Security system, pseudorandom function generator, watermark extractor, and program

The pseudorandom number function generator with embedded watermarks resists attacks from quantum computing devices by using a watermark extraction device to detect and prevent watermark removal.

JP7794305B2Active Publication Date: 2026-01-06NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024520142
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-11
Publication Date
2026-01-06
Estimated Expiration
2042-05-11

AI Technical Summary

Technical Problem

Conventional pseudorandom number generating functions with embedded watermarks are not resistant to attacks by quantum computing devices that mimic their behavior but remove the watermark.

Method used

A pseudorandom number function generator that includes a watermark m∈{0,1} and generates a function C~ with embedded watermarks, using a setup unit, key generation, and watermark embedding unit, and a watermark extraction device to detect quantum computing devices that mimic the function but have removed the watermark.

Benefits of technology

Provides resistance to attacks by quantum computing devices that mimic the behavior of the pseudorandom number generation function with embedded watermarks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007794305000007
    Figure 0007794305000007
  • Figure 0007794305000008
    Figure 0007794305000008
  • Figure 0007794305000009
    Figure 0007794305000009
Patent Text Reader

Abstract

This pseudorandom function generation device generates a pseudorandom function C~ in the manner below, in which a watermark m∈{0,1}Lm is embedded in a pseudorandom function that outputs an output value y∈Ran for the input of an input value x∈Dom. Here, Dom denotes an input space, Ran denotes an output space, Lm denotes a positive integer, and x1||x2 represents a connection between x1 and x2. (1) A setup unit outputs a public parameter pp and a watermark extraction key xk. (2) A key generation unit takes the public parameter pp for input and outputs a PRF key prfk and a public tag τ. (3) A watermark embedding unit takes the public key pp, the PRF key prfk and a watermark m for input and outputs a pseudorandom function C~ in which a message m||0 that is a bit connection of the watermark m and 0 is embedded.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a pseudorandom function technology for embedding a digital watermark, and more particularly to a technology that is resistant to attacks using a quantum computing device. [Background technology]

[0002] Pseudorandom number generating functions in which digital watermarks (hereinafter sometimes simply referred to as "watermarks") are embedded have been proposed (see, for example, Non-Patent Documents 1 to 5). [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] Aloni Cohen, Justin Holmgren, Ryo Nishimaki, Vinod Vaikuntanathan, and Daniel Wichs, "Watermarking cryptographic capabilities," In Daniel Wichs and Yishay Mansour, editors, 48th ACM STOC, pages 1115-1127. ACM Press, June 2016. [Non-patent document 2] Rishab Goyal, Sam Kim, Brent Waters, and David J. Wu, "Beyond software watermarking: Traitor-tracing for pseudorandom functions," In Mehdi Tibouchi and Huaxiong Wang, editors, Asiacrypt 2021 (to appear), Lecture Notes in Computer Science. Springer, 2021. [Non-patent document 3] Sam Kim and David J. Wu, "Watermarking cryptographic functionalities from standard lattice assumptions," In Jonathan Katz and Hovav Shacham, editors, CRYPTO 2017, Part I, volume 10401 of LNCS, pages 503-536. Springer, Heidelberg, August 2017. [Non-patent document 4] Sam Kim and David J. Wu, "Watermarking PRFs from lattices: Stronger security via extractable PRFs," In Alexandra Boldyreva and Daniele Micciancio, editors, CRYPTO2019, Part III, volume 11694 of LNCS, pages 335-366. Springer, Heidelberg, August 2019. [Non-patent document 5] Willy Quach, Daniel Wichs, and Giorgos Zirdelis, "Watermarking PRFs under standard assumptions: Public marking and security with extraction queries," In Amos Beimel and Stefan Dziembowski, editors, TCC 2018, Part II, volume 11240 of LNCS, pages 669-698. Springer, Heidelberg, November 2018. Summary of the Invention [Problem to be solved by the invention]

[0004] However, conventional pseudorandom number generating functions with embedded watermarks are not resistant to attacks such as providing a quantum computing device that mimics the behavior of the pseudorandom number generating function but removes the watermark.

[0005] The present invention has been made in consideration of these points, and aims to provide a technology that is resistant to attacks, such as providing a quantum computing device that mimics the operation of a pseudorandom number generation function with an embedded watermark, but in which the watermark has been removed. [Means for solving the problem]

[0006] The pseudorandom number function generator adds a watermark m∈{0,1} to a pseudorandom number generating function that outputs an output value y∈Ran for an input value x∈Dom. Lm A pseudorandom number generation function C~ with embedded is generated as follows: Here, Dom is the input space, Ran is the output space, Lm is a positive integer, and x1||x2 represents the concatenation of x1 and x2. (1) The setup unit outputs the public parameters pp and the watermark extraction key xk. (2) The key generation unit takes the public parameters pp as input and outputs the PRF key prfk and the public tag τ. (3) The watermark embedding unit takes the public parameters pp, the PRF key prfk, and the watermark m as input, and outputs a pseudorandom number generating function C~ in which a message m∥0, which is a bit concatenation of the watermark m and 0, is embedded.

[0007] The watermark extraction device detects quantum computing devices that mimic the behavior of such pseudorandom number generating function C~ but from which the watermark has been removed, as follows. Here, a classical input / output quantum device C = (q, U) that mimics the behavior of the pseudorandom number generation function C is a quantum computing device that includes a quantum bit string of quantum state q and a unitary device that performs a unitary transformation U on the quantum state q, and A ε,δ P,D (q) is an approximation projection device that takes a quantum state q as input and outputs a measurement value p of the quantum state q. Approximation projection device A ε,δ P,D(q) is determined by parameters ε, δ satisfying 0 ≦ ε, δ < 1, a set P = (P b,x,y , Q b,x,y ) b,x,y of binary projective measurement devices, and a probability distribution D of measurement values, where ε’ = ε / (Lm + 1), λ is a security parameter, δ’ = 2 -λ , P b,x,y = U x,y + |b><b|U x,y , Q b,x,y = I - P b,x,y , b is a variable vector representing the quantum state of the measurement target, |b> represents the ket vector of b, <b| represents the bra vector of b, |b><b| represents a projection operator, U x,y represents a unitary transformation U that mimics the operation of a pseudorandom number generation function C~ that outputs an output value y for an input of an input value x, U x,y + is U x,y 's Hermitian transpose matrix, I represents the identity matrix, [L] represents the set of integers 1,..., L, and for all i ∈ [Lm + 1], D τ,i represents the probability distribution defined by D τ,i : (γ, x, y) ← ELWMPRF.Sim(xk, τ, i), where ELWMPRF.Sim(xk, τ, i) is a simulation function that takes as input a watermark extraction key xk, a public tag τ, and i ∈ [Lm] and outputs (γ, x, y), and γ is a real number representing the probability that y is output for x. (1) The first measurement unit takes as input a watermark extraction key xk, a public tag τ, parameters ε, δ, and information representing the quantum state q of the qubits and the unitary transformation U of a classical input-output quantum device C = (q, U),

Number

[0008] This provides resistance to attacks such as providing a quantum computing device that mimics the behavior of a pseudorandom number generating function with an embedded watermark but from which the watermark has been removed. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a block diagram illustrating the configuration of a security system according to an embodiment. [Figure 2] FIG. 2 is a block diagram illustrating the configuration of a pseudorandom number function generating device according to an embodiment. [Figure 3] FIG. 3 is a block diagram illustrating the configuration of a watermark extraction device according to an embodiment. [Figure 4] FIG. 4 is a flow diagram illustrating the watermark extraction process of the embodiment. [Figure 5] FIG. 5 is a block diagram illustrating the hardware configuration of the pseudorandom number function generating device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. [Definition] First, the notation and terminology used in this specification are defined. <Notation> x1←X1: x1←X1 represents the uniform random selection of an element from a finite set X. y1←A(x1;r1):y1←A(x1;r1) indicates that device A outputs y1 for input x1 and random number r1. Input x1 and random number r1 are real numbers. However, when it is not necessary to explicitly state the random number used by A, y1←A(x1;r1) can be simply expressed as y1←A(x1). x1||x2:x1||x2 represents the concatenation of two bit strings x1 and x2. [L]:[L] denotes the set of integers 1,...,L, where L is a positive integer.

[0011] <function> A function is something that takes an element of a set or a set of elements of several sets as input, and outputs an element of a specific set (function value) corresponding to the input. A function can be rephrased as a mapping, and may be realized by an arithmetic expression, a set of arithmetic expressions, a program, classical operation, or quantum operation. Furthermore, taking α as input means taking some information that specifies α as input. Furthermore, outputting α means outputting some information that specifies α.

[0012] <Quantum calculation> Classical Input / Output Quantum Device C: A classical-input / output quantum device C=(q,U) is a device that includes a quantum bit string in quantum state q and a unitary device that performs a unitary transformation U on this quantum state q (see, for example, Reference 1). In what follows, we will assume a quantum computing device that mimics the behavior of a desired pseudorandom number generation function, and refer to this as a classical-input / output quantum device C. Reference 1: Scott Aaronson, Jiahui Liu, Qipeng Liu, Mark Zhandry, andRuizhe Zhang, "New approaches for quantum copy-protection," In Tal Malkin and Chris Peikert, editors, CRYPTO 2021, Part I, volume 12825 of LNCS, pages 526-555, Virtual Event, August 2021. Springer, Heidelberg.

[0013] Approximate projection device p←A ε,δ P,D (q): Approximate Projection Device A ε,δ P,D(q) is a device that takes a quantum state q as input and outputs a measurement value p of this quantum state q. Approximation Projection Device A ε,δ P,D is determined by real parameters ε and δ, which satisfy 0≦ε,δ<1, a projection measurement device P that performs projection measurement of the quantum state, and a probability distribution D (see, for example, Reference 2). Reference 2: Mark Zhandry, "Schrodinger's pirate: How to trace a quantum decoder," In Rafael Pass and Krzysztof Pietrzak, editors, TCC 2020, Part III, volume 12552 of LNCS, pages 61-91. Springer, Heidelberg, November 2020.

