Encryption processing method, program, and encryption processing system
By storing a subset of intermediate parameters in internal storage and utilizing external storage for lattice cryptosystems, the memory and processing challenges of IoT devices are addressed, enhancing security and efficiency.
Patent Information
- Application Number
- PCT/JP2024/029932
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-24
- Filing Date
- 2024-08-23
- Publication Date
- 2025-07-10
AI Technical Summary
Lattice cryptosystems face challenges in IoT devices due to high memory usage, particularly in SRAM and DRAM, making it difficult to implement due to limited storage capacity, and existing solutions either increase information leakage risk or processing load.
Store only a part of the intermediate parameters in the internal storage device and utilize external storage for the remaining parameters, classifying or dividing them based on device performance and storage capacity, reducing memory usage and processing time.
Reduces internal storage usage and improves resistance to information leakage while maintaining efficient processing times in IoT devices.
Smart Images

Figure JP2024029932_10072025_PF_FP_ABST
Abstract
Description
Cryptographic processing method, program, and cryptographic processing system
[0001] The present disclosure relates to a cryptographic processing method, a program, and a cryptographic processing system.
[0002] Non-Patent Document 1 discloses CRYSTALS-Dilithium, which is a type of encryption technology.
[0003] Non-Patent Document 2 discloses Dilithium, a type of encryption technology.
[0004] Bai. S. , Ducas. L. , Kiltz. E. , Lepoint. T. , Lyubashevsky. V. , Schwabe. P. , Seiler. G. , & Stehle. D. (2021), CRYSTALS-Dilithium Algorithm Specifications and Supporting Documentation (Version 3.1). Specification document (update from February 2021). Greconici. D. O. C. .. , Kannwischer. M. J. .. , & Sprenkels. A. (2020). Compact Dilithium Implementations on Cortex-M3 and Cortex-M4. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021 (1), 1-24.
[0005] The present disclosure provides an encryption processing method and the like that can easily reduce the amount of internal storage used by a device when using a lattice cryptography method.
[0006] In a cryptographic processing method according to one aspect of the present disclosure, first intermediate parameters that are part of intermediate parameters used in the process of executing an algorithm using lattice cryptography are stored in an internal storage device of a device, and when executing the algorithm, the cryptographic processing method executes the algorithm using a second intermediate parameter other than the first intermediate parameter among the intermediate parameters, and the first intermediate parameter read from the internal storage device.
[0007] Furthermore, a program according to one aspect of the present disclosure causes one or more processors to execute the cryptographic processing method.
[0008] According to another aspect of the present disclosure, there is provided a cryptographic processing system including an internal storage device and a computing device. The computing device stores, in the internal storage device, first intermediate parameters that are part of intermediate parameters used in an algorithm using lattice cryptography. When executing the algorithm, the computing device executes the algorithm using a second intermediate parameter other than the first intermediate parameter among the intermediate parameters, and the first intermediate parameter read from the internal storage device.
[0009] The present disclosure has the advantage that it is easy to reduce the amount of internal storage used by a device when executing an algorithm using a lattice cryptography method.
[0010] FIG. 1 is a diagram illustrating a problem when a lattice cryptography method is used in an IoT device. FIG. 2 is a diagram illustrating a problem when a lattice cryptography method is used in an IoT device by the means disclosed in Non-Patent Document 2. FIG. 3 is a diagram illustrating an overview of a cryptographic processing method according to an embodiment. FIG. 4 is a diagram illustrating an overview of classification and division of intermediate parameters. FIG. 5 is a diagram illustrating an overview of pre-processing. FIG. 6 is a block diagram illustrating an example of the functional configuration of a table creation device according to an embodiment. FIG. 7 is a diagram illustrating an example of an intermediate parameter table. FIG. 8 is a diagram illustrating an example of a processing time upper limit table. FIG. 9 is a block diagram illustrating an example of the functional configuration of an IoT device according to an embodiment. FIG. 10 is a block diagram illustrating an example of the functional configuration of a cryptographic processing system according to an embodiment. FIG. 11 is a block diagram illustrating an example of the functional configuration of a signature generation device according to an embodiment. FIG. 12 is a sequence diagram illustrating a first operation example of an IoT device according to an embodiment. FIG. 13 is a sequence diagram illustrating a second operation example of an IoT device according to an embodiment.
[0011] (Knowledge forming the basis of the present disclosure) Lattice cryptography is known as one type of public key cryptography. Compared to other cryptography methods such as Rivest-Shamir-Adleman (RSA) or Elliptic Curve Digital Signature Algorithm (ECDSA), lattice cryptography has advantages such as quantum resistance and fully homomorphism. However, lattice cryptography imposes a heavy processing load when used, and requires a large amount of memory, particularly static random access memory (SRAM) or dynamic random access memory (DRAM), making it difficult to implement in Internet of Things (IoT) devices with relatively small storage capacities.
[0012] Fig. 1 is an explanatory diagram of the issues that arise when a lattice cryptography method is used in an IoT device. In the example shown in Fig. 1, the IoT device includes a CPU (Central Processing Unit), a memory, and a flash ROM (Read Only Memory). The memory is an internal storage device built into the IoT device, and the flash ROM is an external storage device connected to the IoT device. When a lattice cryptography method is used in an IoT device, in a standard method, the CPU performs a process of generating intermediate parameters when a signature generation algorithm or a signature verification algorithm is executed for the first time in the IoT device.
[0013] Here, intermediate parameters are parameters generated within an algorithm and are values used in the process of calculating an output value using an input value in the algorithm. The input value here is, for example, a private key, a public key, or a seed value. Note that, as will be described later, the intermediate parameters are configured as matrices whose elements are polynomials over a finite field. Furthermore, the intermediate parameters are different for each of the signature generation algorithm and the signature verification algorithm. In other words, the intermediate parameters include both parameters for the signature generation algorithm and parameters for the signature verification algorithm.
