IP Library Granted Patent US 12,381,736
Granted Patent B2
US 12,381,736 · App. 18/553,346 · Granted Aug 5, 2025

Cipher system, encryption apparatus, decryption apparatus, method, and program

Inventor: Keita Kusagawa (Tokyo, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L9/3242H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,736
App. No.
18/553,346
Granted
Aug 5, 2025
Kind
B2
Abstract

A cipher system that performs encryption and decryption by a public key encryption scheme including schemes of tag-based encryption, weak commitment, and message authentication code, is configured to, using a security parameter, generate an encryption key, a decryption key, and a common parameter, and use the encryption key and the common parameter as an encryption key and the decryption key as a decryption key of the public key encryption scheme; generate a random number, a commitment, and a decommitment, generate a ciphertext using a plaintext to be encrypted, generate a tag, and use the commitment, the ciphertext, and the tag as a ciphertext of the public key encryption scheme; and parse the ciphertext into the commitment, the ciphertext, and the tag, generate a plaintext and a decommitment, verify whether committing to a random number value has succeeded, and verify the tag in a case where the committing has succeeded.

Claims (13)

1. A cipher system that performs encryption and decryption, the cipher system comprising:

a public key encryption scheme comprising a tag-based encryption (TBE) scheme comprising algorithms GenTBE, EncTBE, and DecTBE; a weak commitment scheme (wCom) comprising the following algorithms Init, S, and R; and a message authentication code scheme (MAC) comprising algorithms T and V; and

one or more information processing devices each including a memory and a processor configured to:

using a security parameter as κ, generate an encryption key ekTBE and a decryption key dkTBE by a key generation algorithm GenTBE(I), generate a common parameter pub by an initialization algorithm Init (1κ), and use the encryption key ekTBE and the common parameter pub as an encryption key ek of the public key encryption scheme and the decryption key dkTBE as a decryption key dk of the public key encryption scheme;

generate a random number r, a commitment com, and a decommitment dec by a sender algorithm S (1κ, pub), generate a ciphertext c by an encryption algorithm EncTBE (ekTBE, com, (m, dec)) using a plaintext to be encrypted as m, generate a tag σ by a MAC generation algorithm T (r, c), and use the commitment com, the ciphertext c, and the tag σ as a ciphertext ct of the public key encryption scheme; and

parse the ciphertext ct into the commitment com, the ciphertext c, and the tag σ, generate a plaintext m and a decommitment dec by a decryption algorithm DecTBE (dkTBE, com, c), verify whether committing to a random number value r has succeeded by a receiver algorithm R (pub, com, dec), and verify the tag σ by a verification algorithm V (r, c, a) in a case where the committing has succeeded.

2. The cipher system according to claim 1 , wherein, in a case where the tag-based encryption scheme TBE is indistinguishability from random bits under selective-tag and weak chosen-ciphertext attack (INDr-st-wCCA) secure, the weak commitment scheme wCom is secure and indistinguishability from random bits (INDr) secure, and the message authentication code scheme MAC is strong existential unforgeability against one-time chosen-message attack (sEUF-OT-CMA) secure and pseudo-random, the public key encryption scheme is indistinguishability from random bits under chosen-ciphertext attack (INDr-CCA) secure, and

in a case where the tag-based encryption scheme TBE is oblivious sampleability under selective-tag and weak chosen-ciphertext attack (OS-st-wCCA) secure, the weak commitment scheme wCom is secure and oblivious sampleability (OS) secure, and the message authentication code scheme MAC is sEUF-OT-CMA secure and OS secure, the public key encryption scheme is oblivious sampleability under chosen ciphertext attack (OS-CCA) secure.

3. A non-transitory computer-readable recording medium having computer -readable instructions stored thereon, which, when executed, cause a computer including a memory and processor to

perform encryption and encryption by a public key encryption scheme comprising a tag-based encryption (TBE) scheme comprising algorithms GenTBE, EncTBE, and DecTBE; a weak commitment scheme (wCom) comprising the following algorithms Init, S, and R; and a message authentication code scheme (MAC) comprising algorithms T and V; wherein the encryption and decryption includes:

using a security parameter as κ, to generate an encryption key ekTBE and a decryption key dkTBE by a key generation algorithm GenTBE (I), generating a common parameter pub by an initialization algorithm Init (1κ), and using the encryption key ekTBE and the common parameter pub as an encryption key ek of the public key encryption scheme and the decryption key dkTBE as a decryption key dk of the public key encryption scheme;

generating a random number r, a commitment com, and a decommitment dec by a sender algorithm S (1κ, pub), generating a ciphertext c by an encryption algorithm EncTBE (ekTBE, com, (m, dec)) using a plaintext to be encrypted as m, generating a tag σ by a MAC generation algorithm T (r, c), and using the commitment com, the ciphertext c, and the tag σ as a ciphertext ct of the public key encryption scheme; and

parsing the ciphertext ct into the commitment com, the ciphertext c, and the tag σ, generating a plaintext m and a decommitment dec by a decryption algorithm DecTBE (dkTBE, com, c), verifying whether committing to a random number value r has succeeded by a receiver algorithm R (pub, com, dec), and verifying the tag σ by a verification algorithm V (r, c, a) in a case where the committing has succeeded.

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072473/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2023
From: KUSAGAWA, KEITA
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065074/0479 →
Continuity (1)
Related Publication 20240187246A1 · Jun 6, 2024
References Cited (11)
US 8108678B1 · Boyen · 2012 [cited by examiner]
US 20140321642A1 · El Aimani · 2014 [cited by examiner]
US 20150067340A1 · Joye · 2015 [cited by examiner]
US 20160105287A1 · Joye · 2016 [cited by examiner]
US 20220200789A1 · Lalande · 2022 [cited by examiner]
US 20220382521A1 · Krcmaricic-Barackov · 2022 [cited by examiner]
Dan Boneh, Ran Canetti, Shai Halevi, and Jonathan Katz. Chosen-ciphertext security from identity-based encryption. SIAM J. Comput., 36(5):1301-1328, 2007. [cited by applicant]
Ran Canetti and Marc Fischlin. Universally composable commitments. In Joe Kilian, editor, CRYPTO 2001, vol. 2139 of LNCS, pp. 19-40. Springer, Heidelberg, Aug. 2001. [cited by applicant]
Charles Rackoff and Daniel R. Simon. Non-Interactive zero-knowledge proof of knowledge and chosen ciphertext attack. In Joan Feigenbaum, editor, CRYPTO'91, vol. 576 of LNCS, pp. 433-444. Springer, Heidelberg, Aug. 1992. [cited by applicant]
Mihir Bellare, Anand Desai, David Pointcheval, and Phillip Rogaway. Relations among notions of security for public- key encryption schemes. In Hugo Krawczyk, editor, CRYPTO'98, vol. 1462 of LNCS, pp. 26-45. Springer, He… [cited by applicant]
Eike Kiltz. Chosen-ciphertext security from tag-based encryption. In Shai Halevi and Tal Rabin, editors, TCC 2006, vol. 3876 of LNCS, pp. 581-600. Springer, Heidelberg, Mar. 2006. [cited by applicant]