Key issuing device, information processing system, method, and program
A distributed key generation system secures ID-based proxy re-encryption by distributing the master private key among multiple devices, preventing decryption by a malicious key issuing authority and ensuring secure re-encryption.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2022-06-30
- Publication Date
- 2026-04-28
AI Technical Summary
In ID-based proxy re-encryption, a malicious key issuing authority can decrypt all ciphertexts using the master private key, posing a security risk.
Implement a distributed key generation system where the master private key is distributed among multiple key issuing devices, generating a distributed user private key using secret sharing and random numbers, ensuring the user private key is distributed and secured across devices, and using re-encryption keys to change decryption destinations without direct access to plaintext.
Prevents decryption of ciphertext by a malicious key issuing authority, enhancing security in ID-based proxy re-encryption systems.
Smart Images

Figure 0007852717000044 
Figure 0007852717000045 
Figure 0007852717000046
Abstract
Description
[Technical Field]
[0001] This disclosure relates to a key issuing device, an information processing system, a method, and program Regarding. [Background technology]
[0002] In encryption technology, ID-based encryption (IBE) and proxy re-encryption (PRE) are known. In relation to these technologies, Non-Patent Document 1 discloses the technology of an Identity-Based Proxy Re-Encryption (IB-PRE) scheme. Non-Patent Documents 2 and 3 disclose technologies related to ID-based encryption. Non-Patent Documents 4 and 5 disclose technologies related to this disclosure. [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] Chunpeng Ge1, Jinyue Xia and Liming Fang, "Key-Private Identity-Based Proxy Re-Encryption", Computers, Materials & Continua 63.2 (2020): 633-647. [Non-Patent Document 2] Martin Geisler and Nigel P. Smart, "Distributing the Key Distribution Center in Sakai-Kasahara Based Systems", IMA International Conference on Cryptography and Coding. Springer, Berlin, Heidelberg, 2009. [Non-Patent Document 3] Aniket Kate, and Ian Goldberg, "Distributed Private-Key Generators for Identity-Based Cryptography," Cryptology ePrint Archive, 2009, URL: https: / / eprint.iacr.org / 2009 / 355.pdf [Non-Patent Document 4] Rosario Gennaro, Michael O. Rabin, and Tal Rabin, "Simplified VSS and Fast-track Multiparty Computations with Applications to Threshold Cryptography," Proceedings of the seventeenth annual ACM symposium on Principles of distributed computing. 1998., URL: https: / / dl.acm.org / doi / 10.1145 / 277697.277716 [Non-Patent Document 5] Yoshinori Aono, et al., "Key-Private Proxy Re-encryption under LWE", International Conference on Cryptology in India. Springer, Cham, 2013 [Overview of the Initiative] [Problems that the invention aims to solve]
[0004] In ID-based proxy re-encryption, a key issuing authority issues a master public key and a master private key. In ID-based proxy re-encryption, the user's private key can be generated using the master private key and the user's ID. The user's ID is often publicly known. Therefore, anyone who obtains the master private key can easily generate the user's private key. Consequently, in the technology described in Non-Patent Document 1, if the key issuing authority is malicious, there is a risk that all ciphertext in the system could be decrypted using the master private key.
[0005] The purpose of this disclosure is to solve these problems and to provide a key issuing device, system, method, and program that can prevent the decryption of ciphertext by a key issuing authority even if the key issuing authority is malicious in ID-based proxy re-encryption technology. [Means for solving the problem]
[0006] The key issuing device according to this disclosure includes: distributed master key generation means for generating at least a distributed master private key distributed among multiple key issuing devices; distributed user private key generation means for generating a distributed user private key in which the user's user private key is distributed, and the user private key is obtained using the distributed user private key obtained from the multiple key issuing devices, and transmission means for transmitting the distributed user private key to the user's user device, wherein the distributed master key generation means has a share of a first random number in a distributed state and Based on the second random number, which is kept secret, and the share of the second random number in a distributed state, the distributed master secret key is generated. The distributed user secret key generation means obtains the share of the third random number, which is kept secret and becomes an element of the user secret key, and the share of the fourth random number, which is kept secret and becomes an element of the user secret key, and multiplies each of the share of the first random number, which is an element of the distributed master secret key, the share of the second random number, which is an element of the distributed master secret key, and the share of the third random number by the share of the fourth random number, and generates the distributed user secret key based on the product obtained as a result of the multiplication.
[0007] Furthermore, the information processing system relating to this disclosure comprises a plurality of key issuing devices, a plurality of user devices, and a re-encryption device, each of the plurality of key issuing devices comprising: distributed master key generation means for generating at least a distributed master private key distributed among the plurality of key issuing devices; and using the distributed master private key and user identification information, generates a distributed user private key in which the user's private key is distributed, and the user private key is obtained using the distributed user private key obtained from the plurality of key issuing devices. The distributed master key generation means comprises a distributed user private key generation means and a transmission means for transmitting the distributed user private key to the user's user device, wherein the distributed master key generation means generates the distributed master private key based on the shares of the first random number in a distributed state of a first random number that is kept secret and the shares of the second random number in a distributed state of a second random number that is kept secret, and the distributed user private key generation means generates the distributed master private key based on the shares of the third random number in a distributed state of a third random number that is kept secret and becomes an element of the user private key and the shares of the fourth random number in a distributed state of a fourth random number that is kept secret The share of the first random number, which is an element of the distributed master secret key, the share of the second random number, which is an element of the distributed master secret key, and the share of the third random number are each multiplied by the share of the fourth random number, and the distributed user secret key is generated based on the product obtained as a result of the multiplication. Each of the plurality of user devices has a user secret key generation means for generating the user secret key using the distributed user secret key obtained from the plurality of key issuing devices, a re-encryption key generation means for generating a re-encryption key using the user secret key, and a decryption means for decrypting the ciphertext to obtain the plaintext. The re-encryption device uses the re-encryption key to make the ciphertext decryptable by the first user device of the plurality of user devices decryptable by the second user device of the plurality of user devices, and re-encrypts the ciphertext decryptable with the user secret key relating to the first user device without decrypting it. The decryption means of the second user device decrypts the re-encrypted ciphertext using the user secret key relating to the second user device.
[0008] Furthermore, the key issuance method relating to this disclosure generates at least a distributed master private key distributed to multiple key issuing devices based on the share of a first random number in a distributed state of a first random number that is kept secret and the share of a second random number in a distributed state of a second random number that is kept secret, and generates a distributed user private key that is in a distributed state of the user's user private key, and the user private key is obtained using the distributed user private key obtained from the multiple key issuing devices, and At that time, the share of the third random number in a distributed state, which is a third random number that is kept secret and becomes an element of the user's private key, and the share of the fourth random number in a distributed state, which is a fourth random number that is kept secret, are obtained, and the share of the first random number, which is an element of the distributed master private key, the share of the second random number, which is an element of the distributed master private key, and the share of the third random number are each multiplied by the share of the fourth random number, and the distributed user private key is generated based on the product obtained from the multiplication, and the distributed user private key is transmitted to the user's device.
[0009] Furthermore, the information processing method relating to this disclosure generates at least a distributed master private key distributed among multiple key issuing devices based on the share of a first random number in a distributed state where a first random number that is kept secret is kept secret, and the share of a second random number in a distributed state where a second random number that is kept secret is kept secret, using each of the multiple key issuing devices; generates a distributed user private key in a distributed state where the user's user private key is kept secret, using the distributed master private key and the user's identification information, and in doing so, obtains the share of a third random number in a distributed state where a third random number that is kept secret and becomes an element of the user private key is kept secret, and obtains the share of the first random number that is an element of the distributed master private key and the elements of the distributed master private key The share of the second random number and the share of the third random number are each multiplied by the share of the fourth random number, and the distributed user secret key is generated based on the product obtained as a result of the multiplication, the distributed user secret key is transmitted to the user's user device, the user device generates a user secret key using the distributed user secret key obtained from a plurality of key issuing devices, generates a re-encryption key using the user secret key, decrypts the ciphertext to obtain the plaintext, the re-encryption device re-encrypts the ciphertext that can be decrypted with the user secret key relating to the first user device without decrypting it, using the re-encryption key to make the ciphertext that can be decrypted with the first user device decryptable with the second user device, and the second user device decrypts the re-encrypted ciphertext using the user secret key relating to the second user device.
[0010] Furthermore, the program relating to this disclosure includes the steps of generating at least a distributed master private key distributed to multiple key issuing devices based on the share of a first random number in a distributed state of a first random number that is kept secret and the share of a second random number in a distributed state of a second random number that is kept secret, and generating a distributed user private key that is a distributed user private key of the user, where the user private key is obtained using the distributed user private key obtained from the multiple key issuing devices, and in doing so, the confidential The computer is instructed to perform the following steps: obtain the share of the third random number in a distributed state, which is an element of the user's private key, and the share of the fourth random number in a distributed state, which is a confidential fourth random number; multiply each of the shares of the first random number, which is an element of the distributed master private key, the share of the second random number, which is an element of the distributed master private key, and the share of the third random number by the share of the fourth random number; generate the distributed user private key based on the product obtained from the multiplication; and transmit the distributed user private key to the user's device. [Effects of the Invention]
[0011] According to this disclosure, we can provide a key issuing device, system, method, and program that can prevent the decryption of ciphertext by a key issuing authority even if the key issuing authority is acting maliciously in an ID-based agent re-encryption technology. [Brief explanation of the drawing]
[0012] [Figure 1] This is a diagram to explain general public-key cryptography. [Figure 2] This is a diagram to explain ID-based cryptography. [Figure 3] This is a diagram illustrating general agent re-encryption. [Figure 4] This diagram illustrates ID-based agent re-encryption. [Figure 5] This is a diagram showing the configuration of the information processing system according to Embodiment 1. [Figure 6] This diagram shows the configuration of the key issuing device according to Embodiment 1. [Figure 7] This diagram shows the configuration of the user device according to Embodiment 1. [Figure 8] This diagram shows the configuration of the re-encryption device according to Embodiment 1. [Figure 9] This flowchart shows the processes performed by the information processing system according to Embodiment 1. [Figure 10] This flowchart shows the processes performed by the information processing system according to Embodiment 1. [Figure 11] This flowchart shows the processes performed by the information processing system according to Embodiment 1. [Figure 12] This flowchart shows the processes performed by the information processing system according to Embodiment 1. [Figure 13] This diagram shows the configuration of the key issuing device according to Embodiment 2. [Figure 14] This block diagram schematically shows examples of hardware configurations for computing processing units that can implement the devices and systems according to each embodiment. [Modes for carrying out the invention]
[0013] (Summary of this embodiment) Prior to describing this embodiment, an overview of this embodiment will be provided. While this embodiment will be described below, the following embodiments do not limit the invention as defined in the claims. Furthermore, not all combinations of features described in the embodiments are necessarily essential to the solution of the invention. Also, the indices (letters, etc.) used in the following description are not necessarily common throughout this specification.
[0014] Figures 1-4 are diagrams illustrating ID-based proxy re-encryption. Figure 1 is a diagram illustrating general public-key cryptography. The ciphertext creator possesses the public keys of users A-C. The ciphertext creator creates ciphertext Ca using user A's public key, ciphertext Cb using user B's public key, and ciphertext Cc using user C's public key. User A possesses user A's private key. User A can decrypt ciphertext Ca using user A's private key. Also, user B possesses user B's private key. User B can decrypt ciphertext Cb using user B's private key. User C possesses user C's private key. User C can decrypt ciphertext Cc using user C's private key.
[0015] Figure 2 is a diagram illustrating ID-based encryption (IBE). In ID-based encryption, the key issuing authority generates a master public key and a master private key. The key issuing authority then embeds each user's ID (actually a hash value of the ID, etc.) into the master private key to obtain the private keys for users A to C. The user's ID (Identification) could be, for example, the user's email address. The key issuing authority distributes the user private keys for users A to C, respectively. The key issuing authority also distributes the master public key to the ciphertext creator. The ciphertext creator can then embed their user ID into the acquired master public key to obtain the public keys for users A to C.