[0014] <Cryptographic calculation> Pseudorandom number generation function PRF: The pseudorandom number generating function PRF is x∈{0,1} λ Take as input, y∈{0,1} λ+L(λ) where λ is a security parameter that is a positive integer, and L(λ) is an integer that is a function value of λ. When L(λ) is positive, the output y is expanded by L(λ) bits compared to the input x, and when L(λ) is negative, the output y is compressed by L(λ) bits compared to the input x, and when L(λ) is 0, the length of the output y and the input x are the same.

[0015] Punctured pseudorandom number generating function PRF PPRF : Punctured pseudorandom number generating function PRF PPRF The following three functions PRF.Gen(1 λ ),PRF.Eval prfk (K,x),PRF.Eval prfk¬x⊆ (S). The input space to which x belongs is {0,1} L1 and the output space to which y belongs is {0,1} L2 where L1 and L2 are positive integers. K←PRF.Gen(1 λ):PRF.Gen(1 λ ) is a key generation function that takes a security parameter λ, which is a positive integer, as input and outputs a real operational key K. y ← PRF.Eval prfk (K,x):PRF.Eval prfk (K, x) is the computation key (or the puncturing key K ¬S⊆ )K and x∈{0,1} L1 takes input, and y∈{0,1} L2 is an arithmetic function that outputs K ¬S⊆ ←PRF.Eval prfk¬x⊆ (S):PRF.Eval prfk¬x⊆ (S) is a set S⊆{0,1} of operation key K and input x. L1 input, and a puncturing key K that can be used only for inputs that do not belong to set S. ¬S⊆ is a puncturing key generation function that outputs

[0016] Secret key cryptography SKE: The secret key cryptosystem SKE consists of the following three functions: SKE.Gen(1 λ ), SKE.Enc(k,m), SKE.Dec(k,ct). The plaintext space to which the plaintext belongs is {P λ} λ∈N where N represents the set of all positive integers (natural numbers). k←SKE.Gen(1 λ ):SKE.Gen(1 λ ) is a private key generation function that takes a security parameter λ as input and outputs a private key k, where k is a real number. ct←SKE.Enc(k,m): SKE.Enc(k,m) is the secret key k and plaintext m∈{P λ} λ∈N is an encryption function that takes input and outputs ciphertext ct. m' or ⊥←SKE.Dec(k,ct): SKE.Dec(k,ct) is a decryption function that takes a private key k and ciphertext ct as input and outputs plaintext m' or error message ⊥ indicating that decryption is not possible. If the private key k and ciphertext ct are correct, then m' = m.

[0017] Constrainable pseudorandom number generating function PRF CPRF : Constrainable pseudorandom number generating function PRF CPRF The following four functions are called: CPRF.Setup(1 λ ),CPRF.Constrain(m sk ,f),CPRF.Eval(msk,x),CPRF.CEval(sk f , x), where x belongs to the input space Dom and y belongs to the output space Ran. msk←CPRF.Setup(1 λ ):CPRF.Setup(1 λ ) is a setup function that takes a security parameter λ as input and outputs a master key msk. sk f ←CPRF.Constrain(msk,f): CPRF.Constrain(msk,f) takes as input a master key msk and an arbitrary function f, and computes a constrained key sk f is a restricted key generation function that outputs y←CPRF.Eval(msk,x): CPRF.Eval(msk,x) is an arithmetic function that takes the master key msk and x∈Dom as input and outputs y∈Ran. y←CPRF.CEval(sk f ,x):CPRF.CEval(sk f ,x) is the restricted key sk f and a restricted operation function that takes x∈Dom as input and outputs y∈Ran.

[0018] Public Key Encryption (PKE): The public key encryption system PKE consists of the following three functions PKE.Gen(1 λ ), PKE.Enc(pk,m), and PKE.Dec(sk,ct). The plaintext space to which the plaintext belongs is {P λ} λ∈N is. (pk,sk)←PKE.Gen(1 λ ):PKE.Gen(1 λ) is a key generation function that takes a security parameter λ as input and outputs a public key pk and a private key sk. ct←PKE.Enc(pk,m): PKE.Enc(pk,m) is the public key pk and plaintext m∈{P λ} λ∈N is an encryption function that takes input and outputs ciphertext ct. m' or ⊥←PKE.Dec(sk,ct): PKE.Dec(sk,ct) is a decryption function that takes the private key sk and the ciphertext ct as input and outputs the plaintext m' or an error message ⊥ indicating that decryption is not possible. If the private key sk and the ciphertext ct are correct, then m' = m.

[0019] Indistinguishability obfuscation function iO: The indistinguishability obfuscation function iO is a circuit (function) {C λ} λ∈N It is a function that takes as input and outputs an obfuscated circuit (see, for example, Reference 3). Reference 3: Boaz Barak, Oded Goldreich, Russell Impagliazzo, Steven Rudich, Amit Sahai, Salil P. Vadhan, and Ke Yang, "On the (im)possibility of obfuscating programs," Journal of the ACM, 59(2):6:1-6:48, 2012.

[0020] Puncturing encryption PE: The puncturable encryption scheme PE consists of the following four functions PE.Gen(1 λ ), PE.Puncture(dk,{c*}), PE.Enc(ek,m), PE.Dec(dk',c'). The plaintext space to which the plaintext belongs is {0,1} Lp and Lp is a positive integer. (ek,dk)←PE.Gen(1 λ ):PE.Gen(1 λ) is a key generation function that takes a security parameter λ as input and outputs an encryption key ek and a decryption key dk. dk ≠c* ←PE.Puncture(dk,{c*}): PE.Puncture(dk,{c*}) takes the decryption key dk and the ciphertext c* as input, and punctures the decryption key dk that can only be used for ciphertext other than c*. ≠c* is a puncturing decryption key generation function that outputs c←PE.Enc(ek,m): PE.Enc(ek,m) is the encryption key ek and the plaintext m∈{0,1} Lp is an encryption function that takes as input and outputs ciphertext c. m' or ⊥←PE.Dec(dk',c'): PE.Dec(dk',c') is a decryption function that takes the decryption key (or punctured decryption key) dk' and the ciphertext c' as input, and outputs the plaintext m' or an error message ⊥ indicating that decryption is not possible. If dk'=dk and c'=c, then m'=m (see, for example, Reference 4). Reference 4: Aloni Cohen, Justin Holmgren, Ryo Nishimaki, Vinod Vaikuntanathan, and Daniel Wichs, "Watermarking cryptographic capabilities," SIAM Journal on Computing, 47(6): 2157-2202, 2018.

[0021] [principle] Next, the principle of this embodiment will be described. Assume that an attacker uses a quantum computing device to launch an attack on a pseudorandom number generation function capable of embedding a watermark. In this attack, the attacker attempts to forge a quantum computing device that mimics the behavior of the pseudorandom number generation function being attacked. The classical values ​​of the input and output of the forged quantum computing device are the same as or indistinguishable from the input and output of the pseudorandom number generation function being attacked, but the forged quantum computing device does not have a watermark embedded. In other words, the attacker attempts an attack by providing a quantum computing device that performs the same or indistinguishable behavior (behavior that mimics the pseudorandom number generation function) as the target pseudorandom number generation function, but from which the watermark has been removed. In this embodiment, a pseudorandom number generation function that is resistant to attacks that attempt to remove the watermark is provided. A pseudorandom number generation function capable of embedding a digital watermark and that is resistant to such attacks can be defined as follows.

[0022] <WMPRF: A pseudorandom number generation function that can embed digital watermarks> The pseudorandom number generation function WMPRF that can embed digital watermarks consists of the following five functions: WMPRF.Setup(1 λ ), WMPRF.Gen(pp), WMPRF.Eval(prfk,x), WMPRF.Mark(pp,prfk,m), WMPRF.Extract(xk,τ,C',ε). The watermark space to which the digital watermark belongs is {0,1} Lm where Lm is a positive integer, the input space to which x belongs is Dom, and the output space to which y belongs is Ran. (pp,xk)←WMPRF.Setup(1 λ ):WMPRF.Setup(1 λ ) is a setup function that takes a security parameter λ as input and outputs a public parameter pp and a watermark extraction key xk. (prfk, τ)←WMPRF.Gen(pp): WMPRF.Gen(pp) is a key generation function that takes public parameters pp as input and outputs a PRF key prfk and a public tag τ. y←WMPRF.Eval(prfk,x): WMPRF.Eval(prfk,x) is an arithmetic function that takes a PRF key prfk and x∈Dom as input and outputs y∈Ran. C~←WMPRF.Mark(pp,prfk,m): WMPRF.Mark(pp,prfk,m) is the public parameter pp, PRF key prfk, and watermark m∈{0,1} Lm is a watermark embedding function that takes as input a pseudorandom number generation function C~ in which a watermark m is embedded. The pseudorandom number generation function C~ is a function that outputs an output value y∈Ran for an input value x∈Dom, and the watermark m is embedded. Note that the upper right subscript "~" of "C~" should be written directly above the "C", but due to restrictions on writing notation, "~" may be written to the upper right of "C". m'←WMPRF.Extract(xk,τ,C,ε): WMPRF.Extract(xk,τ,C,ε) takes as input the watermark extraction key xk, the public tag τ, the extraction parameter ε, and information identifying the classical-input / quantum device C = (q,U), and extracts the watermark m'∈{0,1} Lm is a watermark extraction function that outputs ∪{unmarked}. Note that a classical-input / output quantum device C = (q,U) is a quantum computing device that mimics the behavior of a pseudorandom number generation function C~ with a watermark m embedded in it. That is, the classical values ​​of the input and output of the pseudorandom number generation function C~ and the classical-input / output quantum device C are either identical or indistinguishable. In other words, the behavior of the classical-input / output quantum device C is indistinguishable from the behavior of the pseudorandom number generation function C~. However, there are cases where the watermark m is correctly embedded in the classical-input / output quantum device C, and cases where the watermark m is not embedded in the classical-input / output quantum device C. If the watermark m is correctly embedded in the classical-input / output quantum device C, then m' = m. Also, unmarked is information indicating that a watermark is not embedded in the classical-input / output quantum device C. The information that identifies a classical-input / output quantum device C = (q,U) is information representing the quantum state q of the qubit and the unitary transformation U. The information representing the quantum state q of the quantum bit may be, for example, the quantum bit itself, or some state in which the quantum state q appears. The information representing the unitary transformation U may be, for example, information such as a matrix representing the unitary transformation U itself, or information that controls the operation represented by the unitary transformation U.

