IP Library Granted Patent US 8,520,844
Granted Patent B2
US 8,520,844 · App. 10/600,687 · Granted Aug 27, 2013

Methods and apparatus for providing secure two-party public key cryptosystem

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,520,844
App. No.
10/600,687
Granted
Aug 27, 2013
Kind
B2
Abstract

Techniques for an efficient and provably secure protocol by which two parties, each holding a share of a Cramer-Shoup private key, can jointly decrypt a ciphertext, but such that neither party can decrypt a ciphertext alone. In an illustrative embodiment, the secure protocol may use homomorphic encryptions of partial Cramer-Shoup decryption subcomputations, and three-move Σ-protocols for proving consistency.

Claims (28)

1. A method for use in a device associated with a first party for decrypting a ciphertext according to a Cramer-Shoup based encryption scheme, the method comprising the steps of:

obtaining the ciphertext in the first party device sent from a device associated with a second party; and

generating in the first party device a plaintext corresponding to the ciphertext based on assistance from the second party device, wherein the assistance comprises an exchange of information between the first party device and the second party device separate from the sending of the ciphertext from the second party device to the first party device, the plaintext representing a result of the decryption according to the Cramer-Shoup based encryption scheme, such that the first party device and the second party device jointly perform a Cramer-Shoup based decryption operation of the ciphertext by each respectively performing one or more Cramer-Shoup based subcomputations of the joint Cramer-Shoup based decryption operation based at least in part on respective partial shares of a Cramer-Shoup based key that each party holds, but such that neither can decrypt the ciphertext alone.

2. The method of claim 1 , wherein the generating step further comprises an exchange of information between the first party device and the second party device whereby at least a portion of the information is encrypted using an encryption technique such that one party encrypts information using its own public key and another party can not read the information but can use the information to perform an operation.

3. The method of claim 1 , wherein the generating step further comprises an exchange of information between the first party device and the second party device whereby at least a portion of the information is encrypted using an encryption technique having a homomorphic property.

4. The method of claim 1 , wherein the generating step further comprises:

generating a share of a random secret;

generating information representing encryptions of a form of the random secret, a share of a private key, and the ciphertext;

transmitting at least the encrypted information to the second party device; and

computing the plaintext based at least on the share of the random secret, the share of the private key, the ciphertext, and the data received from the second party device.

5. The method of claim 1 , wherein the first party device and the second party device additively share components of a private key.

6. The method of claim 1 , wherein the generating step further comprises generation and exchange of proofs between the first party device and the second party device that serve to verify operations performed by each party.

7. The method of claim 6 , wherein the proofs are consistency proofs based on three-move Σ-protocols.

8. A method for use in a device associated with a first party for assisting in decrypting a ciphertext according to a Cramer-Shoup based encryption scheme, the method comprising the steps of:

receiving a request generated in and transmitted by a second party device for the partial assistance of the first party device in decrypting the ciphertext according to the Cramer-Shoup based encryption scheme; and

generating results in the first party device based on the partial assistance provided thereby for use in the second party device to complete decryption of the ciphertext, wherein the assistance comprises an exchange of information between the first party device and the second party device separate from the sending of the ciphertext from the first party device to the second party device, such that the first party device and the second party device jointly perform a Cramer-Shoup based decryption operation of the ciphertext by each respectively performing one or more Cramer-Shoup based subcomputations of the joint Cramer-Shoup based decryption operation based at least in part on respective partial shares of a Cramer-Shoup based key that each party holds, but such that neither can decrypt the ciphertext alone.

9. An apparatus for use in a device associated with a first party for decrypting a ciphertext according to a Cramer-Shoup based encryption scheme, the apparatus comprising:

a memory; and

at least one processor coupled to the memory and operative to: (i) obtain the ciphertext in the first party device sent from a device associated with a second party; and (ii) generate in the first party device a plaintext corresponding to the ciphertext based on assistance from a the second party device, wherein the assistance comprises an exchange of information between the first party device and the second party device separate from the sending of the ciphertext from the second party device to the first party device, the plaintext representing a result of the decryption according to the Cramer-Shoup based encryption scheme, such that the first party device and the second party device jointly perform a Cramer-Shoup based decryption operation of the ciphertext by each respectively performing one or more Cramer-Shoup based subcomputations of the joint Cramer-Shoup based decryption operation based at least in part on respective partial shares of a Cramer-Shoup based key that each party holds, but such that neither can decrypt the ciphertext alone.

10. The apparatus of claim 9 , wherein the generating operation further comprises an exchange of information between the first party device and the second party device whereby at least a portion of the information is encrypted using an encryption technique such that one party encrypts information using its own public key and another party can not read the information but can use the information to perform an operation.

11. The apparatus of claim 9 , wherein the generating operation further comprises an exchange of information between the first party device and the second party device whereby at least a portion of the information is encrypted using an encryption technique having a homomorphic property.

12. The apparatus of claim 9 , wherein the generating operation further comprises: (i) generating a share of a random secret; (ii) generating information representing encryptions of a form of the random secret, a share of a private key, and the ciphertext; (iii) transmitting at least the encrypted information to the second party device; and (iv) computing the plaintext based at least on the share of the random secret, the share of the private key, the ciphertext, and the data received from the second party device.

13. The apparatus of claim 9 , wherein the first party device and the second party device additively share components of a private key.

14. The apparatus of claim 9 , wherein the generating operation further comprises generation and exchange of proofs between the first party device and the second party device that serve to verify operations performed by each party.

15. The apparatus of claim 14 , wherein the proofs are consistency proofs based on three-move Σ-protocols.

16. An apparatus for use in a device associated with a first party for assisting in decrypting a ciphertext according to a Cramer-Shoup based encryption scheme, the apparatus comprising:

a memory; and

at least one processor coupled to the memory and operative to: (i) receive a request generated in and transmitted by a second party device for the partial assistance of the first party device in decrypting the ciphertext according to the Cramer-Shoup based encryption scheme; and (ii) generate results in the first party device based on the partial assistance provided thereby for use in the second party device to complete decryption of the ciphertext, wherein the assistance comprises an exchange of information between the first party device and the second party device separate from the sending of the ciphertext from the first party device to the second party device, such that the first party device and the second party device jointly perform a Cramer-Shoup based decryption operation of the ciphertext by each respectively performing one or more Cramer-Shoup based subcomputations of the joint Cramer-Shoup based decryption operation based at least in part on respective partial shares of a Cramer-Shoup based key that each party holds, but such that neither can decrypt the ciphertext alone.

Assignments (9)
SECURITY INTEREST Recorded Jun 1, 2021
From: WSOU INVESTMENTS, LLC
To: OT WSOU TERRIER HOLDINGS, LLC
Reel/Frame 056990/0081 →
RELEASE OF SECURITY INTEREST Recorded May 21, 2019
From: OCO OPPORTUNITIES MASTER FUND, L.P. (F/K/A OMEGA CREDIT OPPORTUNITIES MASTER FUND LP
To: WSOU INVESTMENTS, LLC
Reel/Frame 049246/0405 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2017
From: ALCATEL LUCENT
To: WSOU INVESTMENTS, LLC
Reel/Frame 044000/0053 →
SECURITY INTEREST Recorded Sep 21, 2017
From: WSOU INVESTMENTS, LLC
To: OMEGA CREDIT OPPORTUNITIES MASTER FUND, LP
Reel/Frame 043966/0574 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0555 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2013
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 030542/0001 →
MERGER Recorded Jun 4, 2013
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 030537/0801 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2003
From: MACKENZIE, PHILIP D.
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 014224/0730 →