WO2013150880A1 - 暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラム - Google Patents

暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラム Download PDF

Info

Publication number
WO2013150880A1
WO2013150880A1 PCT/JP2013/057509 JP2013057509W WO2013150880A1 WO 2013150880 A1 WO2013150880 A1 WO 2013150880A1 JP 2013057509 W JP2013057509 W JP 2013057509W WO 2013150880 A1 WO2013150880 A1 WO 2013150880A1
Authority
WO
WIPO (PCT)
Prior art keywords
bit string
vector
matrix
encryption
commutative
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2013/057509
Other languages
English (en)
French (fr)
Inventor
雅則 大矢
聖史 入山
ルイジ アカルディ
マッシモ レゴリ
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tokyo University of Science
Original Assignee
Tokyo University of Science
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tokyo University of Science filed Critical Tokyo University of Science
Priority to CN201380018975.0A priority Critical patent/CN104303453B/zh
Priority to EP13773112.1A priority patent/EP2835932B1/en
Priority to KR1020147030403A priority patent/KR102033196B1/ko
Priority to US14/390,204 priority patent/US9467286B2/en
Publication of WO2013150880A1 publication Critical patent/WO2013150880A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/065—Encryption by serially and continuously modifying data stream elements, e.g. stream cipher systems, RC4, SEAL or A5/3
    • H04L9/0656—Pseudorandom key sequence combined element-for-element with data sequence, e.g. one-time-pad [OTP] or Vernam's cipher
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/065—Encryption by serially and continuously modifying data stream elements, e.g. stream cipher systems, RC4, SEAL or A5/3
    • H04L9/0656—Pseudorandom key sequence combined element-for-element with data sequence, e.g. one-time-pad [OTP] or Vernam's cipher
    • H04L9/0662—Pseudorandom key sequence combined element-for-element with data sequence, e.g. one-time-pad [OTP] or Vernam's cipher with particular pseudorandom sequence generator
    • H04L9/0668—Pseudorandom key sequence combined element-for-element with data sequence, e.g. one-time-pad [OTP] or Vernam's cipher with particular pseudorandom sequence generator producing a non-linear pseudorandom sequence

