Customizable encryption device for B5G / 6G mobile communication systems, customizable encryption method and encryption program for B5G / 6G mobile communication systems

A customizable stream encryption device adjusts parallel processes and function ratios to address performance variations in 5G/6G systems, ensuring compatibility with diverse devices from high-performance smartphones to low-power IoT devices.

JP7796687B2Active Publication Date: 2026-01-09KDDI CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023033393
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-03-06
Publication Date
2026-01-09
Estimated Expiration
2043-03-06

AI Technical Summary

Technical Problem

Current encryption technologies in 5G/6G mobile communication systems are not customizable, leading to potential bottlenecks in performance requirements due to varying device needs, particularly between high-performance devices like smartphones and PCs, and low-power IoT devices.

Method used

A customizable stream encryption device that adjusts the number of parallel stream cipher processes and the ratio of nonlinear functions to logical operations, allowing configuration based on specific performance requirements.

Benefits of technology

The device can meet a wide range of performance needs by optimizing power consumption and security through customizable configurations, supporting both high-speed, high-capacity devices and low-power IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007796687000001
    Figure 0007796687000001
  • Figure 0007796687000002
    Figure 0007796687000002
  • Figure 0007796687000003
    Figure 0007796687000003
Patent Text Reader

Abstract

To provide a customizable streaming encryption device capable of satisfying various performance requirements in a B5G / 6G mobile communication system.SOLUTION: An encryption device 100 includes an initialization processing unit 200 and an encryption processing unit 300. The initialization processing unit 200 includes a round function and stirs an internal state. The encryption processing unit 300 generates a ciphertext by an operation of a key sequence extracted from the stirred internal state and a plaintext. A parallel number of processing in the round function is designated by first configuration designation data S1, and a ratio between a non-linear function and a logical operation in the round function is designated by second configuration designation data S2. Therefore, the encryption device can be provided suitable for various requirements relative to performance, power consumption, and safety.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] In the 3GPP (registered trademark) security architecture, multiple keys to be used for different purposes are derived from a single key using a key derivation algorithm. In 3G to 5G communication systems, MILENAGE and TUAK are used as the key derivation algorithm. Currently, a 256-bit key derivation algorithm is being considered as a key derivation algorithm for B5G (Beyond 5G) / 6G.

[0002] The present invention proposes an encryption device that can be tuned to suit various terminals in this B5G / 6G mobile communication system. [Background technology]

[0003] Conventionally, Non-Patent Documents 1 and 2 define the symmetric key encryption algorithms AES, SNOW-3G, and ZUG for 5G mobile communication systems. [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] 3GPP(registered trademark) TS 35.216: "Specification of the 3GPP(registered trademark) Confidentiality and Integrity Algorithms UEA2 & UIA2; Document 2: SNOW 3G specification". [Non-patent document 2] 3GPP (registered trademark) TS 33.501: "Security architecture and procedures for 5G Systems" Summary of the Invention [Problem to be solved by the invention]

[0005] The 5G / 6G mobile communications system will further enhance the distinctive features of 5G, equipping it with features such as "ultra-high speed and large capacity," "ultra-low latency," and "ultra-large number of simultaneous connections," making it possible to instantly and accurately process huge amounts of data from any location. At the same time, IoT devices, in particular, will need to meet the requirement of "ultra-low power consumption." If low-power consumption technologies are not developed, IT-related power consumption in 2030 is expected to be 36 times that of 2016. This 36-fold increase in power consumption compared to 2016 is also 1.5 times the total power consumption in 2018.

[0006] In this situation, the cryptographic algorithms required for B5G / 6G must be customizable to accommodate various use cases and device requirements. For example, smartphones and personal computers (PCs) require high-performance cryptographic methods to enable ultra-high-speed, high-volume communications. "High performance" here means a large amount of plaintext that can be encrypted per unit time. On the other hand, IoT devices and other devices with limited power supplies must minimize power consumption, even if it means sacrificing some performance.

[0007] The encryption used in current 5G mobile communication systems cannot be customized, so encryption processing could become a bottleneck in the performance requirements of B5G / 6G mobile communication systems.

[0008] Therefore, an object of the present invention is to provide a customizable stream encryption device that can meet a wide variety of performance requirements in B5G / 6G mobile communication systems. [Means for solving the problem]

[0009] The inventors discovered that performance requirements can be met by customizing the number of parallel stream cipher processes and the ratio of processes (e.g., the ratio of nonlinear functions to logical operations), and thus completed the present invention.

