Functional cryptographic system and method, encryption device, decryption device, setup device, key generation device, and program

By integrating quantum-safe indistinguishability obfuscation and puncturable pseudorandom functions, the method prevents the copying of function keys, enhancing the security of functional cryptography against quantum computers.

JP7772211B2Active Publication Date: 2025-11-18NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024527899
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-13
Publication Date
2025-11-18
Estimated Expiration
2042-06-13

AI Technical Summary

Technical Problem

Conventional functional cryptography methods cannot prevent the copying of function keys, as they are based on classical computing technologies and lack the capability to secure digital data from unauthorized duplication.

Method used

A public key functional cryptosystem and a private key copy-protected system are integrated to generate and manage function keys, utilizing quantum-safe indistinguishability obfuscation and puncturable pseudorandom functions to ensure that function keys cannot be copied, even on quantum computers.

Benefits of technology

The proposed method effectively prevents the copying of function keys, ensuring data security by leveraging quantum mechanics principles to maintain the confidentiality of cryptographic functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007772211000001
    Figure 0007772211000001
  • Figure 0007772211000002
    Figure 0007772211000002
  • Figure 0007772211000003
    Figure 0007772211000003
Patent Text Reader

Abstract

A key generation unit 2 of this functional encryption system (i) generates a function key fe.skf in PKFE from an msk and a predetermined key generation function f on the basis of a key generation algorithm PKFE.KG of PKFE, (ii) generates a quantum function key sde.dk~ in SDE from sde.dk included in the msk on the basis of a key generation algorithm QKG~ of SDE, and (iii) outputs a quantum function key skf that is a pair of fe.skf and sde.dk~. By thus generating the quantum function key skf~ as a function key, the function key can be prevented from being copied.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The disclosed technology relates to public key functional cryptography used in telecommunications systems. [Background technology]

[0002] As public key functional cryptography capable of generating a predetermined polynomial number of functional keys, for example, the Gorbunov, Vaikuntanathan, and Wee scheme (see, for example, Reference 1) and the Ananth, Vaikuntanathan scheme (see, for example, Reference 2) can be used. If the one-way functions and public key cryptography used as components of these schemes are quantum computer-safe, the resulting public key functional cryptography will also be quantum computer-safe. Furthermore, by using indistinguishability obfuscation that is quantum computer-safe, it is possible to realize public key functional cryptography that can generate an unlimited number of functional keys (see, for example, Non-Patent Document 1).

[0003] It is known that there are several candidates for quantum-safe indistinguishability obfuscation (see, for example, references 3 to 6). All of these functional cryptography methods can handle polynomial-sized circuits.

[0004] As one-way functions and public key cryptography that are secure against quantum computers, for example, Regev's scheme (see, for example, Reference 7) and Peikert's scheme (see, for example, Reference 8) are available.

[0005] As a puncturable pseudorandom function that is secure against quantum computers, for example, a method that realizes the Goldwasser, Goldreich, and Micali method (see, for example, Reference 9) using a one-way function that is secure against quantum computers can be used.

[0006] As a private key copy-protectable public key cryptosystem, the Coladangelo, Liu, Liu, and Zhandry scheme (see, for example, Reference 10) is available.

[0007] Figure 1 Sergey Gorbunov, Vinod Vaikuntanathan, and Hoeteck Wee. Functional encryption with bounded collusions via multi-party computation. In Reihaneh Safavi-Naini and Ran Canetti, editors, CRYPTO 2012, volume 7417 of LNCS, pages 162-1 Springer, Heidelberg, August 2012. Picture 2 Prabhanjan Ananth and Vinod Vaikuntanathan. Optimal bounded-collusion secure functional encryption. In Dennis Hofheinz and Alon Rosen, editors, TCC 2019, Part I, volume 11891 of LNCS, pages 174-1 Springer, Heidelberg, December. Picture 3: Shweta Agrawal and Alice Pellet-Mary. Indistinguishability obfuscation without maps: Attacks and fixes for noisy linear FE. In Anne Canteaut and Yuval Ishai, editors, EUROCRYPT 2020, Part I, volume 12105 of LNCS, pages 110-140. Springer, Heidelberg, May. Figure 4: James Bartusek, Jiaxin Guan, Fermi Ma, and Mark Zhandry. Return of GGH15: Provable security against zeroizing attacks. In Amos Beimel and Stefan Dziembowski, editors, TCC 2018, Part II, volume 11240 of LNCS, pages 544-574. Springer, Heidelberg, November 2018. Page 5 of Hoeteck Wee and Daniel Wichs. Candidate obfuscation via oblivious LWE sampling. In Anne Canteaut and Francois-Xavier Standaert, editors, EUROCRYPT 2021, Part III, volume 12698 of LNCS, pages 127-156. Springer, Heidelberg, October 2021. Picture 6: Romain Gay and Rafael Pass. Indistinguishability obfuscation from circular security. Cryptology ePrint Archive, Report 2020 / 1010, 2020. https: / / eprint.iacr.org / 2020 / 1010. Figure 7. Oded Regev. On lattices, learning with errors, random linear codes, and cryptography. Journal of the ACM, 56(6):34:1-34:40, 2009. [Reference 8] Chris Peikert. Public-key cryptosystems from the worst-case shortest vector problem: extended abstract. In Michael Mitzenmacher, editor, 41st ACM STOC, pages 333-342. ACM Press, May / June 2009. [Reference 9] Oded Goldreich, Shafi Goldwasser, and Silvio Micali. How to construct random functions. Journal of the ACM, 33(4):792-807, 1986. [Reference 10] Andrea Coladangelo, Jiahui Liu, Qipeng Liu, and Mark Zhandry. Hidden cosets and applications to unclonable cryptography. In Tal Malkin and Chris Peikert, editors, CRYPTO 2021, Part I, volume 12825 of LNCS, pages 556-584, Virtual Event, August 2021. Springer, Heidelberg. [Prior art documents] [Non-patent literature]

[0008] [Non-Patent Document 1] Sanjam Garg, Craig Gentry, Shai Halevi, Mariana Raykova, Amit Sahai, and Brent Waters. Candidate indistinguishability obfuscation and functional encryption for all circuits. SIAM Journal on Computing, 45(3):882-929, 2016. Summary of the Invention [Problem to be solved by the invention]

[0009] There are several conventional functional cryptography methods described in the background art that can handle circuits of all polynomial sizes, but none of them can prevent copying of the function key. This is due to the fundamental problem that all existing descriptions use only technology based on classical computers, and cannot prevent copying of digital data. If copying of the function key cannot be prevented, once the function key sk f If this is given to a user, that user can copy the function key and distribute it to other users illegally.