Definitions

  • the present invention relates to an encryption device, a decryption device, an encryption method, a decryption method, and a program.
  • an encryption device that speeds up encryption processing and increases the strength of decryption is known (Japanese Patent Laid-Open No. 2003-241656).
  • the plaintext D is divided and output as a plurality of divided data by an initial processing function, the plurality of divided data is expanded and replaced to the same size as the encryption key K by an arithmetic function, and a coefficient is mediated. Make the arithmetic function variable. The coefficient is generated by the parameter generation unit.
  • the non-linear encryption block processing unit performs non-linear encryption using the divided data and the encryption key K as variables, and outputs a plurality of pieces of encrypted encrypted data.
  • the post-processing function uses the inverse function of the arithmetic function to reduce and replace the divided encrypted data to the same size as the divided data, synthesize the divided data and output it as ciphertext, and mediate the coefficient to the inverse function. Make the arithmetic function variable.
  • the secret information a and b and the random number information m1 and m2 are added by exclusive OR, the secret information a and b are masked, and the masked secret information A and B are calculated.
  • Means for calculating intermediate values Temp1 to Temp3 for removing the mask of masked secret information A and B using secret information A and B and random number information m1 and m2, masked secret information A and B And an intermediate value Temp1 to Temp3, a cryptographic processing device is known (Japanese Patent Laid-Open No. 2009-005164).
  • Cryptographic processing techniques disclosed in Japanese Patent Laid-Open Nos. 2003-241656 and 2009-005164 are intended to improve the speed and security of encryption processing, but can be decrypted theoretically. Have a potential danger.
  • the capacity is increased and high speed is sacrificed, and there is no technology that comprehensively satisfies the encryption processing requirements of “high speed”, “safety”, and “lightweight”. It was. Therefore, cryptographic methods based on noncommutative functions that are theoretically indecipherable have been proposed (L.Accardi, M.Regoli, M.Ohya, “The QP-DYN Algorithm”, QP-PQ 28, Quantum). Bio-Informatics IV, IV-16, 2011).
  • the present invention has been made in view of the above problems.
  • the encryption device is based on a d ⁇ d matrix A that is private data and two prime numbers p1 and p2, which are set in common with the decryption device.
  • a matrix generation unit that generates two non-commutative matrices A1 and A2, and a d-dimensional initial vector v 0 set in common with the decoding device or a d-dimensional vector v i ⁇ 1 1 previously obtained , by the action of non-commutative matrix A1, with obtaining the vector v i 1, the initial vector v 0, or previous to the vector v i-1 2 d-dimensional obtained, by applying the non-commutative matrix A2
  • a matrix operation unit for obtaining a vector v i 2 , wherein at least one of a sum operation and a product operation when operating the non-commutative matrices A1 and A2 is combined with a plurality of predetermined operators.
  • Substituting non-commutative matrices A1 and A2 with calculation methods A matrix working part that use, the matrix is converted into a bit string by performing a nonlinear transformation to the vector v i 1 determined by the working portion, the converted said bit string is coupled to a bit string W1 previously obtained bit sequence W1
  • a bit string conversion unit that performs nonlinear conversion on the vector v i 2 to convert the vector v i 2 into a bit string, and combines the converted bit string with the previously obtained bit string W2 to obtain the bit string W2, and the bit string conversion unit
  • the operation by the matrix operation unit and the conversion and combination by the bit sequence conversion unit are repeated until the number of bits of each of the bit sequence W1 and the bit sequence W2 obtained by the above becomes the number of bits of the bit sequence representing the data to be encrypted.
  • a bit number determination unit calculates an exclusive OR of the bit string W1 and the bit string W2, By calculating an exclusive OR of a pseudo random number sequence generation unit for obtaining a random number bit sequence, a pseudo random number bit sequence obtained by the pseudo random number sequence generation unit, and a bit sequence representing the data to be encrypted, the encryption target And an encryption unit for encrypting data.
  • the program according to the second aspect includes a computer and two non-commutative matrices based on a d ⁇ d matrix A that is private data and two prime numbers p1 and p2, which are set in common with a decoding device.
  • a non-commutative matrix A1 is applied to a matrix generation unit that generates A1 and A2, a d-dimensional initial vector v 0 set in common with the decoding device, or a d-dimensional vector v i-1 1 obtained previously.
  • At least one of the sum operation and the product operation when operating the non-commutative matrices A1, A2 is replaced with an operation method combining a plurality of types of operators, and the vector is replaced with the non-commutative matrix A1, A2 is repeatedly applied and nonlinear transformation is performed, and the exclusive OR of the obtained bit strings W1 and W2 is calculated to obtain a pseudo random number bit string.
  • Matrix acting portion the initial vector v 0, or vectors v i-1 1 previously obtained, by applying the non-commutative matrix A1, in determining said vectors v i 1, for each element of the vector v i 1, the initial vector v 0 or the vector v i-1 1 was replaced by previously computed vector v i 1 element, by applying a non-commutative matrix A1, a vector v i 1 of the element calculated, the initial vector v 0, or previous to the vector v i-1 2 obtained, by applying the non-commutative matrix A2, in determining said vectors v i 2, the vector v i every two elements, already computed vector v the replaced element of i 2 initial vector v 0 or the vector v i-1 2, by the action of non-commutative matrix A2, the vector v i 2 Elements can be calculated. As a result, the decryption strength can be further increased.
  • the bit string conversion unit converts, as the nonlinear conversion, the vector v i 1 obtained by the matrix operation unit into a bit string, and the converted bit string is a head satisfying a predetermined condition.
  • a cut-off process for cutting a bit string is performed, the bit string with the leading bit string cut is coupled to the previously obtained bit string W1, and the vector v i 2 is converted into a bit string.
  • a cut-off process may be performed so that the bit string from which the leading bit string has been cut is coupled to the previously obtained bit string W2. As a result, the decryption strength can be further increased.
  • bit string conversion unit includes, as the preceding cut-off process, for the converted bit string, as a leading bit string satisfying the predetermined condition, 0 continuous from the beginning, and from the leading It is possible to perform a process of cutting a leading bit string of a predetermined number of bits from the bit string from which the leading bit string is cut while cutting the leading bit string consisting of 1 that appears first. As a result, the decryption strength can be further increased.
  • the decryption device includes two non-commutative matrices A1 based on a d ⁇ d matrix A that is private data and two prime numbers p1 and p2, which are set in common with the encryption device.
  • the non-commutative matrix A1 is applied to the matrix generation unit for generating A2, and the d-dimensional initial vector v 0 set in common with the encryption apparatus or the d-dimensional vector v i-1 1 obtained previously.
  • a program includes a computer and two non-commutative matrices based on a d ⁇ d matrix A that is private data and two prime numbers p1 and p2, which are set in common with an encryption device.
  • At least one of the sum operation and the product operation when operating the non-commutative matrices A1, A2 is replaced with an operation method combining a plurality of types of operators, and the vector is replaced with the non-commutative matrix A1, A2 is repeatedly applied and nonlinear transformation is performed, and the exclusive OR of the obtained bit strings W1 and W2 is calculated to obtain a pseudo random number bit string.
  • the encryption device the decryption device, the encryption method, the decryption method, and the program according to one aspect of the present invention
  • at least one of a sum operation and a product operation when operating the noncommutative matrices A1 and A2 is performed.
  • an encryption processing system 10 includes encryption / decryption devices 12A and 12B, a plurality of user terminals 14A, a plurality of user terminals 14B, and an Internet access network 16. I have.
  • the encryption / decryption devices 12A and 12B are examples of an encryption device and a decryption device.
  • the plurality of user terminals 14A are connected to the encryption / decryption device 12A, and the encryption / decryption device 12A is connected to the Internet access network 16.
  • the plurality of user terminals 14B are connected to the encryption / decryption device 12B, and the encryption / decryption device 12B is connected to the Internet access network 16.
  • the encryption / decryption devices 12A and 12B are connected to each other via the Internet access network 16.
  • the transmission data is output to the Internet access network 16 via the encryption / decryption device 12A, while receiving data via the Internet access network 16 is received.
  • received data is input from the Internet access network 16 via the encryption / decryption device 12A.
  • the transmission data is output to the Internet access network 16 via the encryption / decryption device 12B, while data transmitted via the Internet access network 16 is transmitted.
  • received data is input from the Internet access network 16 via the encryption / decryption device 12B.
  • the encryption / decryption devices 12A and 12B include a CPU (Central Processing Unit), a RAM (Random Access Memory), and a ROM (Read Only Memory) that stores a program for executing a pseudo-random number sequence generation processing routine described later.
  • the computer is functionally configured as shown below.
  • the encryption / decryption devices 12A and 12B include a communication unit 20, a data input / output unit 22, a common data setting unit 24, a pseudo random number sequence generation unit 26, an encryption unit 28, and a decryption unit 30.
  • the pseudo random number sequence generation unit 26 is an example of a matrix generation unit, a matrix operation unit, a bit string conversion unit, a bit number determination unit, and a pseudo random number generation sequence unit.
  • the communication unit 20 transmits and receives data via the Internet access network 16.
  • the data input / output unit 22 receives data output from the user terminals 14A and 14B and outputs data to the user terminals 14A and 14B.
  • the common data setting unit 24 sets common data in the encryption / decryption devices 12A and 12B. Specifically, d ⁇ d matrix A, prime numbers p1, p2, and initial vector v0, which are private data, are set as common data.
  • the pseudo random number sequence generation unit 26 generates a pseudo random number bit sequence using a d ⁇ d matrix A, prime numbers p1 and p2, and an initial vector v0, which are private data, by a method described later.
  • the encryption unit 28 uses the pseudo random number bit string generated by the pseudo random number sequence generation unit 26 as a key for the one-time pad encryption, thereby encrypting the data to be encrypted input by the data input / output unit 22 with a stream cipher. I do. For example, as shown in FIG. 3A, by calculating the XOR of the plain text represented by the bit string and the pseudo random number bit string as the encryption key, every bit from the front (or every byte) ) Encrypt. The data encrypted by the encryption unit 28 is transmitted by the communication unit 20.
  • the decryption unit 30 decrypts the data to be decrypted received by the communication unit 20 by using the pseudo random number bit sequence generated by the pseudo random number sequence generation unit 26 as a key for the one-time pad encryption. . For example, as shown in FIG. 3B, by calculating the XOR of the encrypted text (cypher text) represented by a bit string and the pseudo random number bit string as the encryption key, one bit at a time (or one byte) Decrypt every).
  • the data decrypted by the decryption unit 30 is output to the data terminals 14A and 14B by the data input / output unit 22.
  • the pseudorandom number sequence generation unit 26 generates two non-commutative matrices A1 and A2 using the d ⁇ d matrix A and the prime numbers p1 and p2 set as common private data as follows. To do.
  • the matrix A is a 2 ⁇ 2 matrix will be described as an example.
  • the pseudo-random number generator 26 calculates a matrix A1 'using the matrix A and the prime number p1, as shown in the following equation (1).
  • the pseudo random number sequence generation unit 26 calculates the matrix A2 ′ using the matrix A and the prime number p2, and generates the non-commutative matrix A2 as described above. To do.
  • the period length O (A) of the pseudo-random number sequence generated using the non-commutative matrices A1 and A2 is an arbitrary prime number p used for generating the non-commutative matrices A1 and A2. It can be written as the following equation (4).
