Information processing method, information processing device, and program
The method addresses the inaccuracy in assessing isogenous mapping cryptography security by detecting and distinguishing essentially identical collisions, resulting in a more precise evaluation of public parameter security.
Patent Information
- Application Number
- PCT/JP2025/026892
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-08
- Filing Date
- 2025-07-29
- Publication Date
- 2026-02-12
AI Technical Summary
Existing methods for determining the security of public parameters in isogenous mapping cryptography are inaccurate due to the inability to distinguish between essentially identical collisions, leading to an unreliable assessment of collision counts and security.
An information processing method that detects a first pair of private keys with matching public keys, determines their relative positional relationship, and then identifies additional pairs using a path-connected approach, avoiding redundant collision counting by recognizing essentially identical collisions as a single event.
This method allows for a more accurate determination of the security of public parameters by ensuring that essentially identical collisions are not counted multiple times, thus providing a closer match between detected collision counts and the actual number within a given time period.
Smart Images

Figure JP2025026892_12022026_PF_FP_ABST
Abstract
Description
Information processing method, information processing device, and program
[0001] The present disclosure relates to an information processing method, an information processing device, and a program.
[0002] Isogeneous mapping cryptography is known as a next-generation cryptographic method (quantum-resistant cryptography) that can withstand the computational performance of quantum computers. Isogeneous mapping cryptography is a quantum-resistant cryptography that bases its security on the isogeneous mapping problem, and is expected to have the advantage of smaller key size than other quantum-resistant cryptography (e.g., lattice cryptography, code cryptography, etc.).
[0003] In isogenous mapping cryptography, there are multiple public parameters, and a single private key space is formed by selecting the public parameters. However, it is known that in the private key space, there may be multiple pairs of private keys with the same public key. The number of such pairs of private keys is an index for determining whether the selected public parameters are secure, so a search for such pairs of private keys is performed. Non-Patent Document 1 discloses a ρ-method search that can be used as a method for searching for pairs of private keys with the same public key.
[0004] JM Pollard, Monte Carlo Methods for Index Computation (mod p), [online], July 1978, MATHEMATICS OF COMPUTATION, VOLUME 32, NUMBER 143, PAGES 918-924, [Retrieved July 29, 2024], Internet <S0025-5718-1978-0491431-9.pdf>
[0005] However, the technique of Non-Patent Document 1 may not be able to accurately determine the security of public parameters.
[0006] Therefore, the present disclosure provides an information processing method, an information processing device, and a program that can more accurately determine the security of public parameters.
[0007] An information processing method according to one aspect of the present disclosure is an information processing method for evaluating the security of public parameters for forming a private key space, which is a collection of private keys used in a DH (Diffie-Hellman) key exchange method, wherein the private key space is a vector space, and the information processing method detects a first pair of private keys having matching public keys in the private key space, obtains information indicating the relative positional relationship of the first pair of private keys in the private key space, and further detects a second pair of private keys having matching public keys in the private key space, starting from each of multiple points in the private key space included in a path connecting an arbitrary first point in the private key space and a second point having the relative positional relationship with the first point.
[0008] An information processing device according to one aspect of the present disclosure is an information processing device that evaluates the security of public parameters for forming a private key space, which is a collection of private keys used in a DH (Diffie-Hellman) key exchange method, wherein the private key space is a vector space, and the information processing device includes: a first detection unit that detects a first pair of private keys whose public keys match in the private key space; an acquisition unit that acquires information indicating the relative positional relationship of the first pair of private keys in the private key space; and a second detection unit that detects a second pair of private keys whose public keys match in the private key space, starting from each of a plurality of points in the private key space that are included in a path connecting an arbitrary first point in the private key space and a second point that is in the relative positional relationship with the first point.
[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described information processing method.
[0010] According to one aspect of the present disclosure, it is possible to realize an information processing method and the like that can more accurately determine the safety of public parameters.
[0011] FIG. 1 is a diagram illustrating a configuration of an information processing system according to an embodiment. FIG. 2 is a block diagram illustrating a functional configuration of a public parameter selection device according to an embodiment. FIG. 3 is a block diagram illustrating a functional configuration of a public parameter safety determination device according to an embodiment. FIG. 4 is a sequence diagram illustrating the operation of an information processing system according to an embodiment. FIG. 5 is a flowchart illustrating the operation of a public parameter safety determination device according to an embodiment. FIG. 6 is a diagram illustrating step S31 shown in FIG. 5. FIG. 7 is a diagram illustrating an example of a new starting point saved in step S33 shown in FIG. 5. FIG. 8A is a first diagram illustrating steps S36 and S37 shown in FIG. 5. FIG. 8B is a second diagram illustrating steps S36 and S37 shown in FIG. 5. FIG. 8C is a third diagram illustrating steps S36 and S37 shown in FIG. 5. FIG. 9A is a diagram illustrating a ρ-method search. FIG. 9B is a diagram illustrating a collision in a ρ-method search. FIG. 10A is a diagram illustrating a parallel ρ-method search. FIG. 10B is a diagram illustrating a collision in a parallel ρ-method search. FIG. 11 is a diagram illustrating a problem that occurs when performing a collision search.
[0012] (Background to the Invention of the Present Disclosure) Prior to describing the embodiments of the present disclosure, the background to the invention of the present disclosure will be described with reference to FIGS. 9A to 11. FIG.
[0013] As described in the "Background Art" section, isomorphic mapping cryptography is expected to be a next-generation cryptographic method (quantum-resistant cryptography) that has security that can withstand the computational performance of quantum computers. Specific examples of isomorphic mapping cryptography include, but are not limited to, CSIDH (Commutative Supersingular Isogeny Diffie Hellman), SQISign (Short Quaternion and Isogeny Signature), and CSI-FiSh (Commutative Supersingular Isogeny-based Fiat-Shamir signatures).
