Calculation device, terminal device, network, calculation method, and program

By adjusting key bit lengths and modifying stream cipher constants or initial values based on key size, the computing device generates distinct ciphertexts for 128-bit and 256-bit keys, resolving the issue of identical ciphertexts in mixed key systems.

WO2026063076A1PCT designated stage Publication Date: 2026-03-26KDDI CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

The introduction of 256-bit encryption in communication systems poses a challenge as it is unclear how to distinguish between 128-bit and expanded 256-bit keys or compressed 256-bit and 128-bit keys, leading to identical ciphertexts when using these keys for encryption.

Method used

A computing device and method that adjusts the bit length of common keys by expanding or shortening them and modifies constants or initial values in stream ciphers like AEGIS-256 and Rocca-S based on key bit length to generate distinct ciphertexts.

Benefits of technology

Ensures different ciphertexts are generated even when using keys with different bit sequences, addressing the issue of identical ciphertexts from differently sized keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025027553_26032026_PF_FP_ABST
    Figure JP2025027553_26032026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a calculation device that is provided with at least a processor and a memory and that, when the bit length of a common key which has been assigned to be used for communication between a terminal device and a network differs from the bit length of an input key which is used in a prescribed algorithm, increases or reduces the bit length of the assigned common key, thereby performing conversion into a key with a prescribed bit length, and performs encryption processing or decryption processing on a stream cipher, wherein at least one of a constant and an initial value that are used to initialize the stream cipher differs according to the bit length of the assigned common key.
Need to check novelty before this filing date? Find Prior Art

Description

Computing unit, terminal device, network, calculation method and program

[0001] The present invention relates to a computing device, a terminal device, a network, a computing method, and a program. This application claims priority to Japanese Patent Application No. 2024-162615, filed in Japan on September 19, 2024, the contents of which are incorporated herein by reference.

[0002] Conventional 3GPP (registered trademark) specifications are formulated on the premise that a 128-bit key is assigned to 128-bit encryption. For example, Non-Patent Document 1 defines the specific specifications of such technology. Non-Patent Documents 2 and 3 define the specific specifications of encryption.

[0003] 3GPP, “TS 33.501”, v18.5.0 Hongjun Wu and Bart Preneel, “AEGIS: A Fast Authenticated Encryption Algorithm”, SAC 2013. LNCS, vol 8282, pp. 185-201, 2014. Ravi Anand, Subhadeep Banik, Andrea Caforio, Kazuhide Fukushima, Takanori Isobe, Shisaku Kiyomoto, Fukang Liu, Yuto Nakano, Kosei Sakamoto, and Nobuyuki Takeuchi, “An Ultra-High Throughput AES-Based Authenticated Encryption Scheme for 6G: Design and Implementation”, ESORICS 2023. LNCS, vol 14344, pp. 229-248, 2024.

[0004] Here, discussions are currently underway to introduce 256-bit encryption. If 256-bit encryption is introduced, 256-bit keys and 128-bit keys will coexist. For example, there is a possibility that a 128-bit key may be assigned to 256-bit encryption. In order to use a 128-bit key with 256-bit encryption, it is necessary to expand the 128-bit key to a 256-bit key. In this case, it is impossible to distinguish between the key assigned as 256 bits and the 256-bit key obtained by expanding the 128-bit key. Also, there is a possibility that a 256-bit key may be assigned to 128-bit encryption. In order to use a 256-bit key with 128-bit encryption, it is necessary to compress the 256-bit key to a 128-bit key. In this case, it is impossible to distinguish between the key assigned as 128 bits and the 128-bit key obtained by compressing the 256-bit key.

[0005] In other words, when the bit sequence of the assigned key and the bit sequence of the key obtained by expanding or compressing the assigned key are the same, there is a problem that they cannot be distinguished. Therefore, when encryption processing is performed using these keys, the same ciphertext will be obtained. However, these keys were originally keys with different bit sequences, and it is desirable to obtain different ciphertexts.