[0010] (1) The encryption device according to the present invention is an encryption device including an initialization processing unit that includes a round function and mixes an internal state, and an encryption processing unit that includes a round function, mixes the internal state, and generates ciphertext by calculating the exclusive OR of a key stream extracted from the mixed internal state and plaintext, and customizes the round function based on configuration specification data.

[0011] (2) The configuration designation data may designate the number of parallel processes in the round function.

[0012] (3) The configuration designation data may designate the ratio of nonlinear functions to logical operations in the round function.

[0013] (4) An authentication tag generation processing unit may be provided downstream of the encryption processing unit, the round function may have an external input, and the authentication tag generation processing unit may generate an authentication tag by inputting plain text as the external input of the encryption processing unit.

[0014] (5) An encryption method according to the present invention includes an initialization processing step of mixing an internal state using a round function, and an encryption processing step of mixing the internal state using the round function and generating ciphertext by calculating the exclusive OR of a key stream extracted from the mixed internal state and plaintext, and customizes the round function based on configuration specification data.

[0015] (6) An encryption program according to the present invention causes a computer to function as the encryption device. [Effects of the Invention]

[0016] According to the present invention, a customizable stream encryption device can be provided that can meet a wide variety of performance requirements in B5G / 6G mobile communication systems. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a diagram illustrating a schematic configuration of an encryption device according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating a hardware configuration of an encryption device according to the first embodiment of the present invention. [Figure 3] FIG. 2 is a diagram illustrating a detailed configuration of an encryption device according to the first embodiment of the present invention. [Figure 4] FIG. 3 is a diagram illustrating an example of a round function of the encryption device according to the first exemplary embodiment of the present invention. [Figure 5] FIG. 3 is a diagram illustrating an example of a round function of the encryption device according to the first exemplary embodiment of the present invention. [Figure 6] FIG. 10 is a diagram illustrating a schematic configuration of an encryption device according to a second embodiment of the present invention. [Figure 7] FIG. 10 is a diagram illustrating a detailed configuration of an encryption device according to a second embodiment of the present invention. [Figure 8] FIG. 10 is a diagram illustrating an example of a round function of the encryption device according to the second embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0018] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. [Embodiment 1] 1 shows a schematic configuration of an encryption device 100 according to a first embodiment. The encryption device 100 according to the first embodiment includes an initialization processing unit 200 and an encryption processing unit 300. The initialization processing unit 200 creates an internal state that is mixed based on a key and a random number. The encryption processing unit 300 uses the internal state created by the initialization processing unit 200 to encrypt plaintext and output ciphertext.

[0019] First configuration designation data S1 and second configuration designation data S2 are input to the encryption device 100. The first configuration designation data S1 is data that designates the number of parallel processes in the encryption device 100. The second configuration designation data S2 is data that designates the ratio of processes, for example, the ratio between nonlinear functions and logical operations. The first configuration designation data S1 and the second configuration designation data S2 are collectively referred to as "configuration designation data." The configuration designation data may be input from outside the encryption device 100, or the encryption device 100 may be configured to store the data internally.

[0020] 2 is a diagram showing the hardware configuration of the encryption device 100 of embodiment 1. The encryption device 100 is an information processing device (computer) that includes a control unit 10, a storage unit 20, and various interfaces and the like.

[0021] The control unit 10 is a part that controls the entire encryption device 100, and realizes each function in the first embodiment by appropriately reading and executing various programs stored in the storage unit 20. The control unit 10 may be a CPU.

[0022] The storage unit 20 is a storage area for various programs and various data for causing the hardware group to function as the encryption device 100, and may be a ROM, RAM, flash memory, hard disk drive (HDD), etc. Therefore, configuration designation data may be stored in the storage unit 20. Specifically, the storage unit 20 stores a program (encrypted program) for causing the control unit 10 to execute each function of the first embodiment.

[0023] The control unit 10 functions as a processing unit 11 by executing the encryption program.

[0024] Fig. 3 is a diagram showing a detailed configuration of the encryption device 100 when the number of parallel processes is specified as "4" by the first configuration specification data S1. As shown in Fig. 3, the number of parallel processes means the number of signals in the internal state of Fig. 1. Blocks with "R" written inside, such as 31 to 3m and 51 to 5m in Fig. 3, represent round functions. The round functions shuffle the input internal states and output the shuffled internal states.