[0023] <Pseudo-random number generation function ELWMPRF capable of embedding an Extraction-Less watermark> To define the above-described watermark-embeddable pseudo-random number generation function WMPRF, a pseudo-random number generation function ELWMPRF capable of embedding an Extraction-Less watermark is used. The pseudo-random number generation function ELWMPRF capable of embedding an Extraction-Less watermark consists of five functions ELWMPRF.Setup(1 λ ), ELWMPRF.Gen(pp), ELWMPRF.Eval(prfk, x), ELWMPRF.Mark(pp, prfk, m), ELWMPRF.Sim(xk, τ, i). Note that the watermark space to which the watermark belongs is {0, 1} Lm , the input space to which x belongs is Dom, and the output space to which y belongs is Ran. Also, ELWMPRF.Setup(1 λ ), ELWMPRF.Gen(pp), ELWMPRF.Eval(prfk, x), ELWMPRF.Mark(pp, prfk, m) are the same as WMPRF.Setup(1 λ ), WMPRF.Gen(pp), WMPRF.Eval(prfk, x), WMPRF.Mark(pp, prfk, m) of the watermark-embeddable pseudo-random number generation function WMPRF respectively. That is, ELWMPRF.Setup(1 λ ) = WMPRF.Setup(1 λ ), ELWMPRF.Gen(pp) = WMPRF.Gen(pp), ELWMPRF.Eval(prfk, x) = WMPRF.Eval(prfk, x), ELWMPRF.Mark(pp, prfk, m) = WMPRF.Mark(pp, prfk, m). ELWMPRF.Sim(xk, τ, i) is as follows. (γ, x, y) ← ELWMPRF.Sim(xk, τ, i): ELWMPRF.Sim(xk, τ, i) is a simulation function that takes as input a watermark extraction key xk, a public tag τ, and i ∈ [Lm], and outputs (γ, x, y). γ is 1-bit information of 0 or 1.

[0024] <Pseudo-random number generation function WMPRF capable of embedding an Extraction-Less watermark, based on the pseudo-random number generation function ELWMPRF> Based on the pseudo-random number generation function ELWMPRF capable of embedding an Extraction-Less watermark, the pseudo-random number generation function WMPRF capable of embedding the watermark of this embodiment is defined. The pseudo-random number generation function WMPRF capable of embedding the watermark of this embodiment consists of five functions WM.Setup(1 λ ), WM.Gen(pp), WM.Eval(prfk, x), WM.Mark(pp, prfk, m), WM.Extract(xk, τ, C, ε). Note that the watermark space of the pseudo-random number generation function WMPRF capable of embedding a watermark is {0, 1} Lm and the message space including the watermark space is {0, 1} Lm+1 . The input space to which x belongs is Dom, and the output space to which y belongs is Ran.

[0025] WM.Setup(1 λ ), WM.Gen(pp), WM.Eval(prfk, x) are the same as ELWMPRF.Setup(1 λ ), ELWMPRF.Gen(pp), ELWMPRF.Eval(prfk, x) of the pseudo-random number generation function ELWMPRF capable of embedding an Extraction-Less watermark, respectively. That is, WM.Setup(1 λ ) = ELWMPRF.Setup(1 λ ), WM.Gen(pp) = ELWMPRF.Gen(pp), WM.Eval(prfk, x) = ELWMPRF.Eval(prfk, x).

[0026] WM.Mark(pp, prfk, m) and WM.Extract(xk, τ, C, ε) are as follows. In WM.Extract(xk, τ, C, ε), ELWMPRF.Sim(xk, τ, i) of the pseudo-random number generation function ELWMPRF capable of embedding an Extraction-Less watermark is used.

[0027] <C~←WM.Mark(pp,prfk,m||0)> WM.Mark(pp, prfk, m) takes as input the public parameter pp, the PRF key prfk, and the watermark m ∈ {0, 1} Lm and outputs a message embedding function that takes as input and outputs a pseudorandom number generation function C~ in which the message m||0, which is the bit concatenation of the watermark m and 0, is embedded.

[0028] <WM.Extract(xk,τ,C,ε)> Step WM.Extract-1: First, WM.Extract(xk, τ, C, ε) takes as input the watermark extraction key xk, the public tag τ, the parameter ε, and information representing the quantum state q of the qubits and the unitary transformation U of the classical input-output quantum device C = (q, U), and obtains and outputs the following measurement value p~ by the measurement of the following equation (1). Lm+1 and outputs it.

Equation

[0029] Step WM.Extract-2: Next, WM.Extract(xk,τ,C,ε) calculates the measured value p~ Lm+1 ga p~ Lm+1 Determine whether p~ is satisfied. Lm+1 If it is determined that <(1 / 2)+ε-4ε' is satisfied, WM.Extract(xk,τ,C,ε) outputs information "unmarked" indicating that a watermark is not embedded. Otherwise, the quantum state of the quantum bit after measurement of classical-input / output quantum device C is set to q0, and the process proceeds to the next step, WM.Extract-3.

[0030] Step WM.Extract-3: WM.Extract(xk,τ,C,ε) executes the following steps WM.Extract-31 and WM.Extract-32 in order from i=1 to Lm. Step WM.Extract-31: WM.Extract(xk,τ,C,ε) extracts the watermark extraction key xk, the public tag τ, the parameters ε, and the quantum state q of the qubit. i-1 and information representing the unitary transformation U as input, and the measurement value p~ is obtained by measuring the following equation (2). i and output it.

number

[0031] Step WM.Extract-4: If for all i ∈ [Lm], p~ i ≠(1 / 2)+ε - 4ε’ in step WM.Extract-3, WM.Extract(xk, τ, C, ε) outputs m’ = m1’||…||m Lm ’. If for any i, p~ i =(1 / 2)+ε - 4ε’, WM.Extract(xk, τ, C, ε) outputs m’ = 0 Lm .

[0032] <Pseudo-random number generation function ELWMPRF capable of embedding Extraction-Less watermark based on the LWE (Learning with errors) problem> Next, we present an example of a pseudorandom number generation function ELWMPRF that can embed extraction-less digital watermarks based on the LWE problem. The watermark space of this pseudorandom number generation function ELWMPRF is {0,1} Lm and the input space Dom is {0,1} n1 and the output space Ran is {0,1} m1 where n1 and m1 are positive integers. In this example, we use a constrained pseudorandom number generating function (PRF) based on the difficulty of the LWE problem defined on a mathematical structure called a lattice. CPRF , a secret key cryptosystem SKE, and a public key cryptosystem PKE are used. That is, a constrained pseudorandom number generation function PRF CPRF , the secret key cryptosystem SKE, and the public key cryptosystem PKE are based on, for example, lattice cryptography. As mentioned above, the PRF can be constrained CPRF The four functions CPRF.Setup(1 λ ),CPRF.Constrain(m sk ,f),CPRF.Eval(msk,x),CPRF.CEval(sk f ,x). The master key msk is hardwired, and the CPRF.Eval(msk,x) is used to construct G(x):{0,1} n1 →{0,1} m1 and the restricted key sk f is fixed CPRF.CEval(sk f ,x) to G ¬∈ν (x):{0,1} n1 →{0,1} m2 Also, G ¬∈ν (x) can only be used for inputs x that do not belong to the set ν, where ν represents the set of x for which f(x) = 1 for a function f(·).

[0033] As mentioned above, the secret key cryptosystem SKE consists of three functions SKE.Gen(1 λ ), SKE.Enc(k,m), and SKE.Dec(k,ct). The secret key cryptosystem SKE is, for example, a lattice cryptosystem. However, the plaintext space to which the plaintext belongs is defined as {0,1} Lske Let the ciphertext space to which the ciphertext belongs be {0,1}n1 Here, Lske=ceil(Log2Lm)+1, where ceil represents the ceiling function, ceil(α) means the smallest natural number equal to or greater than α, and Lm and n1 are the positive integers mentioned above.

[0034] As mentioned above, the public key encryption method PKE consists of three functions PKE.Gen(1 λ ), PKE.Enc(pk,m), and PKE.Dec(sk,ct). The public key cryptosystem PKE is, for example, a lattice cryptosystem. However, the plaintext space to which the plaintext belongs is defined as {0,1} 2λ Let's say.

[0035] Under the above assumptions, the pseudorandom number generation function ELWMPRF that can embed extraction-less digital watermarks based on the LWE problem is composed of the following five functions: ELWMPRF.Setup(1 λ ), ELWMPRF.Gen(pp), ELWMPRF.Eval(prfk,x), ELWMPRF.Mark(pp,prfk,m), ELWMPRF.Sim(xk,τ,i).

[0036] <(pp,xk)←ELWMPRF.Setup(1 λ )> ELWMPRF.Setup(1 λ ) takes a security parameter λ as input and (pk,sk)←PKE.Gen(1 λ ) and output (pk,sk) as (pp,xk) ((pp,xk):=(pk,sk)).