[0014] The isogeny cryptosystem uses prime numbers (p), positive integers (n), and small prime numbers (l1, ..., l n) are available. By selecting the public parameters, a private key space is formed. The private key space is a set of private keys corresponding to the selected public parameters, and is a vector space (e.g., a high-dimensional vector space). The set of private keys means the set of all possible permutations of private keys. In isogenous mapping cryptography, it is known that there may be multiple pairs of private keys with the same public key in the private key space. Note that detecting (discovering) a pair of private keys with the same public key is also referred to as detecting (discovering) a collision.
[0015] For example, if a malicious attacker uses collisions (taking advantage of the existence of a pair of private keys with the same public key), it becomes possible to forge a signature. Therefore, from the viewpoint of security, it is better to have a small number of collisions in the private key space. The number and distribution of collisions in the private key space are determined according to the public parameters. A signature forgery may occur when an attacker who does not possess the original private key uses a different private key with a common public key to create a signature of a user who possesses the original private key.
[0016] When selecting public parameters to be used in isogenous mapping cryptography, it is desirable to determine whether the selected public parameters are secure. However, at present, it is not clear what kind of public parameters will reduce the number of collisions. Therefore, to determine whether the selected public parameters are secure (i.e., whether the number of collisions is reduced), it is necessary to actually search for collisions within the private key space formed by the selected public parameters.
[0017] A method for actually searching for collisions in the private key space is, for example, a p-method search, etc. For example, a collision search is performed by parallel computation using a p-method search.
[0018] 9A is a diagram for explaining the ρ-method search. Each intersection of the private key space S shown in FIG. 9A corresponds to a private key. i and e jindicates the dimension of the private key space. For example, one dimension may be a dimension based on one public parameter. For convenience, FIG. 9A shows an example in which the private key space S is a two-dimensional space, but the actual private key space S is a space with three or more dimensions.
[0019] As shown in FIG. 9A, in the ρ method search, a certain point (here, point P 200 ) and moves pseudo-randomly through the vector space, and the public key for the private key of each point is calculated. In the example of FIG. 9A, the public key for the private key of each point is calculated along the path of the arrow. In the example of FIG. 9A, the public key for the private key of each point is calculated along the path of the arrow. 200 , P 203 , and P 209 The public keys corresponding to the 10 points including
[0020] Note that moving pseudo-randomly means, for example, moving according to a value obtained by inputting a seed value into a pseudo-random function (for example, a pseudo-random number generating function). The seed value is not particularly limited, but for example, the point P 200 The seed value may be a value based on, for example, the point P 200 For example, a pseudorandom function using the public key value as a seed value may be used to determine the next destination in the private key space S (i.e., the public key E i The next public key E i+1 ) is determined. It should be noted that the public key E i Any deterministic function may be used as long as it takes in the value of and outputs an element of the set (1, . . . , n).
[0021] Next, if a private key with the same public key exists, the private key pair is saved as a collision.
[0022] FIG. 9B is a diagram for explaining collisions in the ρ method search. 0 is point P 200 9B. 3 is point P 203 is the public key corresponding to the private key of E 9 is point P 209 is the public key corresponding to the private key of
[0023] As shown in FIG. 9B, public key E 3 and E 9 In this case, in the private key space S, there is a private key pair (point P 203 The private key of point P 209 There is a collision between the two secret keys.
[0024] Another method of collision search is the parallel ρ search, which is shown in FIG.
[0025] As shown in Figure 10A, in the parallel ρ method search, multiple starting points are randomly selected and the ρ method search is executed in parallel. When the coordinates of the starting point are used as the seed value, only the same movement method is possible from the same starting point (i.e., the same movement path is used), so a different starting point must be selected each time. In Figure 10A, point P 300 and P 400 is selected.
[0026] FIG. 10B is a diagram for explaining collisions in the parallel ρ method search.
[0027] As shown in Figure 10B, a collision may occur between two movement methods (movement paths). 306 and the public key corresponding to the private key of point P 406 The private key and the corresponding public key match, resulting in a collision.
[0028] The collision search may be performed by a ρ method search, a parallel ρ method search, a combination of these, or another method.
[0029] FIG. 11 is a diagram for explaining the problem when performing collision detection. In FIG. 11, a point P 500 The private key of point P 510 The private key of 550 The private key of point P 560 This shows an example of a collision between the private key of
[0030] Here, point P 500 and P510 and the vector connecting point P 550 and P 560 In the private key space S, a collision that can be expressed by the same vector as a discovered collision can be considered to be essentially the same collision. In other words, the vector connecting the point P 500 The private key of point P 510 Collision with the private key of point P 550 The private key of point P 560 A collision with a private key of 1 can be considered to be essentially the same collision. To more accurately determine the security of the public parameters, it is desirable to count such essentially the same collision as one collision.
[0031] However, the ρ method search disclosed in Non-Patent Document 1 counts such essentially identical collisions multiple times. Furthermore, the parallel ρ method search shown in FIG. 10B has a high probability of rediscovering a collision that has already been found. Thus, with conventional methods, it has been difficult to find essentially different collisions (collisions with different vectors) within a certain period of time, which may result in an inaccurate security assessment. For example, the number of collisions that can be found within a certain period of time may deviate from the actual number of collisions in space, which may result in an inaccurate security assessment. In other words, with conventional methods, it has been difficult to accurately determine the security of public parameters.
[0032] Therefore, the inventors of the present application have conducted extensive research into information processing methods etc. that can more accurately determine the safety of public parameters, and have devised the following information processing method etc. The information processing method may be, for example, an information processing method that can avoid rediscovery of a collision by performing a parallel ρ search starting from each point on the collision path of a discovered collision.
