Arithmetic device, terminal device, network, arithmetic method, and program

The described method addresses the need for key length compression in transitioning from 128-bit to 256-bit encryption by performing arithmetic operations and hashing on common keys, enabling secure communication with existing 128-bit algorithms.

WO2026053660A1PCT designated stage Publication Date: 2026-03-12KDDI CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

The introduction of 256-bit encryption in communication systems necessitates the coexistence with 128-bit encryption, requiring a method to compress the bit length of keys to match the existing 128-bit encryption algorithms.

Method used

A computing device and method that performs arithmetic operations on the bit sequence of a common key to generate a key of equal size to the key used in the cryptographic algorithm, utilizing a hash function to ensure compatibility and security.

Benefits of technology

Enables the generation of a key with the same bit length as the cryptographic algorithm, ensuring secure and efficient communication between terminal devices and networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025027722_12032026_PF_FP_ABST
    Figure JP2025027722_12032026_PF_FP_ABST
Patent Text Reader

Abstract

This arithmetic device causes a computer to execute: a processing step for, when the bit length of a key that is generated from a common key allocated for use in communication between a terminal device and a network and that is used for encryption and integrity assurance is longer than the bit length of an input key used in a predetermined algorithm, performing arithmetic processes different from each other on the bit string of the key generated from the common key and used for encryption and integrity assurance on the basis of a predetermined condition to obtain a bit string different from the bit string of the key generated from the common key and used for encryption and integrity assurance; and a hashing step for inputting the bit string obtained in the processing step to a predetermined hash function agreed in advance between the terminal device and the network to obtain a bit string having the same bit length as the bit length of the input key.
Need to check novelty before this filing date? Find Prior Art

Description

Computing unit, terminal device, network, calculation method, and program

[0001] The present invention relates to a computing device, a terminal device, a network, a computing method, and a program. This application claims priority to Japanese Patent Application No. 2024-154895, filed in Japan on September 9, 2024, the contents of which are incorporated herein by reference.

[0002] Conventional 3GPP (registered trademark) specifications are formulated on the premise that a 128-bit key is assigned to 128-bit encryption. For example, Non-Patent Document 1 defines the specific specifications of such technology.

[0003] 3GPP, "TS 33.501", v18.5.0

[0004] Discussions are currently underway to introduce 256-bit encryption. When 256-bit encryption is introduced, it is expected that 128-bit encryption and 256-bit encryption will coexist. In such cases, there is a demand for using a 256-bit key with 128-bit encryption. That is, there is a demand for compressing the bit length of a given key to generate a key with the same size as the key used in the encryption algorithm.

[0005] This invention has been made in consideration of these circumstances, and its purpose is to provide a computing device, terminal device, network, computing method, and program that can compress the bit length of a given key and generate a key of equal size to the key used in the cryptographic algorithm.

