Multivariate Polynomial Authentication Protocol for Quantum-Resistant Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital signature schemes based on prime factorization and discrete logarithm problems are vulnerable to quantum computers, necessitating the development of new public key authentication and digital signature schemes that utilize the difficulty of solving multivariate polynomial equations for enhanced security.

Innovation Solution

A public key authentication and digital signature scheme utilizing a multi-order multivariate simultaneous equation, where a secret key is verified through an interactive protocol using verification patterns and hash functions, ensuring security without a trapdoor for efficient solution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional digital signature schemes based on prime factorization or discrete logarithm problems are used, then the schemes are easy to implement and understand, but the security is vulnerable to quantum computers

Engineering Contradiction:
Improvesecurity against quantum computersVSAvoidcomplexity of cryptographic scheme
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the mathematical basis from prime factorization/discrete logarithm to multivariate polynomial equations. The security parameter is transformed from number-theoretic problems to algebraic geometry problems, making the system resistant to quantum attacks while maintaining practical implementability through standard computational algebra techniques

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multivariate polynomial equations are used for authentication, then quantum security is improved, but the difficulty of solving the equations increases computational complexity

Engineering Contradiction:
Improvequantum resistanceVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The authentication protocol segments the verification process into multiple independent steps: commitment phase, challenge phase, and response phase. Each phase handles a specific computational task, allowing the system to distribute computational burden and optimize resource usage while maintaining security through the multivariate polynomial structure

Inventive Principle:
Principle #1Segmentation

3Productivity

If a trapdoor mechanism is used to enable efficient solution of multivariate equations, then authentication speed is improved, but the risk of information leakage increases

Engineering Contradiction:
Improveauthentication speedVSAvoidsecret key information leakage
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by establishing the multivariate polynomial equations and public key before any authentication occurs. The trapdoor information is embedded in the public key structure in advance, allowing efficient verification without requiring the holder to reveal secret information during the authentication process, thus preventing information leakage

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8959355B2Authentication device, authentication method, program, and signature generation device
Publication Date: 2015.02.17 SONY GROUP CORP
  • US8959355B2 patent drawing
  • US8959355B2 patent drawing
  • US8959355B2 patent drawing

AI summary

Provided is an authentication device including a key setting unit for setting sεKn to a secret key and setting a multi-order polynomial fi(xl, . . . , xn) (i=1 to m) on a ring K and yi=fi(s) to a public key, a message transmission unit for transmitting a message c to a verifier, a verification pattern reception unit for receiving information on one verification pattern selected by the verifier from k (k≧3) verification patterns for one message c, and a response transmission unit for transmitting, to the verifier, response information, among k types of response information, corresponding to the information on the verification pattern received by the verification pattern reception unit, where the response information is information that enables calculation of the secret key s in a case all of the k verification patterns for the message c performed by using the k types of response information have been successful.