IP Library Granted Patent US 12,739,102
Granted Patent B2
US 12,739,102 · App. 18/459,261 · Granted Sep 15, 2026

Encryption device, key generation device, and computer program product for encryption using indeterminate polynomial equations

Inventor: Koichiro Akiyama (Tokyo, JP)
Assignee: Kabushiki Kaisha Toshiba
H04L9/0825H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,102
App. No.
18/459,261
Granted
Sep 15, 2026
Kind
B2
Abstract

According to one embodiment, an encryption device includes a memory and one or more processors. The one or more processors are configured to: acquire, as a public key, an n-variable symmetric indeterminate equation having an element not more than a constant degree of F p [t] and determined depending on a total degree of each term, and being symmetric for at least two variables; randomly generate an n-variable polynomial having an element not more than a constant degree of F p [t], randomly generate an n-variable symmetric polynomial having an element not more than a constant degree of F p [t] and determined depending on a total degree of each term, and being symmetric for at least two variables, and randomly generate a noise polynomial having an element not more than a constant degree of F p [t]; and generate a ciphertext from the three polynomials and the n-variable symmetric indeterminate equation for the n-variable plaintext polynomial.

Claims (9)

1 . A key generation device comprising:

a memory; and

one or more processors coupled to the memory and configured to:

generate, as a public key, an n-variable indeterminate equation X(x 1 , . . . , x n ) having, as a coefficient, an element that is less than or equal to a constant degree of a univariable polynomial ring F p [t] on a finite field F p and is determined depending on a total degree of each term, and acquire a prime number p, a degree d, a total degree D x regarding variables x 1 , . . . , x n , and a degree d x,ν of a coefficient of a term of the total degree ν, which are used when one or more zero-points u of the n-variable indeterminate equation X(x 1 , . . . , x n ) are generated as a private key;

generate n d-degree polynomials u x1 (t), . . . , u xn (t) included in the univariable polynomial ring F p [t], the n d-degree polynomials having n(d+1) random numbers from 0 to p−1 randomly generated as coefficients, and generate the dx ,ν -degree polynomial τ ij (t) (i+j=ν≤D x ) that is a coefficient other than a constant term of the n-variable indeterminate equation X(x 1 , . . . , x n );

calculate a provisional constant term of the n-variable indeterminate equation X(x 1 , . . . , x n ) from the n polynomials u x1 (t), . . . , u xn (t) and the polynomial τ ij (t) (i+j=ν≤Dx), and generate the n-variable indeterminate equation X(x 1 , . . . , x n ) based on a quotient and a remainder obtained by dividing the provisional constant term by a polynomial u xi (t)u xj (t); and

output the n polynomials u x1 (t), . . . , u xn (t) as the private key to an application that decrypts data encrypted with the public key and output the n-variable indeterminate equation X(x 1 , . . . , x n ) as the public key to the application, wherein

the n-variable indeterminate equation X(x 1 , . . . , x n ) is a symmetric indeterminate equation that is symmetric with respect to at least two variables, and