[0006] The present invention has been made in consideration of such circumstances, and its object is to generate different ciphertexts or decrypt ciphertexts even when encryption processing is performed using a key obtained by expanding or compressing the bit length of a key, provided that the bit sequences of the assigned keys are different, and to provide an arithmetic device, a terminal device, a network, and an arithmetic method.

[0007] (1) One aspect of the present invention is an arithmetic device comprising at least a processor and memory, wherein when the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the device converts the assigned common key to a key of a predetermined bit length by expanding or shortening the bit length of the assigned common key, and performs encryption or decryption processing of a stream cipher, wherein at least one of the constant or initial value used for initializing the stream cipher differs depending on the bit length of the assigned common key. (2) Another aspect of the present invention is the arithmetic device of (1) described above, wherein the number of initializations of the stream cipher is made different from the number of initializations defined by the encryption method used for encryption or decryption processing of the stream cipher, thereby making the initial value used for initializing the stream cipher different depending on the bit length of the assigned common key. (3) Another aspect of the present invention is the arithmetic device of (1) or (2) described above, wherein the encryption method used for encryption or decryption processing of the stream cipher is AEGIS-256. (4) In addition, in the arithmetic unit described in (3) above, at least one bit of the constant S2 or S3 among the 128-bit blocks S0 to S5 is different in the stream cipher initialization process according to the bit length of the assigned common key. (5) In addition, in the arithmetic unit described in (1) or (2) above, the encryption method used for the encryption or decryption process of the stream cipher is Rocca-S. (6) In addition, in the arithmetic unit described in (5) above, at least one value of the constant S[2] or S[1] among S[0] to S[6] indicating the state of Rocca-S is different in the stream cipher initialization process according to the bit length of the assigned common key. (7) In another aspect of the present invention, in the arithmetic unit of (5) described above, the value of S[6] among S[0] to S[6] which indicate the state of Rocca-S is different in the initialization process of the stream cipher according to the bit length of the common key that was assigned.(8) Another aspect of the present invention is a terminal device equipped with the arithmetic unit described in any of (1) to (7) above. (9) Another aspect of the present invention is a network equipped with the arithmetic unit described in any of (1) to (7) above. (10) Another aspect of the present invention is the network described in (9) above, wherein the arithmetic unit is provided in at least one of next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function). (11) Another aspect of the present invention is a calculation method to be executed by an arithmetic unit comprising at least a processor and memory, wherein, when the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned common key is converted to a key of a predetermined bit length by expanding or shortening the bit length, and a stream cipher encryption or decryption process is performed, wherein at least one of the constants or initial values ​​used to initialize the stream cipher differs depending on the bit length of the assigned common key. (12) Another aspect of the present invention is a program to be executed by an arithmetic unit comprising at least a processor and memory, wherein, when the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned common key is converted to a key of a predetermined bit length by expanding or shortening the bit length, and a stream cipher encryption or decryption process is performed, wherein at least one of the constants or initial values ​​used to initialize the stream cipher differs depending on the bit length of the assigned common key.

[0008] According to the present invention, even when encryption processing is performed using a key obtained by expanding or contracting the bit length of the key, if the bit sequences of the assigned keys are different, it is possible to provide a computing device, terminal device, network, and computing method that can generate different ciphertexts or decrypt ciphertexts.

[0009] This figure shows the schematic architecture of a wireless system according to one embodiment. This is a schematic block diagram of the wireless system according to this embodiment. This figure illustrates the processing when a 128-bit key is given to the wireless system according to this embodiment, and when a 256-bit key is given. This is the first figure illustrating the initialization of a block when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. This is the second figure illustrating the initialization of a block when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. This figure shows an example of the correspondence between the number of bits in a key and a constant in the wireless system according to this embodiment. This figure illustrates the initialization of a block when the Rocca-S encryption method is adopted in the wireless system according to this embodiment. This is a block diagram illustrating an example of the internal configuration of the arithmetic unit according to this embodiment.

