IP Library › Granted Patent US 12,284,290
Granted Patent B2
US 12,284,290 · App. 18/178,286 · Granted Apr 22, 2025

Publicly verifiable and resilient symmetric authentication and privacy systems and related methods

Inventor: Attila Altay Yavuz (Tampa, FL)
Assignee: UNIVERSITY OF SOUTH FLORIDA
H04L9/3247H04L9/008H04L9/0861H04L9/0891H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,290
App. No.
18/178,286
Granted
Apr 22, 2025
Kind
B2
Abstract

A method for publicly verifiable symmetric cryptography is disclosed. The method includes: obtaining an initial encrypted key and a homomorphic public key; obtaining a first message and an initial signature; calculating an initial hashed value of the first message; setting a cryptographic function of the initial hashed value of the first message and an initial private key; generating an evaluated value based on the cryptographic function, the homomorphic public key, the initial encrypted key, and the initial hashed value of the first message; and transmitting, at the verifier, a verification result based on a hashed value of the initial signature and the evaluated value. Other aspects, embodiments, and features are also claimed and described.

Claims (68)

1. A method for publicly verifiable symmetric cryptography, the method comprising:

generating, at a processor of a generator, an initial private key based on a security parameter;

generating, at the processor of the generator, a homomorphic private key and a homomorphic public key based on the security parameter;

generating, at the processor of the generator, an initial encrypted key based on the homomorphic public key and the initial private key;

obtaining, from a processor of a signer, the initial private key;

obtaining, at a processor of a verifier, the initial encrypted key and the homomorphic public key;

obtaining, at the processor of the verifier from the signer, a first message and an initial signature, wherein the initial signature is based on an initial hashed value of the first message and the initial private key;

calculating, at the processor of the verifier, the initial hashed value of the first message;

setting, at the processor of the verifier, a cryptographic function of the initial hashed value of the first message and the initial private key;

generating, at the processor of the verifier, an evaluated value based on the cryptographic function, the homomorphic public key, the initial encrypted key, and the initial hashed value of the first message; and

transmitting, at the processor of the verifier, a verification result based on a hashed value of the initial signature and the evaluated value.

2. The method of claim 1 , wherein the homomorphic private key and the homomorphic public key are generated using a fully homomorphic encryption scheme.

3. The method of claim 1 , wherein the initial encrypted key is generated by encrypting the initial private key based on the homomorphic public key using a fully homomorphic encryption scheme.

4. The method of claim 1 , wherein the initial signature is generated using a message authentication code scheme,

wherein the initial signature is an output of the message authentication code scheme, and

wherein the initial hashed value of the first message and the initial private key are inputs of the message authentication code scheme.

5. The method of claim 4 , wherein the initial hashed value of the first message is obtained using a cryptographic hash function with an input of the first message.

6. The method of claim 4 , wherein the message authentication code scheme is designed based on a pseudorandom function.

7. The method of claim 1 , further comprising:

obtaining, at the processor of the verifier from the signer, a plurality of second messages and a plurality of subsequent signatures, wherein a plurality of subsequent signatures is based on a plurality of subsequent hashed values of a plurality of second messages and a plurality of updated private keys.

8. The method of claim 7 , wherein a first updated private key of the plurality of updated private keys is generated based on the initial private key, and

wherein a second updated private keys of the plurality of updated private keys is generated based on the first updated private key.

9. The method of claim 7 , wherein after the plurality of subsequent signatures is generated, the initial private key and the plurality of updated private keys are deleted.

10. The method of claim 7 , further comprising:

calculating, at the processor of the verifier, the plurality of subsequent hashed values of the plurality of second messages; and

applying, at the processor of the verifier, the plurality of subsequent hashed values of the plurality of second messages and the plurality of updated private keys to the cryptographic function.

11. The method of claim 7 , wherein the plurality of updated private keys are generated using a one-way key update function.

12. The method of claim 1 , wherein the cryptographic function includes a hashing function of a pseudorandom function with the initial hashed value of the first message and the initial private key.

