<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ep-patent-document PUBLIC "-//EPO//EP PATENT DOCUMENT 1.5//EN" "ep-patent-document-v1-5.dtd">
<ep-patent-document id="EP10785020B9W1" file="EP10785020W1B9.xml" lang="en" country="EP" doc-number="2502381" kind="B9" correction-code="W1" date-publ="20150225" status="c" dtd-version="ep-patent-document-v1-5">
<SDOBI lang="en"><B000><eptags><B001EP>ATBECHDEDKESFRGBGRITLILUNLSEMCPTIESILTLVFIROMKCYALTRBGCZEEHUPLSK..HRIS..MTNORS..SM..................</B001EP><B003EP>*</B003EP><B005EP>J</B005EP><B007EP>JDIM360 Ver 1.28 (29 Oct 2014) -  2999001/0</B007EP></eptags></B000><B100><B110>2502381</B110><B120><B121>CORRECTED EUROPEAN PATENT SPECIFICATION</B121></B120><B130>B9</B130><B132EP>B1</B132EP><B140><date>20150225</date></B140><B150><B151>W1</B151><B155><B1551>de</B1551><B1552>Beschreibung</B1552><B1551>en</B1551><B1552>Description</B1552><B1551>fr</B1551><B1552>Description</B1552><B1551>de</B1551><B1552>Ansprüche DE</B1552><B1551>en</B1551><B1552>Claims DE</B1552><B1551>fr</B1551><B1552>Revendications DE</B1552><B1551>de</B1551><B1552>Ansprüche EN</B1552><B1551>en</B1551><B1552>Claims EN</B1552><B1551>fr</B1551><B1552>Revendications EN</B1552><B1551>de</B1551><B1552>Ansprüche FR</B1552><B1551>en</B1551><B1552>Claims FR</B1552><B1551>fr</B1551><B1552>Revendications FR</B1552></B155></B150><B190>EP</B190></B100><B200><B210>10785020.8</B210><B220><date>20101119</date></B220><B240><B241><date>20120611</date></B241></B240><B250>en</B250><B251EP>en</B251EP><B260>en</B260></B200><B300><B310>262602 P</B310><B320><date>20091119</date></B320><B330><ctry>US</ctry></B330></B300><B400><B405><date>20150225</date><bnum>201509</bnum></B405><B430><date>20120926</date><bnum>201239</bnum></B430><B450><date>20140430</date><bnum>201418</bnum></B450><B452EP><date>20131206</date></B452EP><B472><B475><date>20140430</date><ctry>AT</ctry><date>20140430</date><ctry>BE</ctry><date>20140730</date><ctry>BG</ctry><date>20140430</date><ctry>CY</ctry><date>20140430</date><ctry>DK</ctry><date>20140430</date><ctry>ES</ctry><date>20140430</date><ctry>FI</ctry><date>20140731</date><ctry>GR</ctry><date>20140430</date><ctry>HR</ctry><date>20140830</date><ctry>IS</ctry><date>20140430</date><ctry>LT</ctry><date>20140430</date><ctry>LV</ctry><date>20140730</date><ctry>NO</ctry><date>20140430</date><ctry>PL</ctry><date>20140901</date><ctry>PT</ctry><date>20140430</date><ctry>RS</ctry><date>20140430</date><ctry>SE</ctry></B475></B472><B480><date>20150225</date><bnum>201509</bnum></B480></B400><B500><B510EP><classification-ipcr sequence="1"><text>H04L   9/30        20060101AFI20131122BHEP        </text></classification-ipcr></B510EP><B540><B541>de</B541><B542>VERFAHREN FÜR EIGENSCHAFTSBASIERTE VERSCHLÜSSELUNG MIT ÖFFENTLICHEM SCHLÜSSEL IM ZUSAMMENHANG MIT EINER KONJUNKTIVEN LOGISCHEN EXPRESSION</B542><B541>en</B541><B542>METHOD FOR PUBLIC-KEY ATTRIBUTE-BASED ENCRYPTION WITH RESPECT TO A CONJUNCTIVE LOGICAL EXPRESSION.</B542><B541>fr</B541><B542>PROCÉDÉ DE CHIFFREMENT À CLÉ PUBLIQUE AVEC ATTRIBUTS RELATIVEMENT À UNE EXPRESSION LOGIQUE CONJONCTIVE</B542></B540><B560><B561><text>EP-A1- 2 068 489</text></B561><B562><text>DAN BONEH ET AL: "Collusion Resistant Broadcast Encryption with Short Ciphertexts and Private Keys", 1 January 2005 (2005-01-01), ADVANCES IN CRYPTOLOGY - CRYPTO 2005 LECTURE NOTES IN COMPUTER SCIENCE;;LNCS, SPRINGER, BERLIN, DE, PAGE(S) 258 - 275, XP019016555, ISBN: 978-3-540-28114-6 section 3.2</text></B562><B562><text>N. ATTRAPADUNGH. IMAI: "Conjunctive broadcast and attribute-based encryption", PAIRING-BASED CRYPTOGRAPHY - PAIRING 2009, THIRD INTERNATIONAL CONFERENCE, PALO ALTO, CA, USA, AUGUST 12-14, 2009, 14 August 2009 (2009-08-14), pages 248-265, XP019125129, cited in the application</text></B562></B560></B500><B700><B720><B721><snm>KARLOV, Alexandre</snm><adr><str>Promenade des Champs-Fréchets 2</str><city>CH-1217 Meyrin</city><ctry>CH</ctry></adr></B721><B721><snm>JUNOD, Pascal</snm><adr><str>Moulin de la Palaz 8</str><city>CH-1302 Vufflens-la-Ville</city><ctry>CH</ctry></adr></B721></B720><B730><B731><snm>Nagravision S.A.</snm><iid>101047091</iid><irf>P-14-755-EP</irf><adr><str>Route de Genève 22-24</str><city>1033 Cheseaux-sur-Lausanne</city><ctry>CH</ctry></adr></B731></B730><B740><B741><snm>Leman Consulting S.A.</snm><iid>100833764</iid><adr><str>Chemin de Précossy 31</str><city>1260 Nyon</city><ctry>CH</ctry></adr></B741></B740></B700><B800><B840><ctry>AL</ctry><ctry>AT</ctry><ctry>BE</ctry><ctry>BG</ctry><ctry>CH</ctry><ctry>CY</ctry><ctry>CZ</ctry><ctry>DE</ctry><ctry>DK</ctry><ctry>EE</ctry><ctry>ES</ctry><ctry>FI</ctry><ctry>FR</ctry><ctry>GB</ctry><ctry>GR</ctry><ctry>HR</ctry><ctry>HU</ctry><ctry>IE</ctry><ctry>IS</ctry><ctry>IT</ctry><ctry>LI</ctry><ctry>LT</ctry><ctry>LU</ctry><ctry>LV</ctry><ctry>MC</ctry><ctry>MK</ctry><ctry>MT</ctry><ctry>NL</ctry><ctry>NO</ctry><ctry>PL</ctry><ctry>PT</ctry><ctry>RO</ctry><ctry>RS</ctry><ctry>SE</ctry><ctry>SI</ctry><ctry>SK</ctry><ctry>SM</ctry><ctry>TR</ctry></B840><B860><B861><dnum><anum>EP2010067817</anum></dnum><date>20101119</date></B861><B862>en</B862></B860><B870><B871><dnum><pnum>WO2011061285</pnum></dnum><date>20110526</date><bnum>201121</bnum></B871></B870><B880><date>20120926</date><bnum>201239</bnum></B880></B800></SDOBI>
<description id="desc" lang="en"><!-- EPO <DP n="1"> -->
<heading id="h0001"><b>Field of the invention</b></heading>
<p id="p0001" num="0001">This invention refers to the field of broadcast encryption, in particular the way to manage authorization rights to access the content described by a logical expression in a broadcast system having a management center and a plurality of receiving devices which have certain characteristics.</p>
<heading id="h0002"><b>Introduction</b></heading>
<p id="p0002" num="0002">The area of broadcast encryption is well known in the art and was discussed for the first time by Fiat and Naor [1]. In this setting, the broadcasting center can send an encrypted message to a set of privileged (i.e., non-revoked) users which is a subset of the set of all possible receivers. Sometimes these terminals can be arranged according to some natural characteristics or attributes like their ZIP code based geographical location, their subscription to certain packages or their software version. Intuitively the broadcaster would like to broadcast to receivers which satisfy some of these properties in a more or less complex manner. For instance the broadcaster may want to enforce the access policy by sending the content only to receivers which are in (("New York") OR ("New Jersey")) AND (with a receiver's firmware not older than 2.1.1). It should be emphasized that in this scenario, the broadcaster does not know the receivers identities and broadcasts to a subsets of receivers according to a logical expression based on their characteristics contrary to the standard broadcast encryption model, where the center broadcasts to a specific subset of receivers by specifying explicitly their identities.</p>
<heading id="h0003"><b>Prior Art</b></heading>
<p id="p0003" num="0003">The notion of attribute-based encryption (ABE) where the center broadcasts to a subset of receivers in terms of descriptive attributes was introduced by Sahai and Waters in [2]. There are two types of ABE, namely: key-policy ABE where the access policy (also called the access structure) is specified in the private key and ciphertext-policy ABE where the access policy is specified in<!-- EPO <DP n="2"> --> the ciphertext. Bethencourt, Sahai and Waters proposed the first construction of a ciphertext-policy ABE in [3]. Current invention concerns only ciphertext-policy ABE schemes, which will be further referenced simply as ABE schemes.</p>
<p id="p0004" num="0004">Those skilled in the art would agree that a logical access policy can be expressed using <b>AND</b>, <b>OR</b> and <b>NOT</b> logical gates. These expressions can be generalized under two forms, namely the <i>disjunctive normal form</i> (DNF) and the <i>conjunctive normal form</i> (CNF). The CNF is the conjunction (in other words a logical <b>AND</b>) of clauses, where a clause is a disjunction (in other words a logical <b>OR</b>) of attributes. The DNF is the disjunction (a logical <b>OR</b>) of conjunctions (a logical <b>AND</b>) of attributes. The <b>NOT</b> gate can be only part of a single attribute. For a set of attributes <i>A</i><sub>1</sub>,<i>A</i><sub>2</sub>,..., <i>A<sub>n</sub></i> an example of a CNF expression would be: <i>(A</i><sub>1</sub> ∨ <i>A</i><sub>2</sub>, ∨ <i>A</i><sub>3</sub>) ∧ (<i>A</i><sub>4</sub> ∨ <i>A</i><sub>5</sub> ∨ ¬<i>A</i><sub>6</sub>) ∧ ... ∧ (<i>A</i><sub><i>n</i>-2</sub> ∨ ¬A<sub><i>n</i>-1</sub> ∨ ¬<i>A<sub>n</sub></i>) and an example of a DNF expression would be: (<i>A</i><sub>1</sub> ∧ ¬<i>A</i><sub>2</sub>¬ ∧ <i>A</i><sub>3</sub>) ∨ (¬<i>A</i><sub>4</sub> ∧ <i>A</i><sub>5</sub> ∧ <i>A</i><sub>6</sub>) ∨ ... ∨ <i>(A</i><sub><i>n</i>-2</sub> ∧ <i>A</i><sub><i>n</i>-1</sub> ∧ <i>¬A<sub>n</sub></i>). In the two examples above the symbol ∧ represents a logical <b>AND</b>, and the symbol ∨ represents a logical <b>OR</b>.</p>
