One public key signature and encryption using butterfly key expansion

The use of Kyber and Dilithium-based butterfly key expansion in public key signature and encryption systems addresses the challenge of pseudonymity and unlinkability, providing secure and efficient pseudonymous certificate management against malicious authorities.

WO2025153955A1PCT designated stage expired Publication Date: 2025-07-24NAT RES COUNCIL OF CANADA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/050409
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-15
Filing Date
2025-01-14
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing public key signature and encryption systems face challenges in providing pseudonymity and unlinkability, especially in lattice-based systems like NTRU, where homomorphic structures between secret and public key domains are unclear, and there is a risk of trust in central authorities compromising anonymity.

Method used

Implementing butterfly key expansion using Kyber and Dilithium encryption and signature schemes, ensuring unlinkability and unforgeability by expanding public keys in a way that maintains secrecy and prevents linking to identities, even with malicious certificate and registration authorities.

Benefits of technology

The system achieves efficient and secure pseudonymous certificate management with reduced communication overhead, ensuring that expanded public keys cannot be linked to identities, even when faced with malicious entities, while maintaining high security standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025050409_24072025_PF_FP_ABST
    Figure IB2025050409_24072025_PF_FP_ABST
Patent Text Reader

Abstract

According to the invention a method and system are provided for one public key signature and encryption using butterfly key expansion by employing Kyber and Dilithium to support unlinkability and unforgeablity against malicious registration and certificate authorities, alone or in concert.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ONE PUBLIC KEY SIGNATURE AND ENCRYPTION USING BUTTERFLY KEY EXPANSION

[0002] FIELD OF THE INVENTION

[0003] This invention relates to signature and encryption and more specifically to signature and encryption via Butterfly Key Expansion (BKE).

[0004] BACKGROUND

[0005] Public key digital signatures are powerful and convenient tool to establish the authenticity of communications in a digital setting. Digital signatures are used to sign web pages, emails and programs. They form an important line of defense against cyberattacks such as phishing, man-in-the-middle, malware and supply chain attacks to name a few. Public keys form the identity on which signatures are verified. A valid signature o for a message m under a public key pk gives confidence that the holder of the corresponding private key sk did indeed sign m.

[0006] In practice, public keys are not useful identifiers compared to names, email addresses and URLs. So keys are bundled with other identification information. This bundle is then signed by a central authority to form a certificate. Anyone who trusts the certificate authority (CA) can validate the identity of certificate holders by storing only the CA’s public key. This widely deployed approach is known as the public-key infrastructure.

[0007] In conjunction with authenticity, public key signatures offer non-repudiability. If pk is associated with Alice’s identity through a valid CA certificate, any valid signature for a message m can be traced back to her and moreover, she can- not claim to not have signed m since only she should be able to produce valid signatures for pk. This is a problem when privacy or anonymity is desired. For example, one may consider a network where exchanges are authenticated (only authorized entities may send valid messages), but anonymous (messages can’t be linked to a given entity). To achieve such a functionality, the CA could issue many pseudonymous certificates to each entity, each with a different public key. Alice can then use her public key a few times before rotating to a new key. This has a big communication overhead if keys are rotated often since Alice must generate and send many public keys. A clever trick to save on bandwidth is to send a single public key and have the CA expand the key into multiple new public keys. If the signature scheme has some homomorphic property to its public keys, then Alice can derive the corresponding private key for each expanded public key. For example in ECDSA, key pairs are of the form sk = u and pk = u ■ G where G is a curve point. The CA expands pk by adding a new multiple of G, obtaining pk' = u ■ G + u' ■ G and signs pk'. If the CA sends pk' along with u' to Alice, she can compute u + u' as the corresponding secret key.

[0008] A downside to the above approach is that the CA is now trusted for both the authenticity and the anonymity of the scheme. This is remediated with the introduction of a new entity, the registration authority (RA), responsible for anonymizing requests sent to the CA, such that no single entity can break anonymity. In short, the RA assembles many public keys, does a first round of key expansion and shuffles the keys before sending them to the CA who expands them again and signs the resulting keys sending them back to the RA to forwards them to Alice. The issue is that the RA can now link expanded keys to identities, so Alice also sends her public key for an encryption scheme, which is expanded by the RA and used by the CA to encrypt the certificates. The resulting scheme is called butterfly key expansion (BKE).