[0016] The ciphertext creator creates ciphertext Ca using user A's public key, ciphertext Cb using user B's public key, and ciphertext Cc using user C's public key, similar to the case in Figure 1. User A then decrypts ciphertext Ca using user A's private key, which was generated from the master private key by the key issuing authority. User B decrypts ciphertext Cb using user B's private key, which was generated from the master private key. User C decrypts ciphertext Cc using user C's private key, which was generated from the master private key by the key issuing authority. ID-based encryption offers the following advantages compared to the public-key encryption in Figure 1: An arbitrary string (such as an email address) can be embedded as a user ID in the user key (public and private key) or ciphertext. Furthermore, ciphertext can be created in advance for users who do not exist in the system (such as non-existent user D in the example in Figure 2). Additionally, a public key certificate, which was required in Figure 1, is unnecessary.
[0017] Figure 3 is a diagram illustrating typical proxy re-encryption (PRE). Proxy re-encryption is a technology that allows the decryption destination to be changed while the information remains encrypted, such as on a server in a cloud environment. Specifically, it can generate a conversion key (re-encryption key) necessary for re-encryption using the public key of the user at the destination (the converted and decrypted destination) and the private key of the user at the source. In the example in Figure 3, user A (source) uses user A's private key and the public keys of users B-D (destinations) to generate conversion key K A→B ,K A→C ,K A→D Generates the conversion key K. A→B ,K A→C ,K A→D This is the key (re-encryption key) used to convert the ciphertext Ca, which can be decrypted with user A's private key, into ciphertexts Cb, Cc, and Cd, which can be decrypted with the private keys of users B, C, and D, respectively.
[0018] User A sends each conversion key to the agent. The agent corresponds to, for example, a proxy server or a gateway server. The agent re-encrypts the ciphertext, for example, when the network environment to which the ciphertext is to be disclosed changes. The agent re-encrypts the ciphertext Ca that can be decrypted with the secret key of User A using each conversion key without decrypting the ciphertext Ca. As a result, the ciphertext Ca is converted into a ciphertext Cb that can be decrypted with the secret key of User B using the conversion key K A→B Similarly, the ciphertext Ca is converted into a ciphertext Cc, Cd that can be decrypted with the secret keys of User C and User D using the conversion keys K A→C , K A→D respectively. Users B to D can decrypt the ciphertexts Cb, Cc, Cd with their own secret keys respectively. If User A does not want to disclose the ciphertext Ca to User D, User A does not need to generate the conversion key K A→D . As a result, the ciphertext Ca remains concealed from User D.
[0019] FIG. 4 is a diagram for explaining identity-based proxy re-encryption (IB-PRE). Identity-based proxy re-encryption performs proxy re-encryption based on identities. Similar to the case of FIG. 2, the key issuing authority generates a master public key and a master secret key. Then, the key issuing authority obtains the secret keys of Users A to D respectively by embedding the ID of each user in the master secret key. Also, in the example of FIG. 4, the key issuing authority distributes the master public key to User A. User A generates a conversion key (re-encryption key) using the master public key and the original secret key. That is, User A obtains the public keys of Users B to D using the IDs of Users B to D. Then, similar to the case of FIG. 3, User A generates the conversion keys K A→B , K A→C , K A→D using the secret key of User A and the public keys of Users B to D.
[0020] Similar to Figure 3, user A sends each transformation key to the agent. The agent re-encrypts the ciphertext Ca, which can be decrypted with user A's private key, using each transformation key without decrypting ciphertext Ca. As a result, ciphertext Ca is converted into ciphertexts Cb, Cc, and Cd. Similar to Figure 3, users B through D can each decrypt ciphertexts Cb, Cc, and Cd using their own private keys.
[0021] As mentioned above, Non-Patent Document 1 discloses a technology for ID-based agent re-encryption. The technology described in Non-Patent Document 1 achieves key privacy, meaning that no information about the target ID is leaked from the conversion key. Furthermore, Non-Patent Document 1 implements a re-encryption function for the so-called exponent-inversion type IBE, one of the three classifications of elliptic curve-based IBEs. It should be noted that while the Kasahara-Sakai scheme is an example of an exponent-inversion type IBE, the scheme used as the basis in Non-Patent Document 1 is not the Kasahara-Sakai scheme. Specifically, the Kasahara-Sakai scheme uses asymmetric pairing and the q-BDHI (Bilinear Diffie-Hellman Inversion) assumption, while Non-Patent Document 1 uses symmetric pairing and the q-DDHE (Decisional Diffie-Hellman Exponent) assumption.
[0022] Also, as a technique for suppressing the leakage of a private key, there is DKG (Distributed Key Generation). Non-Patent Document 2 and Non-Patent Document 3 propose DKG for the Kasahara-Sakai method. Here, Non-Patent Document 2 and Non-Patent Document 3 are techniques related to ID-based cryptography (IBE), and are not techniques related to ID-based proxy re-encryption (IB-PRE). Therefore, the format of the private key according to Non-Patent Document 2 and Non-Patent Document 3 is different from the format of the private key related to IB-PRE as in Non-Patent Document 1. Therefore, it is extremely difficult to simply combine the technique related to Non-Patent Document 1 with the techniques related to Non-Patent Document 2 and Non-Patent Document 3. In contrast, as will be described below, in the present embodiment, DKG is realized in ID-based proxy re-encryption. Therefore, in the present embodiment, even when the key issuing authority has malicious intent in the technique of ID-based proxy re-encryption, it is possible to suppress the decryption of the ciphertext by the key issuing authority.
[0023] (Principle applied in the present embodiment) Here, the principle applied in the present embodiment will be described. In the present embodiment, in realizing DKG, multi-party computation (MPC: Multiparty Computation) based on secret sharing is used. Also, as a method of secret sharing, Shamir's secret sharing scheme (SSS) is used. Note that these are merely examples, and the method of realizing DKG is not limited to the above.
[0024] Shamir's secret sharing scheme is a type of (t, n) threshold secret sharing. Here, n is the total number of participants P i and t (< n) is the threshold value. By distributing the secret information to each of the participants P i each participant obtains a share (dispersed value). Then, when any t or more shares are gathered, the secret can be restored.
[0025] Let f be a polynomial of degree (t-1) over a prime number p, where f(0) = s. Here, f is a polynomial subject to polynomial completion. Also, s ∈ Z. p This is a value that you want to keep secret (secret value). Note that Z p This is the set of values from 0 to p-1. Also, participant P i The share of s for (i=1,···,n) is [s] i Let =f(i). Also, the share of s is given by [s]=([s]1,···,[s] n This is written as ). Here, [s] can also be said to represent the state in which the secret value s is distributed among all participants. Also, [s] i This is the number of participants P when the secret value s is distributed. i This shows the value (variance) that s possesses. For the sake of explanation, in the following explanation, share [s] will be referred to as the variance [s] that s is distributed among the participants. i ,···[s] n It is sometimes used when showing things without distinction.
[0026] Here, c, c1, c2 ∈ Z p In this case, the following equations hold. These can be calculated without communication between participants. Linearity (addition of shares): [c1a+c2b]=c1[a]+c2[b] ·Constant times: [ca]=c[a] Constant addition: [c+a]=c+[a] For example, participant P j Focusing solely on the operation of [ca], the above constant multiplication formula is [ca] j =c[a] j It is written as follows.
[0027] In Shamir's secret sharing scheme, the distribution of the secret value is carried out as follows: The input dealer (one of the participants P) randomly selects a polynomial f for the secret value s, and participant P i ni [s] i Send (=f(i)). This distributes s to each participant.
[0028] Furthermore, in Shamir's secret sharing scheme, the secret value is recovered as follows: the reconstructing party is each participant P. i from [s] i The reconstructing party receives t values. Then, using polynomial completion, the reconstructing party recovers the secret value s using equation (1) below.
number
[0029] Here, .'' i This is the Lagrange coefficient, and is expressed by the following equation (2).
number
[0030] The share of the (t,n) threshold secret sharing scheme is represented by [s], and the share of the (t',n') threshold secret sharing scheme is represented by equation (3) below.
number
[0031] For the sake of notation, equation (3) will be denoted as "[[s]]". In this case, participant P i is, λ i [s] i Keep it a secret, [[λ i [s] i It may also be redistributed as ]]. And Σ[[λ i [s] i You may change the threshold and the number of participants from t,n to t',n', respectively. Note that this can be achieved under the assumption that the old shares before the change are safely deleted.
[0032] Furthermore, in the multi-party calculation in this embodiment, the "Share()" function of SSS is used as the function for distributing the secret value. That is, the distribution of a is performed as shown in equation (4) below. Note that i is participant P, who is the input dealer. i It corresponds to the subscript (index). Also, 'a' is a secret value.
number
[0033] Furthermore, the "Open()" function of SSS is used as the function for recovering the secret value. In other words, a is recovered as shown in equation (5) below.
number
[0034] Furthermore, in this embodiment, the function "Mult()" is used to perform multiplication of shares. That is, the share of secret value a [a] and the share of secret value b [b] are multiplied as shown in equation (6) below.
number
[0035] Mult() can be implemented in various ways. For example, Mult() may be implemented using the method shown in Non-Patent Document 4. Note that implementing Mult() requires communication between participants. Furthermore, Mult() may be implemented in the following steps, but is not limited to these steps.
[0036] Step A1: Participant P i (for i=1,···,n) is given by the following equation (7) c i Calculate c i Distribute it, c i Share [c i Calculate ]. Then, participant P i is share [ci ](=[c i ]1,···,[c i ] n Send this to other participants.
number
[0037] Step A2: By calculating the following equation (8), we obtain [c], which is the result of multiplying [a] and [b].
number
[0038] Note [a] i =f(i), [b] i = g(i). Also, f and g are polynomials of degree (t-1). Let f(i)g(i)=h(i). In this case, h is a polynomial of degree (2t-2). Also, since f(0)=a and g(0)=b, h(0)=ab. Therefore, equation (8) above holds.
[0039] Furthermore, this embodiment uses pairing (bilinear mapping). In this embodiment, calculations are performed under the pairing conditions described below. G,G T Let g and g be multiplicative cyclic groups of order p (where p is a sufficiently large prime number). Then g ∈ G is a generator of G. g is, for example, a rational point on an elliptic curve, but is not limited to that. G is, for example, a set constructed of generators that are rational points on an elliptic curve, but is not limited to that. Also, G T This could be, for example, the set of elements of an extension, but is not limited to this.
[0040] Also, the bilinear map e: G × G → G T It satisfies the following properties. ·Bilinearity: e(g1 a ,g2 b )=e(g1,g2)ab However, a and b are Z p * It is an arbitrary value randomly selected from the given set. Also, g1, g2 ∈ G. Also, Z p * This is the set of values from 1 to p-1. ·Non-degenerate: e(g,g)≠1 • Computational efficiency: For any g1, g2 ∈ G, there exists an efficient algorithm (polynomial-time algorithm) for calculating e(g1, g2). Note that e(g1,g2) is a multiplicative cyclic group G of order p. T It is an element (original).
[0041] Here, we will briefly explain the general idea of using pairing when constructing an encryption scheme. For example, as a public key, g t ,e(g,g) st Let's assume there is a master private key s. In this case, g t ,e(g,g) st Note that t and st cannot be calculated from this. In this case, the ciphertext creator is m·e(g,g) st Then, create an ciphertext of the plaintext m.
[0042] Here, the key issuing authority cannot directly pass s to the user in order to prevent the leakage of the master private key, but the user cannot decrypt the ciphertext without passing some value related to s. Therefore, the key issuing authority can, for example, use g as the private key. s A value in the format of this is passed to the user. At this time, g s Please note that it is not possible to calculate s from this.
[0043] The user is g s Since s cannot be calculated from this, m·e(g,g) st It appears that m cannot be decrypted from. However, the user can use the public key g through pairing. t and private key g s Using this, even when t and s are unknown, e(g t ,g s)=e(g,g) st It is possible to calculate g. That is, by using pairing, x ,g y Even if x and y cannot be calculated from e(g,g) xy You can perform operations like xy in the exponent part.