[0010] Because of the above problems, it would be more desirable to have a function that can prevent the copying of functional keys. However, to date, no functional cryptography has been available that can prevent the copying of functional keys.

[0011] The disclosed technology aims to make it possible to prevent function keys from being copied. [Means for solving the problem]

[0012] In one aspect of the disclosed technology, PKFE is a public key functional cryptosystem capable of generating only one function key, and SDE is a private key copy-protected public key cryptosystem, comprising: a setup unit that (i) generates a public key fe.pk in PKFE and a master private key fe.msk in PKFE from predetermined security parameters based on a setup algorithm PKFE.Setup in PKFE; (ii) generates a public key sde.pk in SDE and a master private key sde.dk in SDE from predetermined security parameters based on a setup algorithm SDE.Setup in SDE; and (iii) outputs a public key pk that is a pair (fe.pk, sde.pk) of fe.pk and sde.pk, and a master private key msk that is a pair (fe.msk, sde.dk) of fe.msk and sde.dk; and (i) generates a function key fe.sk in PKFE from msk and a predetermined key generation function f based on a key generation algorithm PKFE.KG of PKFE. f (ii) generate a quantum function key sde.dk~ in the SDE from sde.dk included in msk based on the key generation algorithm QKG~ in the SDE; and (iii) generate fe.sk f and the quantum function key sk, which is a set of sde.dk~ f and (i) a key generation unit that generates PKFE ciphertext fe.ct from fe.pk included in public key pk and plaintext x based on the PKFE encryption algorithm PKFE.Enc. x (ii) generating sde.pk and fe.ct included in the public key pk based on the encryption algorithm SDE.Enc in the SDE; x (iii) an encryption unit that generates a ciphertext sde.ct in the SDE from the ciphertext ct, and (i) a decryption unit that generates a ciphertext sde.ct in the SDE based on the decryption algorithm SDE.Dec~ in the SDE. f From the ciphertext ct, which is sde.dk~ and sde.ct included in ~, the decryption result fe.ct in SDE x (ii) generate fe.ct based on the decryption algorithm PKFE.Dec in PKFE x and a decoding unit that generates a decoding result y from '.

[0013] In a functional cryptosystem according to one aspect of the present invention, PPRF and PPRF' are puncturable pseudorandom functions, iO1 and iO2 are indistinguishable obfuscation algorithms, and 1SDFE is a functional key copy-protected public key functional cryptosystem capable of generating only one functional key, and (i) a key K in PPRF is generated from predetermined security parameters based on a setup algorithm PRF.Gen in PPRF, and a predetermined setup circuit S 1fe [K] is generated, and (ii) S 1fe Algorithm iO1(S 1fe (i) a setup part that outputs a public key ^pk and a master private key ^msk, where L is a predetermined positive integer and the tag τ←{0,1} L (ii) based on the evaluation function F in the PPRF, generate a value r τ Calculates the given security parameters and r based on the setup algorithm 1SDFE.Setup in 1SDFE. τ From the master private key msk τ and public key pk τ (iii) generating msk based on the key generation algorithm 1SDFE.QKG~ in 1SDFE τ and a quantum function key sk from a given key generation function f. f ~, and (iv) τ and sk f ~ pair (τ,sk f ~) is a function key ^sk f,τ a key generation unit that generates a key K' in the PPRF' from predetermined security parameters based on a setup algorithm PRF.Gen' in the PPRF', and generates a predetermined encryption circuit E using ^pk, K' and plaintext x; 1fe Generate [^pk,K',x], ​​and (ii) E 1fe The circuit iO2(E 1fe (i) an encryption unit that outputs the ciphertext ^ct, and (ii) a circuit that converts ^ct into ^sk. f,τOutput value ct when τ included in ~ is input τ (ii) calculate sk based on the decoding algorithm 1SDFE.Dec~ in 1SDFE f,τ ~ and ct τ and a decoding unit that generates a decoding result y from [Effects of the Invention]

[0014] According to the disclosed technology, it is possible to prevent the function key from being copied. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a diagram illustrating an example of the functional configuration of a functional cryptosystem. [Figure 2] FIG. 2 is a diagram showing an example of a processing procedure of the functional cryptosystem method. [Figure 3] FIG. 3 is a diagram illustrating an example of a functional configuration of a computer. DETAILED DESCRIPTION OF THE INVENTION

[0016] Hereinafter, embodiments of the disclosed technology will be described with reference to the drawings.

[0017] [Notation and definitions] First, we will explain notation and basic definitions. For various cryptographic functions and basic concepts of cryptography (one-way functions, secret key cryptography, public key cryptography, pseudorandom functions, etc.), please refer to reference 11 and other references. For a function f, f≦negl means that f is a negligible function, and f>negl means that f is a non-negligible function.

[0018] [Reference 11] Daisuke Moriyama, Ryo Nishimaki, and Tatsuaki Okamoto, "Mathematics of Public Key Cryptography," edited by the Japan Society for Industrial and Applied Mathematics, Applied Mathematics Series 2 First, we prepare the necessary notation. x ← X denotes uniformly randomly selecting element x from a finite set X. y ← A(x) denotes that a probabilistic or deterministic algorithm A produces output y for input x. For a finite set S, U(S) denotes a uniform distribution on S. [L] and [L,r] denote the sets of integers {1,...L} and {L,...,r}, respectively. λ denotes a security parameter. λ is a given positive integer. y:=z denotes that y is set, defined, or assigned to z.

