Authentication encryption device, authentication encryption method, and authentication encryption program
Patent Information
- Application Number
- JP2024522174
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-25
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2043-07-25
AI Technical Summary
Existing authenticated ciphers using block ciphers require a minimum secret value size that is fixed to s+b bits only when the plaintext block size b is set to s or 0.5s, limiting flexibility and increasing the size of masking implementations.
The authentication encryption device updates the secret value B using the block cipher as an input block, allowing the secret value to be minimized to s+b bits even when the plaintext block size b is set arbitrarily, using methods from Non-Patent Documents 2 and 3 to reduce masking implementation size.
This configuration enables a flexible secret value size that can be reduced to s+b bits regardless of the plaintext block size, minimizing masking implementation size compared to previous methods.
Smart Images

Figure 00000018_0000 
Figure 00000018_0001 
Figure 00000018_0002
Abstract
Description
[Technical field]
[0001] The present disclosure relates to authenticated encryption using block ciphers. [Background technology]
[0002] An authenticated encryption algorithm is an encryption algorithm that has both confidentiality and tamper detection functions. By using an authenticated encryption algorithm, two parties can communicate with each other while keeping the plaintext secret, and the receiver can check whether the message sent over the communication channel has been tampered with.
[0003] The authentication encryption algorithm comprises two algorithms: an encryption function Enc and a decryption function Dec. The encryption function Enc is a function that takes as input the secret key K, nonce N, header A, and plaintext M, and outputs the ciphertext C and an authentication code Tag for detecting tampering. Note that a different value is used for the nonce N for each encryption, and the same value is not used unless the secret key K is changed. The decryption function Dec takes as input the private key K, nonce N, header A, ciphertext C, and an authenticator Tag for tamper detection, and outputs plaintext M if the input values have not been tampered with, and outputs a value indicating that the values have been forged if they have been tampered with. Hereinafter, the value indicating that the values have been forged will be referred to as reject.
[0004] Suppose that sender Alice and receiver Bob communicate using an authenticated encryption algorithm. Alice and Bob share a secret key K in advance. The sender Alice generates a ciphertext C and an authenticator Tag for tamper detection by calculating the encryption function Enc using the private key K, nonce N, header A, and plaintext M as input. The sender Alice transmits the nonce N, header A, ciphertext C, and the authenticator Tag for tamper detection to the receiver Bob. The receiver Bob calculates the decryption function Dec using the private key K, nonce N, header A, ciphertext C, and the authentication code Tag for detecting tampering as input, and determines that no tampering has been detected, and generates plaintext M if no tampering has been detected. Note that the header A is a value that may be made public. In addition, the sender Alice sets the nonce N to a different value for each encryption and does not use the same value.
[0005] The security of an authenticated encryption algorithm includes confidentiality and integrity. The definitions of confidentiality and integrity are described in Non-Patent Document 4. Confidentiality is the security defined as the ability of plaintext to be leaked from ciphertext. In the confidentiality security game, an attacker accesses either the encryption function Enc of the authenticated encryption algorithm or the oracle that outputs random numbers, and identifies which one he or she is accessing. The probability that the attacker will identify the function is called the identification probability. The lower the identification probability, the higher the confidentiality security. Integrity is a security defined as the inability to tamper with public data or ciphertext. In the integrity security game, an attacker accesses the encryption function Enc and decryption function Dec of an authenticated encryption algorithm, inputs forged public data, ciphertext, and authenticator into the decryption function Dec, and aims to pass the tamper check. The probability of passing the tamper check is called the forgery probability. The lower the forgery probability, the higher the integrity security.
[0006] One method for constructing an authenticated encryption algorithm is to use a block cipher. A block cipher E is a function that takes a k-bit key component X and an n-bit input block Y as input, and outputs an n-bit output block Z. This is written as Z=E(X,Y). When the key X is fixed, the block cipher E becomes an n-bit permutation function. Examples of block ciphers include AES described in Non-Patent Document 2 and Skinny described in Non-Patent Document 3. AES is an abbreviation for Advanced Encryption Standard.
[0007] The operation of the authenticated encryption algorithm uses a secret value that depends on the private key and a public value that does not depend on the private key.
[0008] (d+1)-order masking, described in Non-Patent Documents 1, 4-7, etc., is an implementation method for countermeasures against side channel attacks. In (d+1)-order masking, the secret value is divided into d+1 values to protect the private key. If the secret value is v bits, the secret value is divided into d+1 v-bit values in the masking implementation. The mechanism is such that the original secret value cannot be restored unless all d+1 secret values are obtained. In the masking implementation, the secret value is calculated while remaining divided into d+1 parts. Therefore, the smaller the size of the secret value, the smaller the masking implementation size.
[0009] Let us explain the minimum size of the secret value. Let the security level that the authenticated encryption algorithm wants to achieve be s bits, and the plaintext block size be b bits. In addition to the s-bit secret value, a secret value is required to encrypt each b-bit plaintext block. Therefore, the minimum size is s+b bits. The security level s is designed to be 128 bits or more in many methods. The block size b of the plaintext is a value of 1 or more.
[0010] Patent Document 1 and Non-Patent Document 8 describe authenticated encryption using a block cipher. For a target security level s, the size of the secret value of this authenticated encryption is 2s bits, and the plaintext block size is b=s bits. The size of the secret value is smallest only when the plaintext block size is b=s bits, and the plaintext block size cannot be in any range other than b=s bits.
