Entropy Assessor Module for Cryptographic Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptography systems face challenges in accurately assessing entropy, which is crucial for generating robust cryptographic secrets, as existing methods may underestimate or overestimate entropy due to not accounting for cryptographic operations, leading to potential vulnerabilities against adversarial attacks.

Innovation Solution

A cryptography system that includes an entropy source, a cryptographic secret generator, and an entropy assessor module, which uses statistical inference techniques to assess entropy based on sample values from the entropy source, accounting for cryptographic operations to provide a conservative estimate of entropy, ensuring the security of cryptographic secrets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing entropy assessment methods are used, then the assessment process is simple, but the accuracy of entropy estimation deteriorates due to underestimation or overestimation

Engineering Contradiction:
Improveentropy estimation accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an entropy assessor module as an intermediary component that bridges the entropy source and the cryptographic secret generator. This module specifically accounts for cryptographic operations (such as hash functions and block ciphers) that transform entropy from the source into the final secret. By modeling these cryptographic transformations, the assessor provides accurate entropy estimates without requiring complex direct measurement of the cryptographic output, thus resolving the contradiction between accuracy and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conservative entropy estimates are used, then security against adversarial attacks is improved, but the perceived entropy availability deteriorates

Engineering Contradiction:
Improvecryptographic securityVSAvoidentropy availability information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the parameter of entropy assessment from direct measurement of raw entropy source output to assessment of entropy after cryptographic transformation. By modeling the cryptographic operations (hash functions, block ciphers) as parameter transformations, the system can provide conservative estimates that reflect the actual security strength while maintaining accurate information about entropy availability. This resolves the contradiction by showing that conservative estimates do not mean loss of information, but rather accurate accounting of transformable entropy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3605940B1Assessing cryptographic entropy
Publication Date: 2021.06.02 BLACKBERRY LTD
  • EP3605940B1 patent drawingFigure 1
  • EP3605940B1 patent drawingFigure 2
  • EP3605940B1 patent drawing

AI summary

Systems, methods, software, and combinations thereof for evaluating entropy in a cryptography system are described. In some aspects, sample values are produced by an entropy source system. A typicality can be determined for each of the sample values. A grading is determined for preselected distributions based on the typicalities of the sample values. A subset of the preselected distributions are selected based on the gradings. An entropy of the entropy source system is calculated based on the subset of the plurality of distributions.