Multivariable Public-Key Encryption with Compact Quantum-Safe Ciphertext

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing public-key cryptography systems, such as RSA and elliptic curve cryptography, are vulnerable to decryption by quantum computers, and existing alternatives like lattice-based cryptography are inefficient for low-power environments and require large key sizes.

Innovation Solution

A new public-key cryptography system using algebraic surfaces and multivariable polynomials, where a symmetric indeterminate equation is used to generate a ciphertext with a noise polynomial, ensuring security against quantum computers and reducing ciphertext length.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If lattice-based cryptography is used to ensure quantum security, then security against quantum computers is improved, but key size and computational complexity increase making it inefficient for low-power environments

Engineering Contradiction:
Improvesecurity against quantum computersVSAvoidkey size and computational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the mathematical parameters from traditional lattice-based structures to multivariable polynomial equations over finite fields. By using equations with multiple variables and symmetric structures, the system achieves quantum security with significantly reduced key sizes and computational requirements, making it suitable for low-power environments while maintaining security against quantum attacks.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If traditional public-key cryptography (RSA, elliptic curve) is used, then ease of operation is maintained, but security is compromised when quantum computers appear

Engineering Contradiction:
Improveease of operationVSAvoidsecurity against quantum computers
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent substitutes the mathematical foundation from number-theoretic problems (factoring, discrete logarithms) to polynomial equation solving over finite fields. This replacement maintains operational simplicity through standardized cryptographic protocols while providing quantum security, as solving multivariable polynomial equations with symmetric constraints is computationally hard even for quantum computers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If quantum-resistant cryptography is implemented, then security is improved, but ciphertext length increases

Engineering Contradiction:
Improvesecurity against quantum computersVSAvoidciphertext length
Core Design Contradiction:
ReliabilityVSLength of stationary object

Solution Approach 1:

The patent employs asymmetric structures in the polynomial equations where the public key consists of equations with specific symmetric properties, while the private key exploits asymmetric knowledge of the factorization structure. This asymmetry enables compact ciphertext representation similar to traditional cryptography while maintaining quantum resistance through the hardness of solving the multivariable polynomial system.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS12549362B2Encryption device, decryption device, key generation device, encryption method, decryption method, key generation method, computer program product for encryption, computer program product for decryption, and computer program product for key generation
Publication Date: 2026.02.10 KK TOSHIBA
  • US12549362B2 patent drawing
  • US12549362B2 patent drawing
  • US12549362B2 patent drawing

AI summary

According to one embodiment, an encryption device includes a memory and one or more processors. The one or more processors are configured to: acquire, as a public key, an n-variable symmetric indeterminate equation having an element not more than a constant degree of Fp[t] and being symmetric for at least two variables; embed the plaintext into coefficients of an n-variable plaintext polynomial having an element not more than a constant degree of Fp[t]; randomly generate an n-variable polynomial having an element not more than a constant degree of Fp[t], randomly generate an n-variable symmetric polynomial having an element not more than a constant degree of Fp[t] and being symmetric for at least two variables, and randomly generate a noise polynomial having an element not more than a constant degree of Fp[t]; and generate a ciphertext from the three polynomials and the equation for the n-variable plaintext polynomial.