Signature Verification Using Multivariate Polynomial Equations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital signature schemes based on multivariate polynomial problems face limitations in security and efficiency due to the use of easily soluble multi-order multivariate simultaneous equations, which are not effectively secured by classical computers but can be compromised by quantum computers.

Innovation Solution

A signature verification apparatus and method that utilizes a pair of multi-order multivariate polynomials and vectors as public keys to verify the legitimacy of a digital signature, acquiring and restoring predetermined information to ensure high security and efficiency without a known trapdoor for solving the equations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital signature schemes based on multivariate polynomial problems are used, then security against quantum computer attacks is improved, but the equations can still be solved efficiently if trapdoors are present

Engineering Contradiction:
Improvesecurity against quantum attacksVSAvoidequation solving complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and removes the trapdoor component from the multivariate polynomial equation system. By eliminating the trapdoor mechanism that enables efficient solving, the system maintains security against quantum attacks while preventing the weakness of easily soluble equations. The verification process operates on the full, unsimplified equation system without relying on hidden solving paths.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent inverts the traditional approach by making the difficulty of solving the multivariate polynomial equations the core security mechanism rather than relying on trapdoors to enable solving. Instead of hiding a solution path (trapdoor), the system relies on the inherent computational hardness of the equation system itself, turning the problem of solving equations from a vulnerability into the foundation of security.

Inventive Principle:
Principle #13The other way round (Inversion)

2Measurement precision

If all second information is retained for verification, then verification accuracy is improved, but memory requirements increase

Engineering Contradiction:
Improveverification accuracyVSAvoidmemory capacity
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential components needed for verification from the complete set of second information. By identifying and retaining only the critical elements required to verify the digital signature against the multivariate polynomial equations, the system maintains verification accuracy while eliminating redundant data that would consume memory resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by retaining a subset of the second information rather than all available data. The verification process uses precisely the amount of information necessary to confirm signature validity against the public key equations, avoiding the memory overhead of storing excessive or redundant verification data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9129122B2Signature verification apparatus, signature verification method, program, and recording medium
Publication Date: 2015.09.08 SONY GROUP CORP
  • US9129122B2 patent drawing
  • US9129122B2 patent drawing
  • US9129122B2 patent drawing

AI summary

A signature verification apparatus including a signature acquisition unit configured to acquire a digital signature including first information generated based on a pair of multi-order multivariate polynomials F=(f1, . . . , fm) defined in a ring K, a signature key s which is an element of a set Kn, and a document M and a plurality of pieces of second information for verifying that the first information is generated using the signature key s based on the data M, the pair of multi-order multivariate polynomials F, and vectors y=(f1(s), . . . , fm(s)), and a signature verification unit configured to verify legitimacy of the document M by confirming whether or not the first information is restorable using the plurality of pieces of second information included in the digital signature. The pair of multivariate polynomials F and the vectors y are public keys.