[0014] The intermediate parameters generated by the CPU are stored in memory (internal storage device). Then, when the CPU executes either the signature generation algorithm or the signature verification algorithm, it reads the intermediate parameters corresponding to the algorithm from memory and uses the intermediate parameters. Therefore, in standard means, the intermediate parameters, which require a large amount of memory, must be stored in memory, making it difficult to use lattice cryptography in IoT devices with relatively small storage capacities.
[0015] Non-Patent Document 2 discloses a means for solving the problems of the above-mentioned standard means, but the means disclosed in Non-Patent Document 2 still fails to solve the problems when a lattice cryptography method is used in an IoT device. Figure 2 is an explanatory diagram of the problems when a lattice cryptography method is used in an IoT device with the means disclosed in Non-Patent Document 2. Non-Patent Document 2 discloses a first means (see (1) in Figure 2) and a second means (see (2) in Figure 2) as means for solving the problems of the above-mentioned standard means.
[0016] In the first means, the CPU stores intermediate parameters generated in advance when executing the signature generation algorithm or the signature verification algorithm in a flash ROM (external storage device) rather than in a memory (internal storage device). Therefore, in the first means, the intermediate parameters can be stored in a flash ROM, which has looser restrictions on storage capacity than a memory, and therefore there is no need to store the intermediate parameters in a memory.
[0017] In the second means, the CPU generates intermediate parameters from the seed value each time the signature generation algorithm or the signature verification algorithm is executed, thereby eliminating the need to store the intermediate parameters in memory.
[0018] However, both the first and second methods have the following problem. That is, the intermediate parameters stored in a flash ROM (external storage device) by the first method include information such as the signer's private key. Therefore, the first method has the problem of being less resistant to information leakage than standard methods that store intermediate parameters in memory (internal storage device). Note that, while measures such as providing a storage area using TrustZone (registered trademark) in the flash ROM can be considered to increase resistance to information leakage, there is a problem that this tends to increase costs.
[0019] The second method has a problem in that intermediate parameters must be generated each time the signature generation algorithm or signature verification algorithm is executed, which increases the processing load on the CPU and tends to lengthen the processing time.
[0020] In view of the above, the present disclosure aims to provide a cryptographic processing method and the like that can easily reduce memory usage when using a lattice cryptography method by storing only a portion of intermediate parameters in memory (internal storage device).
[0021] More specifically, in the cryptographic processing method according to the first aspect of the present disclosure, a first intermediate parameter, which is part of the intermediate parameters used in the process of executing an algorithm using a lattice cryptography method, is stored in an internal storage device possessed by the device, and when executing the algorithm, the algorithm is executed using a second intermediate parameter other than the first intermediate parameter among the intermediate parameters, and the first intermediate parameter read from the internal storage device.
[0022] This has the advantage that instead of storing all intermediate parameters in the internal storage device, only some of the intermediate parameters (first intermediate parameters) are stored in the internal storage device, making it easier to reduce the amount of internal storage used by the device when executing an algorithm using a lattice cryptography method.
[0023] Also, for example, in a cryptographic processing method according to a second aspect of the present disclosure, in the first aspect, the intermediate parameters are composed of a matrix whose elements are polynomials over a finite field, and each has a plurality of parameters classified by the number of rows or the number of columns, and the first intermediate parameter includes a parameter classified from the plurality of parameters.
[0024] This has the advantage that the intermediate parameters composed of matrices are classified into first intermediate parameters and second intermediate parameters, making it easier to treat the first intermediate parameters and the second intermediate parameters as the original intermediate parameters when executing the algorithm, making it easier to execute the algorithm.
[0025] Also, for example, in a cryptographic processing method according to a third aspect of the present disclosure, in the first aspect, the intermediate parameters are composed of a matrix whose elements are polynomials over a finite field, and the first intermediate parameters include parameters obtained by dividing the matrix constituting the intermediate parameters by a predetermined number of rows or columns.
[0026] This has the advantage that the intermediate parameters, which are composed of matrices, are divided into first intermediate parameters and second intermediate parameters, making it easier to treat the first intermediate parameters and the second intermediate parameters as the original intermediate parameters when executing the algorithm, making it easier to execute the algorithm.
[0027] Also, for example, in a cryptographic processing method according to a fourth aspect of the present disclosure, in any one of the first to third aspects, the second intermediate parameters are stored in an external storage device connected to the device, and when the algorithm is executed, the second intermediate parameters are read from the external storage device.
[0028] This allows intermediate parameters, such as the signer's private key information, that cannot be leaked to be stored in the internal storage device, and the remaining parameters to be stored in the external storage device, which has the advantage of reducing the amount of internal storage used while making it easier to improve resistance to information leaks.
[0029] Furthermore, for example, in the cryptographic processing method according to the fifth aspect of the present disclosure, in any one of the first to third aspects, when the algorithm is executed, a second intermediate parameter is calculated and generated.
[0030] This method calculates only some of the intermediate parameters rather than all of them when the algorithm is executed, which has the advantage of reducing the amount of internal storage used and making it easier to shorten the processing time for calculating the intermediate parameters.
[0031] Also, for example, in a cryptographic processing method relating to a sixth aspect of the present disclosure, in any one of the first to fifth aspects, the first intermediate parameter and the second intermediate parameter are determined based on the processing capacity of the device and the available storage capacity of the internal storage device.
[0032] This has the advantage that the first intermediate parameters and the second intermediate parameters are determined according to the performance of the device, making it easy to store an appropriate amount of the first intermediate parameters in the internal storage device of the device.
[0033] Furthermore, for example, in a cryptographic processing method according to a seventh aspect of the present disclosure, in the sixth aspect, the first intermediate parameter and the second intermediate parameter are determined by referring to an intermediate parameter table, which indicates a correlation between the amount of internal storage used when executing an algorithm, the processing time required to execute the algorithm, and the amount of some intermediate parameters stored in either the internal storage or an external storage connected to the device.