[0033] An information processing method according to a first aspect of the present disclosure is an information processing method for evaluating the security of public parameters for forming a private key space, which is a collection of private keys used in a DH (Diffie-Hellman) key exchange method, wherein the private key space is a vector space, and the information processing method detects a first pair of private keys having matching public keys in the private key space, obtains information indicating the relative positional relationship of the first pair of private keys in the private key space, and further detects a second pair of private keys having matching public keys in the private key space, starting from each of a plurality of points in the private key space included in a path connecting an arbitrary first point in the private key space and a second point having the relative positional relationship with the first point.
[0034] As a result, since both ends of the path are the first point and the second point, a vector connecting the first point and the second point can be obtained. If multiple second pairs having the same vector as the vector are detected, it is possible to determine that they are essentially the same collision. In other words, even if essentially the same collision is detected, it is possible to prevent it from being counted as the number of collisions. Therefore, the number of collisions that can be detected within a certain time period (the number of private key pairs) and the actual number of collisions in the private key space (the true value) can be closer to each other, making it possible to more accurately determine the security of the public parameters selected to form the private key space.
[0035] Furthermore, for example, the information processing method according to the second aspect may be the information processing method according to the first aspect, and when a plurality of second pairs of private keys are detected, the number of pairs of private keys may be counted by calculating a vector in the private key space for each of the plurality of second pairs of private keys, and counting the number of two or more second pairs of private keys with the same calculated vector as one.
[0036] This prevents essentially the same collision from being counted multiple times, so the number of collisions that can be detected within a certain time period (the number of pairs of private keys) and the actual number of collisions in the private key space (the true value) can be closer, allowing for a more accurate assessment of the security of the public parameters.
[0037] Furthermore, for example, an information processing method according to a third aspect may be an information processing method according to the first or second aspect, in which an arbitrary point among the plurality of points included in the path is moved randomly in the private key space, and two or more remaining points among the plurality of points excluding the arbitrary point are each moved in the same manner as the arbitrary point, and a third pair of private keys having matching public keys is further detected in the private key space using each of the plurality of points after movement as a starting point.
[0038] This makes it easier to detect private key pairs with matching public keys and undetected vectors, allowing for more accurate determination of the security of public parameters.
[0039] Also, for example, an information processing method according to a fourth aspect may be the information processing method according to the third aspect, in which the arbitrary point is the first point.
[0040] This allows the multiple points to be moved randomly in response to the first point.
[0041] Furthermore, for example, an information processing method according to a fifth aspect may be the information processing method according to the third or fourth aspect, wherein, when at least one of the plurality of points included in the path that has the first point at one end matches at least one of the plurality of points after the movement, an arbitrary third point in the private key space is newly set, and a fourth pair of private keys having matching public keys in the private key space may be detected, starting from each of the plurality of points in the private key space included in a path connecting the arbitrary third point in the private key space and a fourth point that is in the relative positional relationship with the third point.
[0042] This allows the direction of random movement to be varied when the direction is determined based on the coordinates of an arbitrary point, making it easier to detect a private key pair with an undetected vector. This allows for more accurate determination of the security of the public parameters.
[0043] Also, for example, an information processing method according to a sixth aspect is an information processing method according to any one of the third to fifth aspects, and the direction of movement of the arbitrary point may be determined based on a value based on the arbitrary point.
[0044] This allows multiple points to be moved randomly according to a value based on any point.
[0045] Also, for example, an information processing method according to a seventh aspect may be the information processing method according to the sixth aspect, wherein the value based on the arbitrary point may include the value of a public key corresponding to a private key of the arbitrary point.
[0046] This allows multiple points to be moved randomly according to the value of the public key corresponding to any private key.
[0047] Also, for example, an information processing method according to an eighth aspect is an information processing method according to any one of the first to seventh aspects, and may use a p-method search to detect the second pair of private keys.
[0048] This makes it possible to more accurately determine the security of public parameters even when using conventional methods such as the p-method search.
[0049] Also, for example, an information processing method according to a ninth aspect is an information processing method according to any one of the first to eighth aspects, and the route may be determined by the p-method search.
[0050] This allows the path obtained by the ρ method search to be used as the path connecting the first point and the second point, thereby reducing the processing load for calculating the path connecting the first point and the second point.
[0051] Also, for example, an information processing method according to a tenth aspect is an information processing method according to any one of the first to ninth aspects, and the private key space may be formed according to public parameters of an isogenous mapping cryptosystem.
[0052] This makes it possible to more accurately determine the security of the public parameters of the isogenous cryptosystem.
[0053] An information processing device according to another aspect of the present disclosure is an information processing device that evaluates security of public parameters for forming a private key space, which is a set of private keys used in a Diffie-Hellman (DH) key exchange scheme, wherein the private key space is a vector space, and the information processing device includes: a first detection unit that detects a first pair of private keys whose public keys match in the private key space; an acquisition unit that acquires information indicating a relative positional relationship of the first pair of private keys in the private key space; and a second detection unit that detects a second pair of private keys whose public keys match in the private key space, starting from each of a plurality of points in the private key space included in a path connecting an arbitrary first point in the private key space and a second point having the relative positional relationship with the first point. A program according to another aspect of the present disclosure is a program for causing a computer to execute the information processing method according to any one of the first to tenth aspects.
[0054] As a result, the same effects as those of the above-mentioned information processing method can be achieved.
[0055] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet.
[0056] Hereinafter, the embodiments will be specifically described with reference to the drawings.
[0057] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.
[0058] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.
[0059] In addition, in this specification and drawings, e i axis, e j Axis and e k The axes indicate the three axes of a three-dimensional Cartesian coordinate system.
[0060] Furthermore, in this specification, terms indicating the relationship between elements, such as same and parallel, terms indicating the shape of elements, such as rectangle, as well as numerical values and numerical ranges, are not expressions that only express a strict meaning, but are expressions that also mean a substantially equivalent range, for example, including a difference of about several percent (or about 10%).