[0037] <(prfk,τ)←ELWMPRF.Gen(pp)> Step ELWMPRF.Gen(pp) LWE -1:ELWMPRF.Gen(pp) takes pp:=pk as input. Step ELWMPRF.Gen(pp) LWE -2: ELWMPRF.Gen(pp) takes the security parameter λ and the parameter κ as input, and λ ,1κ ) is obtained. Here, κ represents the size of the circuit (function) D[k,m,x], which will be described later. The size of D[k,m,x] represents the number of gates that make up the logic circuit required to calculate D[k,m,x]. ELWMPRF.Gen(pp) obtains and outputs G(x) by hardwiring the obtained msk to y←CPRF.Eval(msk,x) (G(x)←CPRF.Setup(1 λ ,1 κ )). Step ELWMPRF.Gen(pp) LWE -3: ELWMPRF.Gen(pp) uses the security parameter λ and k←SKE.Gen(1 λ ) Step ELWMPRF.Gen(pp) LWE -4:ELWMPRF.Gen(pp) is the circuit (function) D described later with this k fixed. auth Set [k,x]. Step ELWMPRF.Gen(pp) LWE -5:ELWMPRF.Gen(pp) is a function of G(x) and D auth Using [k,x], the restricted key sk f ←CPRF.Constrain(G(x),D auth [k,x]). Then, ELWMPRF.Gen(pp) generates this restricted key sk f is fixed CPRF.CEval(sk f , x) in G ¬∈νauth (x), where ν auth ⊂{0,1} n1 is D auth It is the set of x that satisfies [k,x]=1. ¬∈νauth The subscript "νauth" of "ν auth ", but due to limitations on notation, it is written as "νauth". Step ELWMPRF.Gen(pp) LWE -6:ELWMPRF.Gen(pp) is prfk = (G(x),k) and τ ← PKE.Enc(pp,(G ¬∈νauth (x), k)) is obtained and output. ¬∈νauth(x), k) is G ¬∈νauth (x) and k, e.g., (G ¬∈νauth (x),k)=G ¬∈νauth (x)||k.

[0038] <y←ELWMPRF.Eval(prfk,x)> ELWMPRF.Eval(prfk,x) takes prfk=(G(x),k) and x as input and outputs y←ELWMPRF.Eval(prfk,x) (=WMPRF.Eval(prfk,x)).

[0039] <C~←ELWMPRF.Mark(pp,prfk,m)> Step ELWMPRF.Mark(pp,prfk,m) LWE -1:ELWMPRF.Mark(pp,prfk,m) sets a circuit (function) D[k,m,x] (described later) with pp=pk and prfk=(G(x),k) and k and m fixed. Step ELWMPRF.Mark(pp,prfk,m) LWE -2: ELWMPRF.Mark(pp,prfk,m) uses G(x) and D[k,m,x] and the restricted key sk f ← Generate CPRF.Constrain(G(x),D[k,m,x]). Next, ELWMPRF.Mark(pp,prfk,m) generates this constraint key sk f is fixed CPRF.CEval(sk f , x) in G ¬∈ν (x), where ν ⊂ {0,1} n is the set of x such that D[k,m,x]=1. ELWMPRF.Mark(pp,prfk,m) is the set of x such that D[k,m,x]=1. ¬∈ν Output (x) as C~.

[0040] <(γ,x,y)←ELWMPRF.Sim(xk,τ,i)> Step ELWMPRF.Sim(xk,τ,i) LWE -1:ELWMPRF.Sim(xk,τ,i) sets sk to xk (sk:=xk). Step ELWMPRF.Sim(xk,τ,i) LWE -2:ELWMPRF.Sim(xk,τ,i) is (G ¬∈νauth (x), k)←PKE.Dec(sk,τ) is obtained (calculated). Step ELWMPRF.Sim(xk,τ,i) LWE -3: ELWMPRF.Sim(xk,τ,i) generates γ←{0,1}. For example, ELWMPRF.Sim(xk,τ,i) randomly generates γ←{0,1}. Step ELWMPRF.Sim(xk,τ,i) LWE -4:ELWMPRF.Sim(xk,τ,i) is the function x←SKE.Enc(k,i||γ) and y←G ¬∈νauth Obtain (calculate) (x). Step ELWMPRF.Sim(xk,τ,i) LWE -5:ELWMPRF.Sim(xk,τ,i) outputs (γ,x,y).

[0041] Circuit D auth Details of D[k,x] and D[k,m,x] are shown. <D auth [k,x]> D auth [k,x] is a circuit where k is fixed and performs the following processing. Input: x∈{0,1} n1 Step D auth [k,x]-1:D auth [k,x] computes d←SKE.Dec(k,x). Step D auth [k,x]-2:D auth [k,x] outputs 0 if d≠⊥, and 1 otherwise.

[0042] <D[k,m,x]> D[k,m,x] is a circuit that performs the following processing with k and m fixed. Input: x∈{0,1} n1 Step D[k,m,x]-1: D[k,m,x] calculates d←SKE.Dec(k,x). Step D[k,m,x]-2: If d≠⊥, then D[k,m,x] performs the following (a) and (b). (a) d=i||η∈{0,1} Lske where i∈[Lm] and η∈{0,1}. That is, we interpret d as the bitwise concatenation of i∈[Lm] and one bit η∈{0,1}. (b) where η=m i If m=m1||...||m, then D[k,m,x] outputs 1, otherwise D[k,m,x] outputs 0. Lm ∈{0,1} Lm is. Step D[k,m,x]-3: If d=⊥, then D[k,m,x] outputs 0.

[0043] <ELWMPRF: A Pseudo-Random Number Generator for Extraction-Less Watermarking Based on Indistinguishability Obfuscation> We present an example of a pseudorandom number generation function ELWMPRF that can embed extraction-less digital watermarks based on indistinguishability obfuscation. The watermark space of this pseudorandom number generation function ELWMPRF is {0,1} Lm and the input space Dom is {0,1} Lin and the output space Ran is {0,1} Lout where Lin and Lout are positive integers. In this example, we consider a puncturing pseudorandom number generating function (PRF) that can be realized using indistinguishability obfuscation and one-way functions. PPRF , using a puncturable encryption scheme PE, an indistinguishability obfuscation function iO, and a pseudorandom number generation function PRF.

[0044] As mentioned above, the puncturing pseudorandom number generating function PRF PPRF The three functions PRF.Gen(1 λ ),PRF.Eval prfk (K,x),PRF.Eval prfk¬x⊆ (S). Here, the calculation function PRF.Eval prfk (K,x) to F(x):{0,1} Lin →{0,1} LoutAlso, the puncturing key generation function PRF.Eval prfk¬x⊆ (S) to F ¬x⊆ It is represented as (S).

[0045] As mentioned above, the puncturable encryption scheme PE consists of four functions PE.Gen(1 λ ), PE.Puncture(dk,{c*}), PE.Enc(ek,m), PE.Dec(dk',c'). Here, the plaintext space and ciphertext space of the puncturable encryption scheme PE are defined as {0,1} Lpt and {0,1} Lct where Lpt and Lct are positive integers, satisfying Lpt = λ + ceil(log2Lm) + 1, Lin = Lct, and Lct = poly(λ, log2Lm), where poly(λ, log2Lm) represents the coefficients of the polynomial whose roots are elements of (λ, log2Lm).

[0046] As mentioned before, the indistinguishability obfuscation function iO is λ} λ∈N is a function that takes as input and outputs an obfuscated circuit.

[0047] As mentioned above, the pseudorandom number generating function PRF is a function x∈{0,1} λ Take as input, y∈{0,1} λ+L(λ) Here, Lout = λ + L(λ) and PRF: {0, 1} λ →{0,1} Lout Let's say.

[0048] Under the above assumptions, the pseudorandom number generation function ELWMPRF that can embed extraction-less digital watermarks based on indistinguishability obfuscation is composed of the following five functions: ELWMPRF.Setup(1 λ ), ELWMPRF.Gen(pp), ELWMPRF.Eval(prfk,x), ELWMPRF.Mark(pp,prfk,m), ELWMPRF.Sim(xk,τ,i).

[0049] <(pp,xk)←ELWMPRF.Setup(1 λ )> ELWMPRF.Setup(1 λ ) is set to (pp,xk):=(⊥,⊥).

[0050] <(prfk,τ)←ELWMPRF.Gen(pp)> Step ELWMPRF.Gen(pp) iO -1:ELWMPRF.Gen(pp) takes pp:=⊥ as input. Step ELWMPRF.Gen(pp) iO -2:ELWMPRF.Gen(pp) is the operation key K←PRF.Gen(1 λ ) and PRF.Eval with this calculation key K fixed prfk Calculate F(x) for (K,x). Step ELWMPRF.Gen(pp) iO -3:ELWMPRF.Gen(pp) is (pe.ek, pe.dk)←PE.Gen(1 λ ) Step ELWMPRF.Gen(pp) iO -4:ELWMPRF.Gen(pp) outputs prfk :=(F(x), pe.dk) and τ := pe.ek.

[0051] <ELWMPRF.Eval(prfk,x)> ELWMPRF.Eval(prfk,x) takes prfk:=(F(x), pe.dk) and x as inputs and outputs y←F(x).

[0052] <ELWMPRF.Mark(pp,prfk,m)> ELWMPRF.Mark(pp,prfk,m) iO -1:ELWMPRF.Mark(pp,prfk,m) takes as input pp:=⊥ and prfk:=(F(x), pe.dk). ELWMPRF.Mark(pp,prfk,m) iO-2:ELWMPRF.Mark(pp,prfk,m) sets the circuit D[F(x),pe.dk,m] to be described later with prfk, pe.dk and m fixed. ELWMPRF.Mark(pp,prfk,m) iO -3:ELWMPRF.Mark(pp,prfk,m) obfuscates D[F(x),pe.dk,m] to obtain iO(D[F(x),pe.dk,m]), which is output as C~.

[0053] <ELWMPRF.Sim(xk,τ,i)> ELWMPRF.Sim(xk,τ,i) iO -1:ELWMPRF.Sim(xk,τ,i) sets xk :=⊥ and τ :=pe.ek. ELWMPRF.Sim(xk,τ,i) iO -2:ELWMPRF.Sim(xk,τ,i) is γ←{0,1} and s←{0,1} λ Generate. ELWMPRF.Sim(xk,τ,i) iO -3:ELWMPRF.Sim(xk,τ,i) computes y ← PRF(s). ELWMPRF.Sim(xk,τ,i) iO -4:ELWMPRF.Sim(xk,τ,i) computes x←PE.Enc(pe.ek, s||i||γ). ELWMPRF.Sim(xk,τ,i) iO -5:ELWMPRF.Sim(xk,τ,i) outputs (γ,x,y).

