates the error vector e.

[0041] The Gabidulin code has the advantage of being able to correct errors expressed as e = Θa. When an error is injected into a link in an LNC, it appears to the Gabidulin code as an additional error expressed as e = Θa. Therefore, the Gabidulin code is highly compatible with LNC.

[0042] Fig. 4 shows a decoder 1 for the Gabidulin code. Each of the terminal nodes t0 to t3 is provided with a decoder 1. The decoder 1 includes a syndrome calculation unit 11, an ELP calculation unit 12, an ELP root calculation unit 13, an error coefficient calculation unit 14, an error span calculation unit 15, an error vector estimation unit 16, and a codeword estimation unit 17. The decoding procedure is described below.

[0043] Step 1: Calculate the syndrome The syndrome calculation unit 11 calculates a syndrome from the received word x' and the check matrix H.

number

number

[0044] Step 2: Calculate ELP The ELP calculation unit 12 calculates the syndrome S using the Berlekamp-Massey method. l Calculate the coefficient γ of the Error Locator Polynomial (ELP) and the estimated rank error number τ from the following equation. The ELP is expressed as follows:

number

[0045] Step 3: Calculate the root (d) of ELP The ELP root calculation unit 13 finds the root (d) of the ELP using Gaussian elimination. The root d of the following equation can be found by solving the following equation for x:

number

[0046] Step 4: Calculate the error coefficient (Θ) The error coefficient calculation unit 14 calculates the error coefficient Θ from the root d. Θ can be calculated from d using the following relationship:

number

[0047] Step 5: Calculate the error span (a) The error span calculation unit 15 calculates the error span a from d. a can be calculated from d using the following relationship:

number

[0048] Step 6: Estimate the error vector The error vector estimation unit 16 estimates the error vector from the error span a and the error coefficient Θ.

number

[0049] Step 7: Codeword estimation The codeword estimation unit 17 obtains the estimated codeword by subtracting the estimated error vector from x'.

number

[0050] [2.4 Consideration] The encoding and decoding of Gabidulin codes is performed in GF(q N ) is calculated using a normal basis. The maximum code length is N symbols, and Gab(N,k) is a code with a code length of N symbols and the number of information symbols is k symbols. Gab(N,k) is a code with a maximum length of N symbols and the number of information symbols is k symbols.

number

[0051] In practical applications, it is often important to be able to select the code length in order to efficiently introduce error-correcting codes. That is, the shortened Gabidulin code Gab(n,k) is useful (n is a divisor of N). However, previous studies have focused on the maximum code length Gab(N,k), i.e., the case where n = N, and no detailed decoding method for the shortened code Gab(n,k) has been considered. Therefore, we consider the issues that arise in decoding the shortened Gabidulin code Gab(n,k).

[0052] First, let us consider the root d found in step 3 above. The root d is found in the finite field GF(q N) element. On the other hand, in step 4, the error coefficient Θ is calculated from the root d, but the error coefficient Θ is n ) and so cannot be calculated as it is. N ) into the subfield GF(q n ) element. Alternatively, by devising a method for calculating d, we can convert d into a subfield GF(q n ) must be found as an element of

[0053] Next, consider the error span a calculated from the root d in step 5 above. The error span a is calculated over the finite field GF(q N ) element. On the other hand, by devising a method for calculating the root d, we can calculate the root d in the subfield GF(q n ) element, it cannot be calculated as it is. n ) into the finite field GF(q N ) must be converted back to the original.

[0054] In addition, the amount of computation required for decoding Gabidulin codes is a problem. In particular, the amount of computation required for multiplication is very large, and a method using a multiplication table has been proposed to reduce the amount of computation required. However, when N is set large, the amount of computation required for multiplication remains a problem, and improvements are needed.

[0055] [3 One embodiment of the present invention] 5 shows a decoder 2 for the shortened Gabidulin code in this embodiment. Similar to the decoder 1, the decoder 2 includes a syndrome calculation unit 11, an ELP calculation unit 12, an ELP root calculation unit 13, an error coefficient calculation unit 14, an error span calculation unit 15, an error vector estimation unit 16, and a codeword estimation unit 17. The decoder 2 also includes a basis transformation unit 21 and a basis inverse transformation unit 22. The decoding procedure is described below.

