WO2017126642A1 - 認証システム及び方法 - Google Patents
認証システム及び方法 Download PDFInfo
- Publication number
- WO2017126642A1 WO2017126642A1 PCT/JP2017/001845 JP2017001845W WO2017126642A1 WO 2017126642 A1 WO2017126642 A1 WO 2017126642A1 JP 2017001845 W JP2017001845 W JP 2017001845W WO 2017126642 A1 WO2017126642 A1 WO 2017126642A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- noise
- challenge
- authentication
- generated
- response
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
Definitions
- the present invention relates to an authentication system and method, and in an exemplary embodiment, relates to an authentication system and method in an asymmetric computer resource environment.
- the authentication protocol is a protocol for the prover P to authenticate itself to the verifier V.
- the prover P is a tag and the verifier V is a reader.
- FIG. 1 shows an outline of an authentication protocol, and a typical authentication protocol is constructed by using a pseudo-random function (PRF) f (AES or the like) for a tag and a reader to share a common key.
- PRF pseudo-random function
- the reader sends a challenge c to the tag, and the tag returns f (c) in response to this, and the reader verifies whether the evaluation of c received from the tag is correct.
- Non-Patent Documents 3 and 5 Authentication based on the LPN problem
- Non-Patent Documents 1, 2, 4 Authentication based on random selection
- Non-Patent Document 3 proposes the following three authentication protocols. (1) Authentication Protocol Secure Against Active Attacks (Protocol A1) (2) The First MAC based Construction of Authentication Protocol Secure against MIM (Protocol MAC1) (3) The Second MAC based Construction of Authentication Protocol Secure against MIM (Protocol MAC2) Protocol A1 is secure under an active attack scenario, and protocols MAC1 and MAC2 are secure under a man-in-the-middle (MIM) attack scenario.
- Non-Patent Document 5 proposes another authentication protocol that is secure under a MIM attack scenario.
- Verifier Alice and Prover Bob are lightweight symmetric cryptographic operations with a block length of n Assume that a challenge-response authentication protocol is used. here, Is an appropriate key space.
- E is a secret key that can be efficiently used by passive attackers. The function It can be calculated from the samples. This is obvious when E is linear.
- Random selection is to compensate E's helplessness by the following execution modes.
- Alice and Bob A set of keys from, where L> 1 is a small constant Share
- a lightweight authentication protocol that can be applied to a wireless sensor network (WSN) or IoT (Internet of Things).
- WSN wireless sensor network
- IoT Internet of Things
- a lightweight authentication protocol that can be applied to an environment (asymmetric computer resource environment) in which a device having scarce computer resources such as a tag or a sensor communicates with a computer resource-rich device such as a PC.
- the asymmetric computer resource environment is a sensor or tag as a prover between the person who proves that he is surely himself (the prover) and the person who verifies and confirms it (verifier).
- Non-Patent Documents 3 and 5 provide some interesting elements, but they are not lightweight enough for some M2M authentication scenarios, and the asymmetric computer resource environment The following restrictions are not taken into account.
- the authentication protocols described in Non-Patent Documents 1, 2, and 4 employ an interesting paradigm called random selection, but do not have the desired cryptographic security. That is, the protocols disclosed in Non-Patent Documents 1 to 5 are not appropriate in that they do not consider an asymmetric computer resource environment and / or do not provide desired cryptographic security. J. Cichon, M. Klonowski and M. Kutyowski, “Privacy protection for RFID with hidden subset identifiers”, PERVASIVE 2008, Lecture Notes in Computer Science, vol. 5013, pp.
- the present invention considers (i) the asymmetry, and (ii) The purpose is to achieve sufficient security in terms of cryptographic theory, even if it is a tag or a sensor, which is sufficiently light enough not to cause a problem.
- the authentication system employed by the present invention includes an authenticated device and an authentication device,
- the device to be authenticated is A storage unit for storing common information including a secret key;
- a noise generator that generates first noise with severe intensity restrictions and second noise with less intensity restrictions;
- a response generator With The authentication device is A storage unit for storing common information including a secret key;
- a noise candidate generator that comprehensively generates first noise candidates with severe intensity restrictions;
- the response generation unit of the device to be authenticated generates a response using the first noise and the second noise generated by the device to be authenticated, the challenge received from the authentication device, and the common information
- the local response generation unit of the authentication device generates a local response using the first noise candidate generated by the authentication device exhaustively, the challenge generated by the authentication device, and the common information
- the authentication determination unit of the authentication device determines authentication by comparing the local response generated using the noise candidates exhaustively with the response received from the device to be authenticated.
- the authentication method employed by the present invention is: The device to be authenticated and the authentication device share common information including the secret key, The authenticating device generates a challenge and sends it to the authenticated device; The device to be authenticated generates first noise with severe intensity restriction and second noise with loose intensity restriction, the generated first noise and second noise, the challenge received from the authentication device, and the common information And generate a response using and send it to the authentication device, The authentication device comprehensively generates first noise candidates with severe intensity restrictions, and generates a local response using the generated first noise candidates, the challenge generated by the authentication device, and the common information. Then, the generated local response is compared with the response received from the device to be authenticated to determine authentication.
- the amount of processing for generating a response by the authenticated device that is the prover is lighter than the amount of calculation for determining authentication by generating a local response by the authenticating device that is the verifier.
- the first noise is a binary vector of N bit strings generated so that the number of “1” s is ⁇ or less,
- the second noise is a randomly generated binary vector;
- the first noise candidate is a number delta pieces become so exhaustively generated N-bit Retsugun (N C delta-number of N group consisting bit sequence) of "1".
- the noise generator is A binary vector generation unit that randomly generates a binary vector composed of an N-bit string and the number of binary vectors “1” generated by the binary vector generation unit are extracted as weights and compared with a parameter ⁇ included in common information.
- a determination unit If the binary vector generated by the binary vector generation unit has more than ⁇ weights, the generation of the binary vector is repeated until the binary vector weight becomes ⁇ or less, and the binary vector weight becomes ⁇ or less.
- the binary vector at the time of An arbitrary binary vector generated by the binary vector generation unit is set as the second noise,
- the noise candidate generation unit generates binary vectors of all N bit strings having a weight ⁇ and sets them as first noise candidates.
- the device to be authenticated generates a commitment and transmits the commitment to the authentication device.
- the common information includes a secret key S that is an m ⁇ n binary vector,
- the first noise is Then, each bit of e * of m bits is generated according to the Bernoulli distribution of parameter ⁇ * to generate e * randomly, and its weight is a condition Obtained by generating a new e * until The second noise is In accordance with the Bernoulli distribution of the parameter ⁇ and each e of the m bits e is generated randomly.
- the first noise candidate is M-dimensional binary vectors of weights ⁇ are candidates for the first noise e * Is obtained as
- the response generation unit uses an operator O,
- the secret data S, the first noise e * , and the challenge c are input, and the randomized secret data S * and the randomized challenge s * are output.
- the local response generation unit uses the operator O, Secret data S, each first noise candidate , Challenge c, as input, and output randomized secret data S * and randomized challenge s * , Local response from randomized secret data S * , randomized challenge s * , commitment r Produces
- the authentication determination unit All first noise candidates about If the condition is satisfied, the response is permitted and the authentication is accepted.
- the common information includes a secret key s that is an n-dimensional binary vector, and Cryptographic algorithm for encrypting n-dimensional binary vectors
- a secret key s that is an n-dimensional binary vector
- Cryptographic algorithm for encrypting n-dimensional binary vectors
- the local response generator is configured to generate each first noise candidate. And using challenge m, noisy challenge And perform mapping of the secret data s using the noisy challenge to generate the mapped secret data , Encrypt the challenge m using the mapped secret data, and Produces
- the authentication determination unit All first noise candidates about If the condition is satisfied, the response is permitted and the authentication is accepted.
- a prover which is a device with scarce computer resources, performs a lightweight matrix calculation
- a verifier which is a device with rich computer resources, performs a verification operation including a non-lightweight vector evaluation, thereby computing resources.
- the operation cost on the device side with scarce computer resources is reduced by biasing the processing with high load to the device side with rich computer resources while ensuring safety. Therefore, if the prover's computer resources are overwhelmingly less than that of the verifier, for example, even if the prover is a tag or a sensor, it is light enough that it does not matter and is secure enough for cryptographic theory.
- An authentication protocol can be provided.
- An overview of the challenge-response authentication protocol is shown.
- An authentication scenario in an asymmetric computer resource environment (a prover with low computing ability and a verifier with high computing ability) is shown.
- Asymmetric computer resource environment This embodiment relates to an authentication method and system in an asymmetric computer resource environment.
- the asymmetric computer resource environment is an environment in which a device having scarce computer resources such as a tag or a sensor performs cryptographic communication with a computer resource-rich device such as a PC.
- authentication according to the present embodiment is performed between a first device (authentication device) as a verifier and a second device (authenticated device) as a prover.
- the first device and the second device both include a computer and have a communication function (typically a wireless communication function).
- the computer includes an input unit, a storage unit, a processing unit (arithmetic unit or CPU), an output unit, and the like as hardware, and executes predetermined processing by software (computer program).
- the first device is rich in computer resources (CPU, memory, etc.), and the second device is scarce in computer resources.
- the first device has a higher processing capability (calculation capability) than the second device, and the second device can operate with lower power consumption.
- Examples of the first device include PCs (desktops, laptops, notebooks, etc.), servers, mobile computers (smartphones, mobile phones, PDAs, tablets, wearable computers with predetermined computer resources, etc.), tag readers, etc.
- the Examples of the second device include a sensor (IC built-in), an RFID tag, an IC tag, an IC card, and a wearable computer.