[0044] (Embodiment 1) The embodiments will be described below with reference to the drawings. For clarity of explanation, the following descriptions and drawings have been omitted and simplified as appropriate. In addition, the same elements are denoted by the same reference numerals in each drawing, and redundant explanations have been omitted where necessary.
[0045] Figure 5 shows the configuration of an information processing system 50 according to Embodiment 1. The information processing system 50 includes a plurality of key issuing devices 100-1 to 100-n (where n is an integer of 2 or more), an encryption device 60, a plurality of user devices 200, and a re-encryption device 300. The key issuing devices 100, encryption devices 60, user devices 200, and re-encryption device 300 are connected to each other so as to be able to communicate via wired or wireless connections.
[0046] Each component of the information processing system 50 can be implemented by, for example, a computer. The information processing system 50 implements DKG in IB-PRE using the above-mentioned components. More details will be provided later. The information processing system 50 can also function as a key generation system (key issuance system) that generates public and private keys.
[0047] The key issuing device 100 may be managed by the key issuing authority described above. The key issuing device 100-i (i=1,···,n) is a participant P in the secret sharing described above. iThis corresponds to the above. The key issuing device 100 is configured to generate at least a distributed master secret key and to generate a distributed user secret key in a distributed state using the distributed master secret key and the user's identification information. The key issuing device 100 then transmits the distributed user secret key to the user's user device. Here, the distributed master secret key can also be said to be a master secret key in a virtually distributed state. Note that in this embodiment, the master secret key is not actually generated. Furthermore, the distributed master secret key is distributed among multiple key issuing devices 100 and includes elements for generating the distributed user secret key. Furthermore, the distributed user secret key is distributed among multiple key issuing devices 100, and the system is configured to obtain the user secret key using the distributed user secret key obtained from multiple key issuing devices 100. More details will be described later.
[0048] The encryption device 60 is configured to create ciphertext. Specifically, the encryption device 60 encrypts plaintext m to create ciphertext C. The encryption device 60 may be integrated with the user device 200. In this case, for example, user A's user device 200A may function as the encryption device 60.
[0049] The user devices 200 can be managed by the users described above. In the example in Figure 5, user devices 200A to 200D can be managed by users A to D, respectively. Although Figure 5 shows four user devices 200, the number of user devices 200 is arbitrary. Each user device 200 is configured to generate a user private key for the user managing the user device 200 using the distributed user private key obtained from multiple key issuing devices 100. The user device 200 is also configured to generate a re-encryption key (transformation key) using the user private key. Furthermore, the user device 200 is configured to decrypt the ciphertext and obtain the plaintext using the user private key related to the user device 200. More details will be described later.
[0050] The re-encryption device 300 may be managed by the agent described above. The re-encryption device 300 may consist of, for example, the proxy server or gateway server described above. The re-encryption device 300 is configured to re-encrypt ciphertext that can be decrypted with the user secret key relating to the first user device of the multiple user devices 200 without decrypting it, using a re-encryption key. In other words, the re-encryption device 300 uses the re-encryption key to convert ciphertext that can be decrypted with the user secret key relating to the first user device into ciphertext that can be decrypted with the user secret key relating to the second user device. In this case, this re-encryption key is a conversion key that makes ciphertext decryptable on the first user device decryptable on the second user device of the multiple user devices 200. At this time, the second user device decrypts the re-encrypted ciphertext using the user secret key relating to the second user device. More details will be described later.
[0051] For example, in the example in Figure 4, user A's user device 200A is designated as the first user device, and user B's user device 200B is designated as the second user device. In this case, the re-encryption device 300 uses the re-encryption key K. A→B The ciphertext Ca is converted (re-encrypted) to ciphertext Cb using the method described. User device 200B decrypts the re-encrypted ciphertext Cb using user B's private key.
[0052] Figure 6 shows the configuration of the key issuing device 100 according to Embodiment 1. The key issuing device 100 has as its components a random number generation unit 102, a distribution unit 104, a random number share acquisition unit 106, a share multiplication unit 108, a restoration unit 110, and a share storage unit 112. The key issuing device 100 also has as its components a distributed master key generation unit 120, a master public key generation unit 130, a distributed user private key generation unit 140, and a transmission unit 150. The random number generation unit 102 may be configured as a subroutine called from the distributed master key generation unit 120, the master public key generation unit 130, and the distributed user private key generation unit 140. Similarly, the distribution unit 104, the random number share acquisition unit 106, the share multiplication unit 108, the restoration unit 110, and the share storage unit 112 may be configured as subroutines called from the distributed master key generation unit 120, the master public key generation unit 130, and the distributed user private key generation unit 140.
[0053] The random number generation unit 102 functions as a random number generation means. The distribution unit 104 functions as a distribution means. The random number share acquisition unit 106 functions as a random number share acquisition means. The share multiplication unit 108 functions as a share multiplication means. The restoration unit 110 functions as a restoration means. The distributed master key generation unit 120 functions as a distributed master key generation means. The master public key generation unit 130 functions as a master public key generation means. The distributed user private key generation unit 140 functions as a distributed user private key generation means. The transmission unit 150 functions as a transmission means.
[0054] The random number generation unit 102 is configured to generate random numbers. The random number generation unit 102 also generates random number elements that will be kept secret. The distribution unit 104 is configured to perform secret sharing on the random numbers (random number elements). The distribution unit 104 may, for example, perform secret sharing using the function shown in equation (4) above to obtain the share (distribution value) of the random number elements. The distribution unit 104 transmits the obtained share (distribution value) of the random number elements to the other key issuing device 100.
[0055] The random number share acquisition unit 106 is configured to acquire the share of a random number using the shares of multiple random number elements received from multiple key issuing devices 100. The random number share acquisition unit 106 may acquire the share of a random number by summing the shares (variance values) of multiple random number elements received from multiple key issuing devices 100. The share multiplication unit 108 is configured to multiply shares together. The share multiplication unit 108 may multiply shares together using, for example, the function shown in equation (6) above. The restoration unit 110 restores the share of a certain value (secret value) and acquires that value. The restoration unit 110 may perform the restoration using, for example, the function shown in equation (5) above. The share storage unit 112 stores the shares (variance values) acquired in the process of calculations related to shares. The share storage unit 112 stores the shares (variance values) acquired in the processing of S120 to S140 described later. The share storage unit 112 may temporarily store the shares (variance values).
[0056] The distributed master key generation unit 120 is configured to generate at least a distributed master private key that is distributed among multiple key issuing devices 100. The distributed master key generation unit 120 may also generate a distributed master public key that is distributed among multiple key issuing devices 100. Details will be described later. The master public key generation unit 130 is configured to generate a master public key. Details will be described later. The distributed user private key generation unit 140 is configured to generate a distributed user private key using the distributed master private key and user identification information. Details will be described later. The transmission unit 150 is configured to transmit the distributed user private key to the user device 200 of the user corresponding to the above identification information.
[0057] Figure 7 shows the configuration of the user device 200 according to Embodiment 1. The user device 200 includes a user private key generation unit 210, a user private key storage unit 220, a re-encryption key generation unit 230, and a decryption unit 240. The user private key generation unit 210 functions as a means for generating user private keys. The user private key storage unit 220 functions as a means for storing user private keys. The re-encryption key generation unit 230 functions as a means for generating re-encryption keys. The decryption unit 240 functions as a means for decryption.
[0058] The user private key generation unit 210 is configured to generate a user private key for a user who manages the user device 200 using distributed user private keys obtained from multiple key issuing devices 100. Further details will be described later. The user private key storage unit 220 is configured to store the generated user private key.
[0059] The re-encryption key generation unit 230 is configured to generate a re-encryption key using the user's private key. For example, the re-encryption key generation unit 230 of user device 200A uses user A's private key K A Using the re-encryption key (transformation key) K A→B ,K A→C ,K A→D This generates the ciphertext. More details will be provided later. The decryption unit 240 is configured to decrypt the ciphertext and obtain the plaintext using the user's secret key related to the user device 200. More details will be provided later.
[0060] Figure 8 shows the configuration of the re-encryption device 300 according to Embodiment 1. The re-encryption device 300 includes a re-encryption key storage unit 310, a ciphertext storage unit 320, and a re-encryption unit 330. The re-encryption key storage unit 310 functions as a re-encryption key storage means. The ciphertext storage unit 320 functions as a ciphertext storage means. The re-encryption unit 330 functions as a re-encryption means.
[0061] The re-encryption key storage unit 310 stores the re-encryption key generated by the user device 200. The ciphertext storage unit 320 stores the ciphertext generated by the encryption device 60. The re-encryption unit 330 is configured to re-encrypt, without decrypting, the ciphertext that can be decrypted with the user secret key related to the first user device among the plurality of user devices 200 using the re-encryption key. That is, the re-encryption unit 330 uses the re-encryption key to convert (re-encrypt) the ciphertext that can be decrypted with the user secret key related to the first user device into the ciphertext that can be decrypted with the user secret key related to the second user device. Details will be described later.
[0062] FIGS. 9 to 12 are flowcharts showing the processes executed by the information processing system 50 according to the first embodiment. FIG. 9 shows the information processing method (key issuance method, key generation method) executed by the information processing system 50. Also, in FIG. 9, S120 to S160 show the key issuance method (key generation method) realized by the key issuance device 100.
[0063] The information processing system 50 sets a global parameter gparam (step S102). In S102, the information processing system 50 performs "Global Setup". The global parameter gparam can be made public within the information processing system 50. Note that the setting of the global parameter may be performed by any of the key issuance devices 100, or may be performed by a device (not shown) managed by a standardization institution.
[0064] Specifically, the information processing system 50 sets a global parameter gparam = (p, G, e, g, H) using a security parameter λ. Here, p is a prime number. G is a multiplicative cyclic group of order p. e is a bilinear mapping, e: G×G→G T where. g is a generator of G, g∈G. H is a hash function, H: G T →Z pThat is, in Non-Patent Document 1, h which is an element (source) of G was set as a global parameter (public parameter), but in the present embodiment, h is not made public. This is because if h is made public, there is a possibility that the plaintext may be obtained from the ciphertext by an attacker.
[0065] Each of the plurality of key issuing apparatuses 100 generates a distributed master key (step S120). In S120, the key issuing apparatus 100 performs "Distribute Setup". As will be described later, the key issuing apparatus 100-i (i = 1, ···, n) uses the global parameter gparam to generate a distributed master key (mpk i , msk i ). Here, mpk i is the distributed master public key. Also, msk i is the distributed master secret key. That is, the distributed master key (mpk i , msk i ) is a pair of the distributed master public key mpk i and the distributed master secret key msk i .
[0066] By each of the plurality of key issuing apparatuses 100-1 to 100-n generating a distributed master key, a set of distributed master keys {(mpk i , msk i )} = {(mpk1, msk1), ···, (mpk n , msk n )} is generated. That is, the distributed master public keys mpk1 to mpk n are in a state of being distributed to the plurality of key issuing apparatuses 100. Similarly, the distributed master secret keys msk1 to msk n are in a state of being distributed to the plurality of key issuing apparatuses 100. The plurality of key issuing apparatuses 100-1 to 100-n cooperate to generate the distributed master key {(mpk i , msk i ).
[0067] Figure 10 is a flowchart showing the process at S120 in Figure 9. Figure 10 shows the process of the distributed master key generation unit 120 according to Embodiment 1. In the following description, the process of the distributed master key generation unit 120 of the key issuing device 100-i is described, but the same process is performed for other key issuing devices 100. In other words, the same process is performed for key issuing devices 100-i (i=1,...,n). This is also true for other processes.
[0068] The distributed master key generation unit 120 generates random number elements (step S122). In other words, the distributed master key generation unit 120 of the key issuing device 100-i generates random number elements α i ,β i This generates the distributed master key generation unit 120 may perform the processing in S122 using the random number generation unit 102 described above. Here, α i ,β i ∈Z p It is. Also, the random number element α i (The first random number element) becomes an element of random number α (the first random number). Also, random number element β i The (second random number element) becomes an element of the random number β (second random number). Note that the values of the random numbers α and β are kept secret from each key issuing device 100, that is, they are not known to each key issuing device 100.
