NTRU Parameter Generation for Error-Free Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

NTRU cryptosystems face issues with decryption errors and security against third-party decryption, as existing techniques lack conditions for generating parameters that prevent decryption errors and ensure security.

Innovation Solution

A parameter generation apparatus that generates error-free output parameters for NTRU cryptosystems using error condition information, ensuring no decryption errors occur during encryption and decryption processes, and providing security against third-party decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If existing NTRU parameters are used for high-speed processing, then processing speed is improved, but decryption errors occur and security against third-party decryption is compromised

Engineering Contradiction:
Improveprocessing speedVSAvoiddecryption accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies parameter changes by establishing specific mathematical relationships between NTRU parameters (N, p, q, df, dg) to eliminate decryption errors. The invention defines that q must be an odd number, df must satisfy 1 ≤ df < q/2, and dg must satisfy 1 ≤ dg < q/2, with additional constraints on the relationship between these parameters to ensure reliable decryption while maintaining security

Inventive Principle:
Principle #35Parameter changes

2Speed

If existing NTRU parameters are used for high-speed processing, then processing speed is improved, but security against third-party decryption deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidthird-party decryption vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent strengthens security against third-party decryption by imposing strict constraints on NTRU parameters. It requires that q be an odd number and establishes specific relationships between df, dg, and q to increase the difficulty of lattice-based attacks while maintaining polynomial operation efficiency for legitimate decryption

Inventive Principle:
Principle #35Parameter changes

3Reliability

If parameters are selected to prevent decryption errors, then decryption accuracy is improved, but device complexity increases due to additional parameter constraints

Engineering Contradiction:
Improvedecryption accuracyVSAvoidparameter generation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces parameter generation complexity by providing clear, deterministic rules for selecting NTRU parameters. The invention specifies that q must be an odd number and defines explicit ranges and relationships for df and dg, allowing systematic parameter generation without requiring complex optimization algorithms or extensive computational searches

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7929688B2Parameter generation apparatus, encryption system, decryption system, encryption apparatus, decryption apparatus, encryption method, decryption method, and program thereof
Publication Date: 2011.04.19 PANASONIC HOLDINGS CORP
  • US7929688B2 patent drawing
  • US7929688B2 patent drawing
  • US7929688B2 patent drawing

AI summary

A parameter generation apparatus for generating parameters causing no decryption error for an NTRU cryptosystem so that an encrypted communication can be carried out between an encryption apparatus and a decryption apparatus in a secure and reliable manner. The parameter generation apparatus includes: a provisional parameter generation unit operable to generate a set of provisional parameters that do not cause any decryption errors, based on error condition information that is provided in advance, the error condition information indicating a condition for causing no decryption error; and an output parameter generation unit operable to generate an output parameter that does not cause any decryption errors, using the set of provisional parameters, based on a lattice constant that is calculated from the set of provisional parameters.