[0061] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.
[0062] (Embodiment) Hereinafter, an information processing method and an information processing system that executes the information processing method according to the present embodiment will be described with reference to Figs. 1 to 8C.
[0063] [1. Configuration of Information Processing System] First, the configuration of an information processing system according to this embodiment will be described with reference to FIGS. 1 to 3. FIG. 1 is a diagram illustrating the configuration of an information processing system 10 according to this embodiment. Note that FIG. 1 illustrates an exemplary configuration of the information processing system 10, and the configuration of the information processing system 10 is not limited to that illustrated in FIG. 1. The information processing system 10 is a system for evaluating the security of public parameters selected to form a private key space, which is a set of private keys used in a DH (Diffie-Hellman) key exchange method (e.g., key exchange for isogenic mapping cryptography). The information processing system 10 is applicable to a DH key exchange method in which the private key space is a vector space. Below, an example will be described in which the private key space is a key space formed according to the public parameters of isogenic mapping cryptography.
[0064] As shown in Fig. 1, an information processing system 10 includes a public parameter selection device 100 and a public parameter safety judgment device 200. The public parameter selection device 100 and the public parameter safety judgment device 200 are connected to each other so that they can communicate with each other. Note that Fig. 1 illustrates an example in which the public parameter selection device 100 and the public parameter safety judgment device 200 are separate devices, but they may also be integrated devices, for example.
[0065] The public parameter selection device 100 generates public parameters for isogenous mapping cryptography. Furthermore, the public parameter selection device 100 determines whether the public parameters for isogenous mapping cryptography generated by the public parameter selection device 100 are usable, based on the determination result of the public parameter security determination device 200.
[0066] Fig. 2 is a block diagram showing the functional configuration of public parameter selection device 100 according to this embodiment. Note that Fig. 2 shows an exemplary functional configuration of public parameter selection device 100, and the functional configuration of public parameter selection device 100 is not limited to that shown in Fig. 2.
[0067] As shown in FIG. 2 , public parameter selection device 100 includes, as its functional configuration, a receiving unit 110, a public parameter useability determining unit 120, a storage unit 130, a public parameter generating unit 140, and a transmitting unit 150. Public parameter selection device 100 also includes, as its hardware configuration, a non-volatile memory in which a program is stored, a volatile memory that is a temporary storage area for executing the program, an input / output port, a communication interface, a processor that executes the program, and the like. The memory may be a ROM (Read Only Memory) or a RAM (Random Access Memory), and can store a program to be executed by the processor. Each functional configuration of public parameter selection device 100 is realized by a processor that executes a program stored in the memory, and the like. The public parameter selection device 100 may be realized by a mobile terminal such as a stationary PC (Personal Computer), a smartphone, a tablet, or a dedicated computer, or may be realized by a server (e.g., a cloud server), or may be realized by a combination thereof.
[0068] The receiving unit 110 receives the result of the judgment on the safety of the public parameters generated by the public parameter generating unit 140 from the public parameter safety judgment device 200. The receiving unit 110 may receive the judgment result directly from the public parameter safety judgment device 200, or may receive the judgment result via another device. The receiving unit 110 may be configured to include, for example, a communication circuit (or a communication module).
[0069] The public parameter usability determining unit 120 determines whether the public parameters generated by the public parameter generating unit 140 are usable based on the determination result received via the receiving unit 110. For example, if the determination result indicates that the number of collisions is equal to or less than a predetermined number, the public parameter usability determining unit 120 determines that the public parameters are usable, and if the determination result indicates that the number of collisions is greater than the predetermined number, the public parameter usability determining unit 120 determines that the public parameters are unusable.
[0070] The storage unit 130 stores various information, programs, etc. for generating public parameters and determining whether they can be used. The storage unit 130 may store a predetermined number of items, for example. The storage unit 130 may also store at least one of the generated public parameters and the determination results from the public parameter safety determination device 200. The storage unit 130 is realized by, but is not limited to, a semiconductor memory or a hard disk drive (HDD), etc.
[0071] The public parameter generator 140 generates public parameters to be used in the isogenous cryptography. The method by which the public parameter generator 140 generates the public parameters is not particularly limited, and any known method may be used. For example, the public parameter generator 140 may select any candidate value from a plurality of candidate values for each public parameter.
[0072] The transmitting unit 150 transmits the public parameters generated by the public parameter generating unit 140 to the public parameter safety determining device 200. The transmitting unit 150 may be configured to include, for example, a communication circuit (or a communication module).
[0073] Referring back to FIG. 1, the public parameter security determination device 200 executes a process for determining whether or not the public parameters of the isogenous encryption generated by the public parameter selection device 100 are secure.
[0074] Fig. 3 is a block diagram showing the functional configuration of public parameter safety judgment device 200 according to this embodiment. Note that Fig. 3 shows an exemplary functional configuration of public parameter safety judgment device 200, and the functional configuration of public parameter safety judgment device 200 is not limited to that shown in Fig. 3.
[0075] As shown in FIG. 3 , the public parameter safety determination device 200 is an example of an information processing device, and includes, as its functional configuration, a receiving device 210, a transmitting device 220, and a collision number calculation device 300. The collision number calculation device 300 executes processing for determining the safety of public parameters, and includes, as its functional configuration, a private key space generation unit 310, a ρ-method search unit 320, a parallel ρ-method search starting point calculation unit 330, a parallel ρ-method search unit 340, and a storage unit 350. The public parameter safety determination device 200 also includes, as its hardware configuration, a nonvolatile memory storing a program, a volatile memory serving as a temporary storage area for executing the program, an input / output port, a communication interface, and a processor for executing the program. The memory may be a ROM or RAM, and can store a program executed by the processor. Each functional configuration of the public parameter safety determination device 200 is realized by a processor executing a program stored in the memory. The public parameter safety judgment device 200 may be realized by a mobile terminal such as a stationary PC, a smartphone, a tablet, etc., a dedicated computer, etc., or by a server (e.g., a cloud server), or by a combination thereof.