[0069] The distributed master key generation unit 120 secretly shares the random number element (step S124). In other words, the distributed master key generation unit 120 of the key issuing device 100-i secretly shares the random number element α i ,β i The distributed master key generation unit 120 may perform the processing in S124 using the distribution unit 104 described above. The distributed master key generation unit 120 generates a random number element α i ,β i A secret sharing operation is performed on the result, and the random number element α obtained through the secret sharing is then generated. i Share [α] i ] (variance value) and random number element β i Share [β] i The `(dispersion value)` is transmitted to the other key issuing device 100.
[0070] Specifically, the distributed master key generation unit 120 of the key issuing device 100-i generates a random number element α according to the following equation (9). i Share [α] i Generates the variance value.
number
[0071] Similarly, the distributed master key generation unit 120 of the key issuing device 100-i generates random number elements β according to the following equation (10). i Share [β] i Generates the variance value.
number
[0072] Then, the distributed master key generation unit 120 of the key issuing device 100-i generates the share [α i ] (variance value) and share [β i The variance value [α] is transmitted to the other key issuing device 100. Specifically, the distributed master key generation unit 120 of key issuing device 100-i transmits the variance value [α] to key issuing device 100-j (j=1,···,n). i ] j and [β i ] j This sends [α i ]=([α i ]1,···,[α i ] n ) and [β i ]=([β i ]1,···,[β i ] n The state of ) is generated. The same process is also performed in the other key issuing devices 100. Therefore, the key issuing device 100-i receives [α1] from multiple key issuing devices 100. i ,···,[α n ] i , and [β1] i ,···,[β n ] i Obtain it.
[0073] The distributed master key generation unit 120 obtains the shares [α] and [β] (variance values) of random numbers α and β (step S126). The distributed master key generation unit 120 may perform the processing in S126 using the random number share acquisition unit 106 described above. The distributed master key generation unit 120 obtains the share [α] (variance value) of random number α (first random number) using the shares (variance values) of the first random number elements obtained from the multiple key issuing devices 100. Similarly, the distributed master key generation unit 120 obtains the share [β] (variance value) of random number β (second random number) using the shares (variance values) of the second random number elements obtained from the multiple key issuing devices 100.
[0074] Specifically, the distributed master key generation unit 120 sums the shares (variance values) of the first random number elements obtained from multiple key issuing devices 100 to obtain the share [α] (variance value) of the random number α (first random number). Similarly, the distributed master key generation unit 120 sums the shares (variance values) of the second random number elements obtained from multiple key issuing devices 100 to obtain the share [β] (variance value) of the random number β (second random number).
[0075] In other words, the distributed master key generation unit 120 generates shares [α] and [β] (dispersion values) respectively using the following equations (11) and (12).
number
number
[0076] Focusing on the key issuing device 100-i, the distributed master key generation unit 120 generates random number elements α from multiple key issuing devices 100. j The variance of (j=1,···,n) [α j ] i The sum of these gives the variance (share) of the random number α [α]. i The distributed master key generation unit 120 obtains the distribution value [α] by the following equation (13). iGenerates.
number
[0077] Similarly, the distributed master key generation unit 120 generates random number elements β obtained from multiple key issuing devices 100. j The variance of (j=1,···,n) [β j ] i The sum of these gives the variance (share) of the random number β [β]. i The distributed master key generation unit 120 obtains the variance value [β] by the following equation (14). i Generates.
number
[0078] The distributed master key generation unit 120 generates a distributed master key (step S128). Specifically, the distributed master key generation unit 120 generates a distributed master key based on the acquired shares [α], [β] (dispersion value). The distributed master key generation unit 120 of the key issuing device 100-i generates a distributed master key based on the acquired shares [α], [β] (dispersion value [α] i ,[β] i Based on ), distributed master key (mpk) i ,msk i The distributed master key generation unit 120 generates a distributed master public key that is distributed among multiple key issuing devices 100, based on the share [α] (variance value) of the first random number α and the share [β] (variance value) of the second random number β. The distributed master key generation unit 120 also generates a distributed master private key that is distributed, based on the share [α] (variance value) of the first random number α in its distributed state and the share [β] (variance value) of the second random number β in its distributed state.
[0079] More specifically, the distributed master key generation unit 120 of the key issuing device 100-i generates the distributed master public key mpk according to the following equation (15): i Generates.
number
[0080] Furthermore, the distributed master key generation unit 120 of the key issuing device 100-i generates the distributed master secret key msk according to the following equation (16): i Generates.
number
[0081] The processing of the distributed master key generation unit 120 described above makes it possible to achieve a state in which the random numbers α and β are distributed among multiple key issuing devices 100-1 to 100-n without informing any of the key issuing devices 100 (key issuing authorities) of the values of the random numbers α and β. In other words, as in the example in Figure 4, if the key is not generated in a distributed manner, it is sufficient for a single key issuing authority (key issuing device) to generate the random numbers α and β. In contrast, when the key is generated in a distributed manner, in order to achieve the objective of suppressing the leakage of the private key, none of the key issuing devices 100 (key issuing authorities) should know the random numbers α and β. Therefore, in the processing of S122, each key issuing device 100-i (i=1,···,n) is the random number element α i ,β i Generates a random number element α in the processing of S124. i ,β i The random numbers α and β are secretly shared. Then, through the process in S126, each key issuing device 100-i generates a share [α], [β] (dispersion value) of the random numbers α and β. Through this process, a state in which the random numbers α and β are distributed can be achieved without any key issuing device 100 (key issuing authority) knowing the values of the random numbers α and β. Then, with the random numbers α and β kept secret from any key issuing device 100 (key issuing authority), each key issuing device 100 can generate a distributed master key using the share (dispersion value) of the random numbers α and β.
[0082] Returning to the explanation of Figure 9, the master public key generation unit 130 of each of the multiple key issuing devices 100 generates a master public key (step S130). In S130, the key issuing device 100 performs "Distribute PKG (Public Key Generation)". As described above, in the process of S120, the multiple key issuing devices 100-1 to 100-n generate a set of distributed master public keys {mpk i}={mpk1,···,mpk n The following is generated: The key issuing device 100-i (i=1,···,n) has global parameters gparam and a set of distributed master public keys {mpk i The master public key (mpk) is generated using}. In other words, the master public key generation unit 130 generates a master public key based on the distributed master public keys obtained from multiple key issuing devices 100-1 to 100-n.
[0083] Figure 11 is a flowchart showing the process of S130 in Figure 9. Figure 11 shows the process of the master public key generation unit 130 according to Embodiment 1. The master public key generation unit 130 transmits the distributed master public key (step S132). Specifically, the master public key generation unit 130 of the key issuing device 100-i (i=1,···,n) transmits the distributed master public key mpk shown in equation (15) above. i This is transmitted (broadcast) to all key issuing devices 100. The master public key generation unit 130 may also transmit the distributed master public key to devices that require the master public key (encryption device 60, user device 200, or key issuing device 100).
[0084] The master public key generation unit 130 generates a master public key (step S134). Specifically, the master public key generation unit 130 generates a distributed master public key {mpk} obtained from multiple key issuing devices 100. i}={mpk1,···,mpk n}={(g^([α] i ),e(g,g)^([β] iUsing ))}, the master public key is generated. At this time, as will be described later, the master public key generation unit 130 uses the function shown in equation (5) above to restore shares [α] and [β], thereby generating the master public key mpk=(g α ,e(g,g) β The master public key generation unit 130 may perform the processing in S134 using the restoration unit 110 described above.
[0085] More specifically, the master public key generation unit 130 generates the master public key mpk using the following equations (17) and (18). Note that the same master public key can be generated in each key issuing device 100 through this process. In this way, by restoring the exponents of powers of g and powers of e(g,g), any key issuing device 100 (key issuing authority) can generate the master public key mpk = (g α ,e(g,g) β ) may be generated.
number
number
[0086] Furthermore, the master public key generation unit 130 generates all n {[α]} from all key issuing devices 100-1 to 100-n. i}={[α]1,···,[α] n It is not necessary to obtain} and perform the calculation shown in equation (17). The master public key generation unit 130 generates t or more [α] i By obtaining the (variance value of α), g α It can generate all n {[β] from all key issuing devices 100-1 to 100-n. Similarly, the master public key generation unit 130 can generate all n {[β] i}={[β]1,···,[β] n It is not necessary to obtain} and perform the calculation shown in equation (18). The master public key generation unit 130 generates t or more [β] iBy obtaining the (variance value of β), e(g,g) β It can generate [this].
[0087] In this embodiment, the parameter h disclosed in Non-Patent Document 1 is set to h=g β We consider this to be the case. In this case, from the bilinearity of the pairing described above, the following equation (19) holds.
number
[0088] As described above, in the technology of Non-Patent Document 1, the above h is disclosed. That is, in the technology of Non-Patent Document 1, (g, g1, h, H) is disclosed as a disclosed parameter. Note that g1 = g α Please note that this is the case. On the other hand, in this embodiment, instead of h, e(g,h) (=e(g,g) β ) is made public. In other words, in this embodiment, (g, g1, e(g, h), H) is made public as a public parameter. Therefore, in this embodiment, h is not made public, so attacks from attackers as described above can be suppressed. Note that if e(g, h) = e(g, g), then h = g, so h will be made public. Therefore, in this case, the processing flow returns to the processing of S120, and the processing is executed again from S120.
[0089] Returning to the explanation of Figure 9, the distributed user private key generation unit 140 of each of the multiple key issuing devices 100 generates a distributed user private key (step S140). In S140, the key issuing device 100 performs "Distribute KeyGen (Key Generation)". As described above, in the process of S120, the set of distributed master private keys {msk} is generated by the multiple key issuing devices 100-1 to 100-n. i}={msk1,···,msk n The following is generated. The key issuing device 100-i (i=1,···,n) has global parameters gparam and a set of distributed master secret keys {msk iUsing the user ID, which is the user's identification information, a distributed user secret key is generated in which the user secret key of the user corresponding to the identification information ID is distributed.
[0090] In other words, the distributed user secret key generation unit 140 generates the distributed master secret key {msk} obtained from multiple key issuing devices 100-1 to 100-n. i Based on the user's identification ID, the distributed user secret key (dk) ID,i Multiple key issuing devices 100-1 to 100-n each generate a distributed user secret key, thereby creating a set of distributed user secret keys called {dk ID,i}={dk ID,1 ,···,dk ID,n This generates a distributed user private key (dk). ID,1 ,···,dk ID,n The keys are distributed across multiple key issuing devices 100. Note that the identification information ID is, for example, an email address, so the user's identification information ID may be made public.
[0091] Figure 12 is a flowchart showing the process of S140 in Figure 9. Figure 12 shows the process of the distributed user private key generation unit 140 according to Embodiment 1. The distributed user private key generation unit 140 generates random number elements (step S142). That is, the distributed user private key generation unit 140 of the key issuing device 100-i generates random number elements r ID,i ,w i This generates the distributed user secret key generation unit 140 may perform the processing in S142 using the random number generation unit 102 described above. Here, r ID,i ,w i ∈Z p It is. Also, the random number element r ID,i (The third random element) is random number r ID It becomes an element of (the third random number). Also, random number element w i (The fourth random number element) becomes an element of random number w (the fourth random number). Note that random number r ID Please note that the value of w is kept secret from each key issuing device 100, that is, it is kept unknown to each key issuing device 100.
[0092] The distributed user secret key generation unit 140 secretly shares the random number element (step S144). In other words, the distributed user secret key generation unit 140 of the key issuing device 100-i secretly shares the random number element r ID,i ,w i The distributed user secret key generation unit 140 may perform the processing in S144 using the distribution unit 104 described above. The distributed user secret key generation unit 140 generates a random number element r ID,i ,w i A secret sharing operation is performed on the result, and the random number element r obtained through the secret sharing is then generated. ID,i Share [r ID,i ](variance value) and random number element w i Share [w i The `(dispersion value)` is transmitted to the other key issuing device 100.