  • the period of A becomes longer than that.
  • v i A 1 i v 0 .
  • the pseudo random number sequence generation unit 26 obtains the bit sequence W 1 from the obtained vector sequence V by non-linear transformation.
  • a cut-off process is performed to remove the leading bit string including the bit string composed of 0 and the next 1 appearing from the leading bit.
  • the cut-off it is known that the remaining bit string has high randomness.
  • Random cut as described above, the leading bit string consisting of the consecutive 0 that appears first and the 1 that appears next is cut.
  • Fixed cut the number of bits set in advance is cut. For example, when the number of bits to be cut by Fixed cut is 3, the first 3 bits of the bit string obtained as a result of Random cut are cut.
  • This cut-off process is performed on all the elements of v i , and W is a bit string in which all the elements after the cut-off process are arranged.
  • the attacker cannot restore the non-commutative matrices A 1 and A 2 without verifying the possibility of all cutoffs, the attacker can improve the strength against the attack.
  • the vector v i by the action of non-commutative matrix A1, A2, in obtaining the new vector v i + 1, a sum operation and product operation number between, as follows Replace with an operation that combines multiple operators.
  • a and b are 32-bit numbers, and the symbol a ⁇ k is a symbol for shifting a by k bits, (sum operation) a + b is replaced with a + b mod 2 32 .
  • (product operation) a ⁇ b is replaced with a ⁇ (b / 2 27 ) xor b.
  • a ⁇ (b / 2 27 ) represents that a is shifted by a quotient obtained by dividing b by 2 27
  • xor represents a bitwise exclusive OR.
  • the matrix operation method may be further replaced as follows.
  • v i (v i 1 , v i 2 ,..., V i d ) is obtained by applying the matrix A to the initial vector v 0 i times (d is the dimension of A)
  • v i A method for obtaining + 1 (v i + 1 1 , v i + 1 2 ,..., V i + 1 d ) is as follows.
  • v i + 1 2 (A (v i + 1 1 , v i 2 ,..., V i d )) 2 .
  • This a non-commutative matrix A the first element of v i is applied to replaced with a v i + 1 1, in which removal of the second element. Note that the calculation required here is only the calculation of the second element.
  • v i + 1 3 (A (v i + 1 1 , v i + 1 2 ,..., V i d )) 2 .
  • the first and second elements of v i are replaced, the non-commutative matrix A is applied, and the third element is extracted.
  • the processing for the bit string W1 is interrupted at the moment when the bit number of the bit string W1 reaches n, and the remaining part of the bit string W1 is discarded.
  • PRBS generation unit 26 similarly for non-commutative matrix A 2, repeats the action of the vector and the cut-off process, to generate a bit string W 2. Also, at the moment when the number of bits of the bit string W2 reaches n, the processing for the bit string W2 is interrupted and the remaining part of the bit string W2 is discarded.
  • the pseudo random number sequence generation unit 26 calculates the XOR of the finally obtained bit sequence W 1 and the bit sequence W 2, and sets the obtained bit sequence as the pseudo random number bit sequence.
  • the bit string obtained by XOR of the bit string W 1 and the bit string W 2 may be further subjected to nonlinear transformation, and the result may be a pseudo-random bit string.
  • the pseudo random number sequence generation unit 26 generates a pseudo random number bit sequence having the same number of bits as the number of bits of the encryption target data or the number of bits of the decryption target data.
  • the user terminal 14A when data is transmitted from the user terminal 14A to the user terminal 14B, the user terminal 14A outputs the transmission data to the encryption / decryption device 12A.
  • the pseudo-random number sequence generation processing routine shown in FIG. 4 is executed in the encryption / decryption device 12A.
  • the encryption / decryption device 12A generates non-commutative matrices A1 and A2 using the non-commutative matrix A and primes p1 and p2 set in common with the encryption / decryption device 12B.
  • the encryption / decryption device 12A sets a variable i for identifying a vector to 0, which is an initial value. Also, an initial vector v0 is set.
  • step 104 the decryption unit 12A is in the vector v i, respectively by the action of non-commutative matrix A1, A2, to calculate the vector v i + 1 1, v i + 1 2.
  • step 106 each of the vectors v i + 1 1 and v i + 1 2 calculated in step 104 is converted into a bit string, and a cut-off process is performed on each bit string to cut the leading bit string. Turn off.
  • step 108 the encryption / decryption device 12A adds each of the bit strings obtained in step 106 so as to be further aligned with the bit strings W1 and W2.
  • step 110 the encryption / decryption device 12A determines whether or not the number of bits of each of the bit strings W1 and W2 has reached the number of bits of the bit string of the transmission data (encryption target data). If the number of bits of each of the bit strings W1 and W2 has not reached the bit number of the bit string of the transmission data (data to be encrypted) input from the user terminal 14A, in step 112, the encryption / decryption device 12A The variable i is incremented by 1, and the process returns to step 104 to repeat the processes after step 104.
  • the encryption / decryption device 12A performs the process using the non-commutative matrix A1 in the processes after step 104. Not performed.
  • the encryption / decryption device 12A performs the process using the non-commutative matrix A2 in the processes after step 104 above. Absent.
  • step 110 if it is determined that the number of bits of both the bit strings W1 and W2 has reached the bit number of the bit string of the transmission data, the encryption / decryption device 12A proceeds to step 114.
  • step 114 the encryption / decryption device 12A calculates the XOR of the bit strings W1 and W2, generates a pseudo random number bit string S, and ends the pseudo random number sequence generation processing routine.
  • the encryption / decryption device 12A is encrypted by calculating the XOR between the pseudo random number bit sequence S generated by the pseudo random number sequence generation processing routine and the bit sequence of the transmission data input from the user terminal 14. Generate transmission data. Also, the encryption / decryption device 12A transmits the encrypted transmission data to the user terminal 14B via the Internet access network 16.
  • the encrypted transmission data is received by the encryption / decryption device 12B, and the pseudo-random number sequence generation processing routine of FIG. 4 is executed in the encryption / decryption device 12B in the same manner, and the pseudo-random number having the same number of bits as the encrypted transmission data is executed.
  • a random bit string S is generated.
  • the encryption / decryption device 12B generates a plaintext of the encrypted transmission data by calculating an XOR between the generated pseudo random number bit string S and the bit string of the encrypted transmission data. Also, the encryption / decryption device 12B outputs the plaintext of the transmission data to the user terminal B designated as the transmission destination.
  • the pseudo-random number sequence corresponding to one component of the above-described embodiment is subjected to a statistical test (NISTU01 test) in the process of creating the present invention (F. Giuseppe, “Benchmarking for the QP Cryptographic Diformate, Dipartmento Informate, e Production, Universita di Roma “Tor Vergata” (Italian), see 2009).
  • NISTU01 test is performed by acquiring only the input / output state with the program source closed.
  • NIST is the National Institute of Standards and Technology.
  • the NISTU01 test is one of the tests performed by NIST to impose cryptographic algorithms and implementation requirements that are approved for use by US government agencies. Yes, it evaluates the safety of pseudo-random number sequences.
  • Tests include SmallCrush, BigCrush, Rabbit, Alphabit, FIPS-140-2, pseudoDIEHARD.
  • the pseudo-random number sequence generation algorithm RC4 that is widely used at present is used as a comparison target.
  • the pseudo-random number sequence corresponding to one component of the above-described embodiment passed all statistical tests, but the comparison target RC4 failed to pass many tests.
  • the pseudo-random number sequence generation algorithm described in the embodiment can generate a statistically safe pseudo-random number sequence.
  • the encryption / decryption device replaces the sum operation and product operation when operating the non-commutative matrices A1 and A2 with an operation method combining a plurality of types of operators. Then, the non-commutative matrices A1 and A2 are repeatedly applied to the initial vector and nonlinear transformation is performed, and the XOR of the obtained bit strings W1 and W2 is calculated to obtain a pseudo-random bit string.
  • the encryption / decryption device performs encryption or decryption using a pseudo random number bit string, thereby speeding up the encryption process or the decryption process when the number of bits of the data to be encrypted or the data to be decrypted is variable, In addition, the decryption strength can be increased.
  • pseudo random number sequence generation algorithm statistical randomness and long period of the pseudo random number sequence can be guaranteed by using some non-linear transformation, and by using the generated pseudo random number sequence, a safe A disposable encryption key (One-Time-Pad key) can be generated.
  • streaming encryption can be realized, multimedia files such as audio and video can be transferred safely and at high speed.
  • the present invention may be applied, or may be applied to keyless entry of automobiles. Further, the present invention may be applied to HDD (hard disk disk drive) encryption. For example, all data stored in the HDD may be encrypted by the encryption method described in the present embodiment so that only authorized users can read it. Further, the present invention may be applied to the security of the Cloud service.
  • HDD hard disk disk drive
  • the program has been described as an embodiment in which the program is installed in advance.
  • the program can be provided by being stored in a computer-readable recording medium.
  • the computer-readable medium includes two non-permitted computers based on a d ⁇ d matrix A that is private data and two prime numbers p1 and p2, which are set in common with a decoding device.
  • a matrix generation unit that generates a permutation matrix A1, A2, a non-commutative matrix A1 into a d-dimensional initial vector v 0 set in common with the decoding device or a d-dimensional vector v i-1 1 obtained previously.
  • Matrix working part that, the matrix is converted into a bit string by performing a nonlinear transformation to the vector v i 1 determined by the working portion, the converted by the bit string is coupled to a bit string W1 previously obtained determining the bit string W1
  • a non-linear conversion is performed on the vector v i 2 to convert it into a bit string
  • the bit string conversion unit that obtains the bit string W2 by combining the converted bit string with the previously obtained bit string W2 is obtained by the bit string conversion unit.
  • the bit number determination of repeating the action by the matrix action unit and the conversion and combination by the bit string conversion unit until the number of bits of the bit string W1 and the bit string W2 reaches the bit number of the bit string representing the data to be encrypted.
  • a pseudo-random number sequence generation unit for obtaining a target sequence and calculating the exclusive OR of the pseudo-random number bit sequence obtained by the pseudo-random number sequence generation unit and the bit sequence representing the encryption target data. It is a computer readable medium storing a program for functioning as an encryption unit for encrypting data.
  • the computer-readable medium includes two non-permitted computers based on a d ⁇ d matrix A that is private data and two prime numbers p1 and p2 that are set in common with an encryption device.
  • Matrix working part that, the matrix is converted into a bit string by performing a nonlinear transformation to the vector v i 1 determined by the working portion, the converted by the bit string is coupled to a bit string W1 previously obtained determining the bit string W1
  • a non-linear conversion is performed on the vector v i 2 to convert it into a bit string, and the bit string conversion unit that obtains the bit string W2 by combining the converted bit string with the previously obtained bit string W2 is obtained by the bit string conversion unit.
  • bit number determination of repeating the operation by the matrix operation unit and the conversion and combination by the bit string conversion unit until the number of bits of each of the bit string W1 and the bit string W2 reaches the bit number of the bit string representing the data to be decoded.
  • calculating an exclusive OR of the bit string W1 and the bit string W2 A pseudo-random number sequence generation unit for obtaining a target sequence, and calculating the exclusive OR of the pseudo-random number bit sequence obtained by the pseudo-random number sequence generation unit and the bit sequence representing the decryption target data.
  • the computer-readable medium stores a program for functioning as a decryption unit that decrypts data.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • Nonlinear Science (AREA)
  • Storage Device Security (AREA)
  • Complex Calculations (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

