Isogeny-Based Key Distribution for Quantum-Resistant Multicast

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing dynamic multicast key distribution (DMKD) protocols are not quantum-resistant, particularly due to their reliance on Diffie-Hellman key exchange, which may not guarantee security with the advent of quantum computers, and proposed quantum-resistant methods using key encapsulation mechanisms incur additional communication costs.

Innovation Solution

A key distribution system employing isogeny cryptography between terminal devices, utilizing an isogeny calculating unit to calculate public values based on torsion subgroups of elliptic curves, and a distributing unit to share these values among terminal devices via a key distribution server, enabling a quantum-resistant multi-party key exchange with reduced communication rounds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a key encapsulation mechanism is used to achieve quantum-resistant key distribution, then security against quantum computers is improved, but communication cost increases due to requiring an extra communication round

Engineering Contradiction:
Improvequantum resistanceVSAvoidcommunication cost
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent changes the cryptographic parameter from traditional Diffie-Hellman or key encapsulation mechanisms to isogeny-based cryptography. This parameter change enables quantum resistance while reducing communication rounds to 2, resolving the contradiction between security and communication cost.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the cryptographic mechanism from classical algebraic problems (Diffie-Hellman) or key encapsulation to isogeny-based mathematical problems. This substitution achieves quantum resistance without the communication overhead of key encapsulation mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of time

If the Diffie-Hellman key exchange is used in DMKD protocol, then communication cost is reduced, but quantum security is compromised

Engineering Contradiction:
Improvecommunication costVSAvoidquantum security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent changes the cryptographic parameter from Diffie-Hellman to isogeny-based cryptography, maintaining efficient communication while achieving quantum security. The isogeny-based key exchange requires only 2 communication rounds and provides resistance against quantum computer attacks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the Diffie-Hellman key exchange mechanism with an isogeny-based key exchange mechanism. This substitution replaces the classical mathematical foundation with one that is quantum-resistant, achieving both low communication cost and quantum security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If isogeny cryptography is used for multi-party key exchange, then quantum resistance is achieved with low communication cost, but system complexity increases due to torsion subgroup calculations

Engineering Contradiction:
Improvequantum resistanceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key exchange process into distinct phases: setup phase (generating public parameters including torsion subgroups), key exchange phase (computing isogenies and sharing public values), and key derivation phase (computing the shared session key). This segmentation manages complexity by organizing operations into manageable, reusable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-computing and publishing public parameters including torsion subgroups and their bases before the actual key exchange. This preliminary setup reduces the computational complexity during the key exchange phase, as participants can reuse these pre-computed values.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11411720B2Key distribution system, terminal device, key distribution method, and program
Publication Date: 2022.08.09 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11411720B2 patent drawing
  • US11411720B2 patent drawing
  • US11411720B2 patent drawing

AI summary

With respect to a key distribution system including N terminal devices Ui and a key distribution server used for exchanging a session key, the key distribution system includes an isogeny calculating unit configured to calculate a first public value using a basis of a first torsion subgroup of a predetermined elliptic curve at an odd-numbered terminal device Ui and calculate a second public value using a basis of a second torsion subgroup of the predetermined elliptic curve at an even-numbered terminal device Ui, when N is an even number, a distributing unit configured to distribute the first public value calculated at the odd-numbered terminal device Ui to a terminal device Ui−1 and a terminal device Ui+1, and distribute the second public value calculated at the even-numbered terminal device Ui to a terminal device Ui−1 and a terminal device Ui+1, from the key distribution server, a key generating unit configured to use second public values distributed by the distributing unit to generate the session key at the odd-numbered terminal device Ui, and use first public values distributed by the distributing unit to generate the session key at the even-numbered terminal device Ui, wherein the isogeny calculating unit calculates the first public value using the basis of the first torsion subgroup and the second public value using the basis of the second torsion subgroup at a predetermined terminal device UI among the terminal devices Ui, when N is an odd number.