[0011] Non-Patent Document 9 describes authenticated encryption using a block cipher. For a target security level s, the size of the secret value of this authenticated encryption is 1.5s bits, and the plaintext block size is b=0.5s. The plaintext block size is smallest only when b=0.5s bits, and the plaintext block size cannot be in any range other than b=0.5s bits. [Prior art documents] [Patent documents]
[0012] [Patent Document 1] International Publication No. 2022-215249 [Non-patent literature]
[0013] [Non-Patent Document 1] Hannes Gross, Stefan Mangard, and Thomas Korak. Domain-oriented masking: Compact masked hardware implementations with arbitrary protection order. IACR ePrint 2016 / 486, 2016. [Non-Patent Document 2] National Institute of Standards and Technology (NIST). Announcing the Advanced Encryption Standard (AES). FIPS PUB 197, 2001. [Non-Patent Document 3] Christof Beierle, Jeremy Jean, Stefan Kolbl, Gregor Leander, Amir Moradi, Thomas Peyrin, Yu Sasaki, Pascal Sasdrich, and Siang Meng Sim. The SKINNY family of block ciphers and its low-latency variant MANTIS. In CRYPTO2016, pages 123-153, LNCS volume 9815, Springer, 2016. [Non-Patent Document 4] Tetsu Iwata, Keisuke Ohashi, and Kazuhiko Minematsu. Breaking and Repairing GCM Security Proofs. CRYPTO 2012, Proceedings. pages 31-49. LNCS volume 7417. Springer. 2012. [Non-Patent Document 5] Svetla Nikova, Christian Rechberger, and Vincent Rijmen. Threshold implementations against side-channel attacks and glitches. In Information and Communications Security, 8th International Conference, ICICS 2006, pages 529-545, LNCS volume 4307. Springer. 2006. [Non-Patent Document 6] Oscar Reparaz, Begul Bilgin, Svetla Nikova, Benedikt Gierlichs, and Ingrid Verbauwhede. Consolidating masking schemes. In CRYPTO 2015, LNCS volume 9215, pages 764-783, Springer, 2015. [Non-Patent Document 7] Gaetan Cassiers, Benjamin Gregoire, Itamar Levi, and Francois-Xavier Standaert. Hardware private circuits: From trivial composition to full verification. IEEE Trans. Computers, 70(10):1677-1690, 2021. [Non-Patent Document 8] Yusuke Naito, Yu Sasaki, Takeshi Sugawara. AES-LBBB: AES Mode for Lightweight and BBB-Secure Authenticated Encryption. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021(3): 298-333 (2021). [Non-Patent Document 9] Yusuke Naito, Yu Sasaki, and Takeshi Sugawara. Secret Can Be Public: Low-Memory AEAD Mode for High-Order Masking. CRYPTO2022: page 315-345. Summary of the Invention [Problem to be solved by the invention]
[0014] For a target security level s and plaintext block size b, there exists an authenticated encryption scheme using a block cipher such that the secret value is minimal if and only if b=s or b=0.5s. An object of the present disclosure is to make it possible to realize a configuration that can reduce a secret value to a minimum of s+b bits when the block size b of the plaintext is set to an arbitrary value. [Means for solving the problem]
[0015] The authentication encryption device according to the present disclosure comprises: an initial processing unit for generating a secret value B from a secret key in authenticated encryption; a function F processing unit that updates the secret value B by the block cipher using the secret value B generated by the initial processing unit as an input block of the block cipher; a ciphertext processing unit that executes at least one of a process of encrypting a plaintext M and a process of decrypting a ciphertext C by using the secret value B updated by the function F processing unit; Equipped with. Effect of the Invention
[0016] In the present disclosure, the secret value B is used as an input block of the block cipher, and the secret value B is updated by the block cipher. This makes it possible to realize a configuration that can make the secret value the minimum s+b bits even when the plaintext block size b is set to an arbitrary value. By setting b<0.5s, masking implementation is performed using the block ciphers described in Non-Patent Documents 2 and 3. This makes it possible to reduce the implementation size compared to the masking implementation using the methods described in Patent Document 1 and Non-Patent Documents 8 and 9. [Brief description of the drawings]
[0017] [Figure 1] FIG. 1 is a configuration diagram of an authentication encryption device 10 according to a first embodiment. [Diagram 2] FIG. 2 is an explanatory diagram of block cipher E in the first embodiment. [Diagram 3] FIG. 4 is an explanatory diagram of a function F according to the first embodiment. [Figure 4] 4 is a flowchart of processing of a function F according to the first embodiment. [Diagram 5] 4 is a flowchart showing processing of an encryption function Enc according to the first embodiment. [Figure 6] 5 is a flowchart of an initial process in the encryption function Enc according to the first embodiment. [Figure 7] FIG. 4 is an explanatory diagram of header processing in the encryption function Enc according to the first embodiment. [Figure 8]6 is a flowchart of a header process in the encryption function Enc according to the first embodiment. [Figure 9] FIG. 4 is an explanatory diagram of a main process in the encryption function Enc according to the first embodiment. [Figure 10] 4 is a flowchart of a main process in the encryption function Enc according to the first embodiment. [Figure 11] FIG. 4 is an explanatory diagram of authentication processing in the encryption function Enc according to the first embodiment. [Figure 12] 4 is a flowchart of authentication processing in the encryption function Enc according to the first embodiment. [Figure 13] FIG. 4 is an explanatory diagram of a main process in a decoding function Dec according to the first embodiment. [Figure 14] 6 is a flowchart of a main process in a decoding function Dec according to the first embodiment. [Figure 15] 11 is a flowchart of authentication processing in a decryption function Dec according to the first embodiment. [Figure 16] FIG. 13 is a configuration diagram of an authentication encryption device 10 according to a first modified example. [Figure 17] FIG. 1 is a diagram showing an example of the configuration of an authentication encryption device 10 according to a first modified example. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0018] Embodiment 1 ***Configuration Description*** The configuration of an authentication encryption device 10 according to the first embodiment will be described with reference to FIG. The authentication encryption device 10 is a computer. The authentication encryption device 10 includes the following hardware components: a processor 11, a memory 12, a storage 13, and a communication interface 14. The processor 11 is connected to other hardware components via signal lines and controls these other hardware components.
[0019] The processor 11 is an IC that performs processing. IC is an abbreviation for Integrated Circuit. Specific examples of the processor 11 include a CPU, a DSP, and a GPU. CPU is an abbreviation for Central Processing Unit. DSP is an abbreviation for Digital Signal Processor. GPU is an abbreviation for Graphics Processing Unit.
[0020] The memory 12 is a storage device that temporarily stores data. Specific examples of the memory 12 include SRAM and DRAM. SRAM is an abbreviation for Static Random Access Memory. DRAM is an abbreviation for Dynamic Random Access Memory.
[0021] The storage 13 is a storage device that stores data. A specific example of the storage 13 is an HDD. HDD is an abbreviation for Hard Disk Drive. The storage 13 may also be a portable recording medium such as an SD (registered trademark) memory card, CompactFlash (registered trademark), NAND flash, a flexible disk, an optical disk, a compact disk, a Blu-ray (registered trademark) disk, or a DVD. SD is an abbreviation for Secure Digital. DVD is an abbreviation for Digital Versatile Disk.