 暗号化装置は、プライベートデータA及び素数p1、p2に基づいて、非可換行列A1、A2を生成し(100)、ベクトルvi 1、vi-1 2に、非可換行列A1、A2を作用させる(104)。暗号化装置は、ベクトルvi 1、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、ビット列W1,W2に結合させる(106,108)。暗号化装置は、ビット列W1及びビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、非可換行列の作用及び非線形変換を繰り返す(110)。暗号化装置は、ビット列W1及びビット列W2の排他的論理和を計算して、擬似乱数ビット列を求め(112)、擬似乱数ビット列を用いて暗号化を行う。これにより、暗号化装置は、暗号化対象データのビット数が可変である場合において、暗号化処理を高速化し、かつ暗号解読強度を強くすることができる。

Description

暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラム
 本発明は、暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラムに関する。
 従来より、暗号化処理を高速、かつ暗号解読強度を強くする暗号化装置が知られている(特開2003-241656号公報)。この暗号化装置では、初期処理関数により、平文Dを分割し複数の分割データとして出力し、複数の分割データを演算関数により暗号鍵Kと同じ大きさに拡大置換し、係数を媒介することにより演算関数を可変にする。その係数は、媒介変数生成部により生成される。そして、非線形暗号化ブロック処理部により、分割データと暗号鍵Kとを変数として非線形に暗号化し、暗号化した複数の分割暗号化データを出力する。さらに、後処理関数により、演算関数の逆関数を使い分割暗号化データを分割データと同じ大きさに縮小置換し、分割データを合成し暗号文として出力し、係数を媒介することにより逆関数の演算関数を可変にする。
 また、秘密情報a,bと乱数情報m1,m2とを排他的論理和により加算することによって秘密情報a,bをマスクし、マスクされた秘密情報A,Bを算出する手段と、マスクされた秘密情報A,Bと乱数情報m1,m2とを用いて、マスクされた秘密情報A,Bのマスクを除去するための中間値Temp1~Temp3を算出する手段と、マスクされた秘密情報A,Bと中間値Temp1~Temp3を用いて、秘密情報a,bの論理積や論理和に関する演算を行う手段とを備えた暗号処理装置が知られている(特開2009-005164号公報)。
 特開2003-241656号公報、特開2009-005164号公報によって開示された暗号処理技術は暗号化処理の高速性、安全性の高度化を図るものであるが、理論的に解読が可能であるという潜在的な危険性を有する等の問題を抱えている。この問題を解消するためには容量が大きくなって高速性を犠牲にされる場合があり、「高速」、「安全」、「軽量」という暗号化処理の要求を総合的に満足させる技術はなかった。そこで、理論上は解読不能な非可換関数を元にした暗号方式が提案されている(L.Accardi, M.Regoli, M.Ohya,“The QP-DYN Algorithm”,QP-PQ 28, Quantum Bio-Informatics IV, 1-16, 2011)。
 L.Accardi, M.Regoli, M.Ohya,“The QP-DYN Algorithm”,QP-PQ 28, Quantum Bio-Informatics IV, 1-16, 2011によって開示された技術では暗号化処理の概念は示されているが、高速性と暗号の頑健性を決定する力学系への変換やベクトル列の導出などを設定すること、さらにはこの暗号化処理を装置に実装することは困難であった。
 本発明は、前記課題を鑑み、なされたものである。
 上記の目的を達成するために第1の態様に係る暗号化装置は、復号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部と、前記復号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部と、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部と、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部と、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部と、前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記暗号化対象データを表わすビット列との排他的論理和を計算することにより、前記暗号化対象データを暗号化する暗号化部と、を含んで構成されている。
 第2の態様に係るプログラムは、コンピュータを、復号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部、前記復号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部、及び前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記暗号化対象データを表わすビット列との排他的論理和を計算することにより、前記暗号化対象データを暗号化する暗号化部として機能させるためのプログラムである。
 このように、非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、複数種類の演算子を組み合わせた演算方法に置換して、ベクトルに、非可換行列A1、A2を繰り返し作用させると共に非線形変換を行って、得られるビット列W1、W2の排他的論理和を計算して、擬似乱数ビット列を求める。擬似乱数ビット列を用いて暗号化することにより、暗号化対象データのビット数が可変である場合において、暗号化処理を高速化し、かつ暗号解読強度を強くすることができる。
 第3の態様に係る行列作用部は、前記初期ベクトルv0、又は前回求められたベクトルvi-1 1に、非可換行列A1を作用させて、前記ベクトルvi 1を求める際に、ベクトルvi 1の要素毎に、既に計算されたベクトルvi 1の要素に置き換えた前記初期ベクトルv0又は前記ベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1の前記要素を計算し、前記初期ベクトルv0、又は前回求められたベクトルvi-1 2に、非可換行列A2を作用させて、前記ベクトルvi 2を求める際に、ベクトルvi 2の要素毎に、既に計算されたベクトルvi 2の要素に置き換えた前記初期ベクトルv0又は前記ベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2の前記要素を計算するようにすることができる。これによって、暗号解読強度をより強くすることができる。
 第4の態様に係るビット列変換部は、前記非線形変換として、前記行列作用部によって求められたベクトルvi 1をビット列に変換し、変換されたビット列に対して、予め定められた条件を満たす先頭ビット列をカットするカットオフ処理を行い、前記先頭ビット列がカットされた前記ビット列を前回求められたビット列W1に結合させると共に、ベクトルvi 2をビット列に変換し、変換されたビット列に対して、前記カットオフ処理を行い、前記先頭ビット列がカットされた前記ビット列を前回求められたビット列W2に結合させるようにすることができる。これによって、暗号解読強度をより強くすることができる。
 また、第5の態様に係るビット列変換部は、前前記カットオフ処理として、前記変換されたビット列に対して、前記予め定められた条件を満たす先頭ビット列として、先頭から連続する0と、先頭から最初に出現する1とからなる先頭ビット列をカットすると共に、前記先頭ビット列がカットされた前記ビット列から、予め定められたビット数の先頭ビット列をカットする処理を行うようにすることができる。これによって、暗号解読強度をより強くすることができる。
 第6の態様に係る復号化装置は、暗号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部と、前記暗号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部と、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部と、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、復号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部と、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部と、前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記復号化対象データを表わすビット列との排他的論理和を計算することにより、前記復号化対象データを復号化する復号化部と、を含んで構成されている。
 第7の態様に係るプログラムは、コンピュータを、暗号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部、前記暗号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、復号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部、及び前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記復号化対象データを表わすビット列との排他的論理和を計算することにより、前記復号化対象データを復号化する復号化部として機能させるためのプログラムである。
 このように、非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、複数種類の演算子を組み合わせた演算方法に置換して、ベクトルに、非可換行列A1、A2を繰り返し作用させると共に非線形変換を行って、得られるビット列W1、W2の排他的論理和を計算して、擬似乱数ビット列を求める。擬似乱数ビット列を用いて復号化することにより、復号化対象データのビット数が可変である場合において、復号化処理を高速化し、かつ暗号解読強度を強くすることができる。
 本発明の一態様である暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラムによれば、非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、複数種類の演算子を組み合わせた演算方法に置換して、ベクトルに、非可換行列A1、A2を繰り返し作用させると共に非線形変換を行って、得られるビット列W1、W2の排他的論理和を計算して、擬似乱数ビット列を求める。擬似乱数ビット列を用いて暗号化又は復号化することにより、暗号化対象データ又は復号化対象データのビット数が可変である場合において、暗号化処理又は復号化処理を高速化し、かつ暗号解読強度を強くすることができる。
本発明の実施の形態に係る暗号化処理システムの構成を示す概略図である。 本発明の実施の形態に係る暗号復号装置の構成を示す概略図である。 暗号化方法を説明するための図である。 復号化方法を説明するための図である。 本発明の実施の形態に係る暗号復号装置における擬似乱数列発生処理ルーチンの内容を示すフローチャートである。 実験結果を示すグラフである。
 以下、図面を参照して本発明の実施の形態を詳細に説明する。
<システム構成>
 図1に示すように、本発明の実施の形態に係る暗号化処理システム10は、暗号復号装置12A、12Bと、複数のユーザ端末14Aと、複数のユーザ端末14Bと、インターネットアクセス網16とを備えている。なお、暗号復号装置12A、12Bは、暗号化装置、復号化装置の一例である。
 複数のユーザ端末14Aは、暗号復号装置12Aと接続されており、暗号復号装置12Aは、インターネットアクセス網16に接続されている。また、複数のユーザ端末14Bは、暗号復号装置12Bと接続されており、暗号復号装置12Bは、インターネットアクセス網16に接続されている。暗号復号装置12A、12Bは、インターネットアクセス網16を介して相互に接続されている。
 ユーザ端末14Aは、インターネットアクセス網16を介したデータ送信を行う場合に、暗号復号装置12Aを介して、送信データがインターネットアクセス網16に出力され、一方、インターネットアクセス網16を介したデータ受信を行う場合に、暗号復号装置12Aを介して、受信データがインターネットアクセス網16から入力される。
 また、ユーザ端末14Bは、インターネットアクセス網16を介したデータ送信を行う場合に、暗号復号装置12Bを介して、送信データがインターネットアクセス網16へ出力され、一方、インターネットアクセス網16を介したデータ受信を行う場合に、暗号復号装置12Bを介して、受信データがインターネットアクセス網16から入力される。
 暗号復号装置12A、12Bは、CPU(Central Processing Unit)と、RAM(Random Access Memory)と、後述する擬似乱数列発生処理ルーチンを実行するためのプログラムを記憶したROM(Read Only Memory)とを備えたコンピュータで構成され、機能的には次に示すように構成されている。図2に示すように、暗号復号装置12A、12Bは、通信部20、データ入出力部22、共通データ設定部24、擬似乱数列発生部26、暗号化部28、及び復号化部30を備えている。なお、擬似乱数列発生部26は、行列生成部、行列作用部、ビット列変換部、ビット数判定部、及び擬似乱数発生列部の一例である。
 通信部20は、インターネットアクセス網16を介してデータの送受信を行う。
 データ入出力部22は、ユーザ端末14A、14Bから出力されたデータが入力されると共に、ユーザ端末14A、14Bに対してデータを出力する。
 共通データ設定部24は、暗号復号装置12A、12Bで共通のデータを設定する。具体的には、プライベートデータであるd×dの行列A、素数p1、p2、初期ベクトルv0が共通のデータとして設定される。
 擬似乱数列発生部26は、後述する手法により、プライベートデータであるd×dの行列A、素数p1、p2、及び初期ベクトルv0を用いて、擬似乱数ビット列を発生させる。
 暗号化部28は、擬似乱数列発生部26によって発生した擬似乱数ビット列を、ワンタイムパッド暗号の鍵として用いることで、データ入出力部22により入力された暗号化対象データに対して、ストリーム暗号を行う。例えば、図3Aに示すように、ビット列で表した平文(plain text)と、暗号化の鍵としての擬似乱数ビット列とのXORを演算することにより、前から1ビット毎に(あるいは1バイト毎に)暗号化する。暗号化部28により暗号化されたデータは、通信部20によりデータ送信される。
 復号化部30は、擬似乱数列発生部26によって発生した擬似乱数ビット列を、ワンタイムパッド暗号の鍵として用いることで、通信部20により受信された復号化対象データに対して、復号化を行う。例えば、図3Bに示すように、ビット列で表した暗号化文(cypher text)と、暗号化の鍵としての擬似乱数ビット列とのXORを演算することにより、前から1ビット毎に(あるいは1バイト毎に)復号化する。復号化部30により復号化されたデータは、データ入出力部22により、データ端末14A、14Bへ出力される。
 次に、本実施の形態における擬似乱数ビット列を発生させる原理について説明する。
 まず、擬似乱数列発生部26は、共通のプライベートデータとして設定されたd×dの行列A及び素数p1、p2とを用いて、以下のように、2つの非可換行列A1、A2を生成する。なお、以下では、行列Aが、2×2の行列である場合を例に説明する。
 擬似乱数列発生部26は、以下の(1)式に示すように、行列Aと素数p1とを用いて、行列A1’を計算する。
Figure JPOXMLDOC01-appb-M000001