[0006] (1) One aspect of the present invention is a computer having at least a processor and memory, which is a computing device that performs the following steps: a processing step to obtain a bit sequence different from the bit sequence of the key used for encryption and integrity, which is generated from a common key assigned for use in communication between a terminal device and a network, when the key and bit length used for encryption and integrity assurance are longer than the bit length of the input key used in a predetermined algorithm, by performing different arithmetic operations on the bit sequence of the key used for encryption and integrity assurance generated from the common key based on predetermined conditions; and a hashing step to obtain a bit sequence having the same bit length as the bit length of the input key, by inputting the bit sequence obtained in the processing step into a predetermined hash function agreed in advance between the terminal device and the network. (2) Another aspect of the present invention is a computing device as described in (1) above, wherein the key generated from the common key used for encryption and integrity assurance is a key in which an encryption key for encryption and an authentication key used for integrity assurance are linked. (3) In another aspect of the present invention, in the arithmetic device described in (2) above, the encryption key and the authentication key are generated between the terminal device and the network each time the AKA algorithm for authentication is executed, and the processing step and the hashing step are executed each time the encryption key and the authentication key are generated. (4) In another aspect of the present invention, in the arithmetic device described in any of (1) to (3) above, the bit sequence obtained by the hashing step is the input key, which is a combination of the encryption key for encryption and the authentication key used for integrity assurance. (5) In another aspect of the present invention, in the arithmetic device described in any of (1) to (4) above, the hash function is the same function even if different arithmetic processes are performed in the processing step. (6) In another aspect of the present invention, in the arithmetic device described in any of (1) to (5) above, the processing step obtains a bit sequence different from the bit sequence of the common key by performing a shift operation on the bit sequence of the key used for encryption and integrity assurance generated from the common key.(7) In addition, in an arithmetic device described in any of (1) to (6) above, the processing step obtains a bit sequence different from the bit sequence of the common key by performing an operation using a bit sequence of a key used for encryption and integrity assurance generated from the common key and fixed values ​​that are different from each other based on predetermined conditions. (8) In addition, in an arithmetic device described in any of (1) to (7) above, the processing step obtains a bit sequence different from the bit sequence of the common key by concatenating a bit sequence of a key used for encryption and integrity assurance generated from the common key and fixed values ​​that are different from each other based on predetermined conditions. (9) In addition, in an arithmetic device described in any of (1) to (8) above, the hashing step obtains a bit sequence having the same bit length as the bit length of the input key as a hash value by inputting the bit sequence obtained by the processing step into the hash function. (10) In addition, in an arithmetic device described in any of (1) to (8) above, the hashing step obtains a first hash value by inputting the upper bits of the bit sequence obtained in the processing step into a first hash function agreed in advance between the terminal device and the network, obtains a second hash value by inputting the lower bits of the bit sequence obtained in the processing step into a second hash function agreed in advance between the terminal device and the network, and obtains a bit sequence having the same bit length as the bit length of the input key by performing a predetermined operation based on the obtained first hash value and the second hash value. (11) In addition, in an arithmetic device described in (10) above, the hashing step obtains a bit sequence having the same bit length as the bit length of the input key by performing an exclusive OR operation between the obtained first hash value and the second hash value. (12) In addition, in one aspect of the present invention, in any of the calculation devices described in (1) to (11) above, the calculation processes that are different from each other based on predetermined conditions performed by the processing step are calculation processes that are different from each other for each business operator.(13) Another aspect of the present invention is a terminal device equipped with the arithmetic unit described in any of (1) to (12) above. (14) Another aspect of the present invention is a network equipped with the arithmetic unit described in any of (1) to (12) above. (15) Another aspect of the present invention is the network described in (14) above, wherein the arithmetic unit is provided in at least one of next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function). (16) Another aspect of the present invention is a calculation method comprising: a processing step to obtain a bit sequence different from the bit sequence of the key used for encryption and integrity assurance generated from the common key, when the key and bit length used for encryption and integrity assurance generated from the common key are longer than the bit length of the input key used in a predetermined algorithm, by performing different arithmetic operations on the bit sequence of the key used for encryption and integrity assurance generated from the common key based on predetermined conditions; and a hashing step to obtain a bit sequence having the same bit length as the bit length of the input key by inputting the bit sequence obtained in the processing step into a predetermined hash function agreed in advance between the terminal device and the network. (17) Another aspect of the present invention is a program that causes a computer to perform the following steps: when the key and bit length of a key used for encryption and integrity assurance, which is generated from a common key assigned for use in communication between a terminal device and a network, is longer than the bit length of an input key used in a predetermined algorithm, a processing step of obtaining a bit sequence different from the bit sequence of the key used for encryption and integrity assurance generated from the common key by performing different arithmetic operations on the bit sequence of the key used for encryption and integrity assurance generated from the common key based on predetermined conditions; and a hashing step of inputting the bit sequence obtained in the processing step into a predetermined hash function agreed in advance between the terminal device and the network, to obtain a bit sequence having the same bit length as the bit length of the input key.

[0007] According to the present invention, it is possible to provide a computing device, terminal device, network, computing method, and program that can compress the bit length of a given key and generate a key equal in size to the key used in the cryptographic algorithm.

[0008] FIG. 1 is a diagram showing a general architecture of a wireless system according to an embodiment. FIG. 2 is a block diagram showing a schematic representation of a wireless system according to the embodiment. FIG. 3 is a diagram for explaining processing when a 128-bit key is provided to a wireless system according to the embodiment and processing when a 256-bit key is provided to the wireless system according to the embodiment. FIG. 4 is a sequence diagram showing timing of generation of a common key and an encryption key and compression of the keys according to the embodiment. FIG. 5 is an image diagram for explaining an overview of a first calculation method according to the embodiment. FIG. 6 is a flowchart showing a series of steps of the first calculation method according to the embodiment. FIG. 7 is a flowchart showing an overview of a modified example of the first calculation method according to the embodiment. FIG. 8 is an image diagram for explaining an overview of a modified example of a second calculation method according to the embodiment. FIG. 9 is a block diagram showing an example of the internal configuration of a network or a terminal device according to the embodiment.

[0009] [Embodiments] Preferred embodiments of a computing device, a terminal device, a network, a computing method, and a program according to aspects of the present invention are described in detail below with reference to the accompanying drawings. Note that the aspects of the present invention are not limited to these embodiments and include various modifications or improvements. In other words, the components described below include those that would be easily conceivable to a person skilled in the art or that are substantially identical, and the components described below can be combined as appropriate. Furthermore, various omissions, substitutions, or modifications of the components can be made without departing from the spirit of the present invention. Furthermore, in the drawings below, the scale and number of components may differ from the scale and number of the actual structures to make each configuration easier to understand.

[0010] In the following description, for convenience of explanation, terms and names defined in the 3GPP (registered trademark) LTE (3rd Generation Partnership Project Long Term Evolution) standard may be used. However, the present embodiment is not limited by such terms and names and may be applied to systems based on other standards.