[0054] <D[F(x), pe.dk, m]> Details of D[F(x), pe.dk, m] are shown below. D[F(x), pe.dk, m] is a circuit that performs the following processing with prfk, pe.dk, and m fixed. Input: x∈{0,1} Lm Step D[F(x), pe.dk, m]-1: D[F(x), pe.dk, m] computes d←PE.Dec(pe.dk, x). Step D[F(x), pe.dk, m]-2: If d≠⊥, then D[F(x), pe.dk, m] performs the following steps (c) and (d). (c) Let d = s||i||η, where s∈{0,1} λ , i∈[Lm], and η∈{0,1}. (d) where η=m i If so, then D[F(x), pe.dk, m] outputs PRF(s), else it outputs F(x). Step D[F(x), pe.dk, m]-3: If d=⊥, then D[F(x), pe.dk, m] outputs F(x).

[0055] [First embodiment] <Configuration> As shown in FIG. 1, the security system 1 of this embodiment includes a pseudorandom function generating device 110, a watermark extracting device 120, and a pseudorandom function utilizing device 130, which are configured to be able to communicate with each other via a network.

[0056] <Pseudorandom number function generator 110> 2, the pseudo-random function generating device 110 has a setup unit 111, a key generating unit 112, a watermark embedding unit 113, an output unit 114, a memory 115, and a control unit 116, and executes each process based on the control unit 116. Information input to the pseudo-random function generating device 110 and information obtained by each unit are stored in the memory 115 one by one, and are read and used as needed.

[0057] <Watermark Extraction Device 120> As illustrated in FIG. 3, the watermark extraction device 120 has measurement units 121 and 123 (first measurement unit, second measurement unit), extraction units 122 and 124 (first measurement unit, second measurement unit), memory 125, and control unit 126, and performs each process based on the control unit 126.

[0058] <Pseudo-random number function generation process> Next, a description will be given of a pseudorandom number generation process performed by the pseudorandom number function generation device 110. The pseudorandom number function generation device 110 adds a watermark m∈{0,1} to a pseudorandom number generation function that outputs an output value y∈Ran in response to an input value x∈Dom. Lm Generate a pseudorandom number generating function C~ with embedded Dom, Ran, and Lm as positive integers. As shown in FIG. 2, the setup unit 111 of the pseudorandom function generation device 110 includes a 1 representing a security parameter λ. λ The setup unit 111 receives the security parameter λ as an input and sets (pp, xk)←WM.Setup(1 λ ) to obtain and output the public parameters pp and the watermark extraction key xk. Note that (pp, xk)←WM.Setup(1 λ The details of this step are disclosed in, for example, Non-Patent Documents 1 to 5 (step S111).

[0059] The key generation unit 112 receives the public parameters pp as input, and obtains and outputs the PRF key prfk and the public tag τ by (prfk, τ)←WM.Gen(pp). Details of (prfk, τ)←WM.Gen(pp) are disclosed in, for example, Non-Patent Documents 1 to 5 (step S112).

[0060] The watermark embedding unit 113 embeds the public parameters pp, the PRF key prfk, and the watermark m∈{0, 1} Lm is taken as input, and a pseudo-random number generating function C~ is obtained by C~←WM.Mark(pp,prfk,m∥0) to embed a message m∥0, which is a bit concatenation of watermark m and 0, and output. Note that WM.Mark(pp,prfk,m∥0) is not disclosed, but details of WM.Mark(pp,prfk,m) are disclosed in, for example, Non-Patent Documents 1 to 5 (step S113).

[0061] The pseudorandom number generation function C~, the watermark extraction key xk, and the public tag τ are sent to the output unit 114 and output from there. The pseudorandom number generation function C~ is sent to the pseudorandom number function utilization device 130 via the network and used for processing in the pseudorandom number function utilization device 130. The watermark extraction key xk and the public tag τ are sent to the watermark extraction device 120 via the network. Other public parameters such as the security parameter λ are made public via the network (step S114).

[0062] <Watermark extraction process> Next, the watermark extraction process performed by the watermark extraction device 120 will be described with reference to FIGS. The measurement unit 121 of the watermark extraction device 120 receives as input the watermark extraction key xk, the public tag τ, real number parameters ε, δ (0≦ε, δ<1), the security parameter λ, and information representing the quantum state q and unitary transformation U of the quantum bit of the classical input / output quantum device C=(q,U) that mimics the operation of the pseudorandom number generation function C~, and obtains the measurement value p~ by measuring equation (1). Lm+1 As mentioned above, D in Eq. (1) is obtained and output. τ,Lm+1 is D τ,Lm+1 :(γ, x, y)←ELWMPRF.Sim(xk, τ, Lm+1) represents the probability distribution defined by (step S121).

[0063] The extraction unit 122 extracts the measured value p~ Lm+1 and the quantum state q of the quantum bit after measurement of the classical input / output quantum device C is taken as input, and the measured value p~ Lm+1 ga p~ Lm+1 <(1 / 2)+ε-4ε′ is satisfied (step S122a). Lm+1 If it is determined that p~<(1 / 2)+ε-4ε' is satisfied, the extraction unit 122 outputs information "unmarked" indicating that a watermark is not embedded in the classical input / output quantum device C (step S122b), and ends the process. Lm+1 <(1 / 2)+ε-4ε', it is mathematically provable that no watermark is embedded in the classical-input / output quantum device C.

[0064] On the other hand, the measured value p~ Lm+1 ga p~ Lm+1 If it is determined that <(1 / 2)+ε-4ε' is not satisfied, the measurement value p~ Lm+1 outputs the quantum state q of the quantum bit after measurement of the classical input / output quantum device C as q0 (step S122c).

[0065] The measurement unit 123 sets i=1 (step S123a).

[0066] The measurement unit 123 measures the watermark extraction key xk, the public tag τ, the parameters ε and δ, the security parameter λ, and the quantum state q of the quantum bit. i-1 and information representing the unitary transformation U as input, and the measurement p~ is obtained by measuring equation (2). i As mentioned above, D in Eq. (2) τ,i is D τ,i :(γ,x,y)←ELWMPRF.Sim(xk,τ,i) represents the probability distribution defined by (step S123b).

[0067] The measurement unit 123 measures the quantum state of the quantum bit of the classical input / output quantum device C after measurement as q i Let p~ i >(1 / 2)+ε-4ε' (step S123c). i >(1 / 2)+ε-4ε', the measurement unit 123 i '=0 (step S123e), and the process proceeds to step S123g. i If it is determined that p is not >(1 / 2)+ε-4ε', the measurement unit 123 i <(1 / 2)+ε-4ε' (step S123d). i <(1 / 2)+ε-4ε', the measurement unit 123 i '=1 (step S123f), and the process proceeds to step S123g. iIf it is determined that it is not <(1 / 2)+ε-4ε' (i.e., if p~ i =(1 / 2)+ε-4ε'), the measurement unit 123 Lm and sends it to the extraction unit 124. In this case, the extraction unit 124 extracts the watermark m′=0 Lm (Step S124a), and the process ends. i =(1 / 2)+ε-4ε', watermark m'=0 is added to the classical input / output quantum device C. Lm It is mathematically provable that was embedded.

[0068] In step S123g, the measurement unit 123 determines whether i=Lm (step S123g). If i=Lm is not true, the measurement unit 123 sets i+1 as a new i (i←i+1) (step S123h), and the process returns to step S123b. On the other hand, if i=Lm (p~ for all i∈[Lm]), i =(1 / 2)+ε-4ε'), the measurement unit 123 calculates m for all i∈[Lm]. i ' to the extraction unit 124. The extraction unit 124 extracts the watermark m'=m1'||...||m Lm ' is output (step S124b), and the process ends. Although details are omitted, for all i∈[Lm], p i =(1 / 2)+ε-4ε', the watermark m'=m1'||...||m Lm It is mathematically provable that ' was embedded.

[0069] <Features of this embodiment> As described above, in this embodiment, if watermark m has been removed from a classical-input / output quantum device C that mimics the behavior of a pseudo-random number generation function C~ in which watermark m has been embedded, information "unmarked" indicating that no watermark has been embedded in the classical-input / output quantum device C is output in step S122b. This makes it possible to detect a quantum computing device C that mimics the behavior of a pseudo-random number generation function C~ in which watermark m has been embedded but from which watermark m has been removed. Furthermore, if watermark m has also been embedded in a classical-input / output quantum device C, the correct watermark m' can be obtained in step S124a or S124b. In other words, this embodiment is the first pseudo-random number function method capable of embedding digital watermarks that is resistant to attackers using quantum computing devices. Even if an attacker attempting to remove a digital watermark embedded in a pseudo-random number generation function turns that pseudo-random number generation function into a quantum device, the digital watermark can still be correctly extracted from the quantum device.

[0070] [Second embodiment] The second embodiment is a specific example of the first embodiment, and is an example using a pseudorandom number generation function ELWMPRF that can embed an extraction-less digital watermark based on the LWE problem described above. Hereinafter, the explanation of the matters that have already been explained will be simplified. In the second embodiment, the input space Dom is {0, 1} n1 and the output space Ran is {0,1} m1 where n1 and m1 are each a positive integer.

[0071] <Pseudo-random number function generation process> The setup unit 111 receives the security parameter λ as an input and sets (pk, sk)←PKE.Gen(1 λ ) is obtained, and (pk,sk) is output as (pp,xk):=(pk,sk) (step S111).

[0072] The key generation unit 112 receives pp=pk as input, receives a security parameter λ and a parameter κ representing the size of D[k, m, x] as input, and generates msk←CPRF.Setup(1 λ ,1 κ) and obtain G(x) by fixing msk to y←CPRF.Eval(msk,x). Then, using the security parameter λ, k←SKE.Gen(1 λ ) and generate D with fixed k. auth [k, x]. Furthermore, the key generation unit 112 sets G(x) and D auth Using [k,x], sk f ←CPRF.Constrain(G(x),D auth [k,x]) and sk f is fixed CPRF.CEval(sk f , x) in G ¬∈νauth (x), and generate prfk = (G(x),k) and τ ← PKE.Enc(pp,(G ¬∈νauth (x),k) is obtained and output. auth ⊂{0,1} n1 is D auth It is a set of x that satisfies [k, x]=1 (step S112).