[0010] [Embodiments] Preferred embodiments of the computing device, terminal device, network, computing method, and program according to aspects of the present invention will be described in detail below with reference to the attached drawings. It should be noted that the embodiments of the present invention are not limited to these embodiments, and include various modifications or improvements. In other words, the components described below include those that are easily conceivable by those skilled in the art, and those that are substantially the same, and the components described below can be combined as appropriate. Furthermore, various omissions, substitutions, or modifications of components can be made without departing from the spirit of the present invention. Also, in the following drawings, the scale and number of components in each structure may differ from the scale and number of components in the actual structure in order to make each structure easier to understand.

[0011] In the following description, for the sake of clarity, terms and names defined in the IETF (Internet Engineering Task Force), 3GPP (registered trademark), and LTE (3rd Generation Partnership Project Long Term Evolution) standards may be used. However, this embodiment is not limited by such terms and names and is applicable to systems based on other standards.

[0012] [Wireless System] Figure 1 is a diagram showing the schematic architecture of a wireless system according to one embodiment. The wireless system 1 shown in the figure has a control plane (C-Plane), which is a function for controlling communication, and a user plane (U-Plane), which is a function for realizing user communication, as its functional configuration. For the sake of simplicity, the figure shows the basic architecture used in fifth-generation mobile communication systems (5G), but the wireless system 1 to which this embodiment is applied is not limited to an example applied to 5G, but can be broadly applied to other systems.

[0013] In the following explanation, configurations other than UE (User Equipment) may be referred to as the network. The network includes the access layer and the non-access layer. The access layer includes at least a base station, and the non-access layer includes at least an AMF (Access and Mobility Management Function). As shown in the diagram, the UE and AMF communicate with each other via the N1 interface. In the following explanation, base stations and AMF may be referred to as higher-level concepts and simply as the network.

[0014] Figure 2 is a schematic block diagram of the wireless system according to this embodiment. The figure schematically represents a part of the configuration of the wireless system 1. The wireless system 1 has a network 30 and terminal devices 50. As an example, the figure shows one network and multiple terminal devices 50. Specifically, as an example of multiple terminal devices 50, terminal device 50-1, terminal device 50-2, ... and terminal device 50-m (where m is a natural number of 1 or more) are shown.

[0015] Network 30 communicates information with terminal devices 50. Network 30 includes at least a base station. The base station may include the functions of an O-RU (Radio Unit), an O-DU (Distributed Unit), and an O-CU (Central Unit), as defined in the O-RAN (Open-RAN) specification, for example.

[0016] Base stations are sometimes also called next generation Node B (gNodeB or gNB), en-gNB, Next Generation-Radio Access Network (NG-RAN) node, eNB, low-power node, CU, DU, RU, gNB-DU, Remote Radio Head (RRH), Integrated Access and Backhaul / Backhauling (IAB) node, etc. A base station is not limited to a single node, but may consist of multiple nodes (for example, a combination of lower-level nodes such as RU or DU and higher-level nodes such as CU).

[0017] The terminal device 50 is used by the user. Specific examples of the terminal device 50 include smartphones, tablet devices, wearable devices, etc. The terminal device 50 may also be referred to as a user device or UE.

[0018] Here, both the network 30 and the terminal device 50 are equipped with a computing device 10. The computing device 10 comprises at least a processor and memory as hardware components. The computing device 10 may also be implemented by having a computer execute a program. The computing device 10 performs calculations to expand or compress the number of bits in a key used for encryption or decryption. The configurations of the computing devices 10 in the network 30 and the terminal device 50 may be the same or different. However, at least a part of the configuration of the computing devices 10 in the network 30 and the terminal device 50 shall be the same.

[0019] Furthermore, the location of the arithmetic unit 10 within the network 30 is arbitrary. For example, the arithmetic unit 10 may be located in gNodeB or AMF. Alternatively, the arithmetic unit 10 may be located in at least one of gNodeB or AMF within the network 30.