[0011] 1 is a diagram showing a schematic architecture of a wireless system according to one embodiment. The wireless system 1 shown in the figure has, as its functional configuration, a control plane (C-Plane), which is a function for controlling communication, and a user plane (U-Plane), which is a function for realizing user communication. For the sake of simplicity, the figure shows the basic architecture used in a fifth-generation mobile communication system (5th Generation; 5G). However, the wireless system 1 to which this embodiment is applied is not limited to an example applied to 5G, and can be widely applied to other systems.

[0012] In the following description, configurations other than UE (User Equipment) may be referred to as a network. The network includes an access stratum and a non-access stratum. The access stratum includes at least a base station, and the non-access stratum includes at least an AMF (Access and Mobility Management Function). As shown in the figure, the UE and the AMF cooperate with each other via the N1 interface. In the following description, the base station and the AMF may be referred to as a higher-level concept and simply referred to as a network.

[0013] Figure 2 is a schematic block diagram of the wireless system according to this embodiment. The figure schematically represents a part of the configuration of the wireless system 1. The wireless system 1 has a network 30 and terminal devices 50. As an example, the figure shows one network and multiple terminal devices 50. Specifically, as an example of multiple terminal devices 50, terminal device 50-1, terminal device 50-2, ... and terminal device 50-m (where m is a natural number of 1 or more) are shown.

[0014] Network 30 communicates information with terminal devices 50. Network 30 includes at least a base station. The base station may include the functions of an O-RU (Radio Unit), an O-DU (Distributed Unit), and an O-CU (Central Unit), as defined in the O-RAN (Open-RAN) specification, for example.

[0015] Base stations are sometimes also called next generation Node B (gNodeB or gNB), en-gNB, Next Generation-Radio Access Network (NG-RAN) node, eNB, low-power node, CU, DU, RU, gNB-DU, Remote Radio Head (RRH), Integrated Access and Backhaul / Backhauling (IAB) node, etc. A base station is not limited to a single node, but may consist of multiple nodes (for example, a combination of lower-level nodes such as RU or DU and higher-level nodes such as CU).

[0016] The terminal device 50 is used by the user. Specific examples of the terminal device 50 include smartphones, tablet devices, wearable devices, etc. The terminal device 50 may also be referred to as a user device or UE.

[0017] Here, both the network 30 and the terminal device 50 are equipped with a computing device 10. The computing device 10 comprises at least a processor and memory as hardware components. The computing device 10 may also be implemented by having a computer execute a program. The computing device 10 performs calculations to expand or compress the number of bits in a key used for encryption or decryption. The configurations of the computing devices 10 in the network 30 and the terminal device 50 may be the same or different. However, at least a part of the configuration of the computing devices 10 in the network 30 and the terminal device 50 shall be the same.

[0018] Furthermore, the location of the arithmetic unit 10 within the network 30 is arbitrary. For example, the arithmetic unit 10 may be located in gNodeB or AMF. Alternatively, the arithmetic unit 10 may be located in at least one of gNodeB or AMF within the network 30.

[0019] Figure 3 illustrates the processing in the case where a 128-bit key and a 256-bit key are provided to the wireless system according to this embodiment. Here, the wireless system 1 may be provided with a 128-bit key or a 256-bit key. Whether to use a 128-bit key or a 256-bit key for encrypted communication is decided at the start of communication. Specifically, the network 30 and the terminal device 50 negotiate at the start of communication to determine the algorithm to be used. If the negotiation results in the use of a 128-bit key and a 128-bit key is provided, it is possible to perform encrypted communication with each other using the 128-bit key as is. However, if a 256-bit key is provided, it is necessary to first compress the 256-bit key to 128 bits and then perform encrypted communication with each other using the compressed 128-bit key.

[0020] Figure 3(A) shows an example where a 128-bit key is provided. In this case, the network 30 and the terminal device 50 can communicate with each other using the 128-bit key in an encrypted manner.

[0021] Figure 3(B) shows an example where a 256-bit key is provided. In this case, both the network 30 and the terminal device 50 are required to compress the 256-bit key to 128 bits. The network 30 and the terminal device 50 then use the compressed key to perform encrypted communication with each other.

[0022] [Key Compression Method] A specific example of a key compression method will be described below. The key compression method described below is performed by the computing devices 10 provided in the network 30 and the terminal device 50, respectively. In other words, the key compression method described below is performed separately and independently in both the network 30 and the terminal device 50. In the above example, a 256-bit key is compressed to 128 bits, but the number of bits of the key targeted by the key compression method according to this embodiment is not limited to this example. In the following description, the number of bits of the key will be generalized.

[0023] Assume that a common key K1 has been generated between the terminal device 50 and the network 30 as a key to be used for encryption. The common key K1 can also be said to be a key assigned for use in communication between the terminal device 50 and the network 30. Also, assume that algorithm E has been selected as the encryption method to be used between the terminal device 50 and the network 30. The input key for algorithm E is referred to as input key K2. The input key K2 can also be said to be a key used in the predetermined algorithm E. The above-mentioned arithmetic device 10 generates the input key K2 by compressing the common key K1. The terminal device 50 and the network 30, which communicate information with each other, generate the same input key K2 by compressing the same common key K1.