[0034] This has the advantage that the first intermediate parameters and the second intermediate parameters are determined by referring to an intermediate parameter table according to the performance of the device, making it easier to store an appropriate amount of the first intermediate parameters in the device's internal memory device.
[0035] Also, for example, in the cryptographic processing method according to the eighth aspect of the present disclosure, in the seventh aspect, the maximum amount of parameters that can be stored in either the internal storage device or the external storage device is determined based on at least one of the purpose of the device, the environment in which the device is used, and the security requirements indicating the degree of security required of the device, and an intermediate parameter table is created based on the determined maximum amount of parameters.
[0036] This has the advantage that since the intermediate parameter table is created in accordance with the specifications of the device, it is easy to store an appropriate amount of first intermediate parameters in the internal storage device of the device.
[0037] Also, for example, a program according to a ninth aspect of the present disclosure causes one or more processors to execute the cryptographic processing method according to any one of the first to seventh aspects.
[0038] This has the advantage that instead of storing all intermediate parameters in the internal storage device, only some of the intermediate parameters (first intermediate parameters) are stored in the internal storage device, making it easier to reduce the amount of internal storage used by the device when executing an algorithm using a lattice cryptography method.
[0039] Furthermore, for example, a cryptographic processing system according to a tenth aspect of the present disclosure includes an internal storage device and a computing device. The computing device stores in the internal storage device first intermediate parameters that are part of intermediate parameters used in an algorithm using lattice cryptography, and when executing the algorithm, executes the algorithm using a second intermediate parameter other than the first intermediate parameter among the intermediate parameters, and the first intermediate parameter read from the internal storage device.
[0040] This has the advantage that instead of storing all intermediate parameters in the internal storage device, only some of the intermediate parameters (first intermediate parameters) are stored in the internal storage device, making it easier to reduce the amount of internal storage used by the device when executing an algorithm using a lattice cryptography method.
[0041] Furthermore, these comprehensive or specific aspects may be realized in a system, an apparatus, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or may be realized in any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a recording medium.
[0042] Hereinafter, embodiments will be described in detail with reference to the drawings. Note that the embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, or step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not recited in independent claims will be described as optional components. Note that each figure is a schematic diagram and is not necessarily an exact illustration. Furthermore, in each figure, substantially identical components are assigned the same reference numerals, and duplicated descriptions may be omitted or simplified.
[0043] (Embodiments) [1. Overview] First, an overview of a cryptographic processing method (cryptographic processing system) according to an embodiment will be described. Fig. 3 is a diagram for explaining the overview of the cryptographic processing method according to an embodiment. Fig. 3(a) is a diagram for explaining the overview of a first method of the cryptographic processing method according to an embodiment, and Fig. 3(b) is a diagram for explaining the overview of a second method of the cryptographic processing method according to an embodiment. The device shown in Fig. 3 (here, an IoT device) includes a CPU, a memory, and a flash ROM, similar to the example shown in Fig. 1.
[0044] In both the first and second methods of the cryptographic processing method according to the embodiment, first intermediate parameters, which are part of the intermediate parameters used in an algorithm using lattice cryptography (here, a signature generation algorithm or a signature verification algorithm), are stored in a memory (internal storage device) of the IoT device. That is, unlike the standard means described above, the cryptographic processing method according to the embodiment stores only part of the intermediate parameters (first intermediate parameters) in memory rather than storing all of the intermediate parameters in memory.
[0045] Here, as already mentioned, the intermediate parameters are configured as matrices whose elements are polynomials over a finite field. The inventors of the present application have noticed that the intermediate parameters configured as matrices can be classified or divided in the manner shown in FIG.
[0046] 4 is a diagram for explaining an outline of classification and division of intermediate parameters. As shown in FIG. 4, the intermediate parameters are classified by the number of rows or the number of columns (here, the number of rows). 1 , mp 2 , ... (in the figure, two parameters mp 1 , mp 2 In the example shown in FIG. 1 is composed of a matrix with k rows and n columns (k and n are natural numbers), and the parameter mp 2 is composed of a matrix with l rows and n columns (l is a natural number and l≠k).
[0047] When classifying the intermediate parameters, the first intermediate parameter includes a parameter classified from the plurality of parameters. In the example shown in FIG. 4, the intermediate parameter (parameter mp 1 , mp 2 ), for example, the first intermediate parameter is the parameter mp 1 In this case, the second intermediate parameter other than the first intermediate parameter among the intermediate parameters is the parameter mp 2 This becomes:
[0048] In addition, when dividing the intermediate parameters, the first intermediate parameters include parameters obtained by dividing the matrix constituting the intermediate parameters by a predetermined number of rows or columns. 1 , mp 2 ), for example, the first intermediate parameter is a parameter mp consisting of a matrix of m rows (m is a natural number, 1≦m<k+l) among the intermediate parameters, which are a matrix of k+l rows in total. 11 In this case, the second intermediate parameters are the parameters consisting of the remaining k+l-m rows of the matrix (parameters mp 12 , mp 2)
[0049] 3 , in both the first method and the second method, when the IoT device executes the signature generation algorithm or the signature verification algorithm for the first time, the CPU executes a process of generating intermediate parameters. In the first method, as shown in (a) of FIG. 3 , the CPU classifies or divides the generated intermediate parameters into first intermediate parameters and second intermediate parameters, stores the first intermediate parameters in memory (internal storage device), and stores the second intermediate parameters in flash ROM (external storage device). Then, when the CPU executes either the signature generation algorithm or the signature verification algorithm, it reads the first intermediate parameters corresponding to that algorithm from memory and reads the second intermediate parameters corresponding to that algorithm from flash ROM, thereby using the intermediate parameters.
[0050] 3(b), the CPU classifies or divides the intermediate parameters into first and second intermediate parameters and stores the first intermediate parameters in memory (internal storage device). When executing either the signature generation algorithm or the signature verification algorithm, the CPU reads the first intermediate parameters corresponding to the algorithm from memory and calculates and generates the second intermediate parameters corresponding to the algorithm, thereby using the intermediate parameters.