<p id="p0005" num="0005">An important notion is the one of a monotonic logical expression. The expression is called monotonic if it can be defined as a composition of logical <b>ANDs</b> and <b>ORs</b>, but without any <b>NOTs</b>.</p>
<p id="p0006" num="0006">It should be noted that the prior art describes ABE schemes, methods and systems which operate with DNF types of logical expressions, most of the them being monotonic and restricted to a certain fixed number of clauses or attributes per such expression. For instance, recently, such methods were disclosed in [4],[5] and [6].</p>
<p id="p0007" num="0007">Those skilled in the art would notice that the crucial property of an ABE scheme is the so-called attribute-collusion resistance property. This is represented by the fact that provided two decryption keys <i>dk</i><sub><i>u</i><sub2>1</sub2></sub> and <i>dk</i><sub><i>u</i><sub2>2</sub2></sub> for attributes <i>A</i><sub>1</sub> and <i>A</i><sub>2</sub> respectively, such that the key <i>dk</i><sub><i>u</i><sub2>1</sub2></sub> is not able to decrypt<!-- EPO <DP n="3"> --> any ciphertext intended solely for <i>A</i><sub>2</sub> and vice-versa, these keys can not be used in any way in order to decrypt a cryptogram described by an expression <i>A</i><sub>1</sub> ∧ <i>A</i><sub>2</sub>.</p>
<heading id="h0004"><b>Problem to be solved</b></heading>
<p id="p0008" num="0008">The aim of the present invention is to address CNF types of logical expressions for ABE. The benefit of the present application is hence the possibility to efficiently perform ciphertext-policy ABE for CNF expressions with logical <b>AND</b>s and <b>OR</b>s, as well as logical <b>NOT</b>s.</p>
<heading id="h0005"><b>Brief description of the invention</b></heading>
<p id="p0009" num="0009">The aim is achieved thanks to a method for providing attribute-based encryption for conjunctive normal form (CNF) expressions, the said CNF expression consisting of at least one clause over a set of attributes, the said method consisting of a key generation engine, an encryption engine and a decryption engine, and comprising the steps of:
<ul id="ul0001" list-style="none" compact="compact">
<li>Generating by the key generation engine a random <i>g</i> ∈ <i>G</i>, where <i>G</i> is a prime order group of order <i>p</i>, four random values α,γ,β,<i>r</i> ∈<i><sub>R</sub> Z</i>/<i>p</i>Z<i>,</i> and for <i>i</i> = 1,2,..., <i>n, n</i> + 2,...,2<i>n</i> computing by the key generation engine 2n values <i>g<sub>i</sub></i> = <i>g<sup>a<sup2>i</sup2></sup></i> ∈ <i>G</i> and <i>v</i> = <i>g</i><sup>γ</sup> ∈ <i>G</i>.</li>
</ul></p>
<p id="p0010" num="0010">Generating by the encryption engine the encryption key <maths id="math0001" num=""><math display="inline"><mi mathvariant="italic">PK</mi><mo>=</mo><mfenced separators=""><msup><mi>g</mi><mi>r</mi></msup><mo>⁢</mo><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><mi>r</mi></msubsup><mo>⁢</mo><msup><mi>v</mi><mi>r</mi></msup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi>β</mi></msubsup><mo>⁢</mo><msub><mi>g</mi><mi>n</mi></msub></mfenced></math><img id="ib0001" file="imgb0001.tif" wi="78" he="10" img-content="math" img-format="tif" inline="yes"/></maths> consisting of 2n+3 group elements, n being the number expressing the size of the attribute set. For the abovementioned CNF expression over a set of attributes, CNF expression consisting of N clauses, generating by the encryption engine N random values <i>t</i><sub>1</sub>,<i>t</i><sub>2</sub>,...,<i>t<sub>N</sub></i> ∈<i><sub>R</sub></i> Z/<i>p</i>Z, computing by the encryption engine the value <maths id="math0002" num=""><math display="inline"><mi>t</mi><mo>=</mo><mstyle displaystyle="true"><munderover><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><msub><mi>t</mi><mi>i</mi></msub></math><img id="ib0002" file="imgb0002.tif" wi="17" he="14" img-content="math" img-format="tif" inline="yes"/></maths> mod <i>p</i>, generating by the encryption engine the cryptogram <maths id="math0003" num=""><math display="inline"><mi mathvariant="italic">hdr</mi><mo>=</mo><mfenced separators=""><msubsup><mi>g</mi><mi>n</mi><mi>t</mi></msubsup><mo>,</mo><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mn>1</mn></msub><mo>,</mo><mo>…</mo><mo>,</mo><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mi>N</mi></msub></mfenced></math><img id="ib0003" file="imgb0003.tif" wi="45" he="11" img-content="math" img-format="tif" inline="yes"/></maths> consisting of 2N+1 group elements with <maths id="math0004" num=""><math display="inline"><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mi>i</mi></msub><mo>=</mo><mfenced separators=""><msup><mi>g</mi><msub><mi mathvariant="italic">rt</mi><mi>i</mi></msub></msup><mo>⁢</mo><msup><mfenced separators=""><msup><mi>v</mi><mi>r</mi></msup><mstyle displaystyle="true"><munder><mo>∏</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>β</mi><mi>i</mi></msub></mrow></munder></mstyle><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi></mrow><mi>r</mi></msubsup></mfenced><msub><mi>t</mi><mi>i</mi></msub></msup></mfenced></math><img id="ib0004" file="imgb0004.tif" wi="51" he="20" img-content="math" img-format="tif" inline="yes"/></maths> for each clause β<i><sub>i</sub></i> in the abovementioned CNF<!-- EPO <DP n="4"> --> expression and generating the session key <i>SK</i> as <maths id="math0005" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi>β</mi></msubsup></mfenced><mi>t</mi></msup><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><mi>g</mi><mo>⁢</mo><mi>g</mi></mfenced><mrow><mi>β</mi><mo>⁢</mo><mi>r</mi><mo>⁢</mo><msup><mi>α</mi><mfenced separators=""><mi>n</mi><mo>+</mo><mn>1</mn></mfenced></msup><mo>⁢</mo><mi>t</mi></mrow></msup><mo>,</mo></math><img id="ib0005" file="imgb0005.tif" wi="59" he="10" img-content="math" img-format="tif" inline="yes"/></maths> wherein the said session key or parts thereof is used to derive a symmetric key to encrypt the message, or to encrypt the message with the said session key. Generating by the key generation engine a plurality of private decryption keys<maths id="math0006" num=""><math display="inline"><msub><mi mathvariant="italic">dk</mi><mi>u</mi></msub><mo>=</mo><mfenced separators=""><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup><mo>,</mo><msubsup><mi>g</mi><mn>1</mn><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><mo>,</mo><msubsup><mi>g</mi><mi>n</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><mo>,</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><msub><mi>d</mi><msub><mi>i</mi><mn>1</mn></msub></msub><mo>,</mo><mo>,</mo><msub><mi>d</mi><msub><mi>i</mi><mi>N</mi></msub></msub><mo>,</mo><msub><mi>d</mi><msub><mi>j</mi><mn>1</mn></msub></msub><mo>,</mo><mo>,</mo><msub><mi>d</mi><msub><mi>j</mi><mi>R</mi></msub></msub></mfenced></math><img id="ib0006" file="imgb0006.tif" wi="106" he="12" img-content="math" img-format="tif" inline="yes"/></maths> each of the said decryption keys explicitly associated with at least one positive attribute by the mean of the group element <maths id="math0007" num=""><math display="inline"><msub><mi>d</mi><msub><mi>i</mi><mi>j</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>i</mi><mi>j</mi></msub><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0007" file="imgb0007.tif" wi="18" he="10" img-content="math" img-format="tif" inline="yes"/></maths> and explicitly associated with at least one negative attribute by the means of the group element <maths id="math0008" num=""><math display="inline"><msub><mi>d</mi><msub><mi>j</mi><mi>k</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>j</mi><mi>k</mi></msub><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0008" file="imgb0008.tif" wi="19" he="11" img-content="math" img-format="tif" inline="yes"/></maths> wherein the value <i>s<sub>u</sub></i>, is a random group element and is unique for every decryption key.</p>
<heading id="h0006"><b>Brief description of the figure</b></heading>
<p id="p0011" num="0011">The method of the invention will be better understood thanks to the attached figures in which:
<ul id="ul0002" list-style="dash" compact="compact">
<li>the <figref idref="f0001">figure 1</figref> illustrates a broadcaster and a plurality of receivers</li>
<li>the <figref idref="f0001">figure 2</figref> illustrates a management center in communication with a plurality of receivers.</li>
</ul></p>
<heading id="h0007"><b>Detailed description of the invention</b></heading>
<p id="p0012" num="0012">The present invention relates to cryptographic systems and methods and provides an attribute collusion-resistant ciphertext-policy attribute-based encryption scheme for conjunctive normal form (CNF) expressions.</p>
<heading id="h0008">Bilinear Maps</heading>
<p id="p0013" num="0013">The present invention relies on bilinear maps (also called pairings in the related art). Let G and G<sub>T</sub> be two cyclic groups of prime order p and a generator <i>g</i> ∈ <i>G</i>. Let <i>e</i> : <i>G</i> × <i>G</i> → <i>G<sub>T</sub></i> be a non-degenerate bilinear map such that for all <i>x, y</i> ∈ <i>G</i> and <i>a, b</i> ∈ Z/<i>p</i>Z, we have <i>e</i>(<i>x<sup>a</sup></i>, <i>y<sup>b</sup></i>) = <i>e</i>(<i>x</i>,<i>y</i>)<i><sup>ab</sup></i> and <i>e</i>(<i>g</i>,<i>g</i>) ≠ 1. The function e(.,.) should be also efficiently computable. For example, such maps can be, for instance, Weil or Tate pairings on supersingular elliptic curves. Their usage and implementation is well-known<!-- EPO <DP n="5"> --> in the art. Weil and Tate pairings are provided here as examples and for the purpose of the preferred embodiment and it should be noted that any admissible pairing function e(.,.) with the above properties can be used. The preferred method involved in the computation of such a function will be the so-called Miller's algorithm for pairing calculation which is well known in the related art [7].</p>