[0024] [Timing of Common Key and Encryption Key Generation and Key Compression] Fig. 4 is a sequence diagram showing timing of common key and encryption key generation and key compression according to this embodiment. The timing of common key and encryption key generation and key compression will be described with reference to this diagram.

[0025] (Step S11) First, an AKA (Authentication Key Agreement) protocol is executed between the terminal device 50 and the network 30. Specific examples of the AKA protocol include 5G-AKA and EAP-AKA.

[0026] (Step S12) When the AKA protocol is executed, an encryption key CK1 and an authentication key IK1 are generated from the common key K1 that has already been assigned in the terminal device 50. If the common key K1 is 256 bits, the encryption key CK1 and the authentication key IK1 will each be 256 bits. In other words, the key formed by concatenating the encryption key CK1 and the authentication key IK1 will be 512 bits.

[0027] (Step S13) Also, similar to step S12, an encryption key CK1 and an authentication key IK1 are generated from the already assigned common key K1 on the network 30 side. Because the common key K1 has been agreed upon between the network 30 and the terminal device 50, the encryption key CK1 and authentication key IK1 generated by the terminal device 50 are identical to the encryption key CK1 and authentication key IK1 generated by the network 30.

[0028] (Step S14) Once the encryption key CK1 and authentication key IK1 have been generated, the encryption key CK1 and authentication key IK1 are compressed to generate an input key K2. The input key K2 is, for example, a key in which the encryption key CK2 and the authentication key IK2 are concatenated, and may be, for example, a 256-bit bit string in which the 128-bit encryption key CK2 and the 128-bit authentication key IK2 are concatenated.

[0029] (Step S15) As in step S14, the encryption key CK1 and authentication key IK1 are compressed on the network 30 side to generate an input key K2. Since the encryption key CK1 and authentication key IK1 are the same between the network 30 and the terminal device 50, the input key K2 generated by the terminal device 50 and the input key K2 generated by the network 30 are the same.

[0030] [First Calculation Method] Figure 5 is an illustrative diagram illustrating the outline of the first calculation method according to this embodiment. The outline of the first calculation method will be explained with reference to the figure. The first calculation method comprises an encryption key / authentication key generation step P10, a processing step P11, and a hashing step P12.

[0031] First, in the encryption key / authentication key generation process P10, an encryption key CK1 and an authentication key IK1 are generated from a common key K1. The encryption key CK1 is a key used for encryption. The authentication key IK1 is a key used for integrity protection. A key used for integrity protection is, for example, an authentication key used to detect data tampering. The encryption key CK1 and the authentication key IK1 may be used in conjunction with each other, and the encryption key CK1 and the authentication key IK1 can also be collectively referred to as keys used for encryption and integrity protection. Hereinafter, in this embodiment, it is assumed that the encryption key CK1 and the authentication key IK1 are used in conjunction with each other as the input key K2, but this embodiment is not limited to this example. The encryption key CK1 and the authentication key IK1 may also be used separately and independently.

[0032] The encryption key / authentication key generation process P10 may be executed in response to the execution of the AKA algorithm for mutual authentication between the terminal device 50 and the network 30. In other words, the encryption key CK1 and the authentication key IK1 may be generated each time the AKA algorithm is executed. Furthermore, the processing process P11 and the hashing process P12, which will be described later, may be executed each time the AKA algorithm is executed and the encryption key CK1 and the authentication key IK1 are generated.

[0033] Next, the generated encryption key CK1 and authentication key IK1 are input to processing step P11. In processing step P11, if the bit length (e.g., 512 bits) of the bit string obtained by concatenating the encryption key CK1 and authentication key IK1 is longer than the bit length (e.g., 256 bits) of the input key K2 used in algorithm E, some kind of arithmetic processing is performed on the bit string obtained by concatenating the encryption key CK1 and authentication key IK1, thereby obtaining a bit string that is at least different from the bit string of the common key K1.

[0034] Here, the calculation processes performed in processing step P11 are different from each other based on predetermined conditions. These different processes based on predetermined conditions may, for example, be different processes for each business operator, or different processes for each country, region, or organization. More specifically, these different calculation processes may be different calculations themselves, or the fixed values ​​used in the calculations may be different. In the following explanation, as an example, we will describe the case in which the calculation processes performed in processing step P11 are different for each business operator. A specific example of calculation processing will be described below.

[0035] (1) For example, as an example of arithmetic processing, processing by shift operations can be illustrated. More specifically, shift operations may include logical shifts, arithmetic shifts, and cyclic shifts. Processing step P11 can also be performed by performing a shift operation on a bit sequence formed by concatenating the encryption key CK1 and the authentication key IK1, thereby obtaining a bit sequence different from the bit sequence formed by concatenating the encryption key CK1 and the authentication key IK1.