[0022] The communication interface 14 is an interface for communicating with an external device. Specific examples of the communication interface 14 include Ethernet (registered trademark), USB, and HDMI (registered trademark) ports. USB is an abbreviation for Universal Serial Bus. HDMI is an abbreviation for High-Definition Multimedia Interface.
[0023] The authentication encryption device 10 includes, as functional components, an initial processing unit 21, a function F processing unit 22, a ciphertext processing unit 23, and an authentication processing unit 24. The ciphertext processing unit 23 includes an encryption processing unit 231 and a decryption processing unit 232. The functions of the functional components of the authentication encryption device 10 are realized by software. The storage 13 stores programs that realize the functions of the functional components of the authentication encryption device 10. The programs are loaded into the memory 12 by the processor 11 and executed by the processor 11. In this way, the functions of the functional components of the authentication encryption device 10 are realized.
[0024] 1 shows only one processor 11. However, there may be a plurality of processors 11, and the plurality of processors 11 may cooperate to execute programs that realize the respective functions.
[0025] ***Explanation of Operation*** The operation of the authentication encryption device 10 according to the first embodiment will be described with reference to FIGS. The operation procedure of the authentication encryption device 10 according to the embodiment 1 corresponds to the authentication encryption method according to the embodiment 1. Moreover, the program for realizing the operation of the authentication encryption device 10 according to the embodiment 1 corresponds to the authentication encryption program according to the embodiment 1.
[0026] **Prerequisite explanation** The operator shown in Equation 1 represents an exclusive OR operator.
number
[0027] 0 i Let be a string of i bits of 0, and 1 i Let be a string of i bits of 1.
[0028] For a bit string X, the bit length of X is written as |X|. If X is an empty string, |X|=0.
[0029] For two bit strings X and Y, let X||Y be a bit string formed by bit-concatenating Y to the end of X.
[0030] The function f is a surjective function that takes the nonce N, the counter value ctr, and the division value w as input, and outputs a c-bit value. In other words, if (N, ctr, w) ≠ (N', ctr', w'), then the function f is a function such that f(N, ctr, w) ≠ f(N', ctr', w'). An example of the function f is a function where c=c1+c2+c3 for c1, c2, and c3, N is c1 bits, ctr is c2 bits, and w is c3 bits, and f(N,ctr,w)=N||ctr||w. In the following example, ctr and w are expressed as integers. When actually used, convert them to bit strings.
[0031] The function ozp[i] is a function that takes a value of i bits or less as input and outputs a value of i bits. The function ozp[i] is injective for inputs of i-1 bits or less. Examples of the function ozp[i] include the following functions. For a value V of 1 to i-1 bits, a 1 is bit-concatenated to the end of V, and a bit string of 0s is bit-concatenated to the end of V so that the bit length is i. The output of the function ozp[i](V) is the result of this. For an i-bit value V, the value V is the output of the function ozp[i](V). For an empty string V, 0 i Let be the output of function ozp[i](V).
[0032] The function zp[i] is a function that takes a value of i bits or less as input and outputs a value of i bits. The function zp[i] is a function that outputs different values for two different input values of the same bit length. Examples of functions zp[i] include the following: For a value V of i-1 bits or less, the output of function zp[i](V) is the value obtained by concatenating a string of 0s after V so that the bit length is i. For an i-bit value V, the output of function zp[i](V) is the value V.
[0033] The function tr[i] is a function that outputs a predetermined i bits among the input bit string when the input is a bit string of i bits or more. Examples of the function tr[i] include a function that outputs the upper i bits or the lower i bits of the input bit string. The function tr[i] is an injective function when the input is a bit string of 1 bit or more and i - 1 bits or less. Examples of the function tr[i] include the functions exemplified as the function zp[i] or the function ozp[i].
[0034] Let b be an integer satisfying 0 < b ≤ n. Here, n is the size of the input block of the block cipher. Let t be an integer satisfying 0 < t. Let r be an integer satisfying 0 < r. Let w be an integer satisfying t / b ≤ w. Let the length of the encryption key of the block cipher be k = r + c.
[0035] **Function F** The authentication encryption device 10 constructs an authentication encryption using the function F. In the function F, the block cipher E is used.
[0036] Referring to FIG. 2, the block cipher E in Embodiment 1 will be described. The block cipher E is a function that takes a k-bit key component X and an n-bit input block Y as inputs and outputs an n-bit output block Z. Assume that this block cipher E is drawn as shown in FIG. 2.
[0037] Referring to FIGS. 3 and 4, the function F according to Embodiment 1 will be described. The function F is a function that takes an r-bit value T, an n-bit value B, a nonce N, a counter value ctr, and a division value w as inputs and outputs an r-bit value T' and an n-bit value B'. That is, (T', B') = F(N, ctr, w, T, B). The counter value ctr is counted for each process and different values are set. The function F is processed by the function F processing unit 22.
[0038] The process of the function F will be specifically described. (Step S101: B update process) The function F processing unit 22 inputs the nonce N, the counter value ctr, and the divided value w into the function f after the value T, and combines the output value obtained as the key component of the block cipher E. The function F processing unit 22 also sets the value B as the input block of the block cipher E. Then, the function F processing unit 22 updates the value B by calculating the block cipher E, and generates a value B'.
[0039] (Step S102: T update process) The function F processing unit 22 updates the value T by exclusive ORing the value T and the output value obtained by inputting the value B' to the function tr[r], thereby generating the value T'.
[0040] (Step S103: Output process) The function F processing unit 22 outputs a pair of an r-bit value T' and an n-bit value B'.
[0041] **Encryption function Enc** The encryption function Enc in the authenticated encryption realized by the authenticated encryption device 10 according to the first embodiment will be described. The input values of the encryption function Enc are an r+n-bit secret key K, a nonce N, a header A, and a plaintext M. The header A may be an empty string. Also, the plaintext M may be an empty string.
[0042] 5, in the encryption function Enc, an initial process, a header process, a main process, and an authentication process are executed in this order. The initial process, the header process, the main process, and the authentication process will be described below.