- the authentication system is a challenge-response authentication system including an authenticated device that is a prover and an authentication device that is a verifier.
- the authenticated device and the authenticated device share common information including secret data, the authenticated device generates a challenge and transmits the challenge to the authenticated device, and the authenticated device that has received the challenge receives the challenge and the secret data , Execute a predetermined process to generate a response, send the response to the authentication device, and the authentication device that has received the response performs a predetermined process using the challenge and secret data, and performs a local response
- the response received from the device to be authenticated and the local response generated by the authentication device are compared, the received response is evaluated, and it is determined whether or not to accept the response.
- the authentication device includes a common information storage unit that stores common information including secret data, a noise generation unit, a challenge generation unit, a local response generation unit, and an authentication determination unit.
- the device to be authenticated includes a common information storage unit that stores common information including secret data, a noise generation unit, and a response generation unit.
- the authentication protocol I described later further includes a commitment generation unit. Both the authentication device and the device to be authenticated include a data transmission / reception unit.
- the noise generation unit of the device to be authenticated generates first noise with severe intensity restriction and second noise with weak intensity restriction.
- the noise generation unit of the authentication device is a noise candidate generation unit that comprehensively generates noise candidates with severe intensity restrictions.
- the noise generation unit is a binary vector generation unit that generates a binary vector
- the response generation unit of the device to be authenticated generates a response using the first noise and the second noise generated by the device to be authenticated, the challenge received from the authentication device, and the common information.
- the response generation algorithm is a process that can be executed by a lightweight calculation.
- the response generation process in the device to be authenticated includes “a challenge generated by the authentication device and transmitted to the device to be authenticated” and “two noises generated by the device to be authenticated and not transmitted to the authentication device (noise with severe intensity restrictions).
- protocol I "the commitment generated by the device to be authenticated and sent to the authentication device"
- the authentication device has a realistic load (moderate complexity processing in Fig. 4).
- a partial response is extracted from the secret information and scrambled response is generated with a strength that can be verified by the attacker and at a strength that the attacker cannot obtain sufficient information.
- the local response generation unit of the authentication device generates a local response using the noise candidates generated by the authentication device, the challenge generated by the authentication device, and the common information.
- the authentication determination unit of the authentication device determines authentication by comparing a local response generated by using the noise candidates exhaustively with a response received from the device to be authenticated.
- the process in the authentication device is a process that can be executed only by comprehensively testing noise candidates whose intensity is severely limited, without considering noise candidates whose intensity is not strictly limited.
- FIG. 4 shows an authentication framework according to this embodiment.
- the authentication framework consists of a number of boxes as shown in Fig. 4, which are "shared secret data”, “commitment”, “challenge”, “proof” Lightweight processing (lightweight processing P) '', ⁇ response (response) '', ⁇ reasonable complexity of the verifier (moderate complexity processing V) '', ⁇ authentication result (authentication result) '', In each authentication protocol according to the present embodiment, which will be described later, different designs and configurations are employed in a predetermined box.
- This embodiment has a new design / configuration in “common secret data”, “processing at the prover”, “response”, and “processing at the verifier”.
- the present embodiment is particularly characterized by “Process P in the prover (authenticated device) (see FIGS. 5 and 6)” and “Process V in the verifier (authenticating device) (see FIGS. 7 and 8)”. Have.
- the authentication protocol according to the present embodiment can respond to the following requests. (a) be compatible with the authentication scenario under the asymmetric computer resource environment shown in FIG.
- the authentication protocol includes an authentication protocol I and an authentication protocol II.
- Authentication protocol I provides authentication security based on a combination of two problems: (i) LPN problem and (ii) random selection problem.
- Authentication protocol II provides (i) an appropriate cryptographic algorithm (stream Encryption security), (ii) random selection paradigm, and (iii) randomization of ciphertext.
- the weight of the binary vector e which is equal to the number of “1” in the binary vector e.
- the parameter ⁇ defines the upper limit of the weight.
- Matrix S * and vector s * are defined as follows. here, It is. Here, “1” is an mxn binary matrix with all elements being 1, ie, Is a matrix in which each element of the matrix E * is bit-inverted.
- the operator Is the "secret data S", "binary vector e * (the present embodiment, although the random matrix E * defined by the vector e * are generated, specific calculation of randomization is not limited to this embodiment ) ”And“ challenge c ”are input, and“ randomized secret data S * ”and“ randomized challenge s * ”are output.
- the prover generates a commitment message r, which is a randomly generated n-dimensional binary vector, and transmits it to the verifier.
- the verifier generates a challenge message c, which is a randomly generated n-dimensional binary vector and has a weight greater than ⁇ , and transmits it to the prover.
- Step 3 When the prover receives the challenge message c from the verifier, the prover generates a response in the following procedure (process P in FIG. 4).
- e * is a first sequence (vector) for data randomization, that is, first noise
- e is for data randomization.
- the second series (vector) that is, the second noise.
- the first noise (e * ) is noise with a more severe intensity limit
- the second noise (e) is a noise with less severe intensity limit.
- the prover uses the operator O to calculate an m ⁇ n binary matrix S * and an m-dimensional binary vector s *, and calculates a response z.
- a first noise e * is generated in the block “Random selection”.
- the generated first noise e * is used to map the secret data (secret key) S. Is executed to obtain randomized secret data S * .
- E * is a random matrix defined by the vector e * .
- Step 4 When the verifier receives the response z, the verifier determines success or failure of authentication in the following procedure (Process V in FIG. 4).
- the verifier selects a combination of ⁇ elements “1” from the m dimension, that is, a combination obtained by: M * binary vectors (weight ⁇ ) as e * candidates And using the operator O, the matrix S * and the vector s * are evaluated as follows. And It is.
- Verifiers should consider all candidates considered as candidates about If the condition is satisfied, the response z is permitted and the authentication is accepted (passed). Otherwise, the response z is rejected and the authentication is rejected (failed).
- thr is a preset threshold value, and thr ⁇ m / 2.
- the process V in the verifier will be described more specifically with reference to FIG.
- the first noise candidate in the block “Setting a hypothesis on random selection” Is generated.
- mapping of secret data Use the mapping of secret data (secret key) S Is executed to obtain randomized secret data S * .
- E * is a vector Is a random matrix defined by
- the generated first noise candidate Randomize challenge c using random matrix E * defined by Is executed to obtain s * .
- E * defined by Is executed to obtain s * .
- Mapped Secret Data a random response s * and a local response Is generated.
- Step 1 The verifier sends a message m, which is an n-dimensional binary vector, to the prover.
- Step 2 When the prover obtains the message m from the verifier, the prover generates a response in the following procedure (process P in FIG. 4).
- e * is a first sequence (vector) for randomization, that is, first noise
- e is a second sequence for randomization.
- Vector that is, the second noise.
- the first noise (e * ) is noise with a more severe intensity limit
- the second noise (e) is a noise with less severe intensity limit.
- a response z is obtained by using s (v) as a key by scrambling with an encryption algorithm.
- a first noise e * is generated in the block “Random selection”.
- mapping of secret data using the generated first noise e * and the challenge m received from the authentication device, the noisy challenge v Is generated, mapping of the secret data (secret key) s is performed using the noisy challenge v, and the mapped secret data s (v) Get.
- the encryption of the challenge m is performed using the mapped secret data s (v), and the encryption (scramble) challenge E s (v ) (m) is generated, and the response z is generated using the generated second noise e. Is generated.
- Step 3 When the verifier receives the response z, the verifier determines success or failure of authentication in the following procedure (Process V in FIG. 4).
- the verifier selects a combination of ⁇ elements “1” from the n dimension, that is, a combination obtained by: N * -dimensional binary vectors (weight ⁇ ) as e * candidates And for each candidate And evaluate each candidate according to the result.
- Verifiers should consider all candidates considered as candidates about If the condition is satisfied, the response z is permitted and the authentication is accepted (passed). Otherwise, the response z is rejected and the authentication is rejected (failed).
- thr is a preset threshold value, and thr ⁇ n / 2.
- the encryption of challenge m is performed using the mapped secret data, and the encryption (scramble) challenge is performed. Is generated.
- the authentication protocol according to this embodiment is the result of the authentication protocol disclosed in Non-Patent Documents 3, 5 and 1, 2, and 4. It is based on a non-obvious combination of these disclosures.
- the authentication protocol according to the present embodiment employs some elements disclosed in Non-Patent Documents 3 and 5.
- the elements disclosed in Non-Patent Documents 3 and 5 have poor calculation capability. Factors that cannot support the lightweight authentication of parties (usually provers), especially (i) Long binary vector permutation, which is the main element in Non-Patent Document 3, (ii) The calculation in the non-binary finite field which is the main element in Non-Patent Document 5 is not included.
- Table 1 compares the secret key and communication dimensions, assuming that n is the dominant parameter.
- the authentication protocol according to the present embodiment does not include a long binary vector permutation that is a main element in Non-Patent Document 3, and an operation in a non-binary finite field that is a main element in Non-Patent Document 5.
- Table 3 shows the response in comparison.
- Table 4 shows the dominant operation on the verifier side in comparison.
- the authentication protocol according to the present invention can be used as a security technique for such a system.
- the power consumption on the side of a device with scarce computer resources can be greatly suppressed, so that the application range is greatly expanded.
- security of critical infrastructure such as electric power, healthcare embedded in people or using mobile devices, services for elderly people, agriculture using various sensors, fishery support and disaster countermeasure systems
- Applications such as next-generation credit card payments on the go can be expected to have significant market applications as well as global markets.