[0051] As described above, in the cryptographic processing method (cryptographic processing system) according to the embodiment, instead of storing all of the intermediate parameters in memory (internal storage device), only some of the intermediate parameters (first intermediate parameters) are stored in memory, which has the advantage of making it easier to reduce memory usage when executing an algorithm using a lattice cryptography method.
[0052] [2. Pre-processing] Next, a description will be given of pre-processing that is performed on a device (here, an IoT device) that is equipped with the cryptographic processing system according to the embodiment when using the cryptographic processing system. In the embodiment, the pre-processing includes a process of creating an intermediate parameter table and a processing time upper limit table using the table creation device 100 (see FIG. 5 ), and a process of storing the created intermediate parameter table and processing time upper limit table in the IoT device 200 (see FIG. 5 ).
[0053] The table creation device 100 is realized by an information terminal such as a personal computer, a smartphone, or a tablet terminal. The IoT device 200 is a device that can be connected to the Internet, such as a home appliance such as an air conditioner or a washing machine. The IoT device 200 is not limited to a home appliance as long as it is a device that can be connected to the Internet. Furthermore, the device is not limited to the IoT device 200, and may be a device that can communicate with other devices via a network such as the Internet.
[0054] Here, the intermediate parameter table is a data table showing the correlation between the memory usage used when executing an algorithm using lattice cryptography, the processing time required to execute the algorithm, and the amount of some intermediate parameters stored in either memory (internal storage device) or flash ROM (external storage device). Furthermore, the processing time upper limit table is a data table showing the correlation between the upper limit of processing time required to execute an algorithm using lattice cryptography and the function that executes the algorithm. Details of the intermediate parameter table and the processing time upper limit table will be described later.
[0055] FIG. 5 is a diagram illustrating an overview of the pre-processing. As shown in FIG. 5, when manufacturing the IoT device 200, a manufacturer that produces the IoT device 200 inputs the specifications of the IoT device 200 into the table creation device 100, thereby creating an intermediate parameter table and a processing time upper limit table to be stored in the IoT device 200. The table creation device 100 creates the intermediate parameter table and the processing time upper limit table while operating the IoT device 200. Next, the table creation device 100 stores the created intermediate parameter table and the processing time upper limit table in a storage device possessed by the IoT device 200. At this time, the table creation device 100 also stores the created intermediate parameter table and the processing time upper limit table in a server 300 that manages the IoT device 200 by, for example, updating firmware used in the IoT device 200. Then, when the IoT device 200 is shipped and sold, the user owns the IoT device 200 in which the intermediate parameter table and the processing time upper limit table are stored in a storage device, i.e., the IoT device 200 has been pre-processed.
[0056] 6 is a block diagram showing an example of the functional configuration of a table creation device 100 according to an embodiment. The table creation device 100 includes a processor and a memory, and realizes its functions by the processor executing a program stored in the memory. As shown in FIG. 6, the table creation device 100 includes a specification acquisition unit 101, an operation instruction unit 102, an intermediate parameter table creation unit 103, an intermediate parameter table output unit 104, a processing time upper limit determination unit 105, a processing time upper limit table creation unit 106, and a processing time upper limit table output unit 107.
[0057] The specification acquisition unit 101 receives input of specifications for the IoT device 200. The specifications describe, for example, the storage capacity of the memory (internal storage device) of the IoT device 200, the capacity of the flash ROM (external storage device), and the storage capacity of a storage area in the flash ROM that uses TrustZone (registered trademark). The specifications also describe, for example, the purpose, usage environment, and safety requirements of the IoT device 200. The safety requirements indicate the degree of safety (i.e., resistance to information leakage) required of the IoT device 200.
[0058] The operation command unit 102 commands the IoT device 200 to execute a predetermined operation. The predetermined operation is a process of generating a predetermined amount of parameters from the intermediate parameters. Here, the predetermined amount refers to several row components or several column components of a matrix that constitutes the intermediate parameters. This makes it possible to calculate the memory usage when a predetermined amount of parameters is stored in the memory (internal storage device) of the IoT device 200, and the processing time required for processing using the predetermined amount of parameters. The calculated memory usage and processing time are referenced by the intermediate parameter table creation unit 103 as data associated with the predetermined amount of parameters. The operation command unit 102 commands the IoT device 200 to repeatedly execute the predetermined operation while changing the predetermined amount.
[0059] The intermediate parameter table creation unit 103 creates the intermediate parameter table by referring to the specifications acquired by the specification acquisition unit 101 and the above data calculated by the IoT device 200 by issuing an instruction to the IoT device 200 by the operation instruction unit 102. In the embodiment, the intermediate parameter table creation unit 103 creates an intermediate parameter table to be referenced in a first method of the cryptographic processing method and an intermediate parameter table to be referenced in a second method of the cryptographic processing method.
[0060] 7A and 7B are diagrams showing examples of intermediate parameter tables. Fig. 7A shows an intermediate parameter table to be referenced when using the first cryptographic processing method and classifying the intermediate parameters into first and second intermediate parameters. Fig. 7B shows an intermediate parameter table to be referenced when using the first cryptographic processing method and dividing the intermediate parameters into first and second intermediate parameters. Fig. 7C shows an intermediate parameter table to be referenced when using the second cryptographic processing method and classifying the intermediate parameters into first and second intermediate parameters. Fig. 7D shows an intermediate parameter table to be referenced when using the second cryptographic processing method and dividing the intermediate parameters into first and second intermediate parameters.
[0061] 7A shows the correlation between the memory usage and processing time and the number of rows (or columns) when intermediate parameters having a number of rows (or a number of columns) are stored in a flash ROM. The numerical values for "rows" and "columns" in FIG. 7A correspond to "a" above.
[0062] 7B shows the correlation between the memory usage and processing time and the number of rows (or columns) when the intermediate parameters are divided into b rows from the top (or b columns from the left) and stored in a flash ROM. The numerical values for "rows" and "columns" in FIG. 7B correspond to "b" above.