 
 そして、擬似乱数列発生部26は、<g>={1,…,p1-1}となるジェネレータgを求める。例えば、p1=7のジェネレータは、以下のように、<3>={1,…,6}である。
31=3,32=9mod7=2,33=27mod7=6,34=81mod7=4,
35=243mod7=5,・・・
 そして、擬似乱数列発生部26は、A1”を、以下の(2)式で表わすとすると、det A1”=gになるようにd’を変更し、d’を変更したA”1を、非可換行列A1とする。
Figure JPOXMLDOC01-appb-M000002

 
 また、擬似乱数列発生部26は、以下の(3)式に示すように、行列Aと素数p2とを用いて、行列A2’を計算し、上記と同様に、非可換行列A2を生成する。
Figure JPOXMLDOC01-appb-M000003

 
 ここで、非可換行列A1、A2を用いて生成される擬似乱数列の周期の長さO(A)は、非可換行列A1、A2の生成に用いる、任意の素数pを用いて、以下の(4)式のように書ける。
O(A)≧p   ・・・(4)
 たとえば、pを100000ビットの素数とした場合、Aの周期はそれ以上に長くなる。
 また、擬似乱数列発生部26は、共通に設定された初期ベクトルv0に対して、生成された非可換行列A1を用いて変換を行い、ベクトルv1を得る。また、擬似乱数列発生部26は、ベクトルv1に対して、非可換行列A1を用いた変換を繰り返し、ベクトル列V={v0,v1,...,vt}を得る。ここでvi=A1 iv0である。
 そして、擬似乱数列発生部26は、得られたベクトル列Vから非線形変換により、ビット列W1を得る。ベクトル列Vからビット列Wを得る非線形変換として、Vの要素をvi=(vi,0,vi,1,...,vi,n)とし、vi,0をバイナリ変換したビット列から、先頭ビットから続く0と次に現われた1とからなるビット列を含む先頭ビット列を取り除くカットオフ処理を行う。ここで、カットオフの後、残ったビット列は高い乱数性を持つことが知られている。
 本実施の形態では、カットオフ処理において、Random cut及びFixed cut の2種類のカットオフを使用している。
 Random cutでは、上述したように、最初に現れる連続した0と、次に出現する1とからなる先頭ビット列をカットする。また、Fixed cutでは、あらかじめ決めておいたビット数だけカットする。例えば、Fixed cutでカットするビット数が3である場合、Random cutの結果として得られるビット列の先頭3ビットをカットする。
 viの要素すべてにこのカットオフ処理を行い、カットオフ処理後の要素を全て並べたビット列をWとする。
 攻撃者は、すべてのカットオフの可能性を検証しなければ、非可換行列A1とA2を復元することはできないため、攻撃に対する強さを向上させることができる。
 また、本実施の形態では、ベクトルviに、非可換行列A1、A2を作用させて、新しいベクトルvi+1を得る際に、数同士の和演算及び積演算を、以下のように複数の演算子を組み合わせた演算に置き換える。
 例えば、a、bを32bitの数とし、記号a<<kを、aをkビットずらす記号とすると、(和演算)a+bを、a+b mod 232に置き換える。また、(積演算)a×b を、 a<< (b / 227) xor bに置き換える。ここで、a<< (b / 227)は、a を 、bを227で割った商だけずらすことを表わし、xorはビットごとの排他的論理和を表わす。
 また、ベクトルviに、非可換行列A1、A2を作用させて、新しいベクトルvi+1を得る際に、更に、行列の作用の方法を以下のように置き換えてもよい。
 例えば、vi=(vi 1, vi 2,..., vi d)を、行列Aを初期ベクトルv0にi回作用させたものとする(dはAの次元)と、vi+1=(vi+1 1, vi+1 2,..., vi+1 d)を得る方法を以下のようにする。
 まず、vi+1 1=(Avi)1とする。これはベクトルAviの1番目の要素だけである。また、必要な計算は1番目の要素の計算だけである。2x2行列で書くと、
Figure JPOXMLDOC01-appb-M000004

