摘要 |
<p>Various embodiments relate to a method for integrity protected calculation of a cryptographic function including: performing an operation c = a o b in a cryptographic function f(x 1 , x 2 , ... , x n ) defined over a commutative ring R; choosing a' and b' corresponding to a and b such that a' and b' are elements of a commutative ring R'; computing c' = a' o' b'; computing a" = CRT(a, a') and b" = CRT(b, b'), where CRT is the Chinese Remainder Theorem; computing c" = a" o" b"; mapping c" into R'; and determining if the mapping ofc" into R' equals c'.</p> |