- the utility value is high as those basic technologies.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Abstract
安全性を確保しつつ、計算機資源の乏しいデバイス側の動作コストを低くできる認証プロトコルを提供する。 証明者と検証者が秘密鍵を含む共通情報を共有し、検証者は証明者にチャレンジメッセージを送信し、チャレンジメッセージを受信した証明者は、受信したメッセージ及び前記共通情報を用いて、第1処理を実行してレスポンスを生成して当該レスポンスを検証者に送信し、レスポンスを受信した検証者は、受信したレスポンス及び前記共通情報を用いて、前記第1処理よりも計算量の大きい第2処理を実行して、レスポンスを評価し、当該レスポンスを受け入れるか否かを判定する。
Description
本発明は、認証システム及び方法に係り、典型的な態様例では、非対称計算機資源環境における認証システム及び方法に関する。
認証プロトコルは、証明者Pが自身を検証者Vに対して認証するためのプロトコルである。例えばRFID実装においては、証明者Pはタグ、検証者Vはリーダである。図1は、認証プトコルの概要を示し、典型的な認証プロトコルは、タグとリーダが共通鍵を共有するための疑似乱数関数(PRF)f(AES等)を用いることで構築される。認証プロトコルは、リーダがチャレンジcをタグに送信し、タグはこれに対してf(c)を返し、リーダは、タグから受信したcの評価が正しいかについて検証する。
この手法の主な問題は、疑似乱数関数が、数学的仮説あるいはAESのようなアドホックのブロック暗号に基づいて証明可能安全性を備えていたとしても、制限された計算機資源を備えた軽量デバイスにおいて手順を実行するにはコストが高いということである。
軽量の認証手法としては、以下の2つの手法が提案されている。
(i)LPN問題に基づく認証(非特許文献3、5)
(ii)ランダム選択に基づく認証(非特許文献1、2、4)
(i)LPN問題に基づく認証(非特許文献3、5)
(ii)ランダム選択に基づく認証(非特許文献1、2、4)
LPN問題に基づく認証
LPN問題(Learning parity with Noise)の困難性を仮定して、それに基づく幾つかの認証プロトコルが提案されている。LPN問題自体については、当業者に知られているので、本明細書での詳細な説明は省略する。非特許文献3には、以下の3つの認証プロトコルが提案されている。
(1)Authentication Protocol Secure Against Active Attacks (Protocol A1)
(2)The First MAC based Construction of Authentication Protocol Secure against MIM (Protocol MAC1)
(3)The Second MAC based Construction of Authentication Protocol Secure against MIM (Protocol MAC2)
プロトコルA1は、アクティブ攻撃シナリオ下において安全であり、プロトコルMAC1、MAC2は、中間者(MIM)攻撃シナリオ下において安全である。
非特許文献5には、MIM攻撃シナリオ下において安全である別の認証プロトコルが提案されている。
LPN問題(Learning parity with Noise)の困難性を仮定して、それに基づく幾つかの認証プロトコルが提案されている。LPN問題自体については、当業者に知られているので、本明細書での詳細な説明は省略する。非特許文献3には、以下の3つの認証プロトコルが提案されている。
(1)Authentication Protocol Secure Against Active Attacks (Protocol A1)
(2)The First MAC based Construction of Authentication Protocol Secure against MIM (Protocol MAC1)
(3)The Second MAC based Construction of Authentication Protocol Secure against MIM (Protocol MAC2)
プロトコルA1は、アクティブ攻撃シナリオ下において安全であり、プロトコルMAC1、MAC2は、中間者(MIM)攻撃シナリオ下において安全である。
非特許文献5には、MIM攻撃シナリオ下において安全である別の認証プロトコルが提案されている。
ランダム選択(Random Selection)に基づく認証
認証プロトコルにおけるランダム選択の原理は以下の通りである。
検証者アリスと証明者ボブが、プロック長nの軽量の対称暗号演算
を用いるチャレンジ・レスポンス認証プロトコルを実行するとする。
ここで、
は、適切な鍵空間である。
さらに、Eは、パッシブな攻撃者によって効率的に秘密鍵
を関数
のサンプルから計算できるものとする。これは、Eが線形の場合は自明である。
認証プロトコルにおけるランダム選択の原理は以下の通りである。
検証者アリスと証明者ボブが、プロック長nの軽量の対称暗号演算
を用いるチャレンジ・レスポンス認証プロトコルを実行するとする。
ここで、
は、適切な鍵空間である。
さらに、Eは、パッシブな攻撃者によって効率的に秘密鍵
を関数
のサンプルから計算できるものとする。これは、Eが線形の場合は自明である。
ランダム選択は、Eの無力さを以下の実行モードによって補償することである。
単一の
を保有することに代えて、アリスとボブは、共通の秘密情報として、
からの複数の鍵から成る集合(L>1は小さな定数である)
を共有する。
単一の
を保有することに代えて、アリスとボブは、共通の秘密情報として、
からの複数の鍵から成る集合(L>1は小さな定数である)
を共有する。
アリスからチャレンジ
を受信すると、ボブは、選択インデックス
を選択し、レスポンス
を出力する。
チャレンジuに関するレスポンスyの検証は、全ての
について、
を計算することによって効率的に実行される。
を受信すると、ボブは、選択インデックス
を選択し、レスポンス
を出力する。
チャレンジuに関するレスポンスyの検証は、全ての
について、
を計算することによって効率的に実行される。
ここで、軽量の認証プロトコルの開発においては、ワイヤレス・センサーネットワーク(WSN)やIoT(Internet of Things)において適用し得る軽量の認証プロトコルの開発が課題である。すなわち、タグやセンサー等の計算機資源の乏しいデバイスが、PCのような計算機資源豊かなデバイスと通信を行う環境(非対称計算機資源環境)に適用し得る軽量の認証プロトコルの開発が重要である。非対称計算機資源環境とは、「自分は確かに自分である」と証明する側(証明者)と、それを検証して確認する側(検証者)との間に、証明者としてセンサーやタグなどの計算機資源が乏しいデバイスを想定し、検証者としてサーバなどの計算機資源が豊かな装置を想定するがゆえに、計算機資源の大きな格差が存在する環境をいう(図2)。
しかしながら、(1)非特許文献3、5に記載された認証プロトコルは、幾つかの興味深い要素を提供しているが、幾つかのM2M認証シナリオにとって十分に軽量ではなく、また、非対称計算機資源環境下の制約を考慮していない。(2)非特許文献1、2、4に記載された認証プロトコルは、ランダムセレクションという興味深いパラダイムを採用しているが、所望の暗号セキュリティを備えていない。すなわち、非特許文献1~5に開示されたプロトコルは、非対称計算機資源環境を考慮していない点、あるいは/および、所望の暗号セキュリティを提供しない点において、適切ではない。
J. Cichon, M. Klonowski and M. Kutyowski, "Privacy protection for RFID with hidden subset identifiers", PERVASIVE 2008, Lecture Notes in Computer Science, vol. 5013, pp. 298-314, 2008. Z. Golebiewski, K. Majcher and F. Zagrski, "Attacks on CKK family of RFID authentication protocols", In: Coudert, D., Simplot-Ryl, D., Stojmenovic, I. (eds.) ADHOC-NOW 2008. Lecture Notes in Computer Science, vol. 5198, pp. 241-250, 2008 E. Kiltz, K. Pietrzak, D. Cash, A. Jain, and D. Venturi, "Efficient Authentication from Hard Learning Problems", EUROCRYPT 2011, Lecture Notes in Computer Science, vol. 6632, pp. 7-26, 2011. M. Krause and M. Hamann, "The Cryptographic Power of Random Selection", SAC 2011, Lecture Notes in Computer Science, vol. 7118, pp. 134-150, 2012. V. Lyubashevsky and D. Masny, "Man-in-the-Middle Secure Authentication Schemes from LPN and Weak PRFs", CRYPTO 2013, Lecture Notes in Computer Science, vol. 8043, pp. 308-325, 2013.
J. Cichon, M. Klonowski and M. Kutyowski, "Privacy protection for RFID with hidden subset identifiers", PERVASIVE 2008, Lecture Notes in Computer Science, vol. 5013, pp. 298-314, 2008. Z. Golebiewski, K. Majcher and F. Zagrski, "Attacks on CKK family of RFID authentication protocols", In: Coudert, D., Simplot-Ryl, D., Stojmenovic, I. (eds.) ADHOC-NOW 2008. Lecture Notes in Computer Science, vol. 5198, pp. 241-250, 2008 E. Kiltz, K. Pietrzak, D. Cash, A. Jain, and D. Venturi, "Efficient Authentication from Hard Learning Problems", EUROCRYPT 2011, Lecture Notes in Computer Science, vol. 6632, pp. 7-26, 2011. M. Krause and M. Hamann, "The Cryptographic Power of Random Selection", SAC 2011, Lecture Notes in Computer Science, vol. 7118, pp. 134-150, 2012. V. Lyubashevsky and D. Masny, "Man-in-the-Middle Secure Authentication Schemes from LPN and Weak PRFs", CRYPTO 2013, Lecture Notes in Computer Science, vol. 8043, pp. 308-325, 2013.