[0020] Figure 3 illustrates the processing in the case where a 128-bit key and a 256-bit key are provided to the wireless system according to this embodiment. Here, the wireless system 1 may be provided with a 128-bit key or a 256-bit key. Whether to perform encrypted communication using a 128-bit key or a 256-bit key is decided at the start of communication. Specifically, the network 30 and the terminal device 50 negotiate at the start of communication to determine the algorithm to be used.

[0021] If, as a result of negotiation, it is decided to use 128 bits and a 128-bit key is provided, it is possible to encrypt communication between parties using the 128-bit key directly. However, if a 256-bit key is provided, it is necessary to first compress the 256-bit key to 128 bits and then use the compressed 128-bit key to encrypt communication between parties. Figures 3(A) and 3(B) show an example where, as a result of negotiation, it is decided to use 128 bits. Figures 3(C) and 3(D) show an example where, as a result of negotiation, it is decided to use 256 bits.

[0022] Figure 3(A) shows an example where, as a result of negotiation, it is decided to use 128 bits and a 128-bit key is provided. In this case, the network 30 and the terminal device 50 can communicate with each other using the 128-bit key in an encrypted manner.

[0023] Figure 3(B) shows an example where, as a result of negotiation, it is decided to use 128 bits and a 256-bit key is provided. In this case, both the network 30 and the terminal device 50 are required to compress the 256-bit key to 128 bits. The network 30 and the terminal device 50 then use the compressed key to perform encrypted communication with each other.

[0024] Figure 3(C) shows an example where, as a result of negotiation, it is decided to use 256 bits and a 128-bit key is provided. In this case, both the network 30 and the terminal device 50 are required to expand the 128-bit key to 256 bits. The network 30 and the terminal device 50 then use the expanded key to perform encrypted communication with each other.

[0025] Figure 3(D) shows an example where, as a result of negotiation, it is decided to use 256 bits and a 256-bit key is provided. In this case, the network 30 and the terminal device 50 can communicate with each other using the 256-bit key in an encrypted manner.

[0026] Here, if the 128-bit key given in Figure 3(A) and the 128-bit key compressed from the 256-bit key in Figure 3(B) are identical, then despite the given keys being different, the encryption process will produce the same ciphertext for both. Similarly, if the 256-bit key given in Figure 3(D) and the 256-bit key expanded from the 128-bit key in Figure 3(C) are identical, then despite the given keys being different, the encryption process will produce the same ciphertext for both.

[0027] Thus, it is undesirable for the same ciphertext to be produced from two different sets of bit sequences. In other words, it is desirable that a given 128-bit key and a 128-bit key compressed based on a given 256-bit key be different keys, and that each generates a different ciphertext. Similarly, it is desirable that a given 256-bit key and a 256-bit key expanded based on a given 128-bit key be different keys, and that each generates a different ciphertext.

[0028] If we want to distinguish between key lengths, we need to provide information about the key length using a separate input parameter, distinct from the key itself. However, in the current specification, there is no input parameter to define the bit length of the key.

[0029] The following describes a method for performing encryption processing using a key obtained by expanding or contracting the bit length of the key, in which the bit length of the key before expansion or contraction is reflected in the encryption processing, and for generating different ciphertexts when the given keys are different. In this embodiment, the encryption or decryption processing of a stream cipher is assumed, but any encryption method can be used. Below, as examples of encryption methods, an example using AEGIS-256 and an example using Rocca-S will be described.

[0030] [AEGIS-256] Figure 4 is the first diagram illustrating the initialization of blocks when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. In AEGIS-256, 128-bit blocks are initialized as shown in the figure. The figure shows 128-bit blocks S0 to S5 from top to bottom. As shown in the figure, S2 is const1 and S3 is const0. That is, S2 and S3 are defined as constants.

[0031] Figure 5 is a second diagram illustrating the initialization of a block when the AEGIS-256 encryption method is adopted in the wireless system according to this embodiment. In AEGIS-256, a constant (const) is defined as a value formed by concatenating S3 = const0 and S2 = const1. S3 = const0 can also be said to be the upper 16 bytes of const, and S2 = const1 can be said to be the lower 16 bytes of const.