[0056] Step 1: Calculate the syndrome The syndrome calculation unit 11 calculates a syndrome from the received word x' and the check matrix H.

number

number

[0057] Step 2: Calculate ELP The ELP calculation unit 12 calculates the syndrome S using the Berlekamp-Massey method. l Calculate the coefficient γ of the Error Locator Polynomial (ELP) and the estimated rank error number τ from the following equation. The ELP is expressed as follows:

number

[0058] Step 3: Change the basis In step 4 described later, we divide the root d into the subfield GF(q n In step 3, the basis conversion unit 21 performs a basis conversion to find the root d as an element of the finite field GF(q N ) in step 3, the basis conversion unit 21 converts γ into the subfield GF(q n ) element. Also, a check matrix is ​​used to solve the equation with γ as a coefficient, but the elements of the check matrix are in the finite field GF(q N ), so in step 3, the basis conversion unit 21 also converts the elements of the check matrix into the subfield GF(q n ) element. This transforms the finite field GF(q N ) is a subfield GF(q n ) can be replaced by the calculation above, which reduces the amount of calculation. In particular, the effect of reducing the amount of calculation for multiplication is very large.

[0059] The basis transformation will be further explained. β∈GF(q N ) is a finite field GF(q N ) is a normal basis element of the finite field GF(q N ) is a normal basis of [β [0] ,β [1] ,···,β [N-1] ]. Also, let n be a divisor of N. Finite field GF(q N ) subfield GF(q n ) is a normal basis element of α. In other words, the finite field GF(q n ) is a normal basis of [α [0] ,α [1] ,···,α [n-1] ]. On the other hand, α is constructed in the finite field GF(q N ), and the finite field GF(q N ) using the normal basis element β is as follows: α=α0β [0] +α1β [1] +···+α n-1 β [n-1] +α0β [n] +α1β [n+1] +···+α n-1 β [2n-1] +α n-1 β [N-1] There are various methods for determining α. For example, α can be determined by random search.

[0060] In step 3, the basis conversion unit 21 converts the following γ into a subfield GF(q n ) to convert it to its original form. γ=γ0β [0] +γ1β [1] +···+γ n-1 β [n-1] +γ0β [n] +γ1β [n+1] +···+γ n-1 β [2n-1] + γ n-1 β [N-1]

[0061] The calculation formula performed by the basis conversion unit 21 is as follows:

number

[0062] That is, the finite field GF(q N ) only n symbols are picked out of the N symbols of the element. For example, in the finite field GF(q N ), n coefficients γ0, γ1, . . . , γ appear periodically when γ, an element of n-1 is picked up. Furthermore, in the finite field GF(q N ), n coefficients α0, α1, . . . , α that appear periodically when α, an element of n-1 Next, the inverse matrix P of the matrix P consisting of the n symbols picked up for γ and the n symbols picked up for α is calculated. -1 This multiplication is the basis conversion. After the basis conversion, γ' will have n symbols.

[0063] Note that GF(q n ) is a finite field GF(q N ), so the finite field GF(q N ) is a subfield GF(q n ) can be converted into an element of the subfield GF(q n ), but if it is not possible to convert it, it is determined that correction is impossible and the decoding is stopped. By stopping the decoding at an early stage, unnecessary calculations can be reduced. n ) is guaranteed in advance.

[0064] Step 4: Calculate the root (d) of ELP The ELP root calculation unit 13 finds the root (d) of the ELP using Gaussian elimination. The root d of the following equation can be found by solving the following equation for x:

number

[0065] This formula contains a Frobenius q-power exponent, making it an easy-to-solve linear system. Here, α is a function of the subfield GF(q n ) and has N symbols.

number

[0066] The j-th column of Ψ is α [j] can be easily found by substituting

number

[0067] Finite field GF(16 16 ) (i.e., q=16, N=16, n=4) is used as an example to explain the cases with and without basis transformation. When basis transformation is not performed, γ and α are in the finite field GF(q N ) and has 16 symbols. Then, Ψ0 to Ψ3 (column vectors of matrix Ψ) calculated by the following formula are also elements of the finite field GF(q N ) and has 16 symbols.

number

[0068] In this way, when no basis conversion is performed, column vectors Ψ0, Ψ1, Ψ2 and Ψ3 having 16 symbols are calculated using multiplication and Frobenius q-th powers.