本発明は、認証のための通信手順(プロトコル)において、証明者の計算機資源が検証者のそれよりも圧倒的に乏しい場合に、(i)その非対称性を考慮し、(ii)証明者がタグやセンサーであっても問題にならないほど十分に軽量で、しかも(iii)暗号理論的に十分な安全性を達成すること、を目的とするものである。
本発明が採用した認証システムは、被認証デバイスと認証デバイスを備え、
前記被認証デバイスは、
秘密鍵を含む共通情報を格納する記憶部と、
強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成する雑音生成部と、
レスポンス生成部と、
を備え、
前記認証デバイスは、
秘密鍵を含む共通情報を格納する記憶部と、
強度制限の厳しい第1雑音の候補を網羅的に生成する雑音候補生成部と、
チャレンジ生成部と、
ローカルレスポンス生成部と、
認証判定部と、
を備え、
前記被認証デバイスの前記レスポンス生成部は、当該被認証デバイスが生成した第1雑音及び第2雑音と、前記認証デバイスから受信したチャレンジと、前記共通情報と、を用いてレスポンスを生成し、
前記認証デバイスの前記ローカルレスポンス生成部は、当該認証デバイスが網羅的に生成した第1雑音候補と、当該認証デバイスが生成したチャレンジと、前記共通情報と、を用いてローカルレスポンスを生成し、
前記認証デバイスの前記認証判定部は、前記雑音候補を網羅的に用いて生成された前記ローカルレスポンスと、前記被認証デバイスから受信した前記レスポンスと、を比較して、認証を判定する。
前記被認証デバイスは、
秘密鍵を含む共通情報を格納する記憶部と、
強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成する雑音生成部と、
レスポンス生成部と、
を備え、
前記認証デバイスは、
秘密鍵を含む共通情報を格納する記憶部と、
強度制限の厳しい第1雑音の候補を網羅的に生成する雑音候補生成部と、
チャレンジ生成部と、
ローカルレスポンス生成部と、
認証判定部と、
を備え、
前記被認証デバイスの前記レスポンス生成部は、当該被認証デバイスが生成した第1雑音及び第2雑音と、前記認証デバイスから受信したチャレンジと、前記共通情報と、を用いてレスポンスを生成し、
前記認証デバイスの前記ローカルレスポンス生成部は、当該認証デバイスが網羅的に生成した第1雑音候補と、当該認証デバイスが生成したチャレンジと、前記共通情報と、を用いてローカルレスポンスを生成し、
前記認証デバイスの前記認証判定部は、前記雑音候補を網羅的に用いて生成された前記ローカルレスポンスと、前記被認証デバイスから受信した前記レスポンスと、を比較して、認証を判定する。
本発明が採用した認証方法は、
被認証デバイスと認証デバイスが秘密鍵を含む共通情報を共有し、
前記認証デバイスはチャレンジを生成して前記被認証デバイスに送信し、
前記被認証デバイスは、強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成し、生成した第1雑音及び第2雑音と、前記認証デバイスから受信したチャレンジと、前記共通情報と、を用いてレスポンスを生成して、前記認証デバイスに送信し、
前記認証デバイスは、強度制限の厳しい第1雑音の候補を網羅的に生成し、生成した第1雑音候補と、当該認証デバイスが生成したチャレンジと、前記共通情報と、を用いてローカルレスポンスを生成し、生成したローカルレスポンスと、前記被認証デバイスから受信した前記レスポンスと、を比較して、認証を判定する。
被認証デバイスと認証デバイスが秘密鍵を含む共通情報を共有し、
前記認証デバイスはチャレンジを生成して前記被認証デバイスに送信し、
前記被認証デバイスは、強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成し、生成した第1雑音及び第2雑音と、前記認証デバイスから受信したチャレンジと、前記共通情報と、を用いてレスポンスを生成して、前記認証デバイスに送信し、
前記認証デバイスは、強度制限の厳しい第1雑音の候補を網羅的に生成し、生成した第1雑音候補と、当該認証デバイスが生成したチャレンジと、前記共通情報と、を用いてローカルレスポンスを生成し、生成したローカルレスポンスと、前記被認証デバイスから受信した前記レスポンスと、を比較して、認証を判定する。
本発明において、証明者である被認証デバイスによってレスポンスを生成するための処理の計算量は、検証者である認証デバイスによってローカルレスポンスを生成して認証を判定する計算量よりも軽量である。
1つの態様では、前記第1雑音は、「1」の数がΔ個以下となるように生成されたNビット列のバイナリベクトルであり、
前記第2雑音は、ランダムに生成されたバイナリベクトルであり、
前記第1雑音候補は、「1」の数がΔ個となるように網羅的に生成されたNビット列群(NCΔ個のNビット列からなる群)である。
1つの態様では、前記雑音生成部は、
Nビット列からなるバイナリベクトルをランダムに生成するバイナリベクトル生成部と、前記バイナリベクトル生成部により生成されたバイナリベクトルの「1」の数を重みとして抽出し、共通情報に含まれるパラメータΔと比較する判定部と、を備え、
前記バイナリベクトル生成部により生成されたバイナリベクトルの重みがΔ個より多い場合には、バイナリベクトルの重みがΔ個以下になるまでバイナリベクトルの生成を繰り返し、バイナリベクトルの重みがΔ個以下となった時のバイナリベクトルを第1雑音とし、
前記バイナリベクトル生成部により生成された任意のバイナリベクトルを第2雑音とし、
前記雑音候補生成部は、重みΔの全てのNビット列のバイナリベクトルを生成して第1雑音候補とする。
前記第2雑音は、ランダムに生成されたバイナリベクトルであり、
前記第1雑音候補は、「1」の数がΔ個となるように網羅的に生成されたNビット列群(NCΔ個のNビット列からなる群)である。
1つの態様では、前記雑音生成部は、
Nビット列からなるバイナリベクトルをランダムに生成するバイナリベクトル生成部と、前記バイナリベクトル生成部により生成されたバイナリベクトルの「1」の数を重みとして抽出し、共通情報に含まれるパラメータΔと比較する判定部と、を備え、
前記バイナリベクトル生成部により生成されたバイナリベクトルの重みがΔ個より多い場合には、バイナリベクトルの重みがΔ個以下になるまでバイナリベクトルの生成を繰り返し、バイナリベクトルの重みがΔ個以下となった時のバイナリベクトルを第1雑音とし、
前記バイナリベクトル生成部により生成された任意のバイナリベクトルを第2雑音とし、
前記雑音候補生成部は、重みΔの全てのNビット列のバイナリベクトルを生成して第1雑音候補とする。
1つの態様(後述する認証プロトコルI)では、 前記被認証デバイスは、コミットメントを生成して、前記認証デバイスに送信し、
前記共通情報は、m×nバイナリベクトルである秘密鍵Sを含み、
前記第1雑音は、
にしたがって、mビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、mビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのm次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンス生成部は、演算子Oを用いて、
秘密データS、第1雑音e*、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、第2雑音e、コミットメントr、から、レスポンス
を生成し、
前記ローカルレスポンス生成部は、前記演算子Oを用いて、
秘密データS、各第1雑音候補
、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、コミットメントrから、ローカルレスポンス
を生成し、
前記認証判定部は、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る。
前記共通情報は、m×nバイナリベクトルである秘密鍵Sを含み、
前記第1雑音は、
にしたがって、mビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、mビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのm次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンス生成部は、演算子Oを用いて、
秘密データS、第1雑音e*、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、第2雑音e、コミットメントr、から、レスポンス
を生成し、
前記ローカルレスポンス生成部は、前記演算子Oを用いて、
秘密データS、各第1雑音候補
、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、コミットメントrから、ローカルレスポンス
を生成し、
前記認証判定部は、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る。
1つの態様(後述する認証プロトコルII)では、前記共通情報は、n次元バイナリベクトルである秘密鍵sと、
n次元のバイナリベクトルを暗号化する暗号アルゴリズム
と、
を含み、
前記第1雑音は、
にしたがって、nビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、nビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのn次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンス生成部は、第1雑音e*、チャレンジmを用いて、ノイジーチャレンジv
を生成し、ノイジーチャレンジvを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データs(v)を用いてチャレンジmの暗号化を実行し、第2雑音eを付加することで、レスポンス
を生成し、
前記ローカルレスポンス生成部は、各第1雑音候補
と、チャレンジmを用いて、ノイジーチャレンジ
を生成し、ノイジーチャレンジを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データを用いてチャレンジmの暗号化を実行して、ローカルレスポンス
を生成し、
前記認証判定部は、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る。
n次元のバイナリベクトルを暗号化する暗号アルゴリズム
と、
を含み、
前記第1雑音は、
にしたがって、nビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、nビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのn次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンス生成部は、第1雑音e*、チャレンジmを用いて、ノイジーチャレンジv
を生成し、ノイジーチャレンジvを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データs(v)を用いてチャレンジmの暗号化を実行し、第2雑音eを付加することで、レスポンス
を生成し、
前記ローカルレスポンス生成部は、各第1雑音候補
と、チャレンジmを用いて、ノイジーチャレンジ
を生成し、ノイジーチャレンジを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データを用いてチャレンジmの暗号化を実行して、ローカルレスポンス
を生成し、
前記認証判定部は、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る。