[0073] The watermark embedding unit 113 embeds the public parameters pp, the PRF key prfk, and the watermark m∈{0, 1} Lm takes as input, sets pp=pk and prfk=(G(x),k), and sets D[k,m,x] with k and m fixed. Furthermore, the watermark embedding unit 113 uses G(x) and D[k,m,x] to embed sk f ←Create CPRF.Constrain(G(x),D[k,m,x]) and sk f is fixed CPRF.CEval(sk f , x) in G ¬∈ν (x) and G ¬∈ν (x) is output as a pseudorandom number generator C~, where ν ⊂ {0,1} n is a set of input values ​​x that satisfy D[k,m,x]=1 (step S113).

[0074] The rest is as explained in the pseudo-random number function generation process of the first embodiment.

[0075] <Watermark extraction process> In this embodiment, D in formula (1)τ,Lm+1 :(γ,x,y)←ELWMPRF.Sim(xk,τ,Lm+1) takes xk, τ, and Lm+1 as inputs, and sk:=xk. (G ¬∈νauth (x),k) ← PKE.Dec(sk,τ), γ ← {0,1}, then x ← SKE.Enc(k, Lm+1||γ) and y ← G ¬∈νauth It is a function that obtains (x) and outputs (γ, x, y). D in Equation (2) τ,i :(γ,x,y)←ELWMPRF.Sim(xk,τ,i) takes xk, τ, and i∈[Lm] as inputs, and sk:=xk, and (G ¬∈νauth (x), k) ← PKE.Dec(sk, τ), γ ← {0, 1}, then x ← SKE.Enc(k, i||γ) and y ← G ¬∈νauth This is a function that obtains (x) and outputs (γ, x, y). The rest is the same as that explained in the watermark extraction process of the first embodiment.

[0076] [Third embodiment] The third embodiment is a specific example of the first embodiment, and is an example using a pseudorandom number generation function ELWMPRF that can embed an extraction-less digital watermark based on indistinguishability obfuscation. In the third embodiment, the input space Dom is {0, 1} Lin and the output space Ran is {0,1} Lout where Lin and Lout are positive integers.

[0077] <Pseudo-random number function generation process> The setup unit 111 receives a security parameter λ as an input, sets (pp, xk):=(⊥, ⊥), and outputs (pp, xk) (step S111).

[0078] The key generation unit 112 receives pp:=⊥ as an input and generates a calculation key K←PRF.Gen(1 λ ) and PRF.Eval with a fixed operation key K prfk Calculate F(x) for (K,x), and (pe.ek, pe.dk) ← PE.Gen(1 λ) and outputs prfk:=(F(x), pe.dk) and τ:=pe.ek (step S112).

[0079] The watermark embedding unit 113 takes pp:=⊥ and prfk:=(F(x), pe.dk) as input, sets D[F(x), pe.dk, m] with prfk, pe.dk, and m fixed, obtains iO(D[F(x), pe.dk, m]) by obfuscating D[F(x), pe.dk, m], and outputs iO(D[F(x), pe.dk, m]) as a pseudo-random number generation function C~ (step S113).

[0080] The rest is as explained in the pseudo-random number function generation process of the first embodiment.

[0081] <Watermark extraction process> In this embodiment, D in formula (1) τ,Lm+1 :(γ,x,y)←ELWMPRF.Sim(xk,τ,Lm+1) is (pe.ek, pe.dk)←PE.Gen(1 λ ) Let τ:=pe.ek be the pe.ek obtained in (1), xk:=⊥, and γ←{0,1} and s←{0,1} λ Let y←PRF(s), calculate x←PE.Enc(pe.ek, s||Lm+1||γ) for Lm+1, and output (γ, x, y). D in Equation (2) τ,i :(γ,x,y)←ELWMPRF.Sim(xk,τ,i) is (pe.ek, pe.dk)←PE.Gen(1 λ ) Let τ:=pe.ek be the pe.ek obtained in (1), xk:=⊥, and γ←{0,1} and s←{0,1} λ where y←PRF(s), and for i∈[Lm], calculate x←PE.Enc(pe.ek, s||i||γ), and output (γ, x, y). The rest is as explained in the watermark extraction process of the first embodiment.

[0082] [Hardware configuration] The pseudorandom function generation device 110 in each embodiment is configured by a general-purpose or dedicated computer having a processor (hardware processor) such as a central processing unit (CPU) and memories such as random-access memory (RAM) and read-only memory (ROM) executing a predetermined program. That is, the pseudorandom function generation device 110 in each embodiment has, for example, processing circuitry configured to implement each of the components. This computer may have one processor and memory, or multiple processors and memories. This program may be installed on the computer or may be pre-recorded in a ROM or the like. Furthermore, some or all of the processing units may be configured using electronic circuits that independently perform processing functions, rather than electronic circuits that perform functional configurations by loading a program, such as a CPU. Furthermore, the electronic circuits constituting one device may include multiple CPUs.

[0083] FIG. 5 is a block diagram illustrating the hardware configuration of a pseudorandom function generation device 110 according to each embodiment. As illustrated in FIG. 5, the pseudorandom function generation device 110 of this example includes a central processing unit (CPU) 10a, an input unit 10b, an output unit 10c, a random access memory (RAM) 10d, a read-only memory (ROM) 10e, an auxiliary storage device 10f, a communication unit 10h, and a bus 10g. The CPU 10a of this example includes a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, and executes various arithmetic processes according to various programs loaded into the register 10ac. The input unit 10b is an input terminal, keyboard, mouse, touch panel, or the like, through which data is input. The output unit 10c is an output terminal, display, or the like, through which data is output. The communication unit 10h is a LAN card or the like, controlled by the CPU 10a that has loaded a predetermined program. The RAM 10d is a static random access memory (SRAM), a dynamic random access memory (DRAM), or the like, and has a program area 10da where a predetermined program is stored and a data area 10db where various data are stored. The auxiliary storage device 10f is a hard disk, a magneto-optical disc (MO), a semiconductor memory, or the like, and has a program area 10fa where a predetermined program is stored and a data area 10fb where various data are stored. The bus 10g connects the CPU 10a, the input unit 10b, the output unit 10c, the RAM 10d, the ROM 10e, the communication unit 10h, and the auxiliary storage device 10f so that information can be exchanged. The CPU 10a writes the program stored in the program area 10fa of the auxiliary storage device 10f to the program area 10da of the RAM 10d in accordance with the loaded OS (Operating System) program. Similarly, the CPU 10a writes various data stored in the data area 10fb of the auxiliary storage device 10f to the data area 10db of the RAM 10d. The address on the RAM 10d where this program or data is written is stored in the register 10ac of the CPU 10a.The control unit 10aa of the CPU 10a sequentially reads out these addresses stored in the register 10ac, reads out programs and data from the areas on the RAM 10d indicated by the read addresses, causes the calculation unit 10ab to sequentially execute the calculations indicated by the programs, and stores the calculation results in the register 10ac. With this configuration, the functional configuration of the pseudorandom number function generation device 110 is realized.

[0084] The above-mentioned program can be recorded on a computer-readable recording medium. Examples of computer-readable recording media include non-transitory recording media. Examples of such recording media include magnetic recording devices, optical disks, magneto-optical recording media, and semiconductor memories.

[0085] This program may be distributed, for example, by selling, transferring, or lending a portable recording medium, such as a DVD or CD-ROM, on which the program is recorded. Furthermore, the program may be distributed by storing the program in a storage device of a server computer and transferring the program from the server computer to other computers via a network. As described above, a computer that executes such a program may, for example, first temporarily store the program recorded on a portable recording medium or transferred from the server computer in its own storage device. Then, when executing a process, the computer reads the program stored in its own storage device and executes processing in accordance with the read program. Alternatively, the program may be executed by a computer that reads the program directly from a portable recording medium and executes processing in accordance with the program. Furthermore, the computer may execute processing in accordance with the received program each time a program is transferred from the server computer to the computer. Alternatively, the server computer may not transfer the program to the computer, but may instead execute the processing function simply by issuing an execution instruction and obtaining the results, thereby executing the processing described above through a so-called ASP (Application Service Provider) type service. In this embodiment, the program includes information used for processing by an electronic computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that dictate computer processing).

[0086] In each embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized by hardware.

[0087] The watermark extraction device 120 in each embodiment may be configured as a quantum computing device, or may be configured as a hybrid of a quantum computing device and a device configured by a general-purpose or dedicated classical computer executing a predetermined program.

[0088] [Other modifications, etc.] The present invention is not limited to the above-described embodiments. For example, the various processes described above may not only be executed in chronological order as described, but may also be executed in parallel or individually depending on the processing capabilities of the devices that execute the processes or as needed. It goes without saying that other modifications are possible without departing from the spirit of the present invention. [Industrial Applicability]

[0089] The present invention can be used in fields such as cryptography, secret sharing, and secure computation, which use pseudorandom number functions. [Explanation of symbols]

[0090] 1. Security System 110 Pseudorandom function generator 111 Setup section 112 Key generation section 113 Watermark Embedding Section 120 Watermark Extraction Device 121,123 Measuring part 122,124 Extraction part