[0009] Butterfly key expansion as a solution to the pseudonymity problem in certificate provisioning comes from a Security Credential Management System (SCMS) designed for V2V communication.

[0010] In one known technique of butterfly key expansion only one public key is sent and expanded upon. For discrete-logarithm based systems this is relatively straightforward, but becomes more challenging for lattice-based signing and key establishment. Even though public keys in many lattice-based protocols are module learning with errors samples, the parameters, rings, and distributions of values are tailored much more specifically than in discrete logarithm systems.

[0011] In another known technique based on a Ring-LWE signature scheme conceptually similar to Dilithium, the key exchange protocol was based on the Lyubashevsky-Peikert- Regev system, which is also part of the lineage of Kyber.

[0012] A more technique replaces elliptic curve cryptography with the post-quantum system NTRU in butterfly key expansion. The fundamental property that enables butterfly key expansion is a homomorphism between the secret key and public key domains, something which both LWE and discrete logarithm based solution enjoy. NTRU has no obvious homomorphic structure between its secret and public key domains, making it unclear precisely how butterfly key expansion with NTRU might operate.

[0013] SUMMARY

[0014] The invention disclosed herein provides for a method and system of signature and encryption amongst at least one RA and one CA comprising using butterfly key expansion for encryption using a single key, using butterfly key expansion for signature verification using the single key, and wherein the single key is made mathematically unlinkable and unforgeable against said RA and CA, alone and in combination.

[0015] As per disclosed in greater detail below, according to one aspect of the invention, unlinkability and unforgeability is derived from use of Kyber expansion and Dilithium expansion.

[0016] BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The drawings have not necessarily been drawn to scale. Similarly, some components and / or operations can be separated into different blocks or combined into a single block for the purposes of discussion of some of the implementations of the present technology. Moreover, while the technology is amenable to various modifications and alternative forms, specific implementations have been shown by way of example in the drawings and are described in detail below. The intention, however, is not to limit the technology to the particular implementations described. On the contrary, the technology is intended to cover all modifications, equivalents, and alternatives falling within the scope of the technology as defined by the appended claims.

[0018] Figure 1 shows a process of key processing according to the art.

[0019] Figure 2 shows a routine according to the invention.

[0020] Figure 3 shows a routine according to the invention.

[0021] Figure 4 shows a routine according to the invention.

[0022] Figure 5 shows parameters of the invention.

[0023] Figure 6 shows a routine according to the invention.

[0024] Figure 7 shows a routine according to the invention.

[0025] Figure 8 shows a routine according to the invention.

[0026] Figure 9 shows two routines according to the invention.

[0027] Figure 10 shows parameters of the invention.

[0028] DETAILED DESCRIPTION

[0029] In the following description, for the purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of implementations of the present technology. It will be apparent, however, to one skilled in the art that implementations of the present technology can be practiced without some of these specific details.

[0030] The design techniques introduced here can be implemented as special-purpose hardware (for example, circuitry), as programmable circuitry appropriately programmed with software and / or firmware, or as a combination of special-purpose and programmable circuitry. Hence, implementations can include a machine-readable medium having stored thereon instructions which can be used to program a computer (or other electronic devices) to perform a process. The machine-readable medium can include, but is not limited to, floppy diskettes, optical disks, compact disc read-only memories (CD-ROMs), magneto-optical disks, ROMs, random access memories (RAMs), erasable programmable read-only memories (EPROMs), electrically erasable programmable read-only memories (EEPROMs), magnetic or optical cards, flash memory, or other type of media / machine-readable medium suitable for storing electronic instructions.

[0031] The phrases “in some implementations,” “according to some implementations,” “in the implementations shown,” “in other implementations,” and the like generally mean the particular feature, structure, or characteristic following the phrase is included in at least one implementation of the present technology, and can be included in more than one implementation. In addition, such phrases do not necessarily refer to the same implementations or different implementations.

[0032] This invention provides variants of the Kyber and Dilithium encryption and signature schemes that allow for their public keys to be expanded, for the recovery of the secret key corresponding to the expanded public keys and for the encryption / decryption and signing / verification with respect to expanded public keys. When we instantiate the butterfly key expansion protocol with our variants, we obtain a certificate management system that improves upon previous works in a few key ways.

[0033] Variants, according to the invention, is based on Dilithium and Kyber, which have been selected for standardization by NIST. The protocol is minimalist. In this way, it benefits in part from the public scrutiny Dilithium and Kyber have received over the years, as well as the strong performance characteristics of the two. The end result is smaller, with the final encrypted package sent to vehicles taking around 2600 bytes less.