本発明では、計算機資源が乏しいデバイスである証明者は、軽量な行列計算を行い、計算機資源が豊かなデバイスである検証者は、軽量ではないベクトル評価を含む検証演算を行うことで、計算資源に応じた非対称的な方式とし、安全性を確保しつつ、負荷の高い処理を計算機資源が豊かなデバイス側へ偏らせることによって、計算機資源の乏しいデバイス側の動作コストを低くした。したがって、証明者の計算機資源が検証者のそれよりも圧倒的に乏しい場合、例えば、証明者がタグやセンサーであっても問題にならないほど十分に軽量で、かつ、暗号理論的に十分な安全性を備えた認証プロトコルを提供することができる。
[A]非対称計算機資源環境
本実施形態は、非対称計算機資源環境における認証方法及びシステムに関する。非対称計算機資源環境とは、タグやセンサー等の計算機資源の乏しいデバイスが、PCのような計算機資源豊かなデバイスと暗号通信を行う環境である。図2に示すように、本実施形態に係る認証は、検証者としての第1デバイス(認証デバイス)と証明者としての第2デバイス(被認証デバイス)との間で行われる。第1デバイス、第2デバイスは共にコンピュータを含んでいると共に、通信機能(典型的には無線通信機能)を備えている。コンピュータは、ハードウェアとして、入力部、記憶部、処理部(演算部ないしCPU)、出力部等を備えており、ソフトウェア(コンピュータプログラム)によって所定の処理を実行する。
本実施形態は、非対称計算機資源環境における認証方法及びシステムに関する。非対称計算機資源環境とは、タグやセンサー等の計算機資源の乏しいデバイスが、PCのような計算機資源豊かなデバイスと暗号通信を行う環境である。図2に示すように、本実施形態に係る認証は、検証者としての第1デバイス(認証デバイス)と証明者としての第2デバイス(被認証デバイス)との間で行われる。第1デバイス、第2デバイスは共にコンピュータを含んでいると共に、通信機能(典型的には無線通信機能)を備えている。コンピュータは、ハードウェアとして、入力部、記憶部、処理部(演算部ないしCPU)、出力部等を備えており、ソフトウェア(コンピュータプログラム)によって所定の処理を実行する。
本実施形態では、第1デバイスは計算機資源(CPU、メモリ等)が豊かであり、第2デバイスは計算機資源が乏しい。第1デバイスは第2デバイスよりも処理能力(計算能力)が高く、また、第2デバイスはより小さい消費電力で動作可能である。第1デバイスとしては、PC(デスクトップ、ラップトップ、ノートブック等)、サーバ、モバイルコンピュータ(スマートフォン、携帯電話、PDA、タブレット、所定の計算機資源を備えたウェラブルコンピュータ等)、タグリーダ等が例示される。第2デバイスとしては、センサー(IC内蔵)、RFIDタグ、ICタグ、ICカード、ウェアラブルコンピュータが例示される。
[B]認証システム
図3、図4に示すように、認証システムは、証明者である被認証デバイスと、検証者である認証デバイスと、を備えたチャレンジ・レスポンス認証システムである。被認証デバイスと認証デバイスが秘密データを含む共通情報を共有し、認証デバイスはチャレンジを生成して当該チャレンジを被認証デバイスに送信し、チャレンジを受信した被認証デバイスは、受信したチャレンジ及び秘密データを用いて、所定の処理を実行してレスポンスを生成して当該レスポンスを認証デバイスに送信し、レスポンスを受信した認証デバイスは、チャレンジ及び秘密データを用いて、所定の処理を事項してローカルレスポンスを生成し、被認証デバイスから受信したレスポンスと認証デバイスで生成したローカルレスポンスとを比較して、受信したレスポンスを評価し、当該レスポンスを受け入れるか否かを判定する。
図3、図4に示すように、認証システムは、証明者である被認証デバイスと、検証者である認証デバイスと、を備えたチャレンジ・レスポンス認証システムである。被認証デバイスと認証デバイスが秘密データを含む共通情報を共有し、認証デバイスはチャレンジを生成して当該チャレンジを被認証デバイスに送信し、チャレンジを受信した被認証デバイスは、受信したチャレンジ及び秘密データを用いて、所定の処理を実行してレスポンスを生成して当該レスポンスを認証デバイスに送信し、レスポンスを受信した認証デバイスは、チャレンジ及び秘密データを用いて、所定の処理を事項してローカルレスポンスを生成し、被認証デバイスから受信したレスポンスと認証デバイスで生成したローカルレスポンスとを比較して、受信したレスポンスを評価し、当該レスポンスを受け入れるか否かを判定する。
認証デバイスは、秘密データを含む共通情報を格納する共通情報記憶部と、雑音生成部と、チャレンジ生成部と、ローカルレスポンス生成部と、認証判定部と、を備えている。被認証デバイスは、秘密データを含む共通情報を格納する共通情報記憶部と、雑音生成部と、レスポンス生成部と、を備えている。後述する認証プロトコルIでは、さらに、コミットメント生成部を備えている。認証デバイス及び被認証デバイスは、共に、データの送受信部を備えている。
被認証デバイスの雑音生成部は、強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成する。認証デバイスの雑音生成部は、強度制限の厳しい雑音の候補を網羅的に生成する雑音候補生成部である。後述する実施形態では、雑音生成部は、バイナリベクトルを生成するバイナリベクトル生成部であり、
被認証デバイスのレスポンス生成部は、当該被認証デバイスが生成した第1雑音及び第2雑音と、認証デバイスから受信したチャレンジと、共通情報と、を用いてレスポンスを生成する。レスポンスの生成アルゴリズムは、軽量な計算で実行できる処理である。
被認証デバイスにおけるレスポンス生成処理は、「認証デバイスが生成して被認証デバイスに送信したチャレンジ」と、「被認証デバイスが生成し、認証デバイスには送信しない、2つの雑音(強度制限の厳しい雑音と厳しくない雑音)」と、を用いて(プロトコルIでは「被認証デバイスが生成して認証デバイスに送信したコミットメント」も用いて)、認証デバイスが現実的な負荷(図4のmoderate complexity processing)で検証可能な範囲で、かつ、攻撃者が十分な情報を得られない強度で、秘密情報から部分情報を抽出してスクランブルを施したレスポンスを生成するものである。
認証デバイスのローカルレスポンス生成部は、当該認証デバイスが網羅的に生成した雑音候補と、当該認証デバイスが生成したチャレンジと、共通情報と、を用いてローカルレスポンスを生成する。認証デバイスの認証判定部は、雑音候補を網羅的に用いて生成されたローカルレスポンスと、前記被認証デバイスから受信したレスポンスと、を比較して、認証を判定する。認証デバイスにおける処理は、強度制限の厳しい雑音の候補を網羅的にテストするだけで、強度制限の厳しくない雑音の候補を考えることなく、実行できる処理である。
図4に本実施形態に係る認証フレームワークを示す。認証フレームワークは、図4に示す複数のボックスから構成されており、これらのボックスは、「共通秘密データ(shared secret data)」、「コミットメント(commitment)」、「チャレンジ(challenge)」、「証明者における軽量な処理(lightweight processing P)」、「レスポンス(response)」、「検証者における無理の無い程度の複雑な処理(moderate complexity processing V)」、「認証結果(authentication result)」からなり、後述する本実施形態に係るそれぞれの認証プロトコルでは、所定のボックスにおいて異なる設計や構成が採用される。
本実施形態は、「共通秘密データ」、「証明者における処理」、「レスポンス」、「検証者における処理」において新規の設計/構成を備えている。本実施形態は、特に、「証明者(被認証デバイス)における処理P(図5、図6参照)」、「検証者(認証デバイス)における処理V(図7、図8参照)」に特徴を有している。それによって、本実施形態に係る認証プロトコルは、以下の要求に対応することができる。
(a)図2に示す非対称計算機資源環境下での認証シナリオに適合するものであること、
(b)証明者と検証者との間に実装の複雑性(implementation complexities)のトレードオフを解決するものであること、
(c)以下の2つの概念に基づく認証の高い安全性を提供するものであること、
- LPN問題とランダムセレクション問題の組み合わせ、
- 適切な暗号、ランダムセレクション、暗号文のランダム化の組み合わせ。
(a)図2に示す非対称計算機資源環境下での認証シナリオに適合するものであること、
(b)証明者と検証者との間に実装の複雑性(implementation complexities)のトレードオフを解決するものであること、
(c)以下の2つの概念に基づく認証の高い安全性を提供するものであること、
- LPN問題とランダムセレクション問題の組み合わせ、
- 適切な暗号、ランダムセレクション、暗号文のランダム化の組み合わせ。
[C]認証プロトコル
本実施形態に係る認証プロトコルは、認証プロトコルIと、認証プロトコルIIからなる。認証プロトコルIは、(i) LPN問題と、(ii)ランダムセレクション問題 の2つの問題の組み合わせに基づいた認証セキュリティを提供するものであり、認証プロトコルIIは、(i)適切な暗号アルゴリズム(ストリーム暗号)、(ii) ランダムセレクションパラダイム、(iii)暗号文のランダム化、の組み合わせに基づいた認証セキュリティを提供するものである。
本実施形態に係る認証プロトコルは、認証プロトコルIと、認証プロトコルIIからなる。認証プロトコルIは、(i) LPN問題と、(ii)ランダムセレクション問題 の2つの問題の組み合わせに基づいた認証セキュリティを提供するものであり、認証プロトコルIIは、(i)適切な暗号アルゴリズム(ストリーム暗号)、(ii) ランダムセレクションパラダイム、(iii)暗号文のランダム化、の組み合わせに基づいた認証セキュリティを提供するものである。
演算子
は、
●与えられたmxnのバイナリ行列(各要素は0または1)
ここで、
は行列Sのi番目の行、
●m次元のバイナリベクトルe*、
●n次元のバイナリベクトルc、
について、以下の手順で、mxnバイナリ行列S*、m次元バイナリベクトルs*を返すものである。
は、
●与えられたmxnのバイナリ行列(各要素は0または1)
ここで、
は行列Sのi番目の行、
●m次元のバイナリベクトルe*、
●n次元のバイナリベクトルc、
について、以下の手順で、mxnバイナリ行列S*、m次元バイナリベクトルs*を返すものである。
すなわち、一般的に表現すると、演算子
は、「秘密データS」、「バイナリベクトルe* (本実施形態では、ベクトルe*によって規定されるランダム行列E*が生成されるが、ランダム化の具体的な計算は本実施形態に限定されない)」、「チャレンジc」、を入力として、「ランダム化された秘密データS*」、「ランダム化されたチャレンジs*」、を出力する。
は、「秘密データS」、「バイナリベクトルe* (本実施形態では、ベクトルe*によって規定されるランダム行列E*が生成されるが、ランダム化の具体的な計算は本実施形態に限定されない)」、「チャレンジc」、を入力として、「ランダム化された秘密データS*」、「ランダム化されたチャレンジs*」、を出力する。
[C-2]認証プロトコルI
[共有情報]
証明者と検証者との間で共有されるデータは、
●行列形式(m×n次元バイナリ行列)の秘密鍵S、
●パラメータ
m,n:次元数、
Δ:バイナリベクトル生成時の重み(「1」の数)の上限、
τ,τ*:ベルヌーイ分布において「1」を生成する確率、
thr:認証の合否を決定する閾値、
である。
[共有情報]
証明者と検証者との間で共有されるデータは、
●行列形式(m×n次元バイナリ行列)の秘密鍵S、
●パラメータ
m,n:次元数、
Δ:バイナリベクトル生成時の重み(「1」の数)の上限、
τ,τ*:ベルヌーイ分布において「1」を生成する確率、
thr:認証の合否を決定する閾値、
である。
[ステップ1]
証明者は、ランダムに生成されたn次元バイナリベクトルであるコミットメントメッセージrを生成し、検証者に送信する。
証明者は、ランダムに生成されたn次元バイナリベクトルであるコミットメントメッセージrを生成し、検証者に送信する。
[ステップ2]