13. The method of claim 1 , wherein the evaluated value is generated using an evaluation function of a fully homomorphic encryption scheme,

wherein the evaluation function evaluates the cryptographic function with inputs of the initial encrypted key, and the initial hashed value of the first message, and

wherein an output of the evaluation function includes the evaluated value.

14. The method of claim 1 , wherein the verification result indicates that the first message is verified when the hashed value of the initial signature is equal to the evaluated value.

15. The method of claim 1 , further comprising:

calculating, at the processor of the verifier, a plurality of subsequent hashed values of a plurality of second messages, wherein a plurality of subsequent signatures is obtained based on a plurality of subsequent hashed values of a plurality of second messages and a plurality of updated private keys,

wherein the cryptographic function is further based on the plurality of subsequent hashed values of the plurality of second messages and the plurality of updated private keys,

wherein the evaluated value is generated further based on the plurality of subsequent hashed values of the plurality of second messages,

wherein the verification result is based on a hashed value of a cumulative signature and the evaluated value,

wherein the cumulative signature is obtained based on the initial signature, the plurality of subsequent signatures, the initial private key, and the plurality of updated private keys.

16. A method for publicly verifiable symmetric cryptography, the method comprising:

generating, at a processor of a generator, a master key based on a security parameter;

generating, at the processor of the generator, a homomorphic private key and a homomorphic public key based on the security parameter;

generating, at the processor of the generator, an encrypted key based on the homomorphic public key and the master key;

generating, at the processor of the generator, a plurality of logger keys for a plurality of signers based on a plurality of corresponding logger identifications and the master key;

obtaining, from a processor of a first signer of the plurality of signers, a logger key of the plurality of logger keys corresponding to the first signer;

obtaining, at a processor of a verifier, the encrypted key and the homomorphic public key;

obtaining, at the processor of the verifier from the first signer, a message and a signature corresponding to the first signer, the signature being based on the logger key and a hashed value of the message;

calculating, at the processor of the verifier, the logger key based on the master key and a logger identification corresponding to the logger key;

calculating, at the processor of the verifier, the hashed value of the message corresponding to the first signer;

setting, at the processor of the verifier, a hash function of the hashed value and the logger key;

generating, at the processor of the verifier, an evaluated value based on the hash function, the homomorphic public key, the encrypted key, and the hashed value of the message; and

transmitting, at the processor of the verifier, a verification result based on the evaluated value and a hashed value of the signature corresponding to the first signer.

17. The method of claim 16 , wherein the encrypted key is generated by encrypting the master key based on the homomorphic public key.

18. A method for publicly verifiable symmetric cryptography operable at a processor of a verifier, the method comprising:

obtaining an initial encrypted key and a homomorphic public key;

obtaining a first message and an initial signature;

calculating an initial hashed value of the first message;

setting a cryptographic function of the initial hashed value of the first message and an initial private key;

generating an evaluated value based on the cryptographic function, the homomorphic public key, the initial encrypted key, and the initial hashed value of the first message; and

transmitting a verification result based on a hashed value of the initial signature and the evaluated value.

19. The method of claim 18 , further comprising:

obtaining a plurality of second messages;

calculating a plurality of subsequent hashed values of the plurality of second messages; and

applying the plurality of subsequent hashed values of the plurality of second messages and a plurality of updated private keys to the cryptographic function.

20. The method of claim 18 , wherein the cryptographic function includes a hashing function of a pseudorandom function with the initial hashed value of the first message and the initial private key.

21. The method of claim 18 , wherein the evaluated value is generated using an evaluation function of a fully homomorphic encryption scheme,

wherein the evaluation function evaluates the cryptographic function with inputs of the initial encrypted key, and the initial hashed value of the first message, and

wherein an output of the evaluation function includes the evaluated value.