[0034] Variants, according to the invention, provide security definitions of unlinkability and unforgeability in the context of butterfly key expansion and prove that our scheme satisfies those definition, assuming the security of MLWE. Definitions take into account some subtle attacks that an adversary could potentially launch, like being able to see which expanded public keys a vehicle uses or doesn’t use, and whether that leaks identifying information. This level of detail in the security analysis was not present in prior works.

[0035] Unified Butterfly Key Expansion previous works introduced the unified variant of BKE, in which the expanded public keys are used for both encryption and signature verification. Reusing keys for different purposes is generally seen as unsafe. Described herein are types of signature and encryption schemes can be safely combined to use the same public key. Our results show that Dilithium and Kyber public keys can safely be used for both encryption and signature verification, as long as there exist sets of parameters where the public keys of both schemes are compatible.

[0036] We write X «— Bq as the following distribution: sample (a1 ,...,ar|,b1 ,...,br|) «— {0, 1 }2q uniformly at random and output X = Pr|=1 (ai - bi).

[0037] The hardness assumption on which both Kyber and Dilithium rely is the module learning with errors assumption.

[0038] Definition 1 (MLWE): Let Rq be the ring Zq[X] / (Xn + 1) of polynomials over Zq. The decisional module learning with errors problem (MLWE) consists of distinguishing a uniform sample (A,b) «— Rmxk x Rm from a sample (A,b) where A «— Rmxk is uniformly distributed and b = As + e where s «— Bqk and e «— Bpm. For any PPT algorithm A, we define AdvA-LWE as the advantage of adversary A in distinguishing both distributions.

[0039] Butterfly key expansion (BKE) was introduced in in the context of vehicle to vehicle (V2V) communications. The BKE process is a means to provision a vehicle with an arbitrary number of pseudonymous certificates in a way that satisfies two fundamental properties: 1 - The computational and communication burden on the vehicle is minimized: their role is limited to providing a single pair of public keys, and then receives the certified public keys.

[0040] 2 - Neither the Registration authority nor the certificate authority is capable of compromising the pseudonimity of the vehicle.

[0041] This is accomplished through the butterfly key expansion process. A single pair of caterpillar public keys (one for encryption, one for signing) is generated by the vehicle and provided to the Registration Authority (RA). The RA takes these keys and checks the vehicle’s eligibility to receive a collection of pseudonymous certificates. After this check, the single pair of caterpillar public keys (pko,pkK) are expanded into many public keys {(pkD , pkK,i)}ie[N]. This is done by pseudorandomly generating additional public keys and adding them with the caterpillar public keys. The key property to enable this is a homomorphism between the private and public key spaces. The result of adding together two public keys is still a public key, with the secret key corresponding to the sum of the two individual secret keys. The intent of this process is that the caterpillar public keys are entirely re-randomized, such that observing the resulting public keys reveals no information about the original, but such that the original caterpillar secret keys are still required to sign or decrypt messages. The RA is then meant to produce and collect a large number of these keys, from a large number of vehicles. The expanded public keys are then ‘shuffled’ with expanded public keys from many other vehicles to provide anonymity against the CA. This bundle of shuffled expanded key pairs is forwarded on to the certificate authority.

[0042] The certificate authority (CA) receives this bundle of key pairs, and is unable to link together any two pairs as coming from the same vehicle. The CA then expands each signing key once more using a random nonce Ti. This is done to ensure pseudonimity against the RA. The CA then creates a certificate for the expanded signing key pk'o . Note that the RA has never seen this public key, and the certificate authority has no way to connect one pseudonymous public key to another. The remaining task is to get the certificates and the final public keys back to the vehicle. The CA uses the expanded encryption key pkK, i to encrypts the certificate and the secret expansion nonce Ti associated with the (doubly) expanded signing public key pk'o , and sends the resulting ciphertexts back to the RA, so that the RA can sort the encrypted packages out and forward them to the correct vehicle.

[0043] Finally, the vehicle receives a collection of encrypted packages {pkgi}ie[N] from the RA. At this point, whenever they need a new pseudonymous key pair and certificate, they can derive the expanded encryption secret key, decrypt the package, and then derive the (doubly expanded) signature keypair.