[0019] Note that "~" is used to indicate algorithms and information that run on a quantum computer. For example, A~, KeyGen~, and pk~ refer to algorithms or information that run on a quantum computer. Algorithms and information without "~" are algorithms and information that run on a normal computer.

[0020] [Cryptographic technology] Below, cryptography techniques necessary for understanding this disclosure will be explained.

[0021] Definition 1.1 (Puncturable pseudorandom function (see References 12-14)) For sets D and R, a puncturable pseudorandom function PPRF consists of a set of algorithms (PRF.Gen, F, Punc) that satisfy the following "functionality preservation under puncturing" and "pseudorandomness at punctured points".

[0022] Functional preservation under holes: A subset of any polynomial size {x i} i∈[k] ⊆D, any x∈D\{x i} i∈[k] For Pr[F(K,x)=F(K * ,x):K←PRF.Gen(1 λ ),K←Punc(K * ,{x i} i∈[k] )]=1 holds.

[0023] Pseudorandomness at the punctured point: All polynomial-sized subsets {xi} i∈[k] ⊆D, for every polynomial-time attacker A~, the following holds:

[0024] Adv pprf F,A~ :=Pr[A~(K * ,{F(K,x i )} i∈[k] )=1]-Pr[A~(K * ,U k )=1]≦negl(λ) However, K←PRF.Gen(1 λ ),K * ←Punc(K,{x i} i∈[k] ) and U denotes the uniform distribution on R.

[0025] Note that PRF.Gen is a key generation algorithm in PPRF, F is an evaluation function in PPRF, and Punc is a puncturing function in PPRF. λ ) is {0,1} λ The polynomial-time attacker A is an attacker using a quantum computer algorithm.

[0026] [Reference 12] Dan Boneh and Brent Waters. Constrained pseudorandom functions and their applications. In Kazue Sako and Palash Sarkar, editors, ASIACRYPT 2013, Part II, volume 8270 of LNCS, pages 280-300. Springer, Heidelberg, December 2013. [Reference 13] Elette Boyle, Shafi Goldwasser, and Ioana Ivan. Functional signatures and pseudorandom functions. In Hugo Krawczyk, editor, PKC 2014, volume 8383 of LNCS, pages 501-519. Springer, Heidelberg, March 2014. [Reference 14] Aggelos Kiayias, Stavros Papadopoulos, Nikos Triandopoulos, and Thomas Zacharias. Delegatable pseudorandom functions and applications. In Ahmad- Reza Sadeghi, Virgil D. Gligor, and Moti Yung, editors, ACM CCS 2013, pages 669-684. ACM Press, November 2013. Theorem 1.2 (See, e.g., References 10, 12-14.) If there exists a one-way function, then there exists a holey pseudorandom function that maps an n(λ)-bit string to an m(l)-bit string for any efficiently computable n(λ) and m(λ).

[0027] Definition 1.3 (Indistinguishability Obfuscation (see, for example, Reference 15 and Non-Patent Document 1)) A probabilistic polynomial-time algorithm iO is a circuit class {C λ} λ Indistinguishability obfuscation for ∈N means that it satisfies the following "functionality" and "indistinguishability".

[0028] Functionality: Any security parameter λ∈N, circuit C∈C λ , for input x, Pr[C'(x)=C(x)|C'←iO(C)]=1 holds true.

[0029] Indistinguishability: For any polynomial-time attacker D, for any circuit C0,C1∈C such that C0(x)=C1(x) and |C0|=|C1| for any input x. λ In contrast, Adv io iO,D~ (λ):=|Pr[D~(iO(C0))=1]-Pr[D~(iO(C1))=1]|≦negl(λ) holds true.

[0030] [Reference 15] Boaz Barak, Oded Goldreich, Russell Impagliazzo, Steven Rudich, Amit Sahai, Salil P. Vadhan, and Ke Yang. On the (im)possibility of obfuscating programs. Journal of the ACM, 59(2):6:1-6:48, 2012. The polynomial-time attacker D~ is an algorithmic attacker using a quantum computer.

[0031] Definition 1.4 (Public-key functional cryptography (see, e.g., Reference 16)) Public key functional encryption PKFE for plaintext space X, output space Y, and function space F is the following set of probabilistic polynomial-time algorithms (Setup, KeyGen, Enc, Dec).

[0032] Setup(1 λ ) → (msk,pk): The setup algorithm uses security parameters 1 λ It takes as input a master private key msk and a public key pk as output.

[0033] KeyGen(msk,f) →sk f : The key generation algorithm takes a master secret key msk and a function f∈F as input and generates a function key sk f Output.

[0034] Enc(pk,x)→ct x: The encryption algorithm takes a public key pk and plaintext x∈X as input and generates ciphertext ct x Output.

[0035] Dec(sk f ,ct x ) → y: The decryption algorithm is the function key sk f and the ciphertext ct x It takes input as input and outputs y∈Y or ⊥, where ⊥ indicates that an error has occurred.

[0036] [Reference 16] Dan Boneh, Amit Sahai, and Brent Waters. Functional encryption: Definitions and challenges. In Yuval Ishai, editor, TCC 2011, volume 6597 of LNCS, pages 253-273. Springer, Heidelberg, March 2011. ct x sk f By decrypting using the function f(x), we can obtain f(x). i} i∈[q] sk fi Even if you receive i (x) No more information can be obtained.

[0037] In public key functional cryptography, a master private key is not required for encryption, and encryption can be performed using the public key pk.

[0038] Theorem 1.5 (See, for example, Non-Patent Document 1.) If indistinguishability obfuscation and a one-way function exist, then there exists public key functional cryptography that can generate an unlimited number of functional keys in a polynomial number.

[0039] Definition 1.6 (Private Key Copy-Protected Public Key Cryptography) The secret key copy-protected public key encryption SDE consists of the following four algorithms (Setup, QKG, Enc, Dec). In the following, M is the plaintext space of SDE.

[0040] Setup(1 λ ) → (pk,sk): The setup algorithm uses security parameter 1 λ It takes as input and outputs the public key pk and the private key sk.

