Embodiments of the present application provide a
key encapsulation method and device, the method comprising: in response to a
key encapsulation request for transmitting data to a receiving end, obtaining a public key corresponding to the receiving end, and encoding a
plaintext message to be encapsulated into a message polynomial on a polynomial ring; performing linear compression on the message polynomial using an inverse element of a preset small coefficient polynomial to obtain a compressed
plaintext polynomial; generating a first
ciphertext component based on a second public key component and an
encryption polynomial, and generating a second
ciphertext component based on a first public key component and the compressed
plaintext polynomial. The encapsulation result containing the first
ciphertext component and the second ciphertext component is sent to the receiving end, so that the receiving end uses a corresponding private key to unencapsulate the encapsulation result, obtains the compressed plaintext polynomial, and
decodes the compressed plaintext polynomial to restore the plaintext message. This can effectively
resist quantum computers, effectively reduce the ciphertext length of the encapsulated plaintext message, and further reduce storage and communication overhead.