 
となるが、和演算と積演算は、上述したように、別の演算で置き換えられている。
 そして、vi+1 2=(A(vi+1 1, vi 2,..., vi d))2とする。これは非可換行列Aを、viの1番目の要素をvi+1 1に置き換えたものに作用させ、2番目の要素を取り出したものである。なお、ここで必要な計算は、2番目の要素の計算だけである。
 そして、vi+1 3=(A(vi+1 1, vi+1 2,..., vi d))2とする。これは上記と同様に、viの1番目、2番目の要素を置き換えて、非可換行列Aを作用させ、3番目の要素を抜き出したものである。
 以降、d番目の要素まで同様に行い、vi+1を得る。
 また、暗号化する平文のビット数をnとすると、ビット列W1のビット数がnに到達した瞬間、ビット列W1に対する処理は中断され、ビット列W1の余った部分は捨てられる。
 擬似乱数列発生部26は、非可換行列A2に対しても同様に、ベクトルへの作用及びカットオフ処理を繰り返し行い、ビット列W2を生成する。また、ビット列W2のビット数がnに到達した瞬間、ビット列W2に対する処理は中断され、ビット列W2の余った部分は捨てられる。
 そして、擬似乱数列発生部26は、最終的に得られたビット列W1とビット列W2とのXORを計算し、得られたビット列を、擬似乱数ビット列とする。なお、ビット列W1とビット列W2とのXORにより得られたビット列に対して、更に非線形変換を行って、その結果を、擬似乱数ビット列としてもよい。
 擬似乱数列発生部26は、上記のように、暗号化対象データのビット数又は復号化対象データのビット数と同じビット数の擬似乱数ビット列を発生させる。
<暗号化処理システムの動作>
 次に、本実施の形態に係る暗号化処理システム10の動作について説明する。
 まず、ユーザ端末14Aから、データをユーザ端末14Bへ送信する場合に、ユーザ端末14Aが、送信データを、暗号復号装置12Aに出力する。
 また、暗号復号装置12Aにおいて、図4に示す擬似乱数列発生処理ルーチンが実行される。
 まず、ステップ100において、暗号復号装置12Aは、暗号復号装置12Bと共通に設定された非可換行列A、素数p1、p2を用いて、非可換行列A1、A2を生成する。ステップ102では、暗号復号装置12Aは、ベクトルを識別する変数iを初期値である0に設定する。また、初期ベクトルv0を設定する。
 次のステップ104では、暗号復号装置12Aは、ベクトルviに、非可換行列A1、A2をそれぞれ作用させて、ベクトルvi+1 1、vi+1 2を計算する。ステップ106では、上記ステップ104で計算されたベクトルvi+1 1、vi+1 2の各々を、ビット列に変換すると共に、それぞれのビット列に対して、カットオフ処理を行い、先頭ビット列をカットオフする。そして、ステップ108において、暗号復号装置12Aは、上記ステップ106で得られたビット列の各々を、ビット列W1、W2に対して更に並べるように追加する。
 ステップ110では、暗号復号装置12Aは、ビット列W1、W2の各々のビット数が、送信データ(暗号化対象データ)のビット列のビット数に到達したか否かを判定する。ビット列W1、W2の各々のビット数が、ユーザ端末14Aから入力された送信データ(暗号化対象データ)のビット列のビット数に到達していない場合には、ステップ112において、暗号復号装置12Aは、変数iを1インクリメントして、上記ステップ104へ戻って、ステップ104以降の処理を繰り返す。ここで、ビット列W1のみについて、ビット数が、送信データのビット列のビット数に到達した場合には、上記ステップ104以降の処理において、暗号復号装置12Aは、非可換行列A1を用いた処理は行わない。また、ビット列W2のみについて、ビット数が、送信データのビット列のビット数に到達した場合には、上記ステップ104以降の処理において、暗号復号装置12Aは、非可換行列A2を用いた処理は行わない。
 また、上記ステップ110において、暗号復号装置12Aは、ビット列W1、W2の双方のビット数が、送信データのビット列のビット数に到達したと判定された場合には、ステップ114へ進む。
 ステップ114では、暗号復号装置12Aは、ビット列W1、W2のXORを演算して、擬似乱数ビット列Sを生成し、擬似乱数列発生処理ルーチンを終了する。
 そして、暗号復号装置12Aは、上記の擬似乱数列発生処理ルーチンによって生成された擬似乱数ビット列Sと、ユーザ端末14から入力された送信データのビット列とのXORを演算することにより、暗号化された送信データを生成する。また、暗号復号装置12Aは、暗号化された送信データを、インターネットアクセス網16を介してユーザ端末14Bへ送信する。
 暗号化された送信データは、暗号復号装置12Bによって受信され、暗号復号装置12Bにおいて、上記図4の擬似乱数列発生処理ルーチンが同様に実行され、暗号化された送信データと同じビット数の擬似乱数ビット列Sが生成される。
 そして、暗号復号装置12Bは、生成された擬似乱数ビット列Sと、暗号化された送信データのビット列とのXORを演算することにより、暗号化された送信データの平文を生成する。また、暗号復号装置12Bは、送信データの平文を、送信先として指定されたユーザ端末Bへ出力する。
 前記した実施形態の一構成要素にあたる擬似乱数列は本発明を創作する過程で統計テスト(NISTU01テスト)を実施している(F.Giuseppe,“Benchmarking for the QP Cryptographic Suite”,Dipartmento di Informatica, Sistemi e Produzione, Universita di Roma “Tor Vergata”(イタリア語)、2009参照)。以下、NISTU01テストの結果について簡単に説明するが、本テストは、プログラムソースがクローズされた状態で入出力の状態のみを取得して行っているものである。ここで、NISTとは米国立標準技術研究所であって、NISTU01テストは、NISTが米国の政府機関での使用を認める暗号アルゴリズムおよび実装の要件を課す目的で実施しているテストの一つであり、疑似乱数列の安全性を評価するものである。
 U01はCライブラリで提供されているものを用いた。テストには、SmallCrush,BigCrash,Rabbit,Alphabit,FIPS-140-2,pseudoDIEHARDが含まれている。ここで、現在広く用いられている擬似乱数列発生アルゴリズムRC4を比較対象とした。
 前記した実施形態の一構成要素にあたる擬似乱数列は、全ての統計テストをパスしたが、比較対象であるRC4は、多くのテストをパスできなかった。これにより、実施の形態で説明した擬似乱数列の発生アルゴリズムでは、統計的に安全な擬似乱数列を生成できることが分かった。
 続いて、前記した実施形態の一構成要素にあたる暗号化方法(以下、QP-DYNとも称する。)についても本発明を創作する過程で実施した実験結果について説明する。
 この実験は、暗号化速度を検証することを目的に、ストリーム暗号の暗号化速度の検証を実施している(Performance Analysis of Algorithms and Statistical Tests,(イタリア語),2011)。なお、この実験についても、前記したNISTU01テストと同様に、プログラムソースがクローズされた状態で入出力の状態のみを取得して行っているものである。
 実験の環境は以下の通りである。Windows7(登録商標)上のパフォーマンスは、以下の表1に示す。
Figure JPOXMLDOC01-appb-T000005

 
 いくつかのファイル(10MB、100MB、pdfファイル、ディスクイメージ(ubuntu-10.10-desktop-i386.iso),mp4ビデオ3.5G,Wordドキュメント等)でデータの暗号化の実験を行い、読み書きのプロセスまで含めた1秒あたりの暗号化データ量の計測を行った。
 比較対象として、AESとTwoFishを用いた。仕様を以下の表2に示す。
Figure JPOXMLDOC01-appb-T000006

 
 各テストデータに対して暗号化における1秒あたりの暗号化データ量を計測し、平均を求めると、図5に示す実験結果が得られた。これより、256ビットの鍵長のAESとTwoFishより、QP-DYN288ビットと1156ビットのほうが、1秒あたりの暗号化データ量が多いことが分かった。
 以上説明したように、本発明の実施の形態に係る暗号復号装置は、非可換行列A1、A2を作用させる際の和演算及び積演算を、複数種類の演算子を組み合わせた演算方法に置換して、初期ベクトルに、非可換行列A1、A2を繰り返し作用させると共に非線形変換を行って、得られるビット列W1、W2のXORを計算して、擬似乱数ビット列を求める。暗号復号装置は、擬似乱数ビット列を用いて暗号化又は復号化することにより、暗号化対象データ又は復号化対象データのビット数が可変である場合において、暗号化処理又は復号化処理を高速化し、かつ暗号解読強度を強くすることができる。
 また、他のストリーム暗号より高速で、計算能力の低い小型デバイス上でも実装が可能である。
 また、擬似乱数列発生アルゴリズムにおいて、いくつかの非線形変換を用いることにより、擬似乱数列の統計的ランダム性と長周期を保証することができ、生成された擬似乱数列を用いることにより、安全な使い捨て暗号鍵(One-Time-Padキー)を生成することができる。
 また、ストリーミング暗号を実現することができるため、音声・動画などのマルチメディア・ファイルを安全にかつ高速に転送することができる。
 なお、本発明は、上述した実施形態に限定されるものではなく、この発明の要旨を逸脱しない範囲内で様々な変形や応用が可能である。
 例えば、ストリーミング暗号以外に、本発明を適用してもよく、自動車のキーレスエントリーなどへ応用してもよい。また、HDD(hard disk drive)の暗号化に応用してもよい。例えば、本実施の形態で説明した暗号化方法により、HDDに保存されるすべてのデータが暗号化され、正当なユーザしか読み出しできないようにしてもよい。また、Cloudサービスのセキュリティに、本発明を応用してもよい。
 また、本願明細書中において、プログラムが予めインストールされている実施形態として説明したが、当該プログラムを、コンピュータ読み取り可能な記録媒体に格納して提供することも可能である。
 本発明の一態様のコンピュータ可読媒体は、コンピュータを、復号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部、前記復号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部、及び前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記暗号化対象データを表わすビット列との排他的論理和を計算することにより、前記暗号化対象データを暗号化する暗号化部として機能させるためのプログラムを記憶したコンピュータ可読媒体である。
 本発明の一態様のコンピュータ可読媒体は、コンピュータを、暗号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部、前記暗号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、復号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部、及び前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記復号化対象データを表わすビット列との排他的論理和を計算することにより、前記復号化対象データを復号化する復号化部として機能させるためのプログラムを記憶したコンピュータ可読媒体である。
 日本出願2012-084113の開示はその全体が参照により本明細書に取り込まれる。
 本明細書に記載された全ての文献、特許出願、及び技術規格は、個々の文献、特許出願、及び技術規格が参照により取り込まれることが具体的かつ個々に記載された場合と同程度に、本明細書中に参照により取り込まれる。