[0041] QKG~(sk) → sk~: The key generation algorithm QKG takes a private key sk as input and outputs a quantum decryption key sk~, which is in a quantum state. This is a quantum algorithm.

[0042] Enc(pk,m)→ct m : The encryption algorithm takes a public key pk and plaintext m∈M as input and generates ciphertext ct m Output.

[0043] Dec~(sk,ct m ) → m': The decryption algorithm is the quantum decryption key sk~ and the ciphertext ct m It takes as input m'∈{⊥}∪M and outputs m'∈{⊥}∪M. This is a quantum algorithm.

[0044] ct using sk~ m By decrypting, you can get m. m It is impossible to obtain any information about m from sk~, and it is also impossible to create a copy of sk~.

[0045] Theorem 1.7 (See, e.g., References 10 and 17.) Under the assumption that indistinguishability obfuscation exists that is secure against quantum attackers and that a problem called the learning with errors problem cannot be broken even by a quantum computer, secret-key copy-resistant public-key cryptography exists.

[0046] [Reference 17] Eric Culf and Thomas Vidick. A monogamy-of-entanglement game for subspace coset states. CoRR, abs / 2107.13324, 2021. Theorem 1.8 (See, for example, Reference 7.) Under the assumption that a problem called the learning with errors problem cannot be broken even by a quantum computer, one-way functions and public key cryptography that are secure against quantum computers exist.

[0047] Currently, there is no known algorithm that can break the Learning with Errors problem in polynomial time using a quantum computer, but it is expected that one-way functions and public key cryptography that are secure against quantum computers exist.

[0048] Next, a description will be given of public key functional encryption capable of preventing copying of a function key, in other words, the concept of preventing copying of a function key in functional encryption.

[0049] Definition 1.9 (Functional Key Copy-Proof Public Key Functional Cryptography) The function-key copy-protected public-key functional cipher SDFE consists of five algorithms (Setup, KG, QKG, Enc, Dec). In the following, X, Y, and F are the plaintext, output, and function spaces of SDFE, respectively.

[0050] Setup(1 λ ) → (pk,msk): Setup algorithm is security parameter 1 λ It takes as input a public key pk and a master private key msk as output.

[0051] QKG~(msk,f)→sk f ~: The key generation algorithm takes a master secret key msk and a function f∈F as input and generates a quantum function key sk in a quantum state. f Outputs ~. This is a quantum algorithm.

[0052] Enc(pk,x)→ct x : An encryption algorithm takes a public key pk and plaintext x∈X as input and generates ciphertext ct x Output.

[0053] Dec~(sk f~,ct) → y: The decryption algorithm is the quantum function key sk f ~ and ciphertext ct x It takes as input and outputs y∈{⊥}∪Y. This is a quantum algorithm.

[0054] ct x sk f Decrypting with ~ gives f(x). The attacker can decrypt multiple functions {f i} i∈[q] sk fi Even if you receive ~ i (x) No more information can be obtained. f It is impossible to copy ~.

[0055] [First embodiment] A functional cryptographic system and method according to a first embodiment will be described.

[0056] The functional cryptosystem and method of the first embodiment realizes a public key functional cryptography OSDFE that can generate only one functional key and is capable of preventing copying of the functional key.

[0057] As shown in FIG. 1, the functional cryptosystem of the first embodiment includes a setup unit 1, a key generation unit 2, an encryption unit 3, and a decryption unit 4.

[0058] As shown in Fig. 1, the setup unit 1 is provided in, for example, a setup device A1. The key generation unit 2 is provided in, for example, a key generation device A2. The encryption unit 3 is provided in, for example, an encryption device A3. The decryption unit 4 is provided in, for example, a decryption device A4.

[0059] The setup unit 1, the key generation unit 2, the encryption unit 3, and the decryption unit 4 may be provided in other devices.

[0060] The functional encryption method includes the processes of steps S1 to S4 illustrated in FIG.

[0061] The OSDFE uses the following two components (1) and (2).

[0062] (1) Private key copy-protected public key encryption SDE = (SDE.Setup, SDE.QKG~, SDE.Enc, SDE.Dec~) (2) PKFE = (PKFE.Setup, PKFE.KG, PKFE.Enc, PKFE.Dec) is a (normal) public key functional encryption algorithm that can generate only one functional key. (Setup section 1) The setup unit 1 is configured as follows: λ ) processing is performed.

[0063] OSDFE.Setup(1 λ ) includes, for example, the following processes (1) to (3).

[0064] (1)(fe.pk,fe.msk)←PKFE.Setup(1 λ ) (2)(sde.pk,sde.dk)←SDE.Setup(1 λ ) (3) Output the public key pk:=(fe.pk,sde.pk) and master private key msk:=(fe.msk,sde.dk) The following process is performed.

[0065] That is, the setup unit 1 (i) generates a public key fe.pk in PKFE and a master private key fe.msk in PKFE from predetermined security parameters based on a setup algorithm PKFE.Setup in PKFE, (ii) generates a public key sde.pk in SDE and a master private key sde.dk in SDE from predetermined security parameters based on a setup algorithm SDE.Setup in SDE, and (iii) outputs a public key pk, which is the pair (fe.pk, sde.pk) of fe.pk and sde.pk, and a master private key msk, which is the pair (fe.msk, sde.dk) of fe.msk and sde.dk (step S1).

[0066] The master private key msk is output to the key generation unit 2. The public key pk is output to the encryption unit 3.

[0067] (Key generation unit 2) The key generation unit 2 performs the process of OSDFE.QKG~(msk, f) shown below as an example.

[0068] OSDFE.QKG~(msk,f) includes, for example, the following processes (1) to (4).

