Probabilistic Symmetric Encryption Using Error-Correcting Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current probabilistic symmetric encryption methods struggle to reconcile mathematical proof of computational security with efficient implementation speed and realistic resource requirements, particularly in low-cost cryptography applications like RFID tags.
Innovation Solution
A probabilistic symmetric encryption method using a secret key represented as a matrix, combining error-correcting code encoding with the addition of a noise vector to encrypt messages, leveraging the difficulty of the LPN problem for security, which involves encoding a message element into a code word, encrypting it by adding the product of the secret matrix and a random vector, and then adding a noise vector to create an encrypted message pair.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If probabilistic symmetric encryption methods using block cipher algorithms and operating modes are used, then encryption speed is improved and implementation is efficient, but mathematical proof of computational security cannot be provided
Solution Approach 1:
The patent changes the fundamental parameters of the encryption system by using error-correcting codes with specific rate and length parameters that enable both efficient implementation and mathematical security proofs. The code rate and length are carefully selected to balance security requirements with computational efficiency.
Solution Approach 2:
The patent replaces traditional block cipher mechanical operations with algebraic operations based on error-correcting codes over finite fields. This substitution enables mathematical security reductions while maintaining implementation efficiency through straightforward algebraic computations.
2Reliability
If mathematical proof of computational security is provided, then security reliability is improved, but implementation speed decreases and resource requirements become unrealistic
Solution Approach 1:
The patent optimizes code parameters (rate, length, minimum distance) to achieve a balance where mathematical security proofs are possible while keeping computational complexity low enough for efficient implementation. Specific parameter selections enable linear-time decoding algorithms.
Solution Approach 2:
The patent applies different properties to different parts of the cryptographic system: error-correcting codes provide the mathematical security foundation, while efficient algebraic operations provide the speed. Each component is optimized for its specific function rather than requiring uniform properties throughout.
3Productivity
If traditional block cipher algorithms are used, then encryption efficiency is maintained, but security cannot be proven against polynomial-time attackers
Solution Approach 1:
The patent substitutes traditional block cipher substitution-permutation networks with algebraic operations based on error-correcting codes. This substitution enables security reductions to hard problems in coding theory while maintaining efficiency through simple field operations.
Solution Approach 2:
The patent uses error-correcting codes that serve multiple functions simultaneously: they provide the mathematical structure for provable security, enable efficient encoding and decoding operations, and offer flexibility in parameter selection for different security and performance requirements.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The invention relates to a method for the probabilistic symmetrical encryption of an element of a plaintext message (x) using a secret key that can be represented in the form of a matrix (M). The method includes an encryption step (E4) of the plaintext message element (x) using the matrix (M) parameterised by a random vector (a) in order to obtain an encrypted message element (y) coupled to the random vector (a). It further comprises an encoding step (E1) of the plaintext message element (x) into a code word (C (x)) using an error correction code having a given correction capacity (t) and an addition step (E6) of a noise vector (e). The error correction code and the noise vector (e) are adapted so that the weight of the Hamming of the noise vector (e) is lower than or equal to the correction capacity (t) of the correction code.