[0076] The receiving device 210 receives the public parameters from the public parameter selection device 100. The receiving device 210 may receive the public parameters directly from the public parameter selection device 100, or may receive the public parameters via another device. The receiving device 210 may be configured to include, for example, a communication circuit (or a communication module).
[0077] The transmitting device 220 transmits the result of the determination of the safety of the public parameters by the collision number calculation device 300 to the public parameter selection device 100. The transmitting device 220 may be configured to include, for example, a communication circuit (or a communication module).
[0078] The private key space generation unit 310 generates one private key space based on the public parameters received via the receiving device 210. Any known method may be used to generate the private key space.
[0079] The p-method search unit 320 is a processing unit that detects collisions by p-method search as shown in Fig. 9A. The p-method search unit 320 may also detect collisions by parallel p-method search as shown in Fig. 10A. The p-method search unit 320 is an example of a first detection unit and an acquisition unit.
[0080] The parallel ρ method search starting point calculation unit 330 is a processing unit that calculates a starting point in a parallel ρ method search as shown in Fig. 10A. The parallel ρ method search starting point calculation unit 330 may calculate different coordinates in the private key space generated by the private key space generation unit 310 as starting points for the parallel ρ method search. Note that the method for calculating the starting point in the parallel ρ method search is not particularly limited, and any known method may be used.
[0081] The parallel ρ method search unit 340 is a processing unit that detects collisions using a parallel ρ method search as shown in Fig. 10B. The parallel ρ method search unit 340 detects collisions at multiple starting points using a ρ method search, using a seed value based on the starting point calculated by the parallel ρ method search starting point calculation unit 330. The parallel ρ method search unit 340 is an example of a second detection unit.
[0082] The storage unit 350 stores various information, programs, and the like for determining the safety of the public parameters. The storage unit 350 may store at least one of the received public parameters and the determination results for the public parameters. The storage unit 350 is realized by, but is not limited to, a semiconductor memory or a HDD. Note that the storage unit 350 may be independently disposed outside the collision number calculation device 300.
[0083] 2. Operation of Information Processing System Next, the operation of the information processing system 10 configured as described above will be described with reference to Fig. 4 to Fig. 8C. Fig. 4 is a sequence diagram showing the operation (information processing method) of the information processing system 10 according to this embodiment.
[0084] As shown in FIG. 4, the public parameter generator 140 of the public parameter selection device 100 generates public parameters for isogenous cryptography (S10).
[0085] Next, the transmitting unit 150 transmits the public parameters generated by the public parameter generating unit 140 to the public parameter safety judgment device 200 (S20). The receiving device 210 of the public parameter safety judgment device 200 receives the public parameters transmitted from the public parameter selecting device 100.
[0086] Next, the public parameter safety judgment device 200 executes a process for judging the safety of the public parameters (S30). The public parameter safety judgment device 200 calculates the number of collisions in the private key space formed based on the received public parameters.
[0087] Next, the public parameter safety judgment device 200 transmits the judgment result to the public parameter selection device 100 (S40). The receiving unit 110 of the public parameter selection device 100 receives the judgment result transmitted from the public parameter safety judgment device 200. The judgment result may include, for example, the number of collisions.
[0088] Next, the public parameter usability determining unit 120 of the public parameter selection device 100 determines whether or not the public parameters can be used based on the determination result (S50). The public parameter usability determining unit 120 may, for example, determine whether or not the number of collisions in the private key space formed based on the public parameters is equal to or less than a predetermined number, and determine whether or not the public parameters can be used based on the determination result. For example, if the number of collisions is equal to or less than the predetermined number, the public parameter usability determining unit 120 determines that the public parameters can be used, and if the number of collisions is greater than the predetermined number, determines that the public parameters cannot be used. Note that the predetermined number is set in advance.
[0089] The process of step S30 will now be described with reference to Figures 5 to 8C. Figure 5 is a flowchart showing the operation (information processing method) of public parameter safety determination apparatus 200 according to this embodiment.
[0090] First, the p-module search unit 320 of the public parameter security judgment device 200 performs a p-module search in the private key space generated by the private key space generation unit 310 to detect a collision (S31). In step S31, the p-module search unit 320 detects a pair (first pair) of private keys whose public keys match in the private key space. Figure 6 is a diagram for explaining step S31 shown in Figure 5.
[0091] As shown in FIG. 6, the ρ-method search unit 320 randomly selects a point P 100 (In Figure 6, the point with coordinates (0, 0)) is selected, and the point P 100 The ρ-method search unit 320 pseudo-randomly moves through the vector space, using a value based on the vector space as a seed value, to calculate a public key and search for a pair of colliding private keys. 100 Calculate the public key of each point passed through, including , and determine whether there is a public key with a matching value.
[0092] Note that step S31 may be performed by a parallel ρ search. That is, step S31 only needs to detect a pair of colliding private keys. Furthermore, the number of pairs of private keys detected in step S31 is not limited to one, and may be multiple. Here, multiple means the number of pairs of private keys with different vectors. By detecting multiple pairs of private keys, multiple different collision paths can be obtained.
[0093] Hereafter, point P 103 and the public key corresponding to the private key of point P 109 A case where a collision between the private key of the RSA and the corresponding public key is detected will be described.