[0069] The basis of the solution space for ΨX=0 can be found using Gaussian elimination as follows:

number

[0070] In contrast, according to the present embodiment in which a basis conversion is performed, γ and α are first converted by the basis conversion (the converted values ​​are

number

number

number

number

number

number

[0071] In this way, when the basis change is performed, a column vector with four symbols is obtained by multiplication and exponentiation of Frobenius q.

number

[0072]

number

number

[0073] Target matrix

number

[0074] As mentioned above using the Gab(4,2) code as an example, the calculation of the column vectors Ψ0, Ψ1, Ψ2, and Ψ3 without basis conversion is

number

number

[0075] The basis transformation will be explained again below. Multiplication is required in the process of finding the root d. If the basis transformation in step 3 is not performed, step 4 is N ) multiplication over the finite field GF(q N ) is complex, so a method using a multiplication table has been proposed to reduce the amount of calculation. A multiplication table is an NxN matrix, and multiplication is performed using matrix operations. However, when N is large, the amount of calculation for multiplication is still large. In this embodiment, since the basis transformation is performed in step 3, step 4 is performed in the subfield GF(q n ) The multiplication table is an n×n matrix, which can significantly reduce the amount of multiplication calculations. In the application of Gabidulin codes to LNC, it is desirable to set N to a large value, and n is often much smaller than N. For example, N = 4000, n = 4. In this case, the finite field GF(q N ) is a 4000 × 4000 matrix, while the multiplication table for multiplication over the subfield GF(q n ) is a 4×4 matrix. n ) matrix operations are performed on the finite field GF(q N ) The amount of calculation is clearly less than the matrix operations above. It is also trivial that other calculations such as addition and Frobenius q-power exponentiation are simplified.

[0076] Step 5: Calculate the error coefficient (Θ) The error coefficient calculation unit 14 calculates the error coefficient Θ from the root d. Θ can be calculated from d using the following relationship:

number

[0077] Step 6: Inverse basis transformation The calculation to find the error span a in step 7 described later is performed over the finite field GF(q N ) in step 6, the inverse basis transformation unit 22 performs an inverse basis transformation to convert the root d into the finite field GF(q N ) to convert it to its original form.

[0078] Step 7: Calculate the error span a The error span calculation unit 15 calculates the error span a from the root d. The following relationship can be used to calculate a from d:

number

[0079] The error span a is the sum of the finite field GF(q N ), it is necessary to calculate it on the finite field. When the basis transformation (step 3) is performed as in this embodiment, the calculation of the error span a (step 7) must be performed after the inverse basis transformation (step 6). The calculation of the error coefficient Θ (step 5) can be done either before or after the inverse basis transformation (step 6). If the calculation of the error coefficient Θ (step 5) is performed after the inverse transformation of the basis (step 6), it may be performed simultaneously with the calculation of the error span a (step 7).

[0080] Step 8: Estimate the error vector The error vector estimation unit 16 estimates the error vector from the error span a and the error coefficient Θ.

number

[0081] Step 9: Codeword estimation The codeword estimation unit 17 obtains an estimated codeword by subtracting the estimated error vector from the received word x'.

number

[0082] [4 Usage examples] Consider a shortened Gabidulin code Gab(4,2) with the following properties: p=2 s=4 q=p s =24 = 16 ·N = 16 · Finite field: GF(16 16 ) · Symbol length: n = 4 (Since n < N, it is a shortened code) · Number of information symbols: k = 2 · Maximum number of correctable rank errors: τ = 1 · Primitive polynomial: x 16 + x 3 + 8x + 3 · GF(16 16 ) primitive element for constructing a normal basis on: β = x 15 + 9x 2 + 10x + 15 · GF(16 4 ) primitive element for constructing a normal basis on: α = 0001000100010001

[0083] Encoding by the source node is performed by matrix operations on GF(16 16 ) through the generator matrix G. The information data U is a 2-symbol vector on GF(16 16 ) and is shown by the following formula.

Number

[0084] The source node encodes by the product of the generator matrix G and the information data U to obtain the codeword x.

Number

[0085] Suppose the following rank-1 error e is injected into the codeword x, and the received word is x'.

Number

[0086] Decoding in the decoder 2 within the terminal node starts from syndrome calculation, obtains the error span a and the error coefficient Θ, and estimates the error vector e to perform.

[0087] Step 1: Calculate the syndrome The syndrome calculation unit 11 calculates syndromes S0 and S1 from the received word x' and the check matrix H.

number

[0088] Step 2: Calculate ELP The ELP calculation unit 12 calculates the coefficients γ0, γ1 of the error locator polynomial (ELP) and the estimated rank error number τ from the syndromes S0, S1 using the Berlekamp-Massey method.

number

[0089] ELP is given by the following formula:

number

[0090] Step 3: Change the basis The basis conversion unit 21 is a finite field GF(16 16 ) and the element α of the check matrix are placed in the subfield GF(16 4 ) as the element on the left. The method of this transformation is as described above. All elements of the check matrix can be calculated from α.

number

[0091] Step 4: Calculate the root (d) of ELP The root calculation unit 13 of the ELP finds d by finding the root of Γ(x)=0.

number

[0092] Here, since τ=1, d has one element, which is expressed as d0 and shown in the following equation.

number

[0093] Multiplication is required in the process of calculating d0. In step 3, all the numbers used in the calculation are in the subfield GF(16 4 ), and multiplication can be performed by matrix operations using a 4x4 multiplication table. If the base conversion had not been performed, multiplication would be performed by matrix operations using a 16x16 multiplication table. It can be seen that the amount of calculation required for multiplication is significantly reduced by performing the base conversion. It is also obvious that other calculations such as addition and Frobenius q-power exponentiation are also simplified.