[0032] In this embodiment, for example, when a key smaller than 256 bits (e.g., a 128-bit key) is given and the given key is expanded for use in AEGIS-256, the key length is used as an input parameter and reflected in the value of const. For example, since the first byte of const is 00, this first byte is set to a value corresponding to the key length.

[0033] Furthermore, the input parameter for determining the key length is not limited to the example of using the first byte; any bit from the bits defined as constants may be used. That is, in each of the 128-bit blocks S0 to S5, at least one bit of the constant S2 or S3 may differ depending on the bit length of the assigned key during the initialization process of the stream cipher.

[0034] Figure 6 shows an example of the correspondence between the number of bits in a key and a constant in the wireless system according to this embodiment. In the figure, the number of bits in the assigned key is shown in the left column, and the value of the first byte of const is shown in the right column, showing the correspondence between them. As shown in the figure, it is conceivable that the value of the first byte be defined as 01 when using a 192-bit key, 02 when using a 128-bit key, and 03 when using an 80-bit key.

[0035] Note that the illustrated example is just one example, and the value of the first byte of const may be any other value. For example, the value of const could be the number of bits in the key itself. For example, it is possible to define it as C0 when using a 192-bit key, 80 when using a 128-bit key, and 50 when using an 80-bit key.

[0036] Furthermore, this example is not limited to cases where only a part of a block defined as a constant, such as the first byte of const, is modified; it is also possible to prepare a different initial value depending on the length of the bit sequence of the key being used.

[0037] [Rocca-S] Figure 7 is a diagram illustrating the initialization of a block when the Rocca-S encryption method is adopted in the wireless system according to this embodiment. In the Rocca-S initialization process, first, as shown in the figure, N, K0, and K1 are loaded into S[0] to S[6]. Here, S[2] is defined as the constant Z0, and S[4] is defined as the constant Z1. At least a portion of Z0 and Z1 may differ depending on the bit length of the assigned key, as explained with reference to Figure 6. In other words, among S[0] to S[6] which indicate the state of Rocca-S, the value of at least one of the constants S[2] or S[1] differs in the stream cipher initialization process depending on the bit length of the assigned common key.

[0038] In addition to the example of changing at least one of the values ​​of S[2]=Z0 or S[4]=Z1, the value of S[6]=0 may be set to be different depending on the bit length. For example, when using a 192-bit key, S[6] may be initialized as C000...0, when using a 128-bit key, as S[6]=8000...0, and when using an 80-bit key, as S[6]=5000...0. In other words, of the S[0] to S[6] values ​​that indicate the state of Rocca-S, at least the value of S[6] will be different depending on the bit length of the assigned common key during the initialization process of the stream cipher.

[0039] [Method based on the number of initialization rounds] An example of a case in which the constants used to initialize the stream cipher are different depending on the bit length of the assigned symmetric key has been described with reference to Figures 4 to 7. However, this embodiment is not limited to the case in which the constants are different, and the initial values ​​may be different by other methods. For example, it is conceivable to change the number of initialization rounds depending on the bit length of the assigned symmetric key.

[0040] Specifically, in AEGIS-256, the number of initialization rounds is defined as R = 16. For example, the number of initialization rounds may be R + a rounds depending on the bit length of the assigned common key. More specifically, the value of a is a natural number greater than or equal to 1, and a = 0 when using a 256-bit key, a = 1 when using a 192-bit key, a = 2 when using a 128-bit key, and a = 3 when using an 80-bit key. In Rocca-S, the number of initialization rounds is also defined as R = 16. In Rocca-S, as in AEGIS-256, the number of initialization rounds may be R + a rounds depending on the bit length of the assigned common key.

[0041] In other words, the number of initializations for a stream cipher may be made different from the number of initializations defined by the encryption scheme used in the encryption or decryption of the stream cipher, thereby allowing the initial value used to initialize the stream cipher to vary according to the bit length of the assigned common key.