[0036] (2) As an example of arithmetic processing, arithmetic processing with fixed values ​​that differ for each business operator can be exemplified. More specifically, arithmetic processing with fixed values ​​may include arithmetic operations and logical operations. The fixed values ​​used in the arithmetic processing may be those that have been assigned to each business operator in advance. Processing step P11 can also be used to obtain a bit sequence different from the bit sequence formed by linking the encryption key CK1 and the authentication key IK1, by performing operations using a bit sequence formed by linking the encryption key CK1 and the authentication key IK1, and a fixed value that differs for each business operator.

[0037] (3) As an example of arithmetic processing, a process of concatenating with a fixed value that differs for each business operator can be exemplified. More specifically, the process of concatenating with a fixed value may be a process of concatenating a fixed value, such as 4 bits or 8 bits, that has been pre-assigned to each business operator, to the end or beginning of the bit sequence that concatenates the encryption key CK1 and the authentication key IK1. Processing step P11 can also be used to obtain a bit sequence different from the bit sequence that concatenates the encryption key CK1 and the authentication key IK1 by concatenating the bit sequence that concatenates the encryption key CK1 and the authentication key IK1 with a fixed value that differs for each business operator. Here, the number of bits will increase due to the concatenation. However, it is acceptable if the number of bits increases (or decreases) as a result of the calculation by processing step P11.

[0038] (4) As an example of arithmetic processing, it is conceivable to perform processing that combines multiple processes from (1) to (3) described above. This combined processing may be a combination of at least two of the following: shift operations such as logical shifts, arithmetic shifts, and cyclic shifts; arithmetic operations, logical operations, and concatenation processing with fixed values ​​that differ for each business operator.

[0039] Next, the bit sequence after processing in step P11 (processed bit sequence) is input to the hashing step P12.

[0040] In the hashing step P12, the bit sequence obtained in processing step P11 is input to a predetermined hash function to obtain a bit sequence with the same bit length as the input key K2. The bit sequence obtained in the hashing step P12 can also be said to be the input key K2, which is formed by linking the encryption key CK2 used for encryption and the authentication key IK2 used for integrity assurance. Here, the hash function used in the hashing step P12 is a function agreed upon in advance between the terminal device 50 and the network 30. This hash function may be stored in memory units (not shown) of the terminal device 50 and the network 30, respectively.

[0041] Here, it is preferable that the hash function used in the hashing step P12 be the same function even if different arithmetic operations are performed in each processing step. Specifically, it is preferable that the hash function be the same function even if the operators are different. From the viewpoint of ensuring independence, it is preferable that different input keys K2 are generated for each operator, even from the same common key K1. The memory capacity of the hash function used in the hashing step P12 is greater than the memory capacity of the arithmetic method used in the processing step P11. Therefore, if different hash functions are prepared for each operator, the terminal device 50 must store as many hash functions as there are operators, which is a burden on the terminal device 50 (in other words, a large memory area must be secured). According to this embodiment, by using a common hash function for each operator and using different arithmetic methods for each operator, the load on the terminal device 50 can be reduced while ensuring the independence of the input keys K2 (and thus improving security).

[0042] In the first calculation method, the hashing step P12 uses the hash value obtained by inputting the bit sequence obtained in the processing step P11 into a hash function as the input key K2. In other words, the hashing step P12 can also be said to obtain a hash value by inputting the bit sequence obtained in the processing step P11 into a hash function, thereby obtaining a bit sequence with the same bit length as the input key K2.

[0043] 6 is a flowchart showing a series of steps in the first calculation method according to this embodiment. With reference to this figure, the series of steps in the calculation method described with reference to FIG. 5 will be described.

[0044] (Step S21) First, execution of the AKA protocol triggers the generation of an encryption key CK1 and an authentication key IK1 from the common key K1. This step corresponds to the encryption key and authentication key generation step P10 in FIG. 5.

[0045] (Step S22) Next, the calculation device 10 compares the bit lengths of the common key K1 and the input key K2. When the bit length of the common key K1 is |K1| and the bit length of the input key K2 is |K2|, if |K1|>|K2| (i.e., step S22; YES), the calculation device 10 proceeds to step S23 to generate the input key K2 from the common key K1, and continues the subsequent processing. If |K1|>|K2| is not true (i.e., step S22; NO), the calculation device 10 does not need to perform key compression processing, and therefore ends the processing.

[0046] (Step S23) Next, the calculation device 10 performs different calculation processes on the bit string formed by concatenating the encryption key CK1 and the authentication key IK1 based on predetermined conditions. Specifically, the calculation device 10 performs different calculation processes for each business operator on the bit string formed by concatenating the encryption key CK1 and the authentication key IK1. This step is processing step P11 in FIG. 5.

[0047] (Step S24) Furthermore, the calculation device 10 obtains a hash value by inputting the bit string obtained in step S23 into a predetermined hash function. This step is the hashing step P12 in Fig. 5. The calculation device 10 can use the obtained hash value as the input key K2.

