IP Library › Granted Patent US 12,273,464
Granted Patent B2
US 12,273,464 · App. 18/541,533 · Granted Apr 8, 2025

Providing a cryptographic information

Inventor: Thomas Poeppelmann (Munich, DE)
Assignee: Infineon Technologies AG
H04L9/3247H04L9/0894H04L9/3093H04L9/3218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,464
App. No.
18/541,533
Granted
Apr 8, 2025
Kind
B2
Abstract

Cryptographic information is compiled by: (a) determining a first portion of the cryptographic information based on an input and a randomness: (b) checking a rejection criterion based on the first portion; (b1) re-starting step (a) with a different randomness if the rejection criterion is fulfilled; (b2) if not all portions of the cryptographic information have been generated, determining a subsequent portion of the cryptographic information based on the input and the randomness and continuing with step (b) or, otherwise, continuing with step (c); (c) determining the first portion of the cryptographic information based on the input and the randomness; (d) conveying the respective portion of the cryptographic information; and (e) if not all portions of the cryptographic information have been generated, determining a subsequent portion of the cryptographic information based on the input and the randomness and continuing with step (d).

Claims (61)

1. A method for compiling a cryptographic information, comprising:

(a) determining a first portion of the cryptographic info nation based on are input, and a randomness;

(b) checking whether a rejection criterion based on the first portion of the cryptographic information is fulfilled; and

(c) re-starting step (a) with a new randomness in the event the rejection criterion is fulfilled with respect to the first portion of the cryptographic information; and,

(d) for each of any subsequent portion of the cryptographic information not yet determined,

(d1) determining a subsequent portion of the cryptographic; information based on the input and the most recently used randomness,

(d2) checking whether the rejection criterion is fulfilled based on the subsequent portion of the cryptographic information, and

(d3) re-starting step (a) with a new randomness in the event the rejection criterion is fulfilled with respect to the respective subsequent portion of the cryptographic information; and

(e) responsive to the first portion and each subsequent portion being determined without any respective events of fulfillment of the rejection criterion:

(e1) determining the first portion of the cryptographic information again, based on the input and the most recently used randomness and conveying the determined first portion of the cryptographic information; and

(e2) determining each subsequent portion of the cryptographic information again, based on the input and the randomness, and conveying each determined subsequent portion.

2. The method of claim 1 , wherein the method comprises not storing more than one portion of the cryptographic information at one time when processing the loop determined by steps (a) to (d).

3. The method of claim 1 , wherein the method comprises not storing more than one determined portion of the cryptographic information at one time when performing steps (e1) and (e2).

4. The method of claim 1 , wherein said determining the first portion each subsequent portion of the cryptographic information again and conveying the determined first portion and each determined subsequent portion comprises, for each portion determined again, conveying the portion determined again before determining any further portion again.

5. The method of claim 1 , further comprising:

for each portion of the cryptographic information determined by the loop of steps (a) to (d), generating and storing a first hash value that is associated with the respective portion of the cryptographic information;

within step (e), generating a second hash value for each portion of the cryptographic information and comparing the second hash value with the first hash value that is associated with the same portion of the cryptographic information; and

conveying the respective portion only if the first hash value corresponds to the second hash value.

6. The method of claim 5 , wherein in the event that the first hash value does not correspond to the second hash value, the method further comprises triggering at least one of any one or more of the following actions:

issuing a notification or an alarm;

stopping the method;

entering an exception handling;

re-starting step (a) with a different randomness.

7. The method of claim 1 , wherein the cryptographic information is or comprises at least one of any one or more of the following:

a signature;

a pairing information;

an information associated with a zero-knowledge-proof.

8. The method of claim 1 , wherein the method further comprises:

encrypting each portion of the cryptographic information with a secret key, prior to conveying the respective portion; and

conveying the secret key.

9. The method of claim 8 , wherein the secret key is conveyed after the last encrypted portion of the cryptographic information has been conveyed.

10. The method of claim 1 , wherein the input is a message.

11. The method of claim 1 , wherein the cryptographic information is compiled based on the portions of the cryptographic information conveyed.

12. The method of claim 11 , comprising conducting an authentication based on the cryptographic information.

13. The method of claim 1 , wherein processing the cryptographic information or a portion of the cryptographic information utilizes at least one cryptographic Lattice operation.

14. The method of claim 1 , wherein used on a security device or for operating a security device, wherein such security device comprises at least one of any one or more of the following:

an integrated circuit,

a hardware security module,

a trusted platform module,

a crypto unit,

a FPGA,

a processing unit,

a controller,

a smartcard.

15. A security device for compiling a cryptographic information, the security device comprising digital hardware and interface circuitry configured to:

(a) determine a first portion of the cryptographic information based on an input and a randomness;

(b) check whether a rejection criterion based on the first portion of the cryptographic information is fulfilled; and

(c) re-start step (a) with a new randomness in the event the rejection criterion is fulfilled with respect to the first portion of the cryptographic information; and,

(d) for each of any subsequent portion of the cryptographic information not yet determined,

(d1) determine a subsequent portion of the cryptographic information based on the input and the most recently used randomness,

(d2) check whether the rejection criterion is fulfilled based on the subsequent portion of the cryptographic information, and

(d3) re-start step (a) with a new randomness in the event the rejection criterion is fulfilled with respect to the respective subsequent portion the cryptographic inform ration; and

(e) responsive to the first portion and each subsequent portion being determined without any respective events of fulfillment of the rejection criterion:

(e1) determine the first portion of the cryptographic information again, based on the input and the most recently used randomness, and conveying the determined first portion of the cryptographic information; and

(e2) determine each subsequent portion of the cryptographic information again, based on the input and the randomness, and conveying each determined subsequent portion.