[0069] (1) msk = (fe.msk, sde.dk) (2)fe.sk f ←Create PKFE.KG(msk,f) (3) sde.dk~←QKG~(sde.dk) (4) Function key sk f ~:=(fe.sk f ,sde.dk~) output That is, the key generation unit 2 (i) generates a function key fe.sk in PKFE from msk and a predetermined key generation function f based on the key generation algorithm PKFE.KG of PKFE. f (ii) generate a quantum function key sde.dk~ in the SDE from sde.dk included in msk based on the key generation algorithm QKG~ in the SDE; and (iii) generate fe.sk f and the quantum function key sk, which is a set of sde.dk~ f 1 to 4 are output (step S2). In step S2, (i) corresponds to (2), (ii) corresponds to (3), and (iii) corresponds to (4).

[0070] quantum function key sk f ~ is output to the decoding unit 4.

[0071] (Encryption part 3) The encryption unit 3 performs the process of OSDFE.Enc(pk, x) illustrated below.

[0072] OSDFE.Enc(pk,x) includes, for example, the following processes (1) to (4).

[0073] (1) Decompose pk = (fe.pk, sde.pk) (2)fe.ct x ←Create PKFE.Enc(fe.pk,x) (3)sde.ct←SDE.Enc(sde.pk,fe.ct x ) generation (4) ct:=sde.ct output That is, the encryption unit 3 (i) derives ciphertext fe.ct in PKFE from fe.pk included in the public key pk and plaintext x based on the encryption algorithm PKFE.Enc of PKFE. x (ii) generating sde.pk and fe.ct included in the public key pk based on the encryption algorithm SDE.Enc in the SDE; x (iii) generates ciphertext sde.ct in SDE from (i), (ii) corresponds to (ii), (iii) corresponds to (iii), and (iv) corresponds to (iv).

[0074] The ciphertext ct is output to the decryption unit 4 .

[0075] (Decoding unit 4) The decoding unit 4 performs the following OSDFE.Dec~(sk f ~,ct) processing is performed.

[0076] OSDFE.Dec~(sk f ~,ct) includes, for example, the following processes (1) to (3).

[0077] (1)sk f ~=(fe.sk f ,sde.dk~) and decomposition (2)fe.ct x '←Calculate SDE.Dec~(sde.dk~,sde.ct) (3)y←PKFE.Dec(fe.ct x ') That is, the decoding unit 4 (i) decodes the sk based on the decoding algorithm SDE.Dec~ in the SDE. f From the ciphertext ct, which is the sde.dk~ included in ~ and the sde.ct, the decryption result fe.ct in the SDE x (ii) generating the fe.ct based on the decryption algorithm PKFE.Dec in the PKFE; x A decryption result y is generated from (i) and (ii) in step S4.

[0078] OSDFE provides the effect of Theorem 2.1 below.

[0079] Theorem 2.1 If PKFE is a secure public key functional encryption system that can generate only one function key, and SDE is a secure private key copy-resistant public key encryption system, then the proposed method above is a secure function key copy-resistant public key functional encryption system that can generate only one function key.

[0080] In this way, public key functional encryption with function key copy prevention is a public key functional encryption that makes it impossible to copy the function key by utilizing the principles of quantum mechanics. After returning the function key of the function f, even if you obtain the ciphertext of x, you cannot obtain the information of f(x).

[0081] [Second embodiment] A functional cryptographic system and method according to a second embodiment will now be described.

[0082] The functional cryptosystem and method of the second embodiment realizes a functional key copy-protected public key functional cryptography SDFE that can generate an unlimited number of functional keys.

[0083] As shown in FIG. 1, the functional cryptosystem of the second embodiment also includes a setup unit 1, a key generation unit 2, an encryption unit 3, and a decryption unit 4.

[0084] As shown in Fig. 1, the setup unit 1 is provided in, for example, a setup device A1. The key generation unit 2 is provided in, for example, a key generation device A2. The encryption unit 3 is provided in, for example, an encryption device A3. The decryption unit 4 is provided in, for example, a decryption device A4.

[0085] The setup unit 1, the key generation unit 2, the encryption unit 3, and the decryption unit 4 may be provided in other devices.

[0086] The functional encryption method of the second embodiment also includes the processes of steps S1 to S4 illustrated in FIG.

[0087] The processes (steps S1 to S4) of the setup unit 1, key generation unit 2, encryption unit 3, and decryption unit 4 in the second embodiment are different from those in the first embodiment.

[0088] The OSDFE uses the following four components (1) to (4).

[0089] (1) A function key copy-proof public key functional cryptosystem 1SDFE, which can generate only one function key, is defined as follows: 1SDFE = (1SDFE.Setup, 1SDFE.KG, 1SDFE.QKG, 1SDFE.Enc, 1SDFE.Dec) (2) Indistinguishability obfuscation algorithms iO1 and iO2 (3) Punctable pseudorandom function PPRF = (PRF.Gen,F,Punc), where F: {0,1} λ ×{0,1} L →R Setup and R Setup is the random number space of 1SDFE.Setup. L is a predetermined positive integer.

[0090] (4) Punctable pseudorandom function PPRF' = (PRF.Gen', F', Punc'), where F': {0, 1} λ ×{0,1} L →R Enc and R Enc is the random number space of 1SDFE.Enc. L is a predetermined positive integer.

[0091] The random number space of 1SDFE.Enc is the set to which the random numbers used in 1SDFE.Enc belong.

[0092] (Setup section 1) The setup section 1 is SDFE.Setup(1 λ ) processing is performed.

[0093] SDFE.Setup(1 λ ) includes, for example, the following processes (1) and (2).

[0094] (1) K←PRF.Gen(1 λ ) and the setup circuit S 1fe Generate [K] (2)(^pk,^msk):=(iO1(S 1fe ),K) as the public key and master private key. That is, the setup unit 1 (i) generates a key K in the PPRF from predetermined security parameters based on a setup algorithm PRF.Gen in the PPRF, and uses K to generate a predetermined setup circuit S 1fe [K] is generated, and (ii) S 1fe Algorithm iO1(S 1fe [K]) is set as the public key ^pk, and K is output as the master private key ^msk (step S1).

[0095] The master private key ^msk is output to the key generation unit 2. The public key ^pk is output to the encryption unit 3.

[0096] Hereafter, setup circuit S 1fe [K](τ) is explained. Setup circuit S 1fe [K](τ) is also an algorithm that does not have any substance.