[0094] Next, when the ρ-method search unit 320 detects a collision path between the pair of private keys, the ρ-method search unit 320 obtains a collision path from the pair of private keys and stores the obtained collision path in the storage unit 350 (S32). Here, the ρ-method search unit 320 obtains a collision path between the point P 103 From point P 109 The path (collision vector) from the first path to the second path is stored in the storage unit 350. For example, the ρ-method search unit 320 stores the path from the first path to the second path (collision vector) in the storage unit 350. j −1, e j −1, e i +1, ei +1, e j −1, e i -1" is stored in the storage unit 350.
[0095] In step S32, at least the point P 103 and P 109 For example, in step S32, the information indicating the relative positional relationship between the point P 103 and P 109 The information of the vector connecting the points P 103 and P 109 The coordinates of the collision paths may be stored. The collision paths may be included in the information indicating the relative positional relationship.
[0096] For example, the public key corresponding to the private key (0, . . . , 0) is expressed by the following formula 1, and the private key (s 1、9 -s 1、3 , ..., s n、9 -s n、3 ) is represented by the following formula 2, and the public key corresponding to the private key (0, . . . , 0) and the private key (s 1、9 -s 1、3 , ..., s n、9 -s n、3 ) collide, the ρ method search unit 320 may store the values of the following equations 1 to 3 in the storage unit 350 as values related to the collision.
[0097]
[0098]
[0099]
[0100] where n is a positive integer, E is an elliptic curve, and S 1、9 , ..., S n、9 , and S 1、3 , ..., S n、3 denotes the value of the private key. Furthermore, the following formula 5 denotes an ideal class generated from the ideal class shown in formula 4.
[0101]
[0102]
[0103] Furthermore, the prime number p shown in Equation 4 is shown in Equation 6.
[0104]
[0105] Next, the parallel ρ method search starting point calculation unit 330 calculates a new starting point (here, point P 0 ), and the point along the collision path saved in step S32 from the starting point is used as the starting point of the next ρ method search (here, point P 0 , ..., P K ) in the storage unit 350 (S33). The new starting point selected in step S33 is the point P 100 It is a point with different coordinates.
[0106] FIG. 7 is a diagram showing an example of the new starting point saved in step S33 shown in FIG.
[0107] As shown in FIG. 7, the parallel ρ method search starting point calculation unit 330 calculates an arbitrary point P 0 Select the point P 0 From "e j −1, e j −1, e i +1, e i +1, e j −1, e i -1" and each point moved to P 1 , P 2 , P 3 , P 4 , P 5 , P 6 Let point P 0 ~P 6 is stored in the storage unit 350 as the starting point for the next ρ method search. 103 and P 109 and the vector connecting point P 0 and P 6 Since the vector connecting point P is the same vector as the vector connecting point P 0 The private key of point P 6 The private key of point P 0 is the first point, and point P 6 is the second point, the path shown in FIG. 7 is the first point and the relative positional relationship with the first point (point P 103 and P 109For example, the path is determined by a ρ method search.
[0108] The information used in step S33 is the point P 103 and P 109 The information may be information indicating the relative positional relationship between the two.
[0109] One end of the path is point P 0 and the other end of the path is point P 6 If so, the path therebetween is not limited to the path indicated by the collision path. 0 and P 6 Alternatively, a route that connects the above two points in an L-shape or a U-shape may be generated, or another route that does not intersect along the way may be generated.
[0110] The point P 0 There is no particular limitation on the method of selection, and any known method may be used.
[0111] Referring again to FIG. 5, the parallel ρ method search unit 340 searches for the point P 0 ~P 6 In step S34, the parallel ρ method search unit 340 performs a ρ method search on each of the points P 0 and P 6 A plurality of points P in the private key space S included in the path connecting 0 ~P 6 A ρ-method search is performed using each of these as a starting point, and a pair of private keys (second pair) having matching public keys is detected in the private key space S. The parallel ρ-method search unit 340 may detect a collision of private keys, for example, by performing a parallel ρ-method search. When a collision of private keys is detected, information about the colliding private keys is stored in the storage unit 350.
[0112] The parallel ρ method search unit 340 searches for the point P 0 ~P 6 It is not limited to performing a ρ method search for each of the points P 0 ~P 6 It is sufficient to perform a ρ method search for at least one (for example, two or more) starting points.
[0113] Next, the parallel ρ method search unit 340 determines whether to end the search (S35). The parallel ρ method search unit 340 may determine to end the search when, for example, the elapsed time since the process of step S30 is executed exceeds a threshold time, or the number of times the pseudo-random walk has been performed exceeds a threshold number of times. Note that the conditions for ending the search are not limited to these. The conditions for ending the search may also be set in advance and stored in the storage unit 350.
[0114] If the parallel ρ method search unit 340 determines that the search should be terminated (Yes in S35), it terminates the processing of step S30, and if it determines that the search should not be terminated (No in S35), it proceeds to step S36.
[0115] Next, if the parallel ρ method search unit 340 determines not to end the search (No in S35), the parallel ρ method search start point calculation unit 330 calculates the start point (here, point P 0 ) by a pseudo-random walk (S36). 0 The value of the public key corresponding to the point P 0 Move randomly.
[0116] In addition, point P 0 is an example of an arbitrary point, and the value of the public key is an example of a value based on an arbitrary point. 0 The direction of movement in the pseudo-random walk is determined based on the value at an arbitrary point. 0、k It is written as follows.
[0117] 8A is a first diagram for explaining steps S36 and S37 shown in FIG. 5. In FIGS. 8A to 8C, for convenience, the private key space S is a three-dimensional space (e i , e j , e k 8A to 8C, the new starting point saved in step S33 is indicated by a circle, and the route is indicated by a solid arrow. Also, in FIGS. 8A to 8C, the starting point after the move is indicated by a circle containing an x, and the route is indicated by a dashed arrow. k When viewed from the axial direction, the starting point overlaps before and after the movement (i.e., e i Axis and ej If the axis values are the same, the starting point after the movement is shown in the diagram.