[0063] 7C shows the correlation between the memory usage and processing time and the number of rows (or columns) when intermediate parameters having c rows (or c columns) are stored in memory. The numerical values for "rows" and "columns" in FIG. 7C correspond to "c" above.
[0064] 7D shows the correlation between the memory usage and processing time and the number of rows (or columns) when the intermediate parameters are divided into d rows from the top (or d columns from the left) and stored in memory. The numerical values for "rows" and "columns" in FIG. 7D correspond to "d" above.
[0065] An example of creating an intermediate parameter table will be described below. Here, it is assumed that the intermediate parameters are configured as a matrix of 30 rows and 30 columns in total.
[0066] First, an example of creating an intermediate parameter table referenced by the first method of the cryptographic processing method will be described. In the first method, some of the intermediate parameters are stored in the external storage device 224, and the intermediate parameters include information such as the signer's private key. Therefore, the intermediate parameter table creation unit 103 determines the maximum amount (maximum number of rows or maximum number of columns) of the intermediate parameters that can be stored in the external storage device 224 (second intermediate parameters) based on the specifications of the IoT device 200, and generates an intermediate parameter table based on the determined maximum amount.
[0067] Specifically, the intermediate parameter table creation unit 103 determines the maximum amount of the second intermediate parameters based on, for example, the following calculation algorithm. Here, it will be described that the maximum amount of the second intermediate parameters is the maximum number of rows. The calculation algorithm is based on the following conditions: (1) the amount of usage (ROM usage) when the second intermediate parameters are stored in the external storage device 224 is equal to or less than the storage capacity of the external storage device 224, (2) the amount of ROM usage is equal to or less than the size of TrustZone (registered trademark), (3) if the use of the IoT device 200 is a "home appliance," the maximum number of rows is 20 rows or less, (4) if the use of the IoT device 200 is a "camera," the maximum number of rows is 15 rows or less, and (5) if the use environment of the IoT device 200 is "indoors," the maximum number of rows is 15 rows or less. The maximum amount of the second intermediate parameter that satisfies a total of nine conditions is determined: (1) the maximum number of lines is 20 lines or less; (2) the maximum number of lines is 15 lines or less when the usage environment of the IoT device 200 is "outdoors"; (3) the maximum number of lines is 20 lines or less when the safety requirement of the IoT device 200 is "Level 1"; (4) the maximum number of lines is 15 lines or less when the safety requirement of the IoT device 200 is "Level 2"; and (5) the maximum number of lines is 10 lines or less when the safety requirement of the IoT device 200 is "Level 3." Note that the uses of (3) and (4) are not limited to these and may be other uses, and the numerical values are not limited to these and may be other values. Furthermore, the usage environments of (5) and (6) are not limited to these and may be other usage environments, and the numerical values are not limited to these and may be other values. Furthermore, the safety requirements of (7) to (9) are not limited to these and may be other requirements, and the numerical values are not limited to these and may be other values.
[0068] Furthermore, the calculation algorithm does not have to determine the maximum amount of the second intermediate parameter based on all of the use, usage environment, and safety requirements of the IoT device 200, but may determine the maximum amount of the second intermediate parameter based on at least one of the use, usage environment, and safety requirements.
[0069] As a specific example, assume that the storage capacity of the external storage device 224 is 100 MB, the size of TrustZone (registered trademark) is 50 MB, the purpose of the IoT device 200 is "home appliance," the usage environment is "outdoors," and the safety requirement is "Level 1." Also assume that the ROM usage increases by 5 MB every time one row of parameters is stored in the external storage device 224. In this case, the intermediate parameter table creation unit 103 determines the maximum number of second intermediate parameters (here, the maximum number of rows) to be 10 rows, and creates an intermediate parameter table based on the determined maximum number of second intermediate parameters.
[0070] Next, an example of creating an intermediate parameter table referenced by the second method of the cryptographic processing method will be described. In the second method, some intermediate parameters (first intermediate parameters) are stored in the internal storage device 223, and the remaining intermediate parameters (second intermediate parameters) are calculated when the algorithm is executed. Here, the storage capacity of the internal storage device 223 differs for each IoT device, and parameters that require a storage capacity larger than that of the internal storage device 223 cannot be stored in the internal storage device 223. For this reason, the intermediate parameter table creation unit 103 determines the maximum number (maximum number of rows or maximum number of columns) of intermediate parameters that can be stored in the internal storage device 223 based on the specifications of the IoT device 200 (particularly the storage capacity of the internal storage device 223 of the IoT device 200), and creates an intermediate parameter table based on the determined maximum number.
[0071] Specifically, the intermediate parameter table creation unit 103 determines the maximum amount of the first intermediate parameters based on, for example, the following calculation algorithm. Here, it is assumed that the maximum amount of the first intermediate parameters is the maximum number of rows. The calculation algorithm determines the maximum amount of the first intermediate parameters that satisfies the condition that the memory usage when the first intermediate parameters are stored in the internal storage device 223 is equal to or less than the storage capacity of the internal storage device 223.
[0072] As a specific example, assume that the storage capacity of the internal storage device 223 is 10,000 bytes. Also assume that the memory usage increases by 1,000 bytes each time one row of parameters is stored in the internal storage device 223. In this case, the intermediate parameter table creation unit 103 determines the maximum amount of first intermediate parameters (here, the maximum number of rows) to be 10 rows, and creates an intermediate parameter table based on the determined maximum amount of first intermediate parameters.
[0073] The intermediate parameter table output unit 104 outputs the intermediate parameter table created by the intermediate parameter table creation unit 103. In the embodiment, the intermediate parameter table output unit 104 outputs the intermediate parameter table to each of the IoT device 200 and the server 300.
[0074] The processing time upper limit determination unit 105 determines the upper limit of the processing time for each function executed by the IoT device 200 based on the specifications acquired by the specification acquisition unit 101 .
