IP Library Granted Patent US 8,689,087
Granted Patent B2
US 8,689,087 · App. 12/810,187 · Granted Apr 1, 2014

Method and entity for probabilistic symmetrical encryption

Inventors: Yannick Seurin (Saulx les Chartreux, FR); Henri Gilbert (Bures sur Yvette, FR)
Assignee: Orange
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,689,087
App. No.
12/810,187
Granted
Apr 1, 2014
Kind
B2
Abstract

The invention relates to a method of probabilistic symmetric encryption of a plaintext message element with the aid of a secret key that can be represented in the form of a matrix. It comprises an operation of encrypting the plaintext message element, with the aid of the matrix parametrized by a random vector, so as to obtain an encrypted message element coupled to the random vector. Furthermore, there is envisaged a step of encoding the plaintext message element as a code word with the aid of an error correcting code having a given correction capacity and a step of adding a noise vector. The error correcting code and the noise vector are adapted so that the Hamming weight of the noise vector is less than or equal to the correction capacity of the correcting code.

Claims (26)

1. A method of encryption, comprising:

probabilistic symmetric encryption of a plaintext message element with the aid of a secret key that can be represented in the form of a matrix of dimension (k, n) with k>1 and n >1, and further comprising the following steps:

a step of encoding the plaintext message element as a code word with the aid of an error correcting code having a given correction capacity;

a step of encrypting the code word, during which the result of a product of the secret matrix and of a random vector of dimension k is added to the code word,

a computation step during which a noise vector is added to the encrypted code word so as to obtain an encrypted message element coupled to the random vector,

the error correcting code and the noise vector being adapted so that the Hamming weight of the noise vector is less than or equal to the correction capacity of the correcting code.

2. The method as claimed in claim 1 , wherein the noise vector is generated with the aid of a noise source parametrized in such a way that the probability of the Hamming weight of the noise vector being greater than the correction capacity is less than a predefined threshold.

3. The method as claimed in claim 1 , wherein there is provided a test step for verifying whether the Hamming weight of the noise vector generated is less than or equal to the correction capacity and, if the test is negative, a new noise vector is generated.

4. The method as claimed in claim 1 , wherein, t representing the correction capacity of the error correcting code, η the probability of a bit of the noise vector being equal to 1 and n the length of the error correcting code, said parameters t, η and n are adapted to satisfy the condition t>η·n.

5. The method as claimed in claim 1 , wherein said matrix is a Toeplitz matrix.

6. A method for decrypting an encrypted message element, wherein:

the encrypted message element has been determined by application to a plaintext message element of the encryption method as claimed in claim 1 ;

the method further comprising:

using a secret key that can be represented in the form of a matrix of dimension (k, n) with k>1 and n>1, in which method of decryption, a pair composed of the encrypted message element and of a random vector of dimension k used to encrypt said message element being provided, there is envisaged

a computation phase comprising a step of computing a product of the random vector received and of the matrix and a step of adding a result of said product to the encrypted message element received, and then

a decoding phase during which a decoding of a result of the computation phase is operated with the aid of the error correcting code used during the encryption, so as to obtain the plaintext message element.

7. A non-transitory computer program product, comprising a computer usable medium having a computer readable program code embodied therein, said computer readable program code adapted to be executed to implement the method of claim 6 , when this program is executed by a processor.

8. A non-transitory computer program product, comprising a computer usable medium having a computer readable program code embodied therein, said computer readable program code adapted to be executed to implement the method of claim 1 , when this program is executed by a processor.

9. An entity for encryption, wherein:

said entity is operative for probabilistic symmetric encryption with the aid of a secret key that can be represented in the form of a matrix of dimension (k, n) with k>1 and n>1, and comprises

means for encoding a plaintext message element as a code word with the aid of an error correcting code having a given correction capacity,

means for encrypting the code word designed to add to the code word the result of a product of said matrix and of a random vector of dimension k,

computation means adapted for adding a noise vector to the encrypted code word so as to obtain an encrypted message element coupled to the random vector,

the error correcting code and the noise vector being adapted so that the Hamming weight of the noise vector is less than or equal to the correction capacity of the correcting code.

10. An item of communication equipment integrating the encryption entity defined in claim 9 .

11. An encryption and decryption system comprising a probabilistic symmetric encryption entity as claimed in claim 9 and a corresponding decryption entity, the two entities sharing a secret key that can be represented by a matrix of dimension (k, n) with k>1 and n>1 and the encryption entity providing the decryption entity with a pair composed of an encrypted message element and of a random vector of dimension k used to determine said encrypted message element, in which system the decryption entity comprises computation means adapted for computing a product of the random vector received and said matrix and for adding the result of said product to the encrypted message element received, and decoding means designed to decode the result of the computations performed by the computation means, with the aid of the error correcting code used for the determination of the encrypted message element, so as to obtain a plaintext message element.

Assignments (2)
CHANGE OF NAME Recorded Feb 11, 2014
From: FRANCE TELECOM
To: ORANGE
Reel/Frame 032190/0891 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2010
From: SEURIN, YANNICK; GILBERT, HENRI
To: FRANCE TELECOM
Reel/Frame 024665/0441 →
Priority Claims (1)
FR 08 50168 · Jan 11, 2008 · national
Continuity (1)
Related Publication 20100281336A1 · Nov 4, 2010