[0093] Specifically, the distributed user secret key generation unit 140 of the key issuing device 100-i generates a random number element r according to the following equation (20). ID,i Share [r ID,i Generates the variance value.
number
[0094] Similarly, the distributed user secret key generation unit 140 of the key issuing device 100-i generates a random number element w according to the following equation (21). i Share [w i Generates the variance value.
number
[0095] Then, the distributed user secret key generation unit 140 of the key issuing device 100-i generates the share [r ID,i ](variance value) and share[w i The variance value [r ID,i ]j and [w i ] j This sends [r ID,i ]=([r ID,i ]1,···,[er ID,i ] n ) and [w i ]=([w i ]1,···,[w i ] n The state of ) is generated. The same process is also performed in the other key issuing devices 100. Therefore, the key issuing device 100-i receives [r ID,1 ] i ,···,[r ID,n ] i , and [w1] i ,···,[w n ] i Obtain it.
[0096] The distributed user secret key generation unit 140 generates a random number r ID ,w's share[r ID The distributed user secret key generation unit 140 obtains the variance value ],[w] (step S146). The distributed user secret key generation unit 140 may perform the processing in S146 using the random number share acquisition unit 106 described above. The distributed user secret key generation unit 140 uses the share (variance value) of the third random number element obtained from the multiple key issuing devices 100 to generate a random number r ID (Third random number) share [r ID The `[w](variance value)` is obtained. Similarly, the distributed user secret key generation unit 140 obtains the share [w](variance value) of the random number w (fourth random number) using the share (variance value) of the fourth random number element obtained from the multiple key issuing devices 100.
[0097] Specifically, the distributed user secret key generation unit 140 sums the shares (variance values) of the third random number elements obtained from multiple key issuing devices 100 to generate a random number r ID (Third random number) share [r IDThe `[w](variance value)` is obtained. Similarly, the distributed user secret key generation unit 140 sums the shares (variance values) of the fourth random number element obtained from multiple key issuing devices 100 to obtain the share [w](variance value) of the random number w (fourth random number).
[0098] In other words, the distributed user secret key generation unit 140 generates the share [r ID Generates ],[w] (variance value).
number
number
[0099] Focusing on the key issuing device 100-i, the distributed user secret key generation unit 140 generates random number elements r obtained from multiple key issuing devices 100. ID,j The variance of (j=1,···,n)[r ID,j ] i Summing these together, a random number r ID The variance (share) of [r ID ] i The distributed user secret key generation unit 140 obtains the distributed value [r ID ] i Generates.
number
[0100] Similarly, the distributed user secret key generation unit 140 generates random number elements w obtained from multiple key issuing devices 100. j The variance of (j=1,···,n) [w j ] i The sum of these gives the variance (share) of the random number w [w]. i The distributed user secret key generation unit 140 obtains the distributed value [w] by the following equation (25). i Generates.
number
[0101] The distributed user private key generation unit 140 performs share multiplication (step S148). The distributed user private key generation unit 140 may perform the process in S148 using the share multiplication unit 108 described above. The distributed user private key generation unit 140 performs [β]-[r ID For each of ] and [α]-ID, [w] is multiplied. In other words, the distributed user secret key generation unit 140 multiplies the share of α (first random number) [α], the share of β (second random number) [β], and r ID (Third random number) share [r ID For each of ], multiply by the share [w] of w (the fourth random number). Here, [α] and [β] are the distributed master secret key msk i It is an element of the distributed user secret key generation unit 140. i The elements are the share of α[α] and the distributed master private key msk. i The share of β, which is an element of [β], and r ID Share [r ID For each of ], multiply by the share of w[w].
[0102] Specifically, the distributed user secret key generation unit 140 performs multiplication according to the following equations (26) and (27) in parallel. Thus, in this embodiment, multiple multiplications of shares are performed. As mentioned above, when Mult() is executed, communication takes place between the multiple key issuing devices 100.
number
number
[0103] As shown in equation (26) above, [β]-[r ID By multiplying ] and [w], the product [(β-[r ID])·w] (the second product) is obtained. According to equation (26) above, β-r ID (that is, β and r ID ) is masked (concealed) by w. Also, as shown in equation (27) above, the product [(α-ID)·w] (the first product) is obtained by multiplying [α]-ID and [w]. According to equation (27) above, α-ID (i.e., α) is masked (concealed) by w. Note that, as will be described later, β-r ID and α-ID (i.e., α, β, and r ID ) will be an element of the user's private key.
[0104] The distributed user secret key generation unit 140 reconstructs [(α-ID)·w] and calculates the inverse of the reconstruction result, 1 / (α-ID)·w (step S150). The distributed user secret key generation unit 140 may also perform the processing in S150 using the reconstruction unit 110 described above. The distributed user secret key generation unit 140 reconstructs the first product [(α-ID)·w] obtained by multiplying the elements of the user secret key (α-ID) obtained from the share of random number w [w] by the share of random number w. This gives the value of (α-ID)·w. The distributed user secret key generation unit 140 also calculates the inverse v (first value) of the value (α-ID)·w obtained as a result of the reconstruction.
[0105] Specifically, the distributed user secret key generation unit 140 recovers [(α-ID)·w] using the following formula (28) and obtains the value of (α-ID)·w.
number
[0106] Furthermore, the distributed user secret key generation unit 140 calculates the inverse element v of (α-ID)·w using the following equation (29). Note that if (α-ID)·w=0, the process in S140 is executed again from S142.
number
[0107] Note that even if the value of (α-ID)·w is obtained as in equation (28), the value of α is also kept secret because w is kept secret. Therefore, the inverse element v of the value (α-ID)·w is obtained while α and w remain secret.
[0108] The distributed user secret key generation unit 140 generates a distributed user secret key (step S152). As shown below, the distributed user secret key generation unit 140 generates a distributed user secret key based on the product obtained from the multiplication of equations (26) to (27). As will be described later, the distributed user secret key generation unit 140 generates the distributed user secret key in such a way that the share (variance value) of the random number w is removed when the user secret key is obtained using the distributed user secret keys obtained from multiple key issuing devices 100.
[0109] Specifically, the distributed user secret key generation unit 140 of the key issuing device 100-i generates the elements h of the distributed user secret key shown in the following equation (30) from equations (26) and (29) above. ID,i The distributed user secret key generation unit 140 calculates g to the power of g^([(β-r ID )·w] i (g^([(β-r ID )·w] i ))^v to h ID,i It is calculated as follows. In other words, the distributed user secret key generation unit 140 calculates the first power of g g^([(β-r ID )·w] i The second power of (g^([(β-r ID )·w] i ))^v to h ID,i The calculation is performed as follows: Here, the exponent of the first power of g (first power) is the product obtained from the multiplication in equation (26) [(β-r ID )·w] i This corresponds to the (second product).
number
[0110] Then, the distributed user secret key generation unit 140 of the key issuance device 100-i generates a distributed user secret key dk represented by the following formula (31). ID,i to generate. [Number] ···(31)
[0111] Here, the distributed user secret key dk ID,i is a pair of [r ID i and h ID,i That is, the distributed user secret key generation unit 140 generates a pair of the share (distributed value) of the random number r ID and the first data as the distributed user secret key. Here, the first data is the product (second product) obtained by multiplying the share of the random number w by the elements of the user secret key obtained by the share of the random number β and the share of the random number r ID , and v (first value).
[0112] Returning to the description of FIG. 9. The transmission unit 150 of each of the plurality of key issuance devices 100 transmits the distributed user secret key to the user device 200 (step S160). Specifically, the transmission unit 150 of the key issuance device 100-i transmits the distributed user secret key dk ID,i to the user device 200 of the user corresponding to the identification information ID. Thereby, the user device 200 corresponding to the identification information ID acquires the distributed user secret key dk ID,i (i = 1, ···, n) from the plurality of key issuance devices 100-1 to 100-n.
[0113] The user device 200 generates a user secret key (step S162). Specifically, the user secret key generation unit 210 of the user device 200 corresponding to the identification information ID uses the plurality of distributed user secret keys dk ID,i to obtain the user secret key dk ID =(r ID ,h ID Generate it. The user secret key generation unit 210 may perform the process of S162 by a function substantially the same as the restoration unit 110 described above. The user secret key generated by the user secret key generation unit 210 is stored in the user secret key storage unit 220.
[0114] More specifically, the user secret key generation unit 210 generates r by the following formula (32) ID Generate.
Number
[0115] Also, the user secret key generation unit 210 generates h by the following formula (33). Note that, as described above, note that h = g ID Generate. β It is.
Number
[0116] Note that the user secret key generation unit 210 does not need to obtain all n {dk ID,i} = {dk ID,1 , ···, dk ID,n} from all the key issuing devices 100-1 to 100-n and perform the calculations shown in formula (32) and formula (33). That is, the user secret key generation unit 210 can generate r ID i by obtaining t or more [r ID . Similarly, the user secret key generation unit 210 can generate h ID,i by obtaining t or more h ID .
[0117] Also, comparing formula (30) and formula (33), it can be seen that the random number w is removed in the process of the user secret key generation unit 210 in the user device 200. That is, h ID,iBy adopting the form shown in equation (30), the random number w is removed. Therefore, it can be said that the distributed user secret key generation unit 140 generates distributed user secret keys in such a way that the share of the random number w is removed when a user secret key is obtained using the distributed user secret keys obtained from multiple key issuing devices 100. In this way, the random number w that is not an element of the user secret key is removed.
[0118] Furthermore, as is the case in Non-Patent Document 1, the user secret key in IB-PRE is dk ID =(r ID ,h ID As shown above, it is in the form of a pair of two values. In this way, because the user secret key is in the form of a pair, the ciphertext can be re-encrypted. However, in Non-Patent Documents 2 and 3, which disclose technology related to IBE, the user secret key is in the form of a single value. Therefore, the format of the user secret key is different between IB-PRE and IBE. Consequently, as mentioned above, it is extremely difficult to simply combine the technology related to Non-Patent Document 1 with the technologies related to Non-Patent Documents 2 and 3.
[0119] Furthermore, the key issuing device 100 according to Embodiment 1, with the configuration described above, issues a user private key and elements of the user private key (random number α, random number β, and random number r ID This allows the user's private key to be generated without being known to any of the key issuing devices 100. Therefore, the configuration according to Embodiment 1 makes it possible to suppress the decryption of the ciphertext by the key issuing authority even if the key issuing authority is malicious in the ID-based agent re-encryption technology.
[0120] The encryption device 60 creates a ciphertext (step S170). The encryption device 60 may create a ciphertext from plaintext in substantially the same manner as the method described in Non-Patent Literature 1. The ciphertext created by the encryption device 60 is stored in the ciphertext storage unit 320 of the re-encryption device 300. The encryption device 60 creates a ciphertext C from plaintext m using the following formula (34). IDThis generates a ciphertext that can be decrypted with the user's private key associated with the ID. Note that the master public key (mpk) and the identification information ID may be used to generate a public key for the user corresponding to the ID.
number
[0121] Furthermore, when generating ciphertext that can be decrypted with the user's secret key of user i (i=A,B,C,D), the encryption device 60 converts the plaintext m into ciphertext C_(ID) using the following formula (35). i ) will be generated. Note that ID i This is the identification information of user i.
number
[0122] The re-encryption key generation unit 230 of the user device 200 generates a re-encryption key (step S174). The re-encryption key generation unit 230 generates a re-encryption key using the user's private key. The re-encryption key generation unit 230 may generate the re-encryption key in substantially the same manner as the method described in Non-Patent Document 1.
[0123] The re-encryption key generation unit 230 generates the re-encryption key rk_(ID) using the following formula (36). i →ID j This generates ). Note that dk_(ID i ) is the user's private key for user i. Also, ID j This is the identification information of user j (i≠j, j=A,B,C,D). Therefore, the re-encryption key rk_(ID i →ID j ) is a re-encryption key used to make a ciphertext that can be decrypted on the first user device (user i's user device 200) decryptable on the second user device (user j's user device 200).
number
[0124] The re-encryption unit 330 of the re-encryption device 300 performs re-encryption on the ciphertext stored in the ciphertext storage unit 320 (step S176). The re-encryption unit 330 re-encrypts the ciphertext that can be decrypted with the user secret key related to the first user device among the plurality of user devices 200, without decrypting it, using the re-encryption key stored in the re-encryption key storage unit 310. The re-encryption unit 330 may perform re-encryption in substantially the same manner as the method of Non-Patent Document 1. The re-encrypted ciphertext may be stored in the ciphertext storage unit 320.