[0042] It could be argued that varying the number of initialization rounds according to the bit length (specifically, performing +a rounds) would increase the initialization time, but this increase is negligible and can be ignored.

[0043] [Internal Configuration] Figure 8 is a block diagram showing an example of the internal configuration of the arithmetic unit according to this embodiment. The arithmetic unit 10 is provided in at least one of the terminal device 50 or the network 30. If the bit length of the common key assigned for use in communication between the terminal device 50 and the network 30 differs from the bit length of the input key used in a predetermined algorithm, the arithmetic unit 10 converts the assigned common key to a key of the predetermined bit length by expanding or shortening the bit length, and then performs encryption or decryption processing of the stream cipher.

[0044] At least some of the functions of the arithmetic unit 10 can be realized using a computer as shown in the figure. The computer includes a central processing unit (processor) 901, a RAM 902, an input / output port 903, input / output devices 904 and 905, etc., and a bus 906. The computer itself can be realized using existing technologies. The central processing unit 901 executes instructions included in a program read from the RAM 902 and the like. The central processing unit 901 writes data to the RAM 902, reads data from the RAM 902, and performs arithmetic operations and logical operations according to each instruction. The RAM 902 stores data and programs. Each element included in the RAM 902 has an address and can be accessed using the address. Note that RAM is an abbreviation for "random access memory". The input / output port 903 is a port for the central processing unit 901 to exchange data with external input / output devices and the like. The input / output devices 904 and 905 are input / output devices. The input / output devices 904 and 905 exchange data with the central processing unit 901 via the input / output port 903. The bus 906 is a common communication path used inside the computer. For example, the central processing unit 901 reads from and writes to the data of the RAM 902 via the bus 906. Also, for example, the central processing unit 901 accesses the input / output port via the bus 906. Also, all or part of each functional unit included in the network 30 or the terminal device 50 may be realized using hardware such as an ASIC, a PLD, or an FPGA. Also, all or part of each functional unit may be realized by a combination of software and hardware.

[0045] [Summary of Embodiment] According to the embodiment described above, the arithmetic unit 10 includes at least a processor and a memory. When the bit length of the common key assigned for communication between the terminal device 50 and the network 30 is different from the bit length of the input key used in a predetermined algorithm, the arithmetic unit 10 converts the bit length of the assigned common key into a key of a predetermined bit length by expanding or shortening it, and performs encryption processing or decryption processing of the stream cipher. The arithmetic unit 10 varies at least one of the constant or the initial value used for initializing the stream cipher according to the bit length of the assigned common key. By adopting such a configuration, when performing encryption processing using the key obtained by expanding or shortening the bit length of the key, the bit length of the key before expansion or shortening can be reflected in the encryption processing.

[0046] According to the present embodiment, in order to reflect the bit length of the key before expansion or shortening in the encryption processing, even if the bit sequences of the keys obtained by expanding or shortening the bit length are the same when the bit lengths before expansion or shortening are different, different ciphertexts can be obtained. In other words, according to the present embodiment, even when performing encryption processing using the key obtained by expanding or shortening the bit length of the key, if the bit sequences of the assigned keys are different, different ciphertexts can be generated or the ciphertext can be decrypted.

[0047] Note that according to the above-described embodiment, for example, "when performing encryption processing using the key obtained by expanding or shortening the bit length of the key, the bit length of the key before expansion or shortening is reflected in the encryption processing", it is possible to contribute to Goal 9 of the Sustainable Development Goals (SDGs) led by the United Nations, "Build resilient infrastructure, promote sustainable industrialization, and foster innovation".

[0048] As described above, the embodiments of the present invention have been described in detail with reference to the drawings, but the specific configuration is not limited to this embodiment, and design changes and the like within the scope not departing from the gist of the present invention are also included.