Claims (9)

  1.  復号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部と、
     前記復号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部と、
     前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部と、
     前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部と、
     前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部と、
     前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記暗号化対象データを表わすビット列との排他的論理和を計算することにより、前記暗号化対象データを暗号化する暗号化部と、
     を含む暗号化装置。
  2.  前記行列作用部は、
     前記初期ベクトルv0、又は前回求められたベクトルvi-1 1に、非可換行列A1を作用させて、前記ベクトルvi 1を求める際に、ベクトルvi 1の要素毎に、既に計算されたベクトルvi 1の要素に置き換えた前記初期ベクトルv0又は前記ベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1の前記要素を計算し、
     前記初期ベクトルv0、又は前回求められたベクトルvi-1 2に、非可換行列A2を作用させて、前記ベクトルvi 2を求める際に、ベクトルvi 2の要素毎に、既に計算されたベクトルvi 2の要素に置き換えた前記初期ベクトルv0又は前記ベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2の前記要素を計算する請求項1記載の暗号化装置。
  3.  前記ビット列変換部は、
     前記非線形変換として、前記行列作用部によって求められたベクトルvi 1をビット列に変換し、変換されたビット列に対して、予め定められた条件を満たす先頭ビット列をカットするカットオフ処理を行い、前記先頭ビット列がカットされた前記ビット列を前回求められたビット列W1に結合させると共に、ベクトルvi 2をビット列に変換し、変換されたビット列に対して、前記カットオフ処理を行い、前記先頭ビット列がカットされた前記ビット列を前回求められたビット列W2に結合させる請求項1又は2記載の暗号化装置。
  4.  前記ビット列変換部は、前記カットオフ処理として、前記変換されたビット列に対して、前記予め定められた条件を満たす先頭ビット列として、先頭から連続する0と、先頭から最初に出現する1とからなる先頭ビット列をカットすると共に、前記先頭ビット列がカットされた前記ビット列から、予め定められたビット数の先頭ビット列をカットする処理を行う請求項3記載の暗号化装置。
  5.  暗号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部と、
     前記暗号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部と、
     前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部と、
     前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、復号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部と、
     前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部と、
     前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記復号化対象データを表わすビット列との排他的論理和を計算することにより、前記復号化対象データを復号化する復号化部と、
     を含む復号化装置。
  6.  コンピュータを、
     復号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部、
     前記復号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部、
     前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部、
     前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部、
     前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部、及び
     前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記暗号化対象データを表わすビット列との排他的論理和を計算することにより、前記暗号化対象データを暗号化する暗号化部
     として機能させるためのプログラム。
  7.  コンピュータを、
     暗号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成する行列生成部、
     前記暗号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求める行列作用部であって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させる行列作用部、
     前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるビット列変換部、
     前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、復号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すビット数判定部、
     前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求める擬似乱数列発生部、及び
     前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記復号化対象データを表わすビット列との排他的論理和を計算することにより、前記復号化対象データを復号化する復号化部
     として機能させるためのプログラム。
  8.  行列生成部によって、復号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成するステップと、
     行列作用部によって、前記復号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求めるステップであって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させるステップと、
     ビット列変換部によって、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるステップと、
     ビット数判定部によって、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、暗号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すステップと、
     擬似乱数列発生部によって、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求めるステップと、
     暗号化部によって、前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記暗号化対象データを表わすビット列との排他的論理和を計算することにより、前記暗号化対象データを暗号化するステップと、
     を含む暗号化方法。
  9.  行列生成部によって、暗号化装置と共通に設定された、プライベートデータであるd×dの行列A、及び2つの素数p1、p2に基づいて、2つの非可換行列A1、A2を生成するステップと、
     行列作用部によって、前記暗号化装置と共通に設定されたd次元の初期ベクトルv0又は前回求められたd次元のベクトルvi-1 1に、非可換行列A1を作用させて、ベクトルvi 1を求めると共に、前記初期ベクトルv0、又は前回求められたd次元のベクトルvi-1 2に、非可換行列A2を作用させて、ベクトルvi 2を求めるステップであって、前記非可換行列A1、A2を作用させる際の和演算及び積演算の少なくとも一方を、予め定められた、複数種類の演算子を組み合わせた演算方法に置換して、非可換行列A1、A2を作用させるステップと、
     ビット列変換部によって、前記行列作用部によって求められたベクトルvi 1に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W1に結合させて前記ビット列W1を求めると共に、ベクトルvi 2に対して非線形変換を行ってビット列に変換し、前記変換したビット列を前回求められたビット列W2に結合させて前記ビット列W2を求めるステップと、
     ビット数判定部によって、前記ビット列変換部によって求められた前記ビット列W1及び前記ビット列W2の各々のビット数が、復号化対象データを表わすビット列のビット数になるまで、前記行列作用部による作用と前記ビット列変換部による変換及び結合とを繰り返すステップと、
     擬似乱数列発生部によって、前記ビット列W1及び前記ビット列W2の排他的論理和を計算して、擬似乱数ビット列を求めるステップと、
     復号化部によって、前記擬似乱数列発生部によって求められた擬似乱数ビット列と、前記復号化対象データを表わすビット列との排他的論理和を計算することにより、前記復号化対象データを復号化するステップと
     を含む復号化方法。
PCT/JP2013/057509 2012-04-02 2013-03-15 暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラム Ceased WO2013150880A1 (ja)

Priority Applications (4)

Application Number Priority Date Filing Date Title
CN201380018975.0A CN104303453B (zh) 2012-04-02 2013-03-15 加密装置、解密装置、加密方法、解密方法
EP13773112.1A EP2835932B1 (en) 2012-04-02 2013-03-15 Encryption device, decryption device, encryption method, decryption method, and program
KR1020147030403A KR102033196B1 (ko) 2012-04-02 2013-03-15 암호화 장치, 복호화 장치, 암호화 방법, 복호화 방법, 및 프로그램
US14/390,204 US9467286B2 (en) 2012-04-02 2013-03-15 Encryption device, decryption device, encryption method, decryption method, and program

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2012084113A JP6035459B2 (ja) 2012-04-02 2012-04-02 暗号化装置、復号化装置、及びプログラム
JP2012-084113 2012-04-02

Publications (1)

Publication Number Publication Date
WO2013150880A1 true WO2013150880A1 (ja) 2013-10-10

Family

ID=49300374

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2013/057509 Ceased WO2013150880A1 (ja) 2012-04-02 2013-03-15 暗号化装置、復号化装置、暗号化方法、復号化方法、及びプログラム

Country Status (7)

Country Link
US (1) US9467286B2 (ja)
EP (1) EP2835932B1 (ja)
JP (1) JP6035459B2 (ja)
KR (1) KR102033196B1 (ja)
CN (1) CN104303453B (ja)
TW (1) TWI606714B (ja)
WO (1) WO2013150880A1 (ja)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105721148A (zh) * 2016-04-12 2016-06-29 武汉优信众网科技有限公司 一种基于双随机数的数据文件加密方法及系统
CN105799620A (zh) * 2014-12-29 2016-07-27 上海通用汽车有限公司 车辆电子控制模块的安全代码计算
CN109478999A (zh) * 2016-04-05 2019-03-15 罗之落有限责任公司 用于从在网络上传输并存储在数据存储设施中的数据中移除信息的反式加密方法和设备

