IP Library › Granted Patent US 9,071,442
Granted Patent B2
US 9,071,442 · App. 13/585,685 · Granted Jun 30, 2015

Signcryption method and device and corresponding signcryption verification method and device

Inventor: Laila El Aimani (Rennes, FR)
Assignee: THOMSON LICENSING
H04L9/3247H04L9/30H04L2209/60H04L2209/72H04L9/008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,071,442
App. No.
13/585,685
Granted
Jun 30, 2015
Kind
B2
Abstract

A signcryption is generated by a sender by using a first encryption algorithm to encrypt plaintext m with public key Epk to get ciphertext e, e=E.Encrypt(m); generating a key k and its encapsulation c using an encapsulation algorithm and public key Kpk, k,c=KD.Encapsulate( ); sign (e,c) using Ssk, s=S.sign(e,c); encrypt the signature s using a second encryption algorithm and the key k, e_d=D.Encrypt(s). The signcryption of m is formed by (e,c,e_d). The sender may also prove knowledge of the decryption of e, and that e_d encrypts a valid signature on the concatenation of c and e using the key of the encapsulation. Also provided are the corresponding signcryption verification device and method, and computer program products.

Claims (32)

1. A method of signcrypting a plaintext m by a device, the method comprising, at the device:

encrypting the plaintext m with a first encryption algorithm and a first public key Epk of a receiver to obtain a first ciphertext e;

using a random r, an encapsulation algorithm and a second public key Kpk of the receiver to generate a session key k and an encapsulation c of the session key k;

generating a signature s on the first ciphertext e and the encapsulation c with a signature algorithm using a private signature key Ssk of a sender;

encrypting the signature s with a second encryption algorithm using the session key k to obtain a second ciphertext e_d;

forming a signcryption using a processor from the first ciphertext e, the encapsulation c and the second ciphertext e_d; and

outputting the signcryption.

2. The method of claim 1 , further comprising proving knowledge of the decryption of the first ciphertext e and that the second ciphertext e_d encrypts a valid signature s on the encapsulation c and the first ciphertext e using the key of the encapsulation c.

3. A method of unsigncrypting a received signcryption of a plaintext m by a device, the signcryption comprising a first ciphertext e, an encapsulation c and a second ciphertext e_d, the method comprising at the device:

decrypting, using a processor, the first ciphertext e using a first decryption algorithm and a first private key Esk of a receiver of the signcryption corresponding to a first public key Epk of the receiver that was used to encrypt the first ciphertext e;

retrieving a session key k by decapsulating the encapsulation c using a decapsulation algorithm and a second private key Ksk of the receiver corresponding to a second public key Kpk of the receiver used to encapsulate the session key k;

recovering a signature s by decrypting the second ciphertext e_d using a second decryption algorithm and the session key k; and

verifying that the signature s is correct using a verification algorithm and a public signature key Spk of a sender of the signcryption that corresponds to a private signature key Ssk of the sender used to generate the signature.

4. The method of claim 3 , further comprising proving knowledge of the equality or inequality of the decryption of the plaintext m and the first ciphertext e, the decryption of the second ciphertext e_d and that the decryption is a valid digital signature on the first ciphertext e and the encapsulation c.

5. A signcryption device for signcrypting a plaintext m, the signcryption device comprising:

a processor configured to:

encrypt the plaintext m with a first encryption algorithm and a first public key Epk of a receiver to obtain a first ciphertext e;

use a random r, an encapsulation algorithm and a second public key Kpk of the receiver to generate a session key k and an encapsulation c of the session key k;

generate a signature s on the first ciphertext e and the encapsulation c with a signature algorithm using a private signature key Ssk of a sender;

encrypt the signature s with a second encryption algorithm using the session key k to obtain a second ciphertext e_d; and

form a signcryption from the first ciphertext e, the encapsulation c and the second ciphertext e_d; and

an interface configured to output the signcryption.

6. The signcryption device of claim 5 , wherein the processor is further configured to prove knowledge of the decryption of the first ciphertext e and that the second ciphertext e_d encrypts a valid signature s on the encapsulation c and the first ciphertext e using the key of the encapsulation c.

7. A signcryption verification device for unsigncrypting a received signcryption of a plaintext m, the signcryption comprising a first ciphertext e, an encapsulation c and a second ciphertext e_d, the signcryption verification device comprising:

a processor configured to:

decrypt the first ciphertext e using a first decryption algorithm and a first private key Esk of a receiver of the signcryption corresponding to a first public key Epk of the receiver that was used to encrypt the first ciphertext e;

retrieve a session key k by decapsulating the encapsulation c using a decapsulation algorithm and a second private key Ksk of the receiver corresponding to a second public key Kpk of the receiver used to encapsulate the session key k;

recover a signature s by decrypting the second ciphertext e_d using a second decryption algorithm and the session key k; and

verify that the signature s is correct using a verification algorithm and a public signature key Spk of a sender of the signcryption that corresponds to a private signature key Ssk of the sender used to generate the signature.

8. The signcryption verification device of claim 7 , wherein the processor is further configured to prove knowledge of the equality or inequality of the decryption of the plaintext m and the first ciphertext e, and whether or not the signature s is a valid digital signature on the first ciphertext e and the encapsulation c.

9. A non-transitory computer program product having stored thereon instructions that, when executed by a processor, perform the method of claim 1 .

10. A non-transitory computer program product having stored thereon instructions that, when executed by a processor, perform the method of claim 3 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2012
From: EL AIMANI, LAILA
To: THOMSON LICENSING
Reel/Frame 028787/0523 →
Priority Claims (1)
EP 11306076 · Aug 29, 2011 · regional
Continuity (1)
Related Publication 20130051551A1 · Feb 28, 2013