[0043] <Initial processing> With reference to FIG. 6, the initial processing in the encryption function Enc according to the first embodiment will be described. The initial process in the encryption function Enc is a process for setting values and the like to be used in the process described later.
[0044] (Step S11: Key component setting process) The initial processing unit 21 sets the most significant r bits of the private key K to key component K1, and sets the least significant n bits to key component K2. The initial processing unit 21 also sets the most significant b bits of key component K2 to key component K21, and sets the remaining nb bits to key component K22. That is, K=K1||K2, K2=K21||K22. The initial processing unit 21 may extract key component K1 as a predetermined r bits of the private key K, and may set key component K2 as the remaining n bits of the private key K. The initial processing unit 21 may also extract key component K21 as a predetermined b bits of key component K2, and may set key component K22 as the remaining nb bits of key component K2. The initial processing unit 21 sets the key component K1 to the value IVt, and sets the key component K2 to the value IVb. The values IVt and IVb are used in the header processing.
[0045] (Step S12: Division process) The initial processing unit 21 separates the header A and the plaintext M. Specifically, the initial processing unit 21 divides the header A into header elements A[1], A[2], ..., A[a] for every n bits from the beginning. Also, the initial processing unit 21 divides the plaintext M into plaintext elements M[1], M[2], ..., M[m] for every b bits from the beginning. If header A is not an empty string, header elements A[1], A[2], ..., A[a-1] are each n bits, and header element A[a] is a value between 1 and n bits. Header A is the bitwise concatenation of header elements A[1], A[2], ..., A[a]. If header A is an empty string, a=1 and header element A[1] is an empty string. If plaintext M is not an empty string, plaintext elements M[1], M[2], ..., M[m-1] are each b bits long, and plaintext element M[m] is a value between 1 and b bits long. Plaintext M is the bitwise concatenation of plaintext elements M[1], M[2], ..., M[m]. If plaintext M is an empty string, m=1, and plaintext element M[1] is an empty string.
[0046] <Header processing> The header processing in the encryption function Enc according to the first embodiment will be described with reference to FIGS. The header processing in the encryption function Enc is a process in which, using the values IVt and IVb set in the initial processing, processing the header elements A[1], A[2], ..., A[a] generated in the initial processing, generates values Ht, Hb, and a divided value dA.
[0047] (Step S21: Initial value setting process) The function F processing unit 22 sets the value IVt to the value T*[0], and sets the value IVb to the value B*[0].
[0048] (Step S22: Function F processing) When the value a, which is the division number of the header A, is greater than 1, the function F processing unit 22 executes the following processes (1) and (2) for each integer i, i=1,...,a-1, in ascending order. On the other hand, when the value a, which is the division number of the header A, is 1, the function F processing unit 22 sets the value T*[0] to the value T*[a-1], and sets the value B*[0] to the value B*[a-1]. (1) The function F processing unit 22 sets the exclusive OR of the value A[i] and the value B*[i-1] to the value B*[i-1]. (2) The function F processing unit 22 generates the value T*[i] and the value B*[i] by calculating the function F using the nonce N, the integer i, 0, the value T*[i-1], and the value B*[i-1] as inputs. Here, the value T*[0] and the value B*[0] are secret values generated from a secret key in authenticated encryption. That is, the function F processing unit 22 sets a value generated using the secret value T*[i-1], the nonce N, the value i which is the counter value ctr, and the division number (here, 0) as the key component of the block cipher E. Also, the function F processing unit 22 sets the secret value *B[i-1] to the input block of the block cipher E. Then, the function F processing unit 22 updates the secret value T*[i-1] and the secret value B*[i-1] by the block cipher E to generate the secret value T*[i] and the secret value B*[i].
[0049] (Step S23: Value B update process) The function F processing unit 22 sets the exclusive OR of the output value obtained by inputting the value A[i] into the function ozp[n] and the value B*[a - 1] to the value B*[a]. Also, the function F processing unit 22 sets the value T*[a - 1] to the value T*[a].
[0050] (Step S24: Value dA setting process) The function F processing unit 22 sets the value dA according to whether |A[a]| = n. In Embodiment 1, when |A[a]| = n, the function F processing unit 22 sets 1 to the value dA. When |A[a]| < n, the function F processing unit 22 sets 2 to the value dA.
[0051] (Step S25: Output value setting process) The function F processing unit 22 sets the value T*[a] to the value Ht and sets the value B*[a] to the value Hb.
[0052] The function F processing unit 22 may update the value T[i - 1] with a certain r-bit replacement P1 before (1) in Step S22. Similarly, the function F processing unit 22 may update the value B[i - 1] with a certain n-bit replacement P2 before (1) in Step S22. Also, the function F processing unit 22 may update the value T[i] with a certain r-bit replacement P1' after (2) in Step S22. Similarly, the function F processing unit 22 may update the value B[i] with a certain n-bit replacement P2' after (2) in Step S22. Also, other operations such as addition, subtraction, and multiplication may be used instead of the exclusive OR used in the header processing.
[0053] <Main process> Referring to FIGS. 9 and 10, the main process in the encryption function Enc according to Embodiment 1 will be described. The main process in the encryption function Enc uses the values Ht, Hb, and dA set in the header processing, and performs processing on the plaintext elements M[1], M[2],..., M[m] generated in the initial processing to generate the values St, Sb, dM, and the ciphertext C.
[0054] In the following process, the function h is a permutation of n bits. The function h is a permutation such that, for an n-bit value S and a variable Z, the number 2 has a unique solution for the variable Z.
number
[0055] (Step S31: Initial value setting process) The function F processing unit 22 sets the value Ht to the value T[0], and sets the value Hb to the value B[0].
[0056] (Step S32: Function F processing) If plaintext element M[1] is not a null string, the function F processing unit 22 executes the following processes (1) to (3) for each integer i, i=1,...,m, in ascending order. On the other hand, if plaintext element [1] is a null string, the function F processing unit 22 sets the value T[0] to the value T[m], and sets the value B[0] to the value B[m]. (1) The function F processing unit 22 generates the value T[i] and the value B[i] by calculating the function F using the nonce N, the integer i, the value dA, the value T[i-1], and the value B[i-1] as inputs. Here, the value T[0] and the value B[0] are secret values updated in the header processing. That is, the function F processing unit 22 sets a value generated using the secret value T[i-1], the nonce N, the value i which is the counter value ctr, and the division number (here, dA) as the key component of the block cipher E. Also, the function F processing unit 22 sets the secret value B[i-1] to the input block of the block cipher E. Then, the function F processing unit 22 updates the secret value T[i-1] and the secret value B[i-1] by the block cipher E to generate the secret value T[i] and the secret value B[i].