[0097] The hard-coded value is the key K of the puncturable pseudorandom function PPRF. The input is a tag τ∈{0,1}L The setup circuit S 1fe [K](τ) includes, for example, the following processes (1) and (2).

[0098] (1)r τ ←Calculate F(K,τ) (2)(pk τ ,msk τ )←1SDFE.Setup(1 λ ;r τ ) and calculate pk τ Output That is, the setup circuit S 1fe [K](τ) is a function that (i) calculates a random number r from τ and a key K in the PPRF based on an evaluation function F in the PPRF. τ (ii) generating a security parameter and r based on a setup algorithm 1SDFE.Setup in 1SDFE. τ From the public key pk τ and private key msk τ Generate a public key pk τ Output.

[0099] 1SDFE.Setup(1 λ ;r τ ) in ";r τ " is a random number used in the 1SDFE setup algorithm 1SDFE.Setup, τ means that is used.

[0100] (Key generation unit 2) The key generation unit 2 performs the process of SDFE.QKG~(^msk,f) illustrated below: SDFE.QKG~(^msk,f) includes, for example, the following processes (1) to (4).

[0101] (1) Decompose K into ^msk and tag τ into {0,1} L Randomly select (2)r τ ←Calculate F(K,τ) and (msk τ ,pk τ )←1SDFE.Setup(1 λ ;rτ ) (3)sk f,τ ~←1SDFE.QKG~(msk τ ,f) is generated. (4)^sk f,τ ~←(τ,sk f,τ Outputs ~) That is, the key generation unit 2 generates a tag τ←{0,1} L (ii) based on the evaluation function F in the PPRF, generate a value r τ Calculates the given security parameters and r based on the setup algorithm 1SDFE.Setup in 1SDFE. τ From the master private key msk τ and public key pk τ (iii) generating msk based on the key generation algorithm 1SDFE.QKG~ in 1SDFE τ and a quantum function key sk from a given key generation function f. f ~, and (iv) τ and sk f ~ pair (τ,sk f ~) is a function key ^sk f,τ 〜 is output (step S2).

[0102] Function key ^sk f,τ ~ is output to the decoding unit 4.

[0103] (Encryption part 3) The encryption unit 3 performs the process SDFE.Enc(^pk,x) illustrated below.

[0104] SDFE.Enc(^pk,x) includes, for example, the following processes (1) and (2).

[0105] (1)K'←PRF.Gen'(1 λ ) and the encryption circuit E 1fe Generate [^pk,K',x] (2)^ct←iO2(E 1fe Output [^pk,K',x]) That is, the encryption unit 3 (i) generates a key K' in the PPRF' from predetermined security parameters based on the setup algorithm PRF.Gen' in the PPRF', and executes encryption using ^pk, K' and plaintext x in a predetermined encryption circuit E 1fe Generate [^pk,K',x], ​​and (ii) E 1fe The circuit iO2(E 1fe [^pk, K', x]) is output as ciphertext ^ct (step S3).

[0106] The ciphertext ^ct is output to the decryption unit 4 .

[0107] Below, encryption circuit E 1fe [^pk,K',x](τ) is explained. Encryption circuit E 1fe [^pk,K',x](τ) is also an algorithm that does not have substance.

[0108] The hard-coded values ​​are the circuit ^pk, the key K' of the puncturable pseudorandom function, and the plaintext x. The input is a tag τ∈{0,1} L Encryption circuit E 1fe [^pk,K',x](τ) includes, for example, the following processes (1) and (2).

[0109] (1) Evaluate the circuit ^pk with input τ. That is, pk τ ←Calculate ^pk(τ).

[0110] (2)r' τ ←Calculate F'(K',τ) and τ ←1SDFE.Enc(pk τ ,x;r' τ ) is output.

[0111] That is, encryption circuit E 1fe [^pk,K',x](τ) is (i) the output value pk when τ is input to the circuit ^pk τ (ii) calculate a random number r' from τ and the key K' in PPRF' based on the evaluation function F' in PPRF';τ Generate a public key pk based on the encryption algorithm 1SDFE.Enc in 1SDFE. τ , plaintext x and r' τ From the ciphertext ^ct τ Generate the ciphertext ^ct τ is taken as the ciphertext ^ct.

[0112] 1SDFE.Enc(pk τ ,x;r' τ ) in ";r' τ " is a random number used in the 1SDFE encryption algorithm 1SDFE.Enc, τ means that is used.

[0113] (Decoding unit 4) The decoding unit 4 performs the following SDFE.Dec~(^sk f ,^ct) processing is performed.

[0114] SDFE.Dec~(^sk f , ^ct) includes, for example, the following processes (1) to (3).

[0115] (1)^sk f,τ ~=(τ,sk f,τ ~) and decomposition (2) Evaluate the ciphertext ^ct with the input τ. That is, ct τ ←Calculate ^ct(τ).

[0116] (3)y←1SDFE.Dec~(sk f,τ ~,ct τ ) That is, the decoding unit 4 (i) adds ^sk to the circuit ^ct. f,τ Output value ct when τ included in ~ is input τ (ii) calculate sk based on the decoding algorithm 1SDFE.Dec~ in 1SDFE f,τ ~ and ct τ The decryption result y is generated from (step S4).

[0117] 1SDFE provides the effect of Theorem 2.2 below.

[0118] Theorem 2.2 If 1SDFE is a secure function-key copy-proof public-key functional encryption scheme that can generate only one function key, iO1 and iO2 are secure indistinguishability obfuscation, and PPRF and PPRF' are secure puncturable pseudorandom functions, then the proposed scheme above is a secure function-key copy-proof public-key functional encryption scheme that can generate an unlimited number of function keys.

[0119] In this way, public key functional encryption with function key copy prevention is a public key functional encryption that makes it impossible to copy the function key by utilizing the principles of quantum mechanics. After returning the function key of the function f, even if you obtain the ciphertext of x, you cannot obtain the information of f(x).