<heading id="h0009">Choice of the parameters</heading>
<p id="p0014" num="0014">In the preferred embodiment we are using a supersingular elliptic curve <i>E</i>(<i>F<sub>p</sub></i>) with <i>p</i> ≡ 3 (mod 4) a prime number of at least 512 bits and the order of <i>E</i>(<i>F<sub>p</sub></i>) = <i>p</i>+1<i>.</i> The group of point on the elliptic curve <i>E</i>(<i>F<sub>p</sub></i>) should also have a subgroup of prime order q of at least 160 bits. The sizes of these parameters correspond to the (block cipher) security equivalent of 80 bits. The generation of such elliptic curves is well known in the related art. Hence the following map is defined based on the Tate pairing function: <maths id="math0009" num=""><math display="inline"><mi>E</mi><mfenced open="[" close="]"><mi>q</mi></mfenced><mo>×</mo><mi mathvariant="italic">Eʹ</mi><mfenced><msub><mi>F</mi><mi>p</mi></msub></mfenced><mo>→</mo><msubsup><mi>F</mi><msup><mi>p</mi><mn>2</mn></msup><mo>*</mo></msubsup><mo>,</mo></math><img id="ib0009" file="imgb0009.tif" wi="40" he="10" img-content="math" img-format="tif" inline="yes"/></maths> where <i>E</i>'(<i>F<sub>p</sub></i>) is defined to be the twisted curve and <i>E</i>[<i>q</i>] is the group of q-torsion points on E. Such parameters selection allows us to use a lightweight version of the Miller's algorithm along with arithmetic operations performed mostly in <i>F<sub>p</sub>,</i> which is much faster, contrary to traditional methods of using arithmetic in <i>F<sub>p<sup2>k</sup2></sub></i>. In fact, these methods are also well-known in the art and are disclosed in details in [8]. It should be noted that in this case the group G is represented by the q-torsion subgroup of <i>E</i>(<i>F<sub>p</sub></i>) and has the prime order q.</p>
<heading id="h0010">Preferred implementation of the scheme</heading>
<p id="p0015" num="0015">According to the preferred embodiment of the current invention we consider a system where receivers can be arranged according to some characteristics or attributes, such as geographical position, firmware version, etc. Let n be the total number of such characteristics or attributes and λ be the total number of receivers. Hence for the sake of the preferred embodiment we can name these characteristics with n literals <i>A</i><sub>1</sub>, <i>A</i><sub>2</sub>,<i>..., A<sub>n</sub></i>. The preferred implementation of the current invention includes three randomized algorithms, namely <i>KeyGen,<!-- EPO <DP n="6"> --> Encrypt</i> and <i>Decrypt</i> implemented on a computer or in a dedicated apparatus. It should be also noted that in the below preferred implementation we will use an additive group law notation which is also frequently used in the art.</p>
<p id="p0016" num="0016"><u>KeyGen algorithm</u> starts by generating a random point <i>G</i> ∈ <i>E</i>[<i>g</i>] by any well known mean of the art, as well as four random values α,γ,β,<i>r</i> ∈<i><sub>R</sub> Z</i>/<i>qZ.</i> Then for <i>i</i> = 1,2,..., <i>n, n</i>+2,...,2<i>n</i> the algorithm computes 2n-1 values <i>G<sub>i</sub></i> =α<i><sup>¡</sup>G</i> and <i>V</i> = γ<i>G.</i> The algorithm then generates a public encryption key <i>PK =</i> (<i>rG,rG</i><sub>1</sub>,...,<i>rG<sub>n</sub>,rG</i><sub><i>n</i>+2</sub>,...,<i>rG</i><sub><i>2</i>n</sub>,<i>rV</i>,β<i>G<sub>n</sub></i>,<i>G<sub>n</sub></i>) consisting of 2n+3 points in the group E[q]. The algorithm will also generate a plurality of individual private decryption keys for each of ℓ receivers as follows. First the algorithm generates by any known mean of the art a random value <i>s<sub>u</sub></i> ∈ <i>Z</i>/<i>qZ</i>. Then, for <i>i</i> = 1,2,...,<i>n,n</i>+2,...,2<i>n</i> it sets 2n-1 values <i>s<sub>u</sub>G</i><sub>1</sub>,...,<i>s<sub>u</sub>G<sub>n</sub>,s<sub>u</sub>G</i><sub><i>n</i>+2</sub>,...,<i>s<sub>u</sub>G<sub>2n</sub></i> and computes the value <i>r</i>(β + <i>s<sub>u</sub></i>)<i>G<sub>n</sub>.</i> Finally, for every defined property among <i>A</i><sub>1</sub>,<i>A</i><sub>2</sub>,...,<i>A</i><sub>n</sub> which characterizes the receiver, the algorithm computes N+R values <i>D</i><sub><i>¡</i><sub2>1</sub2></sub>,...,<i>D<sub>i<sub2>N</sub2></sub></i>,<i>D</i><sub><i>j</i><sub2>1</sub2></sub><i>,...,D<sub>j<sub2>R</sub2></sub></i> where <i>D<sub>i<sub2>j</sub2></sub> = γ · s<sub>u</sub>G<sub>i<sub2>j</sub2></sub></i> and <i>D<sub>j<sub2>k</sub2></sub> = γ · s<sub>u</sub>G<sub>j<sub2>k</sub2></sub>.</i> Hence the decryption key for an individual receiver, characterized by N+R properties among n, consists of 2n+N+R group elements (or in the case of the preferred embodiment - points on the elliptic curve <i>E</i>(<i>F<sub>p</sub></i>)), that is <i>dk<sub>u</sub>=</i> (<i>r</i>(<i>β</i> + <i>S<sub>u</sub></i>)<i>G</i><sub>1</sub>,<i>s<sub>u</sub>G</i><sub>1</sub>,...,<i>s<sub>u</sub>G<sub>n</sub></i>,<i>s<sub>u</sub>G</i><sub><i>n</i>+2</sub>,...,<i>s<sub>u</sub>G<sub>2<sub2>n</sub2></sub></i>,<i>D</i><sub><i>¡</i><sub2>1</sub2></sub>,...<i>D</i><sub><i>i<sub>N</sub></i>,</sub> <i>D</i><sub><i>j</i><sub2>1</sub2></sub>,.... <i>D<sub>j<sub2>R</sub2></sub></i>)<i>.</i> The said individual decryption key is loaded into the receiver, preferably by loading the said key into the secure and tamper-resistant non-volatile memory using methods known in the corresponding art.</p>
<p id="p0017" num="0017"><u>Encryption algorithm</u> is provided with an expression in CNF of the form β<sub>1</sub> ∧ β<sub>2</sub> ∧ ... ∧ β<i><sub>N</sub></i>, wherein every clause β<i><sub>i</sub></i> consists of a disjunction (logical <b>OR</b>s) of several attributes. First, the algorithm randomly generates N values <i>t<sub>1</sub>,...,t<sub>N</sub></i> ∈ Z/<i>q</i>Z by any well known mean of the art and computes the value <maths id="math0010" num=""><math display="inline"><mi>t</mi><mo>=</mo><mstyle displaystyle="true"><munderover><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><msub><mi>t</mi><mi>i</mi></msub></math><img id="ib0010" file="imgb0010.tif" wi="17" he="15" img-content="math" img-format="tif" inline="yes"/></maths> mod <i>q</i>. The encryption algorithm also computes the value <i>hdr</i><sub>0</sub> <i>= t · G<sub>n</sub></i>. The algorithm then computes for every clause β<i><sub>i</sub></i> a pair of values,<!-- EPO <DP n="7"> --> namely <i>hdr</i><sub>i,0</sub> = <i>t</i><sub>i</sub>r<i>G</i> and <maths id="math0011" num=""><math display="inline"><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>1</mn></mrow></msub><mo>=</mo><msub><mi>t</mi><mi>i</mi></msub><mo>⁢</mo><mfenced separators=""><mi mathvariant="italic">rV</mi><mo>+</mo><mstyle displaystyle="false"><mstyle displaystyle="true"><munder><mo>∑</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>β</mi><mi>i</mi></msub></mrow></munder></mstyle><msub><mi mathvariant="italic">rG</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi></mrow></msub></mstyle></mfenced><mn>.</mn></math><img id="ib0011" file="imgb0011.tif" wi="52" he="16" img-content="math" img-format="tif" inline="yes"/></maths> It should be noted that the value j corresponds to an attribute in the clause <sub>β<i>i</i></sub>. The said pair of values constitutes the i-th part of the cryptogram. After computing N-th such pair (for the last clause β<i><sub>N</sub></i>), the encryption algorithm computes the session key<maths id="math0012" num=""><math display="inline"><mi>S</mi><mo>⁢</mo><mi>K</mi><mspace width="1em"/><mo>=</mo><mspace width="1em"/><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><mi>r</mi><mo>⋅</mo><msub><mi>G</mi><mn>1</mn></msub><mo>,</mo><mi>β</mi><mo>⋅</mo><msub><mi>G</mi><mi>n</mi></msub></mfenced><mi>t</mi></msup><mspace width="1em"/><mo>=</mo><mspace width="1em"/><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><mi>G</mi><mo>⁢</mo><mi>G</mi></mfenced><msup><mrow><mi>β</mi><mo>⁢</mo><mi>r</mi><mo>⁢</mo><mi>α</mi></mrow><msub><mfenced separators=""><mi>n</mi><mo>+</mo><mn>1</mn></mfenced><mi>t</mi></msub></msup></msup><mn>.</mn></math><img id="ib0012" file="imgb0012.tif" wi="71" he="11" img-content="math" img-format="tif" inline="yes"/></maths> The resulting session key hence has a size of 1024 bits with the parameters of the preferred embodiment. The said session key is then hashed, in the context of the preferred embodiment, using the SHA-256 hash function known in the art. The resulting 128 less significant bits are used as the key for the AES algorithm in encryption mode, the said algorithm also well-known in the art, to encrypt video, audio or other useful messages. Finally, the encryption algorithm outputs the generated cryptogram <i>hdr</i> = (<i>hdr<sub>0</sub>, hdr<sub>i.0</sub>,hdr<sub>i,1</sub>,...,hdr</i><sub><i>N.</i>0</sub>,<i>hdr</i><sub><i>N</i>,1</sub>)<i>.</i> It should be noted, that the CNF expression is broadcasted along with the cryptogram and the useful message which is encrypted by mean of the session key above to the intended recipients.</p>