[0025] At the start of the stream cipher process, a key and an initial value are stored in the internal state. Next, in the initialization processing unit 200, a round function, which will be described in detail later, is applied to the internal state multiple times, thereby shuffling the internal state. Also, in the adders 41 to 44, the key can be added again to the internal state after the round function has been applied, thereby further shuffling the internal state.

[0026] In the encryption processing unit 300, the exclusive-OR calculators 61 to 6n calculate the exclusive-OR of the key stream extracted from the internal state and the plain text to obtain cipher text. Each time a key stream is extracted, a round function is applied to update the internal state. Furthermore, in extracting the key stream, it is also possible to use a key stream generation function that is configured using a nonlinear function, a logical operation, or the like.

[0027] FIG. 4 shows an example of the configuration of a round function when the number of parallel processes specified by the first configuration specification data S1 is "4." The internal state before the update is represented by a1 to d1. The internal state after the update is represented by a2 to d2. The internal state after the update is calculated using a nonlinear function or logical operation of the internal state before the update. An example of a nonlinear function is the AES round function, and an example of a logical operation is an exclusive OR operation. FIG. 4 is merely an example of the configuration of a round function when the number of parallel processes is "4." It is also possible to calculate a logical operation of the pre-update internal states a1 and b1, or to use the pre-update internal states c1 and d1 as inputs to a nonlinear function.

[0028] It is also possible to increase or decrease the number of processes by changing the number of parallel processes. Increasing the number of parallel processes increases the size of the internal state, and the size of the keystream that can be generated each time the round function is applied. This improves the performance of the stream cipher. However, the implementation scale increases, resulting in increased power consumption. Reducing the number of processes reduces the implementation scale and reduces power consumption. However, as a trade-off, the size of the keystream that can be generated at one time also decreases, resulting in a decrease in performance.

[0029] FIG. 5 shows an example of the configuration of a round function when the number of parallel processes is "2".

[0030] Furthermore, Figure 4 shows a round function when the ratio of nonlinear functions to logical operations is "1:1." However, by changing the value of the second configuration specification data S2, the ratio of nonlinear functions to logical operations can be changed to "1:3" or "3:1." Adjusting the ratio of nonlinear functions to logical operations makes it possible to tune security and performance. Increasing the ratio of nonlinear functions improves security but reduces processing performance. On the other hand, increasing the ratio of logical operations improves performance but reduces security.

[0031] As described above, the encryption device of embodiment 1 can adjust the performance, power consumption, and security of the encryption device using configuration specification data, making it possible to provide an encryption device that meets a wide variety of performance requirements.

[0032] [Embodiment 2] FIG. 6 shows a schematic configuration of an encryption device 900 according to the second embodiment. The encryption device 900 of the second embodiment is an encryption device that generates authenticated encryption by using a round function with an external input. This authenticated encryption is generally called "authenticated encryption," and generates an authentication tag (Message Authentication Code (MAC)) at the same time as generating a ciphertext.

[0033] The encryption device 900 includes an associated data processing unit 400 and an authentication tag generation processing unit 500 in addition to the components of the encryption device 100 of the first embodiment. The round functions used in each unit include external inputs. The initialization processing unit 200 uses an additional input as the external input of the round function. The additional input may be a fixed value or a bit string of 0 or 1.

[0034] The related data processing unit 400 uses related information as an external input for the round function. The related information is information specified by the user, and may be a session number or a sequence number, or may be an all-zero value. Furthermore, inputting related information is not essential, and the round function of the related data processing unit 400 may be one that does not require an external input, similar to the round function of the first embodiment.

[0035] The encryption processing unit 300 uses plaintext as an external input to the round function. The authentication tag generation processing unit 500 uses an additional input as an external input of the round function. This additional input may be a fixed value, as in the initialization processing unit 200, or may be a bit string of 0 or 1.

[0036] The hardware configuration of the encryption device 900 of the second embodiment is the same as the hardware configuration of the encryption device 100 of the first embodiment, and therefore a description thereof will be omitted.

[0037] Fig. 7 shows a detailed configuration of the encryption device 900 of the second embodiment. The input from above the round function in Fig. 7 is the external input.

[0038] The initialization processing unit 200 scrambles the internal state by applying the round function to the internal state multiple times. The adder 40 in Fig. 7 is a combination of the adders 41 to 44 in the first embodiment. The adder 40 in Fig. 7 is not essential, and the configuration can also be such that the adder 40 is not included.

[0039] The related data processing unit 400 repeatedly applies the round function and updates the internal state until all related information is input to the round function.