[0048] [Modification of the First Calculation Method] Next, a modification of the first calculation method will be described. In this modification of the first calculation method, the order of the processing step and the hashing step is reversed. That is, in this modification of the first calculation method, the hashing step is performed first, and then the processing step is performed.

[0049] 7 is an image diagram for explaining an overview of a modified example of the first calculation method according to this embodiment. The overview of the modified example of the first calculation method will be explained with reference to the same figure. It should be noted that, in the explanation of the modified example of the first calculation method, explanation of matters that have already been explained may be omitted. The modified example of the first calculation method includes an encryption key / authentication key generation step P20, a hashing step P21, and a processing step P22. The encryption key / authentication key generation step P20 performs the same processing as the encryption key / authentication key generation step P10, and therefore explanation thereof will be omitted.

[0050] The hashing step P21 is a modified example of the hashing step P12. The hashing step P21 is similar to the hashing step P12 in that an input value is input to a predetermined hash function to obtain a bit string having a predetermined bit length. The input to the hashing step P21 is a bit string formed by concatenating the encryption key CK1 and the authentication key IK1, and is therefore different from the hashing step P12, which inputs a processed bit string. In the hashing step P21, by inputting the bit string formed by concatenating the encryption key CK1 and the authentication key IK1 to a predetermined hash function, it is also possible to obtain a bit string different from the bit string formed by concatenating the encryption key CK1 and the authentication key IK1.

[0051] Processing step P22 is a modified example of processing step P11. The calculation performed in processing step P22 is the same as the calculation performed in processing step P11. Processing step P22 differs from processing step P11, which takes as input a bit string formed by concatenating encryption key CK1 and authentication key IK1, in that processing step P22 takes as input a hashed bit string. In processing step P22, by performing calculation processing that differs for each business operator on the bit string obtained in hashing step P21, it is also possible to obtain a bit string having the same bit length as the bit length of input key K2.

[0052] Here, in the modified example of the first calculation method, the bit length of the input and output may differ due to processing step P22. For example, if a 256-bit output is desired and 4-bit bit strings are concatenated in processing step P22, the hash value output by hashing step P21 may be adjusted to 252 bits, or the bit length of the bit string finally output from processing step P22 may be adjusted to be the same as the bit length of input key K2.

[0053] Fig. 8 is a flowchart showing a series of steps in a modified example of the first calculation method according to this embodiment. With reference to Fig. 8, the series of steps in the calculation method described with reference to Fig. 7 will be described. Note that, as steps S21 and S22 have already been described with reference to Fig. 6, their description will be omitted.

[0054] (Step S31) First, the arithmetic unit 10 obtains a hash value by inputting the bit sequence formed by linking the encryption key CK1 and the authentication key IK1 into a predetermined hash function. This step is the hashing step P21 in Figure 7.

[0055] (Step S32) Next, the arithmetic unit 10 performs different arithmetic processing on the bit sequence obtained in step S31 for each business operator. This step is the processing step P22 in Figure 7. The arithmetic unit 10 can use the bit sequence obtained as a result of the arithmetic processing as the input key K2.

[0056] Here, a hash function has the characteristic that even a slight difference in the input value will result in a significantly different output value. When comparing the first calculation method with a modified version of the first calculation method, the first calculation method performs processing before inputting to the hash function, so it can be said that the first calculation method can generate a completely different input key K2 for each business operator. Therefore, it can also be said that the first calculation method can generate a more secure input key K2.

[0057] It should be noted that the processing step according to this embodiment is not limited to the example where it is performed either before or after the hashing step. The processing step may be performed both before and after the hashing step. In other words, the first calculation method and a modified version of the first calculation method may be used in combination.

[0058] [Second Calculation Method] Figure 9 is an illustrative diagram illustrating an overview of a modified example of the second calculation method according to this embodiment. The overview of the second calculation method will be explained with reference to the figure. The second calculation method includes an encryption key / authentication key generation step P30, a processing step P31, and a hashing step P33. The hashing step P33 differs from the hashing step P12 in that it uses multiple hash functions. The encryption key / authentication key generation step P30 was explained with reference to Figure 5. Since it is the same as the encryption key / authentication key generation step P10, the explanation will be omitted. Also, the processing step P31 is the same as the processing step P11 explained with reference to Figure 5, so the explanation will be omitted.

[0059] In the hashing process P33, the extraction process P32 is performed first. The extraction process P32 is the process of extracting the upper bit sequence and the lower bit sequence from the bit sequence obtained as a result of the processing in the processing process P31. If the bit sequence obtained as a result of the processing in the processing process P31 is 512 bits, the extraction process P32 extracts the upper 256 bits and the lower 256 bits.