<heading id="h0011"><u>Decryption algorithm,</u> upon receiving the cryptogram</heading>
<p id="p0018" num="0018"><i>hdr</i> = (<i>hdr</i><sub>0</sub>,<i>hdr</i><sub><i>i</i>,0</sub>,<i>hdr</i><sub><i>i</i>,1</sub>,...,<i>hdr</i><sub><i>N,</i>0</sub>,<i>hdr</i><sub><i>N</i>,1</sub>), the corresponding expression in CNF and the useful encrypted message, examines the expression and determines whether or not the receiver fulfils the necessary conditions for decrypting the message. In the case where it does fulfil the necessary conditions, the decryption algorithm proceeds as follow. First, for every clause in the expression it computes the values <maths id="math0013" num=""><math display="inline"><msubsup><mi mathvariant="italic">SK</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>=</mo><mfrac><mrow><mi>e</mi><mfenced separators=""><msub><mi>s</mi><mi>u</mi></msub><mo>⋅</mo><msub><mi>G</mi><mi>k</mi></msub><mo>,</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>1</mn></mrow></msub></mfenced></mrow><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><msub><mi>D</mi><mi>k</mi></msub><mo>+</mo><mstyle displaystyle="false"><mstyle displaystyle="true"><munder><mo>∑</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>β</mi><mi>i</mi></msub><mo>,</mo><mi>j</mi><mo>≠</mo><mi>k</mi></mrow></munder></mstyle><msub><mi>s</mi><mi>u</mi></msub><mo>⋅</mo><msub><mi>G</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi><mo>+</mo><mi>k</mi></mrow></msub><mo>,</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>0</mn></mrow></msub></mstyle></mfenced></mrow></mfrac><mo>,</mo></math><img id="ib0013" file="imgb0013.tif" wi="72" he="24" img-content="math" img-format="tif" inline="yes"/></maths> where the values <i>D<sub>k</sub></i> are bonded to the characterizing attributes of the receiver, the said attributes being also listed in the clause β<i><sub>i</sub></i>. Each of such N computations is performed using two pairing function described above. After computing N such values <maths id="math0014" num=""><math display="inline"><msubsup><mi mathvariant="italic">SK</mi><mn>1</mn><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><mo>,</mo><msubsup><mi mathvariant="italic">SK</mi><mi>N</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo></math><img id="ib0014" file="imgb0014.tif" wi="30" he="14" img-content="math" img-format="tif" inline="yes"/></maths> the decryption algorithm computes the session key<!-- EPO <DP n="8"> --> as <maths id="math0015" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mfrac><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mn>0</mn></msub><mo>,</mo><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced><mo>⋅</mo><msub><mi>G</mi><mn>1</mn></msub></mfenced></mrow><mrow><mstyle displaystyle="true"><munderover><mo>∏</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><mi>S</mi><mo>⁢</mo><msubsup><mi>K</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup></mrow></mfrac><mn>.</mn></math><img id="ib0015" file="imgb0015.tif" wi="52" he="21" img-content="math" img-format="tif" inline="yes"/></maths> The said session key is then hashed, in the context of this preferred embodiment, using the SHA-256 hash function and the resulting 128 less significant bits are used as the key for the AES algorithm in decryption mode to decrypt the useful message.</p>
<p id="p0019" num="0019">The person skilled in the art would appreciate the fact that the encryption key is public, any party can use it to encrypt any useful contents with respect to any CNF expression and that the said encryption key can not be used to derive the session key or decrypt the useful message without fulfilling a given CNF expression by explicitly possessing the decryption keys corresponding to the said expression. Those familiar with the art would also appreciate the fact that the proposed method fulfills the attribute collusion-resistance property described above. Contrary to the existing schemes of the art, the present invention can support expressions of any number of clauses and attributes without any constraints. Also, the size of the header is linear in the number of clauses and does not depend on the number of the attributes in any clause or in the whole expression.</p>
<p id="p0020" num="0020">It is important to note that the use of the particular supersingular elliptic curve over the finite field of a given size, its prime order subgroup, the specific bilinear map function as defined above, its parameters, key sizes, the use of the SHA-256 hash function and AES encryption algorithm is solely defined for the purpose of the preferred embodiment of the present invention and is not, in any case, limiting. Any elliptic curve, or any other group where the bilinear map can be efficiently and securely computed for a given security parameter can be used for the purpose of the present invention. The useful message, such as (but not limited to) video or audio content, can be encrypted or scrambled by any cryptographically secure means using key or keys derived from the session key defined in the scope of the present invention.<!-- EPO <DP n="9"> --> The above broadcast encryption scheme can be used to transmit messages from a control center to a plurality of terminals. These messages contain initialization data pertaining to one terminal.</p>
<p id="p0021" num="0021">In the <figref idref="f0001">figure 2</figref>, the management center MC stores in its database DB a copy of the key materials sent in the receiving devices RD1, RD2, RD3. According to our example, two subscription packages B1, B2 have been defined, the first one being related to the positive key material K1 and the negative material K1', the second one being related to the positive key material K2 and the negative material K2'.</p>
<p id="p0022" num="0022">The receiving device RD1 being entitled to the subscription package B1 has received the key material K1. Due to the fact that this receiving device RD1 is not entitled to the subscription package B2, the key material K2' was also sent to it.</p>
<p id="p0023" num="0023">The receiving device RD2 being entitled to the subscription package B1 and B2, both key material K1 and K2 were sent to this device.</p>
<p id="p0024" num="0024">The receiving device RD2 being entitled to the Subscription package B2, the key material K2 was sent to it. Due to the fact that this receiving device RD3 is not entitled to the Subscription package B1, the key material K1' was also sent to it.</p>
<p id="p0025" num="0025">In case that the management center MC needs to transmit an access key K to only the receiving devices allowed to the second Subscription package B2 and not allowed to the first Subscription package B1, the cryptogram CY sent to the receiving devices RD will contain the access key combined with the negative key material K1' and the positive key material K2.</p>
<p id="p0026" num="0026">In the authorization message containing the cryptogram, another field into the message contains a descriptor of the keys to be used for the decryption. This can be in the form of two bitmap, each active bits defining a subscription package, and one bitmap for the positive keys and the other one for the negative keys. According to the implementation of the invention, it could<!-- EPO <DP n="10"> --> decided that the positive keys are used first to decrypt the cryptogram and then the negative keys.</p>
<p id="p0027" num="0027">The product key can release a single broadcast product, e.g. a film or can release a service for a day or a month.</p>
<p id="p0028" num="0028">The subscription package can refer to a plurality of services or a single service. The invention thus allows to define the access rule of this product by combining the access to the channel 3 (first subscription package) and not the channel 6 (second subscription package).</p>
<p id="p0029" num="0029">The invention has been described in detail with particular reference to the preferred embodiment thereof. It should be however understood that variations and modifications can be produced.<!-- EPO <DP n="11"> --></p>
<heading id="h0012"><b>REFERENCES</b></heading>
<p id="p0030" num="0030">
<ul id="ul0003" list-style="none">
<li>[1] <nplcit id="ncit0001" npl-type="b"><text>A. Fiat and M. Naor, "Broadcast encryption", CRYPTO'93, Lecture Notes in Computer Science 773, pp. 480491, Springer-Verlag, 1994</text></nplcit>.</li>
<li>[2] <nplcit id="ncit0002" npl-type="b"><text>A. Sahai and B. Waters. Fuzzy identity-based encryption. In Advances in Cryptology - EUROCRYPT 2005, 24th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Aarhus, Denmark, pages 457-473, 2005</text></nplcit>.</li>
<li>[3] <nplcit id="ncit0003" npl-type="s"><text>J. Bethencourt, A. Sahai, and B. Waters. Ciphertext-policy attribute-based encryption. In 2007 IEEE Symposium on Security and Privacy (S&amp;P 2007), 20-23 May 2007, Oakland, California, USA, pages 321-334, 2007</text></nplcit>.</li>