[0057] (2) The encryption processing unit 231 of the ciphertext processing unit 23 generates a cryptographic element C[i] by using the secret value B[i] generated by the function F processing unit 22 after updating the secret value B[i-1]. Specifically, the encryption processing unit 231 sets the exclusive OR of the output value obtained by inputting the value B[i] into the function tr[|M[i]|], the output value obtained by inputting the value K21 into the function tr[|M[i]|], and the plaintext element M[i] to the cipher element C[i]. When the integer i≠m, since |M[i]| is b bits, it is not necessary to convert the value K21 using the function tr[|M[i]|]. That is, instead of the output value obtained by inputting the value K21 into the function tr[|M[i]|], the value K21 can be used directly as the input for the exclusive OR, and the result is the same.
[0058] (3) The function F processing unit 22 sets the exclusive OR of the output value obtained by inputting the value B[i] into the function h, the output value obtained by inputting the plaintext element M[i] into the function ozp[b] and then inputting the resulting output value into the function zp[n], to the value B[i]. When the integer i≠m, since |M[i]| is b bits, it is not necessary to use the function ozp[b]. That is, instead of the output value obtained by inputting the plaintext element M[i] into the function ozp[b], the plaintext element M[i] can be used directly as the input for the function zp[n], and the result is the same.
[0059] (Step S33: Output value setting process) The function F processing unit 22 sets the value T[m] to the value St and the value B[m] to the value Sb.
[0060] (Step S34: Value dM process) The function F processing unit 22 sets the value dM according to whether |M[m]| = b. In Embodiment 1, when |M[m]| = b, the function F processing unit 22 sets 3 to the value dM. When |M[m]| < b, the function F processing unit 22 sets 4 to the value dM.
[0061] (Step S35: Ciphertext generation process) The encryption processing unit 231 of the ciphertext processing unit 23 generates the ciphertext C by bit - combining the cipher elements C[1], ···, C[m] generated in (2) of Step S32. For example, the encryption processing unit 231 sets the ciphertext C = C[1]||C[2]||···||C[m].
[0062] The process of step S32(2) and the process of step S35 constitute the encryption process. In the encryption process, the encryption processing unit 231 generates a cryptographic element C[i] for each integer i, where i=1,...,m, from the secret value B[i] generated by the function F processing unit 22. Then, the encryption processing unit 231 generates a ciphertext C by encrypting the plaintext M using the cryptographic element C[i] for each integer i, where i=1,...,m.
[0063] The function F processing unit 22 may update the value T[i-1] with a certain r-bit substitution before step S32 (1). Similarly, the function F processing unit 22 may update the value B[i-1] with a certain n-bit substitution before step S32 (1). Also, the function F processing unit 22 may update the value T[i] with a certain r-bit substitution after step S32 (3). Similarly, the function F processing unit 22 may update the value B[i] with a certain n-bit substitution after step S32 (3). Also, other operations such as addition, subtraction, and multiplication may be used instead of the exclusive OR used in the main processing.
[0064] <Authentication process> The authentication process in the encryption function Enc according to the first embodiment will be described with reference to FIGS. The authentication process in the encryption function Enc is a process of generating an authenticator Tag using the value St, the value Sb, and the value dM that were set in the main process.
[0065] (Step S41: Initial value setting process) The function F processing unit 22 sets the value St to the value T'[0], and sets the value Sb to the value B'[0].
[0066] (Step S42: Function F processing) The function F processing unit 22 executes the following processes (1) and (2) for each integer i, where i=1,...,w, in ascending order, where w is a preset value. (1) The function F processing unit 22 generates a value T'[i] and a value B'[i] by calculating the function F using the nonce N, the integer i, the value dM, the value T'[i-1], and the value B'[i-1] as inputs. Here, the value T'[0] and the value B'[0] are secret values updated in the main processing. That is, the function F processing unit 22 sets a value generated using the secret value T'[i-1], the nonce N, the value i which is the counter value ctr, and the division number (here, dM) as the key component of the block cipher E. Also, the function F processing unit 22 sets the secret value B'[i-1] to the input block of the block cipher E. Then, the function F processing unit 22 updates the secret value T'[i-1] and the secret value B'[i-1] by the block cipher E to generate the secret value T'[i] and the secret value B'[i].
[0067] (2) The authentication processing unit 24 sets the exclusive OR of the output value obtained by inputting the secret value B'[i] to the function tr[b] and the value K21 to the authentication element Tag[i].
[0068] (Step S43: Authenticator generation process) The authentication processing unit 24 generates an authenticator Tag by bit-combining the authentication elements Tag[1], ..., Tag[w] generated in step S42(2). For example, the authentication processing unit 24 sets the authenticator Tag=tr[t](Tag[1]∥∥Tag[w]).
[0069] **Decryption function Dec** The decryption function Dec in the authenticated encryption realized by the authenticated encryption device 10 according to the first embodiment will be described. The input values of the decryption function Dec are an r+n-bit secret key K, a nonce N, a header A, a ciphertext C, and an authenticator Tag' for detecting tampering. Here, the authenticator Tag' given as an input value of the decryption function Dec is the authenticator Tag generated by the encryption function Enc. In the following explanation, the authenticator given as an input value of the decryption function Dec will be referred to as the authenticator Tag' to distinguish it from the authenticator Tag generated.
[0070] In the decryption function Dec, like the encryption function Enc, the initial process, the header process, the main process, and the authentication process are executed in that order. The initial process, the main process, and the authentication process are explained below. The header process is the same as the encryption function Enc.
[0071] <Initial processing> With reference to FIG. 6, the initial processing in the decoding function Dec according to the first embodiment will be described. The initial process in the decryption function Dec is a process for setting values and the like to be used in the process described later.