Claims

A security system having a pseudo-random number function generator and a watermark extraction device, wherein the pseudo-random number function generator A pseudorandom number generator that outputs y∈Ran for an input value x∈Dom is given a watermark m∈{0,1} Lm Generate a pseudorandom number generating function C~ that embeds Dom is the input space, Ran is the output space, Lm is a positive integer, and x 1 ||x 2 x 1 and x 2 represents the concatenation of has a setup unit that outputs public parameters pp and a watermark extraction key xk, a key generation unit that takes the public parameters pp as input and outputs a PRF key prfk and a public tag τ, and a watermark embedding unit that takes the public parameters pp, the PRF key prfk, and a watermark m as input and outputs a pseudo-random number generation function C~ in which a message m||0, which is a bit concatenation of the watermark m and 0, is embedded, and a classical input-output quantum device C=(q,U) that mimics the operation of the pseudo-random number generation function C~ is a quantum computing device including a quantum bit string in a quantum state q and a unitary device that applies a unitary transformation U to the quantum state q, A ε,δ P,D (q) is an approximate projection device that takes the quantum state q as input and outputs a measurement value p of the quantum state q, the approximate projection device A ε,δ P,D (q) is determined by parameters ε,δ satisfying 0≦ε,δ<1, a set P=(P b,x,y,Q b,x,y ) b,x,y of binary projection measurement devices, and a probability distribution D of measurement values, ε’ = ε / (Lm + 1), λ is a security parameter, δ’ = 2 -λ, P b,x,y = U x,y + |b><b|U x,y, Q b,x,y = I - P b,x,y, b is a variable vector representing a quantum state to be measured, |b> represents a ket vector of b, <b| represents a bra vector of b, |b><b| represents a projection operator, U x,y represents a unitary transformation U that mimics the operation of the pseudo-random number generation function C~ that outputs an output value y for an input of the input value x, U x,y + represents the Hermitian transpose matrix of U x,y, I represents the identity matrix, [L] represents the set of integers 1,…,L, for all i ∈ [Lm + 1], D τ,i represents a probability distribution defined by D τ,i : (γ,x,y)←ELWMPRF.Sim(xk,τ,i), and ELWMPRF.Sim(xk,τ,i) is a simulation function that takes a watermark extraction key xk, a public tag τ, and i ∈ [Lm] as input and outputs (γ,x,y), where γ is a real number representing the probability that y is output for x, the watermark extraction device Taking as input the watermark extraction key xk, the public tag τ, the parameters ε and δ, and information representing the quantum state q and the unitary transformation U of the quantum bit of the classical-input / output quantum device C=(q,U), [Equation 4] a first measurement unit that obtains and outputs a measurement value p~ Lm+1 by measuring a first extraction unit that determines whether the measurement value p~ Lm+1 satisfies p~ Lm+1 <(1 / 2)+ε-4ε', and outputs information "unmarked" indicating that a watermark is not embedded in the classical input / output quantum device C if it is determined that p~ Lm+1 <(1 / 2)+ε-4ε' is satisfied.

2. A pseudorandom number function generating device that generates a pseudorandom number generating function C~ in which a watermark m∈{0,1} Lm is embedded in a pseudorandom number generating function that outputs an output value y∈Ran in response to an input value x∈Dom, comprising: Dom is the input space, Ran is the output space, Lm is a positive integer, x 1 ||x 2 denotes the concatenation of x 1 and x 2 , a setup unit that outputs public parameters pp and a watermark extraction key xk; a key generation unit that receives the public parameters pp as input and outputs a PRF key prfk and a public tag τ; a watermark embedding unit that receives the public parameters pp, the PRF key prfk, and a watermark m as input, and outputs a pseudorandom number generating function C~ in which a message m||0, which is a bit concatenation of the watermark m and 0, is embedded; and The input space Dom is {0,1} n1 and the output space Ran is {0,1} m1 where n1 and m1 are positive integers, and [L] denotes the set of integers 1,…,L, Constrainable pseudorandom number generating function PRF based on the difficulty of the LWE problem CPRF However, msk←CPRF.Setup(1 λ ), sk f ←CPRF.Constrain(m sk ,f),y←CPRF.Eval(msk,x),y←CPRF.CEval(sk f , x), CPRF.Setup(1 λ ) is a setup function that takes a security parameter λ as input and outputs a master key msk, CPRF.Constrain(msk,f) takes the master key msk and an arbitrary function f as input and generates a constrained key sk f is a restricted key generation function that outputs CPRF.Eval(msk, x) is an arithmetic function that takes the master key msk and the input value x∈Dom as input and outputs y∈Ran, CPRF.CEval(sk f , x) is the restricted key sk f and a restricted operation function that takes the input value x∈Dom as an input and outputs the output value y∈Ran, CPRF.Eval(msk,x) where the master key msk is fixed is G(x):{0,1} n1 →{0,1} m1 and The restricted key sk f is fixed CPRF.CEval(sk f ,x) to G ¬∈ν (x):{0,1} n1 →{0,1} m2 and ν represents the set of x for which f(x)=1 for the function f(·), and G ¬∈ν (x) can be used only for x that does not belong to the set ν, The secret key cryptosystem SKE, which is based on the difficulty of the LWE problem, is λ ), ct←SKE.Enc(k,m), m' or ⊥←SKE.Dec(k,ct), KE.Gen(1 λ ) is a private key generation function that takes the security parameter λ as input and outputs a private key k, SKE.Enc(k,m) is the secret key k and m∈{0,1} Lske Takes input and ciphertext ct∈{0,1} n1 is an encryption function that outputs Lske=ceil(Log 2 Lm)+1, and ceil(α) means the smallest natural number equal to or greater than α. SKE.Dec(k,ct) is a decryption function that takes the secret key k and the ciphertext ct as input and outputs m' or error information ⊥ indicating that decryption is not possible, The PKE public key encryption scheme based on the difficulty of the LWE problem is (pk,sk)←PKE.Gen(1 λ ), ct←PKE.Enc(pk,m), m' or ⊥←PKE.Dec(sk,ct), PKE.Gen(1 λ ) is a key generation function that takes the security parameter λ as input and outputs a public key pk and a private key sk, PKE.Enc(pk,m) is the public key pk and m∈{0,1} 2λ is an encryption function that takes input and outputs ciphertext ct, PKE.Dec(sk,ct) is a decryption function that takes the private key sk and the ciphertext ct as input and outputs m' or error information ⊥ indicating that decryption is not possible, D auth [k,x] is a function where k is fixed and x∈{0,1} n1 It is a function that takes as input, calculates d←SKE.Dec(k,x), and outputs 0 if d≠⊥, and 1 otherwise. D[k,m,x] is a vector of k and m, where x∈{0,1} n1 Take as input, calculate d←SKE.Dec(k,x), and if d≠⊥, calculate d=i||η∈{0,1} Lske Let η=m i A function that outputs 1 if ⊥, 0 otherwise, and 0 if ⊥, where i∈[Lm] and η∈{0,1}, and m=m 1 ||…||m Lm ∈{0,1} Lm and The setup unit takes the security parameter λ as an input and sets (pk, sk)←PKE.Gen(1 λ ) and output (pk,sk) as (pp,xk):=(pk,sk), The key generation unit Take pp=pk as input, The security parameter λ and a parameter κ representing the size of D[k,m,x] are taken as inputs, and msk←CPRF.Setup(1 λ , 1 κ ) and obtain G(x) by fixing msk to y←CPRF.Eval(msk,x). Using the security parameter λ, k←SKE.Gen(1 λ ), D with fixed k auth Set [k,x], G(x) and D auth Using [k,x], sk f ←CPRF.Constrain(G(x),D auth [k,x]) and sk f is fixed CPRF.CEval(sk f , x) in G ¬∈νauth Generate (x), prfk = (G(x),k) and τ ← PKE.Enc(pp,(G ¬∈νauth (x),k)) and output it. ν auth ⊂{0,1} n1 is D auth is the set of x such that [k,x]=1, The watermark embedding unit Set D[k,m,x] with pp=pk and prfk=(G(x),k) for fixed k and m, Using G(x) and D[k,m,x], sk f ←Create CPRF.Constrain(G(x),D[k,m,x]) and sk f is fixed CPRF.CEval(sk f , x) in G ¬∈ν (x) and G ¬∈ν (x) is output as the pseudorandom number generating function C, and ν ⊂ {0,1} n is a set of the input values ​​x that satisfy D[k,m,x]=1.

3. A pseudorandom number function generating device that generates a pseudorandom number generating function C~ in which a watermark m∈{0,1} Lm is embedded in a pseudorandom number generating function that outputs an output value y∈Ran in response to an input value x∈Dom, Dom is the input space, Ran is the output space, Lm is a positive integer, x 1 ||x 2 denotes the concatenation of x 1 and x 2 , a setup unit that outputs public parameters pp and a watermark extraction key xk; a key generation unit that receives the public parameters pp as input and outputs a PRF key prfk and a public tag τ; a watermark embedding unit that receives the public parameters pp, the PRF key prfk, and a watermark m as input, and outputs a pseudorandom number generating function C~ in which a message m||0, which is a bit concatenation of the watermark m and 0, is embedded; and The input space Dom is {0,1} Lin and the output space Ran is {0,1} Lout where Lin and Lout are positive integers, Punctured pseudorandom number generating function PRF PPRF However, K←PRF.Gen(1 λ ), y←PRF.Eval prfk (K,x), K ¬S⊆ ←PRF.Eval prfk¬x⊆ (S) PRF.Gen(1 λ ) is a key generation function that takes a security parameter λ as input and outputs a computation key K, PRF.Eval prfk (K, x) is the operation key K and the input value x∈{0, 1} Lin takes as input, and the output value y∈{0,1} Lout Arithmetic function F(x) that outputs: {0,1} Lin →{0,1} Lout and PRF.Eval prfk¬x⊆ (S) is the set S ⊆ {0, 1} of the operation key K and the input value x. L1 input, and a puncturing key K that can be used only for inputs that do not belong to the set S. ¬S⊆ A puncturing key generation function F that outputs ¬x⊆ (S) and The puncturable encryption scheme PE is (ek,dk)←PE.Gen(1 λ ),dk ≠c* ←PE.Puncture(dk,{c*}), c←PE.Enc(ek,m), m' or ⊥←PE.Dec(dk',c') PE.Gen(1 λ ) is a key generation function that takes the security parameter λ as input and outputs the encryption key ek and the decryption key dk, PE.Puncture(dk,{c*}) takes the decryption key dk and the ciphertext c* as input, and punctures the decryption key dk that can only be used for the ciphertext other than c*. ≠c* is a puncturing decryption key generation function that outputs PE.Enc(ek,m) is the encryption key ek and m∈{0,1} Lpt as input and ciphertext c∈{0,1} Lct is an encryption function that outputs PE.Dec(dk',c') is the decryption key dk' and the ciphertext c'∈{0,1} Lct takes as input m'∈{0,1} Lpt Or it is a decoding function that outputs error information ⊥ indicating that decoding is not possible, Lpt and Lct are positive integers, and Lpt = λ + ceil(log 2 Lm)+1, Lin = Lct, and Lct = poly(λ, log 2 Lm), ceil represents the ceiling function, The indistinguishability obfuscation function iO is λ } λ∈N is a function that takes as input and outputs an obfuscated circuit, The pseudorandom number generating function PRF is x∈{0,1} λ Take as input, y∈{0,1} Lout is a function that outputs D[F(x), pe.dk, m] is a function that prfk, pe.dk, and m are fixed and the input value x∈{0,1} Lm Take as input, calculate d←PE.Dec(pe.dk, x), if d≠⊥, set d=s||i||η, and η=m i If so, D[F(x), pe.dk, m] is a function that outputs PRF(s), otherwise it outputs F(x), and if d=⊥ it outputs F(x), The setup unit sets (pp, xk):=(⊥, ⊥), The key generation unit Take pp:=⊥ as input, Operation key K←PRF.Gen(1 λ ) and PRF.Eval prfk Calculate F(x) for (K,x), (pe.ek, pe.dk)←PE.Gen(1 λ ), Print prfk:=(F(x), pe.dk) and τ:=pe.ek, The watermark embedding unit Take as input pp:=⊥ and prfk:=(F(x), pe.dk), Set D[F(x), pe.dk, m] with prfk, pe.dk and m fixed, A pseudorandom number function generating device that obtains iO(D[F(x), pe.dk, m]) by obfuscating D[F(x), pe.dk, m] and outputs iO(D[F(x), pe.dk, m]) as the pseudorandom number generating function C~.