[0118] As shown by the curved arrow in FIG. 8A, the pseudo-random walk 0 Gae i ⇒+1, e k ⇒ Move +1 to point P 0、1 Move to. i ⇒+1, e k The movement +1 may be performed, for example, by one pseudo-random walk, or by multiple (for example, two) pseudo-random walks.
[0119] Referring again to FIG. 5, the parallel ρ method search starting point calculation unit 330 then calculates the starting point P 0 ~P 6 Point P 0 The starting point other than the starting point (here, point P 0 ) in the same direction as the point P 1 ~P 6 The pseudo-random walk is not used for the movement of the points. Conventional ρ search moves points, but in this embodiment, a path including the two colliding points at both ends is translated. In other words, the relative positional relationship between the ends of the path does not change even after the movement.
[0120] As shown in FIG. 8A, point P 0 is point P 0、1 When moving to another point P 1 ~P 6 Each of these is a point P 1、1 ~P 6、1 Move to each of the points P 1 ~P 6 Each of the i ⇒+1, e k ⇒ By moving +1, point P 1、1 ~P 6、1 Move to each of the following.
[0121] In this way, the parallel ρ method search starting point calculation unit 330 calculates the starting point of the plurality of points P 0 ~P 6 Point P 0(an example of an arbitrary point) is randomly moved in the private key space S, and multiple points P 0 ~P 6 Point P 0 The remaining two or more points excluding point P 1 ~P 6 ) at point P 0 Move it in the same way (in the same direction).
[0122] Referring back to FIG. 5, the parallel ρ method search starting point calculation unit 330 then calculates the starting point after the movement (point P 0、i , ..., P k、i ) is the starting point (point P 0 , ..., P k 8A, the parallel ρ method search starting point calculation unit 330 determines whether the moved point P 0、1 ~P 6、1 and point P 0 ~P 6 (Point P 0 The coordinates of the point P are determined to be the same as those of any of the paths that include the point P at one end. 0 ~P 6 and the plane on which point P 0、1 ~P 6、1 The plane on which e exists is k Since the axial position is a different plane, the point P after movement 0、1 ~P 6、1 Each of these is a point P 0 ~P 6 does not match any of the above.
[0123] Referring again to FIG. 5, next, if the parallel ρ method search starting point calculation unit 330 determines that the moved starting point does not match any of the starting points saved in step S33 (No in S38), the parallel ρ method search unit 340 continues processing from step S34 onwards for the moved starting point.
[0124] For example, the parallel ρ method search unit 340 0、1 ~P 6、1 In step S34, the parallel ρ method search unit 340 performs a ρ method search on each of the points P 0、1 and P 6、1A plurality of points P in the private key space S included in the path connecting 0、1 ~P 6、1 A ρ-method search is performed using each of these as a starting point, and a pair of private keys (third pair) with matching public keys is detected in the private key space S. If a collision of private keys is detected, information about the colliding private keys is stored in the storage unit 350.
[0125] Furthermore, if the parallel ρ method search starting point calculation unit 330 determines that the moved starting point matches any of the starting points saved in step S33 (Yes in S38), it returns to step S33 and continues the processing from step S33 onwards. 0、1 A new starting point next to the first starting point is set and stored in the storage unit 350.
[0126] In this way, the processes of steps S34 to S38 or steps S33 to S38 are repeatedly executed until the determination in step S35 is Yes.
[0127] 8B is a second diagram for explaining steps S36 and S37 shown in FIG. 5. 0、1 And further j ⇒ Shows the route if you move -1.
[0128] As shown by the curved arrow in FIG. 8B, step S36 is executed again to find point P 0、1 Gae j ⇒ By moving -1, point P 0、2 Furthermore, by executing step S37 again, the point P 1、1 ~P 6、1 Each of the j ⇒ By moving -1, point P 1、2 ~P 6、2 In other words, the relative positions of both ends of the path do not change after the movement.
[0129] As shown in FIG. 8B, point P 0、1 is point P 0、2 When moving to another starting point P 1、1 ~P 6、1 Each of these is the starting point P 1、2 ~P 6、28B, the starting point after the second movement by the parallel ρ method search starting point calculation unit 330 does not match any of the starting points saved in step S33, so collision detection is performed.
[0130] 8C is a third diagram for explaining steps S36 and S37 shown in FIG. 5. 0、2 And further i ⇒-1, e k 8C shows an example in which the determination in step S38 shown in FIG. 5 is Yes.
[0131] As shown by the curved arrow in FIG. 8C, step S36 is executed again to find point P 0、2 Gae i ⇒-1, e k ⇒ By moving -1, point P 0、3 In addition, by executing step S37 again, the starting point P 1、2 ~P 6、2 Each of the i ⇒-1, e k ⇒ By moving -1, the starting point P 1、3 ~P 6、3 In other words, the relative positions of both ends of the path do not change after the movement.
[0132] Here, point P 1 and P 0、3 coincide, and point P 2 and P 1、3 coincide, and point P 5 and P 4、3 coincide, and point P 6 and P 3、3are the same. In other words, the starting point after the movement is the same as one of the starting points saved in step S33. Therefore, since step S38 returns Yes, the process returns to step S33, a new starting point (an example of an arbitrary third point) is selected, and the point following the collision path saved in step S32 is saved as the starting point for the next ρ method search (S33). The new starting point is a point that is different from any of the points before and after the movement by the pseudo-random walk. Even if step S33 is executed again, the collision path saved in step S32 is commonly used. For example, the parallel ρ method search unit 340 searches the third point and the point P 103 and P 109 The method further detects pairs of private keys (fourth pairs) whose public keys match in the private key space S, starting from each of the multiple points in the private key space S included in the path connecting the first point and the fourth point (which is in a relative positional relationship with the first point).