[0072] The process in step S11 is the same as that in the case of the encryption function Enc.
[0073] (Step S12: Division process) The initial processing unit 21 separates the header A and the ciphertext C. Specifically, the initial processing unit 21 divides the header A into header elements A[1], A[2], ..., A[a] in the same manner as in the case of the encryption function Enc. In addition, the initial processing unit 21 divides the ciphertext C into cipher elements C[1], C[2], ..., C[m] for every b bits from the beginning. If the ciphertext C is not an empty string, then each of the cipher elements C[1], C[2], ..., C[m-1] is b bits long, and the cipher element C[m] is a value between 1 and b bits long. The ciphertext C is the bitwise concatenation of the cipher elements C[1], C[2], ..., C[m]. If the ciphertext C is an empty string, then m=1, and the cipher element C[1] is an empty string.
[0074] <Main processing> The main processing in the decoding function Dec according to the first embodiment will be described with reference to FIGS. The main processing in the decryption function Dec is to use the values Ht, Hb, and dA set in the header processing to process the cryptographic elements C[1], C[2], ..., C[m] generated in the initialization processing, and generate values St, Sb, dM, and plaintext M.
[0075] Note that, similar to the function h used in the main process of the encryption function Enc, the function h in the following process is an n-bit substitution.
[0076] The process of step S51 is the same as the process of step S31 in FIG. 10. Also, the process of step S53 is the same as the process of step S33 in FIG. 10.
[0077] (Step S52: Function F process) When the encryption element C[1] is not an empty string, the function F processing unit 22 executes the following processes (1) to (3) in ascending order for each integer i = 1,..., m. The process of (1) is the same as the process of (1) in step S32 of FIG. 10. Also, the process of (3) is the same as the process of (3) in step S32 of FIG. 10.
[0078] (2) The decryption processing unit 232 of the ciphertext processing unit 23 generates the plaintext element M[i] using the secret value B[i] that has been updated and generated by the function F processing unit 22. Specifically, the decryption processing unit 232 sets the exclusive OR of the output value obtained by inputting the value B[i] to the function tr[|C[i]|], the output value obtained by inputting the value K21 to the function tr[|C[i]|], and the encryption element C[i] to the plaintext element M[i]. Note that when the integer i ≠ m, since |C[i]| is b bits, it is not necessary to convert the value K21 using the function tr[|C[i]|]. That is, it is the same even if the value K21 is used as the input of the exclusive OR as it is instead of the output value obtained by inputting the value K21 to the function tr[|C[i]|].
[0079] (Step S54: Value dM process) The function F processing unit 22 sets the value dm according to whether |C[m]| = b. In Embodiment 1, when |C[m]| = b, the function F processing unit 22 sets 3 to the value dM. When |C[m]| < b, the function F processing unit 22 sets 4 to the value dM.
[0080] (Step S55: Plain text generation process) The decryption processing unit 232 of the ciphertext processing unit 23 performs bit-wise concatenation of the plaintext elements M[1], . . . , M[m] generated in step S52(2) to generate plaintext M. For example, the decryption processing unit 232 sets the plaintext M = M[1]||M[2]||. . . ||M[m].
[0081] The process of step S52(2) and the process of step S55 constitute the decryption process. In the decryption process, the decryption processing unit 232 generates a plaintext element M[i] for each integer i, where i=1,...,m, from the secret value B[i] generated by the function F processing unit 22. Then, the decryption processing unit 232 generates a plaintext M by decrypting the ciphertext C, using the plaintext element M[i] for each integer i, where i=1,...,m.
[0082] The function F processing unit 22 may update the value T[i-1] with a certain r-bit substitution before step S52 (1). Similarly, the function F processing unit 22 may update the value B[i-1] with a certain n-bit substitution before step S52 (1). Also, the function F processing unit 22 may update the value T[i] with a certain r-bit substitution after step S52 (3). Similarly, the function F processing unit 22 may update the value B[i] with a certain n-bit substitution after step S52 (3). Also, other operations such as addition, subtraction, and multiplication may be used instead of the exclusive OR used in the main processing.
[0083] <Authentication process> The authentication process in the decryption function Dec according to the first embodiment will be described with reference to FIG. (Step S61: Authenticator generation process) The authentication encryption device 10 executes the processes from step S41 to step S43 in Fig. 12 described in the authentication process in the encryption function Enc, thereby generating an authenticator Tag.
[0084] (Step S62: Tampering determination process) The authentication processing unit 24 judges whether the authenticator Tag generated in step S61 matches the authenticator Tag' given as input. If the authenticator Tag and the authenticator Tag' match, the authentication processing unit 24 advances the process to step S63. On the other hand, if the authenticator Tag and the authenticator Tag' do not match, the authentication processing unit 24 advances the process to step S64.
[0085] (Step S63: Plain text output process) The authentication processing unit 24 outputs the plaintext M generated in the main processing.
[0086] (Step S64: Forged information output process) The authentication processing unit 24 outputs a value "reject" which indicates that the certificate is forged.
[0087] ***Advantages of the First Embodiment*** As described above, the authentication encryption device 10 according to the first embodiment updates the secret value B by a block cipher, using the secret value B as an input block of the block cipher. This realizes a configuration that can make the secret value the minimum s+b bits even when the block size b of the plaintext is set to an arbitrary value. Specifically, the authentication encryption realized by the authentication encryption device 10 according to the first embodiment is s-bit secure authentication encryption, where r is the number of bits and n is the number of bits r+n=s for a target security level s.
[0088] The authenticated encryption realized by the authenticated encryption device 10 according to the first embodiment can be used as a tamper detection algorithm by making the plaintext M and the ciphertext C null strings.
[0089] The authentication encryption realized by the authentication encryption device 10 according to the first embodiment may fix a random number having a length equal to or shorter than the nonce for one private key K of the authentication encryption, and use the exclusive OR of the random number and the nonce as a new nonce. In addition to the random number for updating the nonce, a random number having a length equal to or shorter than the counter value for one private key K may be fixed, and the exclusive OR of the random number and each counter value may be used as a new counter value. By updating the nonce and counter value by exclusive-ORing the nonce and counter value with a random number, it is possible to ensure the multi-user security of authenticated encryption described in the following document. A fixed random number must be used for each key, and a different random number must be used each time the key is changed. (Viet Tung Hoang, Stefano Tessaro, Aishwarya Thiruvengadam: The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce Randomization. CCS 2018. ACM. pp. 1429-1440.). The security described in the background art with reference to Non-Patent Document 4 is security for a single user.