[0120] [Variations] The specific configurations of the embodiments of the disclosed technology are not limited to those described above, and the specific configurations of the embodiments of the disclosed technology can be appropriately modified in design, etc., within the scope of the spirit of the embodiments of the disclosed technology.

[0121] The various processes described in the embodiments of the disclosed technology may not only be performed chronologically in the order described, but may also be performed in parallel or individually depending on the processing capacity of the device performing the processes or as needed.

[0122] For example, data may be exchanged directly between components of the functional cryptosystem, or may be exchanged via a storage unit (not shown).

[0123] [Programs, recording media] The processing of each unit of each of the above-mentioned devices may be realized by a computer, in which case the processing content of the functions that each device should have is described by a program. Then, by loading this program into storage unit 1020 of computer 1000 shown in Fig. 3 and operating arithmetic processing unit 1010, input unit 1030, output unit 1040, display unit 1060, etc., various processing functions of each of the above-mentioned devices are realized on the computer.

[0124] The program describing the processing contents can be recorded on a computer-readable recording medium, such as a non-transitory recording medium, specifically a magnetic recording device, an optical disk, or the like.

[0125] The program may be distributed, for example, by selling, transferring, lending, etc. a portable recording medium such as a DVD or CD-ROM on which the program is recorded. Furthermore, the program may be stored in a storage device of a server computer, and then transferred from the server computer to another computer via a network, thereby distributing the program.

[0126] A computer that executes such a program, for example, first stores the program recorded on a portable recording medium or transferred from a server computer in its own non-transitory storage device, auxiliary storage unit 1050. Then, when executing a process, the computer loads the program stored in auxiliary storage unit 1050, its own non-transitory storage device, into storage unit 1020 and executes processing in accordance with the loaded program. Alternatively, as another form of execution of this program, the computer may load the program directly from a portable recording medium into storage unit 1020 and execute processing in accordance with the program. Furthermore, each time a program is transferred from a server computer to this computer, the computer may execute processing in accordance with the received program. Alternatively, the server computer may not transfer the program to this computer, but may instead execute the processing function by issuing an execution instruction and obtaining the results, thereby executing the above-described processing through a so-called ASP (Application Service Provider) type service. Note that the program in this embodiment includes information used for processing by a computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that define computer processing).

[0127] In this embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing may be realized by hardware. For example, the setup unit 1, key generation unit 2, encryption unit 3, and decryption unit 4 may be configured by a processing circuit.

[0128] It goes without saying that other modifications are possible without departing from the spirit of the present invention.

[0129] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference. [Industrial Applicability]

[0130] One possible use of functional cryptography is to distribute appropriate functional keys to employees of a company and appropriately restrict the data they can access within the encrypted data. However, if an employee copies and takes the distributed functional key with them when they leave the company, the company's data may remain accessible even after they leave. This presents a problem in that it is theoretically impossible to prevent copying with classical computer technology.

[0131] To solve this problem, functional cryptography can be used, which can prevent the copying of functional keys. In the above example, for example, by having employees return their functional keys when they leave the company, it is possible to ensure that no copies remain in the hands of the employee, preventing unintentional data leakage after leaving the company.

Claims

1. PKFE is a public key functional cryptosystem that can generate only one functional key, and SDE is a private key copy-protected public key cryptosystem. (i) a setup unit that generates a public key fe.pk in the PKFE and a master private key fe.msk in the PKFE from predetermined security parameters based on a setup algorithm PKFE.Setup in the PKFE, (ii) generates a public key sde.pk in the SDE and a master private key sde.dk in the SDE from predetermined security parameters based on a setup algorithm SDE.Setup in the SDE, and (iii) outputs a public key pk, which is a pair (fe.pk, sde.pk) of the fe.pk and the sde.pk, and a master private key msk, which is a pair (fe.msk, sde.dk) of the fe.msk and the sde.dk; (i) A function key fe.sk in the PKFE is generated from the msk and a predetermined key generation function f based on the key generation algorithm PKFE.KG of the PKFE. f (ii) generating a quantum function key sde.dk~ in the SDE from the sde.dk included in the msk based on a key generation algorithm QKG~ in the SDE; and (iii) generating a quantum function key sde.dk~ in the SDE from the sde.dk included in the msk based on the key generation algorithm QKG~ in the SDE. f and the quantum function key sk, which is a set of the sde.dk~ f a key generation unit that outputs (i) based on the encryption algorithm PKFE.Enc of the PKFE, the ciphertext fe.ct in the PKFE is obtained from the fe.pk included in the public key pk and the plaintext x. x (ii) generating the sde.pk and fe.ct included in the public key pk based on the encryption algorithm SDE.Enc in the SDE; x (iii) an encryption unit that generates a ciphertext sde.ct in the SDE from the (i) based on the decoding algorithm SDE.Dec~ in the SDE, f From the ciphertext ct, which is the sde.dk~ included in ~ and the sde.ct, the decryption result fe.ct in the SDE x (ii) generating the fe.ct based on the decryption algorithm PKFE.Dec in the PKFE; x a decoding unit that generates a decoded result y from A functional cryptosystem including

2. PPRF,PPRF' are puncturable pseudorandom functions, and iO 1 ,iO 2 is an indistinguishability obfuscation algorithm, and 1SDFE is a function-key copy-resistant public key functional cryptosystem in which only one function key can be generated. (i) generating a key K in the PPRF from predetermined security parameters based on a setup algorithm PRF.Gen in the PPRF, and using the K to generate a predetermined setup circuit S 1fe [K]; and (ii) generating the S 1fe [K] iO 1 The algorithm iO obtained by processing 1 (S 1fe a setup unit that sets [K]) as a public key ^pk and outputs the K as a master private key ^msk; (i) L is a predetermined positive integer, and the tag τ ← {0, 1} L (ii) generating a value r from the τ and the key K in the PPRF based on an evaluation function F in the PPRF; τ and calculating a predetermined security parameter and the r based on a setup algorithm 1SDFE.Setup in the 1SDFE. τ From the master private key msk τ and public key pk τ (iii) generating the msk based on the key generation algorithm 1SDFE.QKG in the 1SDFE τ and a quantum function key sk from a given key generation function f. f (iv) generating τ and sk f ~ pair (τ,sk f ~) is a function key ^sk f,τ a key generation unit that outputs (i) generating a key K' in the PPRF' from predetermined security parameters based on a setup algorithm PRF.Gen' in the PPRF', and encrypting the key K' using the ^pk, K', and plaintext x in a predetermined encryption circuit E 1fe [^pk,K',x], ​​and (ii) generating the E 1fe [^pk,K',x] is the iO 2 The circuit iO obtained by processing 2 (E 1fe an encryption unit that outputs ciphertext ^ct; (i) The circuit ^ct is connected to the circuit ^sk. f,τ The output value ct when the τ included in ~ is input τ (ii) calculating the sk based on the decoding algorithm 1SDFE.Dec~ in the 1SDFE; f,τ ~ and the above ct τ a decoding unit that generates a decoded result y from A functional cryptosystem including