[0044] Note that, In the unified variant of BKE, the same public key is used for both the signature and encryption schemes. Further, for M-LWE based schemes, the public keys are of the form As + e with private key s. Adding two public keys (with the same A matrix) yields (As + e) + (As' + e') = A(s + s') + (e + e') which has the associated private key s + s'.

[0045] This process is illustrated in Figure 1 . For the purpose of simplicity, this figure does not contain the important step of having the RA bundle and shuffle together expanded public keys from many vehicles. This is the step that provides unlinkability for the vehicle against the CA.

[0046] The two stated goals of security with respect to butterfly key expansion are that of unlinkability and unforgeability. Unlinkability refers to the scheme’s effectiveness at providing the expected level of pseudonymity. In other words, the resulting public keys and certificates (as well as any signatures issued under those public keys) cannot be ‘linked’ as having originated from the same vehicle, except possibly through the use of out-of-band data (for example, having observed the origin of two pseudonyms as being the same vehicle). The unlinkability property is meant to hold even against the registration authority and the certificate authority. It is easy to see that unlinkability cannot hold against a collaborating registration and certificate authority. We therefore can only prove unlinkability by making a non-collusion assumption between the RA and the CA.

[0047] Unforgeability refers to the idea that only the vehicle should be able to produce signatures for their public keys. For a system where we are concerned with the possibility of a malicious certificate authority, this poses something of a challenge in how we define what constitutes a public key belonging to a vehicle. A malicious CA can clearly make their own public key, create a certificate for it as if it belongs to a vehicle, and then create signatures all without the vehicle’s knowledge or interaction with the protocol. Indeed, this problem is not unique to SCMS and corrupted certificate authorities constitute a very real problem in general. For our purposes, the best we can hope for is that if the vehicle has accepted a butterfly public key as belonging to them (that is, they have reconstructed it at the end of the pseudonymous certificate provisioning process), then it must be the case that only they can craft signatures for such a key. Anyone else, including the CA, cannot create signatures for a public key that the vehicle might actually use. This helps to minimize the amount of trust that we place in the CA. Note however, that unforgeability does not require an assumption that the RA and the CA do not collude.

[0048] This results in essentially three security properties (and proofs) being needed- unlinkability against the CA, unlinkability against the RA, and unforgeability against the RA and CA collaborating. Note that these three models imply security in models with more restrictions. For example, if we are interested in unforgeability against just the RA, or against someone not involved in the certificate provisioning process, then this is implied by a proof that the RA and the CA together are unable to compromise unforgeability. Unlinkability against a Malicious Certificate Authority: For unlinkability against a malicious certificate authority, we ask that it should not be able to tell, given two certificates it emitted, whether they correspond to the same vehicle or not. Unlinkability against the CA is enforced by the random shuffling of the expanded keys that is performed by the registration authority.

[0049] To model unlinkability against the CA, we conceive a game between the malicious CA and a challenger. The challenger plays the role of both the vehicle and the RA: it generates Dilithium and Kyber keys for two vehicles, expands them as the RA would, shuffles them and sends them to the CA. The goal of the malicious CA is now to output a pair of indices (i,j) such that the expanded public key pairs (pkK .pkD ) and (pkKj.pkKj) originate from the same identity public key. To capture all possible strategies to the malicious CA in the packages it sends back to the RA, we give it access to a decryption oracle for the expanded Kyber keys and to a signature oracle for the expanded Dilithium keys.

[0050] To show that a malicious CA cannot win with probability much better than the trivial (n- 1 ) / (2n-1 ), we use the fact that Kyber and Dilithium are based on the Fujisaki-Okamoto and Fiat-Shamir transforms, respectively, to answer the oracle queries without access to the secret keys by using random oracle recording and reprogramming. Then, since the public keys are expanded using random MLWE samples, by the module learning with errors assumption all keys look uniformly random to the PPT malicious RA.

[0051] Unlinkability against a Malicious Registration Authority: For unlinkability against a malicious registration authority, we ask that it should not be able to distinguish whether two sets of expanded public keys with associated certificates belong to the same vehicle or to different vehicles.

[0052] We model this as a game (Definition 4) between a challenger and the ma- licious RA where the challenger takes the role of both vehicle and certificate authority. In the game, the challenger sends a pair of public keys (pkK,pko) to the malicious RA. Then, when the challenger receives a set of expanded keys from the RA, it either expands and produces certificates for the set of expanded keys {pko,i}i it receives or it samples a fresh public key pko, expands it as an honest RA would as {pk' D Ji and continue the execution as the CA and vehicle would using this set of expanded keys. If the malicious RA cannot distinguish between which course of action the challenger took, it means that it cannot distinguish between certificates for pko and for pk’D.