[0090] ***Other configurations*** <Variation 1> In the first embodiment, each functional component is realized by software. However, as a first modification, each functional component may be realized by hardware. The following describes the first modification in terms of differences from the first embodiment.
[0091] The configuration of the authentication encryption device 10 according to the first modification will be described with reference to FIG. When each functional component is realized by hardware, the authentication encryption device 10 includes an electronic circuit 15 instead of the processor 11, the memory 12, and the storage 13. The electronic circuit 15 is a dedicated circuit for realizing the functions of each functional component, the memory 12, and the storage 13.
[0092] Possible electronic circuits 15 include a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, a logic IC, a GA (Gate Array), an ASIC (Application Specific Integrated Circuit), and an FPGA (Field-Programmable Gate Array).
[0093] Each functional component may be realized by one electronic circuit 15, or each functional component may be distributed across multiple electronic circuits 15. For example, as shown in FIG. 17, the authentication encryption device 10 may be configured to include, as the electronic circuit 15, an initial processing processor that performs the processing of the initial processing unit 21, a function F processing processor that performs the processing of the function F processing unit 22, a ciphertext processing processor that performs the processing of the ciphertext processing unit 23, and an authentication processing processor that performs the processing of the authentication processing unit 24. Furthermore, in the function F processing unit 22, a block cipher processor that processes the block cipher E may be prepared separately from the function F processing processor. Furthermore, the ciphertext processing processor may be divided into an encryption processing processor that performs the processing of the encryption processing unit 231 and a decryption processing processor that performs the processing of the decryption processing unit 232. Furthermore, the authentication processing processor may be divided into an authentication code generation processor that generates an authentication code Tag, and a tampering determination processor that performs tampering determination processing.
[0094] <Variation 2> As a second modification, some of the functional components may be realized by hardware, and other functional components may be realized by software.
[0095] The processor 11, the memory 12, the storage 13, and the electronic circuit 15 are collectively referred to as a processing circuit. In other words, the functions of the respective functional components are realized by the processing circuit.
[0096] <Modification 3> In the first embodiment, the authentication encryption device 10 realizes both the encryption function Enc and the decryption function Dec. However, the authentication encryption device 10 may realize only one of the encryption function Enc and the decryption function Dec. When the authentication encryption device 10 realizes only one of the encryption function Enc and the decryption function Dec, the authentication encryption device 10 only needs to include functional components required for realization. Specifically, when the authentication encryption device 10 realizes only the encryption function Enc, the decryption processing unit 232 of the ciphertext processing unit 23 is not necessary. Also, when the authentication encryption device 10 realizes only the decryption function Dec, the encryption processing unit 231 of the ciphertext processing unit 23 is not necessary.
[0097] In addition, the word "part" in the above description may be read as a "circuit," "step," "procedure," "processing," or "processing circuit."
[0098] The above describes the embodiments and modifications of the present disclosure. Some of these embodiments and modifications may be combined and implemented. Also, one or some of them may be partially implemented. Note that the present disclosure is not limited to the above embodiments and modifications, and various modifications are possible as necessary. [Explanation of symbols]
[0099] 10 Authentication encryption device, 11 processor, 12 memory, 13 storage, 14 communication interface, 15 electronic circuit, 21 initial processing unit, 22 function F processing unit, 23 ciphertext processing unit, 231 encryption processing unit, 232 decryption processing unit, 24 authentication processing unit.
Claims
1. An initial processing unit that generates an r-bit key component K1 extracted from an r + n-bit secret key in an authentication cipher, and generates an n-bit key component K2 remaining after the key component K1 is extracted from the secret key as a secret value B; A function F processing unit that uses a value T that is the key component K1 generated by the initial processing unit as a key component of a block cipher, and updates the secret value B by the block cipher using the secret value B as an input block of the block cipher; A ciphertext processing unit that executes at least one of a process of encrypting a plaintext M and a process of decrypting a ciphertext C using the secret value B updated by the function F processing unit; An authentication cipher device comprising the above.
2. The function F processing unit uses, in addition to the value T, a value generated using a nonce given as an input in the authentication cipher as a key component of the block cipher. The authentication cipher device according to Claim 1.
3. The function F processing unit repeats a process of updating the secret value B by the block cipher, using a new secret value B generated by updating the secret value B as an input block of the block cipher, and using a new value T generated from the new secret value B and the value T as a key component of the block cipher. The authentication cipher device according to Claim 1.
4. An initial processing unit that generates a secret value B from a secret key in an authentication cipher; A function F processing unit that updates the secret value B by a block cipher using the secret value B generated by the initial processing unit as an input block of the block cipher. For each integer i from i = 1 to i = m in ascending order, using the secret value B[i - 1] as an input block of the block cipher, the function F processing unit updates the secret value B[i - 1] by the block cipher to generate a secret value B[i]; The function F processing unit generated for i = 1 A ciphertext processing unit that executes at least one of a process of encrypting a plaintext M and a process of decrypting a ciphertext C using the secret value B[i] for each integer i from i = 1 to i = m; An authentication cipher device comprising the above.
5. The ciphertext processing unit i = 1 , for each integer i from 1 to m, generate a cipher element C[i] from the secret value B[i] and the plaintext element M[i] obtained by dividing the plaintext M into m parts, and generate a ciphertext C by encrypting the plaintext M using the cipher elements C[i] for each integer i from 1 to m, an encryption process; i = 1 , for each integer i from 1 to m, generate a plaintext element M[i] from the secret value B[i] and the cipher element C[i] obtained by dividing the ciphertext C, and execute at least one of a decryption process of generating the plaintext M by decrypting the ciphertext C using the plaintext elements M[i] for each integer i from 1 to m The authentication encryption device according to claim 4.
6. The ciphertext processing unit In the encryption process, i = 1 , for each integer i from 1 to m, generate the cipher element C[i] using the key component K21 which is at least a part of the initial value of the secret value generated by the initial processing unit In the decryption process, i = 1, , for each integer i from 1 to m, generate the plaintext element M[i] using the key component K21 which is at least a part of the initial value of the secret value generated by the initial processing unit The authentication encryption device according to claim 5.