4. A pseudorandom number generator that outputs y∈Ran for an input value x∈Dom is given a watermark m∈{0,1} Lm a classical-input / output quantum device C=(q,U) that mimics the behavior of a pseudo-random number generation function C~ with embedded therein includes a quantum bit string of a quantum state q and a unitary device that performs a unitary transformation U on the quantum state q, Dom is the input space, Ran is the output space, Lm is a positive integer, and x 1 ||x 2 x 1 and x 2 represents the concatenation of A ε,δ P,D (q) is an approximation projection device that takes the quantum state q as an input and outputs a measurement value p of the quantum state q; The approximate projection device A ε,δ P,D (q) is a set of binary projection measurement devices P = (P b,x,y ,Q b,x,y ) b,x,y , and the probability distribution D of the measurements, ε’ = ε / (Lm + 1), where λ is the security parameter, and δ’ = 2 -λ and P b,x,y = U x,y + |b><b|U x,y and Q b,x,y = I - P b,x,y where b is a variable vector representing the quantum state of the measurement target, |b> represents the ket vector of b, <b| represents the bra vector of b, |b><b| represents a projection operator, and U x,y represents a unitary transformation U that mimics the operation of the pseudorandom number generation function C~ that outputs the output value y for the input of the input value x, and U x,y + is U x,y 's Hermitian transpose matrix, I represents the identity matrix, [L] represents the set of integers 1,..., L, and for all i ∈ [Lm + 1], D τ,i is D τ,i : represents the probability distribution defined by (γ, x, y) ← ELWMPRF.Sim(xk, τ, i), where ELWMPRF.Sim(xk, τ, i) is a simulation function that takes as input the watermark extraction key xk, the public tag τ, and i ∈ [Lm] and outputs (γ, x, y), and γ is a real number representing the probability that y is output for x Taking as input the watermark extraction key xk, the public tag τ, the parameters ε and δ, and information representing the quantum state q and the unitary transformation U of the quantum bit of the classical-input / output quantum device C=(q,U), [Equation 5] By measuring the measured value p~ Lm+1 a first measurement unit that obtains and outputs the The measured value p~ Lm+1 ga p~ Lm+1 Determine whether or not <(1 / 2)+ε-4ε' is satisfied, and p~ Lm+1 a first extraction unit that outputs information "unmarked" indicating that a watermark is not embedded in the classical-input / output quantum device C when it is determined that the condition <(1 / 2)+ε-4ε' is satisfied.

5. 5. The watermark extraction device of claim 4, The first extraction unit is Lm+1 If it is determined that the quantum state of the quantum bit after measurement of the classical input / output quantum device C is not satisfied, the quantum state of the quantum bit after measurement of the classical input / output quantum device C is determined to be q 0 and outputs as The watermark extraction device further comprises: In order from i=1 to Lm, the watermark extraction key xk, the public tag τ, the parameters ε and δ, and the quantum state q of the quantum bit i-1 and information representing the unitary transformation U is taken as input, [Equation 6] By measuring the measured value p~ i and the quantum state of the quantum bit after the measurement of the classical input / output quantum device C is q i Let p~ i >(1 / 2)+ε-4ε' then m i Set '=0 and p~ i <1 / 2)+ε-4ε', then m i Set '=1 and p~ with any i i =(1 / 2)+ε-4ε', then m'=0 Lm a second measurement unit that sets For all i∈[Lm], p~ i If m' is not equal to m = (1 / 2) + ε - 4ε', then the watermark m' = m 1 '||…||m Lm ' and for any i, p~ i =(1 / 2)+ε-4ε', then watermark m'=0 Lm a second extraction unit that outputs A watermark extraction device comprising:

6. 6. The watermark extraction device according to claim 4 or 5, The secret key cryptosystem SKE, which is based on the difficulty of the LWE problem, is λ ), ct←SKE.Enc(k,m), m' or ⊥←SKE.Dec(k,ct), KE.Gen(1 λ ) is a private key generation function that takes the security parameter λ as input and outputs a private key k, SKE.Enc(k,m) is the secret key k and m∈{0,1} Lske Takes input and ciphertext ct∈{0,1} n1 is an encryption function that outputs Lske=ceil(Log 2 Lm)+1, and ceil(α) means the smallest natural number equal to or greater than α. SKE.Dec(k,ct) is a decryption function that takes the secret key k and the ciphertext ct as input and outputs m' or error information ⊥ indicating that decryption is not possible, The PKE public key encryption scheme based on the difficulty of the LWE problem is (pk,sk)←PKE.Gen(1 λ ), ct←PKE.Enc(pk,m), m' or ⊥←PKE.Dec(sk,ct), PKE.Gen(1 λ ) is a key generation function that takes the security parameter λ as input and outputs a public key pk and a private key sk, PKE.Enc(pk,m) is the public key pk and m∈{0,1} 2λ is an encryption function that takes input and outputs ciphertext ct, PKE.Dec(sk,ct) is a decryption function that takes the private key sk and the ciphertext ct as input and outputs m' or error information ⊥ indicating that decryption is not possible, ELWMPRF.Sim(xk,τ,Lm+1) takes xk, τ, and Lm+1 as inputs, and sets sk:=xk. (G ¬∈νauth (x),k) ← PKE.Dec(sk,τ), γ ← {0,1}, then x ← SKE.Enc(k, Lm+1||γ) and y ← G ¬∈νauth It is a function that obtains (x) and outputs (γ, x, y), ELWMPRF.Sim(xk,τ,i) takes xk, τ, and i∈[Lm] as inputs, and sk:=xk. (G ¬∈νauth (x), k) ← PKE.Dec(sk, τ), γ ← {0, 1}, then x ← SKE.Enc(k, i||γ) and y ← G ¬∈νauth A watermark extractor is a function that takes (x) and outputs (γ, x, y).

7. 6. The watermark extraction device according to claim 4 or 5, λ is a security parameter, Lout is a positive integer, The pseudorandom number generating function PRF is λ Take as input, y∈{0,1} Lout is a function that outputs The puncturable encryption scheme PE is (ek,dk)←PE.Gen(1 λ ),dk ≠c* ←PE.Puncture(dk,{c*}), c←PE.Enc(ek,m), m' or ⊥←PE.Dec(dk',c') PE.Gen(1 λ ) is a key generation function that takes the security parameter λ as input and outputs the encryption key ek and the decryption key dk, PE.Puncture(dk,{c*}) takes the decryption key dk and the ciphertext c* as input and punctures the decryption key dk ≠c* is a puncturing decryption key generation function that outputs PE.Enc(ek,m) is the encryption key ek and m∈{0,1} Lpt as input and ciphertext c∈{0,1} Lct is an encryption function that outputs PE.Dec(dk',c') is the decryption key dk' and the ciphertext c'∈{0,1} Lct takes as input m'∈{0,1} Lpt Or it is a decoding function that outputs error information ⊥ indicating that decoding is not possible, Lpt and Lct are positive integers, and Lpt = λ + ceil(log 2 Lm)+1, Lin = Lct, and Lct = poly(λ, log 2 Lm) is satisfied, ELWMPRF.Sim(xk,τ,Lm+1) is (pe.ek, pe.dk)←PE.Gen(1 λ ) Let τ:=pe.ek be the pe.ek obtained in (1), xk:=⊥, and γ←{0,1} and s←{0,1} λ Let y ← PRF(s), calculate x ← PE.Enc(pe.ek, s||Lm+1||γ) for Lm+1, and output (γ, x, y). ELWMPRF.Sim(xk,τ,i) is (pe.ek, pe.dk)←PE.Gen(1 λ ) Let τ:=pe.ek be the pe.ek obtained in (1), xk:=⊥, and γ←{0,1} and s←{0,1} λ Let y ← PRF(s), and for i∈[Lm], calculate x ← PE.Enc(pe.ek, s||i||γ), and output (γ,x,y). A watermark extraction device is a function.

8. A program for causing a computer to function as the pseudorandom number function generating device of claim 2 or 3.

Citation Information

Patent Citations

  • Electronic watermark processing system, function execution device, electronic watermark key generation device, electronic watermark embedded device, electronic watermark detection device, electronic watermark removal device, electronic watermark processing method, function execution method and program

    JP2013213962A

  • Digital watermark system, digital watermark key generation device, digital watermark embedding device, digital watermark detection device, digital watermark removal device, function execution device, digital watermark method and program

    JP2015068871A

  • Electronic watermarking system, electronic watermarking method and program

    WO2021095103A1