[0053] Unlinkability against the RA is enforced through the encryption of the certificates using the Kyber expanded public keys. Since the dilithium public keys sent from the RA to the CA are expanded again by the CA, they will look independent from the vehicle’s public key by the MLWE assumption. Because those keys are encrypted with the vehicle’s Kyber expanded keys before being sent to the RA, it will not be able to link an expanded Dilithium key with its certificate to the vehicle’s identify public key pko. To show this, we prove that Kyber still has ciphertext indistinguishability with respect to expanded public keys (Theorem 2).

[0054] Unforgeability: In the context of butterfly key expansion, we ask that the signature scheme used by the vehicle remains unforgeable even against actively colluding RA and CA. Observe that we cannot hope to achieve unlinkability in this setting. We should also note that if the certificate authority wishes to usurp the identity of a vehicle, it can just sample a Dilithium key pair and create a certificate for this key pair with the identity of the vehicle in the certificate metadata. The reason why we consider both the RA and the CA as adversaries when proving unforgeability is to show that the key expansion process does not allow forgeries, even when this expansion is performed by malicious entities.

[0055] We refer to the RA and CA as a single entity (the adversary). The adversary’s goal is to produce a Dilithium public key pko. Intuitively, the adversary cannot win such a game with non-negligible probability since part of the secret key for the expanded public keys pk'D remains knwon only to the vehicle. Our proof relates the unforgeability of expanded Dilithium to that of Dilithium: we construct a reduction, which uses an adversary against expanded Dilithium and tries to produce a forgery for a target Dilithium public key pko. This guess will be correct with inverse polynomial probability and thus leads to a non-negligible advantage against Dilithium if the adversary against expanded Dilithium succeeds with non-negligible probability.

[0056] We modify the Kyber protocols to introduce the ability to add together to public keys, and to be able to encrypt under the resulting public key, and decrypt under the induced secret key. The modified protocols of key generation 200 and expansion 300 and decaps 400 are presented in details in Figures 2, 3 and 4 respectively and we briefly describe the changes here.

[0057] Kyber KeyGen 200 is modified such that every public key uses the same A* matrix (i.e. it is not sampled using a seed p as in regular Kyber). This is done to ensure the additive homomorphic relation between public and private keys.

[0058] Kyber Expand(pkj) 300 is a new algorith for expanding public keys using T as a seed for the pseudorandom values. This algorithm first generates a new Kyber public key using H(pk ) instead of the random value o in KeyGen and adds this new public key to pk (in the NTT domain) to obtain the expanded public key.

[0059] Kyber Encaps(pk) is left unchanged with the exception that the same A" matrix is used for every public key.

[0060] Kyber.Decaps(c,sk ) 400 takes an additional input T which is used as the seed to compute the secret key sk' corresponding to the public key pk' = Kyb.Expand(pkj).

[0061] In Figure 5 we describe the parameters of Kyber, and what parameters we have chosen for our system. We compare this with the parameter set that our set most closely resembles, that of Kyber768. Changes are colored in red. Note that despite basing our parameters on Kyber768, we are not necessarily trying to maintain exactly the same level of security as in Kyber768. We have purposely chosen a higher parameter set (than Kyber512) in order to have a buffer to accommodate small losses in tightness or security induced by the expansion procedure.

[0062] For our purpose, changing the rings R and Rq would be undesirable, as much of Kyber’s efficiency comes from the careful choice of this ring, and the NTT that is possible over it. Therefore, making minimal changes means sticking to altering k, the q values, representing the width of the binomial distribution, and the d values, the degree of rounding employed.

[0063] When two M-LWE public keys As1 + e1 and As2 + e2 are added together (which use the same “A” matrix), this is equivalent to using the secret key (s1 + s2) with the public key A(s1 + s2) + (e1 + e2). When we encrypt with respect to such a matrix, we can analyze the security by considering the resulting distribution of secret keys. Since components of s and e are drawn from Bq1 , the binomial distribution of width parameter q1 , it is easy to see that the distribution of s1 +s2 is B2k q 1 and the same is true for e1 +e2 (recall that additions are over the polynomial ring). In other words, using s1 +s2 as the secret key is equivalent to doubling the q1 parameter during key generation. So for our system we sample secrets from Bqk1 , but analyze security as if secrets were drawn from B2k r)1 .