[0125] The re-encryption unit 330 performs re-encryption according to the following formula (37). That is, the re-encryption unit 330 uses the re-encryption key to convert the ciphertext that can be decrypted with the user secret key related to the first user device (the user device 200 of user i) into the ciphertext that can be decrypted with the user secret key related to the second user device (the user device 200 of user j).
Number
[0126] The decryption unit 240 of the user device 200 decrypts the ciphertext to obtain the plaintext (step S180). The decryption unit 240 decrypts the ciphertext using the user secret key of the corresponding user. The decryption unit 240 may decrypt the ciphertext in substantially the same manner as the method of Non-Patent Document 1.
[0127] When decrypting the ciphertext created in the process of S170, the decryption unit 240 decrypts according to the following formula (38) to obtain the plaintext m. At this time, in formula (38), ID corresponds to the identification information ID of user i i corresponding to.
Number
[0128] On the other hand, when decrypting the ciphertext that has been re-encrypted in the S176 process, the decryption unit 240 decrypts it using the following equation (39) to obtain the plaintext m. In this case, in equation (39), ID is the identification information ID of user j. j This corresponds to the second user device's decryption unit 240, which decrypts the re-encrypted ciphertext using the user's secret key related to the second user device.
number
[0129] <Note> Please note that simply redistributing the master key share when adding or removing key issuing devices 100 (key issuing authorities) presents problems. This is because, as shown below, it is difficult to simply change the initially set value of t (number of fraudsters).
[0130] For example, suppose there are three key issuing devices 100 (n=3), and we allow unauthorized access to up to one key issuing device 100 (t=1). In this case, since "n / 2 > t" holds true, there are no problems such as the leakage of user private keys, and the system operates.
[0131] In this case, suppose we add two more key issuing devices 100, resulting in n=5. At this point, we cannot simply assume that "it is sufficient if n / 2 > t" and set t=2, thereby allowing fraudulent activity by up to two key issuing devices 100. This is because, if we preserve the original share of the secret value before its redistribution, two of the three key issuing devices 100 can cooperate to obtain random numbers α, etc., which are elements of the master secret key. As a result, in this embodiment, a master secret key that is not generated by the key issuing device 100 can be obtained.
[0132] Therefore, if you want to update n along with a change in t, it is necessary not only to appropriately delete the random numbers before the update, but also to reset the random numbers α, change the re-encryption key in the re-encryption device, and update the ciphertext. The public and private keys are renewed by resetting the random numbers α, etc. Regarding the change of the re-encryption key, the re-encryption key may be changed by the user device 200 or by multi-party computation in the key issuing device 100. Furthermore, the update of the ciphertext may be performed without the involvement of the user device 200, which is capable of decrypting the ciphertext.
[0133] Furthermore, the maliciously secure method described in Non-Patent Document 3 terminates the protocol if fraud is detected. However, a robustness-based method is needed that always operates correctly even if fraud occurs. In response to this, the shares of each participant (key issuing device 100) in the SSS may be made into a replicating secret sharing scheme, and a majority vote may be taken during multiplication. In this way, by having each participant (key issuing device 100) replicate and hold a share, it is secure even against attackers who attempt to tamper with the calculation results.
[0134] Furthermore, regarding CCA (Chosen Ciphertext Attack) security, for example, by referring to Non-Patent Document 5, a system that achieves CCA security can be constructed by using the Fujisaki-Okamoto transformation. That is, by applying the Fujisaki-Okamoto transformation to the encryption system (S170) according to this embodiment, CCA security can be achieved.
[0135] (Embodiment 2) Next, Embodiment 2 will be described. Embodiment 2 shows an overview of the configuration according to the embodiment described above. Note that the information processing system 50 according to Embodiment 2 is substantially the same as that according to Embodiment 1, so its description will be omitted. In other words, the information processing system 50 according to Embodiment 2 has a plurality of key issuing devices.
[0136] Figure 13 shows the configuration of the key issuing device 10 according to Embodiment 2. The key issuing device 10 according to Embodiment 2 corresponds to the key issuing device 100 according to Embodiment 1. The key issuing device 10 according to Embodiment 2 includes a distributed master key generation unit 12, a distributed user private key generation unit 14, and a transmission unit 16. The distributed master key generation unit 12 functions as a distributed master key generation means. The distributed user private key generation unit 14 functions as a distributed user private key generation means. The transmission unit 16 functions as a transmission means.
[0137] The distributed master key generation unit 12 corresponds to the distributed master key generation unit 120 according to Embodiment 1. The distributed master key generation unit 12 can be implemented with substantially the same functions as the distributed master key generation unit 120. The distributed master key generation unit 12 generates at least a distributed master secret key that is distributed among multiple key issuing devices 10. The distributed master key generation unit 12 generates a distributed master secret key based on the share ([α]) of the first random number (α) that is distributed among the first random number (α) that is to be kept secret, and the share ([β]) of the second random number (β) that is distributed among the second random number (β) that is to be kept secret.
[0138] The distributed user private key generation unit 14 corresponds to the distributed user private key generation unit 140 according to Embodiment 1. The distributed user private key generation unit 14 can be implemented with substantially the same functions as the distributed user private key generation unit 140. The distributed user private key generation unit 14 generates a distributed user private key using the distributed master private key and the user's identification information. Here, the user private key is obtained using the distributed user private key obtained from multiple key issuing devices. The distributed user private key generation unit 14 generates a third random number (r) which is kept secret and becomes an element of the user private key. ID The share of the third random number in a distributed state ([r IDThe distributed user secret key generation unit 14 obtains the share of the fourth random number ([w]) in the distributed state, where the confidential fourth random number (w) is distributed. The distributed user secret key generation unit 14 multiplies the share of the first random number, the share of the second random number, and the share of the third random number, each of which are elements of the distributed master secret key, by the share of the fourth random number. The distributed user secret key generation unit 14 generates a distributed user secret key based on the product obtained as a result of the multiplication.
[0139] The transmission unit 16 transmits the distributed user secret key to the user's user device 200. As described above, the user device 200 can generate a user secret key using the multiple distributed user secret keys obtained from the multiple key issuing devices 10.
[0140] The key issuing device 10 according to Embodiment 2, with the configuration described above, can generate a user private key without the user private key and its elements (first random number, second random number, and third random number) being known to any other key issuing device 10. Therefore, even if the key issuing authority is malicious in the ID-based agent re-encryption technology, it is possible to suppress the decryption of the ciphertext by the key issuing authority. This is also true for the information processing system 50 having multiple key issuing devices 10, the key issuing method executed by the key issuing device 10, and the program that implements the key issuing method.
[0141] (Example hardware configuration) The following describes an example of hardware resource configurations for realizing the devices and systems according to each of the above embodiments using a single computing device (information processing device, computer). However, each device according to the embodiment (key issuing device, encryption device, user device, re-encryption device, etc.) may be realized using at least two computing devices, either physically or functionally. Furthermore, each device according to the embodiment may be realized as a dedicated device or as a general-purpose information processing device.
[0142] Figure 14 is a schematic block diagram showing an example of the hardware configuration of a computing device that can realize the device and system according to each embodiment. The computing device 1000 has a CPU 1001, a volatile storage device 1002, a disk 1003, a non-volatile recording medium 1004, and a communication IF 1007 (IF: Interface). Therefore, it can be said that the device according to each embodiment has a CPU 1001, a volatile storage device 1002, a disk 1003, a non-volatile recording medium 1004, and a communication IF 1007. The computing device 1000 may be connectable to an input device 1005 and an output device 1006. The computing device 1000 may also be equipped with an input device 1005 and an output device 1006. Furthermore, the computing device 1000 can send and receive information with other computing devices and communication devices via the communication IF 1007.
[0143] The non-volatile recording medium 1004 is a computer-readable medium, such as a Compact Disc or a Digital Versatile Disc. Alternatively, the non-volatile recording medium 1004 may be a USB (Universal Serial Bus) memory, a Solid State Drive, or the like. The non-volatile recording medium 1004 can hold the program without power supply, making it portable. Note that the non-volatile recording medium 1004 is not limited to the media described above. Furthermore, instead of the non-volatile recording medium 1004, the program may be supplied via the communication interface 1007 and a communication network.
[0144] The volatile memory device 1002 is computer-readable and can temporarily store data. The volatile memory device 1002 is a type of memory such as DRAM (dynamic random access memory) or SRAM (static random access memory).
[0145] In other words, when the CPU 1001 executes a software program (computer program; hereinafter simply referred to as "program") stored on disk 1003, it copies it to the volatile storage device 1002 and performs arithmetic processing. The CPU 1001 reads the data necessary for program execution from the volatile storage device 1002. If display is required, the CPU 1001 displays the output result on the output device 1006. When a program is input from an external source, the CPU 1001 obtains the program from the input device 1005. The CPU 1001 interprets and executes the program corresponding to the function (processing) of each component shown in Figures 6 to 8 and 13 above. The CPU 1001 executes the processing described in each embodiment above. In other words, the function of each component shown in Figures 6 to 8 and 13 above can be realized by the CPU 1001 executing a program stored on disk 1003 or the volatile storage device 1002.
[0146] In other words, each embodiment can be understood as being achievable by the program described above. Furthermore, each embodiment can also be understood as being achievable by a computer-readable non-volatile recording medium on which the program described above is recorded.
[0147] (modified version) It should be noted that the present invention is not limited to the embodiments described above, and can be modified as appropriate without departing from the spirit of the invention. For example, the order of each process (step) in the flowchart described above can be changed as appropriate. Also, one or more of the multiple processes (steps) may be omitted. For example, the process S102 in Figure 9 may be omitted. Also, the process S139 in Figure 9 may be omitted.
[0148] Furthermore, in the above-described embodiment, the distributed user secret key generation unit 140 is [β]-[r ID Although we have stated that we multiply [β] by [w], this configuration is not limited to this. As shown in equations (40) and (41) below, [β] and 0-[r ID You may also multiply ] by [w] separately.
number
number
[0149] In this case, the element h of the distributed user secret key ID,i This can be expressed by the following equation (42).
number
[0150] In this case, the user secret key generation unit 210 uses the following formula (43) to generate h ID Generates.
number
[0151] On the other hand, in the case of equations (40) to (43) above, the Mult() operation is performed one more time compared to the case of equations (26), (30), and (33) shown in Embodiment 1. Therefore, by performing the operation as in equation (26), etc., the number of Mult() operations can be suppressed, thereby improving the efficiency of the calculation. In other words, the first power of g g^([(β-r ID )·w] i The second power of (g^([(β-r ID )·w] i ))^v to h ID,i By performing calculations in this way, it becomes possible to improve the efficiency of the calculations.
[0152] In the examples described above, the program includes a set of instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more of the functions described in the embodiments. The program may be stored on a non-temporary computer-readable medium or a physical storage medium. Examples, but not limited to, include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disk (DVD), Blu-ray® disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may be transmitted over a temporary computer-readable medium or a communication medium. Examples, but not limited to, include temporary computer-readable medium or a communication medium that includes electrically, optically, acoustically or otherwise propagating signals.
[0153] Although the present invention has been described above with reference to embodiments, the present invention is not limited thereto. Various modifications to the structure and details of the present invention can be made that are understandable to those skilled in the art within the scope of the invention.
