IP Library Granted Patent US 12,640,906
Granted Patent B2
US 12,640,906 · App. 18/814,720 · Granted May 26, 2026

Ciphertext conversion system, ciphertext conversion method, and non-transitory computer readable medium

Inventor: Yutaka Kawai (Tokyo, JP)
Assignee: MITSUBISHI ELECTRIC CORPORATION
H04L9/0618H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,640,906
App. No.
18/814,720
Granted
May 26, 2026
Kind
B2
Abstract

A ciphertext conversion system ( 100 ) includes a conversion key generation device ( 600 ) and a conversion device ( 700 ). The conversion key generation device ( 600 ) performs encryption of a public-key encryption scheme using a public key and a first decryption enabling condition, so as to generate a first converted public-key ciphertext and a key corresponding to the first converted public-key ciphertext, performs encryption of a symmetric-key encryption scheme using a second symmetric-key encryption secret key as a plaintext and the key corresponding to the first converted public-key ciphertext as a secret key, so as to generate a first partial conversion key, and calculates, as a second partial conversion key, an exclusive-OR of a result of performing encryption using a first symmetric-key encryption secret key and first auxiliary information and a result of performing encryption using the second symmetric-key encryption secret key and second auxiliary information. The conversion device ( 700 ) calculates, as at least part of a converted symmetric-key ciphertext, an exclusive-OR of a symmetric-key ciphertext and the second partial conversion key, where the symmetric-key ciphertext is an exclusive-OR of a plaintext and a result of performing encryption using the first symmetric-key encryption secret key and the first auxiliary information.

Claims (41)

1 . A ciphertext conversion system comprising:

a conversion key generation device including

processing circuitry to

perform encryption of a public-key encryption scheme using a public key and a first decryption enabling condition, so as to generate a first converted public-key ciphertext and a key corresponding to the first converted public-key ciphertext,

perform encryption of a symmetric-key encryption scheme using a second symmetric-key encryption secret key as a plaintext and the key corresponding to the first converted public-key ciphertext as a secret key, so as to generate a first partial conversion key, and

calculate, as a second partial conversion key, an exclusive-OR of a value calculated by performing encryption in a counter mode of a block cipher using a first symmetric-key encryption secret key and first auxiliary information and a value calculated by performing encryption in the counter mode of the block cipher using the second symmetric-key encryption secret key and second auxiliary information; and

a conversion device including

processing circuitry to

calculate, as at least part of a converted symmetric-key ciphertext to be used to decrypt a plaintext used in generating a symmetric-key ciphertext, an exclusive-OR of the symmetric-key ciphertext and the second partial conversion key, the symmetric-key ciphertext being an exclusive-OR of the plaintext and a value calculated by performing encryption in the counter mode of the block cipher using the first symmetric-key encryption secret key and the first auxiliary information.

2 . The ciphertext conversion system according to claim 1 ,

wherein the converted symmetric-key ciphertext is composed of at least part of the converted symmetric-key ciphertext and the second auxiliary information.

3 . The ciphertext conversion system according to claim 1 ,

wherein the public-key encryption scheme is an attribute-based encryption scheme.

4 . The ciphertext conversion system according to claim 2 ,

wherein the public-key encryption scheme is an attribute-based encryption scheme.

5 . The ciphertext conversion system according to claim 3 ,

wherein the processing circuitry of the conversion device performs delegation conversion of the attribute-based encryption scheme using the public key, the first converted public-key ciphertext, and a second decryption enabling condition, so as to generate a second converted public-key ciphertext, the second decryption enabling condition being a condition that is more restrictive than the first decryption enabling condition.

6 . The ciphertext conversion system according to claim 4 ,

wherein the processing circuitry of the conversion device performs delegation conversion of the attribute-based encryption scheme using the public key, the first converted public-key ciphertext, and a second decryption enabling condition, so as to generate a second converted public-key ciphertext, the second decryption enabling condition being a condition that is more restrictive than the first decryption enabling condition.