[0064] Doubling q1 has two main effects: (i) the width of the distribution of the M-LWE secret is wider, which means (ii) the probability of a decryption failure is increased. There is a growing body of analysis that shows that even a single decryption failure is unacceptable from a security perspective, and that therefore decryption failures must be cryptographically unlikely.

[0065] In the Kyber768 parameter set, doubling the width of the binomial s and e are drawn from (and changing no other parameters) increases the probability of a decryption failure from 2-165 to 2-83, a dramatic and unacceptable difference. To offset this while staying with R and Rq, we can simply reduce du and dv. These parameters control how much the ciphertext is rounded for increased efficiency. While they do have an impact on security (the rounding is treated as slightly increasing the size of the error distribution), its effect is minimal. By increasing du and dv, we can lower the probability of a decryption error back down to a cryptographically negligible rate, while only increasing the size of the ciphertext by a reasonable amount.

[0066] The proposed parameter set in Figure 2 achieves a negligible decryption error rate? of 2-146 at a cost of increasing the size of the ciphertext from 1088 bytes to 1344 bytes. The main meaningful change made in this parameter set is the reduction in the extent to which we round the ciphertext. As noted in the Kyber specification, this rounding is estimated to increase security by roughly 6 bits, and thus rounding less does not substantially decrease the security level.

[0067] This system only changes the number of bits used to encode the ciphertext (u,v). Note that the size of the public key in this system is actually smaller, simply because we do not use p to determine the A matrix, instead having all participants in the system use the same A matrix for pseudonymity.

[0068] The modified Dilithium algorithms with the highlighted changes are presented in 6 through 9 respectively as receive 600, sign 700, ver 800, keygen 910 and Expand 920. As in Kyber, an important change to the original Dilithium scheme is that all public keys use the same A matrix. This change gives the homomorphic property to the public keys required for BKE. We describe the most important changes below.

[0069] Dilithium. KeyGen 910 uses the same A" matrix for every public key, so it is expanded deterministically. The helper function Power2Round is replaced with a new function Power2RoundHigh which only returns the high bits of the power of 2 split since the lower bits are often not necessary. Dilithium Expand (pk,T) 920 is a new algorithm that expands the public key pk by generating a new public key using T as seed and returns the sum of both public keys.

[0070] Dilithium. Receive(pk,sk,T,T') 600 is a new algorithm that takes as input a public / private key pair and two expansion seeds, and returns the secret key corresponding to the doubly expanded public key pk' = Expand(Expand(pk,i),T).

[0071] As in Kyber, we want to change as few of these parameters as necessary to still achieve a high level of security. Unlike in Kyber, we will need to expand Dilithium public keys twice for butterfly key expansion. Also unlike Kyber, the security of Dilithium is based on both the module LWE and SIS (short integer solution) problem. Tuning parameters to accommodate two expansion means that we need to ensure that the underlying M-LWE and M-SIS problems remain difficult. We base our parameters off of a mixture of the Dilithium 2 and 3 parameter sets so that the achieved level of security is between the two.

[0072] By adding together three secrets with size at most q we greatly reduce the probability of finding a signature in the while loop. Accordingly, we increase some other parameters to keep the number of expected repetitions similar but accommodate the larger secrets.

[0073] For a list of parameters, their descriptions, and the values in Dilithium 2 and in our system we refer to Figure 10. For security, we need to ensure that the underlying LWE and SIS problems remain difficult. We rely upon the security estimation scripts used by Kyber and Dilithium to evaluate the Core SVP hardness of the underlying instances [DS21], The underlying M-LWE instance has a block size of 422, 123 bits of classical core-SVP hardness, and 111 bits of quantum core-SVP hardness (the numbers for the M-LWE instance in Dilithium 2 are 423, 123, and 112 respectively). Note that the M-LWE instance here is taken with q = 2, as we need the M-LWE instance to be indistinguishable from uniform for a single sample in order to guarantee unlinkability. The underlying M-SIS instance has a block size of 508, 148 bits of classical core-SVP hardness, and 134 bits of quantum core-SVP hardness (for Dilithium 2 these numbers are 423, 123, 112). Note that we have evaluated the hardness only with respect to the SIS instance induced by existential unforgeability, as our proof does not aim for strong unforgeability.