the one or more processors are configured to generate the dx ,ν -degree polynomial τ ij (t) (i+j=ν≤Dx) to be τ ji (t)=τ ij (t).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2023
From: AKIYAMA, KOICHIRO
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 065105/0304 →
Priority Claims (1)
JP 2022-195059 · Dec 6, 2022 · national
Continuity (1)
Related Publication 20240195607A1 · Jun 13, 2024
References Cited (51)
US 5740250A · Moh · 1998 [cited by applicant]
US 6959085B1 · Hoffstein · 2005 [cited by examiner]
US 7773747B2 · Akiyama · 2010 [cited by applicant]
US 7787623B2 · Akiyama · 2010 [cited by examiner]
US 8356183B2 · Takahashi · 2013 [cited by applicant]
US 8522033B2 · Sakumoto · 2013 [cited by applicant]
US 8532289B2 · Gentry et al. · 2013 [cited by applicant]
US 11288985B2 · Akiyama · 2022 [cited by applicant]
US 12034850B2 · Akiyama · 2024 [cited by applicant]
US 20020001383A1 · Kasahara · 2002 [cited by applicant]
US 20040151307A1 · Wang et al. · 2004 [cited by applicant]
US 20060251247A1 · Akiyama · 2006 [cited by examiner]
US 20070061572A1 · Imai · 2007 [cited by applicant]
US 20070110232A1 · Akiyama · 2007 [cited by applicant]
US 20080019511A1 · Akiyama · 2008 [cited by applicant]
US 20090185680A1 · Akiyama · 2009 [cited by applicant]
US 20100054480A1 · Schneider · 2010 [cited by applicant]
US 20100226496A1 · Akiyama et al. · 2010 [cited by applicant]
US 20100329447A1 · Akiyama · 2010 [cited by applicant]
US 20120039473A1 · Gentry · 2012 [cited by applicant]
US 20130089201A1 · Sakumoto · 2013 [cited by applicant]
US 20130177151A1 · Sella et al. · 2013 [cited by applicant]
US 20150033025A1 · Hoffstein · 2015 [cited by applicant]
US 20150172258A1 · Komano · 2015 [cited by examiner]
US 20160119120A1 · Wang · 2016 [cited by applicant]
US 20180034630A1 · Rietman · 2018 [cited by applicant]
US 20190312728A1 · Poeppelmann · 2019 [cited by applicant]
US 20210248928A1 · Akiyama · 2021 [cited by examiner]
US 20220150064A1 · Akiyama · 2022 [cited by applicant]
US 20240195607A1 · Akiyama · 2024 [cited by applicant]
US 20240205006A1 · Akiyama · 2024 [cited by applicant]
US 20240214201A1 · Hoshizuki et al. · 2024 [cited by applicant]
JP 2010204466A · 2010 [cited by applicant]
JP 2021124679A · 2021 [cited by applicant]
JP 202277754A · 2022 [cited by applicant]
JP 202481510A · 2024 [cited by applicant]
Abdelrahaman Aly, “Design of Symmetric-Key Primitives for Advances Cryptographic Protocols,” IACR Trans. on Symmetric Cryptology, vol. 2020, No. 3, pp. 1-45 (2020). [cited by applicant]
Craig Gentry, “Fully Homomorphic Encryption Using Ideal Lattices,” ACM Symp. on Theory of Computing, pp. 169-178, DOI:10.1145/1536414.1536440 (2009). [cited by applicant]
Tsuyoshi Takagi et al., “The Multi-variable Modular Polynomial and Its Applications to Cryptography,” Int'l Symp. on Algorithms and Computation, pp. 386-396 (1996). [cited by applicant]
Michele Mosca, “Cybersecurity in an era with quantum computers: will we be ready?,” DOI:10.1109/MSP.2018.3761723, 4 pages (2018). [cited by applicant]
USPTO, Office Action in U.S. Appl. No. 18/458,570 (Apr. 25, 2025). [cited by applicant]
USPTO, Office Action in U.S. Appl. No. 17/459,320 (Mar. 17, 2023). [cited by applicant]
USPTO, Final Office Action in U.S. Appl. No. 17/459,320 (Sep. 29, 2023). [cited by applicant]
USPTO, Notice of Allowance in U.S. Appl. No. 17/459,320 (May 2, 2024). [cited by applicant]
USPTO, Notice of Allowance in U.S. Appl. No. 17/004,211 (Dec. 24, 2021). [cited by applicant]
Zhicheng Gao et al., “Degree Distribution of the Greatest Common Divisor of Polynomials over F [cited by applicant]
J.von zur Gathen et al, “Approximate polynomial gcd: Small degree and small height perturbations,” J. of Symbolic Computations, vol. 45, pp. 879-886, DOI: 10.1016/j.jsc.2010.04.001 (2010). [cited by applicant]
Yuichi Komano et al., “Algebraic Surface Cryptosystems using Polynomial Approximate GCD,” IEICE Technical Report ISEC2016-35, ITE2016-29, ICSS2016-35, EMM2016-43(Jul. 2016), pp. 217-222, and translation, 12 pages (2016). [cited by applicant]
Yuto Mashima et al., “C language implementation of an indeterminate equation encryption scheme based on the approximate ideal GCD problem and fast implementation using Karatsuba method,” Information Processing Society o… [cited by applicant]
Japan Patent Office, Office Action in JP App. No. 2022-195059 (Aug. 5, 2025). [cited by applicant]
USPTO, Notice of Allowance in U.S. Appl. No. 18/458,570, (Aug. 21, 2025). [cited by applicant]