[0060] The extracted upper bit sequence is input to the first hash function 331. The first hash function 331 outputs a first hash value. In the hashing step P33, the first hash value can also be obtained by inputting the upper bits of the bit sequence obtained in the processing step P31 to the first hash function 331. Similarly, the extracted lower bit sequence is input to the second hash function 332. The second hash function 332 outputs a second hash value. In the hashing step P33, the second hash value can also be obtained by inputting the lower bits of the bit sequence obtained in the processing step P31 to the second hash function 332. Both the first hash function 331 and the second hash function 332 are functions agreed upon in advance between the terminal device 50 and the network 30. These hash functions may be stored in memory units (not shown) of the terminal device 50 and the network 30, respectively.

[0061] Next, a predetermined operation is performed based on the first hash value and the second hash value to obtain a bit sequence with the same bit length as the input key K2. The predetermined operation may be, for example, an exclusive OR operation as shown in the figure. However, this embodiment is not limited to this example, and a bit sequence with the same bit length as the input key K2 may be obtained by other operations based on the first hash value and the second hash value.

[0062] The calculation in the hashing process P33 can be expressed as the following equation (1).

[0063]

[0064] [Internal Configuration] FIG. 10 is a block diagram showing an example of the internal configuration of a network or a terminal device according to this embodiment. At least some of the functions of the network 30 or the terminal device 50 can be implemented using a computer. As shown in the figure, the computer includes a central processing unit (processor) 901, a RAM 902, an input / output port 903, input / output devices 904 and 905, and a bus 906. The computer itself can be implemented using existing technology. The central processing unit 901 executes instructions contained in a program read from the RAM 902 or the like. In accordance with each instruction, the central processing unit 901 writes data to the RAM 902, reads data from the RAM 902, and performs arithmetic and logical operations. The RAM 902 stores data and programs. Each element included in the RAM 902 has an address and can be accessed using the address. Note that RAM stands for "random access memory." The input / output port 903 is a port through which the central processing unit 901 exchanges data with external input / output devices, etc. The input / output devices 904 and 905 are input / output devices. The input / output devices 904 and 905 exchange data with the central processing unit 901 via the input / output port 903. The bus 906 is a common communication path used within the computer. For example, the central processing unit 901 reads and writes data from the RAM 902 via the bus 906. Also, for example, the central processing unit 901 accesses the input / output port via the bus 906. Furthermore, all or part of the functional units provided in the network 30 or the terminal device 50 may be realized using hardware such as an ASIC, a PLD, or an FPGA. Furthermore, all or part of the functional units may be realized by a combination of software and hardware.

[0065] [Summary of Embodiments] According to the embodiments described above, the arithmetic unit 10 causes a computer, which has at least a processor and memory, to perform a processing step and a hashing step. The processing step is performed on the bit sequence of the key used for encryption and integrity assurance, which is generated from a common key K1 assigned for communication between the terminal device 50 and the network 30. If the bit length of the key used for encryption and integrity assurance is longer than the bit length of the input key K2 used in a predetermined algorithm E, the processing step is performed on the bit sequence of the key used for encryption and integrity assurance generated from the common key K1, based on predetermined conditions, to obtain a bit sequence different from the bit sequence of the key used for encryption and integrity assurance generated from the common key K1. The hashing step is performed on the bit sequence obtained in the processing step, which is input into a predetermined hash function agreed upon in advance between the terminal device 50 and the network 30, to obtain a bit sequence having the same bit length as the bit length of the input key K2. By adopting such a configuration, the bit length of a given key can be compressed, and a key equal in size to the key used in the cryptographic algorithm can be generated.

[0066] Furthermore, the above-described embodiment, for example, by "compressing the bit length of a given key and generating a key of the same size as the key used in the cryptographic algorithm," makes it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "build resilient infrastructure, promote sustainable industrialization and foster innovation."

[0067] Although embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments, and design modifications and the like are also included within the scope of the gist of the present invention.

[0068] Furthermore, a computer program for implementing the functions of each of the above-described devices may be recorded on a computer-readable recording medium, and the program may be read and executed by a computer system. The term "computer system" may also include hardware such as an OS and peripheral devices. The term "computer-readable recording medium" refers to a flexible disk, a magneto-optical disk, a ROM, a writable nonvolatile memory such as a flash memory, a portable medium such as a DVD (Digital Versatile Disc), or a storage device such as a hard disk built into a computer system.

[0069] Furthermore, the term "computer-readable recording medium" also includes a storage medium that stores a program for a certain period of time, such as a volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that serves as a server or client when the program is transmitted via a network such as the Internet or a communication line such as a telephone line. The program may also be transmitted from a computer system that stores the program in a storage device or the like to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" that transmits the program refers to a medium that has the function of transmitting information, such as a network (communication network) such as the Internet or a communication line (communication line) such as a telephone line. The program may also be a program that realizes part of the aforementioned functions. Furthermore, the program may be a so-called differential file (differential program) that can realize the aforementioned functions in combination with a program already recorded in the computer system.

[0070] According to the present invention, it is possible to compress the bit length of a given key and generate a key having the same size as the key used in the encryption algorithm.