[0094] Step 5: Calculate the error coefficient (Θ) The error coefficient calculation unit 14 calculates the error coefficient Θ0 from d0.

number

[0095] Step 6: Inverse basis transformation The basis inversion unit 22 is a subfield GF(16 4 ) into the finite field GF(16 16 )Convert to the element above.

number

[0096] Step 7: Calculate the error span a The error span calculation unit 15 obtains the error span a from d0. Since τ=1, a has one element, which is represented as a0 and is shown in the following equation.

number

[0097] Step 8: Estimate the error vector The error vector estimation unit 16 estimates the error vector from the error span a0 and the error coefficient Θ0.

number

[0098] Step 9: Codeword estimation The codeword estimation unit 17 obtains an estimated codeword by subtracting the estimated error vector from the received word x'.

number

[0099] Estimated codeword

number

[0100] According to the above embodiment, it is possible to reduce the amount of calculation required to correct rank errors that tend to occur in communication networks where linear network coding is performed.

[0101] [Another embodiment] Without the basis transformation unit 21 in step 3, in step 4, d0 is converted to the finite field GF(16 16 ) In this case, the inverse basis transformation in step 6 is not necessary, and the calculated d0 can be used directly to calculate a0 in step 7. On the other hand, in step 5, since it becomes impossible to use the calculated d0 directly to calculate Θ0, it is necessary to first calculate d0 in the subfield GF(16 4 ) must be converted to its original form. However, in this embodiment, all the operations in step 4 (the ELP root (d) calculation unit) which require many multiplications are performed in GF(16 16 ), the effect of reducing the amount of calculation is small.

[0102] The above embodiment can be implemented using not only the Gabidulin code but also the MRD code. The shortened Gabidulin code and the shortened MRD code according to the above embodiment can also be used independently of linear network coding. 5. The decoder is only required to include at least the basis transformation unit 21. The decoder is also required to include the finite field GF(q N ) and the subfield GF(q n ) and performing a decoding process including calculations using a basis of the above. Such a decoder can reduce the amount of calculations required when using an MRD code.

[0103] 6 shows an example of the computer hardware configuration of terminal node t0. Terminal node t0 includes a CPU 351, an interface device 352, a display device 353, an input device 354, a drive device 355, an auxiliary storage device 356, and a memory device 357, which are interconnected by a bus 358.

[0104] A program that realizes the functions of terminal node t0 is provided by a recording medium 359 such as a CD-ROM. When recording medium 359 on which the program is recorded is set in drive device 355, the program is installed from recording medium 359 to auxiliary storage device 356 via drive device 355. Alternatively, the program does not necessarily have to be installed by recording medium 359, but can also be installed via a network. Auxiliary storage device 356 stores the installed program as well as necessary files, data, etc.

[0105] The memory device 357 reads and stores the program from the auxiliary storage device 356 when an instruction to start the program is received. The CPU 351 realizes the functions of the terminal node t0 in accordance with the program stored in the memory device 357. The interface device 352 is used as an interface for connecting to other computers via a network. The display device 353 displays a GUI (Graphical User Interface) or the like according to the program. The input device 354 is a keyboard, a mouse, or the like.

[0106] It should be noted that other nodes within the communication network also have the same computer hardware configuration as that of terminal node t0.

[0107] The embodiments described above have aspects not only as an apparatus but also as a method and a computer program.