<li>[4] <nplcit id="ncit0004" npl-type="s" url="http://eprint.iacr.org/2008/290.pdf, 2008. Unpublished manuscript"><text>B. Waters. Ciphertext-policy attribute-based encryption: An expressive, efficient, and provably secure realization. http://eprint.iacr.org/2008/290.pdf, 2008. Unpublished manuscript</text></nplcit>.</li>
<li>[5] <nplcit id="ncit0005" npl-type="b"><text>D. Lubicz and T. Sirvent. Attribute-based broadcast encryption scheme made efficient. In S. Vaudenay et al., editor, Proc. of Advances in Cryptology - Africacrypt'08, volume 5023 of LNCS, pages 325-342. Springer-Verlag, 2008</text></nplcit>.</li>
<li>[6] <nplcit id="ncit0006" npl-type="s"><text>N. Attrapadung and H. Imai. Conjunctive broadcast and attribute-based encryption. In Pairing-Based Cryptography - Pairing 2009, Third International Conference, Palo Alto, CA, USA, August 12-14, 2009, pages 248-265, 2009</text></nplcit>.</li>
<li>[7] <nplcit id="ncit0007" npl-type="s" url="http://crypto.stanford.edu/miller/miller.pdf"><text>V. Miller. Short program for functions on curves. http://crypto.stanford.edu/miller/miller.pdf, 1986. Unpublished manuscript</text></nplcit>.</li>
<li>[8] <nplcit id="ncit0008" npl-type="b"><text>P. Barreto, H. Kim, B. Lynn, M. Scott. Efficient Algorithms for Pairing-Based Cryptosystems. In Advances in Cryptology- CRYPTO 2002, 22nd Annual International Cryptology Conference, pages 354-368, London, UK, 2002. Springer-Verlag</text></nplcit>.</li>
</ul></p>
</description>
<claims id="claims01" lang="en"><!-- EPO <DP n="12"> -->
<claim id="c-en-01-0001" num="0001">
<claim-text>A method for providing attribute-based encryption of a message using conjunctive normal form (CNF) expressions, the said CNF expression comprising at least one clause over a set of <i>n</i> attributes, the said method using a key generation engine, an encryption engine and a decryption engine, and comprising the steps of:
<claim-text>a. generating by the key generation engine: a random <i>g</i> ∈ <i>G</i>, where <i>G</i> is a group of order <i>p</i> where <i>p</i> is a prime number, four random values α,γ,β,<i>r</i>∈<i><sub>R</sub> Z</i>/<i>pZ</i>, and for <i>i =</i> 1,2,..., <i>n,n</i> + 2,...,2<i>n</i> where <i>n</i> is the number of attributes, computing by the key generation engine at least 2n-1 values <i>g<sub>i</sub></i> = g<sup>α<i><sup>i</sup></i></sup> ∈ <i>G</i> and at least one value <i>v = g<sup>γ</sup></i> ∈ <i>G</i>;</claim-text>
<claim-text>b. generating by the encryption engine an encryption key <maths id="math0016" num=""><math display="inline"><mi mathvariant="italic">PK</mi><mo>=</mo><mfenced separators=""><msup><mi>g</mi><mi>r</mi></msup><mo>⁢</mo><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><mi>r</mi></msubsup><mo>⁢</mo><msup><mi>v</mi><mi>r</mi></msup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi>β</mi></msubsup><mo>⁢</mo><msub><mi>g</mi><mi>n</mi></msub></mfenced></math><img id="ib0016" file="imgb0016.tif" wi="76" he="10" img-content="math" img-format="tif" inline="yes"/></maths> comprising at least 2n+3 group elements;</claim-text>
<claim-text>c. for an abovementioned CNF expression over a set of attributes, CNF expression comprising N clauses, generating by the encryption engine N random values <i>t</i><sub>1</sub>,<i>t</i><sub>2</sub>,...,<i>t<sub>N</sub></i> ∈<i><sub>R</sub> Z</i>/<i>pZ</i>, computing by the encryption engine the value <maths id="math0017" num=""><math display="inline"><mi>t</mi><mo>=</mo><mstyle displaystyle="true"><munderover><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><msub><mi>t</mi><mi>i</mi></msub></math><img id="ib0017" file="imgb0017.tif" wi="17" he="14" img-content="math" img-format="tif" inline="yes"/></maths> mod <i>p</i>, generating by the encryption engine a cryptogram <maths id="math0018" num=""><math display="inline"><mi mathvariant="italic">hdr</mi><mo>=</mo><mfenced separators=""><msubsup><mi>g</mi><mi>n</mi><mi>t</mi></msubsup><mo>,</mo><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mn>1</mn></msub><mo>,</mo><mo>…</mo><mo>,</mo><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mi>N</mi></msub></mfenced></math><img id="ib0018" file="imgb0018.tif" wi="44" he="10" img-content="math" img-format="tif" inline="yes"/></maths> consisting of at least 2N+1 group elements with <maths id="math0019" num=""><math display="inline"><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mi>i</mi></msub><mo>=</mo><mfenced separators=""><msup><mi>g</mi><msub><mi mathvariant="italic">rt</mi><mi>i</mi></msub></msup><mo>⁢</mo><msup><mfenced separators=""><msup><mi>v</mi><mi>r</mi></msup><mstyle displaystyle="true"><munder><mo>∏</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>υ</mi><mi>i</mi></msub></mrow></munder></mstyle><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi></mrow><mi>r</mi></msubsup></mfenced><msub><mi>t</mi><mi>i</mi></msub></msup></mfenced></math><img id="ib0019" file="imgb0019.tif" wi="53" he="19" img-content="math" img-format="tif" inline="yes"/></maths> for each clause υ<i><sub>i</sub></i> in the abovementioned CNF expression and generating a session key <i>SK</i>, wherein the said session key or parts thereof is used to derive a symmetric key which is used to encrypt the message, or to encrypt the message with the said session key;<!-- EPO <DP n="13"> --></claim-text>
<claim-text>d. generating by the key generation engine a plurality of private decryption keys <maths id="math0020" num=""><math display="inline"><msub><mi mathvariant="italic">dk</mi><mi>u</mi></msub><mo>=</mo><mfenced separators=""><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mn>1</mn><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>⁢</mo><msub><mi>d</mi><msub><mi>i</mi><mn>1</mn></msub></msub><mo>…</mo><msub><mi>d</mi><msub><mi>i</mi><mi>N</mi></msub></msub><mo>⁢</mo><msub><mi>d</mi><msub><mi>j</mi><mn>1</mn></msub></msub><mo>…</mo><msub><mi>d</mi><msub><mi>j</mi><mi>R</mi></msub></msub></mfenced></math><img id="ib0020" file="imgb0020.tif" wi="105" he="11" img-content="math" img-format="tif" inline="yes"/></maths> each of the said decryption keys explicitly associated with at least one positive attribute by the mean of the group element <maths id="math0021" num=""><math display="inline"><msub><mi>d</mi><msub><mi>i</mi><mi>j</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>i</mi><mi>j</mi></msub><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0021" file="imgb0021.tif" wi="17" he="9" img-content="math" img-format="tif" inline="yes"/></maths> and explicitly associated with at least one negative attribute by the means of the group element <maths id="math0022" num=""><math display="inline"><msub><mi>d</mi><msub><mi>j</mi><mi>k</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>j</mi><mi>k</mi></msub><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0022" file="imgb0022.tif" wi="17" he="9" img-content="math" img-format="tif" inline="yes"/></maths> wherein the value <i>s<sub>u</sub></i> is a random group element and is unique for every decryption key <i>dk<sub>u</sub>.</i></claim-text></claim-text></claim>
<claim id="c-en-01-0002" num="0002">
<claim-text>The method defined in claim 1 wherein the session key <i>SK</i> is computed by the encryption engine using a bilinear map as <maths id="math0023" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi>β</mi></msubsup></mfenced><mi>t</mi></msup><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><mi>g</mi><mo>⁢</mo><mi>g</mi></mfenced><mrow><mi>β</mi><mo>⁢</mo><mi>r</mi><mo>⁢</mo><msup><mi>α</mi><mfenced separators=""><mi>n</mi><mo>+</mo><mn>1</mn></mfenced></msup><mo>⁢</mo><mi>t</mi></mrow></msup><mn>.</mn></math><img id="ib0023" file="imgb0023.tif" wi="58" he="11" img-content="math" img-format="tif" inline="yes"/></maths></claim-text></claim>
<claim id="c-en-01-0003" num="0003">
<claim-text>The method defined in claim 1 further comprising providing the decryption engine with the decryption key <i>dk<sub>u</sub></i> associated with at least one positive and one negative attribute, providing the decryption engine with the cryptogram hdr consisting of at least 2N+1 group elements, and providing the decryption engine with the conjunctive normal form (CNF) expression over a set of attributes of N clauses corresponding to the said cryptogram.</claim-text></claim>
<claim id="c-en-01-0004" num="0004">
<claim-text>The method defined in claims 1 and 3 further comprising computing for each of N clauses by the decryption engine the intermediate values <maths id="math0024" num=""><math display="inline"><msubsup><mi mathvariant="italic">SK</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>=</mo><mfrac><mrow><mi>e</mi><mfenced separators=""><msubsup><mi>g</mi><mi>k</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>⁢</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>1</mn></mrow></msub></mfenced></mrow><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><msub><mi>d</mi><mi>k</mi></msub><mo>⋅</mo><mstyle displaystyle="true"><munder><mo>∏</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>υ</mi><mi>i</mi></msub><mo>,</mo><mi>j</mi><mo>≠</mo><mi>k</mi></mrow></munder></mstyle><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi><mo>+</mo><mi>k</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>0</mn></mrow></msub></mfenced></mrow></mfrac><mo>,</mo></math><img id="ib0024" file="imgb0024.tif" wi="60" he="24" img-content="math" img-format="tif" inline="yes"/></maths> wherein <i>d<sub>k</sub></i> is explicitly associated with an attribute present in the said clause.<!-- EPO <DP n="14"> --></claim-text></claim>