[0071] 1...wireless system, 10...arithmetic device, 30...network, 50...terminal device, K1...common key, E...algorithm, K2...input key, CK1, CK2...encryption key, IK1, IK2...authentication key, P10, P20, P30...encryption key / authentication key generation process, P11, P22, P31...processing process, P12, P21, P33...hashing process, P32...extraction process, 331...first hash function, 332...second hash function

Claims

1. A computer comprising at least a processor and memory, which is a computing device that causes a computer to perform the following steps: a processing step to obtain a bit sequence different from the bit sequence of the key used for encryption and integrity assurance generated from a common key, where the key and bit length used for encryption and integrity assurance are longer than the bit length of the input key used in a predetermined algorithm, by performing different arithmetic operations on the bit sequence of the key used for encryption and integrity assurance generated from the common key based on predetermined conditions; and a hashing step to obtain a bit sequence having the same bit length as the bit length of the input key by inputting the bit sequence obtained in the processing step into a predetermined hash function agreed in advance between the terminal device and the network.

2. The computing device according to claim 1, wherein the key generated from the common key and used for encryption and integrity protection is a key obtained by concatenating an encryption key for encryption and an authentication key for integrity protection.

3. The computing device according to claim 2, wherein the encryption key and the authentication key are generated each time an AKA algorithm for authentication is executed between the terminal device and the network, and the processing step and the hashing step are executed each time the encryption key and the authentication key are generated.

4. The computing device according to claim 1, wherein the bit string obtained by the hashing step is the input key that is a concatenation of an encryption key for encryption and an authentication key used for integrity protection.

5. The computing device according to claim 1, wherein the hash functions are the same even when different computation processes are performed in the processing step.

6. The computing device according to claim 1, wherein the processing step obtains a bit string different from the bit string of the common key by performing a shift operation on the bit string of the key used for encryption and integrity protection generated from the common key.

7. The computing device according to claim 1, wherein the processing step obtains a bit string different from the bit string of the common key by performing an operation using a bit string of a key used for encryption and integrity protection generated from the common key and a fixed value that differs from each other based on a predetermined condition.

8. The arithmetic apparatus according to claim 1, wherein the processing step obtains a bit sequence different from the bit sequence of the common key by concatenating a bit sequence of a key used for encryption and integrity assurance generated from the common key with fixed values ​​that are different from each other based on predetermined conditions.

9. The arithmetic device according to claim 1, wherein the hashing step involves inputting the bit sequence obtained by the processing step into the hash function to obtain a bit sequence having the same bit length as the bit length of the input key as a hash value.

10. The arithmetic device according to claim 1, wherein the hashing step involves inputting the upper bits of the bit sequence obtained in the processing step into a first hash function agreed in advance between the terminal device and the network to obtain a first hash value, inputting the lower bits of the bit sequence obtained in the processing step into a second hash function agreed in advance between the terminal device and the network to obtain a second hash value, and performing a predetermined operation based on the obtained first hash value and the second hash value to obtain a bit sequence having the same bit length as the bit length of the input key.

11. The arithmetic device according to claim 10, wherein the hashing step involves performing an exclusive OR operation between the obtained first hash value and the second hash value to obtain a bit sequence having the same bit length as the input key.

12. The calculation apparatus according to claim 1, wherein the calculation processes performed by the processing step, which differ from one another based on predetermined conditions, are calculation processes that differ from one another for each business operator.

13. A terminal device comprising the arithmetic unit according to any one of claims 1 to 12.

14. A network comprising the computing device according to any one of claims 1 to 12.

15. The network according to claim 14, wherein the computing device is provided in at least one of next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function).

16. A calculation method comprising: a processing step of performing different calculation processes based on predetermined conditions on the bit string of the key used for encryption and integrity protection generated from the common key, where the key and bit length used for encryption and integrity protection are longer than the bit length of the input key used in a predetermined algorithm, to obtain a bit string different from the bit string of the key used for encryption and integrity protection generated from the common key; and a hashing step of inputting the bit string obtained by the processing step into a predetermined hash function agreed upon in advance between the terminal device and the network, to obtain a bit string having the same bit length as the bit length of the input key.

17. A program that causes a computer to execute the following steps: a processing step of performing different arithmetic operations on the bit string of the key used for encryption and integrity protection generated from the common key, based on predetermined conditions, to obtain a bit string different from the bit string of the key used for encryption and integrity protection generated from the common key, when the key and bit length used for encryption and integrity protection are longer than the bit length of the input key used in a predetermined algorithm, said processing step being different from the bit string of the key used for encryption and integrity protection generated from the common key; and a hashing step of inputting the bit string obtained by said processing step into a predetermined hash function agreed upon in advance between said terminal device and said network, to obtain a bit string having the same bit length as the bit length of said input key.

Citation Information

Patent Citations

  • Communication device, control method and program

    JP2017112551A

  • Systems, methods and computer program products for reducing effective key length of ciphers using one-way cryptographic functions and an initial key

    US6560337B1