[0108] The following notes are provided regarding the embodiments described above. [Appendix 1] Finite field GF(q N A decoder for decoding a signal encoded by the MRD code above, The finite field GF(q N ) is defined as the basis of the finite field GF(q N ) subfield GF(q n ), where q is a power of a prime number, and n is a divisor of N; The decryption is performed by decrypting the finite field GF(q N ) and the subfield GF(q n ) basis, Decoder. [Appendix 2] The finite field GF(q N ) and an N×N multiplication table for performing multiplication over the subfield GF(q n an n×n multiplication table for performing multiplications on The multiplication before the transformation by the basis transformation unit is performed using the N×N multiplication table; The multiplication after the conversion by the basis conversion unit is performed using the n×n multiplication table. 10. A decoder according to claim 1. [Appendix 3] The subfield GF(q n ) is the basis of the finite field GF(q N ) a basis inversion unit for inversely transforming the basis of the The decoding further includes decoding the finite field GF(q N ), including calculations using a basis of 3. A decoder according to claim 1 or 2. [Appendix 4] a syndrome calculation unit for calculating a syndrome from the signal; an error locator polynomial calculation unit that uses the syndrome to calculate an error locator polynomial; a root computation unit for computing the roots of the error locator polynomial; an error coefficient calculation unit for calculating an error coefficient from said root; an error span calculation unit for calculating an error span from the root; an error vector estimation unit for estimating an error vector from the error coefficients and the error span; a code word estimation unit for estimating a code word from the error vector; Furthermore, The syndrome calculation unit and the error locator polynomial calculation unit calculate the error locator polynomial over the finite field GF(q N ) basis, The root calculation unit calculates the root of the subfield GF(q n ) basis, The error coefficient calculation unit calculates the error coefficient of the finite field GF(q N ) and the subfield GF(q n ) and calculate using one of the bases, The error span calculation unit, the error vector estimation unit, and the codeword estimation unit calculate the finite field GF(q N ) basis for calculations, 10. A decoder according to claim 3. [Appendix 5] 5. The decoder according to claim 1, wherein if the basis conversion unit is unable to correctly perform conversion, the decoder determines that correction is impossible. [Appendix 6] A communication network having a plurality of nodes and in which communication is carried out using network coding, wherein at least one of the plurality of nodes is equipped with a decoder according to any one of Supplementary Notes 1 to 5.

[0109] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various modifications and changes can be made based on the technical concept of the present invention. [Explanation of symbols]

[0110] NW1 Communication Network 1,2 Decoder 11 Syndrome Calculation Unit 12 ELP Computational Units 13 ELP root calculation unit 14 Error Coefficient Calculation Unit 15 Error Span Calculation Unit 16 Error Vector Estimation Unit 17 Codeword Estimation Unit 21 Basis Conversion Unit 22 Basis Inversion Unit

Claims

1. A finite field GF(q) consisting of normal bases N ) A decoder for decoding a signal encoded by the MRD code above, The finite field GF(q N ) is defined as the basis of the finite field GF(q N ) subfield GF(q n ) where q is a power of a prime number and n is a divisor of N; The decryption is performed by decrypting the finite field GF(q N ) and the subfield GF(q n ) basis, Decoder.

2. The finite field GF(q N an N×N multiplication table for performing multiplication over the subfield GF(q n an n×n multiplication table for performing multiplications on The multiplication before the transformation by the basis transformation unit is performed using the N×N multiplication table; The multiplication after the conversion by the basis conversion unit is performed using the n×n multiplication table. The decoder of claim 1 .

3. The subfield GF(q n ) is the basis of the finite field GF(q N a basis inversion unit for inversely transforming the basis of the The decoding further includes decoding the finite field GF(q N ), including calculations using a basis of 3. A decoder according to claim 1 or 2.

4. a syndrome calculation unit for calculating a syndrome from the signal; an error locator polynomial calculation unit that uses the syndrome to calculate an error locator polynomial; a root computation unit for computing the roots of the error locator polynomial; an error coefficient calculation unit for calculating an error coefficient from said root; an error span calculation unit for calculating an error span from the root; an error vector estimation unit for estimating an error vector from the error coefficients and the error span; a code word estimation unit for estimating a code word from the error vector; Furthermore, The syndrome calculation unit and the error locator polynomial calculation unit calculate the error locator polynomial over the finite field GF(q N ) basis for calculations, The root calculation unit calculates the root of the subfield GF(q n ) basis for calculations, The error coefficient calculation unit calculates the finite field GF(q N ) and the subfield GF(q n ) and calculate using one of the bases, The error span calculation unit, the error vector estimation unit, and the codeword estimation unit calculate the finite field GF(q N ) basis for calculations, 4. The decoder of claim 3.

5. 5. The decoder according to claim 1, wherein when the basis conversion unit is unable to perform conversion correctly, the decoder determines that correction is impossible.

6. A communication network having a plurality of nodes and in which communication is performed by network coding, wherein at least one node among the plurality of nodes is equipped with a decoder according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • One-time pads encryption hub

    CN113544999A

  • Finite field inverse element circuit

    JP1989181232A

  • Chien search using multiple basis representation

    US20100332955A1

  • Error correction method, error correction device and recording medium in which error correction program is recorded

    WO2001084719A1