McEliece Cryptosystem Key Disguise via Asymmetric Transformation Matrices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The McEliece cryptosystem faces challenges in improving security levels without increasing public key size, as existing variants using alternative codes are vulnerable to attacks and exhibit security flaws, particularly due to the use of permutation-equivalent public and secret codes.
Innovation Solution
The proposed solution involves using a more general transformation matrix Q, specifically of the form Q=R+T, where R is a rank-z matrix and T is a sparse matrix, to disguise the private key into the public key, allowing for the use of different code families like Reed-Solomon codes, while maintaining error correction capabilities and reducing error propagation effects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If alternative code families (like Reed-Solomon codes) are used to improve code rate and key size, then productivity and key efficiency are improved, but security is worsened due to vulnerability to attacks exploiting permutation-equivalence between public and secret codes
Solution Approach 1:
The patent applies asymmetry by using a transformation matrix Q that is not permutation-equivalent to its inverse, creating an asymmetric relationship between the public key and secret key. Specifically, the public key uses transformation matrix Q while the secret key uses transformation matrix Q^T (transpose), and Q is designed such that Q ≠ Q^T, breaking the permutation-equivalence that vulnerable systems rely on. This asymmetric design prevents attackers from exploiting the symmetry between public and secret codes.
Solution Approach 2:
The patent changes the fundamental parameter of the transformation matrix from a permutation matrix (used in traditional McEliece systems) to a general non-singular matrix Q with specific properties (Q ≠ Q^T). This parameter change allows the system to use alternative code families like Reed-Solomon codes while maintaining security, as the new matrix parameter breaks the algebraic structures that make alternative codes vulnerable to attacks.
2Ease of operation
If permutation matrices are used in the McEliece cryptosystem, then ease of operation is improved through simple structure, but security is worsened due to permutation-equivalence vulnerability
Solution Approach 1:
The patent changes the transformation matrix parameter from a permutation matrix to a general non-singular matrix Q with the property Q ≠ Q^T. This parameter change maintains operational simplicity through efficient matrix multiplication while eliminating the security vulnerability caused by permutation-equivalence. The new matrix parameter allows for straightforward key generation and encryption operations without requiring complex permutation operations.
Solution Approach 2:
The patent substitutes the mechanical permutation operation (swapping elements positions) with general matrix multiplication using transformation matrix Q. This substitution replaces the discrete, position-based permutation mechanism with a more flexible algebraic operation that achieves the same scrambling effect without creating permutation-equivalence vulnerabilities. The substitution maintains computational efficiency while improving security.
Data Source
AI summary
Methods and apparatus for generating a private-public key pair, for encrypting a message for transmission through an unsecure communication medium (30), and for decrypting the message are disclosed. The methods are based on the well-known McEliece cryptosystem or on its Niederreiter variant. More general transformation matrices Q are used in place of permutation matrices, possibly together with an appropriate selection of the intentional error vectors. The transformation matrices Q are non-singular n×n matrices having the form Q=R+T, where the matrix R is a rank-z matrix and the matrix T is some other matrix rendering Q non-singular. The new Q matrices, though at least potentially being dense, have a limited propagation effect on the intentional error vectors for the authorized receiver. The use of this kind of matrices allows to better disguise the private key into the public one, without yielding any further error propagation effect. Based on this family of Q matrices, the presently proposed cryptosystem enables the use of different families of codes than Goppa codes, such as RS codes, by ensuring increased public key security.