<claim id="c-en-01-0005" num="0005">
<claim-text>The method defined in claim 4 wherein the said intermediate values are computed using bilinear maps.</claim-text></claim>
<claim id="c-en-01-0006" num="0006">
<claim-text>The method defined in claims 4 or 5 further comprising computing by the decryption engine the value of the session key <maths id="math0025" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mfrac><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mn>0</mn></msub><mo>,</mo><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup></mfenced></mrow><mrow><mstyle displaystyle="true"><munderover><mo>∏</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><mi>S</mi><mo>⁢</mo><msubsup><mi>K</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup></mrow></mfrac><mn>.</mn></math><img id="ib0025" file="imgb0025.tif" wi="41" he="20" img-content="math" img-format="tif" inline="yes"/></maths></claim-text></claim>
<claim id="c-en-01-0007" num="0007">
<claim-text>The method defined in claims 1, 3, 4 and 6 further comprising using the session key or parts thereof to derive a symmetric key to decrypt the message, or to decrypt the message with said session key.</claim-text></claim>
<claim id="c-en-01-0008" num="0008">
<claim-text>The method defined in claims 1, 3, 4 and 6 wherein the said session key SK is computed using a bilinear map.</claim-text></claim>
<claim id="c-en-01-0009" num="0009">
<claim-text>A device adapted to implement the method of any of claims 1 to 8.</claim-text></claim>
</claims>
<claims id="claims02" lang="de"><!-- EPO <DP n="15"> -->
<claim id="c-de-01-0001" num="0001">
<claim-text>Verfahren zur attributbezogenen Verschlüsselung einer Nachricht unter Verwendung von Ausdrücken in konjunktiver Normalform (KNF), wobei der besagte KNF-Ausdruck mindestens eine Klausel über eine Menge von <i>n</i> Attributen umfasst und das besagte Verfahren einen Schlüsselgenerator, eine Verschlüsselungsroutine und eine Entschlüsselungsroutine verwendet, mit folgenden Phasen:
<claim-text>a. Erzeugung, mit Hilfe des Schlüsselgenerators: eines zufälligen <i>g</i> ∈ <i>G</i>, wobei <i>G</i> eine Gruppe <i>p</i>-ter Ordnung ist, wobei <i>p</i> eine Primzahl ist; vier zufälliger Werte α,γ,β,<i>r</i> ∈<i><sub>R</sub></i> Z/<i>p</i>Z, und für <i>i</i> = 1,2,...,<i>n</i>,<i>n</i>+2,...,2<i>n</i> wobei <i>n</i> die Zahl der Attribute ist; und Berechnung, mit Hilfe des Schlüsselgenerators, von mindestens 2n-1 Werten <i>g<sub>i</sub></i> = <i>g</i><sup>α<i><sup>i</sup></i></sup> ∈ <i>G</i> und mindestens eines Wertes <i>v</i> = <i>g</i><sup>γ</sup> ∈ <i>G</i>;</claim-text>
<claim-text>b. Erzeugung, mit Hilfe der Verschlüsselungsroutine, eines Chiffrierschlüssels <maths id="math0026" num=""><math display="inline"><mi mathvariant="italic">PK</mi><mo>=</mo><mfenced separators=""><msup><mi>g</mi><mi>r</mi></msup><mo>⁢</mo><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><mi>r</mi></msubsup><mo>⁢</mo><msup><mi>v</mi><mi>r</mi></msup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi mathvariant="normal">β</mi></msubsup><mo>⁢</mo><msub><mi>g</mi><mi>n</mi></msub></mfenced><mo>,</mo></math><img id="ib0026" file="imgb0026.tif" wi="78" he="10" img-content="math" img-format="tif" inline="yes"/></maths> der mindestens 2n+3 Gruppenelemente umfasst;</claim-text>
<claim-text>c. für einen oben erwähnten KNF-Ausdruck über eine Menge von Attributen, wobei der KNF-Ausdruck N Klauseln umfasst, Erzeugung, mit Hilfe der Verschlüsselungsroutine, von N zufälligen Werten <i>t</i><sub>1</sub>,<i>t</i><sub>2</sub>,...,<i>t<sub>N</sub></i> ∈<i><sub>R</sub></i> Z/<i>p</i>Z, Berechnung, mit Hilfe der Verschlüsselungsroutine, des Wertes <maths id="math0027" num=""><math display="inline"><mi>t</mi><mo>=</mo><munderover><mi mathvariant="normal">Σ</mi><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover><msub><mi>t</mi><mi>i</mi></msub></math><img id="ib0027" file="imgb0027.tif" wi="15" he="14" img-content="math" img-format="tif" inline="yes"/></maths> mod <i>p</i>, Erzeugung, der mit Hilfe der Verschlüsselungsroutine, eines Kryptogramms<maths id="math0028" num=""><math display="inline"><mi>h</mi><mo>⁢</mo><mi>d</mi><mo>⁢</mo><msub><mi>r</mi><mi>i</mi></msub><mo>=</mo><mfenced><msup><mi>g</mi><mrow><mi>r</mi><mo>⁢</mo><msub><mi>t</mi><mi>i</mi></msub></mrow></msup><msup><mfenced separators=""><msup><mi>v</mi><mi>r</mi></msup><mo>⁢</mo><munder><mi mathvariant="normal">Π</mi><mrow><mi>j</mi><mo>∈</mo><msub><mi>v</mi><mi>i</mi></msub></mrow></munder><mspace width="1em"/><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi></mrow><mi>r</mi></msubsup></mfenced><msub><mi>t</mi><mi>i</mi></msub></msup></mfenced></math><img id="ib0028" file="imgb0028.tif" wi="44" he="9" img-content="math" img-format="tif" inline="yes"/></maths> das aus mindestens 2N+1-Gruppenelementen besteht, mit <maths id="math0029" num=""><math display="inline"><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mi>i</mi></msub><mo>=</mo><mfenced separators=""><msup><mi>g</mi><msub><mi mathvariant="italic">rt</mi><mi>i</mi></msub></msup><mo>⁢</mo><msup><mfenced separators=""><msup><mi>v</mi><mi>r</mi></msup><mstyle displaystyle="true"><munder><mo>∏</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>υ</mi><mi>i</mi></msub></mrow></munder></mstyle><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi></mrow><mi>r</mi></msubsup></mfenced><msub><mi>t</mi><mi>i</mi></msub></msup></mfenced></math><img id="ib0029" file="imgb0029.tif" wi="52" he="21" img-content="math" img-format="tif" inline="yes"/></maths> für jede Klausel υ<i><sub>i</sub></i> in dem oben erwähnten KNF-Ausdruck und durch Erzeugung eines Sitzungsschlüssels <i>SK</i>, wobei der besagte Sitzungsschlüssel, oder Teile davon, benutzt wird, um einen symmetrischen Schlüssel<!-- EPO <DP n="16"> --> abzuleiten, der benutzt wird, um die Nachricht zu verschlüsseln, oder um die Nachricht mit dem besagten Sitzungsschlüssel zu verschlüsseln;</claim-text>
<claim-text>d. Erzeugung, mit Hilfe des Schlüsselgenerators, einer Vielzahl von privaten Dechiffrierschlüsseln <maths id="math0030" num=""><math display="inline"><msub><mi mathvariant="italic">dk</mi><mi>u</mi></msub><mo>=</mo><mfenced><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup><msubsup><mi>g</mi><mn>1</mn><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><msub><mi>d</mi><msub><mi>i</mi><mn>1</mn></msub></msub><mo>…</mo><msub><mi>d</mi><msub><mi>i</mi><mi>N</mi></msub></msub><msub><mi>d</mi><msub><mi>j</mi><mn>1</mn></msub></msub><mo>…</mo><msub><mi>d</mi><msub><mi>j</mi><mi>R</mi></msub></msub></mfenced></math><img id="ib0030" file="imgb0030.tif" wi="104" he="10" img-content="math" img-format="tif" inline="yes"/></maths> wobei jeder der besagten Dechiffrierschlüssel mittels des Gruppenelements <maths id="math0031" num=""><math display="inline"><msub><mi>d</mi><msub><mi>i</mi><mi>j</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>i</mi><mi>j</mi></msub><mrow><mi mathvariant="normal">γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0031" file="imgb0031.tif" wi="18" he="11" img-content="math" img-format="tif" inline="yes"/></maths> mindestens einem positiven Merkmal eindeutig zugeordnet ist und mittels des Gruppenelements <maths id="math0032" num=""><math display="inline"><msub><mi>d</mi><msub><mi>j</mi><mi>k</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>j</mi><mi>k</mi></msub><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0032" file="imgb0032.tif" wi="18" he="8" img-content="math" img-format="tif" inline="yes"/></maths> mindestens einem negativen Merkmal eindeutig zugeordnet ist, wobei der <i>Wert s<sub>u</sub></i> ein zufälliges Gruppenelement und für jeden Dechiffrierschlüssel <i>dk<sub>u</sub></i> einmalig ist.</claim-text></claim-text></claim>
<claim id="c-de-01-0002" num="0002">
<claim-text>Verfahren nach Anspruch 1, wobei der Sitzungsschlüssel <i>SK</i> von der Verschlüsselungsroutine unter Verwendung einer bilinearen Abbildung wie <maths id="math0033" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi>β</mi></msubsup></mfenced><mi>t</mi></msup><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><mi>g</mi><mo>⁢</mo><mi>g</mi></mfenced><mrow><mi>β</mi><mo>⁢</mo><mi>r</mi><mo>⁢</mo><msup><mi>α</mi><mfenced separators=""><mi>n</mi><mo>+</mo><mn>1</mn></mfenced></msup><mo>⁢</mo><mi>t</mi></mrow></msup><mn>.</mn></math><img id="ib0033" file="imgb0033.tif" wi="54" he="8" img-content="math" img-format="tif" inline="yes"/></maths> berechnet wird.</claim-text></claim>
<claim id="c-de-01-0003" num="0003">
<claim-text>Verfahren nach Anspruch 1, wobei die Entschlüsselungsroutine des weiteren den Dechiffrierschlüssel <i>dk<sub>u</sub></i> umfasst, dem mindestens ein positives und ein negatives Merkmal zugeordnet ist, wobei die Entschlüsselungsroutine das Kryptogramm hdr umfasst, bestehend aus mindestens 2N+1- Gruppenelementen, und wobei die Entschlüsselungsroutine den Ausdruck in konjunktiver Normalform (KNF) über eine Menge von Attributen von N Klauseln entsprechend dem besagten Kryptogramm umfasst.</claim-text></claim>