7 . The ciphertext conversion system according to claim 5 , further comprising

a decryption device including

processing circuitry to

perform decryption of attribute-based encryption using a user secret key corresponding to the first decryption enabling condition and the second converted public-key ciphertext, so as to decrypt the key corresponding to the first converted public-key ciphertext,

perform decryption of symmetric-key encryption using the decrypted key corresponding to the first converted public-key ciphertext and the first partial conversion key, so as to decrypt the second symmetric-key encryption secret key, and

calculate, as the plaintext, an exclusive-OR of at least part of the converted symmetric-key ciphertext and a value calculated by performing encryption in the counter mode of the block cipher using the decrypted second symmetric-key encryption secret key and the second auxiliary information.

8 . The ciphertext conversion system according to claim 6 , further comprising

a decryption device including

processing circuitry to

perform decryption of attribute-based encryption using a user secret key corresponding to the first decryption enabling condition and the second converted public-key ciphertext, so as to decrypt the key corresponding to the first converted public-key ciphertext,

perform decryption of symmetric-key encryption using the decrypted key corresponding to the first converted public-key ciphertext and the first partial conversion key, so as to decrypt the second symmetric-key encryption secret key, and

calculate, as the plaintext, an exclusive-OR of at least part of the converted symmetric-key ciphertext and a value calculated by performing encryption in the counter mode of the block cipher using the decrypted second symmetric-key encryption secret key and the second auxiliary information.

9 . A ciphertext conversion method comprising:

performing encryption of a public-key encryption scheme using a public key and a first decryption enabling condition, so as to generate a first converted public-key ciphertext and a key corresponding to the first converted public-key ciphertext, by a conversion key generation device, which is a computer;

performing encryption of a symmetric-key encryption scheme using a second symmetric-key encryption secret key as a plaintext and the key corresponding to the first converted public-key ciphertext as a secret key, so as to generate a first partial conversion key, by the conversion key generation device;

calculating, as a second partial conversion key, an exclusive-OR of a value calculated by performing encryption in a counter mode of a block cipher using a first symmetric-key encryption secret key and first auxiliary information and a value calculated by performing encryption in the counter mode of the block cipher using the second symmetric-key encryption secret key and second auxiliary information, by the conversion key generation device; and

calculating, as at least part of a converted symmetric-key ciphertext to be used to decrypt a plaintext used in generating a symmetric-key ciphertext, an exclusive-OR of the symmetric-key ciphertext and the second partial conversion key, the symmetric-key ciphertext being an exclusive-OR of the plaintext and a value calculated by performing encryption in the counter mode of the block cipher using the first symmetric-key encryption secret key and the first auxiliary information, by a conversion device, which is a computer.

10 . A non-transitory computer readable medium storing a ciphertext conversion program that causes a conversion key generation device, which is a computer, to execute a conversion destination setting process and a key generation process, and causes a conversion device, which is a computer to execute a conversion process,

the conversion destination setting process being a process of performing encryption of a public-key encryption scheme using a public key and a first decryption enabling condition, so as to generate a first converted public-key ciphertext and a key corresponding to the first converted public-key ciphertext,

the key generation process being a process of performing encryption of a symmetric-key encryption scheme using a second symmetric-key encryption secret key as a plaintext and the key corresponding to the first converted public-key ciphertext as a secret key, so as to generate a first partial conversion key, and

calculating, as a second partial conversion key, an exclusive-OR of a value calculated by performing encryption in a counter mode of a block cipher using a first symmetric-key encryption secret key and first auxiliary information and a value calculated by performing encryption in the counter mode of the block cipher using the second symmetric-key encryption secret key and second auxiliary information,

