This invention provides a method for estimating the resistance of a lattice-based
encryption algorithm to decryption error attacks, comprising: Step 1: Calculating a distribution table of perturbations generated by public-key compression and
ciphertext compression; Step 2: Statistically calculating the mean and variance of the probability distributions satisfied by the private key, temporary private key, and error vector coordinates based on the distribution table; Step 3: Traversing the values of the probability distributions satisfied by the error vector coordinates during the
encryption phase of the lattice-based
encryption algorithm, calculating the attacker's computational cost and
attack strategy corresponding to a fixed perturbation value for each
plaintext loading unit; Step 4: Obtaining an estimate of the computational cost of a decryption error
attack and the
attack strategy based on the attacker's computational cost and
attack strategy. This invention introduces the
impact of public-key compression and
ciphertext compression, which are beyond the attacker's control, into the calculation rule for estimating attack costs. This more accurately reflects the factors that need to be considered in actual attacks, and the inclusion of this perturbation data in the attack cost
estimation examines its
impact on the attacker's computational cost.