[0049] Alternatively, computer programs for realizing the functions of each of the above-mentioned devices may be recorded on a computer-readable recording medium, and the programs recorded on this recording medium may be loaded into a computer system and executed. The term "computer system" here may include hardware such as an operating system and peripheral devices. Furthermore, "computer-readable recording medium" refers to writable non-volatile memory such as flexible disks, magneto-optical disks, ROMs, and flash memory, portable media such as DVDs (Digital Versatile Discs), and storage devices such as hard disks built into a computer system.

[0050] Furthermore, "computer-readable recording media" includes volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. In addition, the above program may be transmitted from the computer system that stores the program in a storage device, etc., to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" for transmitting the program refers to a medium that has the function of transmitting information, such as a network such as the Internet or a communication line such as a telephone line. Furthermore, the above program may be for the purpose of realizing a part of the above-mentioned functions. Moreover, it may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system.

[0051] According to the present invention, even when encryption processing is performed using a key obtained by expanding or contracting the bit length of the key, different ciphertexts can be generated or decrypted if the bit sequences of the assigned keys are different.

[0052] 1... Wireless system, 10... Computing unit, 30... Network, 50... Terminal device

Claims

Equipped with at least a processor and memory, A arithmetic unit that, when the bit length of a common key assigned for use in communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, converts the assigned common key to a key of a predetermined bit length by expanding or shortening the bit length of the common key, and then performs encryption or decryption processing of a stream cipher, Depending on the bit length of the assigned common key, at least one of the constants or initial values ​​used to initialize the stream cipher differs. Computing device.   By making the number of initializations of the stream cipher different from the number of initializations defined by the encryption method used in the encryption or decryption process of the stream cipher, the initial value used for initializing the stream cipher is made different according to the bit length of the assigned common key. The computing device according to claim 1.   The encryption method used for the encryption or decryption of the aforementioned stream cipher is AEGIS-256. The computing device according to claim 1.   Of the 128-bit blocks S0 to S5, at least one of the constant bits of S2 or S3 differs in the stream cipher initialization process according to the bit length of the assigned common key. The computing device according to claim 3.   The encryption method used for the encryption or decryption of the stream cipher is Rocca-S. The computing device according to claim 1.   Among the S[0] to S[6] that indicate the state of Rocca-S, the value of at least one of the constants S[2] or S[1] differs in the initialization process of the stream cipher according to the bit length of the assigned common key. The arithmetic device according to claim 5.   Of the S[0] to S[6] values ​​indicating the state of Rocca-S, the value of S[6] differs depending on the bit length of the shared key assigned during the initialization process of the stream cipher. The arithmetic device according to claim 5.   A terminal device comprising the arithmetic unit according to any one of claims 1 to 7.   A network comprising the computing device according to any one of claims 1 to 7.   The aforementioned computing device is provided in at least one of the next generation Node B (gNodeB or gNB) or AMF (Access and Mobility Management Function), The network according to claim 9.   A method of calculation performed by an arithmetic unit comprising at least a processor and memory, If the bit length of a shared key assigned for communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned shared key is converted to a key of the predetermined bit length by expanding or shortening its bit length, and then the encryption or decryption process of the stream cipher is performed. Depending on the bit length of the assigned common key, at least one of the constants or initial values ​​used to initialize the stream cipher differs. Calculation method.   A program to be executed by a computing device that includes at least a processor and memory, If the bit length of a shared key assigned for communication between a terminal device and a network differs from the bit length of an input key used in a predetermined algorithm, the assigned shared key is converted to a key of the predetermined bit length by expanding or shortening its bit length, and then the encryption or decryption process of the stream cipher is performed. Depending on the bit length of the assigned common key, at least one of the constants or initial values ​​used to initialize the stream cipher differs. program.

Citation Information

Patent Citations

  • Terminal device, radio communication system with the same and program to be executed by computer

    JP2023127198A

  • Encryption device, encryption method, and encryption program

    JP2023152132A

  • Encryption device, decryption device, encryption method, and encryption program

    JP2024123822A

  • Systems, methods and computer program products for reducing effective key length of ciphers using one-way cryptographic functions and an initial key

    US6560337B1