[0075] The processing time upper limit table creation unit 106 creates a processing time upper limit table based on the upper limit of the processing time for each function determined by the processing time upper limit determination unit. FIG. 8 is a diagram showing an example of the processing time upper limit table. In the example shown in FIG. 8, the processing time upper limit table indicates the upper limit of the processing time for the "firmware update" function, the upper limit of the processing time for the "device-to-device communication" function, and the upper limit of the processing time for the "router-to-router communication" function. The "firmware update" function is a function that executes an algorithm using lattice cryptography (here, a signature generation algorithm) when updating firmware. The "device-to-device communication" function is a function that executes an algorithm using lattice cryptography when communicating with other devices. The "router-to-router communication" function is a function that executes an algorithm using lattice cryptography when communicating with a router.
[0076] The processing time upper limit table output unit 107 outputs the processing time upper limit table created by the processing time upper limit table creation unit 106. In the embodiment, the processing time upper limit table output unit 107 outputs the processing time upper limit table to each of the IoT device 200 and the server 300.
[0077] [3. Configuration] Next, an overall configuration including a cryptographic processing system according to an embodiment will be described. In the embodiment, the computing device 220 included in the IoT device 200 corresponds to the cryptographic processing system. Fig. 9 is a block diagram showing an example of the functional configuration of the IoT device 200 according to the embodiment. As shown in Fig. 9, the IoT device 200 includes an input device 210, a computing device 220, an output device 230, and a processing device 240.
[0078] When sending a message to another device, the input device 210 accepts input of data related to the message. In an embodiment, the input device 210 accepts input of the message, a private key corresponding to the message, and information indicating a function corresponding to the message. Furthermore, when receiving a message from another device, the input device 210 acquires data related to the message. In an embodiment, the input device 210 acquires the message, a public key corresponding to the message, a signature corresponding to the message, and information indicating a function corresponding to the message.
[0079] The computing device 220 includes a processor such as a CPU and a memory, and realizes its functions by the processor executing a program stored in the memory. The computing device 220 executes various algorithms using lattice cryptography. In this embodiment, the computing device 220 is configured to be able to execute a signature generation algorithm and a signature verification algorithm. FIG. 10 is a block diagram showing an example of the functional configuration of a cryptographic processing system (computing device 220) according to this embodiment. As shown in FIG. 10, the computing device 220 includes a signature generation device 221, a signature verification device 222, an internal storage device 223, and an external storage device 224.
[0080] The signature generation device 221 executes a signature generation algorithm using lattice cryptography to generate a signature for a message received by the input device 210. Fig. 11 is a block diagram showing an example of the functional configuration of the signature generation device 221 according to the embodiment. As shown in Fig. 11, the signature generation device 221 includes a random number generation unit 221A, a signature generation unit 221B, a determination unit 221C, an adjustment unit 221D, and an output unit 221E.
[0081] The random number generation unit 221A generates random numbers by executing an appropriate random number generation algorithm using a random number seed stored in advance in the internal storage device 223, for example.
[0082] The signature generation unit 221B generates a signature by executing a signature generation algorithm of the lattice cryptography using the random numbers generated by the random number generation unit 221A.
[0083] In the embodiment, when the first cryptographic processing method is used, the signature generation unit 221B executes the signature generation algorithm using intermediate parameters (first intermediate parameters and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and reading the second intermediate parameters from the external storage device 224. When the second cryptographic processing method is used, the signature generation unit 221B executes the signature generation algorithm using intermediate parameters (first intermediate parameters and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and calculating and generating the second intermediate parameters.
[0084] The determination unit 221C determines how to divide the intermediate parameters into first intermediate parameters and second intermediate parameters. In this embodiment, the determination unit 221C determines the first intermediate parameters and the second intermediate parameters based on the processing capability of the IoT device 200 and the available storage capacity of the internal storage device 223. Specifically, before executing the signature generation algorithm, the determination unit 221C obtains the available storage capacity (hereinafter also referred to as "available memory amount") of the internal storage device 223, for example, by an instruction from the OS (Operating System). Furthermore, before executing the signature generation algorithm, the determination unit 221C obtains the upper limit of the processing time for the function that executes the signature generation algorithm by referring to a processing time upper limit table stored in the external storage device 224.
[0085] The determination unit 221C then acquires the intermediate parameter table stored in the external storage device 224 and determines the first and second intermediate parameters based on, for example, the following determination algorithm. The determination algorithm determines the parameters that satisfy seven conditions as the first intermediate parameters: (1) memory usage is smaller than the available memory amount; (2) processing time is shorter than the upper limit of the processing time; (3) classification is prioritized over division; (4) row-based division is prioritized over column-based division; (5) the first method is prioritized over the second method; (6) data with a small memory usage is selected from the intermediate parameter table; and (7) data with a short processing time is selected from the intermediate parameter table. The remaining parameters are determined as the second intermediate parameters. Note that at least one of the conditions (3), (4), and (5) may have the opposite priority. For example, the condition (3) may be a condition that classification is prioritized over division.
[0086] As a specific example, assume that the available memory capacity is 1000 bytes and the upper limit of the processing time is 200 ms. In this case, the determination unit 221C refers to the intermediate parameter table shown in Fig. 7A based on the conditions (3), (4), and (5), and determines the parameters classified into the top 10 rows of the intermediate parameters as first intermediate parameters and the remaining parameters as second intermediate parameters based on the conditions (1), (2), (6), and (7).
[0087] The adjustment unit 221D adjusts the intermediate parameters based on the method determined by the determination unit 221C. In this embodiment, the adjustment unit 221D classifies or divides the first intermediate parameters from the intermediate parameters using the method determined by the determination unit 221C, and sets the remaining intermediate parameters as second intermediate parameters. Then, when the determination unit 221C determines that the first cryptographic processing method will be used, the adjustment unit 221D stores the first intermediate parameters in the internal storage device 223 and stores the second intermediate parameters in the external storage device 224. Furthermore, when the determination unit 221C determines that the second cryptographic processing method will be used, the adjustment unit 221D stores the first intermediate parameters in the internal storage device 223.