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI554073B (zh) * 2014-07-28 2016-10-11 柯呈翰 供加密檔案和/或通訊協定之多重加密方法與系統
CN105076959A (zh) * 2015-07-15 2015-11-25 王永帮 一种薏米木瓜猪蹄粥及其制备方法
TWI575925B (zh) * 2015-11-11 2017-03-21 大宏數創意股份有限公司 資料加解密的方法及系統
DE102019214379B4 (de) * 2019-09-20 2023-03-09 Hans-Joachim Bentz Vorrichtung und Verfahren zur Verschlüsselung
CN110855423A (zh) * 2019-09-23 2020-02-28 深圳市智讯互动体育科技有限公司 加密解密有序数值串的方法、装置及存储介质
CN111191272A (zh) * 2019-11-20 2020-05-22 航天信息股份有限公司 数据脱敏方法、电子设备及存储介质
CN113766242B (zh) * 2020-06-01 2023-05-05 中国移动通信有限公司研究院 水印嵌入方法、水印提取方法及装置
EP4292237A1 (en) * 2021-02-10 2023-12-20 Rampart Communications, Inc. Automorphic transformations of signal samples within a transmitter or receiver
CN112887079B (zh) * 2021-03-11 2022-10-04 中国石油大学(华东) 基于一段随机比特序列生成的变换加密算法
US12328210B1 (en) 2021-10-06 2025-06-10 Rampart Communications, Inc. Methods and apparatus for signal correlation using a quadratic form
CN115795515B (zh) * 2022-12-22 2026-04-14 美的集团股份有限公司 数据加密方法和数据加密装置
CN116094690B (zh) * 2023-04-07 2023-06-06 中铁工程设计咨询集团有限公司 几何图形数字资产加密方法、装置、设备及可读存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001358709A (ja) * 2000-06-13 2001-12-26 Casio Comput Co Ltd 暗号化装置、復号化装置、その方法及び記録媒体
JP2003241656A (ja) 2002-02-19 2003-08-29 Sony Corp 暗号化装置および暗号化方法
JP2007264147A (ja) * 2006-03-27 2007-10-11 Fukuoka Institute Of Technology 疑似乱数列生成装置、暗号化復号化装置、疑似乱数列生成方法、暗号化復号化方法、疑似乱数列生成プログラムおよび暗号化復号化プログラム
JP2009005164A (ja) 2007-06-22 2009-01-08 Dainippon Printing Co Ltd 暗号処理装置,暗号処理プログラム及び暗号処理方法
JP2012084113A (ja) 2010-09-17 2012-04-26 Jtekt Corp 遠隔操作装置及び工作機械

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3773226B2 (ja) * 1997-10-06 2006-05-10 カシオ計算機株式会社 暗号化装置
JP2001016196A (ja) * 1999-04-28 2001-01-19 Fuji Soft Abc Inc 多重アファイン鍵を用いる暗号化・復号化方法、認証方法、及びこれを用いる各装置
US20040086117A1 (en) * 2002-06-06 2004-05-06 Petersen Mette Vesterager Methods for improving unpredictability of output of pseudo-random number generators
JP2007288254A (ja) * 2006-04-12 2007-11-01 Sony Corp 通信システム、通信装置および方法、並びにプログラム
US8781117B2 (en) * 2007-08-29 2014-07-15 Red Hat, Inc. Generating pseudo random bits from polynomials
JP5489696B2 (ja) * 2009-12-21 2014-05-14 Kddi株式会社 ストリーム暗号の暗号化装置、ストリーム暗号の復号化装置、ストリーム暗号の暗号化方法、ストリーム暗号の復号化方法およびプログラム
TWI406138B (zh) * 2010-04-01 2013-08-21 Ind Tech Res Inst 循序運算的伽羅瓦乘法架構與方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001358709A (ja) * 2000-06-13 2001-12-26 Casio Comput Co Ltd 暗号化装置、復号化装置、その方法及び記録媒体
JP2003241656A (ja) 2002-02-19 2003-08-29 Sony Corp 暗号化装置および暗号化方法
JP2007264147A (ja) * 2006-03-27 2007-10-11 Fukuoka Institute Of Technology 疑似乱数列生成装置、暗号化復号化装置、疑似乱数列生成方法、暗号化復号化方法、疑似乱数列生成プログラムおよび暗号化復号化プログラム
JP2009005164A (ja) 2007-06-22 2009-01-08 Dainippon Printing Co Ltd 暗号処理装置,暗号処理プログラム及び暗号処理方法
JP2012084113A (ja) 2010-09-17 2012-04-26 Jtekt Corp 遠隔操作装置及び工作機械

Non-Patent Citations (6)

* Cited by examiner, † Cited by third party
Title
ACCARDI, L ET AL.: "The QP-DYN algorithms", 2011, XP007919884, Retrieved from the Internet <URL:http://www.cryptalarm.it/ca/documenti/upload2set/8125_chap01,pdf> [retrieved on 20130408] *
F. GIUSEPPE: "Benchmarking for the QP Cryptographic Suite", DIPARTMENTO DI INFORMATICA, SISTEMI E PRODUZIONE, UNIVERSITA DI ROMA, 2009
L. ACCARDI; M. REGOLI; M. OHYA: "The QP-DYN Algorithm", QP-PQ 28, QUANTUM BIO-INFORMATICS IV, 2011, pages 1 - 16
L. ACCARDI; M. REGOLI; M.OHYA: "The QP-DYN Algorithm", QP-PQ 28, QUANTUM BIO-INFORMATICS IV, 2011, pages 1 - 16
M. ABUNDO ET AL.: "Hyperbolic automorphisms of tori and pseudo-random sequences", CALCOLO, vol. 29, 1 September 1992 (1992-09-01), pages 213 - 240, XP055169269 *
PERFORMANCE ANALYSIS OF ALGORITHMS AND STATISTICAL TESTS, (IN ITALIAN, 2011

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105799620A (zh) * 2014-12-29 2016-07-27 上海通用汽车有限公司 车辆电子控制模块的安全代码计算
CN109478999A (zh) * 2016-04-05 2019-03-15 罗之落有限责任公司 用于从在网络上传输并存储在数据存储设施中的数据中移除信息的反式加密方法和设备
CN109478999B (zh) * 2016-04-05 2021-12-03 罗之落有限责任公司 用于从在网络上传输并存储在数据存储设施中的数据中移除信息的反式加密方法和设备
CN105721148A (zh) * 2016-04-12 2016-06-29 武汉优信众网科技有限公司 一种基于双随机数的数据文件加密方法及系统
CN105721148B (zh) * 2016-04-12 2019-01-18 武汉珈铭汉象教育科技有限公司 一种基于双随机数的数据文件加密方法及系统

Also Published As

Publication number Publication date
EP2835932A4 (en) 2015-12-23
TW201404107A (zh) 2014-01-16
JP6035459B2 (ja) 2016-11-30
EP2835932A1 (en) 2015-02-11
EP2835932B1 (en) 2020-09-30
KR20140143210A (ko) 2014-12-15
CN104303453B (zh) 2017-07-04
US9467286B2 (en) 2016-10-11
US20150110269A1 (en) 2015-04-23
CN104303453A (zh) 2015-01-21
KR102033196B1 (ko) 2019-11-29
JP2013213930A (ja) 2013-10-17
TWI606714B (zh) 2017-11-21

Similar Documents

Publication Publication Date Title
JP6035459B2 (ja) 暗号化装置、復号化装置、及びプログラム
JP5402632B2 (ja) 共通鍵ブロック暗号化装置、共通鍵ブロック暗号化方法及びプログラム
JP6019453B2 (ja) 暗号化装置、復号化装置、及びプログラム
CN107637010B (zh) 数据加密装置及方法和数据解密装置及方法
EP2911138A2 (en) Variable-length block cipher apparatus and method capable of format preserving encryption
JP6575532B2 (ja) 暗号化装置、復号装置、暗号処理システム、暗号化方法、復号方法、暗号化プログラム、及び復号プログラム
WO2017056150A1 (ja) メッセージ認証子生成装置、メッセージ認証子生成方法及びメッセージ認証子生成プログラム
JP5689826B2 (ja) 秘密計算システム、暗号化装置、秘密計算装置及びその方法、プログラム
Sharma et al. Analysis of AES Encryption with ECC
JP5992651B2 (ja) 暗号化方法、プログラム、および、システム
Waqas et al. Generation of AES-like S-boxes by replacing affine matrix
JP7226829B2 (ja) データ処理装置、方法及びコンピュータプログラム
CN109714154B (zh) 一种代码体积困难白盒安全模型下的白盒密码算法的实现方法
US20250015984A1 (en) Use Of Quantum Resistant Iterative Keypads For Large Files
JP2017038336A (ja) 復号方法
Mohammed et al. Evaluation of rijndael algorithm for audio encryption by brute force attack
Abdulrazaq A novel approach for safeguarding Kurdish text files via modified AES-OTP and enhanced RSA cryptosystem on unreliable networks
JP2015082077A (ja) 暗号化装置、制御方法、及びプログラム
JP5293612B2 (ja) 暗号化装置、復号装置、暗号化方法、復号方法およびプログラム
Padhi et al. Modified version of XTS (XOR-Encrypt-XOR with Ciphertext Stealing) using tweakable enciphering scheme
Welekar et al. A novel approach for file encryption
RU2694336C1 (ru) Способ аутентифицированного шифрования
Rupa Performance Evaluation of Message Security Using Fractal Sieve with MMD
Vajargah et al. Implementation of Chaotic Henon Congruential Generator (CHCG) for Message Encryption
KR20150111785A (ko) 포멧유지 컴포넌트 기반 포멧 유지 암호화 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13773112

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 14390204

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2013773112

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20147030403

Country of ref document: KR

Kind code of ref document: A