[0133] If the determination in step S35 is Yes and multiple pairs of private keys (second pairs) have been detected, the parallel ρ method search unit 340 may calculate a vector in the private key space S for each of the multiple second pairs of private keys, and count the number of pairs of private keys (second pairs) with the same calculated vector as 1. In other words, even if multiple essentially identical collisions occur, they are counted as one collision (one collision).
[0134] (Other Embodiments) While the information processing method according to one or more aspects has been described above based on the embodiments, the present disclosure is not limited to these embodiments. As long as it does not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiments and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.
[0135] For example, in the above embodiment, the public parameters are generated by the public parameter selection device 100, but the present invention is not limited to this and may be generated by a person, for example.
[0136] Furthermore, in the above embodiment, an example was described in which the information processing system 10 is equipped with one public parameter selection device 100, but this is not limited to this, and the information processing system 10 may be equipped with, for example, multiple public parameter selection devices 100.
[0137] In the above embodiment, the starting point moves in a pseudo-random walk, but the present invention is not limited to this. For example, the starting point may move in a predetermined direction and distance. The direction and distance may be determined in advance and stored in the storage unit 350.
[0138] In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0139] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and other orders may be used. Some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.
[0140] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.
[0141] Furthermore, the public parameter safety judgment device 200 according to the above embodiment may be realized as a single device or may be realized by multiple devices. When the public parameter safety judgment device 200 is realized by multiple devices, the components of the public parameter safety judgment device 200 may be distributed in any manner among the multiple devices. When the public parameter safety judgment device 200 is realized by multiple devices, the communication method between the multiple devices is not particularly limited, and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.
[0142] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, which is an integrated circuit. These components may be individually integrated into a single chip, or some or all of them may be integrated into a single chip. Here, the term "LSI" is used, but depending on the level of integration, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI. Furthermore, the integrated circuit implementation method is not limited to LSI, and may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After LSI fabrication, a field programmable gate array (FPGA) that can be programmed or a reconfigurable processor that can reconfigure the connections or settings of circuit cells within the LSI may also be used. Furthermore, if an integrated circuit technology that replaces LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.
[0143] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip, and is specifically a computer system comprising a microprocessor, ROM, RAM, etc. The ROM stores computer programs. The system LSI achieves its functions when the microprocessor operates in accordance with the computer programs.
[0144] Furthermore, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the information processing method shown in FIG. 4 or FIG.
[0145] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.
[0146] The present disclosure is useful for an information processing device or the like that evaluates the security of a private key space.
[0147] 10 Information processing system 100 Public parameter selection device 110 Receiving unit 120 Public parameter use permission determining unit 130, 350 Storage unit 140 Public parameter generating unit 150 Transmitting unit 200 Public parameter safety determining device (information processing device) 210 Receiving device 220 Transmitting device 300 Collision number calculating device 310 Private key space generating unit 320 ρ method search unit (first detecting unit, acquiring unit) 330 Parallel ρ method search starting point calculating unit 340 Parallel ρ method search unit (second detecting unit) S Private key space
Claims
1. An information processing method for evaluating the security of public parameters for forming a private key space, which is a collection of private keys used in a DH (Diffie-Hellman) key exchange method, wherein the private key space is a vector space, and the information processing method comprises: detecting a first pair of private keys whose public keys match in the private key space; obtaining information indicating the relative positional relationship of the first pair of private keys in the private key space; and detecting a second pair of private keys whose public keys match in the private key space, starting from each of a plurality of points in the private key space included in a path connecting an arbitrary first point in the private key space and a second point that is in the relative positional relationship with the first point.
2. The information processing method according to claim 1, wherein when a plurality of second pairs of private keys are detected, a vector in the private key space for each of the plurality of second pairs of private keys is calculated, and the number of two or more second pairs of private keys with the same calculated vector is counted as one, thereby counting the number of pairs of private keys.
3. An information processing method according to claim 1 or 2, wherein an arbitrary point among the plurality of points included in the path is randomly moved in the private key space, and each of the remaining two or more points among the plurality of points excluding the arbitrary point is moved in the same manner as the arbitrary point, and each of the plurality of points after movement is used as a starting point to further detect a third pair of private keys having matching public keys in the private key space.
4. The information processing method according to claim 3, wherein the arbitrary point is the first point.
5. The information processing method of claim 3, wherein if at least one of the multiple points included in the path that has the first point at one end matches at least one of the multiple points after the movement, an arbitrary third point in the private key space is newly set, and a fourth pair of private keys having matching public keys is further detected in the private key space, starting from each of the multiple points in the private key space included in the path connecting the arbitrary third point in the private key space and a fourth point that is in the relative positional relationship with the third point.
6. The information processing method according to claim 3, wherein the direction of movement of the arbitrary point is determined based on a value based on the arbitrary point.
7. The information processing method of claim 6, wherein the value based on the arbitrary point includes a value of a public key corresponding to a private key of the arbitrary point.
8. The information processing method according to claim 1 or 2, wherein the second pair of private keys is detected using a p-module search.
9. The information processing method according to claim 8, wherein the route is determined by the p method search.
10. The information processing method according to claim 1 or 2, wherein the private key space is formed according to public parameters of an isogenous cryptosystem.
11. An information processing device that evaluates the security of public parameters for forming a private key space, which is a collection of private keys used in a DH (Diffie-Hellman) key exchange method, wherein the private key space is a vector space, and the information processing device comprises: a first detection unit that detects a first pair of private keys whose public keys match in the private key space; an acquisition unit that acquires information indicating the relative positional relationship of the first pair of private keys in the private key space; and a second detection unit that detects a second pair of private keys whose public keys match in the private key space, starting from each of multiple points in the private key space included in a path connecting an arbitrary first point in the private key space and a second point that is in the relative positional relationship with the first point.
12. A program for causing a computer to execute the information processing method according to claim 1 or 2.