[0154] Some or all of the above embodiments may also be described as follows, but are not limited to the following: (Note 1) A key issuing device, A distributed master key generation means that generates at least one distributed master secret key that is distributed among multiple key issuing devices, A distributed user secret key generation means generates a distributed user secret key in which the user's user secret key is distributed using the distributed master secret key and user identification information, and the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. A transmission means for transmitting the distributed user secret key to the user's user device, It has, The distributed master key generation means generates the distributed master secret key based on the shares of the first random numbers in a distributed state, where the first random number to be kept secret is also kept secret, and the shares of the second random numbers in a distributed state, where the second random number to be kept secret is also kept secret. The distributed user secret key generation means is The third random number, which is concealed and becomes an element of the user's private key, is distributed, and the share of the fourth random number, which is concealed and becomes a distributed, is obtained. The share of the first random number, which is an element of the distributed master secret key, the share of the second random number, and the share of the third random number are each multiplied by the share of the fourth random number. Based on the product obtained from the multiplication, the distributed user secret key is generated. Key issuing device. (Note 2) The distributed user secret key generation means generates the distributed user secret key such that the share of the fourth random number is removed when the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. The key issuing device described in Appendix 1. (Note 3) The distributed user secret key generation means performs a reconstruction on the first product obtained by multiplying the elements of the user secret key obtained from the share of the first random number and the identification information by the share of the fourth random number, and generates the distributed user secret key using the first value which is the inverse of the value obtained as a result of the reconstruction. The key issuing device described in Appendix 2. (Note 4) The distributed user private key generation means generates the distributed user private key as a set of the third random number share, the second product obtained by multiplying the elements of the user private key obtained from the second random number share and the third random number share by the fourth random number share, and the first data whose elements are the first value. The key issuing device described in Appendix 3. (Note 5) The distributed user secret key generation means generates the first data as the second power of the first power of the generator of a predetermined multiplicative cycle group, with the first value as the exponent. The exponent of the first power corresponds to the product of the second, The key issuing device described in Appendix 4. (Note 6) The distributed master key generation means is A first random number element that will be an element of the first random number and a second random number element that will be an element of the second random number are generated. A secret sharing operation is performed on the first random number element and the second random number element, and the shares of the first random number element and the shares of the second random number element obtained by the secret sharing are transmitted to another key issuing device. The first random number share is obtained using the share of the first random number element obtained from the plurality of key issuing devices, and the second random number share is obtained using the share of the second random number element obtained from the plurality of key issuing devices. The key issuing device described in Appendix 1. (Note 7) The distributed user secret key generation means is A third random number element is generated, which is kept secret and becomes an element of the user's private key, and a fourth random number element is generated, which is kept secret and becomes an element of the fourth random number. A secret sharing operation is performed on the third random number element and the fourth random number element, and the shares of the third random number element and the shares of the fourth random number element obtained by the secret sharing are transmitted to another key issuing device. The third random number share is obtained using the share of the third random number element obtained from the plurality of key issuing devices, and the fourth random number share is obtained using the share of the fourth random number element obtained from the plurality of key issuing devices. The key issuing device described in Appendix 1. (Note 8) Master public key generation means for generating a master public key, It further possesses, The distributed master key generation means further generates a distributed master public key that is distributed among multiple key issuing devices based on the shares of the first random number and the shares of the second random number, The master public key generation means generates the master public key based on the distributed master public key obtained from the plurality of key issuing devices. The key issuing device described in Appendix 1. (Note 9) Multiple key issuing devices, Multiple user devices, A re-encryption device, It has, Each of the aforementioned multiple key issuing devices is: A distributed master key generation means that generates at least one distributed master secret key that is distributed among multiple key issuing devices, A distributed user secret key generation means generates a distributed user secret key in which the user's user secret key is distributed using the distributed master secret key and user identification information, and the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. A transmission means for transmitting the distributed user secret key to the user's user device, It has, The distributed master key generation means generates the distributed master secret key based on the shares of the first random numbers in a distributed state, where the first random number to be kept secret is also kept secret, and the shares of the second random numbers in a distributed state, where the second random number to be kept secret is also kept secret. The distributed user secret key generation means is The third random number, which is concealed and becomes an element of the user's private key, is distributed, and the share of the fourth random number, which is concealed and becomes a distributed, is obtained. The share of the first random number, which is an element of the distributed master secret key, the share of the second random number, and the share of the third random number are each multiplied by the share of the fourth random number. Based on the product obtained from the multiplication, the distributed user secret key is generated. Each of the aforementioned user devices is: A user secret key generation means that generates the user secret key using the distributed user secret keys obtained from multiple key issuing devices, A re-encryption key generation means that generates a re-encryption key using the user's private key, A decryption means for decrypting a ciphertext to obtain plaintext, It has, The re-encryption device uses the re-encryption key for which the ciphertext decryptable by the first user device of the plurality of user devices can be decrypted by the second user device of the plurality of user devices, to re-encrypt the ciphertext decryptable with the user secret key relating to the first user device without decrypting it. The decryption means of the second user device decrypts the re-encrypted ciphertext using the user secret key relating to the second user device. Information processing system. (Note 10) The distributed user private key generation means of the key issuing device generates the distributed user private key such that the share of the fourth random number is removed when the user private key is obtained using the distributed user private key obtained from multiple key issuing devices. The user secret key generation means of the user device generates the distributed user secret key such that the share of the fourth random number is removed. The information processing system described in Appendix 9. (Note 11) The distributed user private key generation means of the key issuing device performs reconstruction on the first product obtained by multiplying the elements of the user private key obtained from the share of the first random number and the identification information by the share of the fourth random number, and generates the distributed user private key using the first value which is the inverse of the value obtained as a result of the reconstruction. The information processing system described in Appendix 10. (Note 12) The distributed user private key generation means of the key issuing device generates the distributed user private key as a set of the third random number share, the second product obtained by multiplying the elements of the user private key obtained from the second random number share and the third random number share by the fourth random number share, and the first data whose elements are the first value. The user secret key generation means of the user device generates the user secret key by performing restoration on the share of the third random number and the product of the second random number, respectively. The information processing system described in Appendix 11. (Note 13) The distributed user private key generation means of the key issuing device generates the first data as the second power of the first power of the generator of a predetermined multiplicative cyclic group of orders, with the first value as the exponent. The exponent of the first power corresponds to the product of the second, The information processing system described in Appendix 12. (Note 14) The distributed master key generation means of the key issuing device is, A first random number element that will be an element of the first random number and a second random number element that will be an element of the second random number are generated. A secret sharing operation is performed on the first random number element and the second random number element, and the shares of the first random number element and the shares of the second random number element obtained by the secret sharing are transmitted to another key issuing device. The first random number share is obtained using the share of the first random number element obtained from the plurality of key issuing devices, and the second random number share is obtained using the share of the second random number element obtained from the plurality of key issuing devices. The information processing system described in Appendix 9. (Note 15) The distributed user private key generation means of the key issuing device is: A third random number element is generated, which is kept secret and becomes an element of the user's private key, and a fourth random number element is generated, which is kept secret and becomes an element of the fourth random number. A secret sharing operation is performed on the third random number element and the fourth random number element, and the shares of the third random number element and the shares of the fourth random number element obtained by the secret sharing are transmitted to another key issuing device. The third random number share is obtained using the share of the third random number element obtained from the plurality of key issuing devices, and the fourth random number share is obtained using the share of the fourth random number element obtained from the plurality of key issuing devices. The information processing system described in Appendix 9. (Note 16) The aforementioned key issuing device is Master public key generation means for generating a master public key, It further possesses, The distributed master key generation means of the key issuing device further generates a distributed master public key that is distributed among multiple key issuing devices based on the share of the first random number and the share of the second random number, The master public key generation means of the key issuing device generates the master public key based on the distributed master public keys obtained from the plurality of key issuing devices. The re-encryption key generation means of the user device generates a re-encryption key using the master public key and the user private key. The information processing system described in Appendix 9. (Note 17) Based on the shares of the first random number in a distributed state where the first confidential random number is kept secret, and the shares of the second random number in a distributed state where the second confidential random number is kept secret, at least a distributed master secret key is generated that is distributed among multiple key issuing devices. Using the distributed master private key and user identification information, a distributed user private key is generated in which the user's private key is distributed, and the user private key is obtained using the distributed user private key obtained from multiple key issuing devices. In doing so, the share of the third random number in the distributed state, which is a confidential element of the user private key, and the share of the fourth random number in the distributed state, which is a confidential element of the user private key, are obtained. The share of the first random number, which is an element of the distributed master private key, the share of the second random number, and the share of the third random number, which are elements of the distributed master private key, are each multiplied by the share of the fourth random number, and the distributed user private key is generated based on the product obtained from the multiplication. The distributed user secret key is transmitted to the user's device. How to issue a key. (Note 18) The distributed user secret key is generated such that the share of the fourth random number is removed when the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. The key issuance method is described in Appendix 17. (Note 19) The elements of the user secret key obtained by multiplying the share of the fourth random number by the share of the first random number and the identification information, and the first product obtained is restored, and the distributed user secret key is generated using the first value which is the inverse of the value obtained as a result of the restoration. The key issuance method is described in Appendix 18. (Note 20) The distributed user secret key is generated as a set of the third random number share, the second product obtained by multiplying the elements of the user secret key obtained from the second random number share and the third random number share by the fourth random number share, and the first data whose elements are the first value. The key issuance method is described in Appendix 19. (Note 21) The first power of the first power of the generator of a predetermined order multiplicative cyclic group, with the first value as the exponent, is generated as the first data. The exponent of the first power corresponds to the product of the second, The key issuance method is described in Appendix 20. (Note 22) A first random number element that will be an element of the first random number and a second random number element that will be an element of the second random number are generated. A secret sharing operation is performed on the first random number element and the second random number element, and the shares of the first random number element and the shares of the second random number element obtained by the secret sharing are transmitted to another key issuing device. The first random number share is obtained using the share of the first random number element obtained from the plurality of key issuing devices, and the second random number share is obtained using the share of the second random number element obtained from the plurality of key issuing devices. The key issuance method is described in Appendix 17. (Note 23) A third random number element is generated, which is kept secret and becomes an element of the user's private key, and a fourth random number element is generated, which is kept secret and becomes an element of the fourth random number. A secret sharing operation is performed on the third random number element and the fourth random number element, and the shares of the third random number element and the shares of the fourth random number element obtained by the secret sharing are transmitted to another key issuing device. The third random number share is obtained using the share of the third random number element obtained from the plurality of key issuing devices, and the fourth random number share is obtained using the share of the fourth random number element obtained from the plurality of key issuing devices. The key issuance method is described in Appendix 17. (Note 24) Based on the shares of the first random number and the shares of the second random number, a distributed master public key is further generated that is distributed among multiple key issuing devices. A master public key is generated based on the distributed master public keys obtained from the aforementioned multiple key issuing devices. The key issuance method is described in Appendix 17. (Note 25) Each of the multiple key issuing devices, Based on the shares of the first random number in a distributed state where the first confidential random number is kept secret, and the shares of the second random number in a distributed state where the second confidential random number is kept secret, at least a distributed master secret key is generated that is distributed among multiple key issuing devices. Using the distributed master private key and user identification information, a distributed user private key is generated in which the user's private key is distributed, and the user private key is obtained using the distributed user private key obtained from multiple key issuing devices. In doing so, the share of the third random number in the distributed state, which is a confidential element of the user private key, and the share of the fourth random number in the distributed state, which is a confidential element of the user private key, are obtained. The share of the first random number, which is an element of the distributed master private key, the share of the second random number, and the share of the third random number, which are elements of the distributed master private key, are each multiplied by the share of the fourth random number, and the distributed user private key is generated based on the product obtained from the multiplication. The distributed user secret key is transmitted to the user's device. The user device described above, The user secret key is generated using the distributed user secret keys obtained from multiple key issuing devices. A re-encryption key is generated using the aforementioned user private key. Decrypt the ciphertext to obtain the plaintext, The re-encryption device, using the re-encryption key for making the ciphertext decryptable on the first user device decryptable on the second user device, re-encrypts the ciphertext decryptable with the user secret key relating to the first user device without decrypting it. The second user device decrypts the re-encrypted ciphertext using the user secret key relating to the second user