22. The method of claim 18 , wherein the verification result indicates that the first message is verified when the hashed value of the initial signature is equal to the evaluated value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: YAVUZ, ATTILA ALTAY
To: UNIVERSITY OF SOUTH FLORIDA
Reel/Frame 063313/0486 →
Continuity (2)
Provisional Application 63316024 · Mar 3, 2022
Related Publication 20230283481A1 · Sep 7, 2023
References Cited (39)
US 10587416B1 · Yavuz · 2020 [cited by applicant]
US 10630478B1 · Yavuz · 2020 [cited by examiner]
US 11184157B1 · Gueron · 2021 [cited by examiner]
US 11689366B2 · Monica · 2023 [cited by examiner]
US 20220377055A1 · Liu · 2022 [cited by examiner]
US 20230188366A1 · Steinmetz · 2023 [cited by examiner]
Agrawal, S., Mohassel, P., Mukherjee, P., & Rindal, P. (Oct. 2018). DiSE: distributed symmetric-key encryption. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (pp. 1-56). [cited by applicant]
Agrawal, S., & Boneh, D. (2009). Homomorphic MACs: MAC-based integrity for network coding. In Applied Cryptography and Network Security: 7th International Conference, ACNS 2009, Paris-Rocquencourt, France, Jun. 2-5, 200… [cited by applicant]
Behnia, R., Yavuz, A. A., Ozmen, M. O., & Yuen, T. H. (2020). Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT. In Information Security: 23rd International Conference, ISC 2020, Bali, In… [cited by applicant]
Bernstein, D., et al. (2015). SPHINCS: practical stateless hash-based signatures. In Annual international conference on the theory and applications of cryptographic techniques (pp. 1-22). [cited by applicant]
Buchmann, Johannes, et al. (2013)“On the security of the Winternitz one-time signature scheme.” International Journal of Applied Cryptography 3.1: (pp. 1-17). [cited by applicant]
Buchmann, J., Dahmen, E., & Hülsing, A. (2011). XMSS—a practical forward secure signature scheme based on minimal security assumptions. In Post-Quantum Cryptography: 4th International Workshop, PQCrypto 2011, Taipei, Ta… [cited by applicant]
Cronin, E., Jamin, S., Malkin, T., & McDaniel, P. (2003). On the performance, feasibility, and use of forward-secure signatures. In Proceedings of the 10th ACM conference on Computer and communications security (pp. 1-1… [cited by applicant]
Crosby, S. A., & Wallach, D. S. (Aug. 2009). Efficient data structures for tamper-evident logging. In USENIX security symposium (pp. 317-334). [cited by applicant]
Delgado-Mohatar, O., Sierra, J. M., Brankovic, L., & Fuster-Sabater, A. (2010). An energy-efficient symmetric cryptography based authentication scheme for wireless sensor networks. In Information Security Theory and Pra… [cited by applicant]
Ghosh, S., & Sarkar, P. (2021). Variants of Wegman-Carter message authentication code supporting variable tag lengths. Designs, Codes and Cryptography, 89, 709-736. [cited by applicant]
Itkis, G., & Reyzin, L. (2001). Forward-secure signatures with optimal signing and verifying. In Advances in Cryptology—CRYPTO 2001: 21st Annual International Cryptology Conference, Santa Barbara, California, USA, Aug. … [cited by applicant]
Johnson, D., Menezes, A., & Vanstone, S. (2001. The elliptic curve digital signature algorithm. Department of Combinatorics and Optimization, University of Waterloo, Canada. pp. 36-63. (DOI) 10.1007/s102070100002. [cited by applicant]
Kampanakis, P., & Yavuz, A. A. (2015). BAFi: a practical cryptographic secure audit logging scheme for digital forensics. Security and Communication Networks, 8(17), 3180-3190. [cited by applicant]
Katz, J., & Lindell, A. Y. (2008). Aggregate message authentication codes. In Cryptographers' Track at the RSA Conference (pp. 155-169). Berlin, Heidelberg: Springer Berlin Heidelberg. [cited by applicant]
Ma, D. (2008). Practical forward secure sequential aggregate signatures. In Proceedings of the 2008 ACM symposium on Information, computer and communications security (pp. 1-10). [cited by applicant]