[0074] Unless the context clearly requires otherwise, throughout the description and the claims, the words “comprise,” “comprising,” and the like are to be construed in an inclusive sense, as opposed to an exclusive or exhaustive sense; that is to say, in the sense of “including, but not limited to.” As used herein, the terms “connected,” “coupled,” or any variant thereof, means any connection or coupling, either direct or indirect, between two or more elements; the coupling of connection between the elements can be physical, logical, or a combination thereof. Additionally, the words “herein,” “above,” “below,” and words of similar import, when used in this application, shall refer to this application as a whole and not to any particular portions of this application. Where the context permits, words in the above Detailed Description using the singular or plural number may also include the plural or singular number respectively. The word “or,” in reference to a list of two or more items, covers all of the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list.

[0075] The above detailed description of implementations of the system is not intended to be exhaustive or to limit the system to the precise form disclosed above. While specific implementations of, and examples for, the system are described above for illustrative purposes, various equivalent modifications are possible within the scope of the system, as those skilled in the relevant art will recognize. For example, some network elements are described herein as performing certain functions. Those functions could be performed by other elements in the same or differing networks, which could reduce the number of network elements. Alternatively, or additionally, network elements performing those functions could be replaced by two or more elements to perform portions of those functions. In addition, while processes, message / data flows, or blocks are presented in a given order, alternative implementations may perform routines having blocks, or employ systems having blocks, in a different order, and some processes or blocks may be deleted, moved, added, subdivided, combined, and / or modified to provide alternative or sub-combinations. Each of these processes, message / data flows, or blocks may be implemented in a variety of different ways. Also, while processes or blocks are at times shown as being performed in series, these processes or blocks may instead be performed in parallel, or may be performed at different times. Further, any specific numbers noted herein are only examples: alternative implementations may employ differing values or ranges. Those skilled in the art will also appreciate that the actual implementation of a database may take a variety of forms, and the term “database” is used herein in the generic sense to refer to any data structure that allows data to be stored and accessed, such as tables, linked lists, arrays, etc.

[0076] The teachings of the methods and system provided herein can be applied to other systems, not necessarily the system described above. The elements, blocks and acts of the various implementations described above can be combined to provide further implementations.

[0077] Any patents and applications and other references noted above, including any that may be listed in accompanying filing papers, are incorporated herein by reference. Aspects of the technology can be modified, if necessary, to employ the systems, functions, and concepts of the various references described above to provide yet further implementations of the technology.

[0078] These and other changes can be made to the invention in light of the above Detailed Description. While the above description describes certain implementations of the technology, and describes the best mode contemplated, no matter how detailed the above appears in text, the invention can be practiced in many ways. Details of the system may vary considerably in its implementation details, while still being encompassed by the technology disclosed herein. As noted above, particular terminology used when describing certain features or aspects of the technology should not be taken to imply that the terminology is being redefined herein to be restricted to any specific characteristics, features, or aspects of the technology with which that terminology is associated. In general, the terms used in the following claims should not be construed to limit the invention to the specific implementations disclosed in the specification, unless the above Detailed Description section explicitly defines such terms. Accordingly, the actual scope of the invention encompasses not only the disclosed implementations, but also all equivalent ways of practicing or implementing the invention under the claims.

[0079] While certain aspects of the technology are presented below in certain claim forms, the inventors contemplate the various aspects of the technology in any number of claim forms. For example, while only one aspect of the invention is recited as implemented in a computer-readable medium, other aspects may likewise be implemented in a computer-readable medium. Accordingly, the inventors reserve the right to add additional claims after filing the application to pursue such additional claim forms for other aspects of the technology.

Claims

ClaimsWhat is claimed is:1 . A method of signature and encryption amongst at least one RA and one CA comprising: using butterfly key expansion for encryption using a single key, using butterfly key expansion for signature verification using the single key, wherein the single key is made mathematically unlinkable and unforgeable against said RA and CA, alone and in combination.

2. The method of claim 1 wherein unlinkability and unforgeability is derived from use of Kyber expansion and Dilithium expansion.

3. A system for signature and encryption amongst at least one RA and one CA comprising:A first unit for butterfly key expansion for encryption using a single key,A second unit for butterfly key expansion for signature verification using the single key, wherein the single key is made mathematically unlinkable and unforgeable against said RA and CA, alone and in combination.

4. The system of claim 3 wherein unlinkability and unforgeability is achieved by a Kyber expansion unit and a Dilithium expansion unit.