<claim id="c-de-01-0004" num="0004">
<claim-text>Verfahren nach den Ansprüchen 1 und 3 mit zusätzlicher Berechnung der Zwischenwerte <maths id="math0034" num=""><math display="inline"><msubsup><mi mathvariant="italic">SK</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>=</mo><mfrac><mrow><mi>e</mi><mfenced separators=""><msubsup><mi>g</mi><mi>k</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>⁢</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>1</mn></mrow></msub></mfenced></mrow><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><msub><mi>d</mi><mi>k</mi></msub><mo>⋅</mo><mstyle displaystyle="true"><munder><mo>∏</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>υ</mi><mi>i</mi></msub><mo>,</mo><mi>j</mi><mo>≠</mo><mi>k</mi></mrow></munder></mstyle><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi><mo>+</mo><mi>k</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>0</mn></mrow></msub></mfenced></mrow></mfrac></math><img id="ib0034" file="imgb0034.tif" wi="59" he="24" img-content="math" img-format="tif" inline="yes"/></maths> für jede von N Klauseln<!-- EPO <DP n="17"> --> durch die Entschlüsselungsroutine, wobei <i>d<sub>k</sub></i> ein Merkmal, das in der besagten Klausel vorhanden ist, eindeutig zugeordnet ist.</claim-text></claim>
<claim id="c-de-01-0005" num="0005">
<claim-text>Verfahren nach Anspruch 4, wobei die Zwischenwerte unter Verwendung von bilinearen Abbildungen berechnet werden.</claim-text></claim>
<claim id="c-de-01-0006" num="0006">
<claim-text>Verfahren nach den Ansprüchen 4 oder 5 mit zusätzlicher Berechnung des Wertes des Sitzungsschlüssels <maths id="math0035" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mfrac><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mn>0</mn></msub><mo>,</mo><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi mathvariant="normal">β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup></mfenced></mrow><mrow><mstyle displaystyle="true"><munderover><mo>∏</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><mi>S</mi><mo>⁢</mo><msubsup><mi>K</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup></mrow></mfrac></math><img id="ib0035" file="imgb0035.tif" wi="40" he="21" img-content="math" img-format="tif" inline="yes"/></maths> durch die der Entschlüsselungsroutine.</claim-text></claim>
<claim id="c-de-01-0007" num="0007">
<claim-text>Verfahren nach den Ansprüchen 1, 3, 4 und 6 mit zusätzlicher Verwendung des Sitzungsschlüssels oder von Teilen davon, um einen symmetrischen Schlüssel abzuleiten, um die Nachricht zu entschlüsseln, oder um die Nachricht mit besagtem Sitzungsschlüssel zu entschlüsseln.</claim-text></claim>
<claim id="c-de-01-0008" num="0008">
<claim-text>Verfahren nach den Ansprüchen 1, 3, 4 und 6, wobei der Sitzungsschlüssel SK unter Verwendung einer bilinearen Abbildung berechnet wird.</claim-text></claim>
<claim id="c-de-01-0009" num="0009">
<claim-text>Vorrichtung zur Durchführung des Verfahrens nach einem beliebigen der Ansprüche 1 bis 8.</claim-text></claim>
</claims>
<claims id="claims03" lang="fr"><!-- EPO <DP n="18"> -->
<claim id="c-fr-01-0001" num="0001">
<claim-text>Méthode pour assurer un cryptage à base d'attributs pour un message utilisant des expressions de forme normale conjonctive (FNC), ladite expression FNC comprenant au moins une clause sur un ensemble de n attributs, ladite méthode utilisant un générateur de clés, un moteur de chiffrement et un moteur de déchiffrement, et comprenant les étapes suivantes:
<claim-text>a. générer au moyen du générateur de clés: une valeur aléatoire <i>g</i> ∈ <i>G</i>, où <i>G</i> est un groupe d'ordre <i>p</i> où <i>p</i> est un nombre premier, quatre valeurs aléatoires α,γ,β,<i>r</i> ∈<i><sub>R</sub></i> Z/<i>p</i>Z, et pour <i>i</i> = 1,2,... ,<i>n,n</i> + 2,... ,2<i>n</i> où <i>n</i> est le nombre d'attributs, calculer au moyen du générateur de clés au moins 2n-1 valeurs <i>g<sub>i</sub> =g</i><sup>α<i><sup>i</sup></i></sup> ∈ <i>G</i> et au moins une valeur <i>v</i> = <i>g</i><sup>γ</sup> ∈ <i>G</i>;</claim-text>
<claim-text>b. générer par le moteur de chiffrement une clé de chiffrement <maths id="math0036" num=""><math display="inline"><mi mathvariant="italic">PK</mi><mo>=</mo><mfenced><msup><mi>g</mi><mi>r</mi></msup><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><mi>r</mi></msubsup><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><mi>r</mi></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><mi>r</mi></msubsup><msup><mi>v</mi><mi>r</mi></msup><msubsup><mi>g</mi><mi>n</mi><mi mathvariant="normal">β</mi></msubsup><msub><mi>g</mi><mi>n</mi></msub></mfenced></math><img id="ib0036" file="imgb0036.tif" wi="72" he="8" img-content="math" img-format="tif" inline="yes"/></maths> comprenant au moins 2n+3 éléments de groupe;</claim-text>
<claim-text>c. pour une expression FNC précitée sur un ensemble d'attributs, l'expression FNC comprenant N clauses, générer par le moteur de chiffrement N valeurs aléatoires <i>t</i><sub>1</sub>,<i>t</i><sub>2</sub>,... ,<i>t<sub>N</sub></i> ∈<i><sub>R</sub></i> Z/<i>p</i>Z, calculer par le moteur de chiffrement la valeur <maths id="math0037" num=""><math display="inline"><mi>t</mi><mo>=</mo><munderover><mi mathvariant="normal">Σ</mi><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover><msub><mi>t</mi><mi>i</mi></msub></math><img id="ib0037" file="imgb0037.tif" wi="14" he="13" img-content="math" img-format="tif" inline="yes"/></maths> mod <i>p</i>, générer par le moteur de chiffrement un cryptogramme <maths id="math0038" num=""><math display="inline"><mi mathvariant="italic">hdr</mi><mo>=</mo><mfenced separators=""><msubsup><mi>g</mi><mi>n</mi><mi>t</mi></msubsup><mo>⁢</mo><msub><mi mathvariant="italic">hdr</mi><mn>1</mn></msub><mn>...</mn><msub><mi mathvariant="italic">hdr</mi><mi>N</mi></msub></mfenced></math><img id="ib0038" file="imgb0038.tif" wi="44" he="9" img-content="math" img-format="tif" inline="yes"/></maths> constitué d'au moins 2N+1- éléments de groupe avec <maths id="math0039" num=""><math display="inline"><mi>h</mi><mo>⁢</mo><mi>d</mi><mo>⁢</mo><msub><mi>r</mi><mi>i</mi></msub><mo>=</mo><mfenced><msup><mi>g</mi><mrow><mi>r</mi><mo>⁢</mo><msub><mi>t</mi><mi>i</mi></msub></mrow></msup><msup><mfenced separators=""><msup><mi>v</mi><mi>r</mi></msup><mo>⁢</mo><munder><mi mathvariant="normal">Π</mi><mrow><mi>j</mi><mo>∈</mo><msub><mi>v</mi><mi>i</mi></msub></mrow></munder><mspace width="1em"/><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi></mrow><mi>r</mi></msubsup></mfenced><msub><mi>t</mi><mi>i</mi></msub></msup></mfenced></math><img id="ib0039" file="imgb0039.tif" wi="48" he="18" img-content="math" img-format="tif" inline="yes"/></maths> pour chaque clause υ<i><sub>i</sub></i> dans l'expression FNC précitée et générer une clé de session <i>SK</i>, dans laquelle ladite clé de session, ou des parties de celle-ci, est utilisée pour dériver une clé symétrique qui est utilisée pour chiffrer le message, ou pour chiffrer le message avec ladite clé de session;<!-- EPO <DP n="19"> --></claim-text>
<claim-text>d. générer par le générateur de clés une pluralité de clés de déchiffrement privées<maths id="math0040" num=""><math display="inline"><msub><mi mathvariant="italic">dk</mi><mi>u</mi></msub><mo>=</mo><mfenced><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup><msubsup><mi>g</mi><mn>1</mn><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>…</mo><msubsup><mi>g</mi><mi>n</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>2</mn></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>…</mo><msubsup><mi>g</mi><mrow><mn>2</mn><mo>⁢</mo><mi>n</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><msub><mi>d</mi><msub><mi>i</mi><mn>1</mn></msub></msub><mo>…</mo><msub><mi>d</mi><msub><mi>i</mi><mi>N</mi></msub></msub><msub><mi>d</mi><msub><mi>j</mi><mn>1</mn></msub></msub><mo>…</mo><msub><mi>d</mi><msub><mi>j</mi><mi>R</mi></msub></msub></mfenced><mo>,</mo></math><img id="ib0040" file="imgb0040.tif" wi="100" he="11" img-content="math" img-format="tif" inline="yes"/></maths> chacune desdites clés de déchiffrement étant explicitement associée à au moins un attribut positif au moyen de l'élément de groupe <maths id="math0041" num=""><math display="inline"><msub><mi>d</mi><msub><mi>i</mi><mi>j</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>i</mi><mi>j</mi></msub><mrow><mi mathvariant="normal">γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0041" file="imgb0041.tif" wi="17" he="9" img-content="math" img-format="tif" inline="yes"/></maths> et explicitement associée à au moins un attribut négatif au moyen de l'élément de groupe <maths id="math0042" num=""><math display="inline"><msub><mi>d</mi><msub><mi>j</mi><mi>k</mi></msub></msub><mo>=</mo><msubsup><mi>g</mi><msub><mi>j</mi><mi>k</mi></msub><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>s</mi><mi>u</mi></msub></mrow></msubsup></math><img id="ib0042" file="imgb0042.tif" wi="18" he="9" img-content="math" img-format="tif" inline="yes"/></maths> dans lequel la valeur <i>s<sub>u</sub></i> est un élément de groupe aléatoire et est unique pour chaque clé de déchiffrement <i>dk<sub>u</sub></i>.</claim-text></claim-text></claim>
