Multivariate Polynomial Coefficient Generation for Quantum-Resistant Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital signature schemes based on multivariate polynomial problems face limitations due to the difficulty in efficiently generating and managing coefficients for multi-order multivariate simultaneous equations, leading to insufficient security against quantum computer attacks.

Innovation Solution

An information processing apparatus and method that generates and allocates numbers for the coefficients of multi-order multivariate polynomials using a predetermined function, grouping coefficients and optimizing their allocation to enhance security and efficiency in public-key authentication and digital signature schemes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multivariate polynomial problems are used as the basis for digital signature schemes to resist quantum computer attacks, then security against quantum attacks is improved, but the complexity of generating and managing coefficients for multi-order multivariate simultaneous equations increases

Engineering Contradiction:
Improvesecurity against quantum attacksVSAvoidcomplexity of generating and managing coefficients
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the coefficient management process by introducing a trusted third party that pre-generates and distributes coefficient sets to multiple parties. This divides the complex task of coefficient generation and management into independent, pre-computed components that can be securely stored and used without requiring complex real-time generation procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted third party performs preliminary actions by generating coefficient sets in advance and distributing them to parties before the actual digital signature operations occur. This pre-computation eliminates the need for complex coefficient generation during critical operations and reduces the computational burden on the parties using the scheme.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-order multivariate simultaneous equations are used with trapdoors for public-key authentication, then authentication security is improved, but the difficulty of efficiently solving the equations increases

Engineering Contradiction:
Improveauthentication securityVSAvoidefficiency of solving equations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by providing different coefficient sets to different parties, where each party receives coefficients tailored to their specific authentication needs. The trusted third party generates coefficient sets with specific properties (such as sparsity patterns or structural characteristics) that optimize both security and solvability for each party's context.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The trusted third party changes parameters of the multivariate polynomial equations by carefully selecting coefficient values that balance security requirements with solvability. By adjusting parameters such as the degree of polynomials, the number of variables, and the specific coefficient distributions, the system achieves both high security and efficient solving capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10020945B2Information processing apparatus and to efficiently substitute coefficients of a multivariate polynomial
Publication Date: 2018.07.10 SONY GROUP CORP
  • US10020945B2 patent drawing
  • US10020945B2 patent drawing
  • US10020945B2 patent drawing

AI summary

Provided an information processing apparatus including a number generation unit configured to generate numbers used in coefficients of terms included in a pair of multi-order multivariate polynomials F=(f1, . . . , fm), using a predetermined function, from information shared between entities executing an algorithm of a public-key authentication scheme or a digital signature scheme that uses a public key including the pair of multi-order multivariate polynomials F, and an allocation unit configured to allocate the numbers generated by the number generation unit to the coefficients of the multi-order multivariate polynomials for which the pair of multi-order multivariate polynomials F are included in constituent elements.