the conversion process being a process of calculating, as at least part of a converted symmetric-key ciphertext to be used to decrypt a plaintext used in generating a symmetric-key ciphertext, an exclusive-OR of the symmetric-key ciphertext and the second partial conversion key, the symmetric-key ciphertext being an exclusive-OR of the plaintext and a value calculated by performing encryption in the counter mode of the block cipher using the first symmetric-key encryption secret key and the first auxiliary information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2024
From: KAWAI, YUTAKA
To: MITSUBISHI ELECTRIC CORPORATION
Reel/Frame 068394/0956 →
Continuity (2)
Continuation PCTJP2022017726 · Apr 13, 2022
Related Publication 20240421975A1 · Dec 19, 2024
References Cited (42)
US 20160119292A1 · Kaseda et al. · 2016 [cited by applicant]
US 20160344708A1 · Kawai et al. · 2016 [cited by applicant]
US 20160380767A1 · Hayashi et al. · 2016 [cited by applicant]
US 20170323114A1 · Egorov et al. · 2017 [cited by applicant]
US 20180091301A1 · Nuñez et al. · 2018 [cited by applicant]
US 20180254892A1 · Egorov et al. · 2018 [cited by applicant]
US 20180254901A1 · Egorov · 2018 [cited by examiner]
US 20210126782A1 · Koseki et al. · 2021 [cited by applicant]
US 20210391981A1 · Okano et al. · 2021 [cited by applicant]
US 20220029795A1 · Kawai et al. · 2022 [cited by applicant]
US 20220385455A1 · Imabayashi · 2022 [cited by applicant]
US 20240048377A1 · Kawai · 2024 [cited by applicant]
US 20240421976A1 · Kawai · 2024 [cited by examiner]
EP 2779523A1 · 2014 [cited by applicant]
EP 3096487A1 · 2016 [cited by applicant]
EP 3618345A1 · 2020 [cited by applicant]
EP 3836479A1 · 2021 [cited by applicant]
EP 4096146A1 · 2022 [cited by applicant]
JP 2008252745A · 2008 [cited by applicant]
JP 201690603A · 2016 [cited by applicant]
JP WO2018225248A1 · 2018 [cited by applicant]
JP 6867718B1 · 2021 [cited by applicant]
WO WO2013069505A1 · 2013 [cited by applicant]
WO WO2014083784A1 · 2014 [cited by applicant]
WO WO2015107620A1 · 2015 [cited by applicant]
WO WO2016051591A1 · 2016 [cited by applicant]
WO WO2017193108A2 · 2017 [cited by applicant]
WO WO2018102382A1 · 2018 [cited by applicant]
WO WO2018208786A1 · 2018 [cited by applicant]
WO WO2018208787A1 · 2018 [cited by applicant]
WO WO2020085151A1 · 2020 [cited by applicant]
WO WO2020240630A1 · 2020 [cited by applicant]
WO WO2022244079A1 · 2022 [cited by applicant]
Ateniese et a. (Improved Proxy Re-encryption Schemes with Applications to Secure Distributed Storage, ACM Transactions on Information and System Security, vol. 9, No. 1, Feb. 2006, pp. 1â30.) (Year: 2006). [cited by examiner]
Almaiah et al. (A new hybrid text encryption approach over mobile ad hoc network, IJECE, 2020, pp. 6461-6471) (Year: 2020). [cited by examiner]
International Search Report (PCT/ISA/210) issued in PCT/JP2022/017726, dated Jun. 28, 2022. [cited by applicant]
Syalim et al., “Improved Proxy Re-encryption Scheme for Symmetric Key Cryptography” in Cryptology ePrint Archive: Report 2021/276, 2017, pp. 1-15. [cited by applicant]
Syalim et al., “Realizing Proxy Re-encryption in the Symmetric World”, Communications in Computer and Information Science 251, Nov. 2011, pp. 1-20. [cited by applicant]
Yu et al., “Achieving Flexibility for ABE with Outsourcing via Proxy Re-Encryption”, ASIACCS'18, Jun. 2018, Session 16: Applied Crypto 2, pp. 659-672. [cited by applicant]
English translation of the International Search Report for International Application No. PCT/JP2021/018664, dated Aug. 3, 2021. [cited by applicant]
English translation of the International Search Report for International Application No. PCT/JP2022/017725, dated Jun. 28, 2022. [cited by applicant]
German Office Action for German Application No. 112021007337.0, dated Aug. 13, 2024, with an English translation. [cited by applicant]