[0088] The output unit 221E outputs the signature generated by the signature generation unit 221B. In the embodiment, the output unit 221E links the signature generated by the signature generation unit 221B to the message accepted by the input device 210 and outputs the signature to the output device 230.
[0089] The signature verification device 222 verifies a signature corresponding to a message received by the input device 210 by executing a signature verification algorithm using a lattice cryptography system. In this embodiment, when the first cryptographic processing method is used, the signature verification device 222 executes the signature verification algorithm using intermediate parameters (first and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and reading the second intermediate parameters from the external storage device 224. When the second cryptographic processing method is used, the signature verification device 222 executes the signature verification algorithm using intermediate parameters (first and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and calculating and generating the second intermediate parameters. Note that the determination of how to divide the intermediate parameters into the first and second intermediate parameters is similar to that of the signature generation device 221, and therefore will not be described here.
[0090] The internal storage device 223 is a storage device built into the IoT device 200, and is, for example, an SRAM or a DRAM. In the embodiment, the internal storage device 223 corresponds to the memory of the computing device 220. The internal storage device 223 stores a first intermediate parameter among the intermediate parameters. The internal storage device 223 also stores a random number seed used by the random number generation unit 221A.
[0091] The external storage device 224 is an external storage device connected to the IoT device 200, such as a flash ROM. In this embodiment, the external storage device 224 stores an intermediate parameter table and a processing time upper limit table. When the first encryption processing method is used, the external storage device 224 also stores a second intermediate parameter among the intermediate parameters.
[0092] When transmitting a message to another device, the output device 230 outputs the signature by transmitting a message affixed with the signature generated by the signature generation device 221 to the other device. If the IoT device 200 is equipped with a display, the output device 230 displays the signature on the display. When receiving a message from another device, the output device 230 outputs the verification result from the signature verification device 222 to the processing device 240. If the IoT device 200 is equipped with a display, the output device 230 displays the verification result on the display.
[0093] The processing device 240 includes a processor and a memory, and realizes its functions by the processor executing a program stored in the memory. The processing device 240 executes various processes related to the entire IoT device 200. For example, when the processing device 240 receives a message from another device, the processing device 240 determines whether to discard the message based on the verification result output from the output device 230. For example, if the verification result indicates that the signature is a fake, the processing device 240 discards the message.
[0094] [4. Operation] An example of the operation of the IoT device 200 according to the embodiment will now be described.
[0095] 12 is a sequence diagram showing a first operation example of the IoT device 200 according to the embodiment. The first operation example is executed when the IoT device 200 transmits a message to another device.
[0096] First, the input device 210 accepts input of data related to a message to be transmitted, including the message, a private key corresponding to the message, and information indicating a function corresponding to the message (S101).
[0097] Next, the signature generation device 221 of the computing device 220 acquires the available storage capacity (available memory amount) of the internal storage device 223, for example, by an instruction from the OS, before executing the signature generation algorithm (S102). Also, before executing the signature generation algorithm, the signature generation device 221 acquires the upper limit of the processing time by referring to the processing time upper limit table stored in the external storage device 224 (S103). Furthermore, before executing the signature generation algorithm, the signature generation device 221 acquires the intermediate parameter table stored in the external storage device 224 (S104).
[0098] Next, the signature generation device 221 references the acquired available memory amount, upper limit of processing time, and intermediate parameter table, and determines first and second intermediate parameters based on the determination algorithm (S105). The signature generation device 221 then generates a signature by executing the signature generation algorithm (S106). As already described, in the embodiment, when the first cryptographic processing method is used, the signature generation device 221 executes the signature generation algorithm using intermediate parameters (first and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and reading the second intermediate parameters from the external storage device 224. When the second cryptographic processing method is used, the signature generation device 221 executes the signature generation algorithm using intermediate parameters (first and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and calculating and generating the second intermediate parameters.
[0099] Then, the output device 230 outputs the signature by transmitting the message with the signature generated by the signature generation device 221 to another device (S107). Also, if the IoT device 200 has a display, the output device 230 displays the signature on the display (S107).
[0100] 13 is a sequence diagram showing a second operation example of the IoT device 200 according to the embodiment. The second operation example is executed when the IoT device 200 receives a message from another device.
[0101] First, the input device 210 acquires data related to a message to be received, including the message, the public key corresponding to the message, the signature corresponding to the message, and information indicating the function corresponding to the message (S201).
[0102] Next, the signature verification device 222 of the computing device 220 obtains the available storage capacity (available memory amount) of the internal storage device 223, for example, in response to an instruction from the OS, before executing the signature verification algorithm (S202). Also, before executing the signature verification algorithm, the signature verification device 222 obtains the upper limit of the processing time by referring to a processing time upper limit table stored in the external storage device 224 (S203). Furthermore, before executing the signature verification algorithm, the signature verification device 222 obtains the intermediate parameter table stored in the external storage device 224 (S204).
[0103] Next, the signature verification device 222 references the acquired available memory capacity, upper limit of processing time, and intermediate parameter table, and determines first and second intermediate parameters based on the judgment algorithm (S205). Then, the signature verification device 222 verifies the signature by executing the signature verification algorithm (S206). As already described, in the embodiment, when the first cryptographic processing method is used, the signature verification device 222 executes the signature verification algorithm using intermediate parameters (first and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and reading the second intermediate parameters from the external storage device 224. On the other hand, when the second cryptographic processing method is used, the signature verification device 222 executes the signature verification algorithm using intermediate parameters (first and second intermediate parameters) obtained by reading the first intermediate parameters from the internal storage device 223 and calculating and generating the second intermediate parameters.
[0104] Then, the output device 230 outputs the verification result from the signature verification device 222 (S207). Furthermore, if the IoT device 200 has a display, the output device 230 displays the verification result on the display (S207).