Ma, D. and Tsudik, G. (2009). A new approach to secure logging. ACM Trans. Stor., 5, 1, Article 2 (Mar. 2009), 21 pages. DOI = 10.1145/1502777.1502779 http://doi.acm.org/10.1145/1502777.1502779. [cited by applicant]
Ma, D., & Tsudik, G. (2007). Forward-secure sequential aggregate authentication. In 2007 IEEE Symposium on Security and Privacy (SP'07) (pp. 1-10). IEEE. [cited by applicant]
Malkin, T., Micciancio, D., & Miner, S. (2002). Efficient generic forward-secure signatures with an unbounded number of time periods. Department of Computer Science and Engineering, University of California, San Diego. … [cited by applicant]
Marson, G. A., & Poettering, B. (2013). Practical secure logging: Seekable sequential key generators. In Computer Security-ESORICS 2013: 18th European Symposium on Research in Computer Security, Egham, UK, Sep. 9-13, 20… [cited by applicant]
Marson, G. A., & Poettering, B. (2014). Even more practical secure logging: Tree-based seekable sequential key generators. In Computer Security-ESORICS 2014: 19th European Symposium on Research in Computer Security, Wro… [cited by applicant]
Mu, Y., Susilo, W., & Zhu, H. (Mar. 2007). Compact sequential aggregate signatures. In Proceedings of the 2007 ACM symposium on Applied computing (pp. 249-253). [cited by applicant]
Ozmen, M. O., Yavuz, A. A., & Behnia, R. (Jun. 2019). Energy-aware digital signatures for embedded medical devices. In 2019 IEEE Conference on Communications and Network Security (CNS) (pp. 55-63). IEEE. [cited by applicant]
Seyitoglu, E. U., Yavuz, A. A., & Ozmen, M. O. (Jun. 2020). Compact and resilient cryptographic tools for digital forensics. In 2020 IEEE Conference on Communications and Network Security (CNS) (pp. 1-9). IEEE. [cited by applicant]
Shamir, A., & Tauman, Y. (2001). Improved online/offline signature schemes. In Advances in Cryptology—CRYPTO 2001: 21st Annual International Cryptology Conference, Santa Barbara, California, USA, Aug. 19-23, 2001 Procee… [cited by applicant]
Shamir, A. (1985). Identity-based cryptosystems and signature schemes. In Advances in Cryptology: Proceedings of CRYPTO 84 4 (pp. 47-53). Springer Berlin Heidelberg. [cited by applicant]
Shoup, V. (2001). A proposal for an ISO standard for public key encryption. Cryptology ePrint Archive (pp. 1-63). [cited by applicant]
Ma, D., & Tsudik, G. (2008). A new approach to secure logging. In Data and Applications Security XXII: 22nd Annual IFIP WG 11.3 Working Conference on Data and Applications Security London, UK, Jul. 13-16, 2008 Proceedin… [cited by applicant]
Yavuz, A. A. (Apr. 2013). Eta: efficient and tiny and authentication for heterogeneous wireless systems. In Proceedings of the sixth ACM conference on Security and privacy in wireless and mobile networks (pp. 67-72). [cited by applicant]
Yavuz, A. A., & Ning, P. (2009). BAF: An efficient publicly verifiable secure audit logging scheme for distributed systems. In 2009 Annual Computer Security Applications Conference (pp. 1-10). IEEE. [cited by applicant]
Yavuz, A. A., & Ning, P. (2009). Hash-based sequential aggregate and forward secure signature for unattended wireless sensor networks. In 2009 6th Annual International Mobile and Ubiquitous Systems Networking & Services… [cited by applicant]
Yavuz, A. A., & Ning, P. (2012). Self-sustaining, efficient and forward-secure cryptographic constructions for unattended wireless sensor networks. Ad Hoc Networks, 10(7), 1204-1220. [cited by applicant]
Yavuz, A. A., Ning, P., & Reiter, M. K. (2012). BAF and FI-BAF: Efficient and publicly verifiable cryptographic schemes for secure logging in resource-constrained systems. ACM Transactions on Information and System Secu… [cited by applicant]
Yavuz, A. A., Ning, P., & Reiter, M. K. (2012). Efficient, compromise resilient and append-only cryptographic schemes for secure audit logging. In Financial Cryptography and Data Security 16th International Conference, … [cited by applicant]