検証者は、ランダムに生成されたn次元バイナリベクトルであり、重みがΔよりも大きいチャレンジメッセージcを生成し、証明者に送信する。
検証者は、ランダムに生成されたn次元バイナリベクトルであり、重みがΔよりも大きいチャレンジメッセージcを生成し、証明者に送信する。
[ステップ3]
証明者は、検証者からチャレンジメッセージcを受信すると、以下の手順でレスポンスを生成する(図4における処理P)。
証明者は、検証者からチャレンジメッセージcを受信すると、以下の手順でレスポンスを生成する(図4における処理P)。
[セレクト(選択)]
●e*の生成
証明者は、mビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成する。
の場合(e*のうち1の立っているビットがΔ個より多ければ)には、新しいe*を生成し、その重みが条件
を満たすまで、新しいe*を生成して再チェックする(Δ個以下になるまで繰り返す)。
●eの生成
証明者は、mビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成する。
●e*の生成
証明者は、mビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成する。
の場合(e*のうち1の立っているビットがΔ個より多ければ)には、新しいe*を生成し、その重みが条件
を満たすまで、新しいe*を生成して再チェックする(Δ個以下になるまで繰り返す)。
●eの生成
証明者は、mビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成する。
認証プロトコルIで採用されるバイナリベクトルe* 、eにおいて、e*は、データのランダム化のための第1系列(ベクトル)、すなわち、第1雑音であり、eは、データのランダム化のための第2系列(ベクトル)、すなわち、第2雑音である。第1雑音(e*)は、強度制限のより厳しい雑音であり、第2雑音(e)は、強度制限がより厳しくない雑音、である。
図5を参照しつつ、証明者(被認証デバイス)における処理Pをより具体的に説明する。ブロック「ランダムセレクション(Random selection)」において第1雑音e*が生成される。ブロック「秘密データのマッピング(Mapping of secret data)」において、生成された第1雑音e*を用いて、秘密データ(秘密鍵)Sのマッピング
が実行され、ランダム化された秘密データS*を得る。ここで、E*は、ベクトルe*によって規定されるランダム行列である。
が実行され、ランダム化された秘密データS*を得る。ここで、E*は、ベクトルe*によって規定されるランダム行列である。
ブロック「レスポンスの評価(Evaluation of response)」において、生成された第1雑音e*により規定されるランダム行列E*を用いて、チャレンジcのランダム化
が実行され、ランダム化されたチャレンジs*を得る。
が実行され、ランダム化されたチャレンジs*を得る。
[送信]
証明者は、レスポンスzを検証者に送信する。
証明者は、レスポンスzを検証者に送信する。
[ステップ4]
検証者は、レスポンスzを受信すると、以下の手順で認証の成否を決定する(図4における処理V)。
検証者は、レスポンスzを受信すると、以下の手順で認証の成否を決定する(図4における処理V)。
検証者は、e*について、m次元から「1」である要素をΔ個選んで得られる組合せ、すなわち、
個のm次元バイナリベクトル(重みΔ)を、e*の候補
として生成し、演算子Oを用いて行列S*及びベクトルs*を以下のように評価する。
であり、
である。
個のm次元バイナリベクトル(重みΔ)を、e*の候補
として生成し、演算子Oを用いて行列S*及びベクトルs*を以下のように評価する。
であり、
である。
検証者は、候補として検討されたすべての
について
を満たす場合には、レスポンスzを許可して認証を受け入れ(合格)、そうでない場合には、レスポンスzは拒否され、認証を棄却(不合格)とする。
ここで、thrは事前に設定された閾値であり、thr<<m/2である。
について
を満たす場合には、レスポンスzを許可して認証を受け入れ(合格)、そうでない場合には、レスポンスzは拒否され、認証を棄却(不合格)とする。
ここで、thrは事前に設定された閾値であり、thr<<m/2である。
図6を参照しつつ、検証者(認証デバイス)における処理Vをより具体的に説明する。ブロック「ランダムセレクションにおける仮定の設定(Setting a hypothesis on random selection)」において第1雑音の候補
が生成される。
が生成される。
ブロック「秘密データのマッピング(Mapping of secret data)」において、生成された第1雑音の候補
用いて、秘密データ(秘密鍵)Sのマッピング
が実行され、ランダム化された秘密データS*を得る。ここで、E*は、ベクトル
によって規定されるランダム行列である。
用いて、秘密データ(秘密鍵)Sのマッピング
が実行され、ランダム化された秘密データS*を得る。ここで、E*は、ベクトル
によって規定されるランダム行列である。
ブロック「マッピングされた秘密データを用いた評価(Evaluation employing mapped secret data)」において、マッピング(ランダム化)された秘密データS*と、コミットメントrと、を用いて、
が生成される。
が生成される。
ブロック「ローカルで生成されたレスポンス推定の評価(Evaluation of locally generated response estimation)」において、生成された第1雑音の候補
により規定されるランダム行列E*を用いて、チャレンジcのランダム化
が実行され、s*を得る。ブロック「マッピングされた秘密データを用いた評価」で生成された
と、ランダム化されたチャレンジs*と、からローカルレスポンス
が生成される。
により規定されるランダム行列E*を用いて、チャレンジcのランダム化
が実行され、s*を得る。ブロック「マッピングされた秘密データを用いた評価」で生成された
と、ランダム化されたチャレンジs*と、からローカルレスポンス
が生成される。
[C-3]認証プロトコルII
[共有情報]
証明者と検証者との間で共有される情報は、
●秘密ベクトル
●n次元のバイナリベクトルを暗号化する暗号(ストリーム暗号)アルゴリズム
●パラメータ
l,n:次元数、
Δ:バイナリベクトル生成時の重み(「1」の数)の上限、
τ,τ*:ベルヌーイ分布において「1」を生成する確率、
thr:認証の合否を決定する閾値、
である。
[共有情報]
証明者と検証者との間で共有される情報は、
●秘密ベクトル
●n次元のバイナリベクトルを暗号化する暗号(ストリーム暗号)アルゴリズム
●パラメータ
l,n:次元数、
Δ:バイナリベクトル生成時の重み(「1」の数)の上限、
τ,τ*:ベルヌーイ分布において「1」を生成する確率、
thr:認証の合否を決定する閾値、
である。
[ステップ1]
検証者は、n次元バイナリベクトルであるメッセージmを証明者に送信する。
検証者は、n次元バイナリベクトルであるメッセージmを証明者に送信する。
[ステップ2]
証明者は、検証者からメッセージmを取得すると、以下の手順でレスポンスを生成する(図4における処理P)。
証明者は、検証者からメッセージmを取得すると、以下の手順でレスポンスを生成する(図4における処理P)。
[セレクト(選択)]
●e*の生成
証明者は、nビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成する。
の場合(e*のうち1の立っているビットがΔ個より多ければ)には、新しいe*を生成し、その重みが条件
を満たすまで、新しいe*を生成して再チェックする(Δ個以下になるまで繰り返す)。
●eの生成
証明者は、nビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成する。
●e*の生成
証明者は、nビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成する。
の場合(e*のうち1の立っているビットがΔ個より多ければ)には、新しいe*を生成し、その重みが条件
を満たすまで、新しいe*を生成して再チェックする(Δ個以下になるまで繰り返す)。
●eの生成
証明者は、nビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成する。
認証プロトコルIIで採用されるバイナリベクトルe* 、eにおいて、e*は、ランダム化のための第1系列(ベクトル)、すなわち、第1雑音であり、eは、ランダム化のための第2系列(ベクトル)、すなわち、第2雑音である。第1雑音(e*)は、強度制限のより厳しい雑音であり、第2雑音(e)は、強度制限がより厳しくない雑音、である。
[評価]
証明者は、メッセージmに生成されたe*(第1雑音)を加えることでvを生成し、s0に「vの第i成分が1であるようなsi(i=1, 2, …, n)」をビット毎の排他的論理和で足し合わせていき、その結果をs(v)とする。s(v)を暗号アルゴリズムによるスクランブルで鍵として利用してレスポンスzを得る。
証明者は、メッセージmに生成されたe*(第1雑音)を加えることでvを生成し、s0に「vの第i成分が1であるようなsi(i=1, 2, …, n)」をビット毎の排他的論理和で足し合わせていき、その結果をs(v)とする。s(v)を暗号アルゴリズムによるスクランブルで鍵として利用してレスポンスzを得る。
図7を参照しつつ、証明者(被認証デバイス)における処理Pをより具体的に説明する。ブロック「ランダムセレクション(Random selection)」において第1雑音e*が生成される。ブロック「秘密データのマッピング(Mapping of secret data)」において、生成された第1雑音e*、認証デバイスから受信したチャレンジmを用いて、ノイジーチャレンジv
が生成され、ノイジーチャレンジvを用いて、秘密データ(秘密鍵)sのマッピングが実行され、マッピングされた秘密データs(v)
を得る。
が生成され、ノイジーチャレンジvを用いて、秘密データ(秘密鍵)sのマッピングが実行され、マッピングされた秘密データs(v)
を得る。
ブロック「軽量暗号化及び加法性雑音(Lightweight Encryption & Additive noise)」において、マッピングされた秘密データs(v)を用いてチャレンジmの暗号化が実行され、暗号化(スクランブル)チャレンジEs(v)(m)が生成され、生成された第2雑音eを用いて、レスポンスz
が生成される。
が生成される。
[送信]
証明者は、レスポンスzを送信する。
証明者は、レスポンスzを送信する。
[ステップ3]
検証者は、レスポンスzを受信すると、以下の手順で認証の成否を決定する(図4における処理V)。
検証者は、レスポンスzを受信すると、以下の手順で認証の成否を決定する(図4における処理V)。
検証者は、e*について、n次元から「1」である要素をΔ個選んで得られる組合せ、すなわち、
個のn次元バイナリベクトル(重みΔ)を、e*の候補
として生成し、各候補について、
を計算し、その結果にしたがって各候補を評価する。
個のn次元バイナリベクトル(重みΔ)を、e*の候補
として生成し、各候補について、
を計算し、その結果にしたがって各候補を評価する。
検証者は、候補として検討されたすべての
について
を満たす場合には、レスポンスzを許可して認証受け入れ(合格)、そうでない場合には、レスポンスzは拒否され、認証を棄却(不合格)とする。
ここで、thrは予め設定された閾値であり、thr<<n/2である。
について
を満たす場合には、レスポンスzを許可して認証受け入れ(合格)、そうでない場合には、レスポンスzは拒否され、認証を棄却(不合格)とする。
ここで、thrは予め設定された閾値であり、thr<<n/2である。
図8を参照しつつ、検証者(認証デバイス)における処理Vをより具体的に説明する。ブロック「ランダムセレクションにおける仮定の設定(Setting a hypothesis on random selection)」において雑音e*の候補