[0105] [5. Advantages] Advantages of the cryptographic processing method (cryptographic processing system) according to the embodiment will be described below. As described above, in the cryptographic processing method according to the embodiment, first intermediate parameters, which are part of the intermediate parameters used when executing an algorithm using a lattice cryptography system, are stored in advance in the internal storage device 223, and when executing the algorithm, the first intermediate parameters read from the internal storage device 223 and second intermediate parameters, which are the remaining intermediate parameters, are used to execute the algorithm.
[0106] Therefore, in the cryptographic processing method according to the embodiment, instead of storing all intermediate parameters in the internal storage device 223, only some of the intermediate parameters (first intermediate parameters) are stored in the internal storage device 223, which has the advantage of making it easier to reduce the amount of internal storage device 223 used by the device (IoT device 200) when executing an algorithm using a lattice cryptography method.
[0107] Furthermore, in the first method of the cryptographic processing method according to the embodiment, parameters that cannot be tolerated for information leakage, such as information on the signer's private key, among the intermediate parameters, can be stored in the internal storage device 223, and the remaining parameters can be stored in the external storage device 224. Therefore, compared to the first means disclosed in Non-Patent Document 2, the first method has the advantage of being able to easily improve resistance to information leakage while reducing the amount of usage of the internal storage device 223.
[0108] Furthermore, in the second method of the cryptographic processing method according to the embodiment, only some of the intermediate parameters are calculated during execution of the algorithm, rather than all of the intermediate parameters. Therefore, compared to the second means disclosed in Non-Patent Document 2, the second method has the advantage of being able to reduce the amount of usage of the internal storage device 223 while making it easier to shorten the processing time for calculating the intermediate parameters.
[0109] Other Embodiments Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.
[0110] In the above embodiment, how the intermediate parameters are divided into the first intermediate parameters and the second intermediate parameters may differ between the signature generation algorithm and the signature verification algorithm. Specifically, the intermediate parameter table and the processing time upper limit table referenced when executing the signature generation algorithm may be different from the intermediate parameter table and the processing time upper limit table referenced when executing the signature verification algorithm.
[0111] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.
[0112] In the above-described embodiments, each component may be realized by executing a software program suitable for that component. Each component may be realized by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0113] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.
[0114] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a method, an integrated circuit, a computer program, and a recording medium.
[0115] For example, the present disclosure may be realized as a cryptographic processing method executed by a computer, or as a program for causing a computer to execute the cryptographic processing method. The present disclosure may also be realized as a computer-readable non-transitory recording medium on which such a program is recorded.
[0116] In addition, this disclosure also includes forms obtained by applying various modifications to the embodiments that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of the embodiments within the scope that does not deviate from the intent of this disclosure.
[0117] The present disclosure is useful when performing encrypted communication in a device.
[0118] 100 Table creation device 101 Specification acquisition unit 102 Operation command unit 103 Intermediate parameter table creation unit 104 Intermediate parameter table output unit 105 Processing time upper limit determination unit 106 Processing time upper limit table creation unit 107 Processing time upper limit table output unit 200 IoT device 210 Input device 220 Calculation device 221 Signature generation device 221A Random number generation unit 221B Signature generation unit 221C Determination unit 221D Adjustment unit 221E Output unit 222 Signature verification device 223 Internal storage device 224 External storage device 230 Output device 240 Processing device 300 Server
Claims
1. A cryptographic processing method, wherein a device stores a first intermediate parameter, which is part of intermediate parameters used in the process of executing an algorithm using a lattice cipher method, in an internal storage device of the device, and when executing the algorithm, the device uses a second intermediate parameter other than the first intermediate parameter among the intermediate parameters and the first intermediate parameter read from the internal storage device to execute the algorithm.
2. The cryptographic processing method according to claim 1, wherein the intermediate parameters are composed of matrices having polynomials over a finite field as elements, and have a plurality of parameters classified by the number of rows or columns, and the first intermediate parameter includes parameters classified from the plurality of parameters.
3. The cryptographic processing method according to claim 1, wherein the intermediate parameters are composed of matrices having polynomials over a finite field as elements, and the first intermediate parameter includes parameters divided by a predetermined number of rows or columns among the matrices constituting the intermediate parameters.
4. The cryptographic processing method according to any one of claims 1 to 3, wherein the device stores the second intermediate parameter in an external storage device connected to the device, and when executing the algorithm, reads the second intermediate parameter from the external storage device.
5. The cryptographic processing method according to any one of claims 1 to 3, wherein when executing the algorithm, the device calculates and generates the second intermediate parameter.
6. The cryptographic processing method according to any one of claims 1 to 3, wherein the first intermediate parameter and the second intermediate parameter are determined based on the processing capacity of the device and the available storage capacity of the internal storage device.
7. The cryptographic processing method according to claim 6, wherein the first intermediate parameter and the second intermediate parameter are determined by referring to an intermediate parameter table, and the intermediate parameter table shows the correlation between the usage amount of the internal storage device used when executing the algorithm, the processing time required when executing the algorithm, and the amount of some of the intermediate parameters stored in either the internal storage device or an external storage device connected to the device.
8. Determine the maximum amount of parameters that can be stored in either the internal storage device or the external storage device based on at least one of the safety requirements indicating the use of the device, the usage environment of the device, and the degree of safety required for the device, and create the intermediate parameter table based on the determined maximum amount of parameters. The encryption processing method according to claim 7.
9. A program for causing one or more processors to execute the encryption processing method according to any one of claims 1 to 3.
10. An encryption processing system comprising an internal storage device and a computing device, wherein the computing device stores a first intermediate parameter, which is a part of intermediate parameters used in an algorithm using a lattice encryption method, in the internal storage device, and when executing the algorithm, executes the algorithm using a second intermediate parameter other than the first intermediate parameter among the intermediate parameters and the first intermediate parameter read from the internal storage device.
Citation Information
Patent Citations
Three-dimensional data processing system
JP1993101153A
Microcomputer and method for protecting its software
JP2007310601A
Information processing device and on-vehicle control device
JP2021157207A