<claim id="c-fr-01-0002" num="0002">
<claim-text>Méthode selon la revendication 1, <b>caractérisée en ce que</b> la clé de session <i>SK</i> est calculée par le moteur de chiffrement en utilisant une application bilinéaire comme <maths id="math0043" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><msubsup><mi>g</mi><mn>1</mn><mi>r</mi></msubsup><mo>⁢</mo><msubsup><mi>g</mi><mi>n</mi><mi>β</mi></msubsup></mfenced><mi>t</mi></msup><mo>=</mo><mi>e</mi><mo>⁢</mo><msup><mfenced separators=""><mi>g</mi><mo>⁢</mo><mi>g</mi></mfenced><mrow><mi>β</mi><mo>⁢</mo><mi>r</mi><mo>⁢</mo><msup><mi>α</mi><mfenced separators=""><mi>n</mi><mo>+</mo><mn>1</mn></mfenced></msup><mo>⁢</mo><mi>t</mi></mrow></msup><mn>.</mn></math><img id="ib0043" file="imgb0043.tif" wi="57" he="12" img-content="math" img-format="tif" inline="yes"/></maths></claim-text></claim>
<claim id="c-fr-01-0003" num="0003">
<claim-text>Méthode selon la revendication 1, comprenant en outre une étape visant à fournir au moteur de déchiffrement une clé de déchiffrement <i>dk<sub>u</sub></i> associée à au moins un attribut positif et un attribut négatif, fournir au moteur de déchiffrement un cryptogramme hdr constitué d'au moins 2N+1- éléments de groupe, et fournir au moteur de déchiffrement l'expression de forme normale conjonctive (FNC) sur un ensemble d'attributs de N clauses correspondant audit cryptogramme.</claim-text></claim>
<claim id="c-fr-01-0004" num="0004">
<claim-text>Méthode selon les revendications 1 et 3, comprenant en outre, pour chacune des N clauses, le calcul par le moteur de déchiffrement des valeurs intermédiaires <maths id="math0044" num=""><math display="inline"><msubsup><mi mathvariant="italic">SK</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>=</mo><mfrac><mrow><mi>e</mi><mfenced><msubsup><mi>g</mi><mi>k</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>1</mn></mrow></msub></mfenced></mrow><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><msub><mi>d</mi><mi>k</mi></msub><mo>⋅</mo><mstyle displaystyle="true"><munder><mo>∏</mo><mrow><mi>j</mi><mo>∈</mo><msub><mi>υ</mi><mi>i</mi></msub><mo>,</mo><mi>j</mi><mo>≠</mo><mi>k</mi></mrow></munder></mstyle><msubsup><mi>g</mi><mrow><mi>n</mi><mo>+</mo><mn>1</mn><mo>-</mo><mi>j</mi><mo>+</mo><mi>k</mi></mrow><msub><mi>s</mi><mi>u</mi></msub></msubsup><mo>,</mo><msub><mi mathvariant="italic">hdr</mi><mrow><mi>i</mi><mo>,</mo><mn>0</mn></mrow></msub></mfenced></mrow></mfrac><mo>,</mo></math><img id="ib0044" file="imgb0044.tif" wi="57" he="21" img-content="math" img-format="tif" inline="yes"/></maths> dans lesquelles <i>d<sub>k</sub></i> est explicitement associé à un attribut présent dans ladite clause.<!-- EPO <DP n="20"> --></claim-text></claim>
<claim id="c-fr-01-0005" num="0005">
<claim-text>Méthode selon la revendication 4, <b>caractérisée en ce que</b> lesdites valeurs intermédiaires sont calculées en utilisant des applications bilinéaires.</claim-text></claim>
<claim id="c-fr-01-0006" num="0006">
<claim-text>Méthode selon les revendications 4 ou 5, comprenant en outre le calcul par le moteur de déchiffrement de la valeur de la clé de session <maths id="math0045" num=""><math display="inline"><mi mathvariant="italic">SK</mi><mo>=</mo><mfrac><mrow><mi>e</mi><mo>⁢</mo><mfenced separators=""><mi mathvariant="italic">hd</mi><mo>⁢</mo><msub><mi>r</mi><mn>0</mn></msub><mo>,</mo><msubsup><mi>g</mi><mn>1</mn><mrow><mi>r</mi><mo>⁢</mo><mfenced separators=""><mi>β</mi><mo>+</mo><msub><mi>s</mi><mi>u</mi></msub></mfenced></mrow></msubsup></mfenced></mrow><mrow><mstyle displaystyle="true"><munderover><mo>∏</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>N</mi></munderover></mstyle><mi>S</mi><mo>⁢</mo><msubsup><mi>K</mi><mi>i</mi><msub><mi>s</mi><mi>u</mi></msub></msubsup></mrow></mfrac><mn>.</mn></math><img id="ib0045" file="imgb0045.tif" wi="41" he="20" img-content="math" img-format="tif" inline="yes"/></maths></claim-text></claim>
<claim id="c-fr-01-0007" num="0007">
<claim-text>Méthode selon les revendications 1, 3, 4 et 6 comprenant en outre l'utilisation de la clé de session, ou de parties de celle-ci, pour dériver une clé symétrique pour déchiffrer le message, ou pour déchiffrer le message avec ladite clé de session.</claim-text></claim>
<claim id="c-fr-01-0008" num="0008">
<claim-text>Méthode selon les revendications 1, 3, 4 et 6, <b>caractérisée en ce que</b> ladite clé de session SK est calculée en utilisant une application bilinéaire.</claim-text></claim>
<claim id="c-fr-01-0009" num="0009">
<claim-text>Dispositif pour la mise en oeuvre de la méthode selon l'une quelconque des revendications 1 à 8.</claim-text></claim>
</claims>
<drawings id="draw" lang="en"><!-- EPO <DP n="21"> -->
<figure id="f0001" num="1,2"><img id="if0001" file="imgf0001.tif" wi="163" he="218" img-content="drawing" img-format="tif"/></figure>
</drawings>
<ep-reference-list id="ref-list">
<heading id="ref-h0001"><b>REFERENCES CITED IN THE DESCRIPTION</b></heading>
<p id="ref-p0001" num=""><i>This list of references cited by the applicant is for the reader's convenience only. It does not form part of the European patent document. Even though great care has been taken in compiling the references, errors or omissions cannot be excluded and the EPO disclaims all liability in this regard.</i></p>
<heading id="ref-h0002"><b>Non-patent literature cited in the description</b></heading>
<p id="ref-p0002" num="">
<ul id="ref-ul0001" list-style="bullet">
<li><nplcit id="ref-ncit0001" npl-type="b"><article><atl>Broadcast encryption</atl><book><author><name>A. FIAT</name></author><author><name>M. NAOR</name></author><book-title>CRYPTO'93, Lecture Notes in Computer Science 773</book-title><imprint><name>Springer-Verlag</name><pubdate>19940000</pubdate></imprint><location><pp><ppf>480491</ppf><ppl/></pp></location></book></article></nplcit><crossref idref="ncit0001">[0030]</crossref></li>
<li><nplcit id="ref-ncit0002" npl-type="b"><article><atl>Fuzzy identity-based encryption.</atl><book><author><name>A. SAHAI</name></author><author><name>B. WATERS</name></author><book-title>Advances in Cryptology - EUROCRYPT 2005, 24th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Aarhus, Denmark</book-title><imprint><name/><pubdate>20050000</pubdate></imprint><location><pp><ppf>457</ppf><ppl>473</ppl></pp></location></book></article></nplcit><crossref idref="ncit0002">[0030]</crossref></li>
<li><nplcit id="ref-ncit0003" npl-type="s"><article><author><name>J. BETHENCOURT</name></author><author><name>A. SAHAI</name></author><author><name>B. WATERS.</name></author><atl>Ciphertext-policy attribute-based encryption</atl><serial><sertitle>2007 IEEE Symposium on Security and Privacy</sertitle><pubdate><sdate>20070520</sdate><edate/></pubdate></serial><location><pp><ppf>321</ppf><ppl>334</ppl></pp></location></article></nplcit><crossref idref="ncit0003">[0030]</crossref></li>
<li><nplcit id="ref-ncit0004" npl-type="s" url="http://eprint.iacr.org/2008/290.pdf, 2008. Unpublished manuscript"><article><author><name>B. WATERS</name></author><atl/><serial><sertitle>Ciphertext-policy attribute-based encryption: An expressive, efficient, and provably secure realization</sertitle></serial></article></nplcit><crossref idref="ncit0004">[0030]</crossref></li>
<li><nplcit id="ref-ncit0005" npl-type="b"><article><atl>Attribute-based broadcast encryption scheme made efficient</atl><book><author><name>D. LUBICZ</name></author><author><name>T. SIRVENT et al.</name></author><book-title>Proc. of Advances in Cryptology - Africacrypt'08</book-title><imprint><name>LNCS</name><pubdate>20080000</pubdate></imprint><vid>5023</vid><location><pp><ppf>325</ppf><ppl>342</ppl></pp></location></book></article></nplcit><crossref idref="ncit0005">[0030]</crossref></li>
<li><nplcit id="ref-ncit0006" npl-type="s"><article><author><name>N. ATTRAPADUNG</name></author><author><name>H. IMAI</name></author><atl>Conjunctive broadcast and attribute-based encryption</atl><serial><sertitle>Pairing-Based Cryptography - Pairing 2009, Third International Conference, Palo Alto, CA, USA</sertitle><pubdate><sdate>20090812</sdate><edate/></pubdate></serial><location><pp><ppf>248</ppf><ppl>265</ppl></pp></location></article></nplcit><crossref idref="ncit0006">[0030]</crossref></li>
<li><nplcit id="ref-ncit0007" npl-type="s" url="http://crypto.stanford.edu/miller/miller.pdf"><article><author><name>V. MILLER</name></author><atl/><serial><sertitle>Short program for functions on curves</sertitle><pubdate><sdate>19860000</sdate><edate/></pubdate></serial></article></nplcit><crossref idref="ncit0007">[0030]</crossref></li>
<li><nplcit id="ref-ncit0008" npl-type="b"><article><atl>Efficient Algorithms for Pairing-Based Cryptosystems</atl><book><author><name>P. BARRETO</name></author><author><name>H. KIM</name></author><author><name>B. LYNN</name></author><author><name>M. SCOTT.</name></author><book-title>Advances in Cryptology- CRYPTO 2002, 22nd Annual International Cryptology Conference</book-title><imprint><name>Springer-Verlag</name><pubdate>20020000</pubdate></imprint><location><pp><ppf>354</ppf><ppl>368</ppl></pp></location></book></article></nplcit><crossref idref="ncit0008">[0030]</crossref></li>
</ul></p>
</ep-reference-list>
</ep-patent-document>