[0040] In the encryption processing unit 300, the exclusive-OR calculators 61 to 6n calculate the exclusive-OR between the key stream extracted from the internal state and the plain text to obtain cipher text, which is the same as in the first embodiment. In the encryption processing unit 300, a round function is applied every time a key stream is extracted, and the internal state is updated. In extracting the key stream, a configuration using a key stream generation function composed of a nonlinear function or a logical operation is also possible.

[0041] In the authentication tag generation processing unit 500, the internal state is agitated by applying the round function to the internal state multiple times, and an authentication tag is obtained as the internal state after updating by the round function 8q in the final stage of the authentication tag generation processing unit 500. For extraction of the authentication tag, it is also possible to use an authentication tag generation function composed of a nonlinear function or a logical operation.

[0042] Fig. 8 shows an example of the configuration of a round function having an external input. In this configuration, as in the first embodiment, it is possible to change the number of parallel processes and adjust the ratio of nonlinear functions to logical operations based on configuration designation data input from outside the encryption device 900 or stored in the storage unit 20 of the encryption device 900. Fig. 8 is merely an example of the configuration of a round function having an external input, and a configuration in which the external input is input to a logical operation may also be used.

[0043] The ciphertext and authentication tag thus generated (the authentication tag generated by the encryption device 900 will be referred to as "authentication tag A") are sent to the receiving side via the communication system. The receiving side generates an authentication tag by performing a predetermined process using the received ciphertext and a key shared with the sending side. This authentication tag generated by the receiving side will be called "authentication tag B." By verifying that authentication tag B matches authentication tag A, it is possible to confirm that the received message has not been tampered with.

[0044] The parallel numbers of processes "4" and "2" in the round functions shown in the first and second embodiments are merely examples, and any number such as "5", "8", or "13" can be used. The ratios of nonlinear functions to logical operations shown in embodiments 1 and 2, such as "1:1", "1:3", and "3:1", are merely examples, and any ratio, such as "1:9" or "4:5", may be used.

[0045] As described above, according to the present invention, it is possible to construct a stream cipher and an authenticated cipher that can be customized to meet performance requirements. Furthermore, according to the present invention, performance, power consumption, and safety can be tuned by adjusting the number of parallel processes in the round function and the ratio of nonlinear functions to logical operations. Furthermore, when the AES round function is used as a nonlinear function, high-speed processing can be expected using AES hardware instructions.

[0046] This invention makes it possible to provide an encryption device that can be customized to meet the requirements of smartphones and PCs that perform "ultra-high speed and large capacity" communications, and IoT devices that require minimal power consumption. This will enable us to contribute to Goal 9 of the United Nations' Sustainable Development Goals (SDGs), which is to "build resilient infrastructure, promote inclusive and sustainable industrialization, and foster innovation." [Explanation of symbols]

[0047] 100 Encryption device 200 Initialization processing section 300 Encryption processing unit 400 Related Data Processing Unit 500 Authentication tag generation processing unit 600 Internal state before update 700 Internal state after update 900 Encryption device

Claims

1. an initialization processing unit including a round function and mixing an internal state; an encryption processing unit including a round function, which shuffles an internal state and generates a ciphertext by calculating an exclusive OR of a keystream extracted from the shuffled internal state and a plaintext; An encryption device comprising: An encryption device that customizes the round functions based on configuration specification data.

2. The encryption device according to claim 1 , wherein the configuration designation data designates the number of parallel processes in the round function.

3. The encryption device according to claim 1 , wherein the configuration designation data designates a ratio of a nonlinear function to a logical operation in the round function.

4. an authentication tag generation processing unit provided downstream of the encryption processing unit; the round function has an external input; 4. The encryption device according to claim 1, wherein the authentication tag generation processing unit generates an authentication tag by inputting plain text as the external input to the encryption processing unit.

5. An initialization processing step in which an initialization processing unit mixes an internal state using a round function; an encryption processing step in which the encryption processing unit shuffles an internal state using a round function and generates a ciphertext by calculating an exclusive OR of a keystream extracted from the shuffled internal state and a plaintext; An encryption method comprising: An encryption method that customizes the round functions based on configuration-specific data.

6. An encryption program for causing a computer to function as the encryption device according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Encryption device and encryption method

    JP1997251267A

  • Ciphering method and decoding method and ciphering device and decoding device

    JP1998232606A

  • Encryption processing device, encryption processing method, and computer program

    JP2005134477A