device. Information processing methods. (Note 26) The key issuing device generates the distributed user secret key such that the share of the fourth random number is removed when the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. The user device generates the distributed user secret key such that the share of the fourth random number is removed. The information processing method described in Appendix 25. (Note 27) The key issuing device performs a reconstruction on the first product obtained by multiplying the elements of the user secret key obtained from the share of the first random number and the identification information by the share of the fourth random number, and uses the first value, which is the inverse of the value obtained as a result of the reconstruction, to generate the distributed user secret key. The information processing method described in Appendix 26. (Note 28) The key issuing device generates the distributed user secret key as a set of the third random number share, the second product obtained by multiplying the elements of the user secret key obtained from the second random number share and the third random number share by the fourth random number share, and the first data whose elements are the first value. The user device generates the user secret key by performing restoration on the share of the third random number and the product of the second random number, respectively. The information processing method described in Appendix 27. (Note 29) The key issuing device generates the first data, which is the first power of the first power of the generator of a predetermined multiplicative cyclic group, with the first value as the exponent. The exponent of the first power corresponds to the product of the second, The information processing method described in Appendix 28. (Note 30) The aforementioned key issuing device, A first random number element that will be an element of the first random number and a second random number element that will be an element of the second random number are generated. A secret sharing operation is performed on the first random number element and the second random number element, and the shares of the first random number element and the shares of the second random number element obtained by the secret sharing are transmitted to another key issuing device. The first random number share is obtained using the share of the first random number element obtained from the plurality of key issuing devices, and the second random number share is obtained using the share of the second random number element obtained from the plurality of key issuing devices. The information processing method described in Appendix 25. (Note 31) The aforementioned key issuing device, A third random number element is generated, which is kept secret and becomes an element of the user's private key, and a fourth random number element is generated, which is kept secret and becomes an element of the fourth random number. A secret sharing operation is performed on the third random number element and the fourth random number element, and the shares of the third random number element and the shares of the fourth random number element obtained by the secret sharing are transmitted to another key issuing device. The third random number share is obtained using the share of the third random number element obtained from the plurality of key issuing devices, and the fourth random number share is obtained using the share of the fourth random number element obtained from the plurality of key issuing devices. The information processing method described in Appendix 25. (Note 32) The aforementioned key issuing device, Based on the shares of the first random number and the shares of the second random number, a distributed master public key is further generated that is distributed among multiple key issuing devices. Based on the distributed master public keys obtained from the aforementioned multiple key issuing devices, a master public key is generated. The user device generates a re-encryption key using the master public key and the user private key. The information processing method described in Appendix 25. (Note 33) A step of generating at least a distributed master private key distributed among multiple key issuing devices based on the shares of the first random number in a distributed state, where the first random number to be kept secret is kept secret, and the shares of the second random number in a distributed state, where the second random number to be kept secret is kept secret. A distributed user secret key is generated using the distributed master secret key and user identification information, wherein the user's user secret key is in a distributed state, and the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices, and in doing so, the share of the third random number in a distributed state, which is a confidential element of the user secret key, and the share of the fourth random number in a distributed state, which is a confidential element of the user secret key, are obtained, and the share of the fourth random number is multiplied by the share of the first random number, which is an element of the distributed master secret key, the share of the second random number, which is an element of the distributed master secret key, and the share of the third random number, and the distributed user secret key is generated based on the product obtained as a result of the multiplication, The steps include transmitting the distributed user secret key to the user's device, A non-temporary, computer-readable medium containing a program that causes a computer to execute a program. [Explanation of Symbols]
[0155] 10 Key issuing device 12. Distributed Master Key Generation Unit 14. Distributed User Secret Key Generation Unit 16 Transmitter 50 Information Processing Systems 60 Encryption device 100 Key Issuing Device 102 Random Number Generation Unit 104 Dispersion section 106 Random Number Share Acquisition Unit 108 Share Multiplication Unit 110 Restoration Section 112 Shared Memory Unit 120 Distributed Master Key Generation Unit 130 Master Public Key Generation Unit 140 Distributed User Private Key Generation Unit 150 Transmitter 200 User Devices 210 User private key generation unit 220 User private key storage unit 230 Re-encryption key generation unit 240 Decoding Unit 300 Re-ciphering device 310 Re-encryption of the key memory section 320 Cipher Memory Department 330 Re-ciphering Department
Claims
1. A key issuing device, A distributed master key generation means that generates at least one distributed master secret key that is distributed among multiple key issuing devices, A distributed user secret key generation means generates a distributed user secret key in which the user's user secret key is distributed using the distributed master secret key and user identification information, and the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. A transmission means for transmitting the distributed user secret key to the user's user device, It has, The distributed master key generation means generates the distributed master secret key based on the shares of the first random numbers in a distributed state, where the first random number to be kept secret is also kept secret, and the shares of the second random numbers in a distributed state, where the second random number to be kept secret is also kept secret. The distributed user secret key generation means is The third random number, which is kept confidential and is an element of the user's private key, is distributed, and the share of the fourth random number, which is kept confidential and is distributed, is obtained. The share of the first random number, which is an element of the distributed master secret key, the share of the second random number, which is an element of the distributed master secret key, and the share of the third random number are each multiplied by the share of the fourth random number. Based on the product obtained from the multiplication, the distributed user secret key is generated. Key issuing device.
2. The distributed user secret key generation means generates the distributed user secret key such that the share of the fourth random number is removed when the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. The key issuing device according to claim 1.
3. The distributed user secret key generation means performs a reconstruction on the first product obtained by multiplying the elements of the user secret key obtained from the share of the first random number and the identification information by the share of the fourth random number, and generates the distributed user secret key using the first value which is the inverse of the value obtained as a result of the reconstruction. The key issuing device according to claim 2.
4. The distributed user private key generation means generates the distributed user private key as a set of the third random number share, the second product obtained by multiplying the elements of the user private key obtained from the second random number share and the third random number share by the fourth random number share, and the first data whose elements are the first value. The key issuing device according to claim 3.
5. The distributed user secret key generation means generates the first data as the second power of the first power of the generator of a predetermined multiplicative cycle group of orders, with the first value as the exponent. The exponent of the first power corresponds to the second product. The key issuing device according to claim 4.
6. The distributed master key generation means is A first random number element that will be an element of the first random number and a second random number element that will be an element of the second random number are generated. A secret sharing operation is performed on the first random number element and the second random number element, and the shares of the first random number element and the shares of the second random number element obtained by the secret sharing are transmitted to another key issuing device. The first random number share is obtained using the share of the first random number element obtained from the plurality of key issuing devices, and the second random number share is obtained using the share of the second random number element obtained from the plurality of key issuing devices. The key issuing device according to claim 1.
7. The distributed user secret key generation means is A third random number element is generated, which is kept secret and becomes an element of the user's private key, and a fourth random number element is generated, which is kept secret and becomes an element of the fourth random number. A secret sharing operation is performed on the third random number element and the fourth random number element, and the shares of the third random number element and the shares of the fourth random number element obtained by the secret sharing are transmitted to another key issuing device. The third random number share is obtained using the share of the third random number element obtained from the plurality of key issuing devices, and the fourth random number share is obtained using the share of the fourth random number element obtained from the plurality of key issuing devices. The key issuing device according to claim 1.
8. Master public key generation means for generating a master public key, It further possesses, The distributed master key generation means further generates a distributed master public key that is distributed among multiple key issuing devices based on the shares of the first random number and the shares of the second random number, The master public key generation means generates the master public key based on the distributed master public key obtained from the plurality of key issuing devices. The key issuing device according to claim 1.
9. Multiple key issuing devices, Multiple user devices, A re-encryption device, It has, Each of the aforementioned multiple key issuing devices is: A distributed master key generation means that generates at least one distributed master secret key that is distributed among multiple key issuing devices, A distributed user secret key generation means generates a distributed user secret key in which the user's user secret key is distributed using the distributed master secret key and user identification information, and the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices. A transmission means for transmitting the distributed user secret key to the user's user device, It has, The distributed master key generation means generates the distributed master secret key based on the shares of the first random numbers in a distributed state, where the first random number to be kept secret is also kept secret, and the shares of the second random numbers in a distributed state, where the second random number to be kept secret is also kept secret. The distributed user secret key generation means is The third random number, which is concealed and becomes an element of the user's private key, is distributed, and the share of the fourth random number, which is concealed and becomes a distributed, is obtained. The share of the first random number, which is an element of the distributed master secret key, the share of the second random number, which is an element of the distributed master secret key, and the share of the third random number are each multiplied by the share of the fourth random number. Based on the product obtained from the multiplication, the distributed user secret key is generated. Each of the aforementioned user devices is: A user secret key generation means that generates the user secret key using the distributed user secret keys obtained from multiple key issuing devices, A re-encryption key generation means that generates a re-encryption key using the user's private key, A decryption means for decrypting a ciphertext to obtain plaintext, It has, The re-encryption device uses the re-encryption key, which enables the decryption of a ciphertext decryptable by a first user device of the plurality of user devices to be decryptable by a second user device of the plurality of user devices, to re-encrypt the ciphertext decryptable with the user secret key relating to the first user device without decrypting it. The decryption means of the second user device decrypts the re-encrypted ciphertext using the user secret key relating to the second user device. Information processing system.
10. A computer, Based on the shares of the first random number in a distributed state where the first confidential random number is distributed, and the shares of the second random number in a distributed state where the second confidential random number is distributed, at least a distributed master secret key is generated that is distributed among multiple key issuing devices. Using the distributed master private key and the user's identification information, a distributed user private key is generated in which the user's private key is distributed, and the user private key is obtained using the distributed user private key obtained from multiple key issuing devices. In doing so, the share of the third random number in the distributed state, which is a confidential element of the user private key, and the share of the fourth random number in the distributed state, which is a confidential element of the user private key, are obtained. The share of the first random number, which is an element of the distributed master private key, the share of the second random number, and the share of the third random number, which are elements of the distributed master private key, are each multiplied by the share of the fourth random number, and the distributed user private key is generated based on the product obtained from the multiplication. The distributed user secret key is transmitted to the user's device. How to issue a key.
11. Each of the multiple key issuing devices, Based on the shares of the first random number in a distributed state where the first confidential random number is distributed, and the shares of the second random number in a distributed state where the second confidential random number is distributed, at least a distributed master secret key is generated that is distributed among multiple key issuing devices. Using the distributed master private key and the user's identification information, a distributed user private key is generated in which the user's private key is distributed, and the user private key is obtained using the distributed user private key obtained from multiple key issuing devices. In doing so, the share of the third random number in the distributed state, which is a confidential element of the user private key, and the share of the fourth random number in the distributed state, which is a confidential element of the user private key, are obtained. The share of the first random number, which is an element of the distributed master private key, the share of the second random number, and the share of the third random number, which are elements of the distributed master private key, are each multiplied by the share of the fourth random number, and the distributed user private key is generated based on the product obtained from the multiplication. The distributed user secret key is transmitted to the user's device. The user device described above, The user secret key is generated using the distributed user secret keys obtained from multiple key issuing devices. A re-encryption key is generated using the aforementioned user private key. Decrypt the ciphertext to obtain the plaintext, The re-encryption device, using the re-encryption key for making the ciphertext decryptable by the first user device decryptable by the second user device, re-encrypts the ciphertext decryptable with the user secret key relating to the first user device without decrypting it. The second user device uses the user's secret key relating to the second user device to decrypt the re-encrypted ciphertext. Information processing methods.
12. A step of generating at least a distributed master secret key distributed among multiple key issuing devices based on the shares of the first random number in a distributed state, and the shares of the second random number in a distributed state, both of which are confidential. A distributed user secret key is generated using the distributed master secret key and user identification information, wherein the user secret key is obtained using the distributed user secret key obtained from multiple key issuing devices, and in doing so, the share of the third random number in the distributed state, which is a confidential element of the user secret key, and the share of the fourth random number in the distributed state, which is a confidential element of the user secret key, are obtained, and the share of the fourth random number is multiplied by the share of the first random number, which is an element of the distributed master secret key, the share of the second random number, which is an element of the distributed master secret key, and the share of the third random number, which are all elements of the distributed master secret key, by the share of the fourth random number, and the distributed user secret key is generated based on the product obtained from the multiplication, The steps include transmitting the distributed user secret key to the user's device, A program that causes a computer to execute something.
Citation Information
Patent Citations
Distributed SM9 key generation method and system
CN113079003A
System and method for securing private keys issued from distributed private key generator (D-PKG) nodes
JP2015505230A
Method for generating secure randomness on blockchain
US20200252211A1
Key recovery using encrypted secret shares
WO2020251795A1