Lattice-Based Functional Encryption Key Generation for Attribute Hiding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Functional encryption schemes based on lattice theory are weakly attribute-hiding, leading to undesirable information leakage from ciphertexts with attributes satisfying certain conditions for secret keys.

Innovation Solution

A cryptographic system generates a secret key with a matrix e that satisfies the equation AY·e=u, where AY is determined by the input parameter Y, using public parameters to prevent information leakage, comprising a key generation apparatus, encryption apparatus, and decryption apparatus.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If functional encryption schemes based on lattice theory are used, then quantum computer durability is improved, but attribute-hiding capability deteriorates (information leakage occurs)

Engineering Contradiction:
Improvequantum computer durabilityVSAvoidattribute-hiding capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The secret key is segmented into multiple components: a first key component (matrix e) and a second key component (matrix f). The ciphertext is also segmented with multiple cipher elements. This segmentation allows the encryption scheme to maintain quantum durability while preventing information leakage by distributing attribute information across multiple key and ciphertext components that must be combined for decryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces an intermediary mechanism through the matrix e and its relationship with matrix AY forming matrix uj. This intermediary structure acts as a mediator between the public parameters and the secret key, enabling the system to achieve full attribute-hiding by preventing direct exposure of attribute information while maintaining the functional encryption capability against quantum computers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If weak attribute-hiding is used in functional encryption, then implementation simplicity is improved, but security deteriorates (undesirable information leakage)

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

By dividing the secret key into multiple components (matrix e and matrix f) and the ciphertext into multiple cipher elements, the invention achieves full attribute-hiding security without significantly complicating implementation. Each component can be generated and managed independently, and the segmentation allows standard lattice-based cryptographic operations to be applied systematically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention changes the cryptographic parameters by introducing the matrix e as a key element that forms matrix uj when multiplied by matrix AY. This parameter change transforms the encryption scheme from weak attribute-hiding to full attribute-hiding, enhancing security while maintaining implementation feasibility through systematic key and ciphertext generation processes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10516534B2Cryptographic system and key generation apparatus
Publication Date: 2019.12.24 MITSUBISHI ELECTRIC CORP
  • US10516534B2 patent drawing
  • US10516534B2 patent drawing
  • US10516534B2 patent drawing

AI summary

A cryptographic system implements a functional encryption scheme that is based on the lattice theory. In the cryptographic system, a key generation apparatus generates, as a secret key skv for a predicate vector v, a secret key skv including a matrix e as a key element, wherein a product of the matrix e and a matrix AY determined by the predicate vector v being input parameter Y forms a matrix uj for a value j in a set [N] including a plurality of values, the matrix uj being among a plurality of matrices u obtained from public parameters PP.