3. An encryption device comprising the encryption unit of the functional encryption system of claim 1.

4. A decryption device comprising the decryption unit of the functional cryptosystem of claim 1.

5. A setup device comprising the setup unit of the functional cryptosystem of claim 1.

6. A key generation device comprising the key generation unit of the functional cryptosystem of claim 1.

7. An encryption device comprising the encryption unit of the functional encryption system of claim 2.

8. A decryption device comprising the decryption unit of the functional cryptosystem of claim 2.

9. A setup device comprising the setup unit of the functional cryptosystem of claim 2.

10. A key generation device comprising the key generation unit of the functional cryptosystem of claim 2.

11. PKFE is a public key functional cryptosystem that can generate only one functional key, and SDE is a private key copy-protected public key cryptosystem. a setup step in which a setup unit (i) generates a public key fe.pk in the PKFE and a master private key fe.msk in the PKFE from predetermined security parameters based on a setup algorithm PKFE.Setup in the PKFE, (ii) generates a public key sde.pk in the SDE and a master private key sde.dk in the SDE from predetermined security parameters based on a setup algorithm SDE.Setup of the SDE, and (iii) outputs a public key pk, which is a pair (fe.pk, sde.pk) of the fe.pk and the sde.pk, and a master private key msk, which is a pair (fe.msk, sde.dk) of the fe.msk and the sde.dk; A key generation unit (i) generates a function key fe.sk in the PKFE from the msk and a predetermined key generation function f based on a key generation algorithm PKFE.KG of the PKFE. f (ii) generating a quantum function key sde.dk~ in the SDE from the sde.dk included in the msk based on a key generation algorithm QKG~ in the SDE; and (iii) generating a quantum function key sde.dk~ in the SDE from the sde.dk included in the msk based on the key generation algorithm QKG~ in the SDE. f and the quantum function key sk, which is a set of the sde.dk~ f a key generation step that outputs an encryption unit (i) deriving an encrypted text fe.ct in the PKFE from the fe.pk included in the public key pk and plain text x based on an encryption algorithm PKFE.Enc of the PKFE; x (ii) generating the sde.pk and fe.ct included in the public key pk based on the encryption algorithm SDE.Enc in the SDE; x (iii) an encryption step of generating a ciphertext sde.ct in the SDE from A decoding unit (i) decodes the sk based on a decoding algorithm SDE.Dec~ in the SDE. f From the ciphertext ct, which is the sde.dk~ included in ~ and the sde.ct, the decryption result fe.ct in the SDE x (ii) generating the fe.ct based on the decryption algorithm PKFE.Dec in the PKFE; x a decoding step of generating a decoded result y from '; Functional cryptography methods, including:

12. PPRF,PPRF' are puncturable pseudorandom functions, and iO 1 ,iO 2 is an indistinguishability obfuscation algorithm, and 1SDFE is a function-key copy-resistant public key functional cryptosystem in which only one function key can be generated. A setup unit (i) generates a key K in the PPRF from predetermined security parameters based on a setup algorithm PRF.Gen in the PPRF, and uses the K to generate a predetermined setup circuit S 1fe [K]; and (ii) generating the S 1fe [K] iO 1 The algorithm iO obtained by processing 1 (S 1fe a setup step of setting [K] as a public key ^pk and outputting K as a master private key ^msk; The key generation unit: (i) L is a predetermined positive integer, and the tag τ ← {0, 1} L (ii) generating a value r from the τ and the key K in the PPRF based on an evaluation function F in the PPRF; τ and calculating a predetermined security parameter and the r based on a setup algorithm 1SDFE.Setup in the 1SDFE. τ From the master private key msk τ and public key pk τ (iii) generating the msk based on the key generation algorithm 1SDFE.QKG in the 1SDFE τ and a quantum function key sk from a given key generation function f. f (iv) generating τ and sk f ~ pair (τ,sk f ~) is a function key ^sk f,τ a key generation step that outputs An encryption unit (i) generates a key K' in the PPRF' from predetermined security parameters based on a setup algorithm PRF.Gen' in the PPRF', and generates a key K' in the PPRF' from predetermined security parameters using the ^pk, the K', and the plaintext x in a predetermined encryption circuit E 1fe [^pk,K',x], ​​and (ii) generating the E 1fe [^pk,K',x] is the iO 2 The circuit iO obtained by processing 2 (E 1fe [^pk,K',x]) as ciphertext ^ct; A decoding unit (i) converts the ^sk into the ^ct which is a circuit. f,τ The output value ct when the τ included in ~ is input τ (ii) calculating the sk based on the decoding algorithm 1SDFE.Dec~ in the 1SDFE; f,τ ~ and the above ct τ a decoding step of generating a decoded result y from Functional cryptography methods, including:

13. A program for causing a computer to function as the encryption unit of the encryption device of claim 3, the decryption unit of the decryption device of claim 4, the setup unit of the setup device of claim 5, the key generation unit of the key generation device of claim 6, the encryption unit of the encryption device of claim 7, the decryption unit of the decryption device of claim 8, the setup unit of the setup device of claim 9, or the key generation unit of the key generation device of claim 10.