が生成される。
が生成される。
ブロック「秘密データのマッピング(Dedicated secret data mapping)」において、生成された雑音e*の候補
と、チャレンジmを用いて、ノイジーチャレンジ
が生成され、ノイジーチャレンジを用いて、秘密データ(秘密鍵)sのマッピングが実行され、マッピングされた秘密データ
を得る。
と、チャレンジmを用いて、ノイジーチャレンジ
が生成され、ノイジーチャレンジを用いて、秘密データ(秘密鍵)sのマッピングが実行され、マッピングされた秘密データ
を得る。
ブロック「軽量暗号化及び加法性雑音(Lightweight Encryption & Additive noise)」において、マッピングされた秘密データを用いてチャレンジmの暗号化が実行され、暗号化(スクランブル)チャレンジ
が生成される。
が生成される。
[D]本実施形態に係る認証プロトコルと非特許文献に係るプロトコルとの対比
本実施形態に係る認証プロトコルは、非特許文献3、5及び1、2、4に開示された認証プロトコルの結果を考慮し、これらの開示事項の非自明な組み合わせに基づくものである。
本実施形態に係る認証プロトコルは、非特許文献3、5に開示されている幾つかの要素を採用するものであるが、非特許文献3、5に開示されている要素において、計算能力の乏しい当事者(通常は、証明者)のおける認証の軽量性をサポートできない要素、特に、
(i)非特許文献3における主要要素である長いバイナリベクト転置(permutation)、
(ii)非特許文献5における主要要素である非バイナリ有限体(non-binary finite field)における演算を含まない。
プロトコルの暗号セキュリティとより計算能力の高い当事者(通常は、検証者)における複雑性の実装とのトレードオフとして、ランダムセレクション手法を採用して計算能力の乏しい当事者におけるプロトコルの暗号セキュリティを確保する。
本実施形態の認証プロトコルの主要な技術的特徴を非特許文献3~5に開示された認証プロトコルにおける対応する要素と対比して示す。
本実施形態に係る認証プロトコルは、非特許文献3、5及び1、2、4に開示された認証プロトコルの結果を考慮し、これらの開示事項の非自明な組み合わせに基づくものである。
本実施形態に係る認証プロトコルは、非特許文献3、5に開示されている幾つかの要素を採用するものであるが、非特許文献3、5に開示されている要素において、計算能力の乏しい当事者(通常は、証明者)のおける認証の軽量性をサポートできない要素、特に、
(i)非特許文献3における主要要素である長いバイナリベクト転置(permutation)、
(ii)非特許文献5における主要要素である非バイナリ有限体(non-binary finite field)における演算を含まない。
プロトコルの暗号セキュリティとより計算能力の高い当事者(通常は、検証者)における複雑性の実装とのトレードオフとして、ランダムセレクション手法を採用して計算能力の乏しい当事者におけるプロトコルの暗号セキュリティを確保する。
本実施形態の認証プロトコルの主要な技術的特徴を非特許文献3~5に開示された認証プロトコルにおける対応する要素と対比して示す。
表2は、証明者側における支配的な演算を対比して示すものである。本実施形態に係る認証プロトコルは、非特許文献3における主要要素である長いバイナリベクト転置(permutation)、非特許文献5における主要要素である非バイナリ有限体における演算を含まない。
高性能な計算機だけでなく情報処理能力の低いウェラブルデバイスやセンサーなどのデバイスを含む複雑なネットワークシステムを構築し、ITが新たなサービスと市場を創出する期待が高まっている。本発明に係る認証プロトコルは、そのようなシステムのためのセキュリティ技術として利用可能である。
本発明に係る認証プロトコルでは、計算機資源の乏しいデバイス側の消費電力を大幅に抑えることができるため、応用範囲が格段に広まる。例えば、電力など重要インフラのセキュリティ、人への埋め込みもしくは携帯デバイスを活用したヘルスケアや高齢者向けサービス、様々なセンサーを活用した農業、漁業支援や災害対策システム、計算機を持ち歩かずとも利用可能な外出先での次世代クレジットカード決済など、市場の大きな応用しかもグローバルな市場への応用が期待できる。ウェアラブルデバイスを着用した作業員がロボットやセンサーと協調して働く制御システムなど、一見異なる応用に見えるものの融合もあり得る。それらの基盤技術として利用価値が高い。
Claims (10)
- 被認証デバイスと認証デバイスを備えた認証システムにおいて、
前記被認証デバイスは、
秘密鍵を含む共通情報を格納する記憶部と、
強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成する雑音生成部と、
レスポンス生成部と、
を備え、
前記認証デバイスは、
秘密鍵を含む共通情報を格納する記憶部と、
強度制限の厳しい第1雑音の候補を網羅的に生成する雑音候補生成部と、
チャレンジ生成部と、
ローカルレスポンス生成部と、
認証判定部と、
を備え、
前記被認証デバイスの前記レスポンス生成部は、当該被認証デバイスが生成した第1雑音及び第2雑音と、前記認証デバイスから受信したチャレンジと、前記共通情報と、を用いてレスポンスを生成し、
前記認証デバイスの前記ローカルレスポンス生成部は、当該認証デバイスが網羅的に生成した第1雑音候補と、当該認証デバイスが生成したチャレンジと、前記共通情報と、を用いてローカルレスポンスを生成し、
前記認証デバイスの前記認証判定部は、前記雑音候補を網羅的に用いて生成された前記ローカルレスポンスと、前記被認証デバイスから受信した前記レスポンスと、を比較して、認証を判定する、
認証システム。 - 前記第1雑音は、「1」の数がΔ個以下となるように生成されたNビット列のバイナリベクトルであり、
前記第2雑音は、ランダムに生成されたバイナリベクトルであり、
前記第1雑音候補は、「1」の数がΔ個となるように網羅的に生成されたNビット列群である、
請求項1に記載の認証システム。 - 前記雑音生成部は、
Nビット列からなるバイナリベクトルをランダムに生成するバイナリベクトル生成部と、
前記バイナリベクトル生成部により生成されたバイナリベクトルの「1」の数を重みとして抽出し、共通情報に含まれるパラメータΔと比較する判定部と、
を備え、
前記バイナリベクトル生成部により生成されたバイナリベクトルの重みがΔ個より多い場合には、バイナリベクトルの重みがΔ個以下になるまでバイナリベクトルの生成を繰り返し、バイナリベクトルの重みがΔ個以下となった時のバイナリベクトルを第1雑音とし、
前記バイナリベクトル生成部により生成された任意のバイナリベクトルを第2雑音とし、
前記雑音候補生成部は、重みΔの全てのNビット列のバイナリベクトルを生成して第1雑音候補とする、
請求項2に記載の認証システム。 - 前記被認証デバイスは、コミットメントを生成して、前記認証デバイスに送信し、
前記共通情報は、m×nバイナリベクトルである秘密鍵Sを含み、
前記第1雑音は、
にしたがって、mビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、mビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのm次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンス生成部は、演算子Oを用いて、
秘密データS、第1雑音e*、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、第2雑音e、コミットメントr、から、レスポンス
を生成し、
前記ローカルレスポンス生成部は、前記演算子Oを用いて、
秘密データS、各第1雑音候補
、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、コミットメントrから、ローカルレスポンス
を生成し、
前記認証判定部は、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る、
請求項1~3いずれか1項に記載の認証システム。 - 前記共通情報は、n次元バイナリベクトルである秘密鍵sと、
n次元のバイナリベクトルを暗号化する暗号アルゴリズム
と、
を含み、
前記第1雑音は、
にしたがって、nビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、nビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのn次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンス生成部は、第1雑音e*、チャレンジmを用いて、ノイジーチャレンジv
を生成し、ノイジーチャレンジvを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データs(v)を用いてチャレンジmの暗号化を実行し、第2雑音eを付加することで、レスポンス
を生成し、
前記ローカルレスポンス生成部は、各第1雑音候補
と、チャレンジmを用いて、ノイジーチャレンジ
を生成し、ノイジーチャレンジを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データを用いてチャレンジmの暗号化を実行して、ローカルレスポンス
を生成し、
前記認証判定部は、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る、
請求項1~3いずれか1項に記載の認証システム。 - 被認証デバイスと認証デバイスとの間の認証方法において、
前記被認証デバイスと前記認証デバイスは秘密鍵を含む共通情報を共有し、
前記認証デバイスはチャレンジを生成して前記被認証デバイスに送信し、
前記被認証デバイスは、強度制限の厳しい第1雑音、強度制限が緩い第2雑音を、それぞれ生成し、生成した第1雑音及び第2雑音と、前記認証デバイスから受信したチャレンジと、前記共通情報と、を用いてレスポンスを生成して、前記認証デバイスに送信し、
前記認証デバイスは、強度制限の厳しい第1雑音の候補を網羅的に生成し、生成した第1雑音候補と、当該認証デバイスが生成したチャレンジと、前記共通情報と、を用いてローカルレスポンスを生成し、生成したローカルレスポンスと、前記被認証デバイスから受信した前記レスポンスと、を比較して、認証を判定する、
認証方法。 - 前記第1雑音は、「1」の数がΔ個以下となるように生成されたNビット列のバイナリベクトルであり、
前記第2雑音は、ランダムに生成されたバイナリベクトルであり、
前記第1雑音候補は、「1」の数がΔ個となるように網羅的に生成されたNビット列群である、
請求項6に記載の認証方法。 - 前記第1雑音の生成は、ランダムに生成されたNビット列からなるバイナリベクトルの「1」の数を重みとして抽出し、生成されたバイナリベクトルの重みがΔ個より多い場合には、バイナリベクトルの重みがΔ個以下になるまでバイナリベクトルの生成を繰り返し、バイナリベクトルの重みがΔ個以下となった時のバイナリベクトルを第1雑音とするものであり、
前記第2雑音は、ランダムに生成された任意のバイナリベクトルであり、
前記第1雑音候補は、重みΔの全てのNビット列のバイナリベクトルを生成することで得られる、
請求項7に記載の認証システム。 - 前記被認証デバイスは、コミットメントを生成して、前記認証デバイスに送信し、
前記共通情報は、m×nバイナリベクトルである秘密鍵Sを含み、
前記第1雑音は、
にしたがって、mビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、mビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのm次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンスは、演算子Oを用いて、