16. The security device of claim 15 , wherein the digital hardware is configured to not store more than one portion of the cryptographic information at one time when performing steps (e1) and (e2).

17. The security device of claim 15 , wherein the digital hardware and interface circuitry are configured to determine the first portion and each subsequent portion of the cryptographic information again and convey the determined first portion and each determined subsequent portion such that each portion determined again is conveyed before any further portion is determined again.

18. A consumable comprising the security device of claim 15 .

19. A system comprising a security device according to claim 15 and a host, wherein the security device is arranged to convey the respective portion of the cryptographic information to the host.

20. The system of claim 17 , wherein the host is arranged to authenticate the security device based on the portions of the cryptographic information received.

21. A non-transitory computer-readable medium comprising, stored thereupon, a computer program product directly loadable into a memory of a digital processing device, the computer program product comprising software code portions for performing the steps of the method of claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2023
From: POEPPELMANN, THOMAS
To: INFINEON TECHNOLOGIES AG
Reel/Frame 065884/0747 →
Priority Claims (1)
DE 102020119569.9 · Jul 24, 2020 · national
Continuity (2)
Continuation 17380634 · Jul 20, 2021
Related Publication 20240137225A1 · Apr 25, 2024
References Cited (21)
US 11615060B2 · Alimi et al. · 2023 [cited by applicant]
US 20110016325A1 · Futa et al. · 2011 [cited by applicant]
US 20140298038A1 · Gauravaram · 2014 [cited by examiner]
US 20180091309A1 · Misoczki · 2018 [cited by examiner]
DE 102018127126A1 · 2019 [cited by applicant]
DE 102019131745A1 · 2020 [cited by applicant]
EP 2030364B1 · 2015 [cited by applicant]
EP 3542336B1 · 2021 [cited by applicant]
Evaluation Criteria for True (Physical) Random Number Generators Used in Cryptographic Applications, by Killmann et al., published 2003. (Year: 2003). [cited by examiner]
Alkim, Erdem , et al., “NewHope”, Version 1.02, 2017, 1-46. [cited by applicant]
Alkim, Erdem , et al., “NewHope without reconciliation”, IACR Cryptology ePrint Archive 2016: 1157 (2016), 2016, 1-9. [cited by applicant]
Alkim, Erdem , et al., “Post-quantum Key Exchange—A New Hope”, IACR Cryptology ePrint Archive 2015: 1092, 2015, 1-18. [cited by applicant]
Chen, Junhua, et al., “A Zero-Knowledge Identity Verification Protocol Using Blind Watermark”, International Conference on Computer Engineering and Technology, 2009, 496-498. [cited by applicant]
Guneysu, Tim , et al., “Practical Lattice-Based Cryptography: A Signature Scheme for Embedded Systems”, Horst Görtz Institute for IT-Security, Ruhr-University Bochum, Germany, CHES 2012, LNCS 7428, 2012, 1-61. [cited by applicant]
Harikrishnan;, M. , et al., “Secure Digital Service Payments using Zero Knowledge Proof in Distributed Network”, 2019 5th International Conference on Advanced Computing & Communication Systems (ICACCS), Mar. 2019, 307-3… [cited by applicant]
Kouicem, Djamel-Eddine , et al., “An Efficient and Anonymous Blockchain-Based Data Sharing Scheme for Vehicular Networks”, 2020 IEEE Symposium on Computers and Communications (ISCC), Jul. 10, 2020, 1-28. [cited by applicant]
Lyubashevsky, Vadim , et al., “On Ideal Lattices and Learning With Errors Over Rings”, Slides presented Eurocrypt 2010, 2010, 1-59. [cited by applicant]
Lyubashevsky, Vadim , “On Ideal Lattices and Learning with Errors Over Rings”, Journal of the ACM, 60(6):43:1-43:35. Preliminary version in Eurocrypt 2010, Jun. 25, 2013, 1-34. [cited by applicant]
Oder, Tobias , et al., “Practical CCA2-Secure and Masked Ring-LWE Implementation”, Horst Görtz Institute for IT Security, Ruhr-Universität Bochum, Germany, Jan. 23, 2018, 1-33. [cited by applicant]
Park, Young-Hoon , et al., “Fast and Secure Group Key Dissemination Scheme for Out-of-Range V2I Communication”, IEEE Transactions on Vehicular Technology (vol. 64, Issue: 12), Dec. 2015, 5642-5652. [cited by applicant]
Schindler, Werner , et al., “Evaluation Criteria for True (Physical) Random Number Generators Used in Cryptographic Applications”, 2003, 431-449. [cited by applicant]