7. An initial processing unit that generates a secret value B from a secret key in authentication encryption; A function F processing unit that updates the secret value B by the block cipher using the secret value B generated by the initial processing unit as an input block of the block cipher; A ciphertext processing unit that executes at least one of a process of encrypting the plaintext M and a process of decrypting the ciphertext C using the secret value B updated by the function F processing unit Comprising The function F processing unit uses the secret value B used in the process of encrypting the plaintext M or decrypting the ciphertext C by the ciphertext processing unit as an input block of the block cipher, and further updates the secret value B by the block cipher. Furthermore An authentication processing unit that generates an authenticator Tag using the secret value B further updated by the function F processing unit An authentication encryption device comprising.
8. The function F processing unit uses the secret value B used in the process of encrypting the plaintext M or decrypting the ciphertext C by the ciphertext processing unit as the secret value B'[0], and i = 1 ,..., for each integer i from 1 to w in ascending order, using the secret value B'[i - 1] as the input block of the block cipher, updating the secret value B'[i - 1] by the block cipher to generate the secret value B'[i], The authentication processing unit generates an authentication element Tag[i] using the secret value B'[i] for each integer i from 1 to w, and generates the authenticator Tag using the authentication elements Tag[i] for each integer i from 1 to w. The authentication encryption device according to claim 7.
9. The authentication processing unit generates the authentication element Tag[i] using, for each integer i from 1 to w, the key component K21 which is at least a part of the initial value of the secret value, the secret value generated by the initial processing unit. The authentication encryption device according to claim 8.
10. The function F processing unit updates the secret value B generated by the initial processing unit with the header A given as an input in the authentication encryption, and then, using the updated secret value B as the input block of the block cipher, executes a header process of updating the secret value B by the block cipher, and sets the secret value B at the time of being updated by the header process as the secret value B[0]. The authentication encryption device according to claim 4.
11. The function F processing unit sets the secret value B generated by the initial processing unit as the secret value B*[0], and for each integer i from 1 to a - 1 in ascending order, after updating the secret value B*[i - 1] with the header element A[i] among the header elements A[1],..., A[a] obtained by dividing the header A into a pieces, using the updated secret value B*[i - 1] as the input block of the block cipher, updates the secret value B*[i - 1] by the block cipher to generate the secret value B*[i], and executes the header process of updating the secret value B*[a - 1] with the header element A[a]. The authentication encryption device according to claim 10.
12. The computer generates an r-bit key component K1 extracted from an r + n-bit secret key in the authentication encryption, and generates an n-bit key component K2 remaining after the key component K1 is extracted from the secret key as the secret value B. The computer uses a value T that is the key component K1 to generate a value as the key component of a block cipher, uses the secret value B as the input block of the block cipher, and updates the secret value B by the block cipher. An authentication encryption method in which the computer executes at least one of a process of encrypting a plaintext M and a process of decrypting a ciphertext C using the updated secret value B.
13. An initial process of generating an r-bit key component K1 extracted from an r + n-bit secret key in authentication encryption, and generating an n-bit key component K2 remaining after the key component K1 is extracted from the secret key as a secret value B. A function F process of using a value generated using the value T that is the key component K1 generated by the initial process as the key component of a block cipher, using the secret value B as the input block of the block cipher, and updating the secret value B by the block cipher. A ciphertext process of executing at least one of a process of encrypting a plaintext M and a process of decrypting a ciphertext C using the secret value B updated by the function F process. An authentication encryption program that causes a computer to function as an authentication encryption device that performs the above.
14. The computer generates a secret value B from a secret key in authentication encryption. The computer uses the secret value B as the input block of a block cipher, updates the secret value B by the block cipher, sets the secret value B at a certain point in time as the secret value B[0], and for each integer i from i = 1,..., m in ascending order, uses the secret value B[i - 1] as the input block of the block cipher, and updates the secret value B[i - 1] by the block cipher to generate the secret value B[i]. An authentication encryption method in which the computer executes at least one of a process of encrypting a plaintext M and a process of decrypting a ciphertext C using the secret value B[i] for each integer i from i = 1,..., m.
15. An initial process of generating a secret value B from a secret key in authentication encryption. A function F process that updates the secret value B by using the block cipher with the secret value B generated by the initial process as an input block of the block cipher. In the function F process, with the secret value B at a certain point in time as the secret value B[0], for each integer i from i = 1,..., m in ascending order, the function F process updates the secret value B[i - 1] by using the block cipher with the secret value B[i - 1] as an input block of the block cipher to generate the secret value B[i]. The authentication cipher process that executes at least one of an encryption process for encrypting the plaintext M and a decryption process for decrypting the ciphertext C by using the secret value B[i] for each integer i from i = 1 ,..., m generated by the function F process, and An authentication cipher program that causes a computer to function as an authentication cipher device that performs the above processes.
16. The computer generates the secret value B from the secret key in the authentication cipher. The computer updates the secret value B by using the block cipher with the secret value B as an input block of the block cipher. The computer executes at least one of an encryption process for encrypting the plaintext M and a decryption process for decrypting the ciphertext C by using the updated secret value B. The computer further updates the secret value B by using the block cipher with the secret value B used in the encryption process for encrypting the plaintext M or the decryption process for decrypting the ciphertext C as an input block of the block cipher. An authentication cipher method in which the computer generates the authenticator Tag by using the further updated secret value B.
17. An initial process for generating the secret value B from the secret key in the authentication cipher. A function F process that updates the secret value B by using the block cipher with the secret value B generated by the initial process as an input block of the block cipher. An authentication cipher process that executes at least one of an encryption process for encrypting the plaintext M and a decryption process for decrypting the ciphertext C by using the secret value B updated by the function F process. Performing In the function F process, the secret value B used in the encryption process for encrypting the plaintext M or the decryption process for decrypting the ciphertext C by the authentication cipher process is used as an input block of the block cipher, and the secret value B is further updated by the block cipher. Furthermore An authentication process for generating the authenticator Tag by using the secret value B further updated by the function F process An authentication cipher program that causes a computer to function as an authentication cipher device that performs the above processes.