秘密データS、第1雑音e*、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、第2雑音e、コミットメントr、から、レスポンス
を生成し、
前記ローカルレスポンス生成部は、前記演算子Oを用いて、
秘密データS、各第1雑音候補
、チャレンジc、を入力として、ランダム化された秘密データS*、ランダム化されたチャレンジs*、を出力するものであり、
ランダム化された秘密データS*、ランダム化されたチャレンジs*、コミットメントrから、ローカルレスポンス
を生成し、
前記認証デバイスは、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る、
請求項6~8いずれか1項に記載の認証方法。 - 前記共通情報は、n次元バイナリベクトルである秘密鍵sと、
n次元のバイナリベクトルを暗号化する暗号アルゴリズム
と、
を含み、
前記第1雑音は、
にしたがって、nビットのe*の各ビットをパラメータτ*のベルヌーイ分布にしたがって生起させてe*をランダムに生成し、その重みが条件
を満たすまで、新しいe*を生成することで得られ、
前記第2雑音は、
にしたがって、nビットのeの各ビットをパラメータτのベルヌーイ分布にしたがって生起させてeをランダムに生成することで得られ、
前記第1雑音候補は、
個の重みΔのn次元バイナリベクトルを、第1雑音e*の候補
として生成することで得られ、
前記レスポンスは、第1雑音e*、チャレンジmを用いて、ノイジーチャレンジv
を生成し、ノイジーチャレンジvを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データs(v)を用いてチャレンジmの暗号化を実行し、第2雑音eを付加することで、レスポンス
を生成し、
前記ローカルレスポンス生成部は、各第1雑音候補
と、チャレンジmを用いて、ノイジーチャレンジ
を生成し、ノイジーチャレンジを用いて、秘密データsのマッピングを実行して、マッピングされた秘密データ
を生成し、マッピングされた秘密データを用いてチャレンジmの暗号化を実行して、ローカルレスポンス
を生成し、
前記認証デバイスは、
にしたがって、すべての第1雑音候補
について
を満たす場合には、前記レスポンスを許可して認証を受け入る、
請求項6~8いずれか1項に記載の認証方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2016-010169 | 2016-01-21 | ||
| JP2016010169A JP6602210B2 (ja) | 2016-01-21 | 2016-01-21 | 認証システム及び方法 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017126642A1 true WO2017126642A1 (ja) | 2017-07-27 |
Family
ID=59361869
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2017/001845 Ceased WO2017126642A1 (ja) | 2016-01-21 | 2017-01-20 | 認証システム及び方法 |
Country Status (2)
| Country | Link |
|---|---|
| JP (1) | JP6602210B2 (ja) |
| WO (1) | WO2017126642A1 (ja) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7768232B2 (ja) | 2021-08-31 | 2025-11-12 | 日本電気株式会社 | 認証システム、被認証者装置、認証者装置、認証方法、および認証プログラム |
-
2016
- 2016-01-21 JP JP2016010169A patent/JP6602210B2/ja not_active Expired - Fee Related
-
2017
- 2017-01-20 WO PCT/JP2017/001845 patent/WO2017126642A1/ja not_active Ceased
Non-Patent Citations (3)
| Title |
|---|
| MIODRAG J. MIHALJEVIC ET AL.: "Lightweight Authentication Protocols Based on the LPN Problem and Random Selection", 2016 SYMPOSIUM ON CRYPTOGRAPHY AND INFORMATION SECURITY (SCIS 2016, vol. 2E1-5, 19 January 2016 (2016-01-19), pages 1 - 6 * |
| SINISA TOMOVIC ET AL.: "A Protocol for Provably Secure Authentication of Tiny Entity to a High Performance Computing One, Mathematical Problem in Engineering", vol. 2016, 2016, pages 1 - 9, XP055402574, Retrieved from the Internet <URL:https://www.hindawi.com/journals/mpe/2016/9289050/abs> [retrieved on 20170411] * |
| XUEDI SONG ET AL.: "The Simple Way to Enhance Security and Reduce Size of HB#", THE 29TH SYMPOSIUM ON CRYPTOGRAPHY AND INFORMATION SECURITY (SCIS 2012, vol. 4D2-3, 30 January 2012 (2012-01-30), pages 1 - 5 * |
Also Published As
| Publication number | Publication date |
|---|---|
| JP6602210B2 (ja) | 2019-11-06 |
| JP2017130855A (ja) | 2017-07-27 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Cao et al. | Chain-based covert data embedding schemes in blockchain | |
| Gasti et al. | Secure, fast, and energy-efficient outsourced authentication for smartphones | |
| Dubey et al. | Cyber security model to secure data transmission using cloud cryptography | |
| Khan et al. | Soteria: A quantum-based device attestation technique for Internet of Things | |
| Lucia et al. | Device authentication schemes in IoT: a review | |
| Shi et al. | A real quantum designated verifier signature scheme | |
| WO2018043573A1 (ja) | 鍵交換方法、鍵交換システム | |
| Mohsin et al. | Exploring the RFID mutual authentication domain | |
| Khan et al. | QuSIM-enhanced GSM security: A quantum prover authentication protocol (QuPAP) for mobile communication | |
| Goel et al. | LEOBAT: Lightweight encryption and OTP based authentication technique for securing IoT networks | |
| Roy et al. | FPGA-based dual-layer authentication scheme utilizing AES and ECC for unmanned aerial vehicles | |
| Kabir et al. | RIOT-based smart metering system for privacy-preserving data aggregation using watermarking and encryption | |
| Aguilera et al. | First end‐to‐end PQC protected DPU‐to‐DPU communications | |
| Roy et al. | A quantum safe user authentication protocol for the internet of things | |
| Jian et al. | Quantum identity authentication using a Hadamard gate based on a GHZ state | |
| JP6602210B2 (ja) | 認証システム及び方法 | |
| Ye et al. | Secure marine environment communication: A multiobject authentication protocol based on secret sharing | |
| Prajapat et al. | Quantum Safe Proxy Blind Signature Protocol Based on 3D Entangled GHZ‐Type States | |
| Atiyah et al. | Lightweight secure Approach for IOT Devices. | |
| Jafer et al. | Review on lightweight encryption algorithms for IoT devices | |
| Lai et al. | A hybrid quantum key distribution protocol for tele-care medicine information systems | |
| Ali-Pour et al. | PECMQ: Private and Encrypted Communications in IoT Systems Using PUFs and MQTT | |
| Arya et al. | Post-quantum image security: Challenges and opportunities | |
| Kumar et al. | LiSP: A lightweight signcryption using PHOTON hash for Internet-of-Things infrastructure | |
| Mihaljević et al. | An encryption technique for provably secure transmission from a high performance computing entity to a tiny one |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17741519 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17